digitaldevelopment.org
HTML metadata
Technology
- CDN
- Fastly
- Server
- Flywheel
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (5)
- cdn.amcharts.com×4
- fonts.googleapis.com×3
- fonts.gstatic.com×2
- www.googletagmanager.com×2
- gmpg.org×1
Registration
- Registrar
- Network Solutions, LLC
- Created
- 2002-03-07
- Expires
- 2029-03-07 1021 days left
- Updated
- 2024-03-04
- Name servers
-
- ns15.worldnic.com
- ns16.worldnic.com
DNS records live
- NS
-
- ns15.worldnic.com
- ns16.worldnic.com
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzEycoqmm58v1blbbc3OYiklmxeB9nJqHY4320sypU5+l/FYD20mwgjVsUOawGbWy2GDU1WN0BxmR+rbub8… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA9H0TMzkwRoFhv1tDzrq1BmCfhMXFlbct6Fj8r9nCn993vhkPRbf770/Bd05+34DTpb801M1L7/Fvsp01Nx…
selectors probed - s1:
Certificate (current)
R12
Expires in 32 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
no-referrer-when-downgrade- permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=*, geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), picture-in-picture=*, publickey-credentials-get=(), screen-wake-lock=(), sync-script=(), sync-xhr=(), usb=(), vertical-scroll=(), web-share=*, xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' http: https://dev-www.digitaldevelopment.org https://dev-digitaldevelopment.flywheelstaging.com https://*.youtube.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' http: https://*.google.com https://*.googleapis.com https://*.googletagmanager.com https://*.youtube.com https://*.google-analytics.com https://*.ytimg.com https://*.moatads.com https://*.doubleclick.net *.bugherd.com *.pusher.com; style-src 'self' 'unsafe-inline' http: https://*.google.com https://*.googleapis.com https://*.youtube.com; img-src 'self' http: data: https://*.ytimg.com https://*.ggpht.com https://*.gstatic.com https://*.google-analytics.com d2iiunr5ws5ch1.cloudfront.net bugherd-attachments.s3.amazonaws.com *.bugherd.com; connect-src 'self' https://*.google-analytics.com https://*.googleapis.com *.pusher.com sessions.bugsnag.com *.bugherd.com wss://*.pusher.com; font-src 'self' data: fonts.gstatic.com use.typekit.net use.fontawesome.com; media-src 'self' *.youtube.com *.vimeo.com; report-u- strict-transport-security
max-age=31536000