eagnews.org
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- WordPress
- Analytics
-
- Google Analytics
- Google Tag Manager
- Ads
-
- Google AdSense
- Meta Pixel
- Fonts
-
- Google Fonts
- Social widgets
-
- Twitter Widget
- Vimeo Embed
Third-party hosts loaded (30)
- cdnjs.cloudflare.com×8
- connect.facebook.net×2
- fonts.googleapis.com×2
- platform.twitter.com×2
- a.vimeocdn.com×1
- api.twitter.com×1
- b.vimeocdn.com×1
- cdn.theardent.group×1
- clients6.google.com×1
- cloudflare.com×1
- edge.quantserve.com×1
- facebook.com×1
- google-analytics.com×1
- google.com×1
- googletagservices.com×1
- graph.facebook.com×1
- img.youtube.com×1
- pagead2.googlesyndication.com×1
- pixel.quantserve.com×1
- player.vimeo.com×1
- plus.google.com×1
- quantcast.com×1
- quantserve.com×1
- secure-a.vimeocdn.com×1
- secure-b.vimeocdn.com×1
- secure.quantserve.com×1
- twitter.com×1
- urls.api.twitter.com×1
- vimeo.com×1
- vimeocdn.com×1
Social
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2012-03-26
- Expires
- 2027-03-26 309 days left
- Updated
- 2026-05-10
- Name servers
-
- erin.ns.cloudflare.com
- oswald.ns.cloudflare.com
DNS records live
- NS
-
- erin.ns.cloudflare.com
- oswald.ns.cloudflare.com
- MX
-
- 10 aspmx.l.google.com
- 20 alt1.aspmx.l.google.com
- 20 alt2.aspmx.l.google.com
- 30 aspmx2.googlemail.com
- 30 aspmx3.googlemail.com
- TXT
-
0pzb5xhpy9n25x1v44n2h0p0sfrgrbr8
Email authentication weak
- SPF
-
v=spf1 include:_spf.google.com ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
WE1
Expires in 77 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- findings
-
- CSP allows unsafe inline scripts/styles
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- content-security-policy
upgrade-insecure-requests; default-src data: 'unsafe-inline' 'unsafe-eval' https:; script-src data: 'unsafe-inline' 'unsafe-eval' https: blob:; style-src data: 'unsafe-inline' https:; img-src data: https: blob:; font-src data: https:; connect-src https: wss: blob:; media-src data: https: blob:; object-src https:; child-src https: data: blob:; form-action https:;- strict-transport-security
max-age=15768000; includeSubdomains; preload