ehonline.eu
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (6)
- www.googletagmanager.com×3
- www.facebook.com×2
- 2fa4e90d3716407e94c3c45659bb725d.js.ubembed.com×1
- ct.pinterest.com×1
- gmpg.org×1
- px.ads.linkedin.com×1
Social
DNS records live
- NS
-
- dns1.cscdns.net
- dns2.cscdns.net
- MX
-
- 10 mx4.mail.ovh.net
- 20 mx3.mail.ovh.net
- TXT
-
Show 4 TXT records
v=spf1 include:_netblocks.eloqua.com -all: facebook-domain-verification=wciglrryhtaod0z6p9eee9lo7a0rl7_globalsign-domain-verification=GlJOcGNNa3yqjpPg_62CQkYHyIPz0kw3CJVNkat37X_globalsign-domain-verification=JzR9oAvj0xONpOKcJP_62x0b767I3YJ8murPdP0AYJ
Certificate (current)
Amazon RSA 2048 M04
Expires in 141 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), ambient-light-sensor=(), autoplay=(self "https://www.youtube.com"), battery=(), camera=(), document-domain=(), encrypted-media=(), fullscreen=(), geolocation=(), magnetometer=(), microphone=(), midi=(), screen-wake-lock=(), web-share=(), wake-lock=()- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-inline' 'unsafe-eval' https: data: blob: https://static.hotjar.com/ https://www.google.com https://rxfrance.piwik.pro https://www.googletagmanager.com https://cdn.cookielaw.org https://securepubads.g.doubleclick.net; script-src-elem 'self' 'unsafe-inline' https: https://maps.googleapis.com/ https://reedexpo.automation.webmecanik.com/mtc.js https://script.hotjar.com/ https://img04.en25.com/i/elqCfg.min.js https://pixel.mathtag.com/ https://try.abtasty.com/ https://static.hotjar.com/ https://www.gstatic.com/ https://www.google.com/ https://a.quora.com/qevents.js https://d.adroll.com/ https://s.adroll.com https://ep1.adtrafficquality.google https://ep2.adtrafficquality.google https://googleads.g.doubleclick.net/ https://script.crazyegg.com/ https://connect.facebook.net https://static.ads-twitter.com https://snap.licdn.com https://rxfrance.piwik.pro https://img.en25.com *.ubembed.com https://www.googletagmanager.com/ https://cdn.cookielaw.org https://securepubads.- strict-transport-security
max-age=31536000; includeSubDomains- cross-origin-embedder-policy
unsafe-none- cross-origin-resource-policy
cross-origin