exaforcestatus.com
HTML metadata
Technology
- Server
- nginx
- Analytics
-
- Google Tag Manager
- Plausible
- Ads
-
- Google Ads (DoubleClick)
- Meta Pixel
Third-party hosts loaded (14)
- cdnjs.betterstack.com×4
- www.googletagmanager.com×3
- analytics.twitter.com×2
- bat.bing.com×2
- connect.facebook.net×2
- d1lppblt9t2x15.cloudfront.net×2
- forms.hsforms.com×2
- googleads.g.doubleclick.net×2
- js.hsforms.net×2
- plausible.io×2
- snap.licdn.com×2
- static.ads-twitter.com×2
- uptime.betterstack.com×2
- betterstack.com×1
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2023-11-24
- Expires
- 2028-11-24 920 days left
- Updated
- 2023-11-24
- Name servers
-
- ns69.domaincontrol.com
- ns70.domaincontrol.com
DNS records live
- NS
-
- ns69.domaincontrol.com
- ns70.domaincontrol.com
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
GoDaddy TLS Intermediate CA DV - R1v1
Expires in 146 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin- permissions-policy
accelerometer=(), autoplay=(), camera=(), encrypted-media=(), fullscreen=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=*, usb=()- x-content-type-options
nosniff- content-security-policy
base-uri *; frame-ancestors *; connect-src * 'unsafe-inline' 'unsafe-eval' data: blob: 'unsafe-hashes'; child-src * 'unsafe-inline' 'unsafe-eval' data: blob: 'unsafe-hashes'; frame-src * 'unsafe-inline' 'unsafe-eval' data: blob: 'unsafe-hashes'; media-src * 'unsafe-inline' 'unsafe-eval' data: blob: 'unsafe-hashes'; font-src * 'unsafe-inline' 'unsafe-eval' data: blob: 'unsafe-hashes'; form-action *; style-src * 'unsafe-inline' 'unsafe-eval' data: blob: 'unsafe-hashes'; script-src * 'unsafe-inline' 'unsafe-eval' data: blob: 'unsafe-hashes'; worker-src * 'unsafe-inline' 'unsafe-eval' data: blob: 'unsafe-hashes'; img-src * 'unsafe-inline' 'unsafe-eval' data: blob: 'unsafe-hashes'; default-src * 'unsafe-inline' 'unsafe-eval' data: blob: 'unsafe-hashes'- strict-transport-security
max-age=63113904; includeSubDomains; preload