giuricivile.it
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
- jQuery
- 3.7.1
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (9)
- cdn.exmarketplace.com×3
- imasdk.googleapis.com×3
- fonts.googleapis.com×2
- apis.google.com×1
- cdnjs.cloudflare.com×1
- i.creativecommons.org×1
- www.facebook.com×1
- www.google.com×1
- www.googletagmanager.com×1
Social
Contact
DNS records live
- NS
-
- dns.technorail.com
- dns2.technorail.com
- dns3.arubadns.net
- dns4.arubadns.cz
- MX
-
- 10 mx.giuricivile.it
Email authentication weak
- SPF
-
v=spf1 ip4:86.107.36.146 +mx +a +ip4:185.81.2.18/24 ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R12
Expires in 59 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), autoplay=*, camera=(), cross-origin-isolated=(), display-capture=(), encrypted-media=(), fullscreen=*, geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=*, publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=(), clipboard-read=(), clipboard-write=(), gamepad=()- x-content-type-options
nosniff- content-security-policy
default-src 'self';script-src 'unsafe-inline' 'unsafe-eval' 'report-sample' 'self' https://*.2mdn.net https://*.scorecardresearch.com https://btloader.com https://www.gstatic.com https://platform.twitter.com https://js.stripe.com https://*.googlesyndication.com https://cdn.ampproject.org https://*.googleapis.com https://apis.google.com https://cdn.exmarketplace.com https://cdn.prod.uidapi.com https://cdn.jsdelivr.net https://*.iubenda.com https://connect.facebook.net https://classifly.xyz/classifly-stable.min.js https://ep2.adtrafficquality.google/sodar/sodar2.js https://onetag-sys.com/static/BannerAdBannerPlacement.js https://*.g.doubleclick.net https://www.googletagmanager.com https://www.google.com;style-src 'unsafe-inline' 'report-sample' 'self' https://*.exmarketplace.com https://*.cloudflare.com https://*.iubenda.com https://www.gstatic.com https://*.googleapis.com https://tracking.tychesoftwares.com ;object-src 'none';base-uri 'self';connect-src 'self' https://api.btloader.com h- strict-transport-security
max-age=31536000;includeSubDomains;preload- cross-origin-opener-policy
unsafe-none- cross-origin-embedder-policy
unsafe-none- cross-origin-resource-policy
same-origin