habitatshop.org

.org crawl

First seen 2026-04-11 · Last seen 2026-05-19 · ok HTTP/1.1 200 1348 ms crawled 2026-05-19

US · 104.26.13.111 · AS13335 Cloudflare, Inc.

Reputation 95/100 weak security headers

Classifying

HTML metadata

Title
Habitat for Humanity Store
Language
en

Technology

CDN
Cloudflare
CMS
Gatsby

Social

Registration

Registrar
Network Solutions, LLC
Created
2023-07-10
Expires
2029-07-10 1146 days left
Updated
2026-05-16
Name servers
  • arch.ns.cloudflare.com
  • roxy.ns.cloudflare.com

DNS records live

NS
  • arch.ns.cloudflare.com
  • roxy.ns.cloudflare.com

Email authentication no MX

SPF
v=spf1 ip4:192.240.182.53 include:apisource.com ~all
softfail (~all)
DMARC
v=DMARC1; p=none;
policy: none (monitoring only)
DKIM
no key found at common selectors

Certificate (current)

WE1
from 2026-04-24 to 2026-07-23
Expires in 64 days

HTTP security headers

Header hygiene 45/100 Checked live page: https://habitatshop.org/

present
  • content-security-policy-report-only
  • x-frame-options
  • x-content-type-options
findings
  • missing HSTS
  • missing Content Security Policy
  • weak frame protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-frame-options
SAMEORIGIN, SAMEORIGIN
x-content-type-options
nosniff
content-security-policy-report-only
font-src use.typekit.net p.typekit.net *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.authorize.net 'self' 'unsafe-inline'; frame-ancestors *.certcapture.com *.authorize.net 'self'; frame-src bid.g.doubleclick.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ *.youtube-nocookie.com www.apptrian.com facebook.com www.facebook.com connect.facebook.net graph.facebook.com *.certcapture.com *.authorize.net www.xtento.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net www.googleadservices.com www.google-analytics.com analytics.google.com www.googletagmanager.com t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sa

Links to (5)

Linked from (1)