healthtech.ch
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- jQuery
- 3.7.1
- Analytics
-
- Google Analytics
- Google Tag Manager
Third-party hosts loaded (6)
- code.jquery.com×2
- ajax.googleapis.com×1
- cdnjs.cloudflare.com×1
- www.google-analytics.com×1
- www.google.com×1
- www.googletagmanager.com×1
Contact
DNS records live
- NS
-
- ns-1083.awsdns-07.org
- ns-1996.awsdns-57.co.uk
- ns-5.awsdns-00.com
- ns-953.awsdns-55.net
- MX
-
- 0 healthtech-ch.mail.protection.outlook.com
Email authentication partial
- SPF
-
v=spf1 include:spf.protection.outlook.com include:sendgrid.net include:_spf.sui-inter.net -allstrict (-all) - DMARC
-
v=DMARC1;p=none;pct=100;rua=mailto:dmarc@healthtech.chpolicy: none (monitoring only) - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2kUyCscY0h3OkFLmVlNXacHZqGxZy00zQrAfkXfV3wTPPDZRP1L4hZ7srobsZY3aPaOKqVYXYrGcVMt91E… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC9P85TBu2fZ6N35F4ekEB8g29rnwUJR8uLJpQwKYngnrn02FPZVmiEZw6NS6bmzlMks/E7+zE/RD/FhOMzMhIcTV…
selectors probed - s1:
Certificate (current)
R12
Expires in 25 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- weak frame protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
ALLOW-FROM https://new.netmailer.ch- x-content-type-options
nosniff- content-security-policy
default-src 'self'; connect-src 'self' *.doubleclick.net *.healthtech.ch *.google.com *.google-analytics.com *.youtube.com *.vimeo.com *.mapbox.com; style-src 'unsafe-inline' 'self' *.myfonts.net *.googleapis.com *.mapbox.com; script-src 'unsafe-inline' 'unsafe-eval' 'self' *.healthtech.ch *.cloudflare.com *.azureedge.net *.googletagmanager.com *.google.com *.gstatic.com *.google-analytics.com code.jquery.com *.youtube.com *.vimeo.com *.mapbox.com; child-src blob:; img-src 'self' *.google.ch *.windows.net *.google.com *.healthtech.ch *.dynamics.com *.google-analytics.com *.mapbox.com data: blob:; font-src 'self' *.alicdn.com *.gstatic.com data:; frame-src 'self' *.healthtech.ch *.dynamics.com *.netmailer.ch *.google.com *.youtube.com *.vimeo.com; object-src 'unsafe-inline' 'unsafe-eval' 'self'- strict-transport-security
max-age=60; includeSubDomains