idea.gov.co
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress 6.9.4
- jQuery
- 3.7.1
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- fonts.googleapis.com×5
- cdn.www.gov.co×2
- fonts.gstatic.com×1
- www.googletagmanager.com×1
Social
Contact
DNS records
- MX
-
- 0 idea-gov-co.mail.protection.outlook.com
Email authentication no MX
- SPF
-
v=spf1 include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; pct=100; rua=mailto:sistemasidea@idea.gov.co; ruf=mailto:sistemasidea@idea.gov.copolicy: quarantine - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuBSMgVTKXENlRHMtaLECE2ppYwxndDk9twulm5BSW22sbIOuNhcCVW31TsiKyTm4oY0VB8x80gsKQR…
selectors probed - selector1:
Certificate (current)
GeoTrust EV RSA CA G2
Expires in 157 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), autoplay=(*), camera=(), encrypted-media=(*), fullscreen=(*), geolocation=(*), microphone=(), midi=(*), payment=(*), display-capture=(*)- x-content-type-options
nosniff- content-security-policy
frame-ancestors 'self'; upgrade-insecure-requests; img-src 'self' data: http://www.idea.gov.co https://www.googletagmanager.com https://idea-sitioweb-dev.azurewebsites.net https://idea-sitioweb-dev.azurewebsites.net https://s3-site-vmas-cdn.s3.amazonaws.com/ https://i.ytimg.com/ https://secure.gravatar.com/ https://s.w.org https://cdn.www.gov.co https://fonts.gstatic.com https://www.gstatic.com https://storageidea.blob.core.windows.net https://cdn.userway.org https://ps.w.org https://api.wpmet.com; default-src 'self'; script-src 'self' https://*.googleapis.com https://*.gstatic.com https://www.google.com/ https://player.vimeo.com/ https://www.youtube.com/ https://platform.twitter.com/ https://yoast.com https://translate.google.com https://translate.googleapis.com https://cdn.userway.org https://cdnjs.cloudflare.com 'unsafe-eval' 'unsafe-inline'; script-src-elem 'self' 'unsafe-inline' https://*.googleapis.com https://*.gstatic.com https://www.googletagmanager.com https://ajax.googleapi- strict-transport-security
max-age=31536000; includeSubDomains;preload- cross-origin-opener-policy
same-origin-allow-popups- cross-origin-embedder-policy
same-origin- cross-origin-resource-policy
same-origin
Links to (7)
- youtube.com×1
- x.com×1
- www.gov.co×1
- linkedin.com×1
- instagram.com×1
- facebook.com×1
- colombia.co×1
idea.gov.co