kaivannaiset.fi
HTML metadata
Technology
- Server
- CMS
- WordPress
- jQuery
- 3.7.1
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (3)
- consent.cookiebot.com×3
- maps.googleapis.com×2
- unpkg.com×2
Social
DNS records live
- NS
-
- ns-fi.elisa.net
- ns-se.elisa.net
- MX
-
- 0 mx.kolumbus.fi
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
WR3
Expires in 63 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(self "https://*.google.com"), autoplay=(self "https://www.youtube.com"), camera=(), cross-origin-isolated=(), display-capture=(), encrypted-media=(self "https://www.youtube.com"), fullscreen=(self "https://www.youtube.com" "https://*.google.com"), geolocation=(self "https://*.google.com"), gyroscope=(self "https://*.google.com"), keyboard-map=(), magnetometer=(self "https://*.google.com"), microphone=(), midi=(), payment=(), picture-in-picture=(self "https://www.youtube.com" "https://*.google.com"), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), xr-spatial-tracking=(), clipboard-read=(), clipboard-write=(self), gamepad=(), hid=(), idle-detection=(), serial=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; img-src 'self' data: https://imgsct.cookiebot.com https://unpkg.com/leaflet@1.9.4/ *.openstreetmap.org img.cromet.fi *.gravatar.com *.googletagmanager.com *.google-analytics.com *.gstatic.com *.googleapis.com googleads.g.doubleclick.net *.google.com *.google.fi *.fls.doubleclick.net ad.doubleclick.net ade.googlesyndication.com secure.adnxs.com *.usercentrics.eu dev.visualwebsiteoptimizer.com *.global.siteimproveanalytics.io *.ytimg.com s.w.org; font-src 'self' data: fonts.gstatic.com; script-src 'self' blob: 'unsafe-eval' 'unsafe-inline' consentcdn.cookiebot.com consent.cookiebot.com *.snoobi.eu www.google.com/recaptcha/ www.gstatic.com/recaptcha/ *.googletagmanager.com tagmanager.google.com *.google-analytics.com ssl.google-analytics.com *.googleapis.com www.googleadservices.com googleads.g.doubleclick.net www.google.com app.usercentrics.eu dev.visualwebsiteoptimizer.com siteimproveanalytics.com www.youtube.com; style-src 'self' 'unsafe-inline' unpkg.co- strict-transport-security
max-age=31536000; includeSubDomains; preload
Links to (3)
- qreform.com×1
- metsa.fi×1
- linkedin.com×1
Linked from (1)
- metsa.fi×1