kiro.dev
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- AmazonS3
- CMS
- Next.js
Third-party hosts loaded (2)
- prod.assets.shortbread.aws.dev×2
- a0.awsstatic.com×1
Social
DNS records live
- NS
-
- ns-1033.awsdns-01.org
- ns-126.awsdns-15.com
- ns-1887.awsdns-43.co.uk
- ns-773.awsdns-32.net
- MX
-
- 10 inbound-smtp.us-east-1.amazonaws.com
- TXT
-
google-site-verification=OSHc8EL1-jbmpSYd0k0IOV6iiwZ67uqCuh-8gmttpIs
Email authentication strong
- SPF
-
v=spf1 include:amazonses.com -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; rua=mailto:dmarc-reports@kiro.dev; ruf=mailto:dmarc-reports@kiro.devpolicy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
Amazon RSA 2048 M01
Expires in 196 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://a0.awsstatic.com https://prod.assets.shortbread.aws.dev; style-src 'self' 'unsafe-inline' https://prod.assets.shortbread.aws.dev https://a0.awsstatic.com; img-src 'self' blob: data: https://a0.awsstatic.com https://prod.tools.shortbread.aws.dev https://dpm.demdex.net https://amazonwebservices.d2.sc.omtrdc.net https://prod.download.desktop.kiro.dev https://cm.everesttech.net; font-src 'self' data:; connect-src 'self' https://prod.assets.shortbread.aws.dev https://prod.log.shortbread.aws.dev https://prod.tools.shortbread.aws.dev https://a0.awsstatic.com https://dpm.demdex.net https://prod.download.desktop.kiro.dev https://vs.aws.amazon.com https://d2c.aws.amazon.com https://*.algolia.net https://*.algolianet.com https://amazonwebservices.d2.sc.omtrdc.net https://cognito-identity.us-east-1.amazonaws.com https://*.appsync-api.us-east-1.amazonaws.com https://*.s3.us-east-1.amazonaws.com; object-src 'none'; base-uri- strict-transport-security
max-age=31536000; includeSubDomains; preload- cross-origin-opener-policy
same-origin
Links to (10)
- youtube.com×4
- github.com×4
- linkedin.com×4
- sreekeshiyer.com×4
- x.com×4
- instagram.com×4
- bsky.app×4
- amazon.com×4
- medium.com×4
- twitch.tv×1