kolejoweabc.pl
HTML metadata
Technology
- CMS
- WordPress 7.0
- PHP
- 8.3.30 security-only
- jQuery
- 3.7.1
- Fonts
-
- Google Fonts
Third-party hosts loaded (6)
- cdn.jsdelivr.net×6
- static.addtoany.com×3
- cdnjs.cloudflare.com×2
- fonts.googleapis.com×2
- fonts.gstatic.com×1
- www.google.com×1
Social
DNS records live
- NS
-
- dns.home.pl
- dns2.home.pl
- dns3.home.pl
- MX
-
- 10 mail.kolejoweabc.pl
- 20 mail2.kolejoweabc.pl
- TXT
-
9a865defe305ffed17ea6fd12b4c9d35977a6fd91b5cce5a9e7047b474a5b767
- Verified for
-
- GlobalSign
Email authentication weak
- SPF
-
v=spf1 ip4:185.236.111.104 ip4:185.236.111.114 ip4:185.236.111.124 ip4:185.236.111.100 ip4:185.236.111.103 ip4:185.236.111.111 -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
Certum OV TLS G2 R39 CA
Expires in 118 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- permissions-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
Header values
- x-frame-options
DENY- permissions-policy
microphone=(), payment=()- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-inline' 'unsafe-eval' https: blob: https://cdn.jsdelivr.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; style-src 'self' 'unsafe-inline' http: blob: https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; img-src 'self' data: blob: filesystem: https://cdn.gtranslate.net/ https://secure.gravatar.com/ https://*.w.org/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; frame-src 'self' blob: https://www.google.com/ https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://static.addtoany.com/; child-src 'self' blob:; block-all-mixed-content; upgrade-insecure-requests- strict-transport-security
max-age=3600