littlegreene.de
HTML metadata
Technology
- CMS
- Gatsby
- Analytics
-
- Google Analytics
- Google Tag Manager
- Hotjar
- Ads
-
- Meta Pixel
- Fonts
-
- Google Fonts
Third-party hosts loaded (21)
- vars.hotjar.com×2
- widget.trustpilot.com×2
- www.littlegreene.com×2
- www.littlegreene.nl×2
- connect.facebook.net×1
- facebook.com×1
- fonts.googleapis.com×1
- google-analytics.com×1
- googletagmanager.com×1
- js.intercomcdn.com×1
- lgpc.prismic.io×1
- maxcdn.bootstrapcdn.com×1
- prismic-io.s3.amazonaws.com×1
- script.hotjar.com×1
- static.cdn.prismic.io×1
- static.hotjar.com×1
- www.googletagmanager.com×1
- www.littlegreene.eu×1
- www.littlegreene.fr×1
- www.littlegreene.ie×1
- www.littlegreene.us×1
Social
Contact
- Address
- 420 Ashton Old Rd, M11 2D, Manchester, United Kingdom
Registration
- Updated
- 2011-11-23
- Name servers
-
- ns1.eurodns.com.
- ns2.eurodns.com.
- ns3.eurodns.com.
- ns4.eurodns.com.
DNS records live
- NS
-
- ns1.eurodns.com
- ns2.eurodns.com
- ns3.eurodns.com
- ns4.eurodns.com
- MX
-
- 0 littlegreene-de.mail.protection.outlook.com
- Verified for
-
- Microsoft 365
Email authentication weak
- SPF
-
v=spf1 include:spf.protection.outlook.com -allstrict (-all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 80 days
HTTP security headers
- present
-
- content-security-policy
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
worker-src https://*.lgpcm2.p.cti.digital.com/ blob:; frame-ancestors 'self'; object-src *.stackla.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; media-src *.adobe.com *.bing.com *.stackla.com *.cdninstagram.com *.gstatic.com *.hcaptcha.com *.intercomcdn.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; manifest-src 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; base-uri *.trustpilot.com *.hcaptcha.com *.stackla.com 'self' 'unsafe-inline' 'unsafe-eval' 'unsafe-hashes'; report-uri https://fcd7480d-2ff3-44bf-9367-c8e0d4f26d3d.sansec.watch/; report-to report-endpoint;, script-src assets.adobedtm.com *.adobe.com *.newrelic.com *.nr-data.net *.commerce-payment-services.com commerce-payments-sdk.adobe.io www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com https://player.vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstat