lubuntu.me
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- Fonts
-
- Google Fonts
Third-party hosts loaded (2)
- fonts.googleapis.com×3
- gmpg.org×1
Social
DNS records live
- NS
-
- bayan.ns.cloudflare.com
- maleah.ns.cloudflare.com
- MX
-
- 10 mx.ubuntu.com
- TXT
-
forward-email-site-verification=JPjcaWRM6E
Email authentication strong
- SPF
-
v=spf1 a mx include:sendgrid.net include:spf.forwardemail.net include:_spf.canonical.com a:alioth.thomas-ward.net -allstrict (-all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:d3cc24e14c1544e5857c6584f233caa5@dmarc-reports.cloudflare.netpolicy: quarantine - DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArPMhOUjTYsFCEetn9k9TiyTbOgtTyrA/ILWLvbhGzbRKiHM0WRlYaVwEn4Gnppi4NrxCP3GlS1XTf1Vomc… - s2:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6Tvl7QpUy7Bh+HGLBjuuYe81AB0J9VF/KN/sX/schc/cKm/QS9dkXEOYeW5lsy3FsZJFjfRtohEpS6I4jk…
selectors probed - s1:
Certificate (current)
R13
Expires in 57 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(self), ambient-light-sensor=(self), autoplay=(self), battery=(self), camera=(self), cross-origin-isolated=(self), display-capture=(self), document-domain=(self), encrypted-media=(self), execution-while-not-rendered=(self), execution-while-out-of-viewport=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), keyboard-map=(self), magnetometer=(self), microphone=(self), midi=(self), navigation-override=(self), payment=(self), picture-in-picture=(self), publickey-credentials-get=(self), screen-wake-lock=(self), sync-xhr=(self), usb=(self), web-share=(self), xr-spatial-tracking=(self), clipboard-read=(), clipboard-write=(), gamepad=(), speaker-selection=(), conversion-measurement=(), focus-without-user-activation=(), hid=(), idle-detection=(), interest-cohort=(), serial=(), sync-script=(), trust-token-redemption=(), window-placement=(), vertical-scroll=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' data:; script-src 'self' 'unsafe-inline' cdnjs.cloudflare.com 'unsafe-eval' ajax.googleapis.com; style-src 'self' data: 'unsafe-inline' *.fonts.googleapis.com fonts.googleapis.com fonts.gstatic.com; img-src 'self' data: *.lubuntu.me secure.gravatar.com; font-src 'self' data: fonts.googleapis.com fonts.gstatic.com