lvpnews.com
HTML metadata
Technology
- Server
- imio
- CMS
- WordPress
- jQuery
- 3.3.1 known XSS (<3.5)
- Analytics
-
- Google Tag Manager
- Ads
-
- Google AdSense
- Meta Pixel
- Fonts
-
- Google Fonts
Third-party hosts loaded (13)
- imengine.prod.ltn.infomaker.io×21
- static.ew.ltn.navigacloud.com×4
- code.jquery.com×2
- connect.facebook.net×2
- www.google.com×2
- www.googletagmanager.com×2
- discovery.evvnt.com×1
- fonts.googleapis.com×1
- gmpg.org×1
- pagead2.googlesyndication.com×1
- prod.ew.ltn.navigacloud.com×1
- s.w.org×1
- www.facebook.com×1
Registration
- Registrar
- Tucows Domains Inc.
- Created
- 2016-01-26
- Expires
- 2031-01-26 1700 days left
- Updated
- 2026-01-23
- Name servers
-
- ns1.pencor.com
- ns2.pencor.com
- ns3.pencor.com
DNS records live
- NS
-
- ns1.pencor.com
- ns2.pencor.com
- ns3.pencor.com
- TXT
-
Show 4 TXT records
_chevv89l95fda8l0urhudhxqidvq150https://smex-ctp.trendmicro.com:443/wis/clicktime/v1/query?url=www.lehighvalleypress.com&umid=c22fa33c-40d9-424d-bf6d-36a15fcc9237&auth=438b0784514c1757bd202125ca4db8b0abdb021e-42ec977ee1c25270969f78fa6a8e46eb6a8c45195g4syx00t5693xd23t4ls6j1mtsr9kxms3hsb7w7wrhlfknmzdzgry1gv5kcq9zd
- Verified for
-
- GlobalSign
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
-
- s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzZ9x1jzUNAcglU3clDtWOoAdsUwJUvxu0VBiyhQDM95789BlhzTisQyg31s7bQxWBgSpIhpKnb1dQBjTGd… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCiERgp4gp/3wYoYqsIJVFRh/6oFTxkRNrlf9nTUuWk7eO977a9GBso8arcAlmoCs+P6T+40f0zrvoFr/B3HQplE…
selectors probed - s1:
Certificate (current)
GlobalSign Atlas R46 DV TLS CA 2026 Q2
Expires in 85 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.googletagmanager.com *.google.com *.doubleclick.net *.googlesyndication.com *.googleadservices.com *.facebook.net *.jquery.com *.navigacloud.com https://weatherwidget.io *.weatherwidget.io *.twitter.com *.evvnt.com *.wgchrrammzv.com https://www.googletagservices.com *.gstatic.com *.googleapis.com *.adtrafficquality.google *.vo.msecnd.net *.azurefd.net *.a3kvau184uea.com *.sy57d8wi.com *.ck4hkyq3myt6.com *.apharponloun.com *.mircheigeshoa.com *.y5kvsuy8wr7c.com *.godiciardstia.com *.1epc8o1tg9zz.com https://everywarestarterkit.local *.everywarestarterkit.local *.pranmcpkx.com *.secondstreetapp.com; style-src 'self' 'unsafe-inline' *.googleapis.com *.ck4hkyq3myt6.com *.y5kvsuy8wr7c.com *.1epc8o1tg9zz.com *.azurefd.net *.secondstreetapp.com; font-src 'self' data: *.gstatic.com *.googleapis.com *.secondstreetapp.com; img-src 'self' data: https:; connect-src 'self' https:; frame-src 'self' *.twitter.com https://weatherwid- strict-transport-security
max-age=31536000; includeSubDomains; preload