lvpnews.com

.com crawl

First seen 2026-05-29 · Last seen 2026-05-31 · ok HTTP/1.1 200 2507 ms crawled 2026-05-31

US · 199.83.128.102 · AS19551 Incapsula Inc

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Lehigh Valley Press
Language
en-US
Canonical
https://www.lvpnews.com/

Technology

Server
imio
CMS
WordPress
jQuery
3.3.1 known XSS (<3.5)
Analytics
  • Google Tag Manager
Ads
  • Google AdSense
  • Meta Pixel
Fonts
  • Google Fonts
Third-party hosts loaded (13)
  • imengine.prod.ltn.infomaker.io×21
  • static.ew.ltn.navigacloud.com×4
  • code.jquery.com×2
  • connect.facebook.net×2
  • www.google.com×2
  • www.googletagmanager.com×2
  • discovery.evvnt.com×1
  • fonts.googleapis.com×1
  • gmpg.org×1
  • pagead2.googlesyndication.com×1
  • prod.ew.ltn.navigacloud.com×1
  • s.w.org×1
  • www.facebook.com×1

Registration

Registrar
Tucows Domains Inc.
Created
2016-01-26
Expires
2031-01-26 1700 days left
Updated
2026-01-23
Name servers
  • ns1.pencor.com
  • ns2.pencor.com
  • ns3.pencor.com

DNS records live

NS
  • ns1.pencor.com
  • ns2.pencor.com
  • ns3.pencor.com
TXT
Show 4 TXT records
  • _chevv89l95fda8l0urhudhxqidvq150
  • https://smex-ctp.trendmicro.com:443/wis/clicktime/v1/query?url=www.lehighvalleypress.com&umid=c22fa33c-40d9-424d-bf6d-36a15fcc9237&auth=438b0784514c1757bd202125ca4db8b0abdb021e-42ec977ee1c25270969f78fa6a8e46eb6a8c4519
  • 5g4syx00t5693xd23t4ls6j1mtsr9kxm
  • s3hsb7w7wrhlfknmzdzgry1gv5kcq9zd
Verified for
  • GlobalSign
  • Google

Email authentication weak

SPF
not published
DMARC
not published
DKIM
  • s1: k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzZ9x1jzUNAcglU3clDtWOoAdsUwJUvxu0VBiyhQDM95789BlhzTisQyg31s7bQxWBgSpIhpKnb1dQBjTGd…
  • s2: k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCiERgp4gp/3wYoYqsIJVFRh/6oFTxkRNrlf9nTUuWk7eO977a9GBso8arcAlmoCs+P6T+40f0zrvoFr/B3HQplE…
selectors probed

Certificate (current)

GlobalSign Atlas R46 DV TLS CA 2026 Q2
from 2026-05-27 to 2026-08-25
Expires in 85 days

HTTP security headers

Header hygiene 70/100 Checked live page: https://www.lvpnews.com/

present
  • strict-transport-security
  • content-security-policy
  • x-content-type-options
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.googletagmanager.com *.google.com *.doubleclick.net *.googlesyndication.com *.googleadservices.com *.facebook.net *.jquery.com *.navigacloud.com https://weatherwidget.io *.weatherwidget.io *.twitter.com *.evvnt.com *.wgchrrammzv.com https://www.googletagservices.com *.gstatic.com *.googleapis.com *.adtrafficquality.google *.vo.msecnd.net *.azurefd.net *.a3kvau184uea.com *.sy57d8wi.com *.ck4hkyq3myt6.com *.apharponloun.com *.mircheigeshoa.com *.y5kvsuy8wr7c.com *.godiciardstia.com *.1epc8o1tg9zz.com https://everywarestarterkit.local *.everywarestarterkit.local *.pranmcpkx.com *.secondstreetapp.com; style-src 'self' 'unsafe-inline' *.googleapis.com *.ck4hkyq3myt6.com *.y5kvsuy8wr7c.com *.1epc8o1tg9zz.com *.azurefd.net *.secondstreetapp.com; font-src 'self' data: *.gstatic.com *.googleapis.com *.secondstreetapp.com; img-src 'self' data: https:; connect-src 'self' https:; frame-src 'self' *.twitter.com https://weatherwid
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (2)

Linked from (1)