medice-health-family.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- CMS
- Nuxt
Third-party hosts loaded (3)
- frontend.prod.medice-portal.net×75
- a.storyblok.com×12
- api.frontend.prod.medice-portal.net×3
Social
Contact
DNS records live
- NS
-
- a.ns14.net
- b.ns14.net
- c.ns14.net
- d.ns14.net
- MX
-
- 10 mail.medice.de
- TXT
-
v=spf1 a mx a:login.medice.com include:_spf.werkbank.de include:_spf.medice.de include:spf.protection.outlook.com ~all
- Verified for
-
- Microsoft 365
Certificate (current)
Amazon RSA 2048 M04
Expires in 266 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
same-origin- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
base-uri 'none'; font-src data: frontend.prod.medice-portal.net https://m.werkbank.de/ medice-health-family.com consent.medice-health-family.com; form-action 'self'; frame-ancestors 'self' app.storyblok.com; img-src data: cdn.shopware.store a.storyblok.com https://m.werkbank.de/ frontend.prod.medice-portal.net medice-health-family.com consent.medice-health-family.com https://cdn.jsdelivr.net censhare.medice.de https://*.googletagmanager.com https://*.google-analytics.com medicearzneimittelpttergmbhcokg5--uat.sandbox.my.site.com medicearzneimittelpttergmbhcokg--stage.sandbox.my.salesforce-sites.com medicearzneimittelpttergmbhcokg.my.salesforce-sites.com; object-src 'none'; script-src-attr 'unsafe-inline'; style-src 'unsafe-inline' 'self' frontend.prod.medice-portal.net https://m.werkbank.de/ medice-health-family.com consent.medice-health-family.com medicearzneimittelpttergmbhcokg--stage.sandbox.my.salesforce-sites.com medicearzneimittelpttergmbhcokg.my.salesforce-sites.com medicearzneim- strict-transport-security
max-age=15552000; includeSubDomains- cross-origin-opener-policy
same-origin- cross-origin-embedder-policy
unsafe-none- cross-origin-resource-policy
same-origin
Links to (11)
- apple.com×1
- bfarm.de×1
- facebook.com×1
- instagram.com×1
- integrityline.com×1
- klarna.com×1
- kpa-stiftung.de×1
- linkedin.com×1
- medice.de×1
- paypal.com×1
- pei.de×1