motive.co
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Nuxt
- Analytics
-
- Cloudflare Insights
- Fathom
Third-party hosts loaded (2)
- cdn.usefathom.com×1
- static.cloudflareinsights.com×1
Social
DNS records live
- NS
-
- ns-1517.awsdns-61.org
- ns-1884.awsdns-43.co.uk
- ns-194.awsdns-24.com
- ns-726.awsdns-26.net
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 9 TXT records
google-site-verification=uuMNpjvq5eRRZ7gDUuYstteSUeEy-IitR9kFstY7Y9Amandrill_verify.hRLukJsr9O4LSQMKZ3SAogmongodb-site-verification=tfXAkjTlFEvdyFPPzTltVgB6UPMmzhhBv=spf1 include:_spf.google.com include:spf.mandrillapp.com -allMS=ms86742133atlassian-sending-domain-verification=aa0756f2-1cc0-422d-8c2f-4a32c10acdd0brevo-code:23668a9073cfc60995ea8ed91e90ab04google-site-verification=LRc5o8OFPRjwiXobGGHNsJ0xpk0ZjH5o3o60Y5NaHp4google-site-verification=Tco4pUwc_PCNsLWPeMpQyYr1JETY15XhwoUY6iYsT1s
Certificate (current)
Amazon RSA 2048 M04
Expires in 54 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-opener-policy
- cross-origin-embedder-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
same-origin- x-frame-options
DENY- permissions-policy
camera=(), display-capture=(), fullscreen=(), geolocation=(), microphone=()- x-content-type-options
nosniff- content-security-policy
default-src https: 'self' *.motive.co; img-src https: 'self' data: *.motive.co; style-src https: 'self' 'unsafe-inline' *.motive.co; script-src https: 'self' 'unsafe-inline' 'unsafe-eval' *.motive.co- strict-transport-security
max-age=63072000; includeSubDomains; preload- cross-origin-opener-policy
same-origin- cross-origin-embedder-policy
credentialless- cross-origin-resource-policy
same-origin