nunchuk.io
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Next.js
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- www-nunchuk-picked-bullfrog.s3.ap-southeast-1.amazonaws.com×39
- fonts.gstatic.com×2
- accounts.google.com×1
- fonts.googleapis.com×1
Social
DNS records live
- NS
-
- bayan.ns.cloudflare.com
- teagan.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
Show 6 TXT records
detectify-verification=b3eda404a87f39c8ceb05784abb3dab8google-site-verification=6tClemmxmZ86wLu5Th8WxQgERc9B4xcEcZKXNJWgkmAgoogle-site-verification=UZ8P0oIor3R-W-MHTiNNtg41eNZbO-iZ0zwfkug76bIgoogle-site-verification=Whsik1XtZHWZiEjXF5qKq2F3xKln_2uN-a0dzJqICUcv=spf1 include:mailgun.org include:amazonses.com include:_spf.google.com include:spf.brevo.com mx -allbrevo-code:c73ede00f5dd1e08ed27b78de41f8d50
Certificate (current)
WE1
Expires in 54 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src 'self' *.nunchuk.io *.segment.com *.squarecdn.com *.google.com *.squareupsandbox.com *.stripe.com *.cloudflare.com; script-src 'self' 'unsafe-inline' *.nunchuk.io vercel.live *.segment.com *.stripe.com *.squarecdn.com *.squareupsandbox.com *.google.com *.cloudflare.com; style-src 'self' 'unsafe-inline' *.nunchuk.io *.squarecdn.com *.stripe.com *.cloudflare.com; style-src-elem 'self' 'unsafe-inline' fonts.gstatic.com fonts.googleapis.com *.google.com *.squarecdn.com *.nunchuk.io *.stripe.com *.cloudflare.com; img-src 'self' data: blob: https: mxc: *.squarecdn.com *.nunchuk.io *.stripe.com *.cloudflare.com; font-src 'self' fonts.gstatic.com *.squarecdn.com *.nunchuk.io *.cloudfront.net *.stripe.com *.cloudflare.com; frame-src 'self' vercel.live *.google.com *.youtube.com *.squarecdn.com *.nunchuk.io *.stripe.com *.squareupsandbox.com *.cloudflare.com; frame-ancestors 'none'; connect-src 'self' https:- strict-transport-security
max-age=63072000; includeSubDomains; preload
Links to (13)
- apple.com×1
- blockstream.com×1
- coldcard.com×1
- foundationdevices.com×1
- github.com×1
- google.com×1
- ledger.com×1
- seedsigner.com×1
- slack.com×1
- tapsigner.com×1
- trezor.io×1
- twenty-two.xyz×1
- x.com×1