omorpho.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Shopify
Third-party hosts loaded (7)
- cdn.sanity.io×38
- cdn.shopify.com×36
- cdn-widgetsrepository.yotpo.com×1
- cdn.gomega.ai×1
- monorail-edge.shopifysvc.com×1
- shop.app×1
- static.klaviyo.com×1
Social
Registration
- Registrar
- GoDaddy.com, LLC
- Created
- 2008-11-15
- Expires
- 2027-11-15 545 days left
- Updated
- 2025-11-16
- Name servers
-
- lisa.ns.cloudflare.com
- mario.ns.cloudflare.com
DNS records live
- NS
-
- lisa.ns.cloudflare.com
- mario.ns.cloudflare.com
- MX
-
- 10 mx1-us1.ppe-hosted.com
- 20 mx2-us1.ppe-hosted.com
- TXT
-
Show 10 TXT records
google-site-verification=7e4nbkjijz83JCUw6qqc-2OIKT-AVO_Clqde3MBZzv4google-site-verification=ugoAMH1yaD2uQ9WgEm6Be6bTPfjhvl4Qf1TtWPcMYP4klaviyo-site-verification=TTXT29pinterest-site-verification=326fe52df394d472ca4f13fa73dffeddprowly-verification=d6b4f0d982dd4db2e0cc6d2716a77762a742e8695b9ed1214bbe3d0ff9737901v=spf1 a:dispatch-us.ppe-hosted.com include:secureserver.net include:mailgun.org ~allCDC6971CD1NETORG6079653.onmicrosoft.comapple-domain-verification=ff0C4AK8g7c6zQTcbtRkKh9-9cOJXEQeDinLkjihMgofacebook-domain-verification=erof99qca4fgugbtgzgop4910mhz9x
Certificate (current)
E7
Expires in 68 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-content-type-options
nosniff- content-security-policy
base-uri 'self'; default-src https://cdn.sanity.io https://lh3.googleusercontent.com https://cdn-widgetsrepository.yotpo.com https://loyalty.yotpo.com 'self' 'nonce-0ee0b9683f4e1eea5006681e4918ec38' https://cdn.shopify.com https://shopify.com; frame-ancestors http://localhost:3333 'self' https://omorpho.sanity.studio; style-src 'self' https://cdn-widgetsrepository.yotpo.com http://staticw2.yotpo.com https://loyalty.yotpo.com https://*.gorgias.help/ https://fonts.googleapis.com https://*.klaviyo.com 'self' 'unsafe-inline' https://cdn.shopify.com; connect-src 'self' https://*.shopify.com/ https://inferred.litix.io/ https://*.mux.com/ https://*.fastly.mux.com https://4comvwrc.api.sanity.io wss://4comvwrc.api.sanity.io https://api-cdn.yotpo.com http://staticw2.yotpo.com https://loyalty.yotpo.com https://cdn-widgetsrepository.yotpo.com https://*.ingest.us.sentry.io https://*.ingest.sentry.io https://production.cdp.ingest.chord.co https://*.facebook.com https://connect.facebook.net https://*- strict-transport-security
max-age=31536000