ooievaarspas.nl
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress 7.0
- PHP
- 8.4.20
- jQuery
- 3.7.1
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (4)
- cdn.jsdelivr.net×2
- www.googletagmanager.com×2
- cdn-cookieyes.com×1
- translate.google.com×1
Social
DNS records live
- NS
-
- a1-207.akam.net
- a13-64.akam.net
- a16-64.akam.net
- a22-64.akam.net
- a5-64.akam.net
- a8-65.akam.net
- MX
-
- 10 smtp.denhaag.nl
- TXT
-
Show 6 TXT records
QuoVadis=de93da79-6a35-4493-a8e7-7dea82d31bfe0sst1svpf07k9f1pnd4gs4zh48bxzjlc66fwlfn6ckvhpqyxpkggjs2vsbw9xb95_9v37lz1ixods4zbqy1ikg2e4yevc4fyQuoVadis=5cd104ac-c020-4c95-9c1c-1034ecc0d45c._b011z6dpy87q9vzlaf2rhj7v4ksj5p7
Email authentication weak
- SPF
-
v=spf1 mx include:_spf.hoppinger.com ip4:213.222.7.72 ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
E8
Expires in 62 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-resource-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), autoplay=(), camera=(), geolocation=(), microphone=(), payment=(), usb=()- x-content-type-options
nosniff- content-security-policy
default-src https: data: blob:; script-src 'unsafe-inline' 'unsafe-eval' https: data:; style-src 'unsafe-inline' https: data:; img-src https: data: blob:; connect-src *; font-src https: data:; media-src https: data: blob:; form-action 'self' https:; frame-ancestors 'self'; frame-src 'self' https: blob:; worker-src https: blob:; upgrade-insecure-requests- strict-transport-security
max-age=31536000- cross-origin-resource-policy
same-site