opencollective.com
HTML metadata
Technology
- CDN
- Cloudflare
- CMS
- Next.js
- Analytics
-
- Cloudflare Insights
Third-party hosts loaded (2)
- opencollective-prod-api.herokuapp.com×2
- static.cloudflareinsights.com×1
Social
Registration
- Registrar
- Cloudflare, Inc.
- Created
- 2002-11-04
- Expires
- 2026-11-04 168 days left
- Updated
- 2025-10-05
- Name servers
-
- pablo.ns.cloudflare.com
- roxy.ns.cloudflare.com
DNS records live
- NS
-
- pablo.ns.cloudflare.com
- roxy.ns.cloudflare.com
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
google-site-verification=_UymNBodbgtmLPT63pJYFvyw1zO3bzLZEY-cLEVEGhsgoogle-site-verification=fW3mBFuNe4Az29d7aTmyeWfPtQqHwCgtV5PwsBxNHLwgoogle-site-verification=skhhgLqcdidjeO39qmJ0PIjb7wGY4LlUoNnpSVLf2bk
Email authentication strong
- SPF
-
v=spf1 include:mailgun.org include:_spf.google.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=quarantine; rua=mailto:a94f0f8bedd9462db42f2d5111dbd025@dmarc-reports.cloudflare.netpolicy: quarantine - DKIM
-
- k2:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAv2aC2KjGKLOwTweBY5A9RpjsxaBXR9r7OAU6U8/zn92ivImI75naUujWbItRI/QmL1jy5PWGqLwoUA…
selectors probed - k2:
Certificate (current)
WE1
Expires in 78 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
no-referrer- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
block-all-mixed-content; default-src 'self' https://cdn.plaid.com/; img-src 'self' https://images.opencollective.com https://next-images.opencollective.com https://pdf.opencollective.com data: *.paypal.com *.paypalobjects.com opencollective.com blog.opencollective.com blob: i.ytimg.com storage.googleapis.com cdn-logos.gocardless.com opencollective-production.s3.us-west-1.amazonaws.com opencollective-production.s3-us-west-1.amazonaws.com; worker-src 'self'; style-src 'self' 'unsafe-inline' https://hcaptcha.com https://*.hcaptcha.com https://challenges.cloudflare.com; connect-src 'self' https://opencollective-prod-api.herokuapp.com https://pdf.opencollective.com https://rest.opencollective.com https://ml.opencollective.com https://oficollective.com wtfismyip.com *.paypal.com *.paypalobjects.com sentry.io *.sentry.io atlas.shopifycloud.com atlas.shopifysvc.com country-service.shopifycloud.com maps.googleapis.com https://wise.com https://transferwise.com https://sandbox.transferwise.tech h- strict-transport-security
max-age=31536000; includeSubDomains
Links to (4)
- github.com×4
- linkedin.com×4
- oficonsortium.org×4
- x.com×4
Linked from (50)
- icons8.de×4
- emmet.io×4
- playframework.com×4
- contributor-covenant.org×4
- cpluspatch.com×4
- catppuccin.com×4
- modx.com×4
- 11ty.dev×4
- a11yproject.com×4
- pnpm.io×4
- sagemath.org×4
- bower.io×4
- electronjs.org×4
- pytest.org×4
- mdxjs.com×4
- styled-components.com×4
- babeljs.io×4
- nativephp.com×4
- himmelblau-idm.org×4
- conda.org×4
- conda-forge.org×4
- lurk.org×4
- prettier.io×4
- rollupjs.org×4
- parceljs.org×4
- nuxt.com×4
- svelte.dev×4
- cljdoc.org×4
- testcontainers.com×4
- scikit-image.org×4
- jestjs.io×4
- prismlauncher.org×4
- openwebdocs.org×4
- f-droid.org×4
- cdnjs.com×4
- gothub.org×4
- obsproject.com×4
- js.org×4
- opensourcepledge.com×4
- icons8.com×4
- icones8.fr×4
- getbootstrap.com×4
- gephi.org×4
- fundoss.org×4
- podlove.org×3
- designtokens.org×3
- climateaction.tech×3
- bundlejs.com×3
- stylelint.io×3
- itk.org×3