originbrief.app
HTML metadata
Technology
- CDN
- Vercel
- CMS
- Next.js
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (30)
- code.market×3
- acidtools.com×2
- aidirs.org×2
- aihuntlist.com×2
- aitoolfame.com×2
- auraplusplus.com×2
- cdn.aijustbetter.com×2
- dofollow.tools×2
- findly.tools×2
- firstlook.tools×2
- gets.tools×2
- goodaitools.com×2
- img.turbo0.com×2
- neeed.directory×2
- newtool.site×2
- open-launch.com×2
- saasfame.com×2
- saastool.site×2
- shinylaunch.com×2
- startupfa.st×2
- storage.shipgrowth.dev×2
- toolfame.com×2
- twelve.tools×2
- ufind.best×2
- unitelist.com×2
- www.agenthunter.io×2
- www.betterlaunch.co×2
- www.foundrlist.com×2
- www.toolpilot.ai×2
- www.uneed.best×2
DNS records live
- NS
-
- dns1.registrar-servers.com
- dns2.registrar-servers.com
- MX
-
- 0 originbrief-app.mail.protection.outlook.com
- TXT
-
MS=ms79778043
Email authentication partial
- SPF
-
v=spf1 include:spf.protection.outlook.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 42 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
DENY- permissions-policy
camera=(), microphone=(), geolocation=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://va.vercel-scripts.com https://www.googletagmanager.com https://code.market; style-src 'self' 'unsafe-inline'; connect-src 'self' https://tgggdkedmusneflqmziu.supabase.co https://*.sentry.io https://va.vercel-scripts.com https://www.google-analytics.com https://region1.google-analytics.com https://code.market https://codemarket-d273ae066a43.herokuapp.com; img-src 'self' data: blob: https://api.producthunt.com https://wired.business https://startupfa.me https://cdn.prod.website-files.com https://www.nxgntools.com https://www.uneed.best https://findly.tools https://www.toolpilot.ai https://neeed.directory https://img.turbo0.com https://www.foundrlist.com https://acidtools.com https://ufind.best https://www.betterlaunch.co https://unitelist.com https://shinylaunch.com https://toolfame.com https://dofollow.tools https://saasfame.com https://newtool.site https://www.agenthunter.io https://aidirs.org https://firstlook- strict-transport-security
max-age=63072000; includeSubDomains; preload
Links to (22)
- acidtools.com×1
- agenthunter.io×1
- aidirs.org×1
- aihuntlist.com×1
- aijustbetter.com×1
- aitoolfame.com×1
- auraplusplus.com×1
- betterlaunch.co×1
- dang.ai×1
- foundrlist.com×1
- goodaitools.com×1
- nxgntools.com×1
- open-launch.com×1
- producthunt.com×1
- saasfame.com×1
- shinylaunch.com×1
- shipgrowth.dev×1
- startupfa.me×1
- toolfame.com×1
- toolpilot.ai×1
- turbo0.com×1
- unitelist.com×1