ottobockcare.us
HTML metadata
Technology
- CDN
- Azure Front Door
- CMS
- Next.js
- Analytics
-
- Google Analytics
- Google Tag Manager
- Cookie consent
-
- Usercentrics
Third-party hosts loaded (9)
- www.ottobockcare.us×16
- images.ctfassets.net×13
- app.usercentrics.eu×5
- api.usercentrics.eu×2
- graphql.usercentrics.eu×2
- privacy-proxy.usercentrics.eu×2
- www.google-analytics.com×2
- www.googletagmanager.com×2
- www.youtube.com×1
Social
DNS records live
- NS
-
- ns1-01.azure-dns.com
- ns2-01.azure-dns.net
- ns3-01.azure-dns.org
- ns4-01.azure-dns.info
- TXT
-
google-site-verification=YAV1bCCS-rHDodg0X7nO9-quxPFHsyCugz0DtzFMV1w
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 117 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
autoplay=(*), fullscreen=(*), geolocation=*- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src 'self' blob: 'unsafe-eval' 'unsafe-inline' *.ottobock.com https://events.ottobock.com https://kraken-qa.ottobock.com *.usercentrics.eu https://www.google-analytics.com/ http://www.googletagmanager.com https://maps.googleapis.com https://ajax.googleapis.com/ https://www.googleadservices.com https://www.google.com https://www.youtube.com/ https://connect.facebook.net/ https://snap.licdn.com/ http://platform.massrelevance.com/js/massrel.js https://analytics.tiktok.com/ *.zoovu.com https://walls.io https://static.hotjar.com https://script.hotjar.com/ https://stable.loyjoy.com *.clarity.ms *.smartassistant.com https://unpkg.com/web-vitals@3.5.2/dist/web-vitals.iife.js https://visualwebsiteoptimizer.com https://app.vwo.com *.optimonk.com https://onsite.optimonk.com https://cdn-asset.optimonk.com https://acsbapp.com/; connect-src 'self' 'self' *.ottobock.com https://*.algolia.net https://*.algolianet.com https://*.algolia.io *.usercentrics.eu *.google-analytics.- strict-transport-security
max-age=63072000; includeSubDomains; preload