parlementairemonitor.nl
HTML metadata
Technology
- Server
- nginx
- jQuery
- 1.7.2 known XSS (<3.5)
DNS records live
- NS
-
- ns0.transip.net
- ns1.transip.nl
- ns2.transip.eu
- MX
-
- 10 mx1.pdc.nl.parlementairemonitor.nl
- 20 mx2.pdc.nl.parlementairemonitor.nl
- TXT
-
"v=spf1 include:_spf.argewebhosting.nl ip4:194.165.34.0/24 redirect=_spf.pdc.nl"
- Verified for
-
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
-
- default:
"v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCmwc0k+LqWYJIIT74+WMLY5aIODzS9dcEKILec1K3mHH0ZhHMm5skv6JSnmtZOu7o/4T6DiUDfH2/YHdeqG…
selectors probed - default:
Certificate (current)
R12
Expires in 59 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- CSP allows unsafe inline scripts/styles
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: yastatic.net cse.google.com ajax.googleapis.com php.pdc.nl www.google.com www.gstatic.com translate.googleapis.com translate.google.com maps.google.com maps.googleapis.com api.microsofttranslator.com; report-uri /cspreport- strict-transport-security
max-age=15768000
Links to (1)
- pdc.nl×1