pathe.com
HTML metadata
Technology
- CMS
- WordPress
- Social widgets
-
- Vimeo Embed
Third-party hosts loaded (2)
- player.vimeo.com×2
- www.youtube.com×2
Social
Registration
- Registrar
- Gandi SAS
- Created
- 1997-08-19
- Expires
- 2026-08-18 90 days left
- Updated
- 2025-10-16
- Name servers
-
- ns-211-c.gandi.net
- ns-237-a.gandi.net
- ns-47-b.gandi.net
DNS records live
- NS
-
- ns-211-c.gandi.net
- ns-237-a.gandi.net
- ns-47-b.gandi.net
- MX
-
- 0 pathe-com.mail.protection.outlook.com
- TXT
-
Show 18 TXT records
R3thMIzg7ZwrZEfbb3NXfmHUDQggxP1wcbXKPgvq9oQ=v=spf1 include:spf.protection.outlook.com ip4:89.107.170.145 ip4:52.28.158.135 ip4:52.29.12.146 ip4:52.58.24.59 ip4:52.58.36.131 ip4:18.195.58.189 ip4:3.120.154.185 ip4:3.66.207.103 ip4:3.65.178.125 ip4:3.65.51.99 ip4:35.156.181.161 ip4:18.196.78.65 ip4:52.28.3.192 ip4:3.72.173.10 ip4:3.121.73.91 ip4:3.68.136.32 ip4:3.121.120.185 ip4:18.198.86.9 ip4:18.196.51.139 ip4:3.74.240.229 ip4:52.29.80.58 ip4:52.58.138.155 ip4:3.66.158.14 ip4:18.192.97.87 -allglobalsign-domain-verification=6q-xyAB-yh20pDW4X7oyoNryNOdlNO8SaMTdBRn9sPglobalsign-domain-verification=WePYpeEv842IMj5MXWuVNrbAjUIOcpq9AiVjHTHktnatlassian-domain-verification=mQHBGesKqUiYBIBQfI5Zg9VDBP948jSPCWgANR5PkESlZzMyLgy5k1wbZimu13zBsoa6AHNVtQKHrr/Six/F8ODu3Lg7mXgn5KK7OjVAjZE4IFroLly0KPS4JPLVIhH/4Z63pSxFJiyo4uz0yriwMA==google-site-verification=5on3j-E1aOG2srfDjkBc0CacBYNUioiD0XSbtGpuAmMglobalsign-domain-verification=jyCWAmWIliZMgWtRx7OQ2lRLgDivZcL9CCNTsMbXNZairalo-domain-verification=0ReCVunnnIeYZyuwMw5Uk/kuxW5DD6+eTjXcSAhGNoYH2WOA71iRtiLIjA=docusign=77524813-dfbd-4089-9a03-43123b7629a7jamf-site-verification=Bw8j5aIevsJJ4ApQbvzCjgremarkable-domain-verification=5c6f34d1-9ba0-4a3d-b001-8caae9424af7globalsign-domain-verification=2HDyfnwn6dh8ABHqbyOwRVXybHr2oPr6igtS18HlI4google-site-verification=5XadJha1n2ea64lvuAqPnT_NatleNkLTZWsd3XDSIBEMS=ms56513989apple-domain-verification=EuRL9peMTVL2KqAPglobalsign-domain-verification=fgMCrtOeOsjs26W8d3GWkgXpXIMr-3Vegb46jMJP90
Certificate (current)
GandiCert
Expires in 149 days
HTTP security headers
- present
-
- content-security-policy
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- content-security-policy
default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://player.vimeo.com/ https://www.youtube.com/iframe_api https://www.youtube.com/s/player/ https://www.google.com/recaptcha/api.js www.gstatic.com www.google-analytics.com www.googletagmanager.com; style-src 'self' 'unsafe-inline'; img-src 'self' 'unsafe-inline' data: blob: http://www.pathe.com http://pathe.com https://secure.gravatar.com https://ps.w.org https://connect.advancedcustomfields.com https://polylang.pro https://s.w.org; connect-src 'self' api.mapbox.com events.mapbox.com yoast.com *.google-analytics.com analytics.google.com *.vimeo.com vimeo.com cdn.plyr.io; worker-src 'self' blob:; frame-src 'self' www.google.com *.vimeo.com vimeo.com; font-src 'self' data:;