praha14.cz
HTML metadata
Technology
- Server
- nginx
- CMS
- WordPress
- jQuery
- 1.10.2 known XSS (<3.5)
- Stack
- PHP
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (5)
- code.jquery.com×3
- aibot.nanotrix.ai×1
- frame.mapy.cz×1
- hcaptcha.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1.websupport.cz
- ns2.websupport.cz
- ns3.websupport.eu
- MX
-
- 1 praha14-cz.mail.protection.outlook.com
- 10 ms10.mepnet.cz
- 10 ms11.mepnet.cz
- 15 smtp.praha14.cz
- TXT
-
atL4uRikJSENu4QdOllGQ2AEPXDQXJCzWoAn5voiZ7e5CAaNHEx4GXAVOy6YbHHfAolWLSf5pmlMmXAXCp0CTA==8xf40mpdck221mrl2670r06c2jkn8fhd_1rgx2rbu2p5q7ntf98qiji21dpprzhr
- Verified for
-
- Apple
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 mx a:mail.praha14.cz ip4:89.233.175.59 include:spf.protection.outlook.com include:spf-westeu.emailsignatures365.com -allstrict (-all) - DMARC
-
v=DMARC1; p=none; rua=mailto:Reports.Dmarc@praha14.cz; ruf=mailto:Reports.Dmarc@praha14.czpolicy: none (monitoring only) - DKIM
-
- selector1:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQD2msh0OkAppcpOH7Ua4c/hYQGfjpjKJOKAfMEVvvk8hd+xjXbwCpP1amrH8HzX5BKmrJ5tQAWMqFcaGcqS1M… - selector2:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQpaP0wayGJFB/G7NnBKRlg24+sdPYZnnSEMWxaV3iGb3RrpxfGo7dGKAXrGKBAsSlHwodR3cdY3TpEsCCto…
selectors probed - selector1:
Certificate (current)
GeoTrust EV RSA CA G2
Expires in 190 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
Header values
- x-frame-options
SAMEORIGIN- permissions-policy
private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com")- x-content-type-options
nosniff- content-security-policy
script-src 'self' data: blob: 'unsafe-inline' 'unsafe-eval' https://code.jquery.com/ https://www.praha14.cz/ https://npmcdn.com https://*.praha14.cz/ https://maps.google.com/ https://maps.googleapis.com/ https://cdnjs.cloudflare.com/ https://schema.org https://*.hcaptcha.com/ https://hcaptcha.com/ https://mapy.cz/ https://*.mapy.cz/ https://mapy.com/ https://*.mapy.com/ https://*.seznam.cz/ https://login.szn.cz/ https://sentry.pszn.cz/ https://aibot.nanotrix.ai/; img-src 'self' data: blob: https://secure.gravatar.com/ https://www.praha14.cz:3000/ https://thebridge.telenorsat.com/ https://npmcdn.com/ https://*.praha14.cz/ https://maps.google.com/ https://maps.googleapis.com/ https://server.arcgisonline.com/ https://cdnjs.cloudflare.com/ https://*.mapy.cz/ https://mapy.com/ https://*.mapy.com/ https://mapy.cz/ https://*.seznam.cz/ https://login.szn.cz/ https://sentry.pszn.cz/ https://s.w.org/; object-src 'self' data: blob: https://*.praha14.cz/ https://www.praha14.cz/ https://docs.google- strict-transport-security
max-age=63072000; includeSubDomains; preload
Links to (7)
- youtube.com×1
- praha.eu×1
- mpo.cz×1
- instagram.com×1
- google.com×1
- facebook.com×1
- apple.com×1
Linked from (2)
- skvpraha.org×1
- gatum.cz×1