rrgsuisse.ch
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress 7.0
- jQuery
- 3.7.1
- Analytics
-
- Google Tag Manager
Third-party hosts loaded (3)
- cdn.by.wonderpush.com×1
- gmpg.org×1
- www.googletagmanager.com×1
Social
DNS records live
- NS
-
- ns3.infomaniak.ch
- ns4.infomaniak.ch
- MX
-
- 5 mta-gw.infomaniak.ch
Email authentication strong
- SPF
-
v=spf1 include:spf.infomaniak.ch -allstrict (-all) - DMARC
-
v=DMARC1; p=reject; pct=100policy: reject (enforced) - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 53 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- cross-origin-resource-policy
- findings
-
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin- x-frame-options
DENY- permissions-policy
accelerometer=(), autoplay=(), bluetooth=(), camera=(), captured-surface-control=(), compute-pressure=(), cross-origin-isolated=(), deferred-fetch=(self), deferred-fetch-minimal=(self), display-capture=(), encrypted-media=(), fullscreen=(self), geolocation=(self https://rrg-partner.ch https://rrgsuisse.ch), gyroscope=(), hid=(), identity-credentials-get=(), idle-detection=(), microphone=(), midi=(), otp-credentials=(), payment=(), picture-in-picture=(), publickey-credentials-create=(), publickey-credentials-get=(), screen-wake-lock=(), serial=(), storage-access=(self), usb=(), web-share=(), window-management=(), xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
base-uri 'self'; connect-src 'self' *.google-analytics.com *.wpengine.com yoast.com *.google.com *.g.doubleclick.net *.facebook.com *.facebook.net *.fbcdn.net https:; default-src 'self'; font-src 'self' *.gstatic.com *.bootstrapcdn.com data: fonts.gstatic.com cdn.jsdelivr.net https:; form-action 'self'; frame-src 'self' rrg-partner.ch *.g.doubleclick.net *.google.com *.fls.doubleclick.net blob: www.google.com https: *.youtube.com *.vimeo.com *.facebook.com; child-src 'self' rrg-partner.ch *.g.doubleclick.net *.google.com *.fls.doubleclick.net blob: www.google.com https: *.youtube.com *.vimeo.com *.facebook.com; frame-ancestors 'self' rrg-partner.ch *.facebook.com; img-src 'self' *.googletagmanager.com *.w.org *.gravatar.com *.google.com *.google-analytics.com *.gstatic.com data: ts.w.org s.w.org ps.w.org https: *.wordpress.org *.renault.ch fr.renault.ch media.renault.ch *.dacia.ch *.nissan-cdn.net cdn.group.renault.com; media-src 'self' s.w.org https:; object-src 'none'; script-src 'se- strict-transport-security
max-age=63072000; includeSubDomains; preload- cross-origin-resource-policy
cross-origin