si-bone.co.uk
HTML metadata
Technology
- Server
- nginx
- Analytics
-
- Google Tag Manager
- Fonts
-
- Adobe Fonts
Third-party hosts loaded (5)
- s3.eu-west-2.amazonaws.com×8
- fast.wistia.net×2
- ajax.googleapis.com×1
- use.typekit.net×1
- www.googletagmanager.com×1
Contact
- Address
- 471 El Camino Real, Suite 101, 95050, Santa Clara, California, United States
Registration
- Registrar
- GoDaddy.com, LLC.
- Created
- 2016-10-28
- Expires
- 2026-10-28 161 days left
- Updated
- 2025-10-29
- Name servers
-
- pdns09.domaincontrol.com.
- pdns10.domaincontrol.com.
DNS records live
- NS
-
- pdns09.domaincontrol.com
- pdns10.domaincontrol.com
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
E7
Expires in 37 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=(), interest-cohort=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; connect-src 'self' *.vimeocdn.com *.googleapis.com *.crazyegg.com https://www.google-analytics.com *.doubleclick.net *.cookielaw.org *.windows.net *.wistia.com *.litix.io *.akamaihd.net *.onetrust.com; img-src 'self' 'unsafe-inline' assets.si-bone.com *.wistia.com *.doubleclick.net *.google.com *.googletagmanager.com *.gstatic.com *.googleapis.com *.ytimg.com *.formstack.com *.typekit.net *.cookielaw.org *.google-analytics.com *.windows.net *.akamaihd.net *.amazonaws.com data:; frame-src *.youtube.com *.vimeo.com *.wistia.com *.wistia.net *.pardot.com; font-src 'self' 'unsafe-inline' *.gstatic.com *.typekit.net *.formstack.com data:; object-src 'unsafe-eval' data:; style-src 'self' 'unsafe-inline' *.typekit.net *.googleapis.com *.formstack.com blob:; media-src 'self' 'unsafe-inline' *.vimeo.com *.vimeocdn.com *.akamaized.net *.wistia.com blob:; script-src 'self' 'unsafe-inline' *.googleadservices.com *.secure.force.com *.formstack.com *.wistia.com *.wistia.net *.you- strict-transport-security
max-age=1780855607
Links to (4)
Linked from (3)
- si-bone.fr×2
- si-bone.com×2
- si-bone.de×2