stanleyworks.ch

.ch crawl

First seen 2026-05-15 · Last seen 2026-05-20 · ok HTTP/1.1 200 5976 ms crawled 2026-05-20

DE · 23.37.49.195 · AS16625 Akamai Technologies, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
STANLEY - Schweiz
Description
STANLEY ist seit 1843 die erste Wahl für Handwerker auf der ganzen Welt. Handwerkskenntnisse, Erfindungen und Innovationen waren schon immer die Basis für alles, was wir tun.

Open Graph

title
STANLEY - Schweiz
description
STANLEY ist seit 1843 die erste Wahl für Handwerker auf der ganzen Welt. Handwerkskenntnisse, Erfindungen und Innovationen waren schon immer die Basis für alles, was wir tun.

Technology

CDN
Akamai
Server
nginx
jQuery
1.8.3 known XSS (<3.5)
Stack
PHP
Analytics
  • Google Tag Manager
Cookie consent
  • OneTrust

Third-party hosts loaded (3)

  • www.stanleysites.com×8
  • cdn.cookielaw.org×1
  • www.googletagmanager.com×1

Social

DNS records live

NS
  • a1-218.akam.net
  • a18-67.akam.net
  • a5-64.akam.net
  • a6-65.akam.net
  • a8-66.akam.net
  • a9-67.akam.net
MX
  • 10 mxa-00254701.gslb.pphosted.com
  • 10 mxb-00254701.gslb.pphosted.com
TXT
  • domain-verification:6fce9463ee817efc4688cfaa06e7a05ed817386f
Verified for
  • Meta
  • Microsoft 365

Email authentication strong

SPF
v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all
softfail (~all)
DMARC
v=DMARC1; p=quarantine; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com;
policy: quarantine
DKIM
no key found at common selectors

Certificate (current)

DigiCert Global G3 TLS ECC SHA384 2020 CA1
from 2026-01-06 to 2027-01-07
Expires in 231 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.stanleyworks.ch/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src https: data: blob: 'unsafe-inline'; script-src https: data: blob: 'unsafe-inline' 'unsafe-eval'; frame-src https:; base-uri 'self'; upgrade-insecure-requests; report-uri /csp.cgi
strict-transport-security
max-age=15768000

Links to (6)

Linked from (1)