stream-festival.at
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
- jQuery
- 3.7.1
Third-party hosts loaded (1)
- gmpg.org×1
Social
DNS records live
- NS
-
- dns1.linz.at
- dns2.linz.at
Email authentication no MX
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 57 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing content type protection
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- content-security-policy
default-src 'self'; img-src 'self' data: *.ytimg.com s.w.org ps.w.org secure.gravatar.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' stats.linz.at; script-src-elem 'self' 'unsafe-inline' https://stats.linz.at; style-src 'unsafe-inline';style-src-attr 'self' 'unsafe-inline'; style-src-elem 'self' 'unsafe-inline'; font-src data: 'self'; connect-src 'self' https://stats.linz.at; media-src 'self' data:; frame-src 'self' blob: *.youtube.com *.youtube-nocookie.com; worker-src blob: 'self' ; report-uri https://csp-report.linz.at- strict-transport-security
max-age=15552000
Links to (9)
- orf.at×1
- nachrichten.at×1
- lt1.at×1
- linztourismus.at×1
- linzerbier.at×1
- linzag.at×1
- linz.at×1
- instagram.com×1
- facebook.com×1