swivelpay.com
HTML metadata
Technology
- CDN
- Amazon CloudFront
- Server
- AmazonS3
- CMS
- Gatsby
Third-party hosts loaded (2)
- applepay.cdn-apple.com×1
- www.consumer-integrations.prodvault.swbc.com×1
Registration
- Registrar
- Amazon Registrar, Inc.
- Created
- 2018-03-22
- Expires
- 2027-03-22 307 days left
- Updated
- 2026-02-15
- Name servers
-
- ns-1256.awsdns-29.org
- ns-1692.awsdns-19.co.uk
- ns-211.awsdns-26.com
- ns-780.awsdns-33.net
DNS records live
- NS
-
- ns-1256.awsdns-29.org
- ns-1692.awsdns-19.co.uk
- ns-211.awsdns-26.com
- ns-780.awsdns-33.net
Certificate (current)
Amazon RSA 2048 M01
Expires in 235 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
- missing Permissions Policy
Header values
- referrer-policy
strict-origin-when-cross-origin- x-content-type-options
nosniff- content-security-policy
default-src 'none'; img-src 'self' https://consumerpay-prod-assets-us-east-1.s3.amazonaws.com https://consumerpay-prod-assets-us-east-1.s3.us-east-1.amazonaws.com https://consumerpay-beta-assets-us-east-1.s3.amazonaws.com https://consumerpay-qa-assets-us-east-1.s3.amazonaws.com https://consumerpay-dev-assets-us-east-1.s3.amazonaws.com https://s3.amazonaws.com https://*.google-analytics.com https://*.googletagmanager.com https://cdn.getswivel.io data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.consumer-integrations.prodvault.swbc.com https://*.googletagmanager.com https://applepay.cdn-apple.com; frame-src 'self' https://www.consumer-integrations.prodvault.swbc.com ; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; object-src 'none'; manifest-src 'self'; connect-src 'self' https://api.getswivel.io https://api.baconpay.com https://api.consumerpay.getswivel.io https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https:- strict-transport-security
max-age=63072000; includeSubDomains; preload