szcworkstracker.co.uk
HTML metadata
Technology
- Server
- LiteSpeed
- CMS
- WordPress
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (5)
- cdnjs.cloudflare.com×4
- fonts.googleapis.com×2
- maps.googleapis.com×2
- fonts.gstatic.com×1
- www.googletagmanager.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- dns1.comlaude-dns.com
- dns2.comlaude-dns.net
- dns3.comlaude-dns.co.uk
- dns4.comlaude-dns.eu
- MX
-
- 10 mx0.123-reg.co.uk
- 20 mx1.123-reg.co.uk
- TXT
-
google-site-verification=-Xv7b8khfYJ69_P4v0Lub2UXb3qjggWsf1iRvxFCHPs
Email authentication weak
- SPF
- not published
- DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
E7
Expires in 10 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
SAMEORIGIN- x-content-type-options
nosniff- content-security-policy
default-src data: 'self' blob: 'self' api-gb.one.network api.os.uk *.cloudflare.com *.akamaihd.net www.wpo365.com *.sizewellc.com *.helpscout.net wp-rocket.me *.wistia.com *.google-analytics.com *.sharepointonline.com *.cloudfront.net yoast.com *.edfenergy.com i.ytimg.com *.youtube.com *.youtube-nocookie.com link.assetfile.io *.googletagmanager.com *.googleapis.com *.gstatic.com *.gravatar.com 'unsafe-eval' *.google.com flo.uri.sh; script-src 'self' 'unsafe-inline' 'unsafe-hashes' 'unsafe-eval' *.hu-manity.co *.braintreegateway.com *.helpscout.net *.wistia.com cdn.jsdelivr.net *.sizewellc.com *.gstatic.com *.google.com *.googletagmanager.com *.googleapis.com *.cloudflare.com *.flourish.studio; style-src 'self' 'unsafe-inline' *.sizewellc.com *.googleapis.com *.cloudflare.com *.googletagmanager.com *.gstatic.com; connect-src 'self' *.sizewellc.com *.hu-manity.co *.googleapis.com *.googletagmanager.com *.google-analytics.com;