unilabs.se

.se crawl

First seen 2026-05-15 · Last seen 2026-05-20 · ok HTTP/1.1 200 739 ms crawled 2026-05-20

US · 104.18.24.74 · AS13335 Cloudflare, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
Hem | Unilabs
Language
en
Generator
Drupal 10 (https://www.drupal.org)
Canonical
https://unilabs.se/
Translations
  • da
  • en
  • es
  • fi
  • fr
  • nb

Technology

CDN
Cloudflare
CMS
Drupal
PHP
8.1.34 end of life
Analytics
  • Google Tag Manager
Cookie consent
  • OneTrust
Fonts
  • Google Fonts
Third-party hosts loaded (9)
  • cdn.cookielaw.org×1
  • fonts.googleapis.com×1
  • unilabs.com×1
  • unilabs.dk×1
  • unilabs.es×1
  • unilabs.fi×1
  • unilabs.fr×1
  • unilabs.no×1
  • www.googletagmanager.com×1

Social

DNS records live

NS
  • dean.ns.cloudflare.com
  • phoenix.ns.cloudflare.com
TXT
  • _1a7eefcua31i1sovfskhho5q283c95e
Verified for
  • Brevo
  • GlobalSign
  • Google

Email authentication no MX

SPF
v=spf1 -all
strict (-all)
DMARC
v=DMARC1; p=quarantine; rua=mailto:rua@dmarc.brevo.com; pct=100
policy: quarantine
DKIM
no key found at common selectors

Certificate (current)

WE1
from 2026-05-18 to 2026-08-17
Expires in 88 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://unilabs.se/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP uses wildcard sources
  • weak frame protection
Header values
referrer-policy
strict-origin
x-frame-options
SAMEORIGIN, SAMEORIGIN
permissions-policy
autoplay=(), geolocation=()
x-content-type-options
nosniff
content-security-policy
default-src 'self' gap: https://ssl.gstatic.com; script-src-elem self https://*.psplugin.com https://*.boost.ai https://unilabs-se.boost.ai *.unilabs.se unilabs.se *.unilabs.com unilabs.com https://www.clarity.ms https://www.google.com https://connect.facebook.net https://fonts.googleapis.com https://static.addtoany.com/ https://*.cookielaw.org https://cdn.cookielaw.org https://www.google-analytics.com/ https://www.googletagmanager.com https://www.googleadservices.com https://static.hotjar.com https://script.hotjar.com/ https://www.google-analytics.com https://googleads.g.doubleclick.net https://*.googletagmanager.com https://www.googletagmanager.com/ 'nonce-gtagNoNcE2024' 'nonce-sChEmA2024' 'nonce-cReAtEcOoKiE2024' 'nonce-oTkStUb' 'nonce-scriptCoOkIeLaW2024' 'nonce-mAiNtEnAnCeNoNcE2024' 'nonce-mAiNtEnAnCeNoNcE2024Ga' 'nonce-bLoGpOsTsNoNcE2024' 'nonce-fUlLWiDtHnOnCe2024' 'nonce-a2aNoNcE2024' 'nonce-oldCookieBar' 'nonce-oNeTrUsTnOnCe2024' 'nonce-gTmNoJs2024' 'nonce-mAiNtEnAnCeGtMnOnCe20
strict-transport-security
max-age=31536000; includeSubDomains

Links to (6)

Linked from (6)