vincizasi.pl
HTML metadata
Technology
- Server
- Apache
- CMS
- WordPress
- jQuery
- 3.7.1
- Analytics
-
- Google Tag Manager
- Fonts
-
- Google Fonts
Third-party hosts loaded (4)
- fonts.googleapis.com×2
- cdn.cookie-script.com×1
- maps.googleapis.com×1
- www.googletagmanager.com×1
Contact
DNS records live
- NS
-
- dns.home.pl
- dns2.home.pl
- dns3.home.pl
- MX
-
- 10 mail.vincizasi.pl
Email authentication weak
- SPF
-
v=spf1 mx ~allsoftfail (~all) - DMARC
- not published
- DKIM
- no key found at common selectors
Certificate (current)
RapidSSL TLS RSA CA G1
Expires in 132 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- short HSTS max-age
- CSP allows unsafe inline scripts/styles
- weak frame protection
Header values
- referrer-policy
no-referrer-when-downgrade- x-frame-options
ALLOW-FROM destinationURL- permissions-policy
microphone=()- x-content-type-options
nosniff- content-security-policy
default-src 'self' 'unsafe-inline' 'unsafe-eval' https: data:- strict-transport-security
max-age=10886400; includeSubDomains; preload