wegfinder.app

.app crawl

First seen 2026-05-27 · Last seen 2026-05-27 · ok HTTP/1.1 200 532 ms crawled 2026-05-30

DE · 49.13.145.66 · AS24940 Hetzner Online GmbH

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
https://start.wegfinder.app

Technology

Server
Portal
Stack
PHP

DNS records live

NS
  • ns.second-ns.com
  • ns1.your-server.de
  • ns3.second-ns.de
MX
  • 10 mail.wegfinder.app
Verified for
  • Google

Email authentication weak

SPF
v=spf1 +a +mx ?all
neutral (?all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

E8
from 2026-04-12 to 2026-07-11
Expires in 40 days

HTTP security headers

Header hygiene 60/100 Checked live page: https://url.wegfinder.app/

present
  • strict-transport-security
  • content-security-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
content-security-policy
frame-src url.wegfinder.app jungidee.at app-scus-dev-qrd-fieldmanager-dev.azurewebsites.net app-scus-dev-qrd-fieldmanager-qa.azurewebsites.net app-scus-dev-qrd-fieldmanager-uat.azurewebsites.net *.uniguest.com blob: data: 'self'; script-src ajax.cloudflare.com cloud.qr1.at cloud.qrd.by mt.webapp-portal.com m.qrplanet.com cdn.webapp-portal.com js.stripe.com code.jquery.com cdn.jsdelivr.net static-v.tawk.to embed.tawk.to maps.googleapis.com *.google-analytics.com *.googletagmanager.com *.google.com 'unsafe-inline' 'unsafe-eval' data: blob: 'self'; connect-src api.qrplanet.com api.qrpci.com maps.googleapis.com maps.google.com *.tawk.to wss://*.tawk.to m.qrplanet.com mt.webapp-portal.com 'self'; style-src data: blob: 'unsafe-inline' *; font-src embed.tawk.to cloud.qr1.at cloud.qrd.by cdn.webapp-portal.com static-v.tawk.to fonts.gstatic.com data: 'self';object-src cloud.qr1.at cloud.qrd.by data: 'self'; img-src * blob: data: 'self'; default-src mt.webapp-portal.com m.qrplanet.com player.vi
strict-transport-security
max-age=63072000; includeSubDomains

Linked from (1)