wellbee.pl
HTML metadata
Technology
- Server
- istio-envoy
- CMS
- Next.js
- JS framework
- Next.js
- Analytics
-
- Google Tag Manager
- Ads
-
- Meta Pixel
- Cookie consent
-
- Cookiebot
Third-party hosts loaded (5)
- www.googletagmanager.com×2
- connect.facebook.net×1
- consent.cookiebot.com×1
- firebaseinstallations.googleapis.com×1
- storage.googleapis.com×1
Social
Contact
- Phone
DNS records live
- NS
-
- ns1.aftermarket.pl
- ns2.aftermarket.pl
- MX
-
- 1 aspmx.l.google.com
- 10 alt3.aspmx.l.google.com
- 10 alt4.aspmx.l.google.com
- 5 alt1.aspmx.l.google.com
- 5 alt2.aspmx.l.google.com
- TXT
-
firebase=wellbee-backendmojecertpl-site-verification-sg5SyAJbZ2qyi9AvbgYVZNxOJhWKTAHo
- Verified for
-
- Microsoft 365
Email authentication partial
- SPF
-
v=spf1 include:_spf.firebasemail.com ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none; rua=mailto:dmarc@wellbee.pl; pct=100; adkim=s; aspf=spolicy: none (monitoring only) - DKIM
-
- google:
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCMcjA5DBA5pKwC74B17LpmLAvJyIGh7YNn1gAn7cOLvJprtg8wDsLzMyYFK3EMCR2WyvZZKBArnVEBTwHHLr… - s1:
k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4cr74bdHh6as4tXoDbRBbu5b5encGdqtYYCSftUcONPjZP2zIN8eigrpPFyIkU3qrL0q/g+ZTTImLl9QtS… - s2:
k=rsa; t=s; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDdSDU0WxXolzVu4gcWqUlbma65ZashTZT49PR3SbovWyLuYhHK+jzhjDMjHeIW/z1iEXkCRNUmvY9iYkWC1JFREw…
selectors probed - google:
Certificate (current)
R12
Expires in 42 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
interest-cohort=()- x-content-type-options
nosniff- content-security-policy
frame-ancestors none; upgrade-insecure-requests; default-src 'self'; script-src 'self' *.googletagmanager.com *.facebook.net *.google-analytics.com *.googleadservices.com *.gstatic.com *.g.doubleclick.net *.google.com *.google.pl *.cookiebot.com *.cloudflare.com *.usemessages.com t.goadservices.com *.zdassets.com *.zendesk.com *.clickmeeting.com *.segment.com px.ads.linkedin.com *.licdn.com *.hotjar.com *.tiktok.com secure.payu.com 'sha256-sFSfLr8/ySs2Ez1VeuXTAqgQCtH0/ynZD7cXVsD3XMM=' 'sha256-uRzvk8IbGgPPzPsZYrG3b2wO1G8+ih0fokZDoQVh0Ss=' 'sha256-3eE9KdM/XL8xYvos0vZSa9WYE03amCEsCtVEhONRBug=' 'sha256-dPHpsWnsCFc5qM9Ph3zogwNk4v5w/vkv6FkJ82AX93o=' 'sha256-+rD06rW3nWx8UCu18Gmyv1SAU72MJI0gsog+UqYCZc0=' 'sha256-HWXQUNqTfzfPEJRTbCxPd1f6UbJX9QTJQaMqE3QuXcU=' 'sha256-CGL4k5O4Vp7yWSkZKo1YmHNNKla7RtkDVYi3ZBo1SRw='; style-src 'self' 'unsafe-inline'; object-src 'none'; frame-src *.youtube.com *.facebook.net *.cookiebot.com m.goadservices.com *.google.com *.clickmeeting.com *.wellbee.pl https://wellb- strict-transport-security
max-age=31536000; includeSubDomains