werkenbijrivas.nl
HTML metadata
Technology
Third-party hosts loaded (1)
- cdn.jsdelivr.net×2
Social
DNS records live
- NS
-
- ns0.transip.net
- ns1.transip.nl
- ns2.transip.eu
- MX
-
- 10 werkenbijrivas.nl
Email authentication partial
- SPF
-
v=spf1 ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
GeoTrust TLS RSA CA G1
Expires in 74 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Permissions Policy
Header values
- referrer-policy
strict-origin- x-frame-options
DENY- x-content-type-options
nosniff- content-security-policy
default-src 'self' vod-progressive.akamaized.net www.gravatar.com player.vimeo.com *.vimeocdn.com packages.umbraco.org our.umbraco.org;script-src 'unsafe-inline' 'unsafe-eval' 'self' https://cdn.jsdelivr.net/npm/bootstrap@4.6.2/dist/js/bootstrap.bundle.min.js https://cdn.jsdelivr.net/npm/jquery@3.5.1/dist/jquery.slim.min.js https://www.youtube.com https://vjs.zencdn.net/7.18.1/video.min.js https://www.googletagmanager.com https://www.google-analytics.com;style-src 'self' 'unsafe-inline';img-src 'self' data: www.gravatar.com umbraco.tv *.umbraco.com https://img.youtube.com *.google-analytics.com;font-src 'self' data: https://fonts.gstatic.com;connect-src 'self' *.google-analytics.com https://www.recaptcha.net;frame-ancestors 'self'; frame-src 'self' https://www.youtube.com https://www.360rondleiding.nl- strict-transport-security
max-age=31536000; includeSubDomains
Links to (6)
Linked from (1)
- rivas.nl×1