wondercar.be

.be crawl

First seen 2026-05-23 · Last seen 2026-05-31 · ok HTTP/1.1 200 1165 ms crawled 2026-05-28

BE · 5.134.7.163 · AS34762 Combell NV

Reputation 84/100 permissive spf dmarc monitor-only

Classifying

HTML metadata

Title
Contactez-nous pour la réparation de votre voiture | WONDERCAR
Description
Une bosse, une griffe ou un accident ? Contactez Wondercar pour la réparation de votre carrosserie.
Language
fr-BE
Canonical
https://wondercar.be/fr/
Translations
  • fr
  • nl

Open Graph

url
https://wondercar.be/fr/
title
Home
locale
fr_FR
site name
Wondercar
description
Une bosse, une griffe ou un accident ? Contactez Wondercar pour la réparation de votre carrosserie.
locale:alternate
nl_BE

Technology

Server
nginx
CMS
WordPress
jQuery
2.10.2 known XSS (<3.5)
Analytics
  • Google Tag Manager

Third-party hosts loaded (4)

  • challenges.cloudflare.com×1
  • nexus.ensighten.com×1
  • widget.trustpilot.com×1
  • www.googletagmanager.com×1

Social

Contact

Phone

DNS records live

NS
  • ns3.inventis.be
  • ns4.inventis.be
MX
  • 1 wondercar-be.mail.protection.outlook.com
Verified for
  • Brevo
  • Google
  • Meta

Email authentication weak

SPF
v=spf1 include:spf.protection.outlook.com include:spf-eu.emailsignatures365.com –all
permissive (+all) — anyone can send as this domain
DMARC
v=DMARC1; p=none; rua=mailto:rua@dmarc.brevo.com
policy: none (monitoring only)
DKIM
  • mail: k=rsa;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDeMVIzrCa3T14JsNY0IRv5/2V1/v2itlviLQBwXsa7shBD6TrBkswsFUToPyMRWC9tbR/5ey0nRBH0ZVxp+lsmTxid2Y2z…
selectors probed

Certificate (current)

R13
from 2026-04-28 to 2026-07-27
Expires in 56 days

HTTP security headers

Header hygiene 85/100 Checked live page: https://wondercar.be/fr/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
no-referrer-when-downgrade
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src * data: blob: filesystem: about: ws: wss: 'unsafe-inline' 'unsafe-eval'; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; connect-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src * data: blob: ; style-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline';
strict-transport-security
max-age=31536000

Links to (5)

Linked from (5)