woostersbakery.com
HTML metadata
Technology
- Server
- LiteSpeed
- CMS
- WordPress
Third-party hosts loaded (1)
- gmpg.org×1
Social
Contact
- Phone
Registration
- Registrar
- Bluehost Inc.
- Created
- 2022-01-01
- Expires
- 2027-01-01 226 days left
- Updated
- 2025-12-17
- Name servers
-
- ns1.krystal.uk
- ns2.krystal.uk
DNS records live
- NS
-
- ns1.krystal.uk
- ns2.krystal.uk
- MX
-
- 10 mx1.krystal.io
- 20 mx2.krystal.io
- TXT
-
google-site-verification=y3hojOjDsgkPPH1pb0PbVIPpX08jLlue1WMJwnRTf4I
Email authentication partial
- SPF
-
v=spf1 ip4:77.72.2.128 +a +mx include:relay.k.io ~allsoftfail (~all) - DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
-
- default:
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAueQjWhOtyExEq3YF/Qnal/ZAHL5/wcLf1VbgUbqOKbpl+CdSTrPUP/W1GE3KIkAuW3D+S+f82iy2wu…
selectors probed - default:
Certificate (current)
R13
Expires in 69 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-frame-options
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
Header values
- referrer-policy
strict-origin-when-cross-origin- x-frame-options
SAMEORIGIN- permissions-policy
accelerometer=(), autoplay=(), camera=(), encrypted-media=(), fullscreen=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), usb=(), xr-spatial-tracking=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; script-src * 'unsafe-inline' 'unsafe-eval' data:; style-src * 'unsafe-inline'; img-src * data:; font-src * data:; frame-src *; connect-src *; media-src * blob:; worker-src 'self' blob:; base-uri 'self'; form-action *; frame-ancestors 'self';- strict-transport-security
max-age=31536000; includeSubDomains; preload