woundwie.de
HTML metadata
Technology
- Server
- nginx
Registration
- Updated
- 2025-02-03
- Name servers
-
- docks12.rzone.de.
- shades13.rzone.de.
DNS records live
- NS
-
- docks12.rzone.de
- shades13.rzone.de
- MX
-
- 5 smtpin.rzone.de
- TXT
-
o2goqgjgmdeoertuu0tn6qcnrv202409220727022k7cuhf1aqeygnqvkkmbrts8o5zp8j6zm6aq81crcevmiiwf05
Certificate (current)
Starfield Secure Certificate Authority - G2
Expires in 311 days
HTTP security headers
- present
-
- content-security-policy
- x-frame-options
- x-content-type-options
- findings
-
- missing HSTS
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing Referrer Policy
- missing Permissions Policy
Header values
- x-frame-options
sameorigin- x-content-type-options
nosniff- content-security-policy
default-src 'self';frame-src 'self' www.youtube-nocookie.com youtube.com www.youtube.com player.vimeo.com vimeo.com *.google.com *.google.de;img-src 'self' 'unsafe-inline' www.google-analytics.com www.google.com www.google.de www.googletagmanager.com maps.gstatic.com maps.googleapis.com maps.gstatic.com maps.googleapis.com data:;style-src 'self' 'unsafe-inline' fonts.googleapis.com;script-src 'self' 'unsafe-inline' www.youtube.com *.google-analytics.com www.googletagmanager.com maps.googleapis.com www.googleadservices.com;connect-src 'self' www.google-analytics.com stats.g.doubleclick.net maps.googleapis.com *.google-analytics.com;font-src 'self' 'unsafe-inline' fonts.gstatic.com data:; object-src 'none';
Links to (1)
- bagw.de×2
Linked from (1)
- bagw.de×2