webtelemetry.dev

hotelpalacebarcelona.com

F

5-star Hotel in Barcelona | Hotel El Palace Barcelona

Welcome to the most famous hotel of Barcelona. Former Ritz Hotel Barcelona. Member of Leading Hotels of the world. Book online now.

Last scanned 45 min agoCompare with another site →

Built with

No platform, CMS or framework detected. Detection is passive: it only sees what a site exposes in its HTML, headers and cookies, so custom or well-hidden stacks show up as nothing rather than as a guess.

Also detected

Libraries
Bootstrap · jQuery
Infrastructure
Nginx
Third-party services
Google Tag Manager

Overview

Status
alive
Registered
2005-07-22 (21 years ago)
First seen here
2026-09-22
Security grade
F (30/100, from headers & TLS)
Privacy score
68/100 (2 third-party script hosts, 1 tracking/marketing services)
Hosting
Google Ireland Limited · AS43515 · Netherlands
Server header
nginx
Response time
320 ms to first byte, measured from our crawler
TLS certificate
Let's Encrypt · TLSv1.3 · expires 2026-11-23
Language
en-gb
Mobile-ready
yes (viewport meta tag)
Linked to from
9 other sites seen so far

Loads scripts from

Third-party domains this page pulls JavaScript or iframes from. Each one can see who visits.

123compareme.combooking-channel.com

What to fix

  1. Add Strict-Transport-Security
    Header: Strict-Transport-Security: max-age=31536000; includeSubDomains
  2. Add a Content-Security-Policy
    Limits which scripts can run, and is the main defense against XSS. Start with Content-Security-Policy-Report-Only to test.
  3. Add X-Content-Type-Options
    Header: X-Content-Type-Options: nosniff
  4. Prevent clickjacking
    Header: X-Frame-Options: DENY (or a CSP frame-ancestors directive).
  5. Add a Referrer-Policy
    Header: Referrer-Policy: strict-origin-when-cross-origin
  6. Mark cookies Secure and HttpOnly
    At least one cookie is sent without these flags, exposing it to interception or scripts.
  7. Publish a DMARC record
    A TXT record at _dmarc.<domain>; start with v=DMARC1; p=none; to monitor.

Security & email signals

Badge

Show this site's security grade in a README or footer:

webtelemetry security grade for hotelpalacebarcelona.com
<a href="https://webtelemetry.dev/site/hotelpalacebarcelona.com"><img src="https://webtelemetry.dev/badge/hotelpalacebarcelona.com.svg" alt="Security grade"></a>

Generated automatically from passive, publicly observable data. Think something here is wrong or want this profile removed? See /bot. Machine-readable: JSON.