webtelemetry.dev

label-emmaus.co

F

Label Emmaüs, vente en ligne solidaire et éthique

Découvrez la boutique en ligne solidaire d'Emmaüs : Déco vintage, fripe pas cher, Livres et BD d'occasion, vaisselle ancienne...

Last scanned 47 min agoCompare with another site →

Built with

CMS
WordPress

Also detected

Libraries
Alpine.js · htmx · jQuery
Infrastructure
Cloudflare
Third-party services
Google Tag Manager · Klaviyo

Overview

Status
alive
Registered
unknown (this domain's registry doesn't publish it via RDAP)
First seen here
2026-09-22
Security grade
F (30/100, from headers & TLS)
Privacy score
22/100 (7 third-party script hosts, 2 tracking/marketing services)
Hosting
Cloudflare, Inc. · AS13335 · Canada
Server header
cloudflare
Response time
874 ms to first byte, measured from our crawler
TLS certificate
Google Trust Services · TLSv1.3 · expires 2026-10-31
Language
fr
Mobile-ready
yes (viewport meta tag)
Structured data
OnlineBusiness
Linked to from
10 other sites seen so far

Loads scripts from

Third-party domains this page pulls JavaScript or iframes from. Each one can see who visits.

sentry-cdn.comadn.cloudcloudflare.comjsdelivr.netweb-boosting.netklaviyo.comcloudflareinsights.com

What to fix

  1. Add Strict-Transport-Security
    Header: Strict-Transport-Security: max-age=31536000; includeSubDomains
  2. Add a Content-Security-Policy
    Limits which scripts can run, and is the main defense against XSS. Start with Content-Security-Policy-Report-Only to test.
  3. Add X-Content-Type-Options
    Header: X-Content-Type-Options: nosniff
  4. Prevent clickjacking
    Header: X-Frame-Options: DENY (or a CSP frame-ancestors directive).
  5. Add a Referrer-Policy
    Header: Referrer-Policy: strict-origin-when-cross-origin
  6. Mark cookies Secure and HttpOnly
    At least one cookie is sent without these flags, exposing it to interception or scripts.

Security & email signals

Badge

Show this site's security grade in a README or footer:

webtelemetry security grade for label-emmaus.co
<a href="https://webtelemetry.dev/site/label-emmaus.co"><img src="https://webtelemetry.dev/badge/label-emmaus.co.svg" alt="Security grade"></a>

Generated automatically from passive, publicly observable data. Think something here is wrong or want this profile removed? See /bot. Machine-readable: JSON.