webtelemetry.dev

threeofwands.com

F

The Three of Wands

My free software stuff.

Last scanned 50 min agoCompare with another site →

Built with

CMS
Ghost
Backend
Express
Generator tag
Ghost 5.130

Also detected

Libraries
jQuery
Third-party services
Google Analytics

Overview

Status
alive
Registered
2017-07-22 (9 years ago)
First seen here
2026-09-22
Security grade
F (55/100, from headers & TLS)
Privacy score
62/100 (4 third-party script hosts, 1 tracking/marketing services)
Hosting
DigitalOcean, LLC · AS14061 · Netherlands
Response time
204 ms to first byte, measured from our crawler
TLS certificate
Let's Encrypt · TLSv1.3 · expires 2026-11-05
Language
en
Mobile-ready
yes (viewport meta tag)
RSS / Atom feed
yes
Structured data
WebSite
Linked to from
4 other sites seen so far

Loads scripts from

Third-party domains this page pulls JavaScript or iframes from. Each one can see who visits.

jsdelivr.netgoogletagmanager.comcloudflare.comjquery.com

What to fix

  1. Add a Content-Security-Policy
    Limits which scripts can run, and is the main defense against XSS. Start with Content-Security-Policy-Report-Only to test.
  2. Add X-Content-Type-Options
    Header: X-Content-Type-Options: nosniff
  3. Prevent clickjacking
    Header: X-Frame-Options: DENY (or a CSP frame-ancestors directive).
  4. Add a Referrer-Policy
    Header: Referrer-Policy: strict-origin-when-cross-origin
  5. Publish a DMARC record
    A TXT record at _dmarc.<domain>; start with v=DMARC1; p=none; to monitor.

Security & email signals

Badge

Show this site's security grade in a README or footer:

webtelemetry security grade for threeofwands.com
<a href="https://webtelemetry.dev/site/threeofwands.com"><img src="https://webtelemetry.dev/badge/threeofwands.com.svg" alt="Security grade"></a>

Generated automatically from passive, publicly observable data. Think something here is wrong or want this profile removed? See /bot. Machine-readable: JSON.