totem-madrid.com
FTótem Madrid - Boutique Hotel
En pleno corazón de la Milla de Oro, Tótem Madrid está situado en un edificio del siglo XIX completamente rehabilitado y convertido en un hotel boutique de lujo.
Built with
- CMS
- WordPress
- Backend
- PHP
- Generator tag
WPML ver:4.6.8 stt:1,4,2;
Also detected
- Infrastructure
- Nginx
Overview
- Status
- alive
- Registered
- 2016-01-12 (11 years ago)
- First seen here
- 2026-09-22
- Security grade
- F (30/100, from headers & TLS)
- Privacy score
- 74/100 (2 third-party script hosts, 0 tracking/marketing services)
- Hosting
- Amazon.com, Inc. · AS16509 · Ireland
- Server header
nginx- Response time
- 1648 ms to first byte, measured from our crawler
- TLS certificate
- DigiCert Inc · TLSv1.2 · expires 2026-12-19
- Language
- es-es
- Mobile-ready
- yes (viewport meta tag)
- Structured data
- WebPage · ImageObject · BreadcrumbList · WebSite
- Linked to from
- 5 other sites seen so far
Loads scripts from
Third-party domains this page pulls JavaScript or iframes from. Each one can see who visits.
mirai.comvimeo.com
What to fix
- Add Strict-Transport-Security
Header: Strict-Transport-Security: max-age=31536000; includeSubDomains - Add a Content-Security-Policy
Limits which scripts can run, and is the main defense against XSS. Start with Content-Security-Policy-Report-Only to test. - Add X-Content-Type-Options
Header: X-Content-Type-Options: nosniff - Prevent clickjacking
Header: X-Frame-Options: DENY (or a CSP frame-ancestors directive). - Add a Referrer-Policy
Header: Referrer-Policy: strict-origin-when-cross-origin - Mark cookies Secure and HttpOnly
At least one cookie is sent without these flags, exposing it to interception or scripts.
Security & email signals
- ✓ HTTPS
- ✗ HSTS
- ✗ Content-Security-Policy
- ✗ X-Content-Type-Options
- ✗ X-Frame-Options
- ✗ Referrer-Policy
- ✗ Permissions-Policy
- ✓ SPF record
- ✓ DMARC record
- ✗ DKIM record
- ✗ Cookies set securely
- ✓ Has real content (not an empty shell)
- ✓ Valid TLS certificate
Badge
Show this site's security grade in a README or footer:

<a href="https://webtelemetry.dev/site/totem-madrid.com"><img src="https://webtelemetry.dev/badge/totem-madrid.com.svg" alt="Security grade"></a>
Generated automatically from passive, publicly observable data. Think something here is wrong or want this profile removed? See /bot. Machine-readable: JSON.