https://www.freundferreteria.com/

Submitted URL:
https://www.freundferreteria.com/
Report Finished:

Risks · 0 found

Practices that may pose security risks

  • No classification

Security Headers · 9 found

HTTP response headers that can harden the security of a web application

NameValueSupportInfo
Strict-Transport-Securitymax-age=31536000; includeSubDomains; preloadGood
X-Frame-OptionsSAMEORIGINGood
X-Content-Type-OptionsnosniffGood
Content-Security-Policydefault-src 'unsafe-inline' 'self' https://analytics.google.com/ https://ws21.hotjar.com/ https://vc.hotjar.io/ wss://ws21.hotjar.com/api/v2/client/ws https://graph.facebook.com/ https://diffuser-cdn.app-us1.com https://conversations.app-us1.com https://prism.app-us1.com https://trackcmp.net https://wp-ui.app-us1.com https://script.hotjar.com https://vars.hotjar.com https://in.hotjar.com https://ws11.hotjar.com wss://ws11.hotjar.com https://www.googleadservices.com https://www.google.com https://www.google.ca https://www.google.com.sv https://www.facebook.com https://googleads.g.doubleclick.net https://s2.adform.net https://a2.adform.net https://f5desar.freundferreteria.com https://connect.facebook.net https://tracking.qa.paypal.com https://www.sandbox.paypal.com https://www.w3.org https://seal.networksolutions.com https://www.google.com https://www.gstatic.com https://tickets.bitworks.com.sv https://www.googletagmanager.com https://www.google-analytics.com https://stats.g.doubleclick.net https://www.paypal.com https://maps.googleapis.com https://maps.gstatic.com https://www.youtube.com/ https://static.hotjar.com https://app.respond.io/ https://cdn.respond.io/ https://cdn.chatapi.net/ data: https://fonts.gstatic.com https://fonts.gstatic.com https://www.googletagmanager.com https://tagmanager.google.com https://ssl.gstatic.com https://www.gstatic.com https://static.hotjar.com https://cdn.chatapi.net/ https://content.hotjar.io/ wss://ws.hotjar.com/; style-src 'unsafe-inline' 'self' https://tickets.bitworks.com.sv/ https://tagmanager.google.com https://fonts.googleapis.com https://fonts.googleapis.com https://static.hotjar.comGood
Referrer-Policysame-originGood
Clear-Site-Data—Good
X-Permitted-Cross-Domain-Policies—Good
Permissions-Policygeolocation=(self)New
Cross-Origin-Embedder-Policy—New
Cross-Origin-Opener-Policy—New
Cross-Origin-Resource-Policy—New
X-XSS-Protection1; mode=blockDeprecated
Feature-Policygeolocation 'self'Deprecated
Expect-CTmax-age=86400; enforceDeprecated
Public-Key-Pins—Deprecated

Security Violations · 21 found

Requests or resources offending security policies

ViolationTypeInfo
Resource
https://www.googletagmanager.com/gtm.js?id=GTM-5P46B4N
Description
Refused to load the script 'https://cdn01.basis.net/assets/up.js?um=1' because it violates the following Content Security Policy directive: "default-src 'unsafe-inline' 'self' https://analytics.google.com/ https://ws21.hotjar.com/ https://vc.hotjar.io/ wss://ws21.hotjar.com/api/v2/client/ws https://graph.facebook.com/ https://diffuser-cdn.app-us1.com https://conversations.app-us1.com https://prism.app-us1.com https://trackcmp.net https://wp-ui.app-us1.com https://script.hotjar.com https://vars.hotjar.com https://in.hotjar.com https://ws11.hotjar.com wss://ws11.hotjar.com https://www.googleadservices.com https://www.google.com https://www.google.ca https://www.google.com.sv https://www.facebook.com https://googleads.g.doubleclick.net https://s2.adform.net https://a2.adform.net https://f5desar.freundferreteria.com https://connect.facebook.net https://tracking.qa.paypal.com https://www.sandbox.paypal.com https://www.w3.org https://seal.networksolutions.com https://www.google.com https://www.gstatic.com https://tickets.bitworks.com.sv https://www.googletagmanager.com https://www.google-analytics.com https://stats.g.doubleclick.net https://www.paypal.com https://maps.googleapis.com https://maps.gstatic.com https://www.youtube.com/ https://static.hotjar.com https://app.respond.io/ https://cdn.respond.io/ https://cdn.chatapi.net/ data: https://fonts.gstatic.com https://fonts.gstatic.com https://www.googletagmanager.com https://tagmanager.google.com https://ssl.gstatic.com https://www.gstatic.com https://static.hotjar.com https://cdn.chatapi.net/ https://content.hotjar.io/ wss://ws.hotjar.com/". Note that 'script-src-elem' was not explicitly set, so 'default-src' is used as a fallback.
Content Security Policy
Resource
https://www.googletagmanager.com/gtm.js?id=GTM-5P46B4N
Description
Refused to load the script 'https://p.teads.tv/teads-fellow.js' because it violates the following Content Security Policy directive: "default-src 'unsafe-inline' 'self' https://analytics.google.com/ https://ws21.hotjar.com/ https://vc.hotjar.io/ wss://ws21.hotjar.com/api/v2/client/ws https://graph.facebook.com/ https://diffuser-cdn.app-us1.com https://conversations.app-us1.com https://prism.app-us1.com https://trackcmp.net https://wp-ui.app-us1.com https://script.hotjar.com https://vars.hotjar.com https://in.hotjar.com https://ws11.hotjar.com wss://ws11.hotjar.com https://www.googleadservices.com https://www.google.com https://www.google.ca https://www.google.com.sv https://www.facebook.com https://googleads.g.doubleclick.net https://s2.adform.net https://a2.adform.net https://f5desar.freundferreteria.com https://connect.facebook.net https://tracking.qa.paypal.com https://www.sandbox.paypal.com https://www.w3.org https://seal.networksolutions.com https://www.google.com https://www.gstatic.com https://tickets.bitworks.com.sv https://www.googletagmanager.com https://www.google-analytics.com https://stats.g.doubleclick.net https://www.paypal.com https://maps.googleapis.com https://maps.gstatic.com https://www.youtube.com/ https://static.hotjar.com https://app.respond.io/ https://cdn.respond.io/ https://cdn.chatapi.net/ data: https://fonts.gstatic.com https://fonts.gstatic.com https://www.googletagmanager.com https://tagmanager.google.com https://ssl.gstatic.com https://www.gstatic.com https://static.hotjar.com https://cdn.chatapi.net/ https://content.hotjar.io/ wss://ws.hotjar.com/". Note that 'script-src-elem' was not explicitly set, so 'default-src' is used as a fallback.
Content Security Policy
Resource
https://www.freundferreteria.com/
Description
Refused to load the image 'https://d21y75miwcfqoq.cloudfront.net/ccc95dd8' because it violates the following Content Security Policy directive: "default-src 'unsafe-inline' 'self' https://analytics.google.com/ https://ws21.hotjar.com/ https://vc.hotjar.io/ wss://ws21.hotjar.com/api/v2/client/ws https://graph.facebook.com/ https://diffuser-cdn.app-us1.com https://conversations.app-us1.com https://prism.app-us1.com https://trackcmp.net https://wp-ui.app-us1.com https://script.hotjar.com https://vars.hotjar.com https://in.hotjar.com https://ws11.hotjar.com wss://ws11.hotjar.com https://www.googleadservices.com https://www.google.com https://www.google.ca https://www.google.com.sv https://www.facebook.com https://googleads.g.doubleclick.net https://s2.adform.net https://a2.adform.net https://f5desar.freundferreteria.com https://connect.facebook.net https://tracking.qa.paypal.com https://www.sandbox.paypal.com https://www.w3.org https://seal.networksolutions.com https://www.google.com https://www.gstatic.com https://tickets.bitworks.com.sv https://www.googletagmanager.com https://www.google-analytics.com https://stats.g.doubleclick.net https://www.paypal.com https://maps.googleapis.com https://maps.gstatic.com https://www.youtube.com/ https://static.hotjar.com https://app.respond.io/ https://cdn.respond.io/ https://cdn.chatapi.net/ data: https://fonts.gstatic.com https://fonts.gstatic.com https://www.googletagmanager.com https://tagmanager.google.com https://ssl.gstatic.com https://www.gstatic.com https://static.hotjar.com https://cdn.chatapi.net/ https://content.hotjar.io/ wss://ws.hotjar.com/". Note that 'img-src' was not explicitly set, so 'default-src' is used as a fallback.
Content Security Policy
Resource
https://www.freundferreteria.com/
Description
Refused to load the script 'https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015' because it violates the following Content Security Policy directive: "default-src 'unsafe-inline' 'self' https://analytics.google.com/ https://ws21.hotjar.com/ https://vc.hotjar.io/ wss://ws21.hotjar.com/api/v2/client/ws https://graph.facebook.com/ https://diffuser-cdn.app-us1.com https://conversations.app-us1.com https://prism.app-us1.com https://trackcmp.net https://wp-ui.app-us1.com https://script.hotjar.com https://vars.hotjar.com https://in.hotjar.com https://ws11.hotjar.com wss://ws11.hotjar.com https://www.googleadservices.com https://www.google.com https://www.google.ca https://www.google.com.sv https://www.facebook.com https://googleads.g.doubleclick.net https://s2.adform.net https://a2.adform.net https://f5desar.freundferreteria.com https://connect.facebook.net https://tracking.qa.paypal.com https://www.sandbox.paypal.com https://www.w3.org https://seal.networksolutions.com https://www.google.com https://www.gstatic.com https://tickets.bitworks.com.sv https://www.googletagmanager.com https://www.google-analytics.com https://stats.g.doubleclick.net https://www.paypal.com https://maps.googleapis.com https://maps.gstatic.com https://www.youtube.com/ https://static.hotjar.com https://app.respond.io/ https://cdn.respond.io/ https://cdn.chatapi.net/ data: https://fonts.gstatic.com https://fonts.gstatic.com https://www.googletagmanager.com https://tagmanager.google.com https://ssl.gstatic.com https://www.gstatic.com https://static.hotjar.com https://cdn.chatapi.net/ https://content.hotjar.io/ wss://ws.hotjar.com/". Note that 'script-src-elem' was not explicitly set, so 'default-src' is used as a fallback.
Content Security Policy
Resource
https://www.googletagmanager.com/gtag/js?id=G-MMC6PC0B4T&l=dataLayer&cx=c&gtm=45He4bk0v9165867531za200
Description
Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-MMC6PC0B4T&gtm=45je4bk0v9169742930z89165867531za200zb9165867531&_p=1732826898303&gcd=13l3l3l2l1l1&npa=1&dma_cps=syphamo&dma=1&tag_exp=101925629~102067555~102067808~102077855~102081485&cid=842751769.1732826900&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=noapi&_s=1&sid=1732826900&sct=1&seg=0&dl=https%3A%2F%2Fwww.freundferreteria.com%2F&dt=FERRETERIA%20FREUND%20EL%20SALVADOR&en=page_view&_fv=1&_nsi=1&_ss=1&tfd=3992' because it violates the following Content Security Policy directive: "default-src 'unsafe-inline' 'self' https://analytics.google.com/ https://ws21.hotjar.com/ https://vc.hotjar.io/ wss://ws21.hotjar.com/api/v2/client/ws https://graph.facebook.com/ https://diffuser-cdn.app-us1.com https://conversations.app-us1.com https://prism.app-us1.com https://trackcmp.net https://wp-ui.app-us1.com https://script.hotjar.com https://vars.hotjar.com https://in.hotjar.com https://ws11.hotjar.com wss://ws11.hotjar.com https://www.googleadservices.com https://www.google.com https://www.google.ca https://www.google.com.sv https://www.facebook.com https://googleads.g.doubleclick.net https://s2.adform.net https://a2.adform.net https://f5desar.freundferreteria.com https://connect.facebook.net https://tracking.qa.paypal.com https://www.sandbox.paypal.com https://www.w3.org https://seal.networksolutions.com https://www.google.com https://www.gstatic.com https://tickets.bitworks.com.sv https://www.googletagmanager.com https://www.google-analytics.com https://stats.g.doubleclick.net https://www.paypal.com https://maps.googleapis.com https://maps.gstatic.com https://www.youtube.com/ https://static.hotjar.com https://app.respond.io/ https://cdn.respond.io/ https://cdn.chatapi.net/ data: https://fonts.gstatic.com https://fonts.gstatic.com https://www.googletagmanager.com https://tagmanager.google.com https://ssl.gstatic.com https://www.gstatic.com https://static.hotjar.com https://cdn.chatapi.net/ https://content.hotjar.io/ wss://ws.hotjar.com/". Note that 'connect-src' was not explicitly set, so 'default-src' is used as a fallback.
Content Security Policy
Resource
https://www.googletagmanager.com/gtag/js?id=G-MMC6PC0B4T&l=dataLayer&cx=c&gtm=45He4bk0v9165867531za200
Description
Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-MMC6PC0B4T&gtm=45je4bk0v9169742930z89165867531za200zb9165867531&_p=1732826898303&gcd=13l3l3l2l1l1&npa=1&dma_cps=syphamo&dma=1&tag_exp=101925629~102067555~102067808~102077855~102081485&cid=842751769.1732826900&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=noapi&_s=1&sid=1732826900&sct=1&seg=0&dl=https%3A%2F%2Fwww.freundferreteria.com%2F&dt=FERRETERIA%20FREUND%20EL%20SALVADOR&en=page_view&_fv=1&_nsi=1&_ss=1&tfd=3992' because it violates the document's Content Security Policy.
Content Security Policy
Resource
https://www.googletagmanager.com/gtag/js?id=G-5ZNENTXHSM&l=dataLayer&cx=c&gtm=45He4bk0v812524486za200
Description
Refused to connect to 'https://region1.analytics.google.com/g/collect?v=2&tid=G-5ZNENTXHSM&gtm=45je4bk0v9121799060z8812524486za200zb812524486&_p=1732826898303&_gaz=1&gcd=13l3l3l2l1l1&npa=1&dma_cps=syphamo&dma=1&tag_exp=101925629~102067555~102067808~102077855~102081485&cid=842751769.1732826900&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=noapi&_s=1&sid=1732826900&sct=1&seg=0&dl=https%3A%2F%2Fwww.freundferreteria.com%2F&dt=FERRETERIA%20FREUND%20EL%20SALVADOR&en=user_id&_fv=2&_ss=1&tfd=4170' because it violates the following Content Security Policy directive: "default-src 'unsafe-inline' 'self' https://analytics.google.com/ https://ws21.hotjar.com/ https://vc.hotjar.io/ wss://ws21.hotjar.com/api/v2/client/ws https://graph.facebook.com/ https://diffuser-cdn.app-us1.com https://conversations.app-us1.com https://prism.app-us1.com https://trackcmp.net https://wp-ui.app-us1.com https://script.hotjar.com https://vars.hotjar.com https://in.hotjar.com https://ws11.hotjar.com wss://ws11.hotjar.com https://www.googleadservices.com https://www.google.com https://www.google.ca https://www.google.com.sv https://www.facebook.com https://googleads.g.doubleclick.net https://s2.adform.net https://a2.adform.net https://f5desar.freundferreteria.com https://connect.facebook.net https://tracking.qa.paypal.com https://www.sandbox.paypal.com https://www.w3.org https://seal.networksolutions.com https://www.google.com https://www.gstatic.com https://tickets.bitworks.com.sv https://www.googletagmanager.com https://www.google-analytics.com https://stats.g.doubleclick.net https://www.paypal.com https://maps.googleapis.com https://maps.gstatic.com https://www.youtube.com/ https://static.hotjar.com https://app.respond.io/ https://cdn.respond.io/ https://cdn.chatapi.net/ data: https://fonts.gstatic.com https://fonts.gstatic.com https://www.googletagmanager.com https://tagmanager.google.com https://ssl.gstatic.com https://www.gstatic.com https://static.hotjar.com https://cdn.chatapi.net/ https://content.hotjar.io/ wss://ws.hotjar.com/". Note that 'connect-src' was not explicitly set, so 'default-src' is used as a fallback.
Content Security Policy
Resource
https://www.googletagmanager.com/gtag/js?id=G-5ZNENTXHSM&l=dataLayer&cx=c&gtm=45He4bk0v812524486za200
Description
Refused to connect to 'https://region1.analytics.google.com/g/collect?v=2&tid=G-5ZNENTXHSM&gtm=45je4bk0v9121799060z8812524486za200zb812524486&_p=1732826898303&_gaz=1&gcd=13l3l3l2l1l1&npa=1&dma_cps=syphamo&dma=1&tag_exp=101925629~102067555~102067808~102077855~102081485&cid=842751769.1732826900&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=noapi&_s=1&sid=1732826900&sct=1&seg=0&dl=https%3A%2F%2Fwww.freundferreteria.com%2F&dt=FERRETERIA%20FREUND%20EL%20SALVADOR&en=user_id&_fv=2&_ss=1&tfd=4170' because it violates the document's Content Security Policy.
Content Security Policy
Resource
https://www.googletagmanager.com/gtag/js?id=G-5ZNENTXHSM&l=dataLayer&cx=c&gtm=45He4bk0v812524486za200
Description
Refused to connect to 'https://region1.analytics.google.com/g/collect?v=2&tid=G-5ZNENTXHSM&gtm=45je4bk0v9121799060z8812524486za200zb812524486&_p=1732826898303&gcd=13l3l3l2l1l1&npa=1&dma_cps=syphamo&dma=1&tag_exp=101925629~102067555~102067808~102077855~102081485&cid=842751769.1732826900&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=noapi&_s=2&sid=1732826900&sct=1&seg=1&dl=https%3A%2F%2Fwww.freundferreteria.com%2F&dt=FERRETERIA%20FREUND%20EL%20SALVADOR&en=page_view&_c=1&tfd=4242' because it violates the following Content Security Policy directive: "default-src 'unsafe-inline' 'self' https://analytics.google.com/ https://ws21.hotjar.com/ https://vc.hotjar.io/ wss://ws21.hotjar.com/api/v2/client/ws https://graph.facebook.com/ https://diffuser-cdn.app-us1.com https://conversations.app-us1.com https://prism.app-us1.com https://trackcmp.net https://wp-ui.app-us1.com https://script.hotjar.com https://vars.hotjar.com https://in.hotjar.com https://ws11.hotjar.com wss://ws11.hotjar.com https://www.googleadservices.com https://www.google.com https://www.google.ca https://www.google.com.sv https://www.facebook.com https://googleads.g.doubleclick.net https://s2.adform.net https://a2.adform.net https://f5desar.freundferreteria.com https://connect.facebook.net https://tracking.qa.paypal.com https://www.sandbox.paypal.com https://www.w3.org https://seal.networksolutions.com https://www.google.com https://www.gstatic.com https://tickets.bitworks.com.sv https://www.googletagmanager.com https://www.google-analytics.com https://stats.g.doubleclick.net https://www.paypal.com https://maps.googleapis.com https://maps.gstatic.com https://www.youtube.com/ https://static.hotjar.com https://app.respond.io/ https://cdn.respond.io/ https://cdn.chatapi.net/ data: https://fonts.gstatic.com https://fonts.gstatic.com https://www.googletagmanager.com https://tagmanager.google.com https://ssl.gstatic.com https://www.gstatic.com https://static.hotjar.com https://cdn.chatapi.net/ https://content.hotjar.io/ wss://ws.hotjar.com/". Note that 'connect-src' was not explicitly set, so 'default-src' is used as a fallback.
Content Security Policy
Resource
https://www.googletagmanager.com/gtag/js?id=G-5ZNENTXHSM&l=dataLayer&cx=c&gtm=45He4bk0v812524486za200
Description
Refused to connect to 'https://region1.analytics.google.com/g/collect?v=2&tid=G-5ZNENTXHSM&gtm=45je4bk0v9121799060z8812524486za200zb812524486&_p=1732826898303&gcd=13l3l3l2l1l1&npa=1&dma_cps=syphamo&dma=1&tag_exp=101925629~102067555~102067808~102077855~102081485&cid=842751769.1732826900&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=noapi&_s=2&sid=1732826900&sct=1&seg=1&dl=https%3A%2F%2Fwww.freundferreteria.com%2F&dt=FERRETERIA%20FREUND%20EL%20SALVADOR&en=page_view&_c=1&tfd=4242' because it violates the document's Content Security Policy.
Content Security Policy
Resource
https://www.googletagmanager.com/gtag/js?id=G-5ZNENTXHSM&l=dataLayer&cx=c&gtm=45He4bk0v812524486za200
Description
Refused to connect to 'https://region1.analytics.google.com/g/collect?v=2&tid=G-5ZNENTXHSM&gtm=45je4bk0v9121799060z8812524486za200zb812524486&_p=1732826898303&gcd=13l3l3l2l1l1&npa=1&dma_cps=syphamo&dma=1&tag_exp=101925629~102067555~102067808~102077855~102081485&cid=842751769.1732826900&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=noapi&_s=3&dp=%2F&sid=1732826900&sct=1&seg=1&dl=https%3A%2F%2Fwww.freundferreteria.com%2F&dt=FERRETERIA%20FREUND%20EL%20SALVADOR&en=page_view&_c=1&ep.page_url=https%3A%2F%2Fwww.freundferreteria.com%2F&tfd=4261' because it violates the following Content Security Policy directive: "default-src 'unsafe-inline' 'self' https://analytics.google.com/ https://ws21.hotjar.com/ https://vc.hotjar.io/ wss://ws21.hotjar.com/api/v2/client/ws https://graph.facebook.com/ https://diffuser-cdn.app-us1.com https://conversations.app-us1.com https://prism.app-us1.com https://trackcmp.net https://wp-ui.app-us1.com https://script.hotjar.com https://vars.hotjar.com https://in.hotjar.com https://ws11.hotjar.com wss://ws11.hotjar.com https://www.googleadservices.com https://www.google.com https://www.google.ca https://www.google.com.sv https://www.facebook.com https://googleads.g.doubleclick.net https://s2.adform.net https://a2.adform.net https://f5desar.freundferreteria.com https://connect.facebook.net https://tracking.qa.paypal.com https://www.sandbox.paypal.com https://www.w3.org https://seal.networksolutions.com https://www.google.com https://www.gstatic.com https://tickets.bitworks.com.sv https://www.googletagmanager.com https://www.google-analytics.com https://stats.g.doubleclick.net https://www.paypal.com https://maps.googleapis.com https://maps.gstatic.com https://www.youtube.com/ https://static.hotjar.com https://app.respond.io/ https://cdn.respond.io/ https://cdn.chatapi.net/ data: https://fonts.gstatic.com https://fonts.gstatic.com https://www.googletagmanager.com https://tagmanager.google.com https://ssl.gstatic.com https://www.gstatic.com https://static.hotjar.com https://cdn.chatapi.net/ https://content.hotjar.io/ wss://ws.hotjar.com/". Note that 'connect-src' was not explicitly set, so 'default-src' is used as a fallback.
Content Security Policy
Resource
https://www.googletagmanager.com/gtag/js?id=G-5ZNENTXHSM&l=dataLayer&cx=c&gtm=45He4bk0v812524486za200
Description
Refused to connect to 'https://region1.analytics.google.com/g/collect?v=2&tid=G-5ZNENTXHSM&gtm=45je4bk0v9121799060z8812524486za200zb812524486&_p=1732826898303&gcd=13l3l3l2l1l1&npa=1&dma_cps=syphamo&dma=1&tag_exp=101925629~102067555~102067808~102077855~102081485&cid=842751769.1732826900&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=noapi&_s=3&dp=%2F&sid=1732826900&sct=1&seg=1&dl=https%3A%2F%2Fwww.freundferreteria.com%2F&dt=FERRETERIA%20FREUND%20EL%20SALVADOR&en=page_view&_c=1&ep.page_url=https%3A%2F%2Fwww.freundferreteria.com%2F&tfd=4261' because it violates the document's Content Security Policy.
Content Security Policy
Resource
https://www.freundferreteria.com/
Description
Refused to load the image 'https://www.google.es/ads/ga-audiences?v=1&t=sr&slf_rd=1&_r=4&tid=G-5ZNENTXHSM&cid=842751769.1732826900&gtm=45je4bk0v9121799060z8812524486za200zb812524486&aip=1&dma=1&dma_cps=syphamo&gcd=13l3l3l2l1l1&npa=1&frm=0&tag_exp=101925629~102067555~102067808~102077855~102081485&tag_exp=101925629~102067555~102067808~102077855~102081485&z=1106413090' because it violates the following Content Security Policy directive: "default-src 'unsafe-inline' 'self' https://analytics.google.com/ https://ws21.hotjar.com/ https://vc.hotjar.io/ wss://ws21.hotjar.com/api/v2/client/ws https://graph.facebook.com/ https://diffuser-cdn.app-us1.com https://conversations.app-us1.com https://prism.app-us1.com https://trackcmp.net https://wp-ui.app-us1.com https://script.hotjar.com https://vars.hotjar.com https://in.hotjar.com https://ws11.hotjar.com wss://ws11.hotjar.com https://www.googleadservices.com https://www.google.com https://www.google.ca https://www.google.com.sv https://www.facebook.com https://googleads.g.doubleclick.net https://s2.adform.net https://a2.adform.net https://f5desar.freundferreteria.com https://connect.facebook.net https://tracking.qa.paypal.com https://www.sandbox.paypal.com https://www.w3.org https://seal.networksolutions.com https://www.google.com https://www.gstatic.com https://tickets.bitworks.com.sv https://www.googletagmanager.com https://www.google-analytics.com https://stats.g.doubleclick.net https://www.paypal.com https://maps.googleapis.com https://maps.gstatic.com https://www.youtube.com/ https://static.hotjar.com https://app.respond.io/ https://cdn.respond.io/ https://cdn.chatapi.net/ data: https://fonts.gstatic.com https://fonts.gstatic.com https://www.googletagmanager.com https://tagmanager.google.com https://ssl.gstatic.com https://www.gstatic.com https://static.hotjar.com https://cdn.chatapi.net/ https://content.hotjar.io/ wss://ws.hotjar.com/". Note that 'img-src' was not explicitly set, so 'default-src' is used as a fallback.
Content Security Policy
Description
Refused to load the script 'https://origin.acuityplatform.com/event/v2/pixel.js' because it violates the following Content Security Policy directive: "default-src 'unsafe-inline' 'self' https://analytics.google.com/ https://ws21.hotjar.com/ https://vc.hotjar.io/ wss://ws21.hotjar.com/api/v2/client/ws https://graph.facebook.com/ https://diffuser-cdn.app-us1.com https://conversations.app-us1.com https://prism.app-us1.com https://trackcmp.net https://wp-ui.app-us1.com https://script.hotjar.com https://vars.hotjar.com https://in.hotjar.com https://ws11.hotjar.com wss://ws11.hotjar.com https://www.googleadservices.com https://www.google.com https://www.google.ca https://www.google.com.sv https://www.facebook.com https://googleads.g.doubleclick.net https://s2.adform.net https://a2.adform.net https://f5desar.freundferreteria.com https://connect.facebook.net https://tracking.qa.paypal.com https://www.sandbox.paypal.com https://www.w3.org https://seal.networksolutions.com https://www.google.com https://www.gstatic.com https://tickets.bitworks.com.sv https://www.googletagmanager.com https://www.google-analytics.com https://stats.g.doubleclick.net https://www.paypal.com https://maps.googleapis.com https://maps.gstatic.com https://www.youtube.com/ https://static.hotjar.com https://app.respond.io/ https://cdn.respond.io/ https://cdn.chatapi.net/ data: https://fonts.gstatic.com https://fonts.gstatic.com https://www.googletagmanager.com https://tagmanager.google.com https://ssl.gstatic.com https://www.gstatic.com https://static.hotjar.com https://cdn.chatapi.net/ https://content.hotjar.io/ wss://ws.hotjar.com/". Note that 'script-src-elem' was not explicitly set, so 'default-src' is used as a fallback.
Content Security Policy
Resource
https://www.freundferreteria.com/
Description
Refused to load the image 'https://www.google.es/pagead/1p-conversion/755303600/?random=1005647241&cv=11&fst=1732826900037&bg=ffffff&guid=ON&async=1&gtm=45be4bk0v9102561001z8812524486za201&gcd=13l3l3l2l1l1&dma_cps=syphamo&dma=1&tag_exp=101925629~102067555~102067808~102077855~102081485&u_w=1&u_h=1&url=https%3A%2F%2Fwww.freundferreteria.com%2F&label=k0A5CLCD1uMZELCJlOgC&hn=www.googleadservices.com&frm=0&tiba=FERRETERIA%20FREUND%20EL%20SALVADOR&value=0&npa=1&pscdl=noapi&auid=628394384.1732826900&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&fdr=SA&fmt=3&ct_cookie_present=false&crd=CLHBsQIIsMGxAgi5wbECCLHDsQIIisWxAgjCybECCOvGsQII08WxAg&pscrd=IhMIpu7dnvP_iQMVSisGAB2ZQgd5MgIIAzICCAQyAggHMgIICDICCAkyAggKMgIIAjICCAsyAggVMgIIHzICCBMyAggSQlRDaEFJZ01hZ3VnWVE0c1dycV9LUHRaTkpFaXNBRUgzMGlCOVdlOVZjb1FVOFQ0QjVQa1V4WTFwY19TQ2REOW5GcHU5N1dHQjNNcjdIWm1ERGpBRXY&is_vtc=1&cid=CAQSGwCa7L7dGdNfrX92Km0FYyiw4IIEIMrmo3K8mQ&eitems=ChAIgMagugYQgNWkooe5-7AoEh0ArWutb1poUGS-LBas5meEBImrqNp6V7z0qhHv_g&random=3371555168&ipr=y' because it violates the following Content Security Policy directive: "default-src 'unsafe-inline' 'self' https://analytics.google.com/ https://ws21.hotjar.com/ https://vc.hotjar.io/ wss://ws21.hotjar.com/api/v2/client/ws https://graph.facebook.com/ https://diffuser-cdn.app-us1.com https://conversations.app-us1.com https://prism.app-us1.com https://trackcmp.net https://wp-ui.app-us1.com https://script.hotjar.com https://vars.hotjar.com https://in.hotjar.com https://ws11.hotjar.com wss://ws11.hotjar.com https://www.googleadservices.com https://www.google.com https://www.google.ca https://www.google.com.sv https://www.facebook.com https://googleads.g.doubleclick.net https://s2.adform.net https://a2.adform.net https://f5desar.freundferreteria.com https://connect.facebook.net https://tracking.qa.paypal.com https://www.sandbox.paypal.com https://www.w3.org https://seal.networksolutions.com https://www.google.com https://www.gstatic.com https://tickets.bitworks.com.sv https://www.googletagmanager.com https://www.google-analytics.com https://stats.g.doubleclick.net https://www.paypal.com https://maps.googleapis.com https://maps.gstatic.com https://www.youtube.com/ https://static.hotjar.com https://app.respond.io/ https://cdn.respond.io/ https://cdn.chatapi.net/ data: https://fonts.gstatic.com https://fonts.gstatic.com https://www.googletagmanager.com https://tagmanager.google.com https://ssl.gstatic.com https://www.gstatic.com https://static.hotjar.com https://cdn.chatapi.net/ https://content.hotjar.io/ wss://ws.hotjar.com/". Note that 'img-src' was not explicitly set, so 'default-src' is used as a fallback.
Content Security Policy
Resource
https://www.freundferreteria.com/
Description
Refused to load the image 'https://a1.seadform.net/serving/cookie/sync/?uid=3940646749095381336&stamp=RROq2q8IDuUDvP-67D9Y4w2' because it violates the following Content Security Policy directive: "default-src 'unsafe-inline' 'self' https://analytics.google.com/ https://ws21.hotjar.com/ https://vc.hotjar.io/ wss://ws21.hotjar.com/api/v2/client/ws https://graph.facebook.com/ https://diffuser-cdn.app-us1.com https://conversations.app-us1.com https://prism.app-us1.com https://trackcmp.net https://wp-ui.app-us1.com https://script.hotjar.com https://vars.hotjar.com https://in.hotjar.com https://ws11.hotjar.com wss://ws11.hotjar.com https://www.googleadservices.com https://www.google.com https://www.google.ca https://www.google.com.sv https://www.facebook.com https://googleads.g.doubleclick.net https://s2.adform.net https://a2.adform.net https://f5desar.freundferreteria.com https://connect.facebook.net https://tracking.qa.paypal.com https://www.sandbox.paypal.com https://www.w3.org https://seal.networksolutions.com https://www.google.com https://www.gstatic.com https://tickets.bitworks.com.sv https://www.googletagmanager.com https://www.google-analytics.com https://stats.g.doubleclick.net https://www.paypal.com https://maps.googleapis.com https://maps.gstatic.com https://www.youtube.com/ https://static.hotjar.com https://app.respond.io/ https://cdn.respond.io/ https://cdn.chatapi.net/ data: https://fonts.gstatic.com https://fonts.gstatic.com https://www.googletagmanager.com https://tagmanager.google.com https://ssl.gstatic.com https://www.gstatic.com https://static.hotjar.com https://cdn.chatapi.net/ https://content.hotjar.io/ wss://ws.hotjar.com/". Note that 'img-src' was not explicitly set, so 'default-src' is used as a fallback.
Content Security Policy
Resource
https://a2.adform.net/
Description
Refused to frame 'https://c1.adform.net/' because it violates the following Content Security Policy directive: "default-src 'self' https://analytics.google.com/ https://ws21.hotjar.com/ https://vc.hotjar.io/ wss://ws21.hotjar.com/api/v2/client/ws https://graph.facebook.com/ https://diffuser-cdn.app-us1.com https://conversations.app-us1.com https://prism.app-us1.com https://trackcmp.net https://wp-ui.app-us1.com https://script.hotjar.com https://vars.hotjar.com https://in.hotjar.com https://ws11.hotjar.com wss://ws11.hotjar.com https://www.googleadservices.com https://www.google.com https://www.google.ca https://www.google.com.sv https://www.facebook.com https://googleads.g.doubleclick.net https://s2.adform.net https://a2.adform.net https://f5desar.freundferreteria.com https://connect.facebook.net https://tracking.qa.paypal.com https://www.sandbox.paypal.com https://www.w3.org https://seal.networksolutions.com https://www.google.com https://www.gstatic.com https://tickets.bitworks.com.sv https://www.googletagmanager.com https://www.google-analytics.com https://stats.g.doubleclick.net https://www.paypal.com https://maps.googleapis.com https://maps.gstatic.com https://www.youtube.com/ https://static.hotjar.com https://app.respond.io/ https://cdn.respond.io/ https://cdn.chatapi.net/ data: https://fonts.gstatic.com https://fonts.gstatic.com https://www.googletagmanager.com https://tagmanager.google.com https://ssl.gstatic.com https://www.gstatic.com https://static.hotjar.com https://cdn.chatapi.net/ https://content.hotjar.io/ wss://ws.hotjar.com/". Note that 'frame-src' was not explicitly set, so 'default-src' is used as a fallback.
Content Security Policy
Resource
https://www.googletagmanager.com/gtag/js?id=G-MMC6PC0B4T&l=dataLayer&cx=c&gtm=45He4bk0v9165867531za200
Description
Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-MMC6PC0B4T&gtm=45je4bk0v9169742930z89165867531za200zb9165867531&_p=1732826898303&gcd=13l3l3l2l1l1&npa=1&dma_cps=syphamo&dma=1&tag_exp=101925629~102067555~102067808~102077855~102081485&cid=842751769.1732826900&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=noapi&_s=2&sid=1732826900&sct=1&seg=0&dl=https%3A%2F%2Fwww.freundferreteria.com%2F&dt=FERRETERIA%20FREUND%20EL%20SALVADOR&en=view_item_list&pr1=id48668180~nmESCALERA%20ART...%20CROMADO~brKWIKSET~pr220.99~k0currency~v0USD~c2Si~c374.01~c4false&pr6=id753874~nmBOTA%20TENIS%20INDUSTRIAL%20DIEL%C3%89CTRICO%20CON%20CUBO%20TALLA%2010%20NEGRO%2FBLANCO~brVAN%20VIEN~pr74~k0currency~v0USD~c2Si~c35~c4false&pr7=id758587~nmESCRITORIO%2073X80X40CM%20MELAMINA%20WENGUE%20PLEGABLE%20ALMYRA~brRTA%20DESIGN~pr49.99~k0currency~v0USD~c2Si~c319.96~c4false&pr8=id627282~nmBARBACOA%20CARBON%2042X50PLG%20CON%20REPISA%20LATERAL%20Y%20FRONTAL~brCHAR-GRILLER~pr199~k0currency~v0USD~c2Si~c365~c4false&tfd=9461' because it violates the following Content Security Policy directive: "default-src 'unsafe-inline' 'self' https://analytics.google.com/ https://ws21.hotjar.com/ https://vc.hotjar.io/ wss://ws21.hotjar.com/api/v2/client/ws https://graph.facebook.com/ https://diffuser-cdn.app-us1.com https://conversations.app-us1.com https://prism.app-us1.com https://trackcmp.net https://wp-ui.app-us1.com https://script.hotjar.com https://vars.hotjar.com https://in.hotjar.com https://ws11.hotjar.com wss://ws11.hotjar.com https://www.googleadservices.com https://www.google.com https://www.google.ca https://www.google.com.sv https://www.facebook.com https://googleads.g.doubleclick.net https://s2.adform.net https://a2.adform.net https://f5desar.freundferreteria.com https://connect.facebook.net https://tracking.qa.paypal.com https://www.sandbox.paypal.com https://www.w3.org https://seal.networksolutions.com https://www.google.com https://www.gstatic.com https://tickets.bitworks.com.sv https://www.googletagmanager.com https://www.google-analytics.com https://stats.g.doubleclick.net https://www.paypal.com https://maps.googleapis.com https://maps.gstatic.com https://www.youtube.com/ https://static.hotjar.com https://app.respond.io/ https://cdn.respond.io/ https://cdn.chatapi.net/ data: https://fonts.gstatic.com https://fonts.gstatic.com https://www.googletagmanager.com https://tagmanager.google.com https://ssl.gstatic.com https://www.gstatic.com https://static.hotjar.com https://cdn.chatapi.net/ https://content.hotjar.io/ wss://ws.hotjar.com/". Note that 'connect-src' was not explicitly set, so 'default-src' is used as a fallback.
Content Security Policy
Resource
https://www.googletagmanager.com/gtag/js?id=G-MMC6PC0B4T&l=dataLayer&cx=c&gtm=45He4bk0v9165867531za200
Description
Refused to connect to 'https://region1.google-analytics.com/g/collect?v=2&tid=G-MMC6PC0B4T&gtm=45je4bk0v9169742930z89165867531za200zb9165867531&_p=1732826898303&gcd=13l3l3l2l1l1&npa=1&dma_cps=syphamo&dma=1&tag_exp=101925629~102067555~102067808~102077855~102081485&cid=842751769.1732826900&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=noapi&_s=2&sid=1732826900&sct=1&seg=0&dl=https%3A%2F%2Fwww.freundferreteria.com%2F&dt=FERRETERIA%20FREUND%20EL%20SALVADOR&en=view_item_list&pr1=id48668180~nmESCALERA%20ART...%20CROMADO~brKWIKSET~pr220.99~k0currency~v0USD~c2Si~c374.01~c4false&pr6=id753874~nmBOTA%20TENIS%20INDUSTRIAL%20DIEL%C3%89CTRICO%20CON%20CUBO%20TALLA%2010%20NEGRO%2FBLANCO~brVAN%20VIEN~pr74~k0currency~v0USD~c2Si~c35~c4false&pr7=id758587~nmESCRITORIO%2073X80X40CM%20MELAMINA%20WENGUE%20PLEGABLE%20ALMYRA~brRTA%20DESIGN~pr49.99~k0currency~v0USD~c2Si~c319.96~c4false&pr8=id627282~nmBARBACOA%20CARBON%2042X50PLG%20CON%20REPISA%20LATERAL%20Y%20FRONTAL~brCHAR-GRILLER~pr199~k0currency~v0USD~c2Si~c365~c4false&tfd=9461' because it violates the document's Content Security Policy.
Content Security Policy
Resource
https://www.googletagmanager.com/gtag/js?id=G-5ZNENTXHSM&l=dataLayer&cx=c&gtm=45He4bk0v812524486za200
Description
Refused to connect to 'https://region1.analytics.google.com/g/collect?v=2&tid=G-5ZNENTXHSM&gtm=45je4bk0v9121799060z8812524486za200zb812524486&_p=1732826898303&gcd=13l3l3l2l1l1&npa=1&dma_cps=syphamo&dma=1&tag_exp=101925629~102067555~102067808~102077855~102081485&cid=842751769.1732826900&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=noapi&_eu=IA&_s=4&cu=USD&sid=1732826900&sct=1&seg=1&dl=https%3A%2F%2Fwww.freundferreteria.com%2F&dt=FERRETERIA%20FREUND%20EL%20SALVADOR&en=view_item_list&pr1=id48668180~nmES...STRIAL%20DIEL%C3%89CTRICO%20CON%20CUBO%20TALLA%2010%20NEGRO%2FBLANCO~brVAN%20VIEN~pr74~k0currency~v0USD~c2Si~c35~c4false&pr7=id758587~nmESCRITORIO%2073X80X40CM%20MELAMINA%20WENGUE%20PLEGABLE%20ALMYRA~brRTA%20DESIGN~pr49.99~k0currency~v0USD~c2Si~c319.96~c4false&pr8=id627282~nmBARBACOA%20CARBON%2042X50PLG%20CON%20REPISA%20LATERAL%20Y%20FRONTAL~brCHAR-GRILLER~pr199~k0currency~v0USD~c2Si~c365~c4false&ep.origin=ESTACION%2BDEL%2BCASCO&ep.item_list_name=Productos%20Destacados&ep.event_category=ecommerce&tfd=9476' because it violates the following Content Security Policy directive: "default-src 'unsafe-inline' 'self' https://analytics.google.com/ https://ws21.hotjar.com/ https://vc.hotjar.io/ wss://ws21.hotjar.com/api/v2/client/ws https://graph.facebook.com/ https://diffuser-cdn.app-us1.com https://conversations.app-us1.com https://prism.app-us1.com https://trackcmp.net https://wp-ui.app-us1.com https://script.hotjar.com https://vars.hotjar.com https://in.hotjar.com https://ws11.hotjar.com wss://ws11.hotjar.com https://www.googleadservices.com https://www.google.com https://www.google.ca https://www.google.com.sv https://www.facebook.com https://googleads.g.doubleclick.net https://s2.adform.net https://a2.adform.net https://f5desar.freundferreteria.com https://connect.facebook.net https://tracking.qa.paypal.com https://www.sandbox.paypal.com https://www.w3.org https://seal.networksolutions.com https://www.google.com https://www.gstatic.com https://tickets.bitworks.com.sv https://www.googletagmanager.com https://www.google-analytics.com https://stats.g.doubleclick.net https://www.paypal.com https://maps.googleapis.com https://maps.gstatic.com https://www.youtube.com/ https://static.hotjar.com https://app.respond.io/ https://cdn.respond.io/ https://cdn.chatapi.net/ data: https://fonts.gstatic.com https://fonts.gstatic.com https://www.googletagmanager.com https://tagmanager.google.com https://ssl.gstatic.com https://www.gstatic.com https://static.hotjar.com https://cdn.chatapi.net/ https://content.hotjar.io/ wss://ws.hotjar.com/". Note that 'connect-src' was not explicitly set, so 'default-src' is used as a fallback.
Content Security Policy
Resource
https://www.googletagmanager.com/gtag/js?id=G-5ZNENTXHSM&l=dataLayer&cx=c&gtm=45He4bk0v812524486za200
Description
Refused to connect to 'https://region1.analytics.google.com/g/collect?v=2&tid=G-5ZNENTXHSM&gtm=45je4bk0v9121799060z8812524486za200zb812524486&_p=1732826898303&gcd=13l3l3l2l1l1&npa=1&dma_cps=syphamo&dma=1&tag_exp=101925629~102067555~102067808~102077855~102081485&cid=842751769.1732826900&ul=en-us&sr=1x1&uaa=&uab=&uafvl=&uamb=0&uam=&uap=&uapv=&uaw=0&frm=0&pscdl=noapi&_eu=IA&_s=4&cu=USD&sid=1732826900&sct=1&seg=1&dl=https%3A%2F%2Fwww.freundferreteria.com%2F&dt=FERRETERIA%20FREUND%20EL%20SALVADOR&en=view_item_list&pr1=id48668180~nmES...STRIAL%20DIEL%C3%89CTRICO%20CON%20CUBO%20TALLA%2010%20NEGRO%2FBLANCO~brVAN%20VIEN~pr74~k0currency~v0USD~c2Si~c35~c4false&pr7=id758587~nmESCRITORIO%2073X80X40CM%20MELAMINA%20WENGUE%20PLEGABLE%20ALMYRA~brRTA%20DESIGN~pr49.99~k0currency~v0USD~c2Si~c319.96~c4false&pr8=id627282~nmBARBACOA%20CARBON%2042X50PLG%20CON%20REPISA%20LATERAL%20Y%20FRONTAL~brCHAR-GRILLER~pr199~k0currency~v0USD~c2Si~c365~c4false&ep.origin=ESTACION%2BDEL%2BCASCO&ep.item_list_name=Productos%20Destacados&ep.event_category=ecommerce&tfd=9476' because it violates the document's Content Security Policy.
Content Security Policy

Certificates · 12 found

SSL/TLS Certificates enable websites to encrypt transactions between the client and the server and provide server identity verification

SubjectIssue dateExpiry date
freundferreteria.comOct 8, 2024, 06:12:35Jan 6, 2025, 06:12:34
seal.networksolutions.comSep 18, 2024, 00:00:00Oct 19, 2025, 23:59:59
www.google.comOct 21, 2024, 08:38:45Jan 13, 2025, 08:38:44
upload.video.google.comOct 21, 2024, 08:38:00Jan 13, 2025, 08:37:59
*.respond.ioNov 6, 2024, 00:00:00Dec 4, 2025, 23:59:59
*.google-analytics.comOct 21, 2024, 08:36:57Jan 13, 2025, 08:36:56
*.gstatic.comOct 21, 2024, 08:37:59Jan 13, 2025, 08:37:58
*.facebook.comSep 7, 2024, 00:00:00Dec 6, 2024, 23:59:59
www.googleadservices.comOct 21, 2024, 08:38:19Jan 13, 2025, 08:38:18
*.g.doubleclick.netOct 21, 2024, 08:36:57Jan 13, 2025, 08:36:56