SSL Report:
www.lematelas.fr
(192.124.249.89)
Assessed on: Mon, 22 Dec 2025 10:08:12 UTC
| Clear cache
Summary
0
20
40
60
80
100
Certificate
Protocol Support
Key Exchange
Cipher Strength
Visit our documentation page
for more information, configuration guides, and books. Known issues are documented
here.
Server sent invalid/disabled HSTS policy. See below for further information. MORE INFO »
This site works only in browsers with SNI support.
This server supports TLS 1.3. MORE INFO »
Certificate #1: RSA 2048 bits (SHA256withRSA)
|
Server Key and Certificate #1
|
|
| Subject |
www.lematelas.fr
Fingerprint SHA256: 9d377e16c2b9ebf22f6e9cad6e4c44a033fdebe87ee741423f8216c6ad9287a9 Pin SHA256: 474z0vMJtUYf/AgzxooVnuQxBZHFFWiLiDUfFVR2AcY= |
| Common names | www.lematelas.fr |
| Alternative names | lematelas.fr www.lematelas.fr |
| Serial Number | 05ebc6b51da94f2d160e2365a5e69a1c1458 |
| Valid from | Mon, 01 Dec 2025 00:46:04 UTC |
| Valid until | Sun, 01 Mar 2026 00:46:03 UTC (expires in 2 months and 6 days) |
| Key | RSA 2048 bits (e 65537) |
| Weak key (Debian) | No |
| Issuer | R12
AIA: http://r12.i.lencr.org/ |
| Signature algorithm | SHA256withRSA |
| Extended Validation | No |
| Certificate Transparency | Yes (certificate) |
| OCSP Must Staple | No |
| Revocation information |
CRL CRL: http://r12.c.lencr.org/89.crl |
| Revocation status | Validation error
CRL ERROR: IOException occurred |
| DNS CAA | No (more info) |
| Trusted | Yes
Mozilla Apple Android Java Windows |
|
|
Certificate #2: RSA 2048 bits (SHA256withRSA)
No SNI
|
|
Configuration
| Protocols | |
| TLS 1.3 | Yes |
| TLS 1.2 | Yes* |
| TLS 1.1 | No |
| TLS 1.0 | No |
| SSL 3 | No |
| SSL 2 | No |
| (*) Experimental: Server negotiated using No-SNI | |
| Cipher Suites | ||
|
# TLS 1.3 (suites in server-preferred order)
|
||
TLS_AES_256_GCM_SHA384 (0x1302)
ECDH x25519 (eq. 3072 bits RSA) FS
|
256 | |
TLS_CHACHA20_POLY1305_SHA256 (0x1303)
ECDH x25519 (eq. 3072 bits RSA) FS
|
256 | |
TLS_AES_128_GCM_SHA256 (0x1301)
ECDH x25519 (eq. 3072 bits RSA) FS
|
128 | |
|
# TLS 1.2 (suites in server-preferred order)
|
||
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (0xcca8)
ECDH x25519 (eq. 3072 bits RSA) FS
|
256 | |
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xc02f)
ECDH x25519 (eq. 3072 bits RSA) FS
|
128 | |
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 (0xc027)
ECDH x25519 (eq. 3072 bits RSA) FS
WEAK
|
128 | |
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013)
ECDH x25519 (eq. 3072 bits RSA) FS
WEAK
|
128 | |
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xc030)
ECDH x25519 (eq. 3072 bits RSA) FS
|
256 | |
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (0xc028)
ECDH x25519 (eq. 3072 bits RSA) FS
WEAK
|
256 | |
TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384 (0xc077)
ECDH x25519 (eq. 3072 bits RSA) FS
WEAK
|
256 | |
TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256 (0xc076)
ECDH x25519 (eq. 3072 bits RSA) FS
WEAK
|
128 | |
TLS_ECDHE_RSA_WITH_ARIA_256_GCM_SHA384 (0xc061)
ECDH x25519 (eq. 3072 bits RSA) FS
|
256 | |
TLS_ECDHE_RSA_WITH_ARIA_128_GCM_SHA256 (0xc060)
ECDH x25519 (eq. 3072 bits RSA) FS
|
128 | |
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xc014)
ECDH x25519 (eq. 3072 bits RSA) FS
WEAK
|
256 | |
TLS_RSA_WITH_AES_128_CBC_SHA (0x2f)
WEAK
|
128 | |
TLS_RSA_WITH_AES_256_CBC_SHA (0x35)
WEAK
|
256 | |
| Handshake Simulation | |||
| Android 4.4.2 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Android 5.0.0 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Android 6.0 | RSA 2048 (SHA256) | TLS 1.2 > http/1.1 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Android 7.0 | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ECDH x25519 FS |
| Android 8.0 | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ECDH x25519 FS |
| Android 8.1 | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
| Android 9.0 | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
| BingPreview Jan 2015 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Chrome 49 / XP SP3 | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ECDH secp256r1 FS |
| Chrome 69 / Win 7 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ECDH x25519 FS |
| Chrome 70 / Win 10 | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
| Chrome 80 / Win 10 R | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
| Firefox 31.3.0 ESR / Win 7 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Firefox 47 / Win 7 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ECDH secp256r1 FS |
| Firefox 49 / XP SP3 | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ECDH secp256r1 FS |
| Firefox 62 / Win 7 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ECDH x25519 FS |
| Firefox 73 / Win 10 R | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
| Googlebot Feb 2018 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ECDH x25519 FS |
| IE 11 / Win 7 R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDH secp256r1 FS |
| IE 11 / Win 8.1 R | RSA 2048 (SHA256) | TLS 1.2 > http/1.1 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDH secp256r1 FS |
| IE 11 / Win Phone 8.1 R | RSA 2048 (SHA256) | TLS 1.2 > http/1.1 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDH secp256r1 FS |
| IE 11 / Win Phone 8.1 Update R | RSA 2048 (SHA256) | TLS 1.2 > http/1.1 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDH secp256r1 FS |
| IE 11 / Win 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Edge 15 / Win 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Edge 16 / Win 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Edge 18 / Win 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Edge 13 / Win Phone 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Java 8u161 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Java 11.0.3 | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH secp256r1 FS |
| Java 12.0.1 | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH secp256r1 FS |
| OpenSSL 1.0.1l R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| OpenSSL 1.0.2s R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| OpenSSL 1.1.0k R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ECDH x25519 FS |
| OpenSSL 1.1.1c R | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
| Safari 6 / iOS 6.0.1 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDH secp256r1 FS |
| Safari 7 / iOS 7.1 R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDH secp256r1 FS |
| Safari 7 / OS X 10.9 R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDH secp256r1 FS |
| Safari 8 / iOS 8.4 R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDH secp256r1 FS |
| Safari 8 / OS X 10.10 R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDH secp256r1 FS |
| Safari 9 / iOS 9 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Safari 9 / OS X 10.11 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Safari 10 / iOS 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Safari 10 / OS X 10.12 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Safari 12.1.2 / MacOS 10.14.6 Beta R | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
| Safari 12.1.1 / iOS 12.3.1 R | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
| Apple ATS 9 / iOS 9 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Yahoo Slurp Jan 2015 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| YandexBot Jan 2015 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
|
# Not simulated clients (Protocol mismatch)
|
|||
| Android 2.3.7 No SNI 2 |
Protocol mismatch (not simulated) |
||
| Android 4.0.4 |
Protocol mismatch (not simulated) |
||
| Android 4.1.1 |
Protocol mismatch (not simulated) |
||
| Android 4.2.2 |
Protocol mismatch (not simulated) |
||
| Android 4.3 |
Protocol mismatch (not simulated) |
||
| Baidu Jan 2015 |
Protocol mismatch (not simulated) |
||
| IE 6 / XP No FS 1 No SNI 2 |
Protocol mismatch (not simulated) |
||
| IE 7 / Vista |
Protocol mismatch (not simulated) |
||
| IE 8 / XP No FS 1 No SNI 2 |
Protocol mismatch (not simulated) |
||
| IE 8-10 / Win 7 R |
Protocol mismatch (not simulated) |
||
| IE 10 / Win Phone 8.0 |
Protocol mismatch (not simulated) |
||
| Java 6u45 No SNI 2 |
Protocol mismatch (not simulated) |
||
| Java 7u25 |
Protocol mismatch (not simulated) |
||
| OpenSSL 0.9.8y |
Protocol mismatch (not simulated) |
||
| Safari 5.1.9 / OS X 10.6.8 |
Protocol mismatch (not simulated) |
||
| Safari 6.0.4 / OS X 10.8.4 R |
Protocol mismatch (not simulated) |
||
| (1) Clients that do not support Forward Secrecy (FS) are excluded when determining support for it. | |||
| (2) No support for virtual SSL hosting (SNI). Connects to the default site if the server uses SNI. | |||
| (3) Only first connection attempt simulated. Browsers sometimes retry with a lower protocol version. | |||
| (R) Denotes a reference browser or client, with which we expect better effective security. | |||
| (All) We use defaults, but some platforms do not use their best protocols and features (e.g., Java 6 & 7, older IE). | |||
| (All) Certificate trust is not checked in handshake simulation, we only perform TLS handshake. | |||
| Protocol Details | |
| Secure Renegotiation | Supported |
| Secure Client-Initiated Renegotiation | No |
| Insecure Client-Initiated Renegotiation | No |
| BEAST attack | Mitigated server-side (more info) |
| POODLE (SSLv3) | No, SSL 3 not supported (more info) |
| POODLE (TLS) | No (more info) |
| Zombie POODLE | No (more info)
TLS 1.2 : 0xc027
|
| GOLDENDOODLE | No (more info)
TLS 1.2 : 0xc027
|
| OpenSSL 0-Length | No (more info)
TLS 1.2 : 0xc027
|
| Sleeping POODLE | No (more info)
TLS 1.2 : 0xc027
|
| Downgrade attack prevention | Yes, TLS_FALLBACK_SCSV supported (more info) |
| SSL/TLS compression | No |
| RC4 | No |
| Heartbeat (extension) | No |
| Heartbleed (vulnerability) | No (more info) |
| Ticketbleed (vulnerability) | No (more info) |
| OpenSSL CCS vuln. (CVE-2014-0224) | No (more info) |
| OpenSSL Padding Oracle vuln. (CVE-2016-2107) |
No (more info) |
| ROBOT (vulnerability) | No (more info) |
| Forward Secrecy | Yes (with most browsers) ROBUST (more info) |
| ALPN | Yes h2 http/1.1 |
| NPN | No |
| Session resumption (caching) | Yes |
| Session resumption (tickets) | Yes |
| OCSP stapling | No |
| Strict Transport Security (HSTS) | Invalid
Server provided more than one HSTS header
|
| HSTS Preloading | Chrome Edge Firefox IE |
| Public Key Pinning (HPKP) | No (more info) |
| Public Key Pinning Report-Only | No |
| Public Key Pinning (Static) | No (more info) |
| Long handshake intolerance | No |
| TLS extension intolerance | No |
| TLS version intolerance | No |
| Incorrect SNI alerts | No |
| Uses common DH primes | No, DHE suites not supported |
| DH public server param (Ys) reuse | No, DHE suites not supported |
| ECDH public server param reuse | No |
| Supported Named Groups | x25519, secp256r1, x448, secp521r1, secp384r1 (server preferred order) |
| SSL 2 handshake compatibility | Yes |
| 0-RTT enabled | No |
|
|
|
1 https://www.lematelas.fr/
(HTTP/1.1 200 OK)
| 1 | |
| Date | Mon, 22 Dec 2025 10:07:56 GMT | |
| Content-Type | text/html; charset=UTF-8 | |
| Content-Length | 1004137 | |
| Connection | close | |
| X-Sucuri-ID | 11039 | |
| X-XSS-Protection | 1; mode=block | |
| X-Frame-Options | SAMEORIGIN | |
| X-Content-Type-Options | nosniff | |
| Strict-Transport-Security | max-age=31536000; includeSubdomains; preload | |
| Content-Security-Policy | upgrade-insecure-requests; | |
| Vary | Accept-Encoding | |
| x-built-with | Hyva Themes | |
| Report-To | {"group":"report-endpoint","max_age":10886400,"endpoints":[{"url":"\/csp_reporter.php"}]} | |
| Content-Security-Policy | font-src fonts.gstatic.com use.typekit.net *.typekit.net *.gstatic.com *.fontawesome.com https://static.payzen.eu/static/ https://*.oney.io https://fonts.gstatic.com *.iadvize.com fonts.googleapis.com *.hotjar.com *.zopim.com data: www.lematelas.fr www.lematelas-hotellerie.com old.someo-literie.com www.someo-literie.com data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.paypal.com https://secure.payzen.eu/vads-payment/ https://api.payzen.eu/api-payment/ https://static.payzen.eu/static/ www.facebook.com secure.payzen.eu *.facebook.com ct.pinterest.com www.lematelas-hotellerie.com www.lematelas.fr old.someo-literie.com www.someo-literie.com 'self' 'unsafe-inline'; frame-ancestors www.lematelas-hotellerie.com tmp.someo-literie.com www.someo-literie.com www.lematelas.fr old.someo-literie.com 'self'; frame-src bid.g.doubleclick.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com *.braintreegateway.com *.paypal.com google.com *.google.com https://secure.payzen.eu/vads-payment/ https://static.payzen.eu/static/ www.facebook.com secure.payzen.eu preprod.lm.octopuce.fr www.lematelas.fr www.youtube-nocookie.com play.google.com *.meubles.fr https://serv.lematelas.fr *.trustpilot.com cdn.dnky.co *.hotjar.com *.facebook.com *.criteo.com js.mollie.com www.instagram.com tpc.googlesyndication.com www.googletagmanager.com td.doubleclick.net ubishaker.com hud.crazyegg.com ct.pinterest.com www.powr.io serv3.someo-literie.com vcdn.powr.io applepay.cdn-apple.com www.lematelas-hotellerie.com old.someo-literie.com www.someo-literie.com 'self' 'unsafe-inline'; img-src widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.vimeocdn.com i.ytimg.com *.youtube.com p.typekit.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com validator.swagger.io *.paypal.com *.typekit.net *.gstatic.com https://images.unsplash.com *.facebook.com *.googleapis.com https://secure.payzen.eu/static/latest/images/type-carte/ https://static.payzen.eu/static/ https://secure.payzen.eu/vads-payment/ https://*.oney.io https://www.google.com https://www.google.fr https://serv.lematelas.fr https://maps.gstatic.com https://maps.googleapis.com https://www.lematelas.fr/ https://www.lematelas-hotellerie.com/ *.trustpilot.net/ https://c.clarity.ms/ https://c.bing.com https://bat.bing.com https://googleads.g.doubleclick.net https://axeptio.imgix.net *.kelkoogroup.net *.linksynergy.com *.nxtck.com *.xg4ken.com *.leadsrx.com *.zdassets.com *.zendesk.com *.affilae.com *.iadvize.com *.pinterest.com ebizmarts-website.s3.amazonaws.com downloads.mailchimp.com gallery.mailchimp.com *.google.com *.google.nl connect.onlinesucces.nl px.ads.linkedin.com stats.g.doubleclick.net *.linkedin.com *.googletagmanager.com amcglobal.sc.omtrdc.net cm.everesttech.net *.trustedshops.com *.zopim.com cdn.jsdelivr.net *.jmango360.com *.datatrics.com *.smaato.net https://www.mollie.com serv.lematelas-hotellerie.com www.google.ro www.google.be www.google.ch connect.facebook.net www.google.dk www.google.bg www.google.com.hk www.google.at www.google.dz www.google.de www.google.ca www.google.es www.google.mg www.google.co.ma www.google.co.uk www.google.lu www.google.tn www.google.it blob cart2quote.zendesk.com www.magentocommerce.com serv.lematelas.fr mcusercontent.com pagead2.googlesyndication.com feed.amasty.net www.cart2quote.com www.lematelas.fr v2assets.zopim.io ssl.google-analytics.com widget.trustpilot.com ftrk.crazyegg.com hud.crazyegg.com www.mageworx.com favicons.axept.io ct.pinterest.com pos.baidu.com lematelas.zendesk.com www.1001bebes.com serv2.lematelas-hotellerie.com admin.lematelas.frc admin.lematelas.fr region1.google-analytics.com serv3.someo-literie.com bat.bing.net www.lematelas-hotellerie.com old.someo-literie.com www.someo-literie.com data: 'self' 'unsafe-inline'; script-src www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com *.commerce-payment-services.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ assets.adobedtm.com amcglobal.sc.omtrdc.net *.magento-ds.com use.typekit.net www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com *.typekit.net google.com *.google.com *.cdn-apple.com https://maps.googleapis.com *.googletagmanager.com *.facebook.net maps.googleapis.com https://api.payzen.eu/api-payment/ https://static.payzen.eu/static/ https://*.oney.io https://serv.lematelas.fr *.trustpilot.com https://www.google.com *.doubleclick.net *.zdassets.com data: https://bat.bing.com https://www.clarity.ms https://s.kk-resources.com https://www.youtube.com *.meubles.fr *.axept.io *.abtasty.com *.linksynergy.com *.nxtck.com *.xg4ken.com *.leadsrx.com *.zendesk.com *.affilae.com *.iadvize.com *.pinterest.com chimpstatic.com downloads.mailchimp.com *.list-manage.com *.paypal.com *.gstatic.com *.googleapis.com *.googleadservices.com cdn.dnky.co api.comapi.com *.trackedlink.net snap.licdn.com checkout.buckaroo.nl *.adyen.com *.zopim.com *.hotjar.com *.sendcloud.sc *.mailchimp.com *.trustedshops.com *.fontawesome.com *.feedbackcompany.com *.google-analytics.com cdn.jsdelivr.net *.googleoptimize.com *.clarity.ms *.datatrics.com *.criteo.net *.criteo.com cdn.mouseflow.com serv3.someo-literie.com js.mollie.com www.instagram.com tpc.googlesyndication.com bat.bing.com static.zdassets.com static.axept.io widget.trustpilot.com www.google.com script.crazyegg.com snippet.maze.co www.lematelas-hotellerie.com inline admin.lematelas.fr s.pinimg.com www.powr.io ct.pinterest.com pagead2.googlesyndication.com assets.oney.io applepay.cdn-apple.com genii-script.tolk.ai www.lematelas.fr old.someo-literie.com www.someo-literie.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src fonts.googleapis.com *.fontawesome.com *.gstatic.com *.googleapis.com https://static.payzen.eu/static/ https://fonts.googleapis.com https://www.googletagmanager.com *.trustpilot.com downloads.mailchimp.com cdn.dnky.co checkout.buckaroo.nl *.mailchimp.com cdn.jsdelivr.net hud.crazyegg.com genii-script.tolk.ai www.lematelas.fr www.lematelas-hotellerie.com old.someo-literie.com www.someo-literie.com 'self' 'unsafe-inline'; object-src www.lematelas.fr www.lematelas-hotellerie.com old.someo-literie.com www.someo-literie.com 'self' 'unsafe-inline'; media-src *.zdassets.com *.zopim.com blob www.lematelas.fr www.lematelas-hotellerie.com old.someo-literie.com www.someo-literie.com 'self' 'unsafe-inline'; manifest-src www.lematelas.fr www.lematelas-hotellerie.com old.someo-literie.com www.someo-literie.com 'self' 'unsafe-inline'; connect-src *.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.adobe.io performance.typekit.net *.sentry.io www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com *.paypal.com google.com *.google.com https://maps.googleapis.com https://player.vimeo.com maps.googleapis.com https://secure.payzen.eu/vads-payment/ https://api.payzen.eu/api-payment/ https://*.oney.io wss://widget-mediator.zopim.com *.zdassets.com *.zendesk.com wss://*.zendesk.com *.doubleclick.net https://serv.lematelas.fr https://serv.lematelas-hotellerie.com *.trustpilot.com https://sentry.io *.clarity.ms https://www.facebook.com *.google.fr www.google-analytics.com *.kelkoogroup.net *.axept.io *.imgix.net *.linksynergy.com *.nxtck.com *.xg4ken.com *.leadsrx.com *.meubles.fr *.pinterest.com *.affilae.com commerce.adobedc.net api.comapi.com stats.g.doubleclick.net *.hotjar.com *.hotjar.io *.zopim.com wss://*.zopim.com dpm.demdex.net *.feedbackcompany.com amcglobal.sc.omtrdc.net *.facebook.com *.datatrics.com bat.bing.com serv.lematelas.fr serv.lematelas-hotellerie.com www.google.ch www.google.be www.google.at www.google.dz bitbucket.org script.crazyegg.com tracking.crazyegg.com pagestates-tracking.crazyegg.com assets-tracking.crazyegg.com hud.crazyegg.com app.crazyegg.com prompts.maze.co serv2.lematelas-hotellerie.com ct.pinterest.com region1.analytics.google.com vcdn.powr.io pagead2.googlesyndication.com www.facebook.com serv3.someo-literie.com lematelas.fr zendesk-eu.my.sentry.io www.powr.io api.crazyegg.com genii-messages.tolk.ai connect.facebook.net genii-script.tolk.ai bat.bing.net www.lematelas.fr www.lematelas-hotellerie.com old.someo-literie.com www.someo-literie.com 'self' 'unsafe-inline'; child-src www.lematelas.fr www.lematelas-hotellerie.com old.someo-literie.com www.someo-literie.com http: https: blob: 'self' 'unsafe-inline'; default-src https://secure.payzen.eu/vads-payment/ https://api.payzen.eu/api-payment/ https://static.payzen.eu/static/ *.abtasty.com www.lematelas.fr www.lematelas-hotellerie.com old.someo-literie.com www.someo-literie.com 'self' 'unsafe-inline' 'unsafe-eval'; base-uri www.lematelas.fr www.lematelas-hotellerie.com old.someo-literie.com www.someo-literie.com 'self' 'unsafe-inline'; report-uri /csp_reporter.php; | |
| X-Content-Type-Options | nosniff | |
| X-XSS-Protection | 1; mode=block | |
| X-Frame-Options | SAMEORIGIN | |
| Age | 16571 | |
| Accept-Ranges | bytes | |
| Pragma | no-cache | |
| Expires | -1 | |
| Cache-Control | no-store, no-cache, must-revalidate, max-age=0 | |
| Strict-Transport-Security | max-age=15552000 | |
| Server | Sucuri/Cloudproxy | |
| X-Sucuri-Cache | MISS | |
| Alt-Svc | h3=":443"; ma=2592000, h3-29=":443"; ma=2592000 | |
| Miscellaneous | |
| Test date | Mon, 22 Dec 2025 10:07:06 UTC |
| Test duration | 66.28 seconds |
| HTTP status code | 200 |
| HTTP server signature | Sucuri/Cloudproxy |
| Server hostname | cloudproxy10089.sucuri.net |
SSL Report v2.4.1
