boboli.com Review

TitletagDescriptiontaglanguage
what's on the menu? | Boboli English
Alexarank
394746
Ip adress44.239.21.168Nameserverns11.constellix.com
ns21.constellix.com
ns31.constellix.com
ns41.constellix.net
ns51.constellix.net
ns61.constellix.net
Status code200
robots.txt
 N/A
HTTP/1.1 301 Moved Permanently
Date: Sat, 07 Dec 2024 04:47:28 GMT
Content-Type: text/html; charset=iso-8859-1
Content-Length: 227
Connection: keep-alive
Server: Apache
Strict-Transport-Security: max-age=15552000
Location: https://boboli.com/

HTTP/1.1 200 OK
Date: Sat, 07 Dec 2024 04:47:30 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Server: Apache
Cache-Control: must-revalidate, no-cache, private
X-Drupal-Dynamic-Cache: UNCACHEABLE
X-UA-Compatible: IE=edge
Content-language: en
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
Expires: Sun, 19 Nov 1978 05:00:00 GMT
X-Generator: Drupal 9 (https://www.drupal.org)
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-eval' 'unsafe-inline' *.cloudflare.com *.consumercare.net *.cookielaw.org *.crazyegg.com *.facebook.net *.force.com *.formstack.com *.mousestats.com *.pinimg.com *.salesforce.com *.salesforceliveagent.com assets.juicer.io bbusf.my.site.com cdn.jsdelivr.net maps.googleapis.com sc-static.net unpkg.com www.google-analytics.com www.google.com www.googletagmanager.com www.gstatic.com; style-src 'self' 'unsafe-inline' *.bootstrapcdn.com *.cloudflare.com *.force.com *.formstack.com *.googleapis.com *.gstatic.com *.salesforce.com assets.juicer.io bbusf.my.site.com cdn.jsdelivr.net unpkg.com; img-src 'self' *.adnxs.com *.cdninstagram.com *.cookielaw.org *.doubleclick.net *.facebook.com *.facebook.net *.formstack.com *.google.be *.google.bf *.google.bs *.google.ca *.google.ch *.google.cl *.google.co.il *.google.co.in *.google.co.ma *.google.co.nz *.google.co.th *.google.co.uk *.google.co.ve *.google.co.za *.google.co.zm *.google.com.ar *.google.com.au *.google.com.bd *.google.com.br *.google.com.cy *.google.com.do *.google.com.eg *.google.com.jm *.google.com.mx *.google.com.my *.google.com.ng *.google.com.ph *.google.com.pk *.google.com.pr *.google.com.sg *.google.com.tr *.google.de *.google.dz *.google.es *.google.fr *.google.hr *.google.hu *.google.ie *.google.lt *.google.mk *.google.nl *.google.ro *.google.si *.google.tn *.google.tt *.googleapis.com *.googletagmanager.com *.gstatic.com *.juicer.io *.unsplash.com cdn.jsdelivr.net cscoreproweustor.blob.core.windows.net data: translate.google.com www.google-analytics.com www.google.com; frame-src 'self' *.doubleclick.net *.facebook.com *.force.com *.googletagmanager.com *.salesforce.com *.salesforceliveagent.com bbusf.my.site.com www.google.com www.youtube.com; frame-ancestors 'self'; font-src 'self' *.alicdn.com *.cdnfonts.com *.formstack.com *.simplycodes.com *.slant.co *.tql.com *.typekit.net *.zip.co assets.merci-app.com bbusf.my.site.com data: fonts.gstatic.com maxcdn.bootstrapcdn.com sc-static.net static.juicer.io; connect-src 'self' *.bootstrapcdn.com *.channelsight.com *.clean.gg *.cookielaw.org *.doubleclick.net *.facebook.com *.fonts.net *.force.com *.google-analytics.com *.google.be *.google.bf *.google.ca *.google.ch *.google.co.il *.google.co.ma *.google.co.nz *.google.co.ve *.google.co.zm *.google.com *.google.com.au *.google.com.bd *.google.com.cy *.google.com.eg *.google.com.pr *.google.com.sg *.google.dz *.google.fr *.google.hr *.google.hu *.google.ie *.google.lt *.google.mk *.google.ro *.google.si *.google.tn *.googleapis.com *.googletagmanager.com *.juicer.io *.onetrust.com *.onetrust.io *.pricespider.com *.salesforce.com *.salesforceliveagent.com *.unpkg.com bbusf.my.site.com cdnjs.cloudflare.com cloud.typography.com streaming.split.io unpkg.com; report-uri https://gbnareports.report-uri.com/r/t/csp/enforce; upgrade-insecure-requests
Strict-Transport-Security: max-age=15552000
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Content-Security-Policy: default-src 'self' 'self' data: 'self' blob: 'unsafe-inline' 'unsafe-eval' *; img-src 'self' blob: data: *
X-Content-Security-Policy: default-src 'self' 'self' data: 'self' blob: 'unsafe-inline' 'unsafe-eval' *; img-src 'self' blob: data: *
Cache-Control: no-store
Pragma: no-cache

iframe