mengotomars.com security report
Certificate, security headers, email authentication, DNS, registration, and exposed hosts — from public sources.
33risk
Moderate
Some surface to tighten, nothing urgent.
0Critical
0High
4Medium
8Low
1Info
Collected 3.3sfrom cache
- Certificate Transparency17
- DNS resolution50
- Network ownership0
- CDN / WAF detection0
- Exposed ports & CVEs35
- Registration
- DNS posture2
- Email authentication2
- Certificate
- Security headers4
- Archived URLs
- Analysis13
- noteFound 46 addresses; enriching the first 12.
- noteCertificate inspection is unavailable in this runtime.
- noteNetwork ownership lookup is unavailable in this runtime; ASN and org are omitted.
- noteCDN/WAF detection is unavailable in this runtime.
- note1 host was identified as CDN/edge infrastructure from ASN ownership rather than a cdncheck fingerprint.
final https://mengotomars.com/status 200time 285msstack cloudflare
- ✓http:// redirects to https://
- !Strict-Transport-Securitymax-age=7889238
- ✓Content-Security-Policyblock-all-mixed-content; frame-ancestors 'none'; upgrade-insecure-requests;
- ✓Clickjacking protectionDENY
- ✓X-Content-Type-Optionsnosniff
- ✗Referrer-Policy
- –Permissions-Policyoptional
- –security.txt publishedoptional — tells researchers where to report bugs
- ✗Cookie _shopify_yno Secure · no HttpOnly · SameSite=lax
- ✗Cookie _shopify_sno Secure · no HttpOnly · SameSite=lax
- ✗Cookie localizationno Secure · no HttpOnly · SameSite=lax
- ✗Cookie cart_currencyno Secure · no HttpOnly · SameSite=lax
- ✓Cookie _shopify_essentialSecure · HttpOnly · SameSite=lax
- ✓Cookie _shopify_analyticsSecure · HttpOnly · SameSite=lax
- ✓Cookie _shopify_marketingSecure · HttpOnly · SameSite=lax
- ✓Receives mail via 5 servers
- ✓SPFends in -allv=spf1 include:g2dk6rwfkv.spf.app.powerdeliverability.email -all
- ✓DMARCp=rejectv=DMARC1; p=reject; rua=mailto:9een4amwxj@rua.app.powerdeliverability.email; ruf=mailto:9een4amwxj@ruf.app.powerdeliverability.email; fo=1;
- ✓MTA-STSinbound mail must use TLS
- !DNSSECanswers can be forged
- –CAAany CA may issue
- –IPv6 (AAAA)IPv4 only
- ✓2 nameservers
- ✓Registered with GoDaddy.com, LLC3.6 years old
- ✓Registration expiry1615 days2031-02-07
- ✓Transfer lockclient delete prohibited, client renew prohibited, client transfer prohibited, client update prohibited
- ✓2 nameservers at registry
| Address | Ports | CVEs | Edge | Network |
|---|---|---|---|---|
| 23.227.38.32 | 80443205220532082208320862087+5 | 0 | Cloudflare~ | — |
| 23.227.153.18 | 804438443 | 0 | direct | — |
| 104.198.8.50 | 80443 | 0 | direct | — |
| 3.175.86.80 | 80443 | 0 | direct | — |
| 3.175.86.82 | 80443 | 0 | direct | — |
| 3.175.86.7 | 80443 | 0 | direct | — |
| 3.175.86.3 | 80443 | 0 | direct | — |
| 52.84.45.4 | 80443 | 0 | direct | — |
| 52.84.45.35 | 80443 | 0 | direct | — |
| 52.84.45.2 | 80443 | 0 | direct | — |
| 52.84.45.9 | 80443 | 0 | direct | — |
| 3.169.64.119 | 80 | 0 | direct | — |
mengotomars.comwww.mengotomars.comquiz-admin.mengotomars.comapi.automations.mengotomars.comsurvey-dashboard.automations.mengotomars.comi.mengotomars.comss.mengotomars.comtry.mengotomars.comquiz.mengotomars.comshop.mengotomars.comlpgen.mengotomars.commedia.mengotomars.comvoyage.mengotomars.commta-sts.mengotomars.comautomations.mengotomars.commetadata.automations.mengotomars.comlp-analyzer.automations.mengotomars.com
Archived URLs
Endpoints the Wayback Machine has kept — config files, backups, scripts. Slow to fetch, so it is here on request.