hogum
qa-profile.stripe.com

qa-profile.stripe.com security report

Certificate, security headers, email authentication, DNS, registration, and exposed hosts — from public sources.

63risk

Elevated

Several issues worth triaging this week.

0Critical
2High
3Medium
3Low
1Info
Collected 2.5sfrom cache
  1. Certificate Transparency1
  2. DNS resolution0
  3. Network ownership
  4. CDN / WAF detection
  5. Exposed ports & CVEs
  6. Registration
  7. DNS posture0
  8. Email authentication0
  9. Certificate
  10. Security headers2
  11. Archived URLs
  12. Analysis9
  • noteCertificate inspection is unavailable in this runtime.
final https://qa-profile.stripe.com/status 530time 27msstack cloudflare
  • http:// redirects to https://
  • Strict-Transport-Security
  • Content-Security-Policy
  • Clickjacking protection
    SAMEORIGIN
  • X-Content-Type-Options
  • Referrer-Policy
    same-origin
  • Permissions-Policyoptional
  • security.txt publishedoptional — tells researchers where to report bugs
  • No MX records — domain does not receive mail
  • SPF
    no record
  • DMARC
    no record
  • MTA-STSn/a
  • !DNSSECanswers can be forged
  • CAAany CA may issue
  • IPv6 (AAAA)IPv4 only
  • 0 nameservers
Archived URLs

Endpoints the Wayback Machine has kept — config files, backups, scripts. Slow to fetch, so it is here on request.