starclinch.com security report
Certificate, security headers, email authentication, DNS, registration, and exposed hosts — from public sources.
79risk
Critical
Exposed services or known CVEs need attention now.
1Critical
2High
4Medium
4Low
1Info
Collected 20.8sfrom cache
- Certificate Transparency36
- DNS resolution24
- Network ownership0
- CDN / WAF detection0
- Exposed ports & CVEs53
- Registration
- DNS posture2
- Email authentication2
- Certificate
- Security headers5
- Archived URLs
- Analysis12
- noteFound 36 hostnames; this runtime allows 50 outbound requests per scan, so the 21 most likely to matter were resolved.
- noteCertificate inspection is unavailable in this runtime.
- noteNetwork ownership lookup is unavailable in this runtime; ASN and org are omitted.
- noteCDN/WAF detection is unavailable in this runtime.
- note2 hosts were identified as CDN/edge infrastructure from ASN ownership rather than a cdncheck fingerprint.
final https://starclinch.com/status 200time 522msstack cloudflare
- ✓http:// redirects to https://
- ✓Strict-Transport-Securitymax-age=31536000; includeSubDomains, max-age=31536000; includeSubDomains; preload
- ✓Content-Security-Policyframe-ancestors 'self' https://list.starclinch.com http://localhost:3000
- ✓Clickjacking protectionDENY
- ✓X-Content-Type-Optionsnosniff, nosniff
- ✓Referrer-Policyno-referrer-when-downgrade
- –Permissions-Policyoptional
- –security.txt publishedoptional — tells researchers where to report bugs
- ✓Receives mail via 5 servers
- !SPFends in ~allv=spf1 include:sender.zoho-books.in include:_spf.google.com ~all
- ✓DMARCp=rejectv=DMARC1; p=reject; rua=mailto:v6hinsuj@ag.dmarcian-ap.com;
- !MTA-STSinbound mail can be downgraded to plaintext
- !DNSSECanswers can be forged
- ✓CAA0 issue "comodoca.com" · 0 issue "digicert.com; cansignhttpexchanges=yes" · 0 issue "letsencrypt.org" · 0 issue "pki.goog; cansignhttpexchanges=yes" · 0 issue "ssl.com" · 0 issuewild "comodoca.com" · 0 issuewild "digicert.com; cansignhttpexchanges=yes" · 0 issuewild "letsencrypt.org" · 0 issuewild "pki.goog; cansignhttpexchanges=yes" · 0 issuewild "ssl.com"
- ✓IPv6 (AAAA)
- ✓2 nameservers
- ✓Registered with GoDaddy.com, LLC11.7 years old
- ✓Registration expiry120 days2027-01-05
- ✓Transfer lockclient delete prohibited, client renew prohibited, client transfer prohibited, client update prohibited
- ✓2 nameservers at registry
| Address | Ports | CVEs | Edge | Network |
|---|---|---|---|---|
| 103.195.185.118 | 2122265380110143443+12 | 33 | direct | — |
| 172.67.145.235 starclinch.com +11 | 80443205220532082208320862087+5 | 0 | Cloudflare~ | — |
| 104.21.89.179 starclinch.com +11 | 80443205220532082208320862087+5 | 0 | Cloudflare~ | — |
| 34.47.241.113 | 8044315672 | 2 | direct | — |
| 151.101.65.195 url.starclinch.com +101 | 80443 | 0 | direct | — |
| 151.101.1.195 | 80443 | 0 | direct | — |
starclinch.comwww.starclinch.combeta.starclinch.comrms-dev.starclinch.comdev-cockpit.starclinch.comapi.starclinch.comex-api.starclinch.comrms-api.starclinch.comuser-api.starclinch.comdashboard.starclinch.com1.starclinch.comgo.starclinch.commy.starclinch.comapp.starclinch.comemi.starclinch.comrms.starclinch.comurl.starclinch.combook.starclinch.comform.starclinch.comnext.starclinch.comuser.starclinch.com
Archived URLs
Endpoints the Wayback Machine has kept — config files, backups, scripts. Slow to fetch, so it is here on request.