hogum
toneitup.com

toneitup.com security report

Certificate, security headers, email authentication, DNS, registration, and exposed hosts — from public sources.

36risk

Moderate

Some surface to tighten, nothing urgent.

0Critical
0High
4Medium
16Low
2Info
Collected 20.8sfrom cache
Domain
unavailable
  1. Certificate Transparency22
  2. DNS resolution31
  3. Network ownership0
  4. CDN / WAF detection0
  5. Exposed ports & CVEs40
  6. Registration
  7. DNS posture2
  8. Email authentication2
  9. Certificate
  10. Security headers4
  11. Archived URLs
  12. Analysis22
  • noteFound 22 hostnames; this runtime allows 50 outbound requests per scan, so the 21 most likely to matter were resolved.
  • noteFound 23 addresses; enriching the first 12.
  • noteCertificate inspection is unavailable in this runtime.
  • noteNetwork ownership lookup is unavailable in this runtime; ASN and org are omitted.
  • noteCDN/WAF detection is unavailable in this runtime.
  • noteRegistration did not complete (Too many subrequests by single Worker invocation. To configure this limit, refer to https://developers.cloudflare.com/workers/wrangler/configuration/#limits). Results below are partial.
  • note2 hosts were identified as CDN/edge infrastructure from ASN ownership rather than a cdncheck fingerprint.
final https://my.toneitup.com/status 200time 839msstack cloudflare
  • http:// redirects to https://port 80 did not answer
  • !Strict-Transport-Security
    max-age=7889238
  • Content-Security-Policy
    block-all-mixed-content; frame-ancestors 'none'; upgrade-insecure-requests;
  • Clickjacking protection
    DENY
  • X-Content-Type-Options
    nosniff
  • Referrer-Policy
  • Permissions-Policyoptional
  • security.txt publishedoptional — tells researchers where to report bugs
  • Cookie _shopify_y
    no Secure · no HttpOnly · SameSite=lax
  • Cookie _shopify_s
    no Secure · no HttpOnly · SameSite=lax
  • Cookie localization
    no Secure · no HttpOnly · SameSite=lax
  • Cookie cart_currency
    no Secure · no HttpOnly · SameSite=lax
  • Cookie _shopify_essential
    Secure · HttpOnly · SameSite=lax
  • Cookie _shopify_analytics
    Secure · HttpOnly · SameSite=lax
  • Cookie _shopify_marketing
    Secure · HttpOnly · SameSite=lax
AddressPortsCVEsEdgeNetwork
104.21.16.74
80443205220532082208320862087+5
0Cloudflare~
172.67.166.231
80443205220532082208320862087+5
0Cloudflare~
44.224.68.31
80443
0direct
18.162.234.233
80443
0direct
32.187.24.222
80443
0direct
63.34.141.205
80443
0direct
52.35.70.36
443
0direct
32.188.51.0
443
0direct
13.224.245.56
80
0direct
13.224.245.52
80
0direct
13.224.245.40
80
0direct
13.224.245.95
80
0direct
Archived URLs

Endpoints the Wayback Machine has kept — config files, backups, scripts. Slow to fetch, so it is here on request.