hogum
vehiclehistory.us

vehiclehistory.us security report

Certificate, security headers, email authentication, DNS, registration, and exposed hosts — from public sources.

44risk

Moderate

Some surface to tighten, nothing urgent.

0Critical
0High
13Medium
12Low
2Info
Collected 21.0sfrom cache
  1. Certificate Transparency3
  2. DNS resolution10
  3. Network ownership0
  4. CDN / WAF detection0
  5. Exposed ports & CVEs39
  6. Registration
  7. DNS posture4
  8. Email authentication2
  9. Certificate
  10. Security headers5
  11. Archived URLs
  12. Analysis27
  • noteCertificate inspection is unavailable in this runtime.
  • noteNetwork ownership lookup is unavailable in this runtime; ASN and org are omitted.
  • noteCDN/WAF detection is unavailable in this runtime.
  • noteNo registration data: RDAP has no record at this level.
  • note2 hosts were identified as CDN/edge infrastructure from ASN ownership rather than a cdncheck fingerprint.
final https://www.vehiclehistory.us/status 200time 2428msstack cloudflare
  • http:// redirects to https://
  • Strict-Transport-Security
    max-age=31536000; includeSubDomains; preload
  • Content-Security-Policy
  • Clickjacking protection
    DENY
  • X-Content-Type-Options
    nosniff
  • Referrer-Policy
    strict-origin-when-cross-origin
  • Permissions-Policy
    camera=(), microphone=(), geolocation=(), payment=(self)
  • security.txt publishedoptional — tells researchers where to report bugs
  • Cookie __sess_vhu
    Secure · HttpOnly · SameSite=lax
  • Cookie sessionId
    no Secure · no HttpOnly · no SameSite
  • Cookie initialUrl
    no Secure · no HttpOnly · no SameSite
  • Cookie variant
    no Secure · no HttpOnly · no SameSite
  • Cookie isHeads
    no Secure · no HttpOnly · no SameSite
  • Cookie isHeadsV2
    no Secure · no HttpOnly · no SameSite
  • Cookie sessionId
    no Secure · no HttpOnly · no SameSite
  • Cookie visitedPage
    no Secure · no HttpOnly · no SameSite
  • Cookie countdownVH
    no Secure · no HttpOnly · no SameSite
  • Cookie referenceId
    no Secure · no HttpOnly · no SameSite
  • Cookie referenceId
    no Secure · no HttpOnly · no SameSite
  • Cookie searchDateTime
    no Secure · no HttpOnly · no SameSite
  • Receives mail via 2 servers
  • !SPFends in ?all
    v=spf1 include:sendgrid.net include:emailsrvr.com include:_spf.google.com include:spf.mailjet.com ip4:66.96.128.0/18 ?all
  • DMARCp=quarantine
    v=DMARC1; p=quarantine; rua=mailto:re+b6dd9a42d348@inbound.dmarcdigests.com
  • !MTA-STSinbound mail can be downgraded to plaintext
AddressPortsCVEsEdgeNetwork
172.64.154.133
80443205220532082208320862087+5
0Cloudflare~
104.18.33.123
80443205220532082208320862087+5
0Cloudflare~
18.161.111.121
80443
0direct
18.161.111.4
80443
0direct
18.161.111.69
80443
0direct
18.161.111.49
80443
0direct
13.224.245.110
80443
0direct
13.224.245.44
80
0direct
13.224.245.30
80
0direct
13.224.245.26
80
0direct
Archived URLs

Endpoints the Wayback Machine has kept — config files, backups, scripts. Slow to fetch, so it is here on request.