apiposture.com

.com crawl

First seen 2026-04-30 · Last seen 2026-05-08 · ok HTTP/1.1 200 788 ms crawled 2026-05-08

US · 188.114.97.3 · AS13335 Cloudflare, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
Scan your APIs in seconds - Find API misconfigurations in seconds.
Description
Scan APIs for authorization flaws and OWASP API risks with ApiPosture. Fast CLI security scanner for .NET, Python, Node, Go, Java, and PHP APIs.
Language
en
Generator
Umbraco CMS
Canonical
https://www.apiposture.com/
Translations
  • en

Open Graph

url
https://www.apiposture.com/
title
Scan your APIs in seconds - Find API misconfigurations in seconds.
locale
en_US
site name
ApiPosture
description
Scan APIs for authorization flaws and OWASP API risks with ApiPosture. Fast CLI security scanner for .NET, Python, Node, Go, Java, and PHP APIs.

Technology

CDN
Cloudflare
Analytics
  • Google Tag Manager
Fonts
  • Google Fonts

Third-party hosts loaded (3)

  • fonts.googleapis.com×1
  • fonts.gstatic.com×1
  • www.googletagmanager.com×1

Registration

Registrar
Cloudflare, Inc.
Created
2026-01-18
Expires
2027-01-18 243 days left
Updated
2026-01-18
Name servers
  • anirban.ns.cloudflare.com
  • kira.ns.cloudflare.com

DNS records live

NS
  • anirban.ns.cloudflare.com
  • kira.ns.cloudflare.com
MX
  • 20 mail.apiposture.com
TXT
  • google-site-verification=FHz-UU1Nchb_CuHPbyJwdM7t0IJpzT-osaUOEt1HMtw

Email authentication strong

SPF
v=spf1 a mx ip4:188.114.96.3 ip4:188.114.97.3 -all
strict (-all)
DMARC
v=DMARC1; p=quarantine; pct=100; adkim=s; aspf=s; rua=mailto:webmaster@apiposture.com; ruf=mailto:webmaster@apiposture.com; fo=1
policy: quarantine
DKIM
no key found at common selectors

Certificate (current)

WE1
from 2026-03-18 to 2026-06-16
Expires in 28 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.apiposture.com/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • short HSTS max-age
  • CSP allows unsafe inline scripts/styles
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SameOrigin
permissions-policy
camera=(), microphone=(), geolocation=(), payment=(), usb=()
x-content-type-options
nosniff
content-security-policy
default-src 'self';script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.googletagmanager.com https://static.cloudflareinsights.com;style-src 'self' 'unsafe-inline' https://fonts.googleapis.com;img-src 'self' data: https://www.google-analytics.com https://www.googletagmanager.com;font-src 'self' https://fonts.gstatic.com;connect-src 'self' https://www.google-analytics.com https://analytics.google.com https://www.googletagmanager.com https://cloudflareinsights.com
strict-transport-security
max-age=0

Links to (1)

Linked from (1)