grass.io

.io toplist crawl

First seen 2026-04-11 · Last seen 2026-05-18 · ok HTTP/1.1 200 1231 ms crawled 2026-05-18

US · 104.18.13.205 · AS13335 Cloudflare, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
Get rewarded for the internet you don't use
Description
Grass turns the unused part of your internet into rewards. Just download the app, let it run in the background, and start earning.
Canonical
https://www.grass.io/

Open Graph

url
https://www.grass.io/
title
Get rewarded for the internet you don't use
site name
Get rewarded for the internet you don't use
description
Grass turns the unused part of your internet into rewards. Just download the app, let it run in the background, and start earning.

Technology

CDN
Amazon CloudFront
CMS
Next.js

Social

DNS records live

NS
  • graham.ns.cloudflare.com
  • tina.ns.cloudflare.com
TXT
  • google-site-verification=JErWi5aWAv1Ur9YjxP5qExTxioNsnxFT_eNV8p2wSgY

Email authentication no MX

SPF
v=spf1 include:_spf.google.com ~all
softfail (~all)
DMARC
v=DMARC1;p=quarantine;sp=quarantine;pct=100;rua=mailto:support@wynd.network;ruf=mailto:nikki@wynd.network;ri=86400;aspf=r;adkim=r;fo=1
policy: quarantine · sp=quarantine
DKIM
no key found at common selectors

Certificate (current)

WE1
from 2026-04-29 to 2026-07-28
Expires in 70 days

HTTP security headers

Header hygiene 65/100 Checked live page: https://www.grass.io/

present
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • missing HSTS
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
origin-when-cross-origin
x-frame-options
DENY
x-content-type-options
nosniff
content-security-policy
default-src 'self'; connect-src 'self' https://*.grass.io https://*.getgrass.io https://*.ghost.io https://*.clarity.ms https://*.google-analytics.com https://*.grassfoundation.io https://*.convertexperiments.com https://*.google.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://*.clarity.ms https://*.googletagmanager.com https://*.youtube.com https://*.convertexperiments.com https://*.google-analytics.com https://*.doubleclick.net https://*.facebook.net; style-src 'self' 'unsafe-inline' https://*.googletagmanager.com https://*.googleapis.com https://*.gstatic.com; img-src 'self' https://cdn.jsdelivr.net https://*.ghost.io https://*.medium.com https://*.googletagmanager.com https://*.google.com https://*.google.com.ph https://*.googleusercontent.com https://*.doubleclick.net https://*.google-analytics.com https://*.pagead2.googlesyndication.com https://*.facebook.com https://i.ytimg.com blob: data:; font-src 'self' https://*.gstatic.com https://*.googleap

Links to (8)

Linked from (1)