hcpcacao.org

.org crawl

First seen 2026-04-18 · Last seen 2026-05-16 · ok HTTP/1.1 200 7191 ms crawled 2026-05-12

US · 216.150.1.1 · AS16509 Amazon.com, Inc.

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Heirloom Cacao Preservation Fund — Protecting Rare Cacao
Description
The HCP Fund identifies, preserves, and celebrates the world's finest heirloom cacao varieties and the farming communities behind them.
Language
en
Canonical
https://www.hcpcacao.org/en

Open Graph

url
https://www.hcpcacao.org/en
title
Heirloom Cacao Preservation Fund — Protecting Rare Cacao
locale
en_US
site name
Heirloom Cacao Preservation Fund
description
The HCP Fund identifies, preserves, and celebrates the world's finest heirloom cacao varieties and the farming communities behind them.

Technology

CDN
Vercel
CMS
Next.js

Third-party hosts loaded (2)

  • images.prismic.io×10
  • pro-hcp.prismic.io×1

Contact

Email

Registration

Registrar
NameCheap, Inc.
Created
2013-09-22
Expires
2026-09-22 124 days left
Updated
2025-08-28
Name servers
  • dns1.registrar-servers.com
  • dns2.registrar-servers.com

DNS records live

NS
  • dns1.registrar-servers.com
  • dns2.registrar-servers.com
MX
  • 1 aspmx.l.google.com
  • 10 aspmx2.googlemail.com
  • 10 aspmx3.googlemail.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
Verified for
  • Google

Email authentication weak

SPF
v=spf1 +a +mx +include:_spf.google.com -all
strict (-all)
DMARC
not published
DKIM
no key found at common selectors

Certificate (current)

R13
from 2026-04-17 to 2026-07-16
Expires in 57 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://www.hcpcacao.org/en

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
findings
  • CSP allows unsafe inline scripts/styles
  • missing Permissions Policy
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
DENY
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.stripe.com https://static.cdn.prismic.io; style-src 'self' 'unsafe-inline'; img-src 'self' https://images.prismic.io data:; media-src 'self' blob:; frame-src https://js.stripe.com https://www.youtube.com https://pro-hcp.prismic.io; connect-src 'self' https://api.stripe.com
strict-transport-security
max-age=63072000

Links to (1)

Linked from (2)