launchchair.io
HTML metadata
Technology
- CDN
- Vercel
- CMS
- WordPress
Third-party hosts loaded (26)
- aitoolfame.com×3
- api.producthunt.com×3
- cdn.openhunts.com×3
- cdn.prod.website-files.com×3
- dododirectory.com×3
- earlyhunt.com×3
- fazier.com×3
- marketingdb.live×3
- peerpush.net×3
- rankinpublic.xyz×3
- saasbison.com×3
- saasfame.com×3
- saasgrow.app×3
- shipyardhq.dev×3
- speaktechenglish.com×3
- startupdirectory.net×3
- startupfa.me×3
- startuups.com×3
- submitmysaas.com×3
- sumodir.com×3
- tinylaunch.com×3
- weliketools.com×3
- www.aat.ee×3
- www.betterlaunch.co×3
- www.proofstories.io×3
- www.scrolllaunch.com×3
Social
DNS records live
- NS
-
- ns69.domaincontrol.com
- ns70.domaincontrol.com
- MX
-
- 10 inbound-smtp.us-east-1.amazonaws.com
- TXT
-
google-gws-recovery-domain-verification=70122735google-site-verification=jY_4mvXLYc-B87N55wy_qfaUM-dhnNRcWm3lQP1ooaE
Email authentication weak
- SPF
- not published
- DMARC
-
v=DMARC1; p=none;policy: none (monitoring only) - DKIM
- no key found at common selectors
Certificate (current)
R13
Expires in 81 days
HTTP security headers
- present
-
- strict-transport-security
- content-security-policy
- x-content-type-options
- referrer-policy
- permissions-policy
- findings
-
- CSP allows unsafe inline scripts/styles
- CSP uses wildcard sources
- missing frame protection
Header values
- referrer-policy
strict-origin-when-cross-origin- permissions-policy
camera=(), microphone=(), geolocation=(), payment=(), usb=(), interest-cohort=()- x-content-type-options
nosniff- content-security-policy
default-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors https://buildhop.io; object-src 'none'; img-src 'self' data: blob: https:; font-src 'self' data: https://fonts.googleapis.com https://fonts.gstatic.com https://crisp.chat https://*.crisp.chat; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://hcaptcha.com https://*.hcaptcha.com https://crisp.chat https://*.crisp.chat; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://hcaptcha.com https://js.hcaptcha.com https://*.hcaptcha.com https://crisp.chat https://*.crisp.chat https://us-assets.i.posthog.com https://*.posthog.com; connect-src 'self' https: wss:; frame-src 'self' https://hcaptcha.com https://js.hcaptcha.com https://*.hcaptcha.com https://checkout.stripe.com https://billing.stripe.com https://crisp.chat https://*.crisp.chat; media-src 'self' https://crisp.chat https://*.crisp.chat https://*.public.blob.vercel-storage.com https://*.blob.vercel-storage.com; worker-src 'self' blob:; upgra- strict-transport-security
max-age=31536000; includeSubDomains; preload
Links to (35)
- aitoolfame.com×1
- betterlaunch.co×1
- bowora.com×1
- buildhop.io×1
- claude.ai×1
- dang.ai×1
- devtool.io×1
- dododirectory.com×1
- earlyhunt.com×1
- fazier.com×1
- findyoursaas.com×1
- grok.com×1
- launchllama.co×1
- linkedin.com×1
- microsaasexamples.com×1
- openai.com×1
- openhunts.com×1
- peerpush.net×1
- perplexity.ai×1
- producthunt.com×1
- proofstories.io×1
- rankinpublic.xyz×1
- saasbison.com×1
- saasfame.com×1
- saasgrow.app×1
- scrolllaunch.com×1
- shipyardhq.dev×1
- startupdirectory.net×1
- startupfa.me×1
- startuups.com×1
- submitmysaas.com×1
- sumodir.com×1
- tinylaunch.com×1
- weliketools.com×1
- x.com×1