lumenate.co

.co crawl

First seen 2026-06-02 · Last seen 2026-06-02 · ok HTTP/1.1 200 438 ms crawled 2026-06-02

US · 172.67.205.234 · AS13335 Cloudflare, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
Lumenate - Your Inner World Awaits
Description
Explore deeper states of consciousness, guided by flickering light. Experience the app for free, and go even deeper with Nova.
Language
en-GB
Generator
WordPress 7.0
Canonical
https://lumenate.co/
Feeds

Open Graph

url
https://lumenate.co/
title
Lumenate - Your Inner World Awaits
locale
en_GB
site name
Lumenate
description
Explore deeper states of consciousness, guided by flickering light. Experience the app for free, and go even deeper with Nova.

Technology

CDN
Cloudflare
CMS
WordPress 7.0
jQuery
3.7.1
Analytics
  • Plausible
Fonts
  • Google Fonts

Third-party hosts loaded (4)

  • plausible.io×2
  • cdn-cookieyes.com×1
  • fonts.googleapis.com×1
  • gmpg.org×1

Social

DNS records live

NS
  • dakota.ns.cloudflare.com
  • janet.ns.cloudflare.com
MX
  • 1 aspmx.l.google.com
  • 10 alt3.aspmx.l.google.com
  • 10 alt4.aspmx.l.google.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
Verified for
  • Google

Email authentication strong

SPF
v=spf1 include:_spf.google.com -all
strict (-all)
DMARC
v=DMARC1; p=quarantine
policy: quarantine
DKIM
  • google: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAlIf0SnSLaN67B6fwEKpLeHcMXok+igTbl5H1I4oHKT12hHf2/tzX7bM+49qPet6H42yXL6PaMFH5dt…
selectors probed

Certificate (current)

E8
from 2026-05-01 to 2026-07-30
Expires in 57 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://lumenate.co/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • weak content type protection
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
SAMEORIGIN
permissions-policy
interest-cohort=(), camera=(), microphone=()
x-content-type-options
nosniff, nosniff
content-security-policy
default-src 'self' https:; script-src 'self' https: 'unsafe-inline' 'unsafe-eval'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https: data: blob:; font-src 'self' https: data:; connect-src 'self' https: wss:; object-src 'none'; frame-ancestors 'self'; base-uri 'self'; form-action 'self' https:; upgrade-insecure-requests; worker-src 'self' blob:;
strict-transport-security
max-age=15552000; includeSubDomains

Links to (4)