pledgely.app

.app crawl

First seen 2026-05-10 · Last seen 2026-05-10 · ok HTTP/1.1 200 1712 ms crawled 2026-05-16

US · 104.21.24.21 · AS13335 Cloudflare, Inc.

Reputation 92/100 no dmarc policy

Classifying

HTML metadata

Title
Pledgely - Quit Porn App | Porn Blocker With Real Stakes
Description
The porn blocker you can't cheat. Pledgely blocks adult content and charges you money if you turn it off. Zero data collection - everything runs on your device.
Language
en
Canonical
https://pledgely.app/

Open Graph

url
https://pledgely.app/
title
Pledgely - Quit Porn App | Porn Blocker With Real Stakes
description
The porn blocker you can't cheat. Blocks adult content and charges you money if you turn it off. Zero data collection.

Technology

CDN
Cloudflare
CMS
Gatsby

Social

DNS records live

NS
  • brett.ns.cloudflare.com
  • val.ns.cloudflare.com
MX
  • 1 aspmx.l.google.com
  • 10 alt3.aspmx.l.google.com
  • 10 alt4.aspmx.l.google.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
  • google-site-verification=ZS71RXpnc32-FBdXWWXJ2DHJIesW3Xgh8GuRWpvRdtQ
  • apple-url-filter=app.pledgely

Email authentication weak

SPF
v=spf1 include:_spf.google.com ~all
softfail (~all)
DMARC
not published
DKIM
  • google: v=DKIM1;k=rsa;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAlUygaHR75ZQvisjwKS2TR6/mLzbrZKgvwwyw81bD7qnDfnikaMBsMeTJTLX7ho4lzWWfMqIaqYN3o7gV…
selectors probed

Certificate (current)

WE1
from 2026-04-18 to 2026-07-17
Expires in 59 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://pledgely.app/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • permissions-policy
findings
  • CSP allows unsafe inline scripts/styles
  • CSP uses wildcard sources
Header values
referrer-policy
strict-origin-when-cross-origin
x-frame-options
DENY
permissions-policy
geolocation=(), microphone=(), camera=()
x-content-type-options
nosniff
content-security-policy
default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://*.js.stripe.com https://js.stripe.com https://m.stripe.network https://maps.googleapis.com https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; connect-src 'self' https://api.stripe.com https://maps.googleapis.com https://cloudflareinsights.com; frame-src 'self' https://*.js.stripe.com https://js.stripe.com https://hooks.stripe.com https://www.youtube.com; object-src 'none'; base-uri 'self'; form-action 'self'
strict-transport-security
max-age=31536000; includeSubDomains; preload

Links to (3)

Linked from (1)