shapescan.xyz

.xyz crawl

First seen 2026-04-11 · Last seen 2026-05-18 · ok HTTP/1.1 200 222 ms crawled 2026-05-18

US · 172.67.72.116 · AS13335 Cloudflare, Inc.

Reputation 100/100

Classifying

HTML metadata

Title
Shape Mainnet blockchain explorer - View Shape Mainnet stats | Blockscout
Description
Open-source block explorer by Blockscout. Search transactions, verify smart contracts, analyze addresses, and track network activity. Complete blockchain data and APIs for the Shape Mainnet Explorer network.
Language
en
Canonical
https://shapescan.xyz/

Open Graph

title
Shape Mainnet blockchain explorer - View Shape Mainnet stats | Blockscout

Technology

CDN
Cloudflare
CMS
Next.js
Analytics
  • Cloudflare Insights
Fonts
  • Google Fonts

Third-party hosts loaded (2)

  • fonts.googleapis.com×2
  • static.cloudflareinsights.com×1

Registration

Registrar
Amazon Registrar, Inc.
Created
2024-05-31
Expires
2027-05-31 375 days left
Updated
2026-04-27
Name servers
  • yolanda.ns.cloudflare.com
  • miles.ns.cloudflare.com

DNS records live

NS
  • miles.ns.cloudflare.com
  • yolanda.ns.cloudflare.com
Verified for
  • Google

Email authentication no MX

SPF
v=spf1 -all
strict (-all)
DMARC
v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s;
policy: reject (enforced) · sp=reject
DKIM
Show 12 DKIM selectors
  • default: v=DKIM1; p=
  • google: v=DKIM1; p=
  • selector1: v=DKIM1; p=
  • selector2: v=DKIM1; p=
  • k1: v=DKIM1; p=
  • k2: v=DKIM1; p=
  • mail: v=DKIM1; p=
  • dkim: v=DKIM1; p=
  • s1: v=DKIM1; p=
  • s2: v=DKIM1; p=
  • mxvault: v=DKIM1; p=
  • smtpapi: v=DKIM1; p=
selectors probed

Certificate (current)

WE1
from 2026-05-09 to 2026-08-07
Expires in 78 days

HTTP security headers

Header hygiene 90/100 Checked live page: https://shapescan.xyz/

present
  • strict-transport-security
  • content-security-policy
  • x-frame-options
  • x-content-type-options
  • referrer-policy
  • cross-origin-opener-policy
findings
  • CSP uses wildcard sources
  • missing Permissions Policy
Header values
referrer-policy
origin-when-cross-origin
x-frame-options
SAMEORIGIN
x-content-type-options
nosniff
content-security-policy
default-src 'self';connect-src 'self' *.shapescan.xyz shapescan.xyz https://shapescan.xyz https://admin-rs.services.blockscout.com https://contracts-info.services.blockscout.com https://metadata.services.blockscout.com https://user-ops-indexer-shape-mainnet.k8s.blockscout.com https://visualizer.services.blockscout.com wss://shapescan.xyz https://shape-mainnet.g.alchemy.com/public https://infragrid.v.network raw.githubusercontent.com api.github.com coinzilla.com *.coinzilla.com https://request-global.czilladx.com *.adx.ws servedbyadbutler.com *.slise.xyz app.specify.sh *.web3modal.com *.web3modal.org *.walletconnect.com *.walletconnect.org wss://relay.walletconnect.com wss://relay.walletconnect.org wss://www.walletlink.org fonts.gstatic.com https://www.google.com/recaptcha/api2/clr cdn.growthbook.io https://delegated-ipfs.dev https://trustless-gateway.link https://eth.blockscout.com https://explorer.optimism.io https://rootstock.blockscout.com https://etc.blockscout.com https://gnosis.
strict-transport-security
max-age=31536000; includeSubDomains
cross-origin-opener-policy
same-origin

Linked from (1)