webtelemetry.dev

corecraftbox.shop

F

My WordPress

Last scanned 42 min agoCompare with another site →

Built with

CMS
WordPress

Also detected

Infrastructure
Nginx

Overview

Status
alive
Registered
not looked up yet
First seen here
2026-09-22
Security grade
F (50/100, from headers & TLS)
Privacy score
100/100 (0 third-party script hosts, 0 tracking/marketing services)
Hosting
Google Ireland Limited · AS43515 · United States
Server header
nginx
Response time
461 ms to first byte, measured from our crawler
TLS certificate
Let's Encrypt · TLSv1.3 · expires 2026-12-21
Language
en-us
Mobile-ready
yes (viewport meta tag)
RSS / Atom feed
yes
Linked to from
1 other sites seen so far

What to fix

  1. Add Strict-Transport-Security
    Header: Strict-Transport-Security: max-age=31536000; includeSubDomains
  2. Add a Content-Security-Policy
    Limits which scripts can run, and is the main defense against XSS. Start with Content-Security-Policy-Report-Only to test.
  3. Prevent clickjacking
    Header: X-Frame-Options: DENY (or a CSP frame-ancestors directive).
  4. Add a Referrer-Policy
    Header: Referrer-Policy: strict-origin-when-cross-origin

Security & email signals

Badge

Show this site's security grade in a README or footer:

webtelemetry security grade for corecraftbox.shop
<a href="https://webtelemetry.dev/site/corecraftbox.shop"><img src="https://webtelemetry.dev/badge/corecraftbox.shop.svg" alt="Security grade"></a>

Generated automatically from passive, publicly observable data. Think something here is wrong or want this profile removed? See /bot. Machine-readable: JSON.