h1.community
CH1 | HackerOne Community
At HackerOne, we're making the internet a safer place. Thousands of talented people – hackers, employees, and community members – have dedicated ourselves to making the internet safer by helping organizations close their attack resistance gap.
Built with
No platform, CMS or framework detected. Detection is passive: it only sees what a site exposes in its HTML, headers and cookies, so custom or well-hidden stacks show up as nothing rather than as a guess.
Also detected
- Infrastructure
- Nginx
- Third-party services
- Google Analytics · Google Tag Manager
Overview
- Status
- alive
- Registered
- 2023-04-06 (3 years ago)
- First seen here
- 2026-09-22
- Security grade
- C (70/100, from headers & TLS)
- Privacy score
- 46/100 (4 third-party script hosts, 2 tracking/marketing services)
- Hosting
- Google LLC · AS396982 · United States
- Server header
nginx- Response time
- 378 ms to first byte, measured from our crawler
- TLS certificate
- Google Trust Services · TLSv1.3 · expires 2026-11-21
- Language
- en
- Mobile-ready
- yes (viewport meta tag)
- RSS / Atom feed
- yes
- Linked to from
- 8 other sites seen so far
Loads scripts from
Third-party domains this page pulls JavaScript or iframes from. Each one can see who visits.
googletagmanager.comgoogleapis.comyoutube-nocookie.combevylabs.com
What to fix
- Add a Content-Security-Policy
Limits which scripts can run, and is the main defense against XSS. Start with Content-Security-Policy-Report-Only to test. - Mark cookies Secure and HttpOnly
At least one cookie is sent without these flags, exposing it to interception or scripts.
Security & email signals
- ✓ HTTPS
- ✓ HSTS
- ✗ Content-Security-Policy
- ✓ X-Content-Type-Options
- ✓ X-Frame-Options
- ✓ Referrer-Policy
- ✗ Permissions-Policy
- ✓ SPF record
- ✓ DMARC record
- ✗ DKIM record
- ✗ Cookies set securely
- ✓ Has real content (not an empty shell)
- ✓ Valid TLS certificate
Badge
Show this site's security grade in a README or footer:

<a href="https://webtelemetry.dev/site/h1.community"><img src="https://webtelemetry.dev/badge/h1.community.svg" alt="Security grade"></a>
Generated automatically from passive, publicly observable data. Think something here is wrong or want this profile removed? See /bot. Machine-readable: JSON.