webtelemetry.dev

h1.community

C

H1 | HackerOne Community

At HackerOne, we're making the internet a safer place. Thousands of talented people – hackers, employees, and community members – have dedicated ourselves to making the internet safer by helping organizations close their attack resistance gap.

Last scanned 43 min agoCompare with another site →

Built with

No platform, CMS or framework detected. Detection is passive: it only sees what a site exposes in its HTML, headers and cookies, so custom or well-hidden stacks show up as nothing rather than as a guess.

Also detected

Infrastructure
Nginx
Third-party services
Google Analytics · Google Tag Manager

Overview

Status
alive
Registered
2023-04-06 (3 years ago)
First seen here
2026-09-22
Security grade
C (70/100, from headers & TLS)
Privacy score
46/100 (4 third-party script hosts, 2 tracking/marketing services)
Hosting
Google LLC · AS396982 · United States
Server header
nginx
Response time
378 ms to first byte, measured from our crawler
TLS certificate
Google Trust Services · TLSv1.3 · expires 2026-11-21
Language
en
Mobile-ready
yes (viewport meta tag)
RSS / Atom feed
yes
Linked to from
8 other sites seen so far

Loads scripts from

Third-party domains this page pulls JavaScript or iframes from. Each one can see who visits.

googletagmanager.comgoogleapis.comyoutube-nocookie.combevylabs.com

What to fix

  1. Add a Content-Security-Policy
    Limits which scripts can run, and is the main defense against XSS. Start with Content-Security-Policy-Report-Only to test.
  2. Mark cookies Secure and HttpOnly
    At least one cookie is sent without these flags, exposing it to interception or scripts.

Security & email signals

Badge

Show this site's security grade in a README or footer:

webtelemetry security grade for h1.community
<a href="https://webtelemetry.dev/site/h1.community"><img src="https://webtelemetry.dev/badge/h1.community.svg" alt="Security grade"></a>

Generated automatically from passive, publicly observable data. Think something here is wrong or want this profile removed? See /bot. Machine-readable: JSON.