webtelemetry.dev

horkoo.com

F

大型一卡通|多媒体信息交互|AI营销枢纽&GEO—厦门浩科电子有限公司

厦门浩科电子有限公司始于2010年,现已成为集研发、设计、生产与销售安防产品的高新科技企业和大型出入口控制、多媒体信息交互、AI营销枢纽&GEO服务三大业务板块的解决方案源头提供商及服务商。公司通过多年对行业优秀供应链的整合及改进,使其产品在品质、外观、工艺、系统结构、功能等方面,均有强势优势。

Last scanned 53 min agoCompare with another site →

Built with

Backend
Laravel

Also detected

Libraries
Bootstrap · jQuery
Infrastructure
Nginx

Overview

Status
alive
Registered
2011-01-06 (16 years ago)
First seen here
2026-09-22
Security grade
F (30/100, from headers & TLS)
Privacy score
82/100 (1 third-party script hosts, 0 tracking/marketing services)
Hosting
Hangzhou Alibaba Advertising Co.,Ltd. · AS37963 · China
Server header
nginx
Response time
1168 ms to first byte, measured from our crawler
TLS certificate
DigiCert Inc · TLSv1.2 · expires 2027-01-08
Language
zh-cn
Mobile-ready
yes (viewport meta tag)
Linked to from
14 other sites seen so far

Loads scripts from

Third-party domains this page pulls JavaScript or iframes from. Each one can see who visits.

ltdcdn.com

What to fix

  1. Add Strict-Transport-Security
    Header: Strict-Transport-Security: max-age=31536000; includeSubDomains
  2. Add a Content-Security-Policy
    Limits which scripts can run, and is the main defense against XSS. Start with Content-Security-Policy-Report-Only to test.
  3. Add X-Content-Type-Options
    Header: X-Content-Type-Options: nosniff
  4. Prevent clickjacking
    Header: X-Frame-Options: DENY (or a CSP frame-ancestors directive).
  5. Add a Referrer-Policy
    Header: Referrer-Policy: strict-origin-when-cross-origin
  6. Mark cookies Secure and HttpOnly
    At least one cookie is sent without these flags, exposing it to interception or scripts.
  7. Publish an SPF record
    A DNS TXT record listing who may send email for this domain, which prevents spoofing.
  8. Publish a DMARC record
    A TXT record at _dmarc.<domain>; start with v=DMARC1; p=none; to monitor.

Security & email signals

Badge

Show this site's security grade in a README or footer:

webtelemetry security grade for horkoo.com
<a href="https://webtelemetry.dev/site/horkoo.com"><img src="https://webtelemetry.dev/badge/horkoo.com.svg" alt="Security grade"></a>

Generated automatically from passive, publicly observable data. Think something here is wrong or want this profile removed? See /bot. Machine-readable: JSON.