webtelemetry.dev

machi-ya.jp

C

ガジェット関連のクラウドファンディング - machi-ya(マチヤ)

「machi-ya(マチヤ)」はデジタル家電、小物などのガジェット関連のプロジェクトに特化したクラウドファンディングサービスです。

Last scanned 52 min agoCompare with another site →

Built with

Backend
Ruby on Rails

Also detected

Infrastructure
Amazon CloudFront · Nginx
Third-party services
Google Tag Manager · Microsoft Clarity

Overview

Status
alive
Registered
unknown (this domain's registry doesn't publish it via RDAP)
First seen here
2026-09-22
Security grade
C (70/100, from headers & TLS)
Privacy score
62/100 (2 third-party script hosts, 2 tracking/marketing services)
Hosting
Amazon.com, Inc. · AS16509 · France
Server header
nginx
Response time
1216 ms to first byte, measured from our crawler
TLS certificate
Amazon · TLSv1.3 · expires 2027-04-07
Language
ja
Mobile-ready
yes (viewport meta tag)
Linked to from
7 other sites seen so far

Loads scripts from

Third-party domains this page pulls JavaScript or iframes from. Each one can see who visits.

fontawesome.comcamp-fire.jp

What to fix

  1. Add a Content-Security-Policy
    Limits which scripts can run, and is the main defense against XSS. Start with Content-Security-Policy-Report-Only to test.
  2. Mark cookies Secure and HttpOnly
    At least one cookie is sent without these flags, exposing it to interception or scripts.
  3. Publish a DMARC record
    A TXT record at _dmarc.<domain>; start with v=DMARC1; p=none; to monitor.

Security & email signals

Badge

Show this site's security grade in a README or footer:

webtelemetry security grade for machi-ya.jp
<a href="https://webtelemetry.dev/site/machi-ya.jp"><img src="https://webtelemetry.dev/badge/machi-ya.jp.svg" alt="Security grade"></a>

Generated automatically from passive, publicly observable data. Think something here is wrong or want this profile removed? See /bot. Machine-readable: JSON.