Skip to main content

Is 36fx.com a Scam? Security Check Results - 36fx.com Reviews

36fx.com favicon

Is 36fx.com Safe? Security Analysis for 三六资讯分享网,36资讯分享网,36分享网,QQ活动,QQ活动网,爱Q网,QQ新闻,QQ技巧,三六,三十六计,one,免费QQ活动,one.36fx.com,现金红包,红包,赚钱,任务,话费,联通,移动,电信,宽带,实物活动,礼品,免费礼品,免费游戏,免费,文件,分享,软件,软件技巧,破解软件,手机app,app,手机软件,电脑软件

Check if 36fx.com is a scam or legitimate. Free security scan and reviews.

OtherChinasmall
jQuery 2.2.4Z-BlogPHP 1.7.4Font AwesomeSwiper 4.3.3Prism.js+3 more
Analyzed 8/3/2025Completed 2:28:18 AM
43
Security Score
HIGH RISK

AI Summary

36fx.com is a Chinese content sharing website primarily focused on QQ-related activities, promotions, cash redemptions, software sharing, and free games. The site targets a general audience interested in online promotions and software tips, operating since 2011. It uses the Z-BlogPHP CMS platform and is hosted by Alibaba Cloud Computing in Beijing. The technical infrastructure includes common web technologies such as jQuery, Font Awesome, and Swiper for UI components, along with custom plugins for minigames and music playback. Analytics are provided by 51.la, a Chinese analytics service. Security posture is basic, with HTTPS enabled but lacking important security headers and DNSSEC. No privacy or cookie policies are present, indicating compliance gaps with data protection regulations. The website is accessible without WAF or blocking mechanisms and contains no adult or explicit content, making it safe for general audiences. Overall, the site is functional and moderately professional but requires improvements in security and privacy compliance to enhance trust and regulatory adherence.

Detected Technologies

jQuery 2.2.4Z-BlogPHP 1.7.4Font AwesomeSwiper 4.3.3Prism.jsCustom minigames plugin (Tetris)51.la analytics SDKMyHK music player

🧠AI Business Intelligence

Technology stack, business insights, and market analysis powered by AI.

Business Intelligence

Market & Strategic Analysis

The website operates as a niche content platform sharing information about QQ activities, cash rewards, software downloads, and promotional events. Its business model appears to rely on content marketing and affiliate promotions, targeting users interested in online rewards and software tips. The site has a small-scale operation with a focus on the Chinese market. It maintains partnerships with various external domains for content and resources but lacks formal business contact information or certifications. Growth indicators include regular content updates and a diverse range of shared activities. The absence of formal privacy and security policies may limit its appeal to more security-conscious users or partners.

Security Posture Analysis

Comprehensive Security Assessment

The security maturity level of 36fx.com is basic. While HTTPS is enabled, the absence of critical security headers such as Content-Security-Policy, HSTS, and X-Frame-Options exposes the site to potential risks like clickjacking and content injection. DNSSEC is not enabled, which could improve DNS security. No incident response or security contact information is provided, limiting the ability to report or respond to security incidents effectively. The use of third-party analytics and plugins introduces potential vulnerabilities if not regularly audited. Compliance with GDPR or other data protection regulations is not evident due to missing privacy and cookie policies. Overall, the site should prioritize implementing security best practices and compliance measures to reduce risk.

Strategic Recommendations

Priority Actions for Security Improvement

1

Implement comprehensive privacy and cookie policies with user consent mechanisms to comply with data protection regulations.

Observations

AI-powered comprehensive website and business analysis.

AI-Enhanced Website Analysis

Business Insights

Description:

三六资讯分享网,36资讯分享网,36分享网,三六分享网,36分享网,QQ活动,QQ活动网,爱Q网,QQ新闻,QQ技巧,三六,三十六计,one,免费QQ活动,one.36fx.com,现金红包,红包,赚钱,任务,话费,联通,移动,电信,宽带,实物活动,礼品,免费礼品,免费游戏,免费,文件,分享,软件,软件技巧,破解软件,手机app,app,手机软件,电脑软件

Key Services:
Information sharing on QQ activitiesPromotion of cash redemptions and rewardsSharing software downloads and tipsSharing free games and tasksActivity and event sharing
Content Quality:

good

Branding:

moderate

Technical Stack

Technologies:
jQuery 2.2.4Z-BlogPHP 1.7.4Font AwesomeSwiper 4.3.3Prism.jsCustom minigames plugin (Tetris)51.la analytics SDKMyHK music player
Frameworks:
Z-BlogPHP
Performance:

moderate

Mobile:

good

Accessibility:

basic

SEO:

good

Security Assessment

Security Score:
40/100
Best Practices:
  • HTTPS enabled (implied by https URLs)
  • No DNSSEC enabled

Analytics & Tracking

Services:
51.la
Tracking Level:moderate
Privacy Compliance:poor

Advertising & Marketing

Tracking Pixels:
51.la
Marketing Tools:
51.la analytics
Transparency Level:basic

Website Quality Assessment

Design Quality:good
User Experience:good
Content Relevance:good
Navigation Clarity:good
Professionalism:basic
Trustworthiness:moderate

Key Observations

1

Website is a content sharing platform focused on QQ activities, promotions, and software tips.

🛡️Security Headers

HTTP security headers analysis and recommendations.

Security Headers

HTTP security headers analysis

25/100
Score

Missing Strict-Transport-Security header

HIGH

Forces HTTPS connections

Missing X-Frame-Options header

HIGH

Prevents clickjacking attacks

Missing X-Content-Type-Options header

MEDIUM

Prevents MIME type sniffing

Missing Content-Security-Policy header

HIGH

Controls resources the browser is allowed to load

Missing Referrer-Policy header

LOW

Controls referrer information sent with requests

Missing Permissions-Policy header

MEDIUM

Controls browser features and APIs

Sensitive data may be cached

LOW

Cache-Control header should include "no-store" for sensitive pages

👤GDPR Compliance

Privacy and data protection assessment under GDPR regulations.

GDPR Compliance

Privacy and data protection assessment

50/100
Score

No Privacy Policy found

HIGH

GDPR requires a clear and accessible privacy policy

No Cookie Policy found

HIGH

GDPR requires clear information about cookie usage

No Cookie Consent Banner found

HIGH

GDPR requires explicit consent for non-essential cookies

GDPR Compliance Analysis

Privacy Policy0% confidence
Cookie Policy0% confidence
Contact Information Found90% confidence
phone

🛡️NIS2 Compliance

Network & Information Security Directive compliance assessment.

NIS2 Compliance

Network & Information Security Directive

2/100
Score

No information security framework found

HIGH

NIS2 requires documented cybersecurity and information security measures

No vulnerability disclosure policy

MEDIUM

NIS2 encourages coordinated vulnerability disclosure

No security policy documentation found

HIGH

NIS2 requires documented cybersecurity governance and risk management

No incident response procedures found

HIGH

NIS2 requires documented incident response and business continuity plans

No business continuity planning found

MEDIUM

NIS2 emphasizes operational resilience and business continuity

No security contact information

HIGH

NIS2 requires clear incident reporting channels

No vulnerability reporting mechanism

MEDIUM

Clear vulnerability reporting supports coordinated disclosure

No NIS2 reference found

LOW

Consider explicitly mentioning NIS2 compliance efforts

Critical sector without clear security compliance

HIGH

Detected sectors: energy, transport, digital

📧Email Security

SPF, DKIM, and DMARC validation and email security assessment.

Email Security

SPF, DKIM, and DMARC validation

65/100
Score

No DMARC record found

HIGH

DMARC provides email authentication and reporting

No DKIM record found

MEDIUM

DKIM adds cryptographic signatures to emails

SPF
Sender Policy Framework
DKIM
DomainKeys Identified Mail
DMARC
Domain-based Message Authentication
MX Records
Mail Exchange Records
BIMI
Brand Indicators
MTA-STS
Mail Transfer Agent Security
TLS-RPT
TLS Reporting
DNSSEC
DNS Security
DMARC Details
Policy:none
MTA-STS Details

🏆SSL/TLS Security

Certificate validity and encryption analysis.

SSL/TLS Security

Certificate validity and encryption analysis

67/100
Score

Weak Protocols Supported

HIGH

Server supports weak protocols: TLSv1.1

Certificate Transparency Not Implemented

LOW

Certificate is not logged in Certificate Transparency logs

SSL Certificate Expires Within 90 Days

MEDIUM

SSL certificate expires in 47 days

Mixed Content Detected

MEDIUM

16 resources loaded over insecure HTTP

Partial SSL/TLS Assessment

LOW

Completed 3 of 4 security checks due to time constraints

Protocol Support

TLSv1.3TLSv1.2TLSv1.1

OCSP Status

OCSP Stapling Enabled

📊DNS Health

DNS configuration and security assessment.

DNS Health

DNS configuration and security assessment

70/100
Score

DNSSEC Not Enabled

MEDIUM

DNSSEC is not configured for this domain

CAA Records Not Configured

LOW

Certificate Authority Authorization (CAA) records not found

Domain Transfer Lock Not Enabled

MEDIUM

Domain can be transferred without authorization

Domain Delete Lock Not Enabled

LOW

Domain can be deleted without additional verification

Domain Registration Details

Domain Age
14 years(mature)
Expiry Risk
low(208 days)
Protection Level
noneDNSSEC OFF
Suspicious Indicators Detected
  • No domain protection locks enabled

DNS Records

A Records:148.66.17.83
Name Servers:
dns17.hichina.com
dns18.hichina.com

DNSSEC Status

DNSSEC Enabled

DNS Performance

Resolution Time:713ms

Network Security

Port scanning and network exposure analysis.

Network Security

Port scanning and network exposure analysis

0/100
Score

High-Risk Service Exposed: FTP

HIGH

Port 21 (FTP) is publicly accessible - FTP - Often unencrypted file transfer

Critical Service Exposed: MySQL

CRITICAL

Port 3306 (MySQL) is publicly accessible - MySQL - Database server

🔧Technical Analysis

Detailed technical findings and analysis from AI assessment.

Technical Analysis

Comprehensive security assessment findings

Additional Findings

The website is built on the Z-BlogPHP CMS platform version 1.7.4, using a combination of jQuery, Font Awesome, Swiper, and Prism.js for UI and syntax highlighting. It includes custom plugins for minigames and a music player, enhancing user engagement. Hosting is provided by Alibaba Cloud Computing, a reputable provider. The site is moderately optimized for mobile devices and SEO, with proper meta tags and responsive design. However, the lack of advanced accessibility features and security headers indicates technical debt and areas for modernization. Performance is moderate, with no major issues detected but potential improvements possible through optimization and security enhancements.
Analyze Another Website