Skip to main content

Is 51ima.com a Scam? Security Check Results - 中关村科金得助智能 Reviews

Is 51ima.com Safe? Security Analysis for 中关村科金得助智能

Check if 51ima.com is a scam or legitimate. Free security scan and reviews.

TechnologyChinamedium
jQuery 1.8.3SwiperCSS3HTML5
Analyzed 8/1/2025Completed 9:43:41 PM
58
Security Score
MEDIUM RISK

AI Summary

中关村科金得助智能 is a Chinese technology company specializing in vertical domain large model AI technologies and applications, focusing on intelligent customer service systems and related AI-driven solutions. The company positions itself as a leading unicorn in the AI vertical domain large model space, offering a broad product portfolio including AI customer service, intelligent marketing, intelligent operations, and knowledge management platforms. Their target audience primarily consists of enterprise clients in finance, insurance, securities, trust, consumer finance, retail, manufacturing, government, and healthcare sectors. Technically, the website employs standard web technologies such as jQuery and Swiper, with moderate performance and good mobile optimization. However, the absence of advanced security headers and privacy policies indicates room for improvement in security posture and compliance. The WHOIS data is unavailable, raising concerns about domain registration legitimacy, though the website content and business presence suggest an operational entity. Overall, the site demonstrates a professional business presence but requires enhancements in security and privacy compliance.

Detected Technologies

jQuery 1.8.3SwiperCSS3HTML5

🧠AI Business Intelligence

Technology stack, business insights, and market analysis powered by AI.

Business Intelligence

Market & Strategic Analysis

The company operates in the AI technology and finance sectors, leveraging proprietary large model AI technologies and multi-modal interaction capabilities. Their business model is B2B SaaS and intelligent solution provision, targeting multiple vertical industries with tailored AI products. The firm claims strong market positioning as a vertical domain AI unicorn with a decade of AI experience and significant data assets. Their product ecosystem includes AI training platforms, intelligent marketing automation, multi-channel contact centers, voice and text robots, and industry-specific AI solutions. The company uses Chinese major analytics and verification services, indicating a focus on the Chinese market. The lack of public WHOIS data and contact information suggests a cautious approach to public disclosure or potential privacy protection. The company’s growth potential is supported by diversified product offerings and industry-specific solutions.

Extracted Contact Information

Marketing Intelligence Data

Email Addresses (11)

d*****@2x.png
s*****@zkj.com
x*****@zkj.com
i*****@4x.png
i*****@4x.png
+6 more emails found

Security Posture Analysis

Comprehensive Security Assessment

The website currently lacks visible security headers such as Content Security Policy, HSTS, or X-Frame-Options, which are important for mitigating common web vulnerabilities. HTTPS usage is assumed but not confirmed from the data provided. No privacy or cookie policies are present, indicating potential compliance gaps with GDPR or similar regulations. No incident response or security contact information is available, limiting transparency and readiness for security incidents. The use of older jQuery version (1.8.3) may pose security risks if not properly patched. Overall, the security maturity level is moderate to low, with recommendations to enhance header security, privacy compliance, and incident response capabilities.

Strategic Recommendations

Priority Actions for Security Improvement

1

Implement comprehensive privacy and cookie policies with clear user consent mechanisms to improve compliance.

Observations

AI-powered comprehensive website and business analysis.

AI-Enhanced Website Analysis

Business Insights

Company:

中关村科金得助智能

Description:

中关村科金得助智能是一家领先的大模型技术与应用公司、人工智能领域垂类大模型独角兽。公司通过自主研发的领域大模型、大数据分析、多模态交互三大核心技术,打造了得助大模型开发平台、智能营销、智能客服、智能运营、知识管理等产品解决方案。拥有人工智能在线客服系统、全媒体呼叫中心系统、电话外呼系统平台、语音机器人、智能陪练、智能质检、海外全语种客服系统等产品矩阵。

Key Services:
得助大模型开发平台智能营销智能客服系统智能运营知识管理全媒体呼叫中心系统电话外呼系统平台语音机器人智能陪练智能质检
Content Quality:

good

Branding:

consistent

Technical Stack

Technologies:
jQuery 1.8.3SwiperCSS3HTML5
Performance:

moderate

Mobile:

good

Accessibility:

basic

SEO:

good

Security Assessment

Security Score:
40/100

Analytics & Tracking

Services:
Baidu Analytics
Tracking Level:moderate
Privacy Compliance:poor

Advertising & Marketing

Tracking Pixels:
Baidu Analytics
Marketing Tools:
Baidu site verificationSogou site verificationBytedance verificationShenma site verification
Transparency Level:basic

Website Quality Assessment

Design Quality:good
User Experience:good
Content Relevance:good
Navigation Clarity:good
Professionalism:good
Trustworthiness:moderate

Key Observations

1

Website is fully accessible with rich content and navigation

🛡️Security Headers

HTTP security headers analysis and recommendations.

Security Headers

HTTP security headers analysis

15/100
Score

Missing Strict-Transport-Security header

HIGH

Forces HTTPS connections

Missing X-Frame-Options header

HIGH

Prevents clickjacking attacks

Missing X-Content-Type-Options header

MEDIUM

Prevents MIME type sniffing

Missing Content-Security-Policy header

HIGH

Controls resources the browser is allowed to load

Missing X-XSS-Protection header

MEDIUM

Legacy XSS protection (deprecated but still recommended)

Missing Referrer-Policy header

LOW

Controls referrer information sent with requests

Missing Permissions-Policy header

MEDIUM

Controls browser features and APIs

Sensitive data may be cached

LOW

Cache-Control header should include "no-store" for sensitive pages

👤GDPR Compliance

Privacy and data protection assessment under GDPR regulations.

GDPR Compliance

Privacy and data protection assessment

50/100
Score

No Privacy Policy found

HIGH

GDPR requires a clear and accessible privacy policy

No Cookie Policy found

HIGH

GDPR requires clear information about cookie usage

No Cookie Consent Banner found

HIGH

GDPR requires explicit consent for non-essential cookies

GDPR Compliance Analysis

Privacy Policy0% confidence
Cookie Policy0% confidence
Contact Information Found90% confidence
emailphone

🛡️NIS2 Compliance

Network & Information Security Directive compliance assessment.

NIS2 Compliance

Network & Information Security Directive

17/100
Score

No information security framework found

HIGH

NIS2 requires documented cybersecurity and information security measures

No vulnerability disclosure policy

MEDIUM

NIS2 encourages coordinated vulnerability disclosure

No security policy documentation found

HIGH

NIS2 requires documented cybersecurity governance and risk management

No incident response procedures found

HIGH

NIS2 requires documented incident response and business continuity plans

No business continuity planning found

MEDIUM

NIS2 emphasizes operational resilience and business continuity

No security contact information

HIGH

NIS2 requires clear incident reporting channels

No vulnerability reporting mechanism

MEDIUM

Clear vulnerability reporting supports coordinated disclosure

No NIS2 reference found

LOW

Consider explicitly mentioning NIS2 compliance efforts

📧Email Security

SPF, DKIM, and DMARC validation and email security assessment.

Email Security

SPF, DKIM, and DMARC validation

60/100
Score

No DKIM record found

MEDIUM

DKIM adds cryptographic signatures to emails

No BIMI Record

LOW

BIMI displays brand logos in email clients

No MTA-STS Policy

MEDIUM

MTA-STS enforces TLS for email delivery

No TLS-RPT Record

LOW

TLS-RPT provides reporting for email TLS issues

No email authentication configured

CRITICAL

Domain is vulnerable to email spoofing

SPF
Sender Policy Framework
DKIM
DomainKeys Identified Mail
DMARC
Domain-based Message Authentication
MX Records
Mail Exchange Records
BIMI
Brand Indicators
MTA-STS
Mail Transfer Agent Security
TLS-RPT
TLS Reporting
DNSSEC
DNS Security

🏆SSL/TLS Security

Certificate validity and encryption analysis.

SSL/TLS Security

Certificate validity and encryption analysis

90/100
Score

Mixed Content Detected

MEDIUM

374 resources loaded over insecure HTTP

Partial SSL/TLS Assessment

LOW

Completed 2 of 4 security checks due to time constraints

Certificate Details

Subject:*.51ima.com
Issuer:RapidSSL TLS RSA CA G1
Valid Until:1/20/2026 (172 days)
SANs:*.51ima.com, 51ima.com

OCSP Status

OCSP Stapling Disabled

📊DNS Health

DNS configuration and security assessment.

DNS Health

DNS configuration and security assessment

60/100
Score

DNSSEC Not Enabled

MEDIUM

DNSSEC is not configured for this domain

CAA Records Not Configured

LOW

Certificate Authority Authorization (CAA) records not found

Domain Transfer Lock Not Enabled

MEDIUM

Domain can be transferred without authorization

Domain Delete Lock Not Enabled

LOW

Domain can be deleted without additional verification

No DMARC Record

MEDIUM

DMARC policy not configured

Domain Registration Details

Domain Age
6 years(mature)
Expiry Risk
low(191 days)
Protection Level
noneDNSSEC OFF
Suspicious Indicators Detected
  • No domain protection locks enabled

DNS Records

A Records:1.94.68.38, 1.94.68.111, 1.94.73.181, 1.94.73.45
Name Servers:
dns27.hichina.com
dns28.hichina.com
MX Records:
5: mxbiz2.qq.com

DNSSEC Status

DNSSEC Not Enabled

Network Security

Port scanning and network exposure analysis.

Network Security

Port scanning and network exposure analysis

100/100
Score

Good Network Security Posture

LOW

No unnecessary services detected on common risky ports

🔧Technical Analysis

Detailed technical findings and analysis from AI assessment.

Technical Analysis

Comprehensive security assessment findings

Additional Findings

The website uses a traditional web stack with HTML5, CSS3, and jQuery 1.8.3, alongside Swiper for UI components. The site is mobile optimized and has good SEO meta tags including Open Graph for social sharing. However, the technology stack is somewhat dated, particularly the jQuery version, which may introduce security and performance risks. No modern JavaScript frameworks or CMS platforms are detected. Performance is moderate, with room for improvement in loading speed and accessibility. The site lacks advanced security configurations and privacy compliance features. Hosting provider and SSL configuration details are not available, limiting full technical assessment.
Analyze Another Website