Skip to main content

Is chinaacc.com a Scam? Security Check Results - 北京正保远程教育科技股份有限公司 Reviews

chinaacc.com favicon

Is chinaacc.com Safe? Security Analysis for 北京正保远程教育科技股份有限公司

Check if chinaacc.com is a scam or legitimate. Free security scan and reviews.

EducationChinalarge
JavaScriptjQuery (implied by legacy code style)JSONP for API callsBaidu AnalyticsZhuge Analytics+1 more
Analyzed 8/4/2025Completed 3:55:23 PM
59
Security Score
MEDIUM RISK

AI Summary

The website www.chinaacc.com represents a well-established Chinese accounting education platform branded as 正保会计网校 (formerly 中华会计网校), specializing in professional accounting training and certification preparation for over 25 years. It offers a comprehensive range of courses including initial, intermediate, and advanced accounting certifications, CPA, tax advisor, asset appraisal, and continuing education. The platform targets accounting professionals and exam candidates in China, providing online courses, free trial lessons, practice questions, and study materials. The business model is primarily online education and course sales, supported by a large faculty and extensive content resources. Technically, the website employs standard web technologies including JavaScript, JSONP APIs, and multiple analytics tools such as Baidu Analytics and Zhuge Analytics. The site is well-structured, mobile-optimized, and features clear navigation and rich content, indicating a mature digital infrastructure. However, no explicit CMS or hosting provider information is discernible from the HTML. From a security perspective, the site uses HTTPS and includes several tracking and advertising scripts but lacks visible security headers and formal privacy or cookie policies with consent mechanisms. No WAF or blocking mechanisms are detected, and no vulnerabilities or exposed sensitive data are apparent. The absence of WHOIS data for the domain is a notable concern, as it conflicts with the website's claim of long-term operation and professional stature, suggesting possible privacy protection or registrar issues. Overall, the website presents a professional and trustworthy front for accounting education but would benefit from enhanced transparency in privacy compliance and domain registration details to strengthen trust and security posture.

Detected Technologies

JavaScriptjQuery (implied by legacy code style)JSONP for API callsBaidu AnalyticsZhuge AnalyticsCustom tracking scripts

🧠AI Business Intelligence

Technology stack, business insights, and market analysis powered by AI.

Business Intelligence

Market & Strategic Analysis

China Accounting Network School (正保会计网校) is a leading player in the Chinese online accounting education market, with a strong brand legacy of 25 years. Its competitive advantage lies in its comprehensive course offerings across multiple accounting certifications and professional development paths, supported by a large pool of expert instructors. The business model focuses on direct-to-consumer online course sales, supplemented by free resources and community engagement. The platform leverages partnerships with subdomains and related services for member management and content delivery. Growth indicators include active course promotions, extensive free trial content, and a vibrant user community. Strategic observations highlight the importance of maintaining domain legitimacy and enhancing privacy compliance to sustain market leadership.

Extracted Contact Information

Marketing Intelligence Data

Phone Numbers (2)

010*******
400*******

Security Posture Analysis

Comprehensive Security Assessment

The website demonstrates a moderate security maturity level with HTTPS enforced and no visible critical vulnerabilities. However, the lack of security headers such as Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), and X-Frame-Options reduces defense-in-depth. The absence of published security policies, incident response contacts, and vulnerability disclosure mechanisms indicates gaps in compliance and readiness. User tracking is moderate, with multiple analytics and advertising scripts present, but no explicit cookie consent or privacy controls detected. The missing WHOIS data raises concerns about domain registration transparency, which could impact trustworthiness. Overall, the security posture is adequate for business operations but requires improvements in policy transparency and technical controls.

Strategic Recommendations

Priority Actions for Security Improvement

1

Implement and publish comprehensive privacy and cookie policies with explicit user consent mechanisms to comply with GDPR and other regulations.

Observations

AI-powered comprehensive website and business analysis.

AI-Enhanced Website Analysis

Business Insights

Company:

北京正保远程教育科技股份有限公司

Description:

正保会计网校(原中华会计网校)是专业的会计门户网站,25年来专注财会职业培训品牌,提供初级会计职称考试、中级会计职称考试、注册会计师考试、税务师、资产评估师、高会、经济师、会计继续教育等各类网上培训服务。

Key Services:
会计职称考试培训注册会计师考试培训税务师考试培训资产评估师培训继续教育课程免费试听与题库服务
Content Quality:

excellent

Branding:

consistent

Technical Stack

Technologies:
JavaScriptjQuery (implied by legacy code style)JSONP for API callsBaidu AnalyticsZhuge AnalyticsCustom tracking scripts
Performance:

moderate

Mobile:

good

Accessibility:

basic

SEO:

good

Security Assessment

Security Score:
75/100
Best Practices:
  • HTTPS enforced (implied by canonical and script URLs)
  • No visible exposed sensitive data in HTML

Analytics & Tracking

Services:
Baidu AnalyticsZhuge AnalyticsCustom analytics
Tracking Level:moderate
Privacy Compliance:basic

Advertising & Marketing

Ad Networks:
ZCMS Advertising
Tracking Pixels:
Baidu AnalyticsZhuge AnalyticsCustom tracking scripts
Marketing Tools:
Custom ad hit count scripts
Transparency Level:basic

Website Quality Assessment

Design Quality:excellent
User Experience:excellent
Content Relevance:excellent
Navigation Clarity:excellent
Professionalism:excellent
Trustworthiness:high

Key Observations

1

Website is a professional Chinese accounting education platform with extensive course offerings.

🛡️Security Headers

HTTP security headers analysis and recommendations.

Security Headers

HTTP security headers analysis

15/100
Score

Missing Strict-Transport-Security header

HIGH

Forces HTTPS connections

Missing X-Frame-Options header

HIGH

Prevents clickjacking attacks

Missing X-Content-Type-Options header

MEDIUM

Prevents MIME type sniffing

Missing Content-Security-Policy header

HIGH

Controls resources the browser is allowed to load

Missing X-XSS-Protection header

MEDIUM

Legacy XSS protection (deprecated but still recommended)

Missing Referrer-Policy header

LOW

Controls referrer information sent with requests

Missing Permissions-Policy header

MEDIUM

Controls browser features and APIs

Sensitive data may be cached

LOW

Cache-Control header should include "no-store" for sensitive pages

👤GDPR Compliance

Privacy and data protection assessment under GDPR regulations.

GDPR Compliance

Privacy and data protection assessment

53/100
Score

No Cookie Policy found

HIGH

GDPR requires clear information about cookie usage

No Cookie Consent Banner found

HIGH

GDPR requires explicit consent for non-essential cookies

No Data Protection Officer mentioned

LOW

Large organizations may need to designate a DPO under GDPR

Privacy policy may not be GDPR compliant

MEDIUM

Privacy policy lacks explicit GDPR compliance elements

GDPR Compliance Analysis

Privacy Policy85% confidence
Cookie Policy0% confidence
Contact Information Found90% confidence
phone

🛡️NIS2 Compliance

Network & Information Security Directive compliance assessment.

NIS2 Compliance

Network & Information Security Directive

17/100
Score

No information security framework found

HIGH

NIS2 requires documented cybersecurity and information security measures

No vulnerability disclosure policy

MEDIUM

NIS2 encourages coordinated vulnerability disclosure

No security policy documentation found

HIGH

NIS2 requires documented cybersecurity governance and risk management

No incident response procedures found

HIGH

NIS2 requires documented incident response and business continuity plans

No business continuity planning found

MEDIUM

NIS2 emphasizes operational resilience and business continuity

No security contact information

HIGH

NIS2 requires clear incident reporting channels

No vulnerability reporting mechanism

MEDIUM

Clear vulnerability reporting supports coordinated disclosure

No NIS2 reference found

LOW

Consider explicitly mentioning NIS2 compliance efforts

📧Email Security

SPF, DKIM, and DMARC validation and email security assessment.

Email Security

SPF, DKIM, and DMARC validation

70/100
Score

No DKIM record found

MEDIUM

DKIM adds cryptographic signatures to emails

No BIMI Record

LOW

BIMI displays brand logos in email clients

No MTA-STS Policy

MEDIUM

MTA-STS enforces TLS for email delivery

No TLS-RPT Record

LOW

TLS-RPT provides reporting for email TLS issues

SPF
Sender Policy Framework
DKIM
DomainKeys Identified Mail
DMARC
Domain-based Message Authentication
MX Records
Mail Exchange Records
BIMI
Brand Indicators
MTA-STS
Mail Transfer Agent Security
TLS-RPT
TLS Reporting
DNSSEC
DNS Security
SPF Details
Record:
v=spf1 ip4:59.151.109.46 ip4:59.151.113.106 include:spf.icoremail.net -all

🏆SSL/TLS Security

Certificate validity and encryption analysis.

SSL/TLS Security

Certificate validity and encryption analysis

67/100
Score

Weak Protocols Supported

HIGH

Server supports weak protocols: TLSv1.1

OCSP Stapling Not Enabled

LOW

OCSP stapling improves performance and privacy

Certificate Transparency Not Implemented

LOW

Certificate is not logged in Certificate Transparency logs

Mixed Content Detected

MEDIUM

7 resources loaded over insecure HTTP

Partial SSL/TLS Assessment

LOW

Completed 3 of 4 security checks due to time constraints

Protocol Support

TLSv1.3TLSv1.2TLSv1.1

OCSP Status

OCSP Stapling Disabled

📊DNS Health

DNS configuration and security assessment.

DNS Health

DNS configuration and security assessment

75/100
Score

DNSSEC Not Enabled

MEDIUM

DNSSEC is not configured for this domain

CAA Records Not Configured

LOW

Certificate Authority Authorization (CAA) records not found

No DMARC Record

MEDIUM

DMARC policy not configured

DNS Records

A Records:59.151.113.79
Name Servers:
ns1.cdeledu.comDNS only
ns2.cdeledu.comDNS only
MX Records:
20: mail.chinaacc.com
10: smtp.chinaacc.com

DNSSEC Status

DNSSEC Not Enabled

SPF Analysis

SPF Record:
v=spf1 ip4:59.151.109.46 ip4:59.151.113.106 include:spf.icoremail.net -all

Network Security

Port scanning and network exposure analysis.

Network Security

Port scanning and network exposure analysis

100/100
Score

Good Network Security Posture

LOW

No unnecessary services detected on common risky ports

🔧Technical Analysis

Detailed technical findings and analysis from AI assessment.

Technical Analysis

Comprehensive security assessment findings

Additional Findings

The website uses a traditional web stack with asynchronous JavaScript calls to multiple subdomains for user management, content recommendation, and advertising. Analytics integration includes Baidu and Zhuge services, indicating a focus on user behavior tracking and marketing optimization. The site is mobile-optimized with responsive design elements and clear navigation menus. Performance appears moderate, with some reliance on external APIs and scripts that could impact load times. No modern CMS or framework is explicitly identified, suggesting a custom or legacy platform. Opportunities exist to modernize the tech stack, improve accessibility compliance, and optimize performance further to enhance user experience and operational resilience.
Analyze Another Website