Skip to main content

Is e-change.io a Scam? Security Check Results - IceNetworks Ltd. Reviews

e-change.io favicon

Is e-change.io Safe? Security Analysis for IceNetworks Ltd.

Check if e-change.io is a scam or legitimate. Free security scan and reviews.

FinanceRussiasmall
Alpine.jsLivewire (Laravel)PusherCloudflare DNSGoogle Sign-In+4 more
Analyzed 10/3/2025Completed 8:58:52 PM
59
Security Score
MEDIUM RISK

AI Summary

E-Change.io is an online cryptocurrency exchange platform operated by IceNetworks Ltd., founded in 2022. The website offers fast and secure cryptocurrency exchange services primarily targeting Russian-speaking users, allowing conversion between cryptocurrencies and fiat currencies with minimal commissions. The platform supports multiple social login options including Google, VK, and Yandex, enhancing user convenience. The business positions itself as a reliable and efficient crypto exchange with promotional campaigns to attract users. Technically, the website employs modern web technologies such as Alpine.js, Livewire (Laravel), Pusher for real-time communication, and integrates third-party SDKs for social authentication. Hosting and DNS services leverage Cloudflare, although DNSSEC is not enabled. The site is mobile-optimized with good SEO practices and uses Yandex Metrika for analytics. However, cookie consent mechanisms are absent, and accessibility features are basic. From a security perspective, the site enforces HTTPS, uses CSRF tokens, and locks domain transfers. Yet, it lacks published security policies or incident response contacts, and DNSSEC is not enabled, which could be improved. No critical vulnerabilities or malicious content were detected. Privacy compliance is basic, with a privacy policy present but no cookie consent banner. Overall, E-Change.io presents a professional and functional cryptocurrency exchange service with moderate security and privacy compliance. Strategic improvements in DNS security, privacy mechanisms, and transparency of security policies would enhance trust and compliance.

Detected Technologies

Alpine.jsLivewire (Laravel)PusherCloudflare DNSGoogle Sign-InVK SDKYandex Passport SDKChart.jsJivoChat

🧠AI Business Intelligence

Technology stack, business insights, and market analysis powered by AI.

Business Intelligence

Market & Strategic Analysis

E-Change.io operates in the finance sector focusing on cryptocurrency exchange services. The company targets Russian-speaking crypto users seeking quick and secure conversions between crypto and fiat currencies. The business model is transactional, generating revenue from exchange commissions. The platform's competitive advantage includes multiple social login options and a user-friendly interface. The company is relatively new (established 2022) and small in size. Partnerships or subsidiaries are not explicitly identified. The presence of promotional campaigns indicates active marketing efforts. The company maintains transparent domain registration and uses trusted third-party services for analytics and chat support.

Extracted Contact Information

Marketing Intelligence Data

Email Addresses (1)

s*****@e-change.io

Security Posture Analysis

Comprehensive Security Assessment

The website demonstrates a moderate security maturity level with HTTPS enforced and domain transfer protection enabled. Use of CSRF tokens and social authentication SDKs adds to security. However, the absence of DNSSEC, lack of published security or incident response policies, and missing cookie consent mechanisms highlight compliance gaps. No exposed sensitive data or vulnerable libraries were detected in the provided content. The security posture would benefit from enhanced DNS security, formalized incident response procedures, and improved privacy compliance to meet GDPR and related regulations.

Strategic Recommendations

Priority Actions for Security Improvement

1

Enable DNSSEC on the domain to strengthen DNS security and prevent spoofing.

Observations

AI-powered comprehensive website and business analysis.

AI-Enhanced Website Analysis

Business Insights

Company:

IceNetworks Ltd.

Description:

Обмен криптовалют на фиат или другую криптовалюту с помощью конвертера криптовалют. Покупайте криптовалюту с минимальной комиссией у нас на сайте.

Key Services:
Cryptocurrency exchangeCrypto to fiat conversionToken exchange
Content Quality:

good

Branding:

consistent

Technical Stack

Technologies:
Alpine.jsLivewire (Laravel)PusherCloudflare DNSGoogle Sign-InVK SDKYandex Passport SDKChart.jsJivoChat
Frameworks:
Laravel (inferred from Livewire usage)
Performance:

moderate

Mobile:

good

Accessibility:

basic

SEO:

good

Security Assessment

Security Score:
75/100
Best Practices:
  • HTTPS enforced
  • Domain locked against transfer
  • Use of CSRF tokens in forms
  • Use of CAPTCHA alternatives (Google Sign-In, VK, Yandex SSO)

Analytics & Tracking

Services:
Yandex Metrika
Tracking Level:moderate
Privacy Compliance:basic

Advertising & Marketing

Tracking Pixels:
Yandex Metrika
Marketing Tools:
JivoChatPusher
Transparency Level:basic

Website Quality Assessment

Design Quality:good
User Experience:good
Content Relevance:good
Navigation Clarity:good
Professionalism:good
Trustworthiness:moderate

Key Observations

1

Website is fully accessible with no blocking or WAF challenges

🛡️Security Headers

HTTP security headers analysis and recommendations.

Security Headers

HTTP security headers analysis

50/100
Score

Missing Strict-Transport-Security header

HIGH

Forces HTTPS connections

Weak X-Frame-Options configuration

LOW

Current value: "sameorigin, SAMEORIGIN"

Weak X-Content-Type-Options configuration

LOW

Current value: "nosnif, nosniff"

Missing Content-Security-Policy header

HIGH

Controls resources the browser is allowed to load

Missing Permissions-Policy header

MEDIUM

Controls browser features and APIs

👤GDPR Compliance

Privacy and data protection assessment under GDPR regulations.

GDPR Compliance

Privacy and data protection assessment

35/100
Score

No Privacy Policy found

HIGH

GDPR requires a clear and accessible privacy policy

No Cookie Policy found

HIGH

GDPR requires clear information about cookie usage

No Cookie Consent Banner found

HIGH

GDPR requires explicit consent for non-essential cookies

Third-party services without privacy policy

HIGH

Detected services: Google APIs

GDPR Compliance Analysis

Privacy Policy0% confidence
Cookie Policy0% confidence
Contact Information Found90% confidence
emailphone

🛡️NIS2 Compliance

Network & Information Security Directive compliance assessment.

NIS2 Compliance

Network & Information Security Directive

2/100
Score

No information security framework found

HIGH

NIS2 requires documented cybersecurity and information security measures

No vulnerability disclosure policy

MEDIUM

NIS2 encourages coordinated vulnerability disclosure

No security policy documentation found

HIGH

NIS2 requires documented cybersecurity governance and risk management

No incident response procedures found

HIGH

NIS2 requires documented incident response and business continuity plans

No business continuity planning found

MEDIUM

NIS2 emphasizes operational resilience and business continuity

No security contact information

HIGH

NIS2 requires clear incident reporting channels

No vulnerability reporting mechanism

MEDIUM

Clear vulnerability reporting supports coordinated disclosure

No NIS2 reference found

LOW

Consider explicitly mentioning NIS2 compliance efforts

Critical sector without clear security compliance

HIGH

Detected sectors: transport, banking, digital

📧Email Security

SPF, DKIM, and DMARC validation and email security assessment.

Email Security

SPF, DKIM, and DMARC validation

70/100
Score

No DKIM record found

MEDIUM

DKIM adds cryptographic signatures to emails

No BIMI Record

LOW

BIMI displays brand logos in email clients

No MTA-STS Policy

MEDIUM

MTA-STS enforces TLS for email delivery

No TLS-RPT Record

LOW

TLS-RPT provides reporting for email TLS issues

SPF
Sender Policy Framework
DKIM
DomainKeys Identified Mail
DMARC
Domain-based Message Authentication
MX Records
Mail Exchange Records
BIMI
Brand Indicators
MTA-STS
Mail Transfer Agent Security
TLS-RPT
TLS Reporting
DNSSEC
DNS Security
SPF Details
Record:
v=spf1 include:spf.messagingengine.com ~all
DNS Lookups:1/10
Policy:~all

🏆SSL/TLS Security

Certificate validity and encryption analysis.

SSL/TLS Security

Certificate validity and encryption analysis

65/100
Score

SSL Certificate Expires Within 90 Days

MEDIUM

SSL certificate expires in 58 days

Weak SSL Key Length

HIGH

SSL certificate uses 256-bit key, which is considered weak

Mixed Content Detected

MEDIUM

2 resources loaded over insecure HTTP

Partial SSL/TLS Assessment

LOW

Completed 2 of 4 security checks due to time constraints

Certificate Details

Subject:e-change.io
Issuer:WE1
Valid Until:12/1/2025 (58 days)
SANs:e-change.io, *.e-change.io

OCSP Status

OCSP Stapling Disabled

📊DNS Health

DNS configuration and security assessment.

DNS Health

DNS configuration and security assessment

70/100
Score

DNSSEC Not Enabled

MEDIUM

DNSSEC is not configured for this domain

CAA Records Not Configured

LOW

Certificate Authority Authorization (CAA) records not found

Domain Delete Lock Not Enabled

LOW

Domain can be deleted without additional verification

No DMARC Record

MEDIUM

DMARC policy not configured

Domain Registration Details

Domain Age
3 years(established)
Expiry Risk
none(647 days)
Protection Level
basicDNSSEC OFF

DNS Records

A Records:172.67.68.147, 104.26.1.170, 104.26.0.170
AAAA Records:2606:4700:20::681a:1aa, 2606:4700:20::ac43:4493, 2606:4700:20::681a:aa
Name Servers:
hadlee.ns.cloudflare.com
kirk.ns.cloudflare.com
MX Records:
10: in1-smtp.messagingengine.com
20: in2-smtp.messagingengine.com
SOA:Serial: 2384207775, TTL: 1800s

DNSSEC Status

DNSSEC Not Enabled

DNS Performance

Resolution Time:58ms

SPF Analysis

SPF Record:
v=spf1 include:spf.messagingengine.com ~all

Network Security

Port scanning and network exposure analysis.

Network Security

Port scanning and network exposure analysis

100/100
Score

Good Network Security Posture

LOW

No unnecessary services detected on common risky ports

🔧Technical Analysis

Detailed technical findings and analysis from AI assessment.

Technical Analysis

Comprehensive security assessment findings

Additional Findings

The website uses a modern technology stack including Alpine.js for reactive UI, Livewire with Laravel backend for dynamic content, and Pusher for real-time features. Social authentication is integrated via Google, VK, and Yandex SDKs. Hosting leverages Cloudflare DNS services, though DNSSEC is not enabled. Performance is moderate with good mobile optimization and SEO practices. The site uses Yandex Metrika for analytics and JivoChat for customer support. Technical debt appears low, but improvements in DNS security and privacy mechanisms are recommended to reduce operational risks.
Analyze Another Website