Skip to main content

Is gxdhhd.com a Scam? Security Check Results - 南宁东恒华道生物科技有限责任公司 Reviews

Is gxdhhd.com Safe? Security Analysis for 南宁东恒华道生物科技有限责任公司

Check if gxdhhd.com is a scam or legitimate. Free security scan and reviews.

ManufacturingChinamedium
HTML5CSS3JavaScriptjQuerySlick Carousel+3 more
Analyzed 8/2/2025Completed 3:30:41 AM
52
Security Score
MEDIUM RISK

AI Summary

南宁东恒华道生物科技有限责任公司是一家专注于定制型酶制剂生产及技术应用服务的高新技术企业,成立于2004年,拥有超过21年的酶解技术沉淀。公司产品涵盖木瓜蛋白酶、碱性蛋白酶、中性蛋白酶、果胶酶、纤维素酶等,广泛应用于食品加工、保健品、饲料加工等多个行业,市场份额领先,产品远销全球多个国家。网站内容丰富,展示了公司的产品、解决方案、客户见证及企业实力,体现出较强的行业专业性和市场竞争力。技术基础包括现代前端技术和百度分析工具,支持PC及移动端访问,具备良好的用户体验和SEO优化。安全方面,网站未显示HTTPS状态和安全头信息,且缺少隐私及Cookie政策,存在一定的合规风险。WHOIS信息缺失,域名注册状态不明,建议进一步核实域名合法性。整体而言,网站专业且内容详实,但安全和隐私合规方面有待加强。

Detected Technologies

HTML5CSS3JavaScriptjQuerySlick CarouselWOW.jsBaidu AnalyticsBaidu Push

🧠AI Business Intelligence

Technology stack, business insights, and market analysis powered by AI.

Business Intelligence

Market & Strategic Analysis

公司在酶制剂制造领域拥有深厚的技术积累和市场经验,凭借ISO9001、FSSC 22000、MUI清真及KLBD-Kosher等多项认证,建立了广泛的代理销售网络和客户基础。业务模式以定制化生产和技术服务为核心,满足多行业客户需求。通过丰富的产品线和技术方案,公司在国内市场占据领先地位,且积极拓展国际市场。网站展示了多样化的产品和解决方案,体现出强大的研发和生产能力。合作伙伴和友情链接覆盖多个相关行业,增强了业务生态。建议公司完善数字化安全和隐私合规体系,以提升客户信任和市场竞争力。

Extracted Contact Information

Marketing Intelligence Data

Email Addresses (1)

n*****@163.com

Phone Numbers (1)

400*******

Security Posture Analysis

Comprehensive Security Assessment

网站当前安全措施表现一般,未检测到HTTPS确认和安全HTTP头,缺少隐私政策和安全事件响应信息,可能存在合规风险。未发现明显的漏洞或敏感信息泄露,但WHOIS信息缺失增加了域名合法性风险。建议尽快部署HTTPS,完善安全头配置,公开隐私和Cookie政策,建立安全事件响应渠道,并定期进行安全审计和漏洞扫描,以提升整体安全成熟度和合规水平。

Strategic Recommendations

Priority Actions for Security Improvement

1

立即部署并强制使用HTTPS,确保数据传输安全。

Observations

AI-powered comprehensive website and business analysis.

AI-Enhanced Website Analysis

Business Insights

Company:

南宁东恒华道生物科技有限责任公司

Description:

广西南宁东恒华道酶制剂生产厂家,主营木瓜蛋白酶,碱性蛋白酶,中性蛋白酶,菠萝蛋白酶,果胶酶,纤维素酶及种类动植物蛋白水解专用复合酶,15年酶解技术沉淀,1000+酶解案例,可定制个性化酶解方案,生产线可满足国内外用酶需求,欢迎来电洽谈!

Key Services:
酶制剂生产酶解技术方案定制技术应用服务
Content Quality:

good

Branding:

consistent

Technical Stack

Technologies:
HTML5CSS3JavaScriptjQuerySlick CarouselWOW.jsBaidu AnalyticsBaidu Push
Platforms:
PCMobile (redirect to m.gxdhhd.com)
Performance:

moderate

Mobile:

good

Accessibility:

basic

SEO:

good

Security Assessment

Security Score:
60/100
Best Practices:
  • No exposed sensitive data in HTML
  • No visible vulnerable libraries

Analytics & Tracking

Services:
Baidu Analytics
Tracking Level:moderate
Privacy Compliance:poor

Advertising & Marketing

Tracking Pixels:
Baidu Analytics
Marketing Tools:
Baidu PushQQ Online Chat
Transparency Level:basic

Website Quality Assessment

Design Quality:good
User Experience:good
Content Relevance:good
Navigation Clarity:good
Professionalism:good
Trustworthiness:high

Key Observations

1

Website is fully accessible with rich content in Chinese language.

🛡️Security Headers

HTTP security headers analysis and recommendations.

Security Headers

HTTP security headers analysis

15/100
Score

Missing Strict-Transport-Security header

HIGH

Forces HTTPS connections

Missing X-Frame-Options header

HIGH

Prevents clickjacking attacks

Missing X-Content-Type-Options header

MEDIUM

Prevents MIME type sniffing

Missing Content-Security-Policy header

HIGH

Controls resources the browser is allowed to load

Missing X-XSS-Protection header

MEDIUM

Legacy XSS protection (deprecated but still recommended)

Missing Referrer-Policy header

LOW

Controls referrer information sent with requests

Missing Permissions-Policy header

MEDIUM

Controls browser features and APIs

Sensitive data may be cached

LOW

Cache-Control header should include "no-store" for sensitive pages

👤GDPR Compliance

Privacy and data protection assessment under GDPR regulations.

GDPR Compliance

Privacy and data protection assessment

50/100
Score

No Privacy Policy found

HIGH

GDPR requires a clear and accessible privacy policy

No Cookie Policy found

HIGH

GDPR requires clear information about cookie usage

No Cookie Consent Banner found

HIGH

GDPR requires explicit consent for non-essential cookies

GDPR Compliance Analysis

Privacy Policy0% confidence
Cookie Policy0% confidence
Contact Information Found90% confidence
emailphone

🛡️NIS2 Compliance

Network & Information Security Directive compliance assessment.

NIS2 Compliance

Network & Information Security Directive

2/100
Score

No information security framework found

HIGH

NIS2 requires documented cybersecurity and information security measures

No vulnerability disclosure policy

MEDIUM

NIS2 encourages coordinated vulnerability disclosure

No security policy documentation found

HIGH

NIS2 requires documented cybersecurity governance and risk management

No incident response procedures found

HIGH

NIS2 requires documented incident response and business continuity plans

No business continuity planning found

MEDIUM

NIS2 emphasizes operational resilience and business continuity

No security contact information

HIGH

NIS2 requires clear incident reporting channels

No vulnerability reporting mechanism

MEDIUM

Clear vulnerability reporting supports coordinated disclosure

No NIS2 reference found

LOW

Consider explicitly mentioning NIS2 compliance efforts

Critical sector without clear security compliance

HIGH

Detected sectors: energy, digital

📧Email Security

SPF, DKIM, and DMARC validation and email security assessment.

Email Security

SPF, DKIM, and DMARC validation

85/100
Score

No DKIM record found

MEDIUM

DKIM adds cryptographic signatures to emails

SPF
Sender Policy Framework
DKIM
DomainKeys Identified Mail
DMARC
Domain-based Message Authentication
MX Records
Mail Exchange Records
BIMI
Brand Indicators
MTA-STS
Mail Transfer Agent Security
TLS-RPT
TLS Reporting
DNSSEC
DNS Security
DMARC Details
Policy:none
MTA-STS Details

🏆SSL/TLS Security

Certificate validity and encryption analysis.

SSL/TLS Security

Certificate validity and encryption analysis

90/100
Score

Mixed Content Detected

MEDIUM

23 resources loaded over insecure HTTP

Partial SSL/TLS Assessment

LOW

Completed 2 of 4 security checks due to time constraints

Certificate Details

Subject:www.gxdhhd.com
Issuer:Encryption Everywhere DV TLS CA - G2
Valid Until:7/20/2026 (352 days)
SANs:www.gxdhhd.com, gxdhhd.com

OCSP Status

OCSP Stapling Disabled

📊DNS Health

DNS configuration and security assessment.

DNS Health

DNS configuration and security assessment

85/100
Score

DNSSEC Not Enabled

MEDIUM

DNSSEC is not configured for this domain

CAA Records Not Configured

LOW

Certificate Authority Authorization (CAA) records not found

DNS Records

A Records:47.105.103.162
Name Servers:
ns1.35.netDNS only
ns2.35.netDNS only
ns3.35.netDNS only
ns4.35.netDNS only
MX Records:
10: mx02.mail.alibaba.com
5: mx01.mail.alibaba.com
SOA:Serial: 2025052102, TTL: 3600s

DNSSEC Status

DNSSEC Not Enabled

DNS Performance

Resolution Time:441ms

Network Security

Port scanning and network exposure analysis.

Network Security

Port scanning and network exposure analysis

20/100
Score

High-Risk Service Exposed: FTP

HIGH

Port 21 (FTP) is publicly accessible - FTP - Often unencrypted file transfer

🔧Technical Analysis

Detailed technical findings and analysis from AI assessment.

Technical Analysis

Comprehensive security assessment findings

Additional Findings

网站采用标准HTML5结构,使用CSS3和JavaScript库(如jQuery、Slick Carousel、WOW.js)实现动态效果和响应式设计。集成百度统计和百度推送服务,支持SEO和用户行为分析。移动端自动重定向至专门的移动站点,提升移动用户体验。页面加载速度适中,结构清晰,导航合理。未检测到使用主流CMS,可能为定制开发。缺少安全头和HTTPS信息,存在技术改进空间。整体技术架构稳定,适合中型制造企业的数字化需求。
Analyze Another Website