Skip to main content

Is lifescienceopenspace.com a Scam? Security Check Results - Klaster LifeScience Krakow Reviews

lifescienceopenspace.com favicon

Is lifescienceopenspace.com Safe? Security Analysis for Klaster LifeScience Krakow

Check if lifescienceopenspace.com is a scam or legitimate. Free security scan and reviews.

HealthcareN/asmall
JavaScriptReactCSSHTML
Analyzed 8/4/2025Completed 12:29:38 PM
53
Security Score
MEDIUM RISK

AI Summary

The website 'LSOS Collaboration Platform' is managed by Klaster LifeScience Krakow and serves as an open collaboration platform aimed at promoting innovation and entrepreneurship in health and quality of life sectors. It targets innovators, entrepreneurs, and community members interested in life sciences. The platform offers services such as community connection, event participation, project collaboration, and partner discovery. The market position is niche, focusing on life sciences innovation. Technically, the website is built using modern JavaScript technologies including React and loads resources from the Innoloft platform. The site appears to have moderate performance and good mobile optimization but lacks visible accessibility features and comprehensive SEO optimization. The HTML snapshot shows minimal content with a loading spinner, indicating possible dynamic content loading or incomplete snapshot. From a security perspective, no HTTPS or security headers information is available in the provided data. There are no visible privacy, cookie, or terms of service policies, nor contact information for security or data protection. The WHOIS data is unavailable, which raises concerns about domain legitimacy and trustworthiness. No vulnerabilities or security best practices are evident from the data. Overall, the website shows a basic level of professionalism and technical implementation but lacks critical security and privacy compliance elements. The domain registration status is unclear, which impacts trust. Strategic improvements in security posture, privacy policies, and transparency are recommended to enhance credibility and user trust.

Detected Technologies

JavaScriptReactCSSHTML

🧠AI Business Intelligence

Technology stack, business insights, and market analysis powered by AI.

Business Intelligence

Market & Strategic Analysis

The platform operates in the healthcare sector with a focus on life sciences innovation and entrepreneurship. It leverages a collaboration model to connect stakeholders and facilitate innovation projects. The business model is centered on community engagement and providing a digital space for networking and resource sharing. The company behind the platform, Klaster LifeScience Krakow, appears to be a small entity focused on regional innovation promotion. There is no evidence of large-scale commercial operations or extensive partnerships. The platform's reliance on Innoloft technology suggests a partnership or service relationship. Growth indicators and revenue streams are not discernible from the data. The lack of visible contact and policy information may limit user trust and adoption.

Security Posture Analysis

Comprehensive Security Assessment

The security posture is weak due to the absence of visible HTTPS enforcement confirmation, lack of security headers, and missing privacy and cookie policies. No incident response or vulnerability disclosure information is provided. The WHOIS data absence further reduces trust in domain legitimacy. There is no evidence of compliance with GDPR or other data protection frameworks. The site does not expose sensitive data or show signs of vulnerabilities in the provided snapshot, but the lack of security best practices is a concern. Incident response readiness and security culture indicators are not observable. Overall, the security maturity level is low, and significant improvements are needed to meet standard compliance and security expectations.

Strategic Recommendations

Priority Actions for Security Improvement

1

Implement HTTPS with a valid SSL/TLS certificate and verify configuration.

Observations

AI-powered comprehensive website and business analysis.

AI-Enhanced Website Analysis

Business Insights

Company:

Klaster LifeScience Krakow

Description:

LSOS is a new, open collaboration platform managed by Klaster LifeScience Krakow. It is an instrument for promoting innovation and entrepreneurship in the areas of health and quality of life. Here you can connect with community members, participate in events and projects, find partners, services and products - everything you need to start or grow an innovative business.

Key Services:
Community connectionEvent participationProject collaborationPartner, service and product discovery
Content Quality:

basic

Branding:

consistent

Technical Stack

Technologies:
JavaScriptReactCSSHTML
Frameworks:
React
Platforms:
Innoloft
Performance:

moderate

Mobile:

good

Accessibility:

basic

SEO:

basic

Security Assessment

0

Analytics & Tracking

Tracking Level:minimal
Privacy Compliance:poor

Advertising & Marketing

Transparency Level:poor

Website Quality Assessment

Design Quality:basic
User Experience:basic
Content Relevance:basic
Navigation Clarity:basic
Professionalism:basic
Trustworthiness:moderate

Key Observations

1

Website content is minimal and mostly a loading spinner visible in HTML snapshot.

🛡️Security Headers

HTTP security headers analysis and recommendations.

Security Headers

HTTP security headers analysis

65/100
Score

Weak X-Content-Type-Options configuration

LOW

Current value: "nosniff, nosniff"

Missing Content-Security-Policy header

HIGH

Controls resources the browser is allowed to load

Missing Permissions-Policy header

MEDIUM

Controls browser features and APIs

Sensitive data may be cached

LOW

Cache-Control header should include "no-store" for sensitive pages

👤GDPR Compliance

Privacy and data protection assessment under GDPR regulations.

GDPR Compliance

Privacy and data protection assessment

50/100
Score

No Privacy Policy found

HIGH

GDPR requires a clear and accessible privacy policy

No Cookie Policy found

HIGH

GDPR requires clear information about cookie usage

No Cookie Consent Banner found

HIGH

GDPR requires explicit consent for non-essential cookies

GDPR Compliance Analysis

Privacy Policy0% confidence
Cookie Policy0% confidence
Contact Information Found90% confidence
phone

🛡️NIS2 Compliance

Network & Information Security Directive compliance assessment.

NIS2 Compliance

Network & Information Security Directive

17/100
Score

No information security framework found

HIGH

NIS2 requires documented cybersecurity and information security measures

No vulnerability disclosure policy

MEDIUM

NIS2 encourages coordinated vulnerability disclosure

No security policy documentation found

HIGH

NIS2 requires documented cybersecurity governance and risk management

No incident response procedures found

HIGH

NIS2 requires documented incident response and business continuity plans

No business continuity planning found

MEDIUM

NIS2 emphasizes operational resilience and business continuity

No security contact information

HIGH

NIS2 requires clear incident reporting channels

No vulnerability reporting mechanism

MEDIUM

Clear vulnerability reporting supports coordinated disclosure

No NIS2 reference found

LOW

Consider explicitly mentioning NIS2 compliance efforts

📧Email Security

SPF, DKIM, and DMARC validation and email security assessment.

Email Security

SPF, DKIM, and DMARC validation

60/100
Score

No DKIM record found

MEDIUM

DKIM adds cryptographic signatures to emails

No BIMI Record

LOW

BIMI displays brand logos in email clients

No MTA-STS Policy

MEDIUM

MTA-STS enforces TLS for email delivery

No TLS-RPT Record

LOW

TLS-RPT provides reporting for email TLS issues

No email authentication configured

CRITICAL

Domain is vulnerable to email spoofing

SPF
Sender Policy Framework
DKIM
DomainKeys Identified Mail
DMARC
Domain-based Message Authentication
MX Records
Mail Exchange Records
BIMI
Brand Indicators
MTA-STS
Mail Transfer Agent Security
TLS-RPT
TLS Reporting
DNSSEC
DNS Security

🏆SSL/TLS Security

Certificate validity and encryption analysis.

SSL/TLS Security

Certificate validity and encryption analysis

72/100
Score

Weak Protocols Supported

HIGH

Server supports weak protocols: TLSv1.1

OCSP Stapling Not Enabled

LOW

OCSP stapling improves performance and privacy

Certificate Transparency Not Implemented

LOW

Certificate is not logged in Certificate Transparency logs

SSL Certificate Expires Within 90 Days

MEDIUM

SSL certificate expires in 63 days

Partial SSL/TLS Assessment

LOW

Completed 3 of 4 security checks due to time constraints

Protocol Support

TLSv1.3TLSv1.2TLSv1.1

OCSP Status

OCSP Stapling Disabled

📊DNS Health

DNS configuration and security assessment.

DNS Health

DNS configuration and security assessment

75/100
Score

DNSSEC Not Enabled

MEDIUM

DNSSEC is not configured for this domain

CAA Records Not Configured

LOW

Certificate Authority Authorization (CAA) records not found

No DMARC Record

MEDIUM

DMARC policy not configured

DNS Records

A Records:3.125.75.36
Name Servers:
ns1.aftermarket.plDNS only
ns2.aftermarket.plDNS only
SOA:Serial: 2301271931, TTL: 3600s

DNSSEC Status

DNSSEC Not Enabled

DNS Performance

Resolution Time:55ms

Network Security

Port scanning and network exposure analysis.

Network Security

Port scanning and network exposure analysis

40/100
Score

Service Exposed: SSH

MEDIUM

Port 22 (SSH) is publicly accessible - SSH - Secure but can be brute-forced

🔧Technical Analysis

Detailed technical findings and analysis from AI assessment.

Technical Analysis

Comprehensive security assessment findings

Additional Findings

The website uses a modern React-based frontend with modular JavaScript and CSS loaded from a CDN (app-cdn.innoloft.com). Fonts are loaded from an external domain (fonts.loftos.io). The site uses CSS custom properties extensively for theming and styling. The HTML snapshot shows minimal static content, likely relying on client-side rendering. No CMS or backend platform is explicitly detected. Hosting provider is not identified from the data. Performance is moderate based on resource loading patterns. Mobile optimization is good due to responsive meta tags and CSS. Accessibility is basic with no ARIA landmarks or roles detected beyond minimal focus guards. SEO meta tags and Open Graph tags are present but limited. There is no evidence of technical debt but the lack of static content may impact SEO and user experience. Modernization opportunities include server-side rendering and enhanced accessibility features.
Analyze Another Website