Skip to main content

Is maiscrm.com a Scam? Security Check Results - 上海群之脉信息科技有限公司 Reviews

maiscrm.com favicon

Is maiscrm.com Safe? Security Analysis for 上海群之脉信息科技有限公司

Check if maiscrm.com is a scam or legitimate. Free security scan and reviews.

TechnologyChinamedium
JavaScriptVue.js (Nuxt.js)Ant Design (Antd)Tencent Map APIBaidu Analytics+1 more
Analyzed 8/2/2025Completed 4:38:11 AM
46
Security Score
HIGH RISK

AI Summary

群脉SCRM由上海群之脉信息科技有限公司运营,专注于提供SaaS级客户关系管理(CRM)解决方案,涵盖智能营销、私域流量运营、导购管理及分销渠道管理等多项服务。该公司定位为一站式SCRM定制解决方案服务商,面向企业客户,尤其是需要全渠道精准营销和新零售场景的中大型企业。网站内容丰富,设计专业,支持移动端访问,体现出较高的数字化成熟度。技术栈采用现代JavaScript框架(Nuxt.js、Ant Design)及腾讯和百度的API服务,显示出良好的技术基础和生态融合能力。安全方面,网站启用HTTPS,声称具备多层次安全体系和7x24小时实时防护,但缺少公开的安全政策和安全事件响应信息。WHOIS信息缺失,存在一定的信任风险。整体风险适中,建议完善隐私合规和安全披露以提升信任度。

Detected Technologies

JavaScriptVue.js (Nuxt.js)Ant Design (Antd)Tencent Map APIBaidu AnalyticsContainerization (mentioned in content)

🧠AI Business Intelligence

Technology stack, business insights, and market analysis powered by AI.

Business Intelligence

Market & Strategic Analysis

群脉SCRM在中国市场定位为专业的SCRM解决方案提供商,业务涵盖互动营销、智能营销、全域会员管理、智慧导购、私域零售及终端运营平台等。其商业模式为基于SaaS的企业服务,目标客户为需要数字化客户管理和营销自动化的企业。网站展示了多个行业客户案例,表明其在快消、母婴、美妆、医药健康等领域有一定市场渗透。合作伙伴网络广泛,涵盖数据分析、短信平台及行业报告等多个领域。缺乏公开的财务和成立年份信息,规模推测为中型企业。整体业务模式成熟,具备较强的市场竞争力和客户服务能力。

Extracted Contact Information

Marketing Intelligence Data

Email Addresses (1)

m*****@maiscrm.com

Phone Numbers (1)

400*******

Security Posture Analysis

Comprehensive Security Assessment

网站采用HTTPS保障数据传输安全,技术架构基于微服务和容器化部署,具备弹性扩容能力,声称服务超过2亿用户。多层次安全体系和7x24小时实时防护机制体现较高的安全意识。然而,缺少安全策略、事件响应联系方式及漏洞披露渠道,安全头部信息未见,存在合规和透明度不足问题。WHOIS信息缺失增加潜在风险。建议加强安全政策公开,完善安全事件响应流程,发布漏洞披露政策以提升安全成熟度和客户信任。

Strategic Recommendations

Priority Actions for Security Improvement

1

发布并公开详细的隐私政策和Cookie政策,确保GDPR及相关法规合规。

Observations

AI-powered comprehensive website and business analysis.

AI-Enhanced Website Analysis

Business Insights

Company:

上海群之脉信息科技有限公司

Description:

群脉SCRM是一款自主开发的SaaS级CRM客户关系管理平台,提供一站式SCRM定制解决方案,涵盖企业营销自动化,私域流量代运营,导购管理软件,分销渠道管理,门店智慧导购管理等功能,助力企业实现全渠道精准营销。

Key Services:
互动营销智能营销全域会员管理智慧导购私域零售终端运营平台用户数据平台
Content Quality:

good

Branding:

consistent

Technical Stack

Technologies:
JavaScriptVue.js (Nuxt.js)Ant Design (Antd)Tencent Map APIBaidu AnalyticsContainerization (mentioned in content)
Frameworks:
Nuxt.jsAnt Design
Platforms:
Web
Performance:

moderate

Mobile:

good

Accessibility:

basic

SEO:

good

Security Assessment

Security Score:
80/100
Best Practices:
  • HTTPS enforced
  • Multi-layer security system mentioned
  • 7x24 real-time protection claimed
  • Microservices architecture and containerization for stability

Analytics & Tracking

Services:
Baidu Analytics
Tracking Level:moderate
Privacy Compliance:poor

Advertising & Marketing

Tracking Pixels:
Baidu Analytics
Marketing Tools:
Tencent Map APIBaidu Analytics
Transparency Level:basic

Website Quality Assessment

Design Quality:good
User Experience:good
Content Relevance:good
Navigation Clarity:good
Professionalism:good
Trustworthiness:high

Key Observations

1

Website is fully accessible with rich content in Chinese language targeting enterprise clients.

🛡️Security Headers

HTTP security headers analysis and recommendations.

Security Headers

HTTP security headers analysis

30/100
Score

Missing X-Frame-Options header

HIGH

Prevents clickjacking attacks

Missing X-Content-Type-Options header

MEDIUM

Prevents MIME type sniffing

Missing Content-Security-Policy header

HIGH

Controls resources the browser is allowed to load

Missing X-XSS-Protection header

MEDIUM

Legacy XSS protection (deprecated but still recommended)

Missing Referrer-Policy header

LOW

Controls referrer information sent with requests

Missing Permissions-Policy header

MEDIUM

Controls browser features and APIs

Sensitive data may be cached

LOW

Cache-Control header should include "no-store" for sensitive pages

👤GDPR Compliance

Privacy and data protection assessment under GDPR regulations.

GDPR Compliance

Privacy and data protection assessment

50/100
Score

No Privacy Policy found

HIGH

GDPR requires a clear and accessible privacy policy

No Cookie Policy found

HIGH

GDPR requires clear information about cookie usage

No Cookie Consent Banner found

HIGH

GDPR requires explicit consent for non-essential cookies

GDPR Compliance Analysis

Privacy Policy0% confidence
Cookie Policy0% confidence
Contact Information Found90% confidence
emailphone

🛡️NIS2 Compliance

Network & Information Security Directive compliance assessment.

NIS2 Compliance

Network & Information Security Directive

2/100
Score

No information security framework found

HIGH

NIS2 requires documented cybersecurity and information security measures

No vulnerability disclosure policy

MEDIUM

NIS2 encourages coordinated vulnerability disclosure

No security policy documentation found

HIGH

NIS2 requires documented cybersecurity governance and risk management

No incident response procedures found

HIGH

NIS2 requires documented incident response and business continuity plans

No business continuity planning found

MEDIUM

NIS2 emphasizes operational resilience and business continuity

No security contact information

HIGH

NIS2 requires clear incident reporting channels

No vulnerability reporting mechanism

MEDIUM

Clear vulnerability reporting supports coordinated disclosure

No NIS2 reference found

LOW

Consider explicitly mentioning NIS2 compliance efforts

Critical sector without clear security compliance

HIGH

Detected sectors: transport, health

📧Email Security

SPF, DKIM, and DMARC validation and email security assessment.

Email Security

SPF, DKIM, and DMARC validation

70/100
Score

No DKIM record found

MEDIUM

DKIM adds cryptographic signatures to emails

No BIMI Record

LOW

BIMI displays brand logos in email clients

No MTA-STS Policy

MEDIUM

MTA-STS enforces TLS for email delivery

No TLS-RPT Record

LOW

TLS-RPT provides reporting for email TLS issues

SPF
Sender Policy Framework
DKIM
DomainKeys Identified Mail
DMARC
Domain-based Message Authentication
MX Records
Mail Exchange Records
BIMI
Brand Indicators
MTA-STS
Mail Transfer Agent Security
TLS-RPT
TLS Reporting
DNSSEC
DNS Security
SPF Details
Record:
v=spf1 include:spf.mxhichina.com -all
DNS Lookups:1/10
Policy:-all

🏆SSL/TLS Security

Certificate validity and encryption analysis.

SSL/TLS Security

Certificate validity and encryption analysis

67/100
Score

Weak Protocols Supported

HIGH

Server supports weak protocols: TLSv1.1

OCSP Stapling Not Enabled

LOW

OCSP stapling improves performance and privacy

Certificate Transparency Not Implemented

LOW

Certificate is not logged in Certificate Transparency logs

Mixed Content Detected

MEDIUM

6 resources loaded over insecure HTTP

Partial SSL/TLS Assessment

LOW

Completed 3 of 4 security checks due to time constraints

Protocol Support

TLSv1.3TLSv1.2TLSv1.1

OCSP Status

OCSP Stapling Disabled

📊DNS Health

DNS configuration and security assessment.

DNS Health

DNS configuration and security assessment

75/100
Score

DNSSEC Not Enabled

MEDIUM

DNSSEC is not configured for this domain

CAA Records Not Configured

LOW

Certificate Authority Authorization (CAA) records not found

No DMARC Record

MEDIUM

DMARC policy not configured

DNS Records

A Records:118.178.155.217
Name Servers:
vip3.alidns.comDNS only
vip4.alidns.comDNS only
MX Records:
5: mxn.mxhichina.com
10: mxw.mxhichina.com
SOA:Serial: 2025073015, TTL: 600s

DNSSEC Status

DNSSEC Not Enabled

DNS Performance

Resolution Time:250ms

SPF Analysis

SPF Record:
v=spf1 include:spf.mxhichina.com -all

Network Security

Port scanning and network exposure analysis.

Network Security

Port scanning and network exposure analysis

0/100
Score

Critical Service Exposed: MSSQL

CRITICAL

Port 1433 (MSSQL) is publicly accessible - MSSQL - Database server

Critical Service Exposed: PostgreSQL

CRITICAL

Port 5432 (PostgreSQL) is publicly accessible - PostgreSQL - Database server

🔧Technical Analysis

Detailed technical findings and analysis from AI assessment.

Technical Analysis

Comprehensive security assessment findings

Additional Findings

网站采用Nuxt.js和Ant Design构建,结合腾讯地图API和百度统计,技术栈现代且生态丰富。页面设计响应式,适配移动端,性能表现中等。缺少CMS迹象,可能为定制开发。未检测到明显技术债务,但缺少安全头部配置。网站内容结构清晰,SEO优化良好。建议提升无障碍支持和性能优化,完善安全配置以降低潜在风险。
Analyze Another Website