Skip to main content

Is meijian.com a Scam? Security Check Results - 美间 Reviews

meijian.com favicon

Is meijian.com Safe? Security Analysis for 美间

Check if meijian.com is a scam or legitimate. Free security scan and reviews.

TechnologyChinamedium
JavaScriptReact (implied by styled-components usage)CDN usage (multiple CDN domains)Baidu AnalyticsMicrosoft Clarity+3 more
Analyzed 8/4/2025Completed 1:38:46 PM
61
Security Score
MEDIUM RISK

AI Summary

美间 is a professional online 2D cloud design platform specializing in home design marketing and sales presentations. It offers a vast library of licensed design materials, PPT templates, images, and AI-powered tools to facilitate quick and efficient design creation for designers and homeowners. The platform integrates advanced technologies such as AI for image enhancement, background removal, and marketing copy generation, positioning itself as a modern and innovative solution in the home design industry. Technically, the website employs modern JavaScript frameworks, multiple CDNs, and analytics tools, ensuring good performance and user experience. Security posture is solid with HTTPS enforcement and security headers, though explicit privacy and cookie policies are not clearly presented. The absence of WHOIS data for the domain is a notable concern, potentially impacting trust from a domain registration perspective. Overall, the platform appears legitimate and professional, serving a medium-sized business in the technology and e-commerce sectors within China.

Detected Technologies

JavaScriptReact (implied by styled-components usage)CDN usage (multiple CDN domains)Baidu AnalyticsMicrosoft ClarityTencent CaptchaNetease IM (instant messaging)Feishu Wiki links

🧠AI Business Intelligence

Technology stack, business insights, and market analysis powered by AI.

Business Intelligence

Market & Strategic Analysis

美间 targets designers and homeowners seeking efficient home design and marketing solutions. Its business model combines free access to a large repository of design assets with premium membership tiers offering enhanced features and content. The company leverages partnerships with kujiale.com and uses Feishu for internal documentation and tutorials, indicating a collaborative ecosystem. The platform's competitive advantage lies in its AI-assisted design tools and extensive template library, catering to a growing market for digital design solutions in home decoration and e-commerce. Revenue streams likely include membership fees and possibly commissions from affiliate marketing or sales. The company maintains a strong online presence with SEO optimizations and multiple verification tags for major Chinese search engines.

Extracted Contact Information

Marketing Intelligence Data

Phone Numbers (1)

057*******

Security Posture Analysis

Comprehensive Security Assessment

The website demonstrates a mature security posture with HTTPS enabled, use of security headers, and bot mitigation via Tencent Captcha. There is active monitoring for errors and performance, indicating proactive operational security. However, the lack of visible privacy and cookie policies, absence of a security.txt file, and no disclosed incident response contacts suggest gaps in compliance and transparency. No vulnerabilities or exposed sensitive data were detected in the analyzed content. The missing WHOIS data raises questions about domain registration transparency, which could be a risk factor. Overall, the security posture is good but could be improved with clearer compliance documentation and vulnerability disclosure mechanisms.

Strategic Recommendations

Priority Actions for Security Improvement

1

Publish a comprehensive privacy policy and cookie policy with clear consent mechanisms to enhance GDPR and privacy compliance.

Observations

AI-powered comprehensive website and business analysis.

AI-Enhanced Website Analysis

Business Insights

Company:

美间

Description:

美间(www.meijian.com)是专注于家居设计营销谈单的网站,免费为设计师、业主提供海量正版设计素材、谈单PPT模板、图片素材、平面素材、彩平图、软装搭配素材、海报模板等,装修效果图一键再创作,让其10秒搞定设计方案、谈单PPT,并有高佣返现。美间设计,让家居设计更简单,更高效!

Key Services:
在线2D云设计平台海量正版设计素材谈单PPT模板图片及平面素材彩平图软装搭配素材海报模板装修效果图再创作AI辅助设计工具
Content Quality:

excellent

Branding:

consistent

Technical Stack

Technologies:
JavaScriptReact (implied by styled-components usage)CDN usage (multiple CDN domains)Baidu AnalyticsMicrosoft ClarityTencent CaptchaNetease IM (instant messaging)Feishu Wiki links
Frameworks:
React (inferred)Styled-components
Platforms:
WebPC ClientMobile App
Performance:

fast

Mobile:

good

Accessibility:

basic

SEO:

good

Security Assessment

Security Score:
85/100
Best Practices:
  • HTTPS enforced
  • No exposed sensitive data in HTML
  • Use of Tencent Captcha for bot prevention
  • Error and performance monitoring enabled

Analytics & Tracking

Services:
Baidu AnalyticsMicrosoft Clarity
Tracking Level:moderate
Privacy Compliance:basic

Advertising & Marketing

Tracking Pixels:
Baidu AnalyticsMicrosoft Clarity
Marketing Tools:
Tencent CaptchaFeishu Wiki for tutorials
Transparency Level:basic

Website Quality Assessment

Design Quality:excellent
User Experience:excellent
Content Relevance:excellent
Navigation Clarity:good
Professionalism:excellent
Trustworthiness:high

Key Observations

1

Website is a professional online 2D cloud design platform focused on home design and marketing materials.

🛡️Security Headers

HTTP security headers analysis and recommendations.

Security Headers

HTTP security headers analysis

15/100
Score

Missing Strict-Transport-Security header

HIGH

Forces HTTPS connections

Missing X-Frame-Options header

HIGH

Prevents clickjacking attacks

Missing X-Content-Type-Options header

MEDIUM

Prevents MIME type sniffing

Missing Content-Security-Policy header

HIGH

Controls resources the browser is allowed to load

Missing X-XSS-Protection header

MEDIUM

Legacy XSS protection (deprecated but still recommended)

Missing Referrer-Policy header

LOW

Controls referrer information sent with requests

Missing Permissions-Policy header

MEDIUM

Controls browser features and APIs

Sensitive data may be cached

LOW

Cache-Control header should include "no-store" for sensitive pages

👤GDPR Compliance

Privacy and data protection assessment under GDPR regulations.

GDPR Compliance

Privacy and data protection assessment

53/100
Score

No Cookie Policy found

HIGH

GDPR requires clear information about cookie usage

No Cookie Consent Banner found

HIGH

GDPR requires explicit consent for non-essential cookies

No Data Protection Officer mentioned

LOW

Large organizations may need to designate a DPO under GDPR

Privacy policy may not be GDPR compliant

MEDIUM

Privacy policy lacks explicit GDPR compliance elements

GDPR Compliance Analysis

Privacy Policy85% confidence
Cookie Policy0% confidence
Contact Information Found90% confidence
phone

🛡️NIS2 Compliance

Network & Information Security Directive compliance assessment.

NIS2 Compliance

Network & Information Security Directive

2/100
Score

No information security framework found

HIGH

NIS2 requires documented cybersecurity and information security measures

No vulnerability disclosure policy

MEDIUM

NIS2 encourages coordinated vulnerability disclosure

No security policy documentation found

HIGH

NIS2 requires documented cybersecurity governance and risk management

No incident response procedures found

HIGH

NIS2 requires documented incident response and business continuity plans

No business continuity planning found

MEDIUM

NIS2 emphasizes operational resilience and business continuity

No security contact information

HIGH

NIS2 requires clear incident reporting channels

No vulnerability reporting mechanism

MEDIUM

Clear vulnerability reporting supports coordinated disclosure

No NIS2 reference found

LOW

Consider explicitly mentioning NIS2 compliance efforts

Critical sector without clear security compliance

HIGH

Detected sectors: transport, digital

📧Email Security

SPF, DKIM, and DMARC validation and email security assessment.

Email Security

SPF, DKIM, and DMARC validation

60/100
Score

No DKIM record found

MEDIUM

DKIM adds cryptographic signatures to emails

No BIMI Record

LOW

BIMI displays brand logos in email clients

No MTA-STS Policy

MEDIUM

MTA-STS enforces TLS for email delivery

No TLS-RPT Record

LOW

TLS-RPT provides reporting for email TLS issues

No email authentication configured

CRITICAL

Domain is vulnerable to email spoofing

SPF
Sender Policy Framework
DKIM
DomainKeys Identified Mail
DMARC
Domain-based Message Authentication
MX Records
Mail Exchange Records
BIMI
Brand Indicators
MTA-STS
Mail Transfer Agent Security
TLS-RPT
TLS Reporting
DNSSEC
DNS Security

🏆SSL/TLS Security

Certificate validity and encryption analysis.

SSL/TLS Security

Certificate validity and encryption analysis

90/100
Score

Mixed Content Detected

MEDIUM

4 resources loaded over insecure HTTP

Partial SSL/TLS Assessment

LOW

Completed 2 of 4 security checks due to time constraints

Certificate Details

Subject:*.meijian.com
Issuer:TrustAsia RSA DV TLS CA G3
Valid Until:12/11/2025 (129 days)
SANs:*.meijian.com, meijian.com

OCSP Status

OCSP Stapling Disabled

📊DNS Health

DNS configuration and security assessment.

DNS Health

DNS configuration and security assessment

85/100
Score

DNSSEC Not Enabled

MEDIUM

DNSSEC is not configured for this domain

CAA Records Not Configured

LOW

Certificate Authority Authorization (CAA) records not found

DNS Records

A Records:121.5.99.24
Name Servers:
cold.dnspod.netDNS only
sunfish.dnspod.netDNS only

DNSSEC Status

DNSSEC Not Enabled

Network Security

Port scanning and network exposure analysis.

Network Security

Port scanning and network exposure analysis

100/100
Score

Good Network Security Posture

LOW

No unnecessary services detected on common risky ports

🔧Technical Analysis

Detailed technical findings and analysis from AI assessment.

Technical Analysis

Comprehensive security assessment findings

Additional Findings

The website uses a modern JavaScript stack, likely React with styled-components, supported by multiple CDN providers for media and static content delivery. It integrates analytics from Baidu and Microsoft Clarity, and uses Tencent Captcha for bot protection. The platform supports multiple environments (dev, prod_test, prod) and has mobile and desktop clients. Performance is optimized with prefetching and caching controls. However, no CMS is explicitly detected, suggesting a custom-built solution. The technical infrastructure is robust and scalable, suitable for a medium-sized digital design platform. Opportunities exist to enhance security headers and accessibility compliance.
Analyze Another Website