Skip to main content

Is pm7.top a Scam? Security Check Results - pm7.top Reviews

pm7.top favicon

Is pm7.top Safe? Security Analysis for 飞鱼搜剧 - 免费资源搜索平台|网盘搜索神器

Check if pm7.top is a scam or legitimate. Free security scan and reviews.

MediaN/asmall
Vue.jsElement PlusAxiosCSSJavaScript
Analyzed 8/2/2025Completed 4:35:50 AM
48
Security Score
HIGH RISK

AI Summary

The website www.89wd.com operates as a Chinese-language free resource search platform named 飞鱼搜剧, specializing in indexing and sharing cloud disk resources and short drama video content. It targets a general audience interested in short dramas and free video resources, positioning itself as a niche search engine for these media types. The business model appears to rely on providing free access to indexed content without hosting or uploading services. Technically, the site uses modern frontend technologies including Vue.js and Element Plus, with client-side JavaScript frameworks and asynchronous data fetching via Axios. The site is moderately optimized for mobile devices and provides a good user experience with clear navigation and relevant content. However, there is no evidence of a backend CMS or hosting provider from the data provided. Security posture is weak due to lack of visible HTTPS confirmation, absence of security headers, and no privacy or cookie policies. The site includes third-party tracking scripts from aizhantj.com, indicating moderate user tracking without clear privacy compliance. WHOIS data is missing or unavailable, which raises concerns about domain legitimacy and trustworthiness. Overall, the site is functional and content-rich but lacks critical security and compliance features, which poses risks for users and the business.

Detected Technologies

Vue.jsElement PlusAxiosCSSJavaScript

🧠AI Business Intelligence

Technology stack, business insights, and market analysis powered by AI.

Business Intelligence

Market & Strategic Analysis

The platform serves a niche market of users seeking free access to short drama and video resources via cloud disk indexing. It leverages a free access business model likely monetized through advertising or affiliate links, as indicated by external links and tracking scripts. The absence of company contact details, privacy policies, or terms of service suggests a low level of formal business transparency. The domain's WHOIS data absence is a significant concern, potentially indicating recent registration, privacy protection, or questionable legitimacy. The site’s partnership with pan.jiajingyu.com suggests some ecosystem relationships, but no formal partnerships or subsidiaries are evident. The platform’s growth potential depends on improving trust signals, compliance, and security posture to attract a broader user base and potential advertisers.

Security Posture Analysis

Comprehensive Security Assessment

The website lacks visible HTTPS confirmation in the provided data, which is a critical security deficiency. No security headers such as Content-Security-Policy, X-Frame-Options, or X-Content-Type-Options are detected, increasing risk of common web vulnerabilities. The absence of privacy and cookie policies indicates poor compliance with data protection regulations such as GDPR. No incident response or security contact information is provided, limiting the ability to report or respond to security incidents. The inclusion of third-party tracking scripts without clear user consent mechanisms further reduces privacy compliance. Overall, the security maturity is low, exposing users and the business to potential risks including data leakage, tracking without consent, and phishing or spoofing due to unclear domain legitimacy.

Strategic Recommendations

Priority Actions for Security Improvement

1

Implement HTTPS with a valid SSL/TLS certificate and enforce secure connections site-wide.

Observations

AI-powered comprehensive website and business analysis.

AI-Enhanced Website Analysis

Business Insights

Description:

飞鱼搜剧为您提供百万级网盘资源的免费分享,专注于打造顶尖的网盘搜索引擎,让您畅享短剧、影视资源无忧。

Key Services:
网盘资源搜索短剧资源分享影视资源索引
Content Quality:

good

Branding:

consistent

Technical Stack

Technologies:
Vue.jsElement PlusAxiosCSSJavaScript
Frameworks:
Vue.jsElement Plus
Performance:

moderate

Mobile:

good

Accessibility:

basic

SEO:

basic

Security Assessment

Security Score:
40/100
Best Practices:
  • Referrer policy set to 'never'

Analytics & Tracking

Services:
aizhantj.com tracking
Tracking Level:moderate
Privacy Compliance:poor

Advertising & Marketing

Tracking Pixels:
aizhantj.com
Marketing Tools:
aizhantj.com tracking script
Transparency Level:basic

Website Quality Assessment

Design Quality:good
User Experience:good
Content Relevance:good
Navigation Clarity:good
Professionalism:good
Trustworthiness:moderate

Key Observations

1

Website is a Chinese language free resource search platform focused on short dramas and cloud disk resources.

🛡️Security Headers

HTTP security headers analysis and recommendations.

Security Headers

HTTP security headers analysis

30/100
Score

Missing X-Frame-Options header

HIGH

Prevents clickjacking attacks

Missing X-Content-Type-Options header

MEDIUM

Prevents MIME type sniffing

Missing Content-Security-Policy header

HIGH

Controls resources the browser is allowed to load

Missing X-XSS-Protection header

MEDIUM

Legacy XSS protection (deprecated but still recommended)

Missing Referrer-Policy header

LOW

Controls referrer information sent with requests

Missing Permissions-Policy header

MEDIUM

Controls browser features and APIs

Sensitive data may be cached

LOW

Cache-Control header should include "no-store" for sensitive pages

👤GDPR Compliance

Privacy and data protection assessment under GDPR regulations.

GDPR Compliance

Privacy and data protection assessment

50/100
Score

No Privacy Policy found

HIGH

GDPR requires a clear and accessible privacy policy

No Cookie Policy found

HIGH

GDPR requires clear information about cookie usage

No Cookie Consent Banner found

HIGH

GDPR requires explicit consent for non-essential cookies

GDPR Compliance Analysis

Privacy Policy0% confidence
Cookie Policy0% confidence
Contact Information Found90% confidence
phone

🛡️NIS2 Compliance

Network & Information Security Directive compliance assessment.

NIS2 Compliance

Network & Information Security Directive

2/100
Score

No information security framework found

HIGH

NIS2 requires documented cybersecurity and information security measures

No vulnerability disclosure policy

MEDIUM

NIS2 encourages coordinated vulnerability disclosure

No security policy documentation found

HIGH

NIS2 requires documented cybersecurity governance and risk management

No incident response procedures found

HIGH

NIS2 requires documented incident response and business continuity plans

No business continuity planning found

MEDIUM

NIS2 emphasizes operational resilience and business continuity

No security contact information

HIGH

NIS2 requires clear incident reporting channels

No vulnerability reporting mechanism

MEDIUM

Clear vulnerability reporting supports coordinated disclosure

No NIS2 reference found

LOW

Consider explicitly mentioning NIS2 compliance efforts

Critical sector without clear security compliance

HIGH

Detected sectors: energy, transport, digital

📧Email Security

SPF, DKIM, and DMARC validation and email security assessment.

Email Security

SPF, DKIM, and DMARC validation

60/100
Score

No DKIM record found

MEDIUM

DKIM adds cryptographic signatures to emails

No BIMI Record

LOW

BIMI displays brand logos in email clients

No MTA-STS Policy

MEDIUM

MTA-STS enforces TLS for email delivery

No TLS-RPT Record

LOW

TLS-RPT provides reporting for email TLS issues

No email authentication configured

CRITICAL

Domain is vulnerable to email spoofing

SPF
Sender Policy Framework
DKIM
DomainKeys Identified Mail
DMARC
Domain-based Message Authentication
MX Records
Mail Exchange Records
BIMI
Brand Indicators
MTA-STS
Mail Transfer Agent Security
TLS-RPT
TLS Reporting
DNSSEC
DNS Security

🏆SSL/TLS Security

Certificate validity and encryption analysis.

SSL/TLS Security

Certificate validity and encryption analysis

72/100
Score

Weak Protocols Supported

HIGH

Server supports weak protocols: TLSv1.1

OCSP Stapling Not Enabled

LOW

OCSP stapling improves performance and privacy

Certificate Transparency Not Implemented

LOW

Certificate is not logged in Certificate Transparency logs

SSL Certificate Expires Within 90 Days

MEDIUM

SSL certificate expires in 56 days

Partial SSL/TLS Assessment

LOW

Completed 3 of 4 security checks due to time constraints

Protocol Support

TLSv1.3TLSv1.2TLSv1.1

OCSP Status

OCSP Stapling Disabled

📊DNS Health

DNS configuration and security assessment.

DNS Health

DNS configuration and security assessment

75/100
Score

DNSSEC Not Enabled

MEDIUM

DNSSEC is not configured for this domain

CAA Records Not Configured

LOW

Certificate Authority Authorization (CAA) records not found

No DMARC Record

MEDIUM

DMARC policy not configured

DNS Records

A Records:154.12.93.103
Name Servers:
cursor.dnspod.netDNS only
leopard.dnspod.netDNS only

DNSSEC Status

DNSSEC Not Enabled

Network Security

Port scanning and network exposure analysis.

Network Security

Port scanning and network exposure analysis

40/100
Score

Service Exposed: SSH

MEDIUM

Port 22 (SSH) is publicly accessible - SSH - Secure but can be brute-forced

🔧Technical Analysis

Detailed technical findings and analysis from AI assessment.

Technical Analysis

Comprehensive security assessment findings

Additional Findings

The website uses a modern JavaScript frontend stack with Vue.js and Element Plus UI framework, providing a responsive and interactive user experience. Axios is used for asynchronous HTTP requests. The site includes multiple CSS stylesheets for layout and design. The presence of third-party tracking scripts indicates integration of external analytics or marketing tools. No backend CMS or server-side technologies are identifiable from the provided data. Performance appears moderate with no explicit indicators of slow loading, but no advanced optimization techniques are evident. Accessibility features are basic, with some ARIA roles used in overlays. SEO optimization is basic, with meta keywords and description present but no Open Graph or structured data detected. Overall, the technical implementation is modern but could benefit from enhanced security and SEO improvements.
Analyze Another Website