
Is receptomat.cz Safe? Security Analysis for receptomat.cz
Check if receptomat.cz is a scam or legitimate. Free security scan and reviews.
AI Summary
Receptomat.cz is a Czech healthcare-focused web and mobile application designed to assist patients in managing prescription medications efficiently. The platform offers services such as checking drug availability, reserving medicines at partner pharmacies, managing medication schedules, and requesting new prescriptions from doctors. The business targets patients and consumers of prescription drugs within the Czech Republic, operating on a freemium model with basic free features and potential premium services. The website is professionally designed with consistent branding and clear navigation, although the application is still in development as indicated by the 'coming soon' modal dialogs. Technically, the website employs modern frontend technologies including Bootstrap 5.3.3, jQuery 3.7.1, and integrates analytics and live chat tools such as Smartlook and Smartsupp. Hosting and domain registration are managed by REG-WEDOS, a Czech provider, consistent with the website's regional focus. The site is mobile-optimized and moderately performant but lacks advanced SEO and accessibility features. From a security perspective, the site uses HTTPS and asynchronous script loading but lacks visible security headers and published privacy or cookie policies, which are critical for GDPR compliance given the healthcare context. Forms collect user emails without visible CAPTCHA or bot protection. Analytics usage is moderate with session replay capabilities, raising privacy considerations. No critical vulnerabilities or suspicious WHOIS patterns were detected, and the domain age supports legitimacy. Overall, the website scores moderately well on content quality, technical implementation, and business credibility but scores low on privacy compliance and security posture. Strategic improvements in privacy policy publication, cookie consent mechanisms, security headers, and form protections are recommended to enhance trust and compliance.
Detected Technologies
🧠AI Business Intelligence
Technology stack, business insights, and market analysis powered by AI.
Business Intelligence
Market & Strategic Analysis
Receptomat.cz operates in the healthcare technology sector, providing a digital solution to streamline prescription medication procurement for patients. Its competitive advantage lies in integrating pharmacy availability data, online reservation, and prescription management into a single platform. The freemium business model allows broad user adoption with potential monetization through premium features. The target market is Czech patients requiring prescription medications, positioning the company as a key intermediary between pharmacies and consumers. The partnership ecosystem includes pharmacies but no explicit partner domains were identified. Growth indicators include ongoing app development and integration of user-friendly features. The company maintains a professional web presence but lacks comprehensive legal and privacy disclosures, which may impact user trust and regulatory compliance.
Extracted Contact Information
Marketing Intelligence Data
Email Addresses (1)
Security Posture Analysis
Comprehensive Security Assessment
The current security maturity level is moderate. The website employs HTTPS and uses reputable third-party analytics and chat services. However, the absence of security headers such as Content Security Policy, HSTS, and X-Frame-Options reduces protection against common web attacks. The lack of published privacy and cookie policies indicates compliance gaps with GDPR, especially critical in healthcare data handling. Forms collecting user emails do not show anti-bot measures, increasing risk of spam or abuse. No incident response or security contact information is provided. Overall, the security culture appears nascent, with room for improvement in formalizing policies, enhancing technical controls, and demonstrating compliance readiness.
Strategic Recommendations
Priority Actions for Security Improvement
Publish comprehensive privacy and cookie policies clearly accessible on the website.
✨Observations
AI-powered comprehensive website and business analysis.
AI-Enhanced Website Analysis
Business Insights
Receptomat is a mobile and web application designed to assist patients in purchasing prescription medications efficiently. It helps users find drug availability, reserve medicines at partner pharmacies, manage medication schedules, and request new prescriptions from doctors.
good
consistent
Technical Stack
moderate
good
basic
poor
Security Assessment
- Use of HTTPS (implied by URL https://)
- No exposed sensitive data in HTML
- Use of async loading for scripts
Analytics & Tracking
Advertising & Marketing
Website Quality Assessment
Key Observations
No privacy or cookie policies published despite GDPR relevance
🛡️Security Headers
HTTP security headers analysis and recommendations.
Security Headers
HTTP security headers analysis
Missing Content-Security-Policy header
HIGHControls resources the browser is allowed to load
Missing Referrer-Policy header
LOWControls referrer information sent with requests
Missing Permissions-Policy header
MEDIUMControls browser features and APIs
👤GDPR Compliance
Privacy and data protection assessment under GDPR regulations.
GDPR Compliance
Privacy and data protection assessment
No Privacy Policy found
HIGHGDPR requires a clear and accessible privacy policy
No Cookie Policy found
HIGHGDPR requires clear information about cookie usage
No Cookie Consent Banner found
HIGHGDPR requires explicit consent for non-essential cookies
EU business without adequate privacy measures
CRITICALEU businesses are subject to strict GDPR requirements
Third-party services without privacy policy
HIGHDetected services: Google Analytics, Cloudflare
GDPR Compliance Analysis
🛡️NIS2 Compliance
Network & Information Security Directive compliance assessment.
NIS2 Compliance
Network & Information Security Directive
No information security framework found
HIGHNIS2 requires documented cybersecurity and information security measures
No vulnerability disclosure policy
MEDIUMNIS2 encourages coordinated vulnerability disclosure
No security policy documentation found
HIGHNIS2 requires documented cybersecurity governance and risk management
No incident response procedures found
HIGHNIS2 requires documented incident response and business continuity plans
No business continuity planning found
MEDIUMNIS2 emphasizes operational resilience and business continuity
No security contact information
HIGHNIS2 requires clear incident reporting channels
No vulnerability reporting mechanism
MEDIUMClear vulnerability reporting supports coordinated disclosure
No NIS2 reference found
LOWConsider explicitly mentioning NIS2 compliance efforts
Critical sector without clear security compliance
HIGHDetected sectors: energy, transport, health, digital
📧Email Security
SPF, DKIM, and DMARC validation and email security assessment.
Email Security
SPF, DKIM, and DMARC validation
No DKIM record found
MEDIUMDKIM adds cryptographic signatures to emails
No BIMI Record
LOWBIMI displays brand logos in email clients
No MTA-STS Policy
MEDIUMMTA-STS enforces TLS for email delivery
No TLS-RPT Record
LOWTLS-RPT provides reporting for email TLS issues
No email authentication configured
CRITICALDomain is vulnerable to email spoofing
🏆SSL/TLS Security
Certificate validity and encryption analysis.
SSL/TLS Security
Certificate validity and encryption analysis
Weak Protocols Supported
HIGHServer supports weak protocols: TLSv1.1
OCSP Stapling Not Enabled
LOWOCSP stapling improves performance and privacy
Certificate Transparency Not Implemented
LOWCertificate is not logged in Certificate Transparency logs
SSL Certificate Expires Within 90 Days
MEDIUMSSL certificate expires in 81 days
Partial SSL/TLS Assessment
LOWCompleted 3 of 4 security checks due to time constraints
Protocol Support
OCSP Status
📊DNS Health
DNS configuration and security assessment.
DNS Health
DNS configuration and security assessment
DNSSEC Not Enabled
MEDIUMDNSSEC is not configured for this domain
CAA Records Not Configured
LOWCertificate Authority Authorization (CAA) records not found
No DMARC Record
MEDIUMDMARC policy not configured
Domain Registration Details
DNS Records
DNSSEC Status
DNS Performance
⚡Network Security
Port scanning and network exposure analysis.
Network Security
Port scanning and network exposure analysis
Service Exposed: SSH
MEDIUMPort 22 (SSH) is publicly accessible - SSH - Secure but can be brute-forced
🔧Technical Analysis
Detailed technical findings and analysis from AI assessment.
Technical Analysis
Comprehensive security assessment findings