
Is szlmhz.com Safe? Security Analysis for 力美会展设计搭建公司
Check if szlmhz.com is a scam or legitimate. Free security scan and reviews.

AI Summary
The website szlmhz.com represents a professional exhibition booth design and construction company based in Shenzhen, China, founded in 2024. The company offers a range of services including booth design, booth construction, showroom design and construction, and event planning services for domestic and international clients. The website content is rich with case studies, client testimonials, and partner logos, indicating a medium-sized business with a solid market position in the manufacturing and exhibition services sector. Technically, the website employs modern JavaScript libraries such as jQuery, Swiper.js, and AOS for animations and user experience enhancements. It uses Baidu Analytics for user tracking and is hosted under a registrar known as Xin Net Technology Corporation. The site is mobile optimized and has good SEO practices but lacks some accessibility features and security headers. From a security perspective, the website uses HTTPS with a good SSL configuration but lacks DNSSEC and important security headers. There are no visible vulnerabilities or exposed sensitive data. However, the absence of privacy and cookie policies, as well as incident response information, indicates compliance gaps, especially regarding GDPR and other data protection regulations. Overall, the website is safe for general audiences, professionally designed, and functional. The domain is newly registered but consistent with the business's founding date. Strategic improvements in privacy compliance, security headers, and incident response transparency are recommended to enhance trust and security posture.
Detected Technologies
🧠AI Business Intelligence
Technology stack, business insights, and market analysis powered by AI.
Business Intelligence
Market & Strategic Analysis
The company operates in the exhibition booth design and construction industry, targeting corporate clients and exhibitors at trade shows and exhibitions. It leverages a business model focused on providing end-to-end design and construction services, including digital and multimedia marketing solutions. The company demonstrates competitive advantages through its extensive project portfolio, industry certifications, and partnerships. Revenue streams likely come from project contracts for booth design, construction, and event services. The partnership ecosystem includes multiple industry players, although no specific partner domains were identified. Growth indicators include recent domain registration and active content updates. The company maintains a consistent brand presence and targets a primarily Chinese market with global outreach.
Extracted Contact Information
Marketing Intelligence Data
Phone Numbers (2)
Security Posture Analysis
Comprehensive Security Assessment
The website exhibits a moderate security maturity level with HTTPS enabled and no obvious vulnerabilities. However, the lack of DNSSEC, security headers (such as Content-Security-Policy, X-Frame-Options), and absence of published security policies or incident response contacts represent gaps. There is no evidence of GDPR compliance mechanisms such as cookie consent banners or privacy policies. The use of third-party analytics (Baidu Analytics) without clear privacy disclosures may pose compliance risks. The security culture appears basic, with room for improvement in transparency and technical controls to protect user data and enhance trust.
Strategic Recommendations
Priority Actions for Security Improvement
Enable DNSSEC on the domain to improve DNS security and prevent spoofing.
✨Observations
AI-powered comprehensive website and business analysis.
AI-Enhanced Website Analysis
Business Insights
力美会展设计搭建公司
深圳展台搭建,深圳展台设计首选【深圳展台设计搭建公司Szlmhz.com】一家专业从事深圳展台搭建,深圳展台设计的展台设计搭建公司,同时提供国内外多行业的展台搭建和展台设计服务。
good
consistent
Technical Stack
moderate
good
basic
good
Security Assessment
- HTTPS enabled
- No exposed sensitive data in HTML
- No visible vulnerable libraries
Analytics & Tracking
Advertising & Marketing
Website Quality Assessment
Key Observations
Website is fully accessible with rich content and multimedia
🛡️Security Headers
HTTP security headers analysis and recommendations.
Security Headers
HTTP security headers analysis
Weak X-Frame-Options configuration
LOWCurrent value: "SAMEORIGIN;"
Weak X-Content-Type-Options configuration
LOWCurrent value: "nosniff;"
Missing Referrer-Policy header
LOWControls referrer information sent with requests
Missing Permissions-Policy header
MEDIUMControls browser features and APIs
👤GDPR Compliance
Privacy and data protection assessment under GDPR regulations.
GDPR Compliance
Privacy and data protection assessment
No Privacy Policy found
HIGHGDPR requires a clear and accessible privacy policy
No Cookie Policy found
HIGHGDPR requires clear information about cookie usage
No Cookie Consent Banner found
HIGHGDPR requires explicit consent for non-essential cookies
GDPR Compliance Analysis
🛡️NIS2 Compliance
Network & Information Security Directive compliance assessment.
NIS2 Compliance
Network & Information Security Directive
No information security framework found
HIGHNIS2 requires documented cybersecurity and information security measures
No vulnerability disclosure policy
MEDIUMNIS2 encourages coordinated vulnerability disclosure
No security policy documentation found
HIGHNIS2 requires documented cybersecurity governance and risk management
No incident response procedures found
HIGHNIS2 requires documented incident response and business continuity plans
No business continuity planning found
MEDIUMNIS2 emphasizes operational resilience and business continuity
No security contact information
HIGHNIS2 requires clear incident reporting channels
No vulnerability reporting mechanism
MEDIUMClear vulnerability reporting supports coordinated disclosure
No NIS2 reference found
LOWConsider explicitly mentioning NIS2 compliance efforts
Critical sector without clear security compliance
HIGHDetected sectors: transport, digital
📧Email Security
SPF, DKIM, and DMARC validation and email security assessment.
Email Security
SPF, DKIM, and DMARC validation
No DKIM record found
MEDIUMDKIM adds cryptographic signatures to emails
No BIMI Record
LOWBIMI displays brand logos in email clients
No MTA-STS Policy
MEDIUMMTA-STS enforces TLS for email delivery
No TLS-RPT Record
LOWTLS-RPT provides reporting for email TLS issues
No email authentication configured
CRITICALDomain is vulnerable to email spoofing
🏆SSL/TLS Security
Certificate validity and encryption analysis.
SSL/TLS Security
Certificate validity and encryption analysis
Unable to retrieve SSL certificate
CRITICALCould not establish secure connection to retrieve certificate information
Mixed Content Detected
MEDIUM25 resources loaded over insecure HTTP
OCSP Status
📊DNS Health
DNS configuration and security assessment.
DNS Health
DNS configuration and security assessment
DNSSEC Not Enabled
MEDIUMDNSSEC is not configured for this domain
CAA Records Not Configured
LOWCertificate Authority Authorization (CAA) records not found
No DMARC Record
MEDIUMDMARC policy not configured
DNS Records
DNSSEC Status
⚡Network Security
Port scanning and network exposure analysis.
Network Security
Port scanning and network exposure analysis
High-Risk Service Exposed: FTP
HIGHPort 21 (FTP) is publicly accessible - FTP - Often unencrypted file transfer
Service Exposed: SSH
MEDIUMPort 22 (SSH) is publicly accessible - SSH - Secure but can be brute-forced
Critical Service Exposed: MySQL
CRITICALPort 3306 (MySQL) is publicly accessible - MySQL - Database server
🔧Technical Analysis
Detailed technical findings and analysis from AI assessment.
Technical Analysis
Comprehensive security assessment findings