Skip to main content

Is ynshangji.com a Scam? Security Check Results - ynshangji.com Reviews

Y

Is ynshangji.com Safe? Security Analysis for 云商网_供求信息发布,新产品发布的B2B商机网平台

Check if ynshangji.com is a scam or legitimate. Free security scan and reviews.

E-commerceChinasmall
JavaScriptiframe
Analyzed 8/2/2025Completed 11:29:07 AM
46
Security Score
HIGH RISK

AI Summary

The website ynshangji.com operates as a Chinese B2B e-commerce platform focused on supply and demand information publishing and product promotion services for small and medium enterprises. It provides free business opportunity websites and aims to assist SMEs in conducting B2B e-commerce. The platform appears to be established since 2009, supported by consistent WHOIS data and a long domain age. Technically, the site relies heavily on iframe embedding for content delivery, with JavaScript-based mobile detection and redirection. The use of Baidu Analytics indicates moderate user tracking, but no privacy or cookie consent mechanisms are present. Security posture is weak, with no detected HTTPS enforcement or security headers, and no contact or incident response information is provided, limiting transparency and trust. Overall, the site is functional but lacks modern security and privacy best practices.

Detected Technologies

JavaScriptiframe

🧠AI Business Intelligence

Technology stack, business insights, and market analysis powered by AI.

Business Intelligence

Market & Strategic Analysis

The business targets Chinese SMEs seeking B2B commerce opportunities, positioning itself as a platform for product and supply-demand information dissemination. Its business model centers on providing free website creation and product promotion services, likely monetized through advertising or premium services not visible in the provided data. The lack of visible contact information and certifications suggests a basic operational maturity. The platform's ecosystem includes subdomains for mobile and desktop versions, but no clear partnerships or subsidiaries are identified. Growth indicators and revenue streams are not discernible from the data. The company is registered with a Chinese registrar consistent with its market focus.

Security Posture Analysis

Comprehensive Security Assessment

Security maturity is low to moderate. The absence of HTTPS enforcement and security headers exposes the site to risks such as man-in-the-middle attacks and clickjacking, especially given the extensive use of iframes. No vulnerability disclosures, incident response contacts, or security policies are present, indicating limited preparedness for security incidents. User tracking via Baidu Analytics is implemented without visible privacy compliance, raising potential GDPR or local privacy regulation concerns. The site would benefit from implementing standard security headers, HTTPS enforcement, and transparent privacy and security policies to improve trust and compliance.

Strategic Recommendations

Priority Actions for Security Improvement

1

Implement HTTPS with strict enforcement and redirect all HTTP traffic to HTTPS.

Observations

AI-powered comprehensive website and business analysis.

AI-Enhanced Website Analysis

Business Insights

Description:

云商网整合企业产品信息、供求信息等B2B商机信息,为企业免费建商机网站,提供产品推广,打造云商网B2B电子商务平台,辅助中小企业开展B2B电子商务。

Key Services:
供求信息发布新产品发布免费建商机网站产品推广
Content Quality:

basic

Branding:

moderate

Technical Stack

Technologies:
JavaScriptiframe
Performance:

moderate

Mobile:

good

Accessibility:

basic

SEO:

poor

Security Assessment

Security Score:
40/100
Best Practices:
  • No exposed sensitive data detected
  • No vulnerable libraries detected

Analytics & Tracking

Services:
Baidu Analytics
Tracking Level:moderate
Privacy Compliance:poor

Advertising & Marketing

Tracking Pixels:
Baidu Analytics
Transparency Level:poor

Website Quality Assessment

Design Quality:basic
User Experience:basic
Content Relevance:basic
Navigation Clarity:poor
Professionalism:basic
Trustworthiness:low

Key Observations

1

Website uses iframe to embed main content from subdomains

🛡️Security Headers

HTTP security headers analysis and recommendations.

Security Headers

HTTP security headers analysis

0/100
Score
Analysis failed - content could not be retrieved

👤GDPR Compliance

Privacy and data protection assessment under GDPR regulations.

GDPR Compliance

Privacy and data protection assessment

50/100
Score

No Privacy Policy found

HIGH

GDPR requires a clear and accessible privacy policy

No Cookie Policy found

HIGH

GDPR requires clear information about cookie usage

No Cookie Consent Banner found

HIGH

GDPR requires explicit consent for non-essential cookies

GDPR Compliance Analysis

Privacy Policy0% confidence
Cookie Policy0% confidence
Contact Information Found90% confidence
phone

🛡️NIS2 Compliance

Network & Information Security Directive compliance assessment.

NIS2 Compliance

Network & Information Security Directive

2/100
Score

No information security framework found

HIGH

NIS2 requires documented cybersecurity and information security measures

No vulnerability disclosure policy

MEDIUM

NIS2 encourages coordinated vulnerability disclosure

No security policy documentation found

HIGH

NIS2 requires documented cybersecurity governance and risk management

No incident response procedures found

HIGH

NIS2 requires documented incident response and business continuity plans

No business continuity planning found

MEDIUM

NIS2 emphasizes operational resilience and business continuity

No security contact information

HIGH

NIS2 requires clear incident reporting channels

No vulnerability reporting mechanism

MEDIUM

Clear vulnerability reporting supports coordinated disclosure

No NIS2 reference found

LOW

Consider explicitly mentioning NIS2 compliance efforts

Critical sector without clear security compliance

HIGH

Detected sectors: transport

📧Email Security

SPF, DKIM, and DMARC validation and email security assessment.

Email Security

SPF, DKIM, and DMARC validation

75/100
Score

No DKIM record found

MEDIUM

DKIM adds cryptographic signatures to emails

No MTA-STS Policy

MEDIUM

MTA-STS enforces TLS for email delivery

SPF
Sender Policy Framework
DKIM
DomainKeys Identified Mail
DMARC
Domain-based Message Authentication
MX Records
Mail Exchange Records
BIMI
Brand Indicators
MTA-STS
Mail Transfer Agent Security
TLS-RPT
TLS Reporting
DNSSEC
DNS Security
DMARC Details
Policy:none

🏆SSL/TLS Security

Certificate validity and encryption analysis.

SSL/TLS Security

Certificate validity and encryption analysis

0/100
Score

Unable to retrieve SSL certificate

CRITICAL

Could not establish secure connection to retrieve certificate information

OCSP Status

OCSP Stapling Disabled

📊DNS Health

DNS configuration and security assessment.

DNS Health

DNS configuration and security assessment

85/100
Score

DNSSEC Not Enabled

MEDIUM

DNSSEC is not configured for this domain

CAA Records Not Configured

LOW

Certificate Authority Authorization (CAA) records not found

DNS Records

A Records:103.93.126.201, 103.93.126.202, 103.93.126.203
Name Servers:
e1.xundns.comDNS only
e2.xundns.comDNS only
MX Records:
10: mxdomain.qq.com

DNSSEC Status

DNSSEC Enabled

DNS Performance

Resolution Time:777ms

Network Security

Port scanning and network exposure analysis.

Network Security

Port scanning and network exposure analysis

100/100
Score

Good Network Security Posture

LOW

No unnecessary services detected on common risky ports

🔧Technical Analysis

Detailed technical findings and analysis from AI assessment.

Technical Analysis

Comprehensive security assessment findings

Additional Findings

The website uses basic JavaScript and iframe technology to deliver content, with mobile device detection scripts redirecting users to mobile-specific subdomains or external URLs. No modern frameworks or CMS platforms are detected. Performance is moderate but could be impacted by iframe usage and multiple external script calls. SEO optimization is poor due to meta robots tags set to noindex, nofollow, and no snippet, effectively blocking search engine indexing. Accessibility is basic with minimal ARIA or semantic HTML features. Hosting provider details are not explicit but the registrar is a Chinese company. The site lacks modern technical implementations such as responsive design without iframe embedding or progressive web app features.
Analyze Another Website