Is zhanfubrowser.com Safe? Security Analysis for 深圳市美源企悦科技有限公司
Check if zhanfubrowser.com is a scam or legitimate. Free security scan and reviews.
AI Summary
站斧浏览器由深圳市美源企悦科技有限公司运营,专注于为跨境电商卖家提供安全、高效的店铺管理浏览器及相关云服务。其产品涵盖云设备、云号码和云桌面,支持多平台账号安全管理和团队协作,市场定位明确,拥有数万客户和多家知名杀毒软件认证。技术架构基于Vue.js,集成了Google Tag Manager和百度统计,整体性能适中,移动端优化基础。安全方面,网站启用HTTPS,但缺少部分安全头和DNSSEC,未见公开的安全政策和事件响应机制。整体业务信息透明,联系方式明确,信任指标较多,适合跨境电商用户使用。
Detected Technologies
🧠AI Business Intelligence
Technology stack, business insights, and market analysis powered by AI.
Business Intelligence
Market & Strategic Analysis
站斧浏览器在跨境电商安全管理领域具有较强竞争力,提供多账号防关联和安全访问解决方案,满足多平台、多店铺运营需求。其商业模式为SaaS及云服务,收入来源可能包括订阅费和增值服务。目标客户为跨境电商卖家及团队,合作伙伴生态丰富。公司成立于2021年,规模中等,品牌形象一致,客户评价积极,显示出良好的市场接受度和成长潜力。
Extracted Contact Information
Marketing Intelligence Data
Phone Numbers (2)
Security Posture Analysis
Comprehensive Security Assessment
网站安全基础良好,使用HTTPS保障数据传输安全,表单输入有基本验证,未发现敏感信息泄露。缺少安全响应政策和漏洞披露渠道,DNSSEC未启用,安全头部配置不足,存在提升空间。无恶意软件或钓鱼迹象,整体安全风险中等。建议加强安全策略公开,完善安全头配置,启用DNSSEC,并建立事件响应流程以提升安全成熟度。
Strategic Recommendations
Priority Actions for Security Improvement
启用DNSSEC以增强域名系统安全。
✨Observations
AI-powered comprehensive website and business analysis.
AI-Enhanced Website Analysis
Business Insights
深圳市美源企悦科技有限公司
站斧浏览器专注解决Amazon、Wish、eBay、Shopee、Lazada等跨境电商账号安全管理问题。为电商卖家提供专业的店铺安全提速运营方案,支持定制化提供服务,利用专业技术团队让跨境更安全高效。
good
consistent
Technical Stack
moderate
basic
basic
basic
Security Assessment
- HTTPS enforced
- No exposed sensitive data in HTML
- Form input validation for phone and SMS code
- Use of private browser to avoid tracking
Analytics & Tracking
Advertising & Marketing
Website Quality Assessment
Key Observations
Website is a professional SaaS platform targeting cross-border e-commerce sellers.
🛡️Security Headers
HTTP security headers analysis and recommendations.
Security Headers
HTTP security headers analysis
Missing Strict-Transport-Security header
HIGHForces HTTPS connections
Missing Content-Security-Policy header
HIGHControls resources the browser is allowed to load
Missing Referrer-Policy header
LOWControls referrer information sent with requests
Missing Permissions-Policy header
MEDIUMControls browser features and APIs
Sensitive data may be cached
LOWCache-Control header should include "no-store" for sensitive pages
👤GDPR Compliance
Privacy and data protection assessment under GDPR regulations.
GDPR Compliance
Privacy and data protection assessment
No Privacy Policy found
HIGHGDPR requires a clear and accessible privacy policy
No Cookie Policy found
HIGHGDPR requires clear information about cookie usage
No Cookie Consent Banner found
HIGHGDPR requires explicit consent for non-essential cookies
Third-party services without privacy policy
HIGHDetected services: Google Analytics
GDPR Compliance Analysis
🛡️NIS2 Compliance
Network & Information Security Directive compliance assessment.
NIS2 Compliance
Network & Information Security Directive
No information security framework found
HIGHNIS2 requires documented cybersecurity and information security measures
No vulnerability disclosure policy
MEDIUMNIS2 encourages coordinated vulnerability disclosure
No security policy documentation found
HIGHNIS2 requires documented cybersecurity governance and risk management
No incident response procedures found
HIGHNIS2 requires documented incident response and business continuity plans
No business continuity planning found
MEDIUMNIS2 emphasizes operational resilience and business continuity
No security contact information
HIGHNIS2 requires clear incident reporting channels
No vulnerability reporting mechanism
MEDIUMClear vulnerability reporting supports coordinated disclosure
No NIS2 reference found
LOWConsider explicitly mentioning NIS2 compliance efforts
📧Email Security
SPF, DKIM, and DMARC validation and email security assessment.
Email Security
SPF, DKIM, and DMARC validation
No DKIM record found
MEDIUMDKIM adds cryptographic signatures to emails
No BIMI Record
LOWBIMI displays brand logos in email clients
No MTA-STS Policy
MEDIUMMTA-STS enforces TLS for email delivery
No TLS-RPT Record
LOWTLS-RPT provides reporting for email TLS issues
SPF Details
🏆SSL/TLS Security
Certificate validity and encryption analysis.
SSL/TLS Security
Certificate validity and encryption analysis
Weak Protocols Supported
HIGHServer supports weak protocols: TLSv1.1
OCSP Stapling Not Enabled
LOWOCSP stapling improves performance and privacy
Certificate Transparency Not Implemented
LOWCertificate is not logged in Certificate Transparency logs
SSL Certificate Expires Within 90 Days
MEDIUMSSL certificate expires in 47 days
HSTS Not Enabled
MEDIUMHTTP Strict Transport Security (HSTS) is not configured
Protocol Support
OCSP Status
📊DNS Health
DNS configuration and security assessment.
DNS Health
DNS configuration and security assessment
DNSSEC Not Enabled
MEDIUMDNSSEC is not configured for this domain
CAA Records Not Configured
LOWCertificate Authority Authorization (CAA) records not found
Domain Transfer Lock Not Enabled
MEDIUMDomain can be transferred without authorization
Domain Delete Lock Not Enabled
LOWDomain can be deleted without additional verification
No DMARC Record
MEDIUMDMARC policy not configured
Domain Registration Details
- •No domain protection locks enabled
DNS Records
DNSSEC Status
SPF Analysis
⚡Network Security
Port scanning and network exposure analysis.
Network Security
Port scanning and network exposure analysis
Good Network Security Posture
LOWNo unnecessary services detected on common risky ports
🔧Technical Analysis
Detailed technical findings and analysis from AI assessment.
Technical Analysis
Comprehensive security assessment findings