Security Analysis Results

gumroad.com

Comprehensive domain security and infrastructure analysis

Live Website Preview

website screenshot of https://gumroad.com/checkout?_gl=1*nf2quz*_ga*MTY1MDI1MTA0MS4xNzUwNjY4Mjgz*_ga_6LJN6D94N6*czE3NTA2NjgyODMkbzEkZzEkdDE3NTA2NjgzMTckajI2JGwwJGgw

No Security Risks Detected

This domain appears to be safe and secure

100%
Score

Disclaimer: This assessment is based on automated analysis of publicly available information. Results are for informational purposes only. For critical applications, consult security professionals.

Scan Complete

Refresh page after 10 minutes
for updated results

Page Information

Target URL
https://gumroad.com/checkout?_gl=1*nf2quz*_ga*MTY1MDI1MTA0MS4xNzUwNjY4Mjgz*_ga_6LJN6D94N6*czE3NTA2NjgyODMkbzEkZzEkdDE3NTA2NjgzMTckajI2JGwwJGgw
Page Title
Gumroad
gumroad.com faviconSite Favicon
Status
Active

Host Information

Domain
gumroad.com
Server
cloudflare
Country
United States
IP Address
104.18.243.99
ASN Information
13335
CLOUDFLARENET

Technologies

Gumroad logo
Gumroad
Ecommerce
Cart Functionality logo
Cart Functionality
Ecommerce
Ruby logo
Ruby
Programming languages
Ruby on Rails logo
Ruby on Rails
Web frameworks
Amazon Web Services logo
Amazon Web Services
PaaS
Stripe logo
Stripe
Payment processors
+10 more technologies detected

SSL Certificate

HTTPS Enabled
Secure
Certificate Issuer
E6
Valid From
2025-06-19 18:43:30
Valid Until
2025-09-17 18:43:29
Subject Name
gumroad.com

Performance Statistics

27
Total Requests
11
Domains
11
IP Addresses
1.11 MB
Transfer Size
Content Size4.54 MB

HTTP Headers

alt-svc
h3=":443"; ma=86400
cache-control
max-age=0, private, must-revalidate
cf-cache-status
DYNAMIC
cf-ray
9542c4e1bc19384b-MAD
content-encoding
br
content-security-policy
default-src https 'self'; child-src * data: blob:; connect-src 'self' blob: www.dropbox.com api.dropboxapi.com s3.amazonaws.com/gumroad s3.amazonaws.com/gumroad/ gumroad-public-storage.s3.amazonaws.com gumroad-public-storage.s3.amazonaws.com/ s3.amazonaws.com/gumroad-public-storage s3.amazonaws.com/gumroad-public-storage/ www.google.com www.gstatic.com *.facebook.com *.facebook.net *.google-analytics.com *.g.doubleclick.net *.googletagmanager.com analytics.google.com *.analytics.google.com files.gumroad.com/ d1bdh6c3ceakz5.cloudfront.net/ *.braintreegateway.com www.paypalobjects.com *.paypal.com *.braintree-api.com iframe.ly help.gumroad.com gumroad.com wss://cable.gumroad.com assets.gumroad.com; font-src * data: blob:; frame-src * data: blob:; img-src * data: blob:; media-src * data: blob:; object-src * data: blob:; script-src 'self' 'unsafe-eval' ajax.cloudflare.com static.cloudflareinsights.com js.stripe.com api.stripe.com connect-js.stripe.com *.braintreegateway.com *.braintree-api.com www.paypalobjects.com *.paypal.com *.google-analytics.com *.googletagmanager.com optimize.google.com www.googleadservices.com www.google.com www.gstatic.com *.facebook.net *.facebook.com www.dropbox.com s.ytimg.com cdn.iframe.ly platform.twitter.com cdn.jwplayer.com *.jwpcdn.com gumroad.us3.list-manage.com analytics.twitter.com help.gumroad.com unpkg.com/@lottiefiles/lottie-player@latest/ gumroad.com assets.gumroad.com 'nonce-xr7/CJC6/b0uMj5mxiMN7yxbteagqwuAirQD5aebV2k=' 'unsafe-inline'; style-src 'self' 'unsafe-inline' s.ytimg.com optimize.google.com fonts.googleapis.com assets.gumroad.com; worker-src * data: blob:
content-type
text/html; charset=utf-8
date
Mon, 23 Jun 2025 08:55:54 GMT
link
<https://assets.gumroad.com/packs/css/4977-d38e6327.css>; rel=preload; as=style; crossorigin=anonymous; nopush,<https://assets.gumroad.com/packs/css/design-e4205157.css>; rel=preload; as=style; crossorigin=anonymous; nopush,<https://assets.gumroad.com/assets/application-cbf244e9109e70d7b04497041636f00173a1e588f9b879b3a3ef11f8dfb86e5c.js>; rel=preload; as=script; nopush
server
cloudflare
server-timing
cfCacheStatus;desc="DYNAMIC" cfOrigin;dur=24,cfEdge;dur=109
strict-transport-security
max-age=31536000
vary
Origin
x-content-type-options
nosniff
x-download-options
noopen
x-gr
PROD
x-original-headers-class
Hash
x-permitted-cross-domain-policies
none
x-request-id
65470f3e-b785-44c0-9596-925dd8f1ef04
x-revision
e6d02e65dc4a
x-runtime
0.020665
x-xss-protection
1; mode=block
22 headers detected

Technology Stack Analysis

Gumroad

Gumroad

Ecommerce

Gumroad is a self-publishing digital marketplace platform to sell digital services such as books, memberships, courses and other digital services.

Cart Functionality

Cart Functionality

Ecommerce

Websites that have a shopping cart or checkout page, either using a known ecommerce platform or a custom solution.

Ruby

Ruby

Programming languages

Ruby is an open-source object-oriented programming language.

Ruby on Rails

Ruby on Rails

Web frameworks

Ruby on Rails is a server-side web application framework written in Ruby under the MIT License.

Amazon Web Services

Amazon Web Services

PaaS

Amazon Web Services (AWS) is a comprehensive cloud services platform offering compute power, database storage, content delivery and other functionality.

Stripe

Stripe

Payment processors

Stripe offers online payment processing for internet businesses as well as fraud prevention, invoicing and subscription management.

PayPal

PayPal

Payment processors

PayPal is an online payments system that supports online money transfers and serves as an electronic alternative to traditional paper methods like checks and money orders.

Atlassian Statuspage

Atlassian Statuspage

Issue trackersPaaS

Statuspage is a status and incident communication tool.

Sendgrid

Sendgrid

Email

SendGrid is a cloud-based email delivery platform for transactional and marketing emails.

reCAPTCHA

reCAPTCHA

Security

reCAPTCHA is a free service from Google that helps protect websites from spam and abuse.

HSTS

HSTS

Security

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

Google Analytics

Google Analytics

Analytics

Google Analytics is a free web analytics service that tracks and reports website traffic.

Cloudflare Browser Insights

Cloudflare Browser Insights

AnalyticsRUM

Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.

Cloudflare

Cloudflare

CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

Amazon S3

Amazon S3

CDN

Amazon S3 or Amazon Simple Storage Service is a service offered by Amazon Web Services (AWS) that provides object storage through a web service interface.

HTTP/3

HTTP/3

Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

Website Cookies 5

_ga

.gumroad.com

Secure None
Value
GA1.1.1355934063.1750668955
Expires:7/28/2026

_ga_6LJN6D94N6

.gumroad.com

Secure None
Value
GS2.1.s1750668955$o1$g0$t1750668955$j60$l0$h0
Expires:7/28/2026

_gumroad_app_session

.gumroad.com

HttpOnly Secure Lax
Value
[_gumroad_app_session redacted]
Expires:7/23/2025

_mkra_stck

gumroad.com

HttpOnly Secure None
Value
mysql%3A1750668959.972821
Expires:6/23/2025

_gumroad_guid

.gumroad.com

HttpOnly Secure Lax
Value
8c143054-809d-4687-a57e-f8dd891158e5
Expires:7/28/2026

External Links 0

Requested Domains 11

assets.gumroad.com

Unknown Type
No category information available

connect-js.stripe.com

Unknown Type
No category information available

connect.facebook.net

Unknown Type
No category information available

gumroad.com

Unknown Type
No category information available

js.stripe.com

Unknown Type
No category information available

region1.google-analytics.com

Unknown Type
No category information available

static.cloudflareinsights.com

Unknown Type
No category information available

www.facebook.com

Unknown Type
No category information available

www.google.com

Unknown Type
No category information available

www.googletagmanager.com

Unknown Type
No category information available

www.gstatic.com

Unknown Type
No category information available
LinkCheck

© 2025 LinkCheck. Secure domain analysis you can trust.