Security Analysis Results

haveibeenpwned.com

Comprehensive domain security and infrastructure analysis

Live Website Preview

website screenshot of https://haveibeenpwned.com/

No Security Risks Detected

This domain appears to be safe and secure

100%
Score

Disclaimer: This assessment is based on automated analysis of publicly available information. Results are for informational purposes only. For critical applications, consult security professionals.

Scan Information

Last checked:July 16, 2025 09:09:05
Scan Complete

Refresh page after 10 minutes
for updated results

Page Information

Target URL
https://haveibeenpwned.com/
Page Title
Have I Been Pwned: Check if your email address has been exposed in a data breach
haveibeenpwned.com faviconSite Favicon
Status
Active

Host Information

Domain
haveibeenpwned.com
Server
cloudflare
Country
United States
IP Address
104.16.123.33
ASN Information
13335
CLOUDFLARENET

Technologies

Bootstrap logo
Bootstrap
UI frameworks
Azure logo
Azure
PaaS
PayPal logo
PayPal
Payment processors
Zendesk logo
Zendesk
Documentation
Sendgrid logo
Sendgrid
Email
Mailgun logo
Mailgun
Email
+7 more technologies detected

SSL Certificate

HTTPS Enabled
Secure
Certificate Issuer
49m299 Gateway Proxy BISO MITM CA
Valid From
2025-07-15 02:22:33
Valid Until
2025-08-14 02:23:03
Subject Name
haveibeenpwned.com

Performance Statistics

31
Total Requests
7
Domains
7
IP Addresses
175.61 KB
Transfer Size
Content Size574.67 KB

HTTP Headers

age
2087
alt-svc
h3=":443"; ma=86400
cache-control
public,max-age=3600
cf-cache-status
HIT
cf-ray
96005c075d6070ed-MRS
cf-team
28b417d4f7000070ed046dc400000001
content-encoding
zstd
content-security-policy
script-src 'self' cdnjs.cloudflare.com az416426.vo.msecnd.net ajax.cloudflare.com challenges.cloudflare.com static.cloudflareinsights.com *.monitor.azure.com *.applicationinsights.io 'report-sha256' 'report-sample' 'sha256-8FjCYsNIDeaGMMoJ8foeQH/amGVkvIz6Yh0clxkQpAg=' 'nonce-WulEVNTIbiw+Vi8265EpUsjww5cCplxgutjPrTTZHb4='; upgrade-insecure-requests; default-src 'none'; base-uri 'self'; worker-src 'self'; style-src 'self' cdnjs.cloudflare.com api.fontshare.com 'report-sample' 'unsafe-inline'; img-src 'self' translate.google.com logos.haveibeenpwned.com haveibeenpwned.com cdnjs.cloudflare.com data:; font-src 'self' cdnjs.cloudflare.com cdn.fontshare.com fonts.scalar.com; frame-ancestors 'none'; frame-src challenges.cloudflare.com; form-action 'self' www.paypal.com billing.stripe.com checkout.stripe.com billing.haveibeenpwned.com; connect-src 'self' stage.haveibeenpwned.com api.pwnedpasswords.com stage-api.haveibeenpwned.com api.haveibeenpwned.com haveibeenpwned.com dc.services.visualstudio.com *.in.applicationinsights.azure.com *.monitor.azure.com www.google.com translate.googleapis.com; manifest-src 'self'; report-uri https://heimdall.report-uri.com/r/t/csp/enforce; report-to default
content-type
text/html; charset=utf-8
date
Wed, 16 Jul 2025 09:09:13 GMT
last-modified
Wed, 16 Jul 2025 08:27:20 GMT
nel
{"report_to":"default","max_age":31536000,"include_subdomains":true}
permissions-policy
accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=(), interest-cohort=()
referrer-policy
no-referrer-when-downgrade
report-to
{"group":"default","max_age":31536000,"endpoints":[{"url":"https://heimdall.report-uri.com/a/t/g"}],"include_subdomains":true}
reporting-endpoints
default="https://heimdall.report-uri.com/a/t/g"
request-context
appId=cid-v1:3665810e-aab5-4aa5-90b9-f46c41b757ec
server
cloudflare
server-timing
cfCacheStatus;desc="HIT" cfOrigin;dur=0,cfEdge;dur=20 cfReqDur;dur=1105.943
strict-transport-security
max-age=31536000; includeSubDomains; preload
vary
Accept-Encoding
x-content-type-options
nosniff
x-frame-options
DENY
23 headers detected

Technology Stack Analysis

Bootstrap

Bootstrap

UI frameworks

Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.

Azure

Azure

PaaS

Azure is a cloud computing service for building, testing, deploying, and managing applications and services through Microsoft-managed data centers.

PayPal

PayPal

Payment processors

PayPal is an online payments system that supports online money transfers and serves as an electronic alternative to traditional paper methods like checks and money orders.

Zendesk

Zendesk

DocumentationIssue trackers

Zendesk is a cloud-based help desk management solution offering customizable tools to build customer service portal, knowledge base and online communities.

+1 more categories
Sendgrid

Sendgrid

Email

SendGrid is a cloud-based email delivery platform for transactional and marketing emails.

Mailgun

Mailgun

Email

Mailgun is a transactional email API service for developers.

Keybase

Keybase

Security

Keybase is for keeping everyone's chats and files safe, from families to communities to companies. MacOS, Windows, Linux, iPhone, and Android.

HSTS

HSTS

Security

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

cdnjs

cdnjs

CDN

cdnjs is a free distributed JS library delivery service.

Cloudflare Browser Insights

Cloudflare Browser Insights

AnalyticsRUM

Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.

Cloudflare

Cloudflare

CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

Azure Monitor

Azure Monitor

AnalyticsPerformance

Azure Monitor collects monitoring telemetry from a variety of on-premises and Azure sources. Azure Monitor helps you maximise the availability and performance of your applications and services.

HTTP/3

HTTP/3

Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

Website Cookies 2

ai_user

haveibeenpwned.com

Secure None
Value
b9ixi8k7ZdJgzLF0gcjBNE|2025-07-16T09:09:25.278Z
Expires:7/16/2026

__cf_bm

.haveibeenpwned.com

HttpOnly Secure None
Value
VBRBa_XHZMCtr4qQ3dMInuJdTvCO8M6DfcKGtrnl3b4-1752656953-1.0.1.1-arDhRICKbP1W.1LIL6AcG.Qqye6rCTAlZfWUc8BhHk60kfxhfMxp3I9bLEukgzR75cwcYwFcEN901hnxQ0lUaDpqOab1kYDwZjK8a7u61Os
Expires:7/16/2025

External Links 7

Try 1Password

1password.com

Analyze
Target URL
https://1password.com/haveibeenpwned

Suggest a Feature

haveibeenpwned.uservoice.com

Analyze
Target URL
https://haveibeenpwned.uservoice.com/

Untitled Link

x.com

Analyze
Target URL
https://x.com/haveibeenpwned

Untitled Link

facebook.com

Analyze
Target URL
https://facebook.com/haveibeenpwned

Untitled Link

www.linkedin.com

Analyze
Target URL
https://www.linkedin.com/company/haveibeenpwned/

Untitled Link

github.com

Analyze
Target URL
https://github.com/HaveIBeenPwned

Untitled Link

infosec.exchange

Analyze
Target URL
https://infosec.exchange/@haveibeenpwned

Requested Domains 7

api.fontshare.com

Unknown Type
No category information available

cdn.fontshare.com

Unknown Type
No category information available

cdnjs.cloudflare.com

Unknown Type
No category information available

challenges.cloudflare.com

Unknown Type
No category information available

haveibeenpwned.com

Apex domain
Categories
Information SecurityInternet Communication

js.monitor.azure.com

Unknown Type
No category information available

static.cloudflareinsights.com

Unknown Type
No category information available
LinkCheck

© 2025 LinkCheck. Secure domain analysis you can trust.