Each technology is matched against a public fingerprint. Evidence is which part of the page or DNS matched; "implied" means another detected technology requires it. Confidence is the fingerprint's own certainty. Dates are when our scanner first and most recently observed it.
Technology
Evidence
Confidence
First seen
Last seen
ArvanCloud
HTTP header
high (100%)
28 Sept 2026
28 Sept 2026
DoubleClick Floodlight
script URL
high (100%)
28 Sept 2026
28 Sept 2026
eNamad
meta tag
high (100%)
28 Sept 2026
28 Sept 2026
Goftino
script URL, JS global
high (100%)
28 Sept 2026
28 Sept 2026
Google Analytics
script URL, cookie, JS global
high (100%)
28 Sept 2026
28 Sept 2026
Google Tag Manager
HTML, script URL, JS global
high (100%)
28 Sept 2026
28 Sept 2026
HSTS
HTTP header
high (100%)
28 Sept 2026
28 Sept 2026
HTTP/3
HTTP header
high (100%)
28 Sept 2026
28 Sept 2026
Loadable-Components
JS global, DOM
high (100%)
28 Sept 2026
28 Sept 2026
Lodash4.18.1
JS global
high (100%)
28 Sept 2026
28 Sept 2026
Matomo Analytics
inline script, JS global
high (100%)
28 Sept 2026
28 Sept 2026
Matomo Tag Manager
JS global
high (100%)
28 Sept 2026
28 Sept 2026
Open Graph
DOM
high (100%)
28 Sept 2026
28 Sept 2026
Priority Hints
DOM
high (100%)
28 Sept 2026
28 Sept 2026
Radix UI
CSS
high (100%)
28 Sept 2026
28 Sept 2026
React
HTML
high (100%)
28 Sept 2026
28 Sept 2026
Sentry
JS global
high (100%)
28 Sept 2026
28 Sept 2026
Tapsell
inline script
high (100%)
28 Sept 2026
28 Sept 2026
WebEngage6.0
script URL, JS global
high (100%)
28 Sept 2026
28 Sept 2026
Yektanet
JS global
high (100%)
28 Sept 2026
28 Sept 2026
Changes over time
No changes since we first indexed this site on 28 Sept 2026. We re-scan about monthly; additions and removals will appear here.
Security headers
C60 of 100 · 3 of 6 checks need attention
Response headers on the home page that tell browsers how to protect visitors, graded the way securityheaders.com does. They describe the site's own defences, not the technologies on it.
HTTPS enforcement (HSTS)Good · 20/20
Set for six months or more and covering subdomains. Adding preload lets browsers enforce it before the first visit.max-age=31104000; includeSubDomains
Content Security PolicyGood · 25/25
Set and restricts where scripts may come from, the strongest defence against injected content.frame-ancestors 'self' bimeh.com defaced.dev webcache.googleusercontent.com *.googleapis.com *.google.com google.com www.googletagmanager.com analytics.google.com
Clickjacking protectionGood · 15/15
Framing is controlled by the Content Security Policy.ALLOW-FROM bimeh.com, webcache.googleusercontent.com
MIME type sniffingMissing · 0/15
Not set. Add X-Content-Type-Options: nosniff so browsers never reinterpret files as scripts.
Referrer policyMissing · 0/15
Not set, so full page addresses may leak to other sites in the Referer header.
Browser feature permissionsMissing · 0/10
Not set. Embedded content inherits every browser feature; a Permissions-Policy header narrows that.
Other headers seen (2), not counted in the grade
Cross-origin isolation (COOP) · Optional. Isolates the window from pages that opened it; mostly matters for sites using SharedArrayBuffer.
Legacy XSS filter · Deprecated header; modern browsers ignore it and it could once be abused. A Content Security Policy replaces it.1; mode=block