Each technology is matched against a public fingerprint. Evidence is which part of the page or DNS matched; "implied" means another detected technology requires it. Confidence is the fingerprint's own certainty. Dates are when our scanner first and most recently observed it.
Technology
Evidence
Confidence
First seen
Last seen
Bootstrap4.5.3
JS global
high (100%)
28 Sept 2026
28 Sept 2026
Cart Functionality
DOM
high (100%)
28 Sept 2026
28 Sept 2026
core-js3.6.5
JS global
high (100%)
28 Sept 2026
28 Sept 2026
DataTables1.10.12
JS global
high (100%)
28 Sept 2026
28 Sept 2026
eNamad
DOM
high (100%)
28 Sept 2026
28 Sept 2026
Font Awesome
DOM
high (100%)
28 Sept 2026
28 Sept 2026
Goftino
script URL
high (100%)
28 Sept 2026
28 Sept 2026
Hammer.js2.0.7
JS global
high (100%)
28 Sept 2026
28 Sept 2026
HTTP/3
HTTP header
high (100%)
28 Sept 2026
28 Sept 2026
jQuery1.12.4
JS global
high (100%)
28 Sept 2026
28 Sept 2026
LazySizes
JS global
high (100%)
28 Sept 2026
28 Sept 2026
Lightbox
JS global
high (100%)
28 Sept 2026
28 Sept 2026
Open Graph
DOM
high (100%)
28 Sept 2026
28 Sept 2026
Selectize
JS global
high (100%)
28 Sept 2026
28 Sept 2026
Webpack
JS global
high (100%)
28 Sept 2026
28 Sept 2026
WHMCS
JS global
high (100%)
28 Sept 2026
28 Sept 2026
Changes over time
No changes since we first indexed this site on 28 Sept 2026. We re-scan about monthly; additions and removals will appear here.
Security headers
F0 of 100 · 6 of 6 checks need attention
Response headers on the home page that tell browsers how to protect visitors, graded the way securityheaders.com does. They describe the site's own defences, not the technologies on it.
HTTPS enforcement (HSTS)Missing · 0/20
Not set. Browsers may still try plain HTTP on later visits; add Strict-Transport-Security with a max-age of at least six months.
Content Security PolicyMissing · 0/25
Not set. Without a policy, any injected script runs with full access to the page.
Clickjacking protectionMissing · 0/15
Not set. The page can be embedded invisibly on another site to trick clicks; add X-Frame-Options: DENY or a frame-ancestors directive.
MIME type sniffingMissing · 0/15
Not set. Add X-Content-Type-Options: nosniff so browsers never reinterpret files as scripts.
Referrer policyMissing · 0/15
Not set, so full page addresses may leak to other sites in the Referer header.
Browser feature permissionsMissing · 0/10
Not set. Embedded content inherits every browser feature; a Permissions-Policy header narrows that.
Other headers seen (1), not counted in the grade
Cross-origin isolation (COOP) · Optional. Isolates the window from pages that opened it; mostly matters for sites using SharedArrayBuffer.
Services behind the domain
Found in maralhost.com's DNS records rather than on the page: email, verification and other tools the organisation uses. A DNS record shows an association; it does not prove the service is still in active use.
Each technology is matched against a public fingerprint. Evidence is which part of the page or DNS matched; "implied" means another detected technology requires it. Confidence is the fingerprint's own certainty. Dates are when our scanner first and most recently observed it.