New: The State of Indie Launches: June 2026. Who adopts a piece of infrastructure tells you how new it is. Read

← Back to browse

BingX Referral Code

Crypto Trading Made Easy. Buy and sell with BingX, a secure platform that makes it easy to trade and store cryptocurrency.

Crypto

Added July 4, 2026 · Last analysed July 4, 2026 · via · 64% unique tagline

StackScope is a free public catalogue of indie launches. We find launches on Product Hunt, Hacker News and similar feeds, then crawl each site to detect its tech stack and score it for launch readiness: DNS, security headers, SEO basics. This page is what we saw on 4 July 2026; the live site may have changed since.

BingX Referral Code is largely in shape, with a thorough launch checklist, well-configured email security, and clean crawl signals. Visible gaps: missing Referrer-Policy and Permissions-Policy, incomplete legal pages, and tracking cookies set before any opt-in.

Launched on Product Hunt on July 4, 2026. The site is served through AWS CloudFront, with a domain registered in 2015. The crawl picked up 50 technologies on this site, covering advertising, analytics, security, and social embeds. The stack includes Apple Sign In, LINE LIFF, and Nuxt.

For context, it's one of only 4 launches we've crawled running LINE LIFF and more locked down than the typical Product Hunt launch.

If you own this site, refresh the snapshot and see the full fix list any time →

Vibe Score 5 · Few AI signals
How much the site looks AI-generated. Informational pattern-match signal, not a verdict. Does not feed the StackScope Score. See which fingerprints fired →

Tech Stack (50) · Scale-up stack

Email
Business email Google Workspace
Lark Suite Email
Email marketing SendPulse
Transactional email Amazon SES
Build & Framework
Auth Apple Sign In (3)
Framework LINE LIFF
Vue.js
JavaScript library DOMPurify
Localization Crowdin
Meta-framework Nuxt
Video YouTube
Commerce & Payments
Finance MQL5
TradingView
Payments Advcash
Mercuryo
Business Tools
Chat Zendesk (2)
Zendesk Chat
Collaboration Lark Suite (2)
Fraud prevention FingerprintJS

Infrastructure

Network
AS16509 · US
DNS
Cloudflare DNS
Authoritative nameserver
DNSSEC
Not enabled
DNS responses unsigned. Cache-poisoning vulnerable.
Green hosting
Not green hosted
No green-energy record. Data from The Green Web Foundation.
SSL Certificate
Amazon
Valid 24 Feb 2026 to 9 Sep 2026
Certificate as captured in this snapshot, not a live check.
Domain Age
11.2 years
Registered Apr 2015 · Amazon Registrar, Inc.

Email Security

SPF -all Strict (-all). Strong.
?
DKIM Not detected at common selectors. Your provider may use a custom one.
DMARC p=quarantine Quarantine (moderate)
?
MTA-STS Not deployed. Mail to your domain can be downgraded to plaintext en route.
?
TLS-RPT Not configured. You won't hear about silent SMTP TLS handshake failures.

Storage (64)

Cookies (28)
NameLifetimeDetected as
afUserId 1y AppsFlyer
AF_SYNC 6d AppsFlyer
device_level 29d -
fcd96aee95037d16 session -
guest_id 1y X (Twitter) Ads
guest_id_ads 1y X (Twitter) Ads
guest_id_marketing 1y X (Twitter) Ads
locale 1y -
muc_ads 1y X (Twitter) Ads
network_delay session -
personalization_id 1y X (Twitter) Ads
ttcsid 2mo TikTok Pixel
ttcsid_D5DIRFBC77UCQLCHJ8F0 2mo TikTok Pixel
ttcsid_D6FA3CJC77U542RF8TE0 2mo TikTok Pixel
uuid 1y -
_fbp 2mo Facebook Pixel
_ga 1y Google Analytics
_ga_9E7SMCQP13 1y Google Analytics
_ga_F8FPFG5ZCL 1y Google Analytics
_ga_Z62L4XBK0S 1y Google Analytics
_gcl_au 2mo Google Ads
_gc_s_cs0_d0_sec0_part0 < 1h -
_gc_usr_id_cs0_d0_sec0_part0 1mo -
_TDID_CK session -
_ttp 2mo TikTok Pixel
_tt_enable_cookie 2mo TikTok Pixel
_twpid 1y X (Twitter) Ads
__cf_bm < 1h Cloudflare
Local storage (23)
KeySizeDetected as
AF_SESSION 13 B -
aibot_sending 5 B -
api_routing_base_V1.0.0 4.9 KB -
api_routing_current_V1.0.0 1.1 KB -
download_show_cache 5 B -
f52fcafbuidsk 4.2 KB -
fcd96aee41cdb925 1 B -
fcd96aee871c0f8d 72 B -
fcd96aee95037d16 204 B -
fcd96aee97717caf 1 B -
fcd96aeebd7dcc4c 112 B -
fcd96aeed29118e0 303 B -
fcd96aeef1fe7b11 32 B -
inviteCode 8 B -
lastExternalReferrer 5 B -
lastExternalReferrerTime 13 B -
p_p_t_id 95 B -
registerForm_inviteCode 8 B -
registerForm_inviteCode_SetTime 13 B -
_gcl_ls 152 B Google Ads
__tea_cache_first_10000005 1 B ByteDance Rangers
__tea_cache_refer_10000005 190 B ByteDance Rangers
__tea_cache_tokens_10000005 116 B ByteDance Rangers
Session storage (7)
KeySizeDetected as
c_p_id 38 B -
c_t_id 38 B -
fcd96aee95037d16 204 B -
tt_appInfo 17 B TikTok Pixel
tt_pixel_session_index 20 B TikTok Pixel
tt_sessionId 60 B TikTok Pixel
__tea_session_id_10000005 78 B ByteDance Rangers
IndexedDB (6)
DatabaseVersionDetected as
api-requests-cache 1 -
applog_sdk_event_store_10000005 2 ByteDance Rangers
CoinInfoDB 1 -
coin_list_header_db 1 -
custom_etag_log_db 1 -
log_sls 3 -

Readiness Breakdown How?

Custom title and meta description
Open Graph tags (title, image, description)
Twitter card meta tags
Canonical URL declared
Responsive viewport meta tag
Favicon present
Semantic HTML (nav, main, article)
Page title is 111 characters (advisory) Google only shows about 60 characters of the title in search results; aim for 50–60 to keep the whole thing visible.

Performance How?

565 ms Server response
30% Faster than peers
4584 ms Largest contentful paint
0.45 Cumulative layout shift
5.6 MB Page weight
470 KB Image weight
9 Third-party domains
0 Console errors
0 Failed requests

22 images: 5 oversized, 22 without width/height, 13 missing alt text

Indicative grade from a single automated render, not a substitute for Lighthouse or field data, and not part of the StackScope score.

Vibe Score Breakdown How?

SignalPoints
AI palette signals +5

This score is based on structural patterns and is not definitive. Many legitimate sites may trigger signals, and AI-built sites may go undetected. It should be treated as an indicator, not a verdict.

AI Stance

No AI stance declared
llms.txt published
No AI bots blocked in robots.txt
? No directive declared
? None advertised

Well-Known Files

robots.txt
sitemap.xml (16 URLs)
security.txt
llms.txt
ads.txt
humans.txt
? Privacy Policy not detected
? Terms of Service not detected
? Consent manager not detected
Analytics set tracking cookies on our visit, with no opt-in step.
Detection works best on English language sites.

Security Headers (4/6)

Permissions-Policy experimental (check browser support)
X-XSS-Protection deprecated (use Content-Security-Policy)

Build

Code splitting
19 JS files
24 CSS files
9 Third-party domains

Brand Colours

Something not look right? If a technology shown here is wrong or out of date, email [email protected] and we'll review it.