← Back to browse

Mochijs

Bun-native, raw-CDP browser automation. Relational fingerprint locking, JIT-installed spoofing, JA4-coherent fetch. Leaves no crumbs.

Developer Tools

Added May 9, 2026 · Last analysed May 9, 2026 · via Hacker News

StackScope records what new websites are built with, the week they launch. Most we find ourselves, by watching public internet infrastructure for brand-new sites; the rest come from Product Hunt, Hacker News and PeerPush. We crawled this one for its tech stack and scored it for launch readiness: DNS, security headers, SEO basics. This page is what we saw on 9 May 2026; the live site may have changed since.

Every technology below links to its own page: which other new sites launched with it. Vendors and agencies watch those pages with Stackdar and hear about new adopters the week they ship, from £15 a month.

Mochijs still has work before launch. What needs work: missing several security headers, incomplete legal pages, and no sitemap.

Launched on Hacker News on May 9, 2026. The site is served through Cloudflare, with a domain registered 1 day before launch. The crawl picked up 3 technologies on this site, covering CDN, DNS providers, and protocol. The stack includes Cloudflare, Cloudflare DNS, and HTTP/3.

If you own this site, refresh the snapshot and see the full fix list any time →

3.6
StackScope Score
Poor
90/100 Launch Readiness
Launch ready
0/3 Legal
Missing
1/2 Crawl files
Partial
Vibe Score 15 · Few AI signals
How much the site looks AI-generated. Informational pattern-match signal, not a verdict. Does not feed the StackScope Score. See which fingerprints fired →

Tech Stack (3)

Infrastructure
CDN Cloudflare (3)
DNS Cloudflare DNS
Protocol HTTP/3 (2)

Infrastructure

Network
AS13335 · US
DNS
Cloudflare DNS
Authoritative nameserver
DNSSEC
Not enabled
DNS responses unsigned. Cache-poisoning vulnerable.
Green hosting
Green hosted
Host runs on renewable energy. Data from The Green Web Foundation.
SSL Certificate
Google Trust Services
Valid 8 May 2026 to 6 Aug 2026
Certificate as captured in this snapshot, not a live check.
Domain Age
3 months
Registered May 2026 · NameCheap, Inc.

Email Security

SPF Not published. Your domain can be spoofed in phishing emails.
?
DKIM Not detected at common selectors. Your provider may use a custom one.
DMARC Not published. Receivers fall back to permissive defaults.
?
MTA-STS Not deployed. Mail to your domain can be downgraded to plaintext en route.
?
TLS-RPT Not configured. You won't hear about silent SMTP TLS handshake failures.

Storage (0)

This site uses no client-side storage we could detect on page load.

Readiness Breakdown How?

Custom title and meta description
Open Graph tags (title, image, description) (partial) missing og:image
Twitter card meta tags
Canonical URL declared
Responsive viewport meta tag
Favicon present
Semantic HTML (nav, main, article)

Vibe Score Breakdown How?

SignalPoints
Placeholder branding +10
AI writing signals +5

This score is based on structural patterns and is not definitive. Many legitimate sites may trigger signals, and AI-built sites may go undetected. It should be treated as an indicator, not a verdict.

AI Stance

Blocks AI crawlers but publishes an llms.txt
llms.txt published
9 AI bots blocked in robots.txt
ai-train = no
search = yes
? ai-input (not declared)
? None advertised

Well-Known Files

robots.txt
sitemap.xml
security.txt
llms.txt
ads.txt
humans.txt
? Privacy Policy not detected
? Terms of Service not detected
Detection works best on English language sites.

Security Headers (0/6)

Permissions-Policy experimental (check browser support)
X-XSS-Protection deprecated (use Content-Security-Policy)

Performance

352ms response time
Faster than 43% of sites
1 third-party domains loaded

Build

0 JS files
1 CSS files
1 Third-party domains

Brand Colours

Something not look right? If a technology shown here is wrong or out of date, email [email protected] and we'll review it.