← Back to browse

Csrf

Show HN: I made a PoC of a website for French students

Education
Germany Estimated origin: Germany

Added May 26, 2026 · Last analysed May 26, 2026 · via Hacker News

StackScope records what new websites are built with, the week they launch. Most we find ourselves, by watching public internet infrastructure for brand-new sites; the rest come from Product Hunt, Hacker News and PeerPush. We crawled this one for its tech stack and scored it for launch readiness: DNS, security headers, SEO basics. This page is what we saw on 26 May 2026; the live site may have changed since.

Every technology below links to its own page: which other new sites launched with it. Vendors and agencies watch those pages with Stackdar and hear about new adopters the week they ship, from £15 a month.

Csrf is early-stage. Main gaps: missing several security headers, incomplete legal pages, and no robots.txt or sitemap.

Launched on Hacker News on May 26, 2026. The site is hosted on Lima City. We've detected 5 technologies on this site, covering servers, business email, hosting, and security. The stack includes HSTS, Lima City, and Lima City Email.

It's one of only 5 launches we've crawled running Lima City.

If you own this site, refresh the snapshot and see the full fix list any time →

2.1
StackScope Score
Poor
41/100 Launch Readiness
Partially ready
0/3 Legal
Missing
0/2 Crawl files
Missing
Vibe Score 0 · No AI signals
How much the site looks AI-generated. Informational pattern-match signal, not a verdict. Does not feed the StackScope Score. See which fingerprints fired →

Tech Stack (5)

Infrastructure
Hosting Lima City
Security HSTS
Server OpenResty
PHP (2)
Email
Business email Lima City Email

Infrastructure

Network
AS47447 · DE
DNSSEC
Not enabled
DNS responses unsigned. Cache-poisoning vulnerable.
Green hosting
Green hosted
Host runs on renewable energy. Data from The Green Web Foundation.
SSL Certificate
Let's Encrypt
Valid 4 May 2026 to 2 Aug 2026
Certificate as captured in this snapshot, not a live check.

Email Security

SPF Not published. Your domain can be spoofed in phishing emails.
?
DKIM Not detected at common selectors. Your provider may use a custom one.
DMARC Not published. Receivers fall back to permissive defaults.
?
MTA-STS Not deployed. Mail to your domain can be downgraded to plaintext en route.
?
TLS-RPT Not configured. You won't hear about silent SMTP TLS handshake failures.

Storage (3)

Cookies (3)
NameLifetimeDetected as
PHPSESSID session PHP
_lcp 7y -
_lcp2 1y -

Readiness Breakdown How?

Custom title and meta description (partial) missing meta description
Responsive viewport meta tag
Favicon present
- Open Graph tags (title, image, description)
- Canonical URL declared
- Twitter card meta tags
- Semantic HTML (nav, main, article)

AI Stance

No AI stance declared
llms.txt published
No AI bots blocked in robots.txt
? No directive declared
? None advertised

Well-Known Files

robots.txt
sitemap.xml
security.txt
llms.txt
ads.txt
humans.txt
? Privacy Policy not detected
? Terms of Service not detected
Detection works best on English language sites.

Security Headers (2/6)

Permissions-Policy experimental (check browser support)
X-XSS-Protection deprecated (use Content-Security-Policy)

Performance

127ms response time
Faster than 81% of sites
2 third-party domains loaded

Build

3 JS files
3 CSS files
2 Third-party domains

Brand Colours

Something not look right? If a technology shown here is wrong or out of date, email [email protected] and we'll review it.