New: The State of Indie Launches: May 2026. What 17,652 indie launch pages run on once you strip Vercel out. Read

← Back to browse

Topline Leads

Identify high-intent leads with Topline Signal. AI-powered lead scoring and intent detection for professional services firms.

topline.com · Added June 3, 2026 · Last analysed June 3, 2026 · via Product Hunt · 50% unique tagline

StackScope is a free public catalogue of indie launches. We find launches on Product Hunt, Hacker News and similar feeds, then crawl each site to detect its tech stack and score it for launch readiness: DNS, security headers, SEO basics. This page is what we saw on 3 June 2026; the live site may have changed since.

Topline Leads ships with the launch fundamentals in place, with complete legal pages, a complete set of security headers, and a thorough launch checklist. What needs work: analytics without a consent banner and incomplete email security.

Launched on Product Hunt on June 3, 2026. The site is hosted on Cloudflare in the United States, with a domain registered in 1995. Our crawler found 21 technologies on this site, covering advertising, analytics, security, and seo. The stack includes Cloudflare, Cloudflare Bot Management, and Cloudflare DNS.

Notably, it's a rare Elastic Email sighting, just 40 in our data and tighter on security headers than most Product Hunt launches.

If you own this site, refresh the snapshot and see the full fix list any time →

10.0
StackScope Score
Excellent
100/100 Launch Readiness
Launch ready
3/3* Legal
Complete*
2/2 Web Standards
Complete
Vibe Score 10 · Few AI signals
Informational pattern-match signal. Does not feed the StackScope Score. See which fingerprints fired →

Tech Stack (21)

Infrastructure
CDN Cloudflare
DNS Cloudflare DNS
Protocol HTTP/3
Security Cloudflare Bot Management
HSTS
Email
Business email Google Workspace
Transactional email Elastic Email
Build & Framework
Site builder Framer
Business Tools
CRM LeadConnector
SaaS Rippling

Infrastructure

Network
AS13335 · US
DNS
Cloudflare DNS
Authoritative nameserver
DNSSEC
Not enabled
DNS responses unsigned. Cache-poisoning vulnerable.
SSL Certificate
Google Trust Services
Valid 30 Apr 2026 to 29 Jul 2026
Certificate as captured in this snapshot, not a live check.
Domain Age
30.5 years
Registered Dec 1995 · Squarespace Domains II LLC

Email Security

SPF ~all Soft-fail (~all). Common and accepted.
DKIM Detected via known email provider
DMARC p=none None (p=none). Monitoring only.
?
MTA-STS Not deployed. Mail to your domain can be downgraded to plaintext en route.
?
TLS-RPT Not configured. You won't hear about silent SMTP TLS handshake failures.

Storage (29)

Cookies (17)
NameLifetimeDetected as
browser_time_zone 12mo -
cf_clearance 12mo Cloudflare
datashopper_session 1h -
lc_session_LgsKWe4qrhe6iGRoE2gM 23h -
lc_session_ucNDNXieKnCrJH7m0mH4 23h -
lidid 1y -
ph_phc_LIGGyj7T7L9TQDVKqTo2HWnOzHhVnLg7MyVADCkuhUZ_posthog 12mo PostHog
XSRF-TOKEN 1h -
_fbp 2mo Facebook Pixel
_ga 1y Google Analytics
_ga_G1W51510J0 1y Google Analytics
_gcl_au 2mo Google Ads
_lc2_fpi 1y LeadConnector
_lc2_fpi_js session LeadConnector
_li_dcdm_c session LiveRamp
_topline_session session -
__cf_bm < 1h Cloudflare
Local storage (6)
KeySizeDetected as
lastExternalReferrer 5 B -
lastExternalReferrerTime 13 B -
ph_phc_LIGGyj7T7L9TQDVKqTo2HWnOzHhVnLg7MyVADCkuhUZ_posthog 1.5 KB PostHog
roi-calculator 179 B -
_gcl_ls 207 B Google Ads
_li_duid 40 B LinkedIn
Session storage (6)
KeySizeDetected as
entryPage 26 B -
pageCount 1 B -
pageHistory 62 B -
ph_phc_LIGGyj7T7L9TQDVKqTo2HWnOzHhVnLg7MyVADCkuhUZ_posthog 388 B PostHog
ph_phc_LIGGyj7T7L9TQDVKqTo2HWnOzHhVnLg7MyVADCkuhUZ_primary_window_exists 4 B PostHog
ph_phc_LIGGyj7T7L9TQDVKqTo2HWnOzHhVnLg7MyVADCkuhUZ_window_id 38 B PostHog

Readiness Breakdown How?

Favicon present
Open Graph tags (title, image, description)
Canonical URL declared
Responsive viewport meta tag
Custom title and meta description
Twitter card meta tags
Semantic HTML (nav, main, article)

Vibe Score Breakdown How?

SignalPoints
AI copy signals +5
AI writing signals +5

This score is based on structural patterns and is not definitive. Many legitimate sites may trigger signals, and AI-built sites may go undetected. It should be treated as an indicator, not a verdict.

AI Stance

Blocks AI crawlers but publishes an llms.txt
llms.txt published
9 AI bots blocked in robots.txt
ai-train = no
search = yes
? ai-input (not declared)
? None advertised

Well-Known Files

security.txt
llms.txt
ads.txt
humans.txt
? Consent manager not detected
Analytics detected; tracking fires without visitor opt-in.
84% unique
Mentions:
GDPR CCPA Cookies Do Not Sell

Security Headers (6/6)

Permissions-Policy experimental (check browser support)
X-XSS-Protection deprecated (use Content-Security-Policy)

Performance

596ms response time
Faster than 28% of sites
13 third-party domains loaded

Build

HTML minified
21 JS files
13 Third-party domains
Something not look right? If a technology shown here is wrong or out of date, email [email protected] and we'll review it.