|Site title||Hotjar: Website Heatmaps & Behavior Analytics Tools|
|Description||See how visitors are really using your website, collect user feedback and turn more visitors into customers.|
|Date first seen||February 2017|
|Netcraft Risk Rating||0/10|
|Netblock Owner||Packet Host, Inc.|
|IP address||220.127.116.11 (VirusTotal)|
|IPv6 address||Not Present|
|Organisation||Hotjar Ltd, Paris, 75013, France|
|Top Level Domain||Commercial entities (.com)|
|DNS Security Extensions||unknown|
|0.0.0.0-255.255.255.255||N/A||IANA-BLK||The whole IPv4 address space|
|↳ 18.104.22.168-22.214.171.124||United States||NET147||Various Registries (Maintained by ARIN)|
|↳ 126.96.36.199-188.8.131.52||Netherlands||RIPE-ERX-147-75-0-0||RIPE Network Coordination Centre|
|↳ 184.108.40.206-220.127.116.11||Switzerland||COSTRA-NET||Costra S.A.|
|↳ 18.104.22.168-22.214.171.124||United States||PACKET-NET-96-20||Packet Host, Inc.|
|↳ 126.96.36.199||United States||PACKET-NET-96-20||Packet Host, Inc.|
|Organisational unit||Not Present|
|Subject Alternative Name||vars.hotjar.com|
|Validity period||From Jun 16 2020 to Sep 14 2020 (2 months, 4 weeks)|
|Public key algorithm||rsaEncryption|
|Public key length||2048|
|Perfect Forward Secrecy||Yes|
|Next Protocol Negotiation||h2,http/1.1|
|Supported TLS Extensions||RFC5746 renegotiation info, RFC4366 server name, RFC4492 EC point formats, RFC5077 session ticket, Next Protocol Negotiation, unknown|
|Issuing organisation||Let's Encrypt|
|Issuer common name||Let's Encrypt Authority X3|
|Issuer unit||Not Present|
|Issuer location||Not Present|
|Issuer state||Not Present|
|Certificate Revocation Lists||Not Present|
|Public Key Hash||88de399a329f4b938d6674d1743588d2cc84a48d314fced9a107c715813331bb|
|OCSP servers||http://ocsp.int-x3.letsencrypt.org - 100% uptime in the past 24 hours
|OCSP stapling response||No response received|
Signed Certificate Timestamps (SCTs)
|Certificate||Let's Encrypt Oak 2020
|Certificate||Google Xenon 2020
This site does not support the SSL version 3 protocol.
The site did not offer the Heartbeat TLS extension prior to the Heartbleed disclosure, and so was not exploitable.
This test does not exploit the Heartbleed vulnerability but uses information from conventional HTTPS requests. More information about Heartbleed detection.
SSL Certificate Chain
|Common name||DST Root CA X3|
|Organisational unit||Not Present|
|Organisation||Digital Signature Trust Co.|
|Validity period||From 2000-09-30 to 2021-09-30|
|Common name||Let's Encrypt Authority X3|
|Organisational unit||Not Present|
|Validity period||From 2016-03-17 to 2021-03-17|
Sender Policy Framework
A host's Sender Policy Framework (SPF) describes who can send mail on its behalf. This is done by publishing an SPF record containing a series of rules. Each rule consists of a qualifier followed by a specification of which domains to apply this qualifier to. For more information please see open-spf.org.
Warning: It appears that this host does not have an SPF record. There may be an SPF record on hotjar.com: Check the site report.
Setting up an SPF record helps prevent the delivery of forged emails from your domain. Please note that an SPF record will only protect the domain it is added to and not any mail-enabled subdomains. It is recommended to add an SPF record to any subdomain with an MX record.
DMARC (Domain-based Message Authentication, Reporting and Conformance) is a mechanism for domain owners to indicate how mail purporting to originate from their domain should be authenticated. It builds on SPF and DKIM, providing a method to set policy and to give reporting of failures. For more information please see dmarc.org.
This host does not have a DMARC record. There may be a DMARC record on the site report for hotjar.com: Check the site report.
|Company||Primary Category||Tracker||Popular Sites with this Tracker|
|Cloudflare||CDN||Cloudflare||www.finanzen.net, www.sciencedirect.com, dash.cloudflare.com|
|Analytics||Facebookpixel||www.mediafire.com, www.3djuegos.com, www.majorgeeks.com|
|Widget||www.wikiwand.com, www.express.co.uk, www.w3schools.com|
|Advertising||Google AdSense||www.foxnews.com, www.liveomg.com, www.repubblica.it|
|Analytics||Google Analytics||www.arco.co.uk, www.paypal.com, www.researchgate.net|
|Googletagmanager||www.bbc.co.uk, www.t-online.de, www.digikala.com|
|CDN||Googlecdn||www.upwork.com, www.etoro.com, www.teamviewer.com|
|MaxCDN||CDN||Bootstrapcdn||www.utorrent.com, www.standardmedia.co.ke, www.pdfdrive.com|
|Optimizely||Analytics||Optimizely||www.foxbusiness.com, www.abebooks.com, vars.hotjar.com|
|Wistia||Analytics||Wistia||www.techsmith.com, www.icsi.co.uk, www.linode.com|
Site Technology (fetched 19 days ago)
Cloud & PaaS
Cloud computing is the use of computing resources (hardware and software) that are delivered as a service over a network (typically the Internet). Platform as a service (PaaS) is a category of cloud computing services that provide a computing platform and a solution stack as a service.
A web accelerator is a proxy server that reduces web site access times.
Includes all the main technologies that Netcraft detects as running on the server such as PHP.
Technology Description Popular sites using this technology SSL A cryptographic protocol providing communication security over the Internet login.microsoftonline.com
Client-Side Scripting Frameworks
Frameworks or libraries allow for easier development of applications by providing an Application Program Interface (API) or a methodology to follow whilst developing.
Content Delivery Network
A content delivery network or content distribution network (CDN) is a large distributed system of servers deployed in multiple data centers in the Internet. The goal of a CDN is to serve content to end-users with high availability and high performance.
Web analytics is the measurement, collection, analysis and reporting of internet data for purposes of understanding and optimizing web usage.
A character encoding system consists of a code that pairs each character from a given repertoire with something else such as a bit pattern, sequence of natural numbers, octets, or electrical pulses in order to facilitate the transmission of data (generally numbers or text) through telecommunication networks or for data storage.
Web Browser Targeting
Web browser targeting enables software applications to make use of specific functions of the browser as well as optimizing the application for specific browser versions.
Technology Description Popular sites using this technology X-Content-Type-Options Browser MIME type sniffing is disabled www.googleadservices.com, www.amazon.com, www.paypal.com X-Frame-Options Same Origin Do not allow this site to be rendered within an iframe www.google.com, vars.hotjar.com, teams.microsoft.com Stylesheet with SRI No description www.pdfdrive.com, tryhackme.com, store.playstation.com X-XSS-Protection Block Block pages on which cross-site scripting is detected www.pinterest.com, login.salesforce.com, discordapp.com
A Document Type Declaration, or DOCTYPE, is an instruction that associates a particular SGML or XML document (for example, a webpage) with a Document Type Definition (DTD).
Technology Description Popular sites using this technology HTML5 Latest revision of the HTML standard, the main markup language on the web disqus.com
HTML5 is a markup language for structuring and presenting content for the World Wide Web and a core technology of the Internet. It is the fifth revision of the HTML standard.
Technology Description Popular sites using this technology Viewport meta tag HTML5 tag usually used for mobile optimization www.foxnews.com
Cascading Style Sheets (CSS) is a style sheet language used for describing the presentation semantics (the look and formatting) of a document written in a markup language (such as XHTML).