Tell Me When Down
How it worksWhat we checkPricing
Security reportsBlogFree toolsCompareDocs
Log inGet started
← all reportsscan another site →
B

dualstream.gg

Grade B — 2 to fix, 4 minor.

0critical2to fix4minor

passive scan · the deep checks need you signed in · scanned 27d ago

This is a passive website security report for dualstream.gg, graded B (78/100). We checked its SSL certificate, HTTP security headers, DNS records, email spoofing protection and publicly exposed files — the same surface a browser and a search engine already see.

We found 6 issues on this scan — each has a plain-English explanation and a copy-paste fix below.

Not your site? Get the same free report for yours →

Security headers02

No Content-Security-Policy

warning

There's no Content-Security-Policy header. A CSP is the single most effective defense against cross-site scripting (XSS): it tells the browser which sources of scripts, styles, and other content are allowed, so an injected <script> from a compromised dependency or a reflected input simply won't run.

Server software/version disclosed

info

Your responses advertise the exact software you run (X-Powered-By: Next.js). It's not a hole by itself, but it hands attackers a shortcut: they can look up known vulnerabilities for that precise version instead of probing blindly.

Cookie security02

Cookies set without the Secure flag

warning

These cookies are set without the Secure flag: NEXT_LOCALE. That means the browser will also send them over plain HTTP, where anyone on the same network can read them — including session cookies, which is enough to hijack a logged-in account.

Cookies readable by JavaScript

info

These cookies are set without HttpOnly: NEXT_LOCALE. Any script on the page — including one injected through an XSS bug or a compromised third-party library — can read them. Session and auth cookies should never be readable by JavaScript.

DNS security02

DNSSEC is not enabled

info

dualstream.gg is not protected by DNSSEC. DNSSEC signs your DNS records so resolvers can detect a forged answer — without it, an attacker who can poison DNS could point your domain at their own server without touching anything you control.

No CAA records

info

dualstream.gg publishes no CAA records. CAA tells the world which certificate authorities are allowed to issue HTTPS certificates for your domain. Without it, any CA can be persuaded to issue a cert for your domain, which widens the door to mis-issuance.

Get the fixes — and go deeper

Sign up to fix these — then run the checks a passive scan can't. The stuff that actually gets vibe-coded apps hacked:

  • Exposed .env files (API keys & passwords)
  • Public .git folders (your whole codebase)
  • Leaked source maps of your original code
  • Open admin panels with no login
  • Debug pages left on (phpinfo, stack traces)
Fix these & go deeper

free for your first app · no card

Not dualstream.gg? Scan your own site free →

Or browse every site we've graded.

Tell Me When Down

Uptime and security monitoring for people who'd rather ship than babysit servers. We watch so you can sleep.

product
How it worksWhat we checkSecurity reportsPricingDocsBlogFAQ
free toolsWebsite security scanSupabase pause checkRender sleep checkMixed content checkerSecurity headers checkCookie security checkSSL expiry check
comparevs UptimeRobotvs Better Stackvs PingdomFor indie hackers
company
StatusAbout our botContactPrivacyTerms
© 2026 TellMeWhenDown · tellmewhendown.com