allcars.com

HTTPS HTTP/2 Gzip Cloudflare Crawled in 25,406ms · June 27, 2026 19:56 UTC

allcars.com Website Overview & Technology Report

🤖 AI Summary
We performed a comprehensive analysis of allcars.com on 2026-06-27. The website returned an HTTP 200 status code with a server response time of 11600ms. The page is served over HTTP/2 protocol with Gzip compression enabled, achieving approximately 60.0% size reduction. The total page weight is 27 KB, and the site is served behind a CDN (Content Delivery Network). Warning: The website does not have a valid SSL certificate. Visitors may see security warnings in their browser, and data transmitted to and from this website is not encrypted. The security headers analysis reveals a score of 30/100 (below average). The following security headers are properly configured: X-Content-Type-Options and Referrer-Policy. However, the site is missing Content-Security-Policy, Strict-Transport-Security (HSTS), X-Frame-Options, and Permissions-Policy, which could expose the site and its users to cross-site scripting (XSS), clickjacking, and other web-based attacks. Our technology detection scan identified 4 technologies across 4 categories powering allcars.com. The detected stack includes Google Analytics 4, Google Tag Manager, Cloudflare Turnstile, and Cloudflare. Based on our comprehensive analysis of domain age, SSL configuration, email authentication, security headers, and blacklist status, allcars.com receives an overall trust score of 64/100, classified as "Likely Safe".
64
/ 100
Trust Score
30
/ 100
Security Headers
HTTP Response
Status200 OK
Response Time11600ms
ProtocolHTTP/2
Page Size27 KB
CompressionGzip
Compression Savings~60.0%
CDNYes ✓
Servercloudflare
Total Requests118
3rd Party Domains8
RedirectNone
Detected Technologies (4)
📊 Google Analytics 4 🏷️ Google Tag Manager 🔒 Cloudflare Turnstile ☁️ Cloudflare
Security Headers
Content-Security-Policy
Not set
Strict-Transport-Security (HSTS)
Not set
X-Frame-Options
Not set
X-Content-Type-Options
Set ✓
Referrer-Policy
Set ✓
Permissions-Policy
Not set
SSL Certificate
IssuerGoogle Trust Services
Issuer FullcountryName=US, organizationName=Google Trust Services, commonName=WE1
SubjectcommonName=allcars.com
Type
TLS VersionTLS 1.3
Cipher SuiteTLS_AES_256_GCM_SHA384
Algorithm
Issued
Expires— (? days)
SANs

allcars.com Trust Score & Safety Analysis

🤖 AI Summary
After conducting a thorough safety and legitimacy analysis, allcars.com receives a trust score of 64/100, which places it in the "Likely Safe" category. This score is calculated by evaluating multiple factors including SSL certificate validity, domain registration history, email authentication protocols, security header configuration, and blacklist status across major threat intelligence databases. The analysis identified several positive trust signals: a valid HTTPS connection protecting data in transit, SPF (Sender Policy Framework) email authentication preventing email spoofing, and DMARC email authentication with a none policy. Areas of concern include: the absence of a Content-Security-Policy header, which leaves the site more vulnerable to cross-site scripting (XSS) attacks, no X-Frame-Options header, which could allow the site to be embedded in malicious iframes (clickjacking), the domain's WHOIS information is hidden behind a privacy service, making it harder to verify the owner's identity, and DNSSEC is not enabled, leaving DNS queries vulnerable to spoofing attacks. While these issues don't necessarily indicate malicious intent, they represent areas where the website's security posture could be improved. We checked allcars.com against 8 major blacklist databases including Google Safe Browsing, Phishtank, Urlhaus, Openphish, Dnsfilter, Spamhaus Dbl, Surbl, and Virustotal. The domain passed all 8 checks with a clean status, meaning it has not been flagged for phishing, malware distribution, spam, or other malicious activities by any of the tested threat intelligence providers.
64
/ 100
Likely Safe
Trust Signals
Valid HTTPS
SPF configured
DMARC configured (p=none)
⚠️ DNSSEC not enabled
Sitemap.xml found
Robots.txt found
⚠️ Missing Content-Security-Policy
⚠️ Missing X-Frame-Options
Blacklist Checks (8/8 clean)
Google Safe Browsing clean
Phishtank clean
Urlhaus clean
Openphish clean
Dnsfilter clean
Spamhaus Dbl clean
Surbl clean
Virustotal clean

allcars.com Technology Stack & Detected Technologies

🤖 AI Summary
Our technology detection engine scanned allcars.com and identified 4 distinct technologies across 4 categories. This analysis is performed by examining HTTP response headers, HTML source code patterns, JavaScript library fingerprints, CSS framework signatures, and DNS records. Analytics: Google Analytics 4 — tracks visitor behavior and provides traffic insights for allcars.com. Tag Manager: Google Tag Manager — manages marketing and analytics tags without code changes for allcars.com. Security: Cloudflare Turnstile — provides security features like bot detection and CAPTCHA for allcars.com. CDN: Cloudflare — accelerates content delivery by caching assets at edge locations worldwide for allcars.com. We also extracted the following tracking identifiers: Google Tag Manager container GTM-KXRQM9P. These IDs can be used to identify other websites operated by the same organization.
Analytics
📊 Google Analytics 4(95%)
Tag Manager
🏷️ Google Tag Manager(95%)
Security
🔒 Cloudflare Turnstile(95%)
CDN
☁️ Cloudflare(100%)
Tracking IDs
gtm_idGTM-KXRQM9P

allcars.com Performance, Speed & Core Web Vitals

🤖 AI Summary
allcars.com delivers its homepage in 11600ms (server response time), which is considered slow by industry standards. The total page weight is 27 KB, and we detected 118 resource requests loading assets from 8 third-party domains. A high number of third-party domains can significantly impact page load time due to additional DNS lookups and TLS handshakes required for each domain. The website uses Gzip compression for text-based assets, achieving an estimated 60.0% reduction in transfer size. This reduces bandwidth usage and improves page load times, especially for visitors on slower connections. Asset minification status: 1 out of 1 CSS files and 0 out of 2 JavaScript files are minified. Minifying the remaining 2 unminified file(s) could further reduce page weight by 10-30% for those assets. Minification is a best practice that reduces download sizes without affecting functionality. The site is served through a Content Delivery Network (CDN), which caches static assets at edge servers around the world. This means visitors from different geographic regions receive content from the nearest edge server, significantly reducing latency. CDN usage is particularly important for websites with a global audience, as it can reduce page load times by 40-60% for distant visitors. From an environmental perspective, each page view of allcars.com produces approximately 0.01g of CO₂, earning a carbon rating of A. This places the website among the cleanest on the web, demonstrating efficient use of server resources and optimized content delivery. For reference, the average web page produces about 0.5g of CO₂ per page view. The page weight of 27 KB is the primary factor in this calculation. Core Web Vitals data from the Chrome User Experience Report (CrUX) is not available for allcars.com. This typically means the site doesn't have enough real-world Chrome user traffic to generate statistically significant field data, or the domain is not included in the CrUX dataset. Core Web Vitals (LCP, INP, CLS) are important Google ranking factors that measure real user experience.
Core Web Vitals data not available
Requires CrUX API key configuration
Carbon Footprint
CO₂ per page view0.01g
RatingA
Page Weight & Optimization
HTML Size27 KB
CompressionGzip
Compression Savings~60.0%
CDNYes ✓
Total Requests118
3rd Party Domains8
CSS Minified1/1
JS Minified0/2

allcars.com DNS Records, Email Authentication & Domain Registration

🤖 AI Summary
allcars.com resolves to the IPv4 address 172.67.132.194 and also supports IPv6 (2606:4700:3031::6815:516), demonstrating modern network infrastructure readiness. The domain has 2 A record(s) configured. The domain name system is managed by 2 name servers: sri.ns.cloudflare.com and tara.ns.cloudflare.com. Having 2 name servers provides good redundancy — if one fails, the others can continue serving DNS queries. The choice of name servers often indicates the DNS hosting provider or CDN service being used. Email for allcars.com is handled by Google Workspace with 5 MX records configured: aspmx.l.google.com, alt1.aspmx.l.google.com, and alt2.aspmx.l.google.com and 2 more. Multiple MX records provide failover redundancy — if the primary mail server is unavailable, email will be routed to the next available server. SPF (Sender Policy Framework) is configured, which specifies which mail servers are authorized to send email on behalf of this domain. This helps prevent email spoofing and improves email deliverability. DMARC (Domain-based Message Authentication, Reporting and Conformance) is configured with a none policy — a monitoring-only setting that doesn't enforce any action on unauthorized emails. DKIM was not detected. Without DKIM, recipients cannot cryptographically verify that emails claiming to be from this domain are authentic. DNSSEC is not enabled for allcars.com. While not critical for most websites, DNSSEC adds an important security layer by ensuring DNS responses haven't been tampered with during transit. Enabling DNSSEC is recommended for domains handling sensitive data or financial transactions. Our subdomain enumeration scan discovered 24 active subdomains for allcars.com: admin.allcars.com, api.allcars.com, app.allcars.com, apps.allcars.com, blog.allcars.com, cdn.allcars.com, community.allcars.com, and dev.allcars.com. Plus 16 additional subdomains. Active subdomains can reveal the organization's infrastructure, including development environments, API endpoints, and third-party service integrations.
DNS Records
A
172.67.132.194
104.21.5.22
AAAA
2606:4700:3031::6815:516
NS
sri.ns.cloudflare.com
tara.ns.cloudflare.com
MX
aspmx.l.google.com
alt1.aspmx.l.google.com
alt2.aspmx.l.google.com
alt3.aspmx.l.google.com
alt4.aspmx.l.google.com
Email & Authentication
SPF
DMARC p=none
DKIM
DNSSEC
MX ProviderGoogle Workspace
Registrar
Organisation
Country
Contact
Registered
Expires
Domain Age
IPv6 SupportYes ✓
Subdomains (24 found)
admin.allcars.com api.allcars.com app.allcars.com apps.allcars.com blog.allcars.com cdn.allcars.com community.allcars.com dev.allcars.com developers.allcars.com docs.allcars.com ftp.allcars.com help.allcars.com m.allcars.com partners.allcars.com portal.allcars.com shop.allcars.com smtp.allcars.com staging.allcars.com static.allcars.com status.allcars.com store.allcars.com support.allcars.com webmail.allcars.com www.allcars.com

allcars.com Page Content, Images & Accessibility

🤖 AI Summary
The homepage of allcars.com contains 587 words of visible text content. This is a moderate amount of content. The page is structured with 8 H2 headings, 10 H3 headings, 1 H4 headings. The page includes 25 images. All images have proper alt text attributes ✓, which is excellent for both accessibility (screen readers) and SEO (search engines can understand image content). The link structure consists of 39 internal links pointing to other pages on the same domain and 38 external links pointing to third-party websites. There are 2 external JavaScript files, 1 CSS stylesheets, and 1 iframes on the page. The site implements the following web standards and features: XML Sitemap (helps search engines discover all pages), robots.txt (controls search engine crawling behavior), and Progressive Web App (PWA) manifest (enabling app-like installation). Notable missing features: Schema.org structured data. Adding these could improve search engine discoverability and rich result eligibility. We detected the following payment methods accepted on allcars.com: Discover. Offering multiple payment options including credit cards and digital wallets improves customer trust and can increase conversion rates. The website has social media presence across 6 platforms: Facebook (@allcarswebsite), Twitter (@allcarscom), Instagram (@allcarsdotcom), Linkedin (@allcars-com), Youtube (@allcarsdotcom), and Tiktok (@allcarsdotcom). An active social media presence is a positive trust indicator and helps build brand awareness and customer engagement.
587
Words
25
Images
100%
Alt Text Score
27
Page Size (KB)
Content Structure
H1Find the Perfect Car at AllCars
H2 Tags8
H3 Tags10
H4 Tags1
H5 Tags0
H6 Tags0
Internal Links39
External Links38
Assets & Features
JavaScript Files2
JS Minified0/2
CSS Files1
CSS Minified1/1
Iframes1
Images25
Missing Alt0
SitemapYes ✓
Robots.txtYes ✓
PWAYes ✓
AMPNo
RSS FeedNo
Payment Methods Detected
💳 Discover
Social Media Presence
Facebook: @allcarswebsiteTwitter: @allcarscomInstagram: @allcarsdotcomLinkedin: @allcars-comYoutube: @allcarsdotcomTiktok: @allcarsdotcom

allcars.com SEO Analysis, Meta Tags & Open Graph

🤖 AI Summary
The title tag for allcars.com is well-optimized at 60 characters: "AllCars | Safely Buy, Sell or Trade Your Car. Easy Financing". The length falls within the ideal range for Google search results, ensuring the full title is displayed without truncation. The meta description is 98 characters (well-optimized): "AllCars created a way to buy a car 100% online that is easy, fair, and designed for peace of mind.". Google typically displays up to 155-160 characters of the meta description in search results. A compelling meta description with a clear call-to-action can significantly improve click-through rates from search results. The canonical url is correctly set to /, preventing duplicate content issues, the page language is declared as en, the meta robots directive is set to index, follow, and a favicon is configured. Open Graph meta tags are configured with 4/4 recommended fields: OG title ("AllCars | Safely Buy, Sell or Trade Your Car. Easy Financing..."), OG description, OG image (social sharing thumbnail), OG type (website). These tags control how the page appears when shared on Facebook, LinkedIn, and other social media platforms that support the Open Graph protocol. A Twitter Card of type summary_large_image is configured, which controls how links appear when shared on Twitter/X. The "summary_large_image" type displays a large image preview, which typically generates higher engagement rates than the basic card type.
Google SERP Preview
AllCars | Safely Buy, Sell or Trade Your Car. Easy Financing
https://allcars.com
AllCars created a way to buy a car 100% online that is easy, fair, and designed for peace of mind.
Meta Tags
TitleAllCars | Safely Buy, Sell or Trade Your Car. Easy Financing...
Title Length60 chars
Meta Desc Length98 chars
H1Find the Perfect Car at AllCars
Languageen
Canonical/
Meta Robotsindex, follow
Meta Keywordsnot set
Schema.org & Social
Schema Types
OG Typewebsite
OG ImageSet ✓
Twitter Cardsummary_large_image
FaviconSet ✓
Open Graph Preview
allcars.com
AllCars | Safely Buy, Sell or Trade Your Car. Easy Financing
AllCars created a way to buy a car 100% online that is easy, fair, and designed for peace of mind.