cash.app Website Overview & Technology Report
🤖 AI Summary
We performed a comprehensive analysis of cash.app on 2026-06-27. The website returned an HTTP 200 status code with a server response time of 16773ms. The page is served over HTTP/2 protocol with Gzip compression enabled, achieving approximately 60.0% size reduction. The total page weight is 476 KB, and the site is served behind a CDN (Content Delivery Network).
Warning: The website does not have a valid SSL certificate. Visitors may see security warnings in their browser, and data transmitted to and from this website is not encrypted.
The security headers analysis reveals a score of 70/100 (good). The following security headers are properly configured: Content-Security-Policy, Strict-Transport-Security (HSTS), X-Frame-Options, and X-Content-Type-Options. However, the site is missing Referrer-Policy and Permissions-Policy, which could expose the site and its users to cross-site scripting (XSS), clickjacking, and other web-based attacks.
Our technology detection scan identified 3 technologies across 2 categories powering cash.app. The detected stack includes Next.js chunks, Angular, and Vite. The site uses Next.js as its primary framework (version chunks).
Based on our comprehensive analysis of domain age, SSL configuration, email authentication, security headers, and blacklist status, cash.app receives an overall trust score of 77/100, classified as "Likely Safe".
HTTP Response
Status200 OK
Response Time16773ms
ProtocolHTTP/2
Page Size476 KB
CompressionGzip
Compression Savings~60.0%
CDNYes ✓
Servercloudflare
Total Requests125
3rd Party Domains9
RedirectNone
Detected Technologies (3)
🔧 Next.js
🔧 Angular
🔨 Vite
Security Headers
✓
Content-Security-Policy
Set ✓
✓
Strict-Transport-Security (HSTS)
Set ✓
✓
X-Content-Type-Options
Set ✓
✗
Referrer-Policy
Not set
✗
Permissions-Policy
Not set
SSL Certificate
IssuerGoogle Trust Services
Issuer FullcountryName=US, organizationName=Google Trust Services, commonName=WE1
SubjectcommonName=cash.app
Type—
TLS VersionTLS 1.3
Cipher SuiteTLS_AES_256_GCM_SHA384
Algorithm—
Issued—
Expires— (? days)
SANs—
cash.app Trust Score & Safety Analysis
🤖 AI Summary
After conducting a thorough safety and legitimacy analysis, cash.app receives a trust score of 77/100, which places it in the "Likely Safe" category. This score is calculated by evaluating multiple factors including SSL certificate validity, domain registration history, email authentication protocols, security header configuration, and blacklist status across major threat intelligence databases.
The analysis identified several positive trust signals: a valid HTTPS connection protecting data in transit, HSTS (HTTP Strict Transport Security) enforcement preventing protocol downgrade attacks, SPF (Sender Policy Framework) email authentication preventing email spoofing, DMARC email authentication with a reject policy — the strongest available setting, and DKIM (DomainKeys Identified Mail) providing cryptographic email verification.
Areas of concern include: missing Referrer-Policy, potentially leaking URL information to third parties, the domain's WHOIS information is hidden behind a privacy service, making it harder to verify the owner's identity, and DNSSEC is not enabled, leaving DNS queries vulnerable to spoofing attacks. While these issues don't necessarily indicate malicious intent, they represent areas where the website's security posture could be improved.
We checked cash.app against 8 major blacklist databases including Google Safe Browsing, Phishtank, Urlhaus, Openphish, Dnsfilter, Spamhaus Dbl, Surbl, and Virustotal. The domain passed all 8 checks with a clean status, meaning it has not been flagged for phishing, malware distribution, spam, or other malicious activities by any of the tested threat intelligence providers.
Trust Signals
✅ Valid HTTPS
✅ HSTS enabled
✅ SPF configured
✅ DMARC configured (p=reject)
✅ DKIM configured
⚠️ DNSSEC not enabled
✅ Sitemap.xml found
✅ Robots.txt found
⚠️ Missing Referrer-Policy
Blacklist Checks (8/8 clean)
✓
Google Safe Browsing
clean
✓
Phishtank
clean
✓
Urlhaus
clean
✓
Openphish
clean
✓
Dnsfilter
clean
✓
Spamhaus Dbl
clean
✓
Surbl
clean
✓
Virustotal
clean
cash.app Technology Stack & Detected Technologies
🤖 AI Summary
Our technology detection engine scanned cash.app and identified 3 distinct technologies across 2 categories. This analysis is performed by examining HTTP response headers, HTML source code patterns, JavaScript library fingerprints, CSS framework signatures, and DNS records.
Framework: Next.js (version chunks) and Angular — provides the application framework and routing for cash.app.
Build Tool: Vite — bundles and optimizes the JavaScript and CSS assets for cash.app.
Framework
🔧 Next.js chunks(100%)🔧 Angular(95%)
Build Tool
cash.app Performance, Speed & Core Web Vitals
🤖 AI Summary
cash.app delivers its homepage in 16773ms (server response time), which is considered slow by industry standards. The total page weight is 476 KB, and we detected 125 resource requests loading assets from 9 third-party domains. A high number of third-party domains can significantly impact page load time due to additional DNS lookups and TLS handshakes required for each domain.
The website uses Gzip compression for text-based assets, achieving an estimated 60.0% reduction in transfer size. This reduces bandwidth usage and improves page load times, especially for visitors on slower connections.
Asset minification status: 0 out of 6 CSS files and 0 out of 24 JavaScript files are minified. Minifying the remaining 30 unminified file(s) could further reduce page weight by 10-30% for those assets. Minification is a best practice that reduces download sizes without affecting functionality.
The site is served through a Content Delivery Network (CDN), which caches static assets at edge servers around the world. This means visitors from different geographic regions receive content from the nearest edge server, significantly reducing latency. CDN usage is particularly important for websites with a global audience, as it can reduce page load times by 40-60% for distant visitors.
From an environmental perspective, each page view of cash.app produces approximately 0.23g of CO₂, earning a carbon rating of B. This places the website among the cleanest on the web, demonstrating efficient use of server resources and optimized content delivery. For reference, the average web page produces about 0.5g of CO₂ per page view. The page weight of 476 KB is the primary factor in this calculation.
Core Web Vitals data from the Chrome User Experience Report (CrUX) is not available for cash.app. This typically means the site doesn't have enough real-world Chrome user traffic to generate statistically significant field data, or the domain is not included in the CrUX dataset. Core Web Vitals (LCP, INP, CLS) are important Google ranking factors that measure real user experience.
Core Web Vitals data not available
Requires CrUX API key configuration
Carbon Footprint
CO₂ per page view0.23g
RatingB
Page Weight & Optimization
HTML Size476 KB
CompressionGzip
Compression Savings~60.0%
CDNYes ✓
Total Requests125
3rd Party Domains9
CSS Minified0/6
JS Minified0/24
cash.app DNS Records, Email Authentication & Domain Registration
🤖 AI Summary
cash.app resolves to the IPv4 address 162.159.140.44, but does not support IPv6. IPv6 adoption is increasingly important as IPv4 address space becomes exhausted, and some ISPs and regions are transitioning to IPv6-only connectivity. The domain has 2 A record(s) configured.
The domain name system is managed by 4 name servers: ns-1248.awsdns-28.org, ns-1816.awsdns-35.co.uk, ns-311.awsdns-38.com, and ns-810.awsdns-37.net. Having 4 name servers provides good redundancy — if one fails, the others can continue serving DNS queries. The choice of name servers often indicates the DNS hosting provider or CDN service being used.
Email for cash.app is handled by Google Workspace with 5 MX records configured: aspmx.l.google.com, alt1.aspmx.l.google.com, and alt2.aspmx.l.google.com and 2 more. Multiple MX records provide failover redundancy — if the primary mail server is unavailable, email will be routed to the next available server.
SPF (Sender Policy Framework) is configured, which specifies which mail servers are authorized to send email on behalf of this domain. This helps prevent email spoofing and improves email deliverability. DMARC (Domain-based Message Authentication, Reporting and Conformance) is configured with a reject policy — the strongest setting, instructing receiving servers to reject unauthorized emails entirely. DKIM (DomainKeys Identified Mail) is configured, adding a cryptographic signature to outgoing emails that receiving servers can verify to confirm the email hasn't been tampered with in transit.
DNSSEC is not enabled for cash.app. While not critical for most websites, DNSSEC adds an important security layer by ensuring DNS responses haven't been tampered with during transit. Enabling DNSSEC is recommended for domains handling sensitive data or financial transactions.
Our subdomain enumeration scan discovered 6 active subdomains for cash.app: api.cash.app, developers.cash.app, help.cash.app, shop.cash.app, status.cash.app, and www.cash.app. Active subdomains can reveal the organization's infrastructure, including development environments, API endpoints, and third-party service integrations.
DNS Records
A
162.159.140.44
172.66.0.44
NS
ns-1248.awsdns-28.org
ns-1816.awsdns-35.co.uk
ns-311.awsdns-38.com
ns-810.awsdns-37.net
MX
aspmx.l.google.com
alt1.aspmx.l.google.com
alt2.aspmx.l.google.com
alt3.aspmx.l.google.com
alt4.aspmx.l.google.com
Email & Authentication
MX ProviderGoogle Workspace
Registrar—
Organisation—
Country—
Contact—
Registered—
Expires—
Domain Age—
IPv6 SupportNo
Subdomains (6 found)
api.cash.app developers.cash.app help.cash.app shop.cash.app status.cash.app www.cash.app
cash.app Page Content, Images & Accessibility
🤖 AI Summary
The homepage of cash.app contains 777 words of visible text content. This is a moderate amount of content. The page is structured with 8 H2 headings, 4 H3 headings, 6 H4 headings, 0 H5, and 2 H6 headings.
The page includes 6 images. All images have proper alt text attributes ✓, which is excellent for both accessibility (screen readers) and SEO (search engines can understand image content).
The link structure consists of 44 internal links pointing to other pages on the same domain and 17 external links pointing to third-party websites. There are 24 external JavaScript files, 6 CSS stylesheets, and 0 iframes on the page.
The site implements the following web standards and features: XML Sitemap (helps search engines discover all pages), robots.txt (controls search engine crawling behavior), and Schema.org structured data (BreadcrumbList, ImageObject, ListItem, and Organization).
We detected the following payment methods accepted on cash.app: Visa, JCB, and Afterpay. Offering multiple payment options including credit cards and digital wallets improves customer trust and can increase conversion rates.
The website has social media presence across 4 platforms: Twitter (@cashapp), Instagram (@cashapp), Linkedin (@cash-app), and Tiktok (@cashapp). An active social media presence is a positive trust indicator and helps build brand awareness and customer engagement.
Content Structure
H1The way money should work
H2 Tags8
H3 Tags4
H4 Tags6
H5 Tags0
H6 Tags2
Internal Links44
External Links17
Assets & Features
JavaScript Files24
JS Minified0/24
CSS Files6
CSS Minified0/6
Iframes0
Images6
Missing Alt0
SitemapYes ✓
Robots.txtYes ✓
PWANo
AMPNo
RSS FeedNo
Schema.org Types
BreadcrumbListImageObjectListItemOrganization
Payment Methods Detected
Social Media Presence
Twitter: @cashappInstagram: @cashappLinkedin: @cash-appTiktok: @cashapp
cash.app SEO Analysis, Meta Tags & Open Graph
🤖 AI Summary
The title tag for cash.app is well-optimized at 56 characters: "Send, Receive, Invest, & Manage Your Money with Cash App". The length falls within the ideal range for Google search results, ensuring the full title is displayed without truncation.
The meta description is 137 characters (well-optimized): "Download Cash App to send & receive money instantly, spend with the Cash App Card, buy bitcoin, invest in stocks, & mana...". Google typically displays up to 155-160 characters of the meta description in search results. A compelling meta description with a clear call-to-action can significantly improve click-through rates from search results.
The canonical url is correctly set to https://cash.app/, preventing duplicate content issues and the page language is declared as en.
Open Graph meta tags are configured with 3/4 recommended fields: OG title ("Send, Receive, Invest, & Manage Your Money with Cash App..."), OG description, OG image (social sharing thumbnail), These tags control how the page appears when shared on Facebook, LinkedIn, and other social media platforms that support the Open Graph protocol.
The site implements Schema.org structured data with the following types: BreadcrumbList, ImageObject, ListItem, and Organization. Structured data helps search engines understand the page content and can enable rich results (featured snippets, knowledge panels, star ratings) in Google search results, which can significantly increase click-through rates.
Google SERP Preview
Send, Receive, Invest, & Manage Your Money with Cash App
https://cash.app
Download Cash App to send & receive money instantly, spend with the Cash App Card, buy bitcoin, invest in stocks, & manage your finances.
Meta Tags
TitleSend, Receive, Invest, & Manage Your Money with Cash App...
Title Length56 chars
Meta Desc Length137 chars
H1The way money should work
Languageen
Canonicalhttps://cash.app/
Meta Robotsnot set
Meta Keywordsnot set
Schema.org & Social
Schema TypesBreadcrumbList, ImageObject, ListItem, Organization
OG Type—
OG ImageSet ✓
Twitter Card—
FaviconNot set
Open Graph Preview
cash.app
Send, Receive, Invest, & Manage Your Money with Cash App
Download Cash App to send & receive money instantly, spend with the Cash App Card, buy bitcoin, invest in stocks, & manage your finances.