Get a snapshot of threejs.org's online performance, security posture, and technology profile.
threejs.org Website Overview & Technology Report
We performed a comprehensive analysis of threejs.org on 2026-06-29. The website returned an HTTP 200 status code with a server response time of 12254ms. The page is served over HTTP/2 protocol with Gzip compression enabled, achieving approximately 60.0% size reduction. The total page weight is 59 KB, and the site is served behind a CDN (Content Delivery Network). The website uses a secure HTTPS connection with a valid SSL certificate issued by Let's Encrypt (DV type). The connection is encrypted using TLS 1.3 with the TLS_AES_128_GCM_SHA256 cipher suite and sha256WithRSAEncryption signature algorithm. The certificate covers 2 domain(s) (Subject Alternative Names) and expires on 2026-09-02, which is 65 days from now. The security headers analysis reveals a score of 0/100 (poor). No security headers are configured, which is a significant security concern. However, the site is missing Content-Security-Policy, Strict-Transport-Security (HSTS), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy, which could expose the site and its users to cross-site scripting (XSS), clickjacking, and other web-based attacks. Our technology detection scan identified 6 technologies across 4 categories powering threejs.org. The detected stack includes React, Google Analytics 4, Zendesk, Vercel, Netlify, and GitHub Pages. The UI is built with React. Based on our comprehensive analysis of domain age, SSL configuration, email authentication, security headers, and blacklist status, threejs.org receives an overall trust score of 60/100, classified as "Likely Safe".
Evaluate trustworthiness based on age, SSL, email authentication, security headers, and blacklist status across 8 threat databases.
threejs.org Trust Score & Safety Analysis
After conducting a thorough safety and legitimacy analysis, threejs.org receives a trust score of 60/100, which places it in the "Likely Safe" category. This score is calculated by evaluating multiple factors including SSL certificate validity, domain registration history, email authentication protocols, security header configuration, and blacklist status across major threat intelligence databases. The analysis identified several positive trust signals: a valid HTTPS connection protecting data in transit and a valid SSL certificate issued by Let's Encrypt with 65 days until expiration. Areas of concern include: the absence of a Content-Security-Policy header, which leaves the site more vulnerable to cross-site scripting (XSS) attacks, no X-Frame-Options header, which could allow the site to be embedded in malicious iframes (clickjacking), missing Referrer-Policy, potentially leaking URL information to third parties, the domain's WHOIS information is hidden behind a privacy service, making it harder to verify the owner's identity, and DNSSEC is not enabled, leaving DNS queries vulnerable to spoofing attacks. While these issues don't necessarily indicate malicious intent, they represent areas where the website's security posture could be improved. We checked threejs.org against 8 major blacklist databases including Google Safe Browsing, Phishtank, Urlhaus, Openphish, Dnsfilter, Spamhaus Dbl, Surbl, and Virustotal. The domain passed all 8 checks with a clean status, meaning it has not been flagged for phishing, malware distribution, spam, or other malicious activities by any of the tested threat intelligence providers.
Security Headers
Blacklist Checks 8/8 Clean ✓
Rankings & Estimates
Discover every technology powering this website — from CMS and frameworks to analytics, payments, and marketing tools.
threejs.org Technology Stack & Detected Technologies
Our technology detection engine scanned threejs.org and identified 6 distinct technologies across 4 categories. This analysis is performed by examining HTTP response headers, HTML source code patterns, JavaScript library fingerprints, CSS framework signatures, and DNS records. UI Library: React — handles the user interface rendering and component management for threejs.org. Analytics: Google Analytics 4 — tracks visitor behavior and provides traffic insights for threejs.org. Support: Zendesk — handles customer support tickets and knowledge bases for threejs.org. Hosting: Vercel, Netlify, and GitHub Pages — provides the server infrastructure for threejs.org. We also extracted the following tracking identifiers: Google Analytics 4 Measurement ID G-JPPX9MZGZ4. These IDs can be used to identify other websites operated by the same organization.
Tracking IDs Detected
Response time, compression, CDN usage, Core Web Vitals, and environmental impact metrics for threejs.org.
threejs.org Performance & Web Vitals Report
threejs.org delivers its homepage in 12254ms (server response time), which is considered slow by industry standards. The total page weight is 59 KB, and we detected 798 resource requests loading assets from 369 third-party domains. A high number of third-party domains can significantly impact page load time due to additional DNS lookups and TLS handshakes required for each domain. The website uses Gzip compression for text-based assets, achieving an estimated 60.0% reduction in transfer size. This reduces bandwidth usage and improves page load times, especially for visitors on slower connections. Asset minification status: 0 out of 1 CSS files and 0 out of 2 JavaScript files are minified. Minifying the remaining 3 unminified file(s) could further reduce page weight by 10-30% for those assets. Minification is a best practice that reduces download sizes without affecting functionality. The site is served through a Content Delivery Network (CDN), which caches static assets at edge servers around the world. This means visitors from different geographic regions receive content from the nearest edge server, significantly reducing latency. CDN usage is particularly important for websites with a global audience, as it can reduce page load times by 40-60% for distant visitors. From an environmental perspective, each page view of threejs.org produces approximately 0.03g of CO₂, earning a carbon rating of A. This places the website among the cleanest on the web, demonstrating efficient use of server resources and optimized content delivery. For reference, the average web page produces about 0.5g of CO₂ per page view. The page weight of 59 KB is the primary factor in this calculation. Core Web Vitals data from the Chrome User Experience Report (CrUX) is not available for threejs.org. This typically means the site doesn't have enough real-world Chrome user traffic to generate statistically significant field data, or the domain is not included in the CrUX dataset. Core Web Vitals (LCP, INP, CLS) are important Google ranking factors that measure real user experience.
Complete DNS record analysis including email authentication (SPF, DMARC, DKIM), registrar details, and subdomain discovery.
threejs.org DNS Records, Email Authentication & Domain Registration
threejs.org resolves to the IPv4 address 185.199.109.153, but does not support IPv6. IPv6 adoption is increasingly important as IPv4 address space becomes exhausted, and some ISPs and regions are transitioning to IPv6-only connectivity. The domain has 4 A record(s) configured. The domain name system is managed by 4 name servers: ns1.dnsimple.com, ns2.dnsimple-edge.net, ns3.dnsimple.com, and ns4.dnsimple-edge.org. Having 4 name servers provides good redundancy — if one fails, the others can continue serving DNS queries. The choice of name servers often indicates the DNS hosting provider or CDN service being used. SPF is not configured, meaning any server could potentially send emails pretending to be from this domain. This is a significant email security concern. DMARC is not configured, leaving the domain vulnerable to email spoofing and phishing attacks that impersonate this domain. DKIM was not detected. Without DKIM, recipients cannot cryptographically verify that emails claiming to be from this domain are authentic. DNSSEC is not enabled for threejs.org. While not critical for most websites, DNSSEC adds an important security layer by ensuring DNS responses haven't been tampered with during transit. Enabling DNSSEC is recommended for domains handling sensitive data or financial transactions.
Content structure, media assets, cookie usage, payment methods, and social media presence for threejs.org.
threejs.org Page Content Analysis
The homepage of threejs.org contains 37 words of visible text content. This is a relatively short page — adding more descriptive content could improve search engine visibility. The page is structured with 6 H2 headings, 0 H3 headings, 0 H4 headings. The page includes 228 images. 228 images (100%) are missing alt text attributes, which is a significant concern for both accessibility and SEO. Screen readers rely on alt text to describe images to visually impaired users, and search engines use alt text to understand image content. Only 0% of images have proper alt text — we recommend adding descriptive alt attributes to all images. The link structure consists of 5 internal links pointing to other pages on the same domain and 242 external links pointing to third-party websites. There are 2 external JavaScript files, 1 CSS stylesheets, and 0 iframes on the page. Notable missing features: XML Sitemap, robots.txt, and Schema.org structured data. Adding these could improve search engine discoverability and rich result eligibility. The website has social media presence across 2 platforms: Twitter (@threejs) and Github (@mrdoob). An active social media presence is a positive trust indicator and helps build brand awareness and customer engagement.
Social Media Presence 2 platforms
Evaluate on-page SEO factors including meta tags, Schema.org markup, content metrics, social presence, and environmental impact.
threejs.org SEO Analysis, Meta Tags & Content
The title tag for threejs.org is well-optimized at 32 characters: "Three.js – JavaScript 3D Library". The length falls within the ideal range for Google search results, ensuring the full title is displayed without truncation. No meta description is configured for threejs.org. This is a critical SEO oversight — without a meta description, Google will auto-generate a snippet from page content, which may not accurately represent the page or entice users to click. Adding a unique, compelling meta description of 120-155 characters is strongly recommended. The page language is declared as en and a favicon is configured. Open Graph meta tags are configured with 1/4 recommended fields: OG image (social sharing thumbnail), These tags control how the page appears when shared on Facebook, LinkedIn, and other social media platforms that support the Open Graph protocol. A Twitter Card of type summary_large_image is configured, which controls how links appear when shared on Twitter/X. The "summary_large_image" type displays a large image preview, which typically generates higher engagement rates than the basic card type.