Get a snapshot of universalis.app's online performance, security posture, and technology profile.
universalis.app Website Overview & Technology Report
We performed a comprehensive analysis of universalis.app on 2026-06-28. The website returned an HTTP 200 status code with a server response time of 6221ms. The page is served over HTTP/2 protocol with Gzip compression enabled, achieving approximately 60.0% size reduction. The total page weight is 53 KB, and the site is served behind a CDN (Content Delivery Network). Warning: The website does not have a valid SSL certificate. Visitors may see security warnings in their browser, and data transmitted to and from this website is not encrypted. The security headers analysis reveals a score of 0/100 (poor). No security headers are configured, which is a significant security concern. However, the site is missing Content-Security-Policy, Strict-Transport-Security (HSTS), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy, which could expose the site and its users to cross-site scripting (XSS), clickjacking, and other web-based attacks. Our technology detection scan identified 3 technologies across 3 categories powering universalis.app. The detected stack includes Next.js css, Webpack, and Google Fonts. The site uses Next.js as its primary framework (version css). Based on our comprehensive analysis of domain age, SSL configuration, email authentication, security headers, and blacklist status, universalis.app receives an overall trust score of 58/100, classified as "Caution Advised".
Evaluate trustworthiness based on age, SSL, email authentication, security headers, and blacklist status across 8 threat databases.
universalis.app Trust Score & Safety Analysis
After conducting a thorough safety and legitimacy analysis, universalis.app receives a trust score of 58/100, which places it in the "Caution Advised" category. This score is calculated by evaluating multiple factors including SSL certificate validity, domain registration history, email authentication protocols, security header configuration, and blacklist status across major threat intelligence databases. The analysis identified several positive trust signals: a valid HTTPS connection protecting data in transit, SPF (Sender Policy Framework) email authentication preventing email spoofing, and DKIM (DomainKeys Identified Mail) providing cryptographic email verification. Areas of concern include: the absence of a Content-Security-Policy header, which leaves the site more vulnerable to cross-site scripting (XSS) attacks, no X-Frame-Options header, which could allow the site to be embedded in malicious iframes (clickjacking), missing Referrer-Policy, potentially leaking URL information to third parties, the domain's WHOIS information is hidden behind a privacy service, making it harder to verify the owner's identity, and DNSSEC is not enabled, leaving DNS queries vulnerable to spoofing attacks. While these issues don't necessarily indicate malicious intent, they represent areas where the website's security posture could be improved. We checked universalis.app against 8 major blacklist databases including Google Safe Browsing, Phishtank, Urlhaus, Openphish, Dnsfilter, Spamhaus Dbl, Surbl, and Virustotal. The domain passed all 8 checks with a clean status, meaning it has not been flagged for phishing, malware distribution, spam, or other malicious activities by any of the tested threat intelligence providers.
Security Headers
Blacklist Checks 8/8 Clean ✓
Discover every technology powering this website — from CMS and frameworks to analytics, payments, and marketing tools.
universalis.app Technology Stack & Detected Technologies
Our technology detection engine scanned universalis.app and identified 3 distinct technologies across 3 categories. This analysis is performed by examining HTTP response headers, HTML source code patterns, JavaScript library fingerprints, CSS framework signatures, and DNS records. Framework: Next.js (version css) — provides the application framework and routing for universalis.app. Build Tool: Webpack — bundles and optimizes the JavaScript and CSS assets for universalis.app. Fonts: Google Fonts — delivers web fonts for typography for universalis.app.
Complete DNS record analysis including email authentication (SPF, DMARC, DKIM), registrar details, and subdomain discovery.
universalis.app DNS Records, Email Authentication & Domain Registration
universalis.app resolves to the IPv4 address 172.67.154.25 and also supports IPv6 (2606:4700:3036::6815:20bd), demonstrating modern network infrastructure readiness. The domain has 2 A record(s) configured. The domain name system is managed by 2 name servers: hera.ns.cloudflare.com and vern.ns.cloudflare.com. Having 2 name servers provides good redundancy — if one fails, the others can continue serving DNS queries. The choice of name servers often indicates the DNS hosting provider or CDN service being used. Email for universalis.app is handled by mailgun.org with 2 MX records configured: mxa.mailgun.org and mxb.mailgun.org. Multiple MX records provide failover redundancy — if the primary mail server is unavailable, email will be routed to the next available server. SPF (Sender Policy Framework) is configured, which specifies which mail servers are authorized to send email on behalf of this domain. This helps prevent email spoofing and improves email deliverability. DMARC is not configured, leaving the domain vulnerable to email spoofing and phishing attacks that impersonate this domain. DKIM (DomainKeys Identified Mail) is configured, adding a cryptographic signature to outgoing emails that receiving servers can verify to confirm the email hasn't been tampered with in transit. DNSSEC is not enabled for universalis.app. While not critical for most websites, DNSSEC adds an important security layer by ensuring DNS responses haven't been tampered with during transit. Enabling DNSSEC is recommended for domains handling sensitive data or financial transactions. Our subdomain enumeration scan discovered 4 active subdomains for universalis.app: docs.universalis.app, staging.universalis.app, status.universalis.app, and www.universalis.app. Active subdomains can reveal the organization's infrastructure, including development environments, API endpoints, and third-party service integrations.
Subdomains 4 found
TXT Records / Service Verifications 3
Evaluate on-page SEO factors including meta tags, Schema.org markup, content metrics, social presence, and environmental impact.
universalis.app SEO Analysis, Meta Tags & Content
The title tag for universalis.app is good at 11 characters: "Universalis". The length is acceptable, though it may be slightly truncated in some search result displays. The meta description is 126 characters (well-optimized): "Final Fantasy XIV Online: Market Board aggregator. Find Prices, track Item History and create Price Alerts. Anywhere, an...". Google typically displays up to 155-160 characters of the meta description in search results. A compelling meta description with a clear call-to-action can significantly improve click-through rates from search results. A favicon is configured. Open Graph meta tags are configured with 4/4 recommended fields: OG title ("Universalis..."), OG description, OG image (social sharing thumbnail), OG type (website). These tags control how the page appears when shared on Facebook, LinkedIn, and other social media platforms that support the Open Graph protocol. The meta keywords tag contains 6 terms including Universalis, FFXIV, Market, Board, and Database. Note: Google has officially confirmed that it does not use the meta keywords tag as a ranking signal. However, some other search engines (Bing, Yandex) may still reference it.
Social Media Presence 1 platforms
Other domains that share the same tracking IDs, IP address, or analytics properties with universalis.app.