Computers, Electronics and Technology / Web Hosting and Domain Names
Origin
Japan
Global rank
#18,629
Rank in Japan
#1,257
Updated at
B86/100
Security level
Good
Data confidence
High
Scope checked
90.2%
The higher the score, the more externally observable protections the system has recorded. This page does not certify that the website is reputable, legitimate, or completely free of vulnerabilities.
Is the website “lolipop.jp” safe?
As of September 3, 2026 at 12:46, lolipop.jp has a security score of 86/100 (grade B: “Good”). CyStack’s automated assessment recorded 11 issues to review after completing 90.2% of applicable checks. The website owner should address “Session cookies protected from scripts (HttpOnly)” first, then review the remaining items in order of impact.
Does lolipop.jp show known scam, phishing, or malware signals?
At assessment time, CyStack did not find lolipop.jp or related infrastructure on any scam, phishing, or malware warning list after checking 5 online reputation sources. This result reflects external observations; it does not guarantee absolute safety or verify the organization’s legal status or reputation.
Potentially exposed domain email addressesChecks infostealer data only for email addresses whose domain exactly matches this target. A record is not counted merely because someone visited or signed in to this website.7 matching email exposure records
7Matching email exposure records
3Related infected devices (estimated)
These matching email records were observed previously, but they may already have been addressed or may no longer be valid. The device count estimates infected devices associated with these email records; it is not the number of devices owned by the organization.
Frequently asked questions
What affects the security of lolipop.jp?
A valid SSL certificate still does not prove that lolipop.jp is safe, legitimate, or free of scam signals. For a more complete assessment, this report also checks phishing and malware, exposed email records, IPs and open ports, subdomains, technologies, and CVEs that may apply to observed versions.
Does lolipop.jp use HTTPS, and is its SSL certificate valid?
lolipop.jp used a valid SSL certificate at assessment time, valid until October 29, 2026. This status may change when the certificate expires or the server configuration changes.
Data compiled from CyStack cybersecurity monitoring systems
CyStack compiles scan results from its internal cybersecurity monitoring systems, including CyStack VulnScan and CyStack Threat Intelligence, together with publicly available Internet data. The assessment only observes and analyzes information already available; it does not attempt unauthorized access, test passwords, send exploit code, or change or disrupt the assessed system.
These 3 failed checks or warnings have the greatest impact on the result for lolipop.jp.
Session cookies protected from scripts (HttpOnly)1 of 1 observed session-like cookie(s) on the inspected root response do not use HttpOnly.High
Why it matters
HttpOnly prevents browser scripts from directly reading a cookie. It does not fix script injection, but it makes theft of session and authentication cookies more difficult.
What to do
Set HttpOnly on session and authentication cookies unless the application has a documented need to read them in browser code.
Scope of this check
This check only evaluates the homepage response and content that the scanner could reach. Other pages and sign-in flows may use different settings.
Evidence and check scope
Session-related cookies:
1
Session cookies using HttpOnly:
0
Response inspected:
Homepage response
Host requested:
lolipop.jp
Host observed:
lolipop.jp
Cookies sent only over HTTPS (Secure)1 of 1 observed session-like cookie(s) on the inspected root response do not use Secure.High
Why it matters
The Secure attribute prevents a browser from sending a cookie over unencrypted HTTP. This bounded check scores cookies whose names look session- or authentication-related; other cookies are reported as context but do not by themselves prove that sensitive data is exposed.
What to do
Set Secure on every session, authentication, and other sensitive cookie served by the HTTPS application.
Allowed browser content (CSP)The inspected root HTML response does not include a Content-Security-Policy header.High
Why it matters
Content Security Policy (CSP) limits where scripts, styles, frames, and other browser content may come from. A strong policy reduces the impact if an attacker manages to inject content into a page.
What to do
Define only the sources the application needs, test the policy before activating it, and avoid broad wildcard (*) rules, unsafe-inline, and unsafe-eval where possible.
Leak evidenceMost recent observation:
Email addressRelated infected deviceInfection evidenceRecorded time
Email addressR*******@lolipop.jpRelated infected deviceD************** (Windows 10 x64)Côte d’IvoireIOC reference: IOC-456B9DC4B9Infection evidenceAcreedRecorded timeEmail addressH*******@lolipop.jpRelated infected device(Windows 11)United StatesIOC reference: IOC-BC549EB2C3Infection evidenceEmail addressC*********@lolipop.jpRelated infected deviceNo safely shareable device details are available for this record.IOC reference: IOC-FFB1AB93BDInfection evidenceStealCEmail addressS********@lolipop.jpRelated infected deviceNo safely shareable device details are available for this record.IOC reference: IOC-FFB1AB93BDInfection evidenceStealCEmail addressS*********@lolipop.jpRelated infected deviceNo safely shareable device details are available for this record.IOC reference: IOC-FFB1AB93BDInfection evidenceStealCEmail addressH*************@lolipop.jpRelated infected deviceNo safely shareable device details are available for this record.IOC reference: IOC-FFB1AB93BDInfection evidenceStealCEmail addressG*******@lolipop.jpRelated infected deviceNo safely shareable device details are available for this record.IOC reference: IOC-FFB1AB93BDInfection evidenceStealC
Data provided by
Discovered subdomains (1,215+)Subdomains discovered by CyStack, with sensitive-looking names shown first. Availability is verified during this assessment; individual subdomains have not been separately security-tested.Partial
This is a quick, point-in-time check from outside the organization. It can surface visible risks, but it does not replace penetration testing or an authenticated assessment.
Have @lolipop.jp email addresses appeared in exposed data or information-stealer (infostealer) logs?
There are currently 7 exposed email records matching the lolipop.jp domain. These records may be old or already resolved. The website owner should verify them before resetting passwords or locking related accounts.
What technologies does lolipop.jp use, and which CVEs (security vulnerabilities) may apply?
The assessment identified 15 technologies on lolipop.jp, including 2 with a version, but CVE matching did not complete for every version. An empty result should not be treated as proof that no vulnerability exists.
Which public IPs, services, and ports does lolipop.jp expose?
The assessment observed 1 public IPs and 2 open ports for lolipop.jp. An open port is not the same as a vulnerability, but the website owner should keep every public service updated and appropriately restrict access.
How many subdomains of lolipop.jp have been discovered?
The assessment observed 1,215+ public subdomains of lolipop.jp. This list can reveal additional entry points such as APIs, administration systems, or test environments, but it does not mean that every subdomain is risky.