3Bar Biologics · Domain Security

3Bar Biologics Domain Security

Domain security

Domain security posture for 3Bar Biologics, probed live across 2 host(s) and 1 registrable domain(s). 1 host(s) serve HTTPS (up to TLSv1.3); 1 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC absent.

CompanyAgricultureAgTechBiotechnologyAgricultural BiologicalsBiomanufacturingCDMOMicrobialsCrop InputsSustainabilityContract Manufacturing

Transport & Host Security

www.3barbiologics.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 21 15:20:23 2026 GMT
3barbiologics.com
HTTPS: no · HSTS: no

Domain (DNS/Email) Security

3barbiologics.com
DNSSEC: no · SPF: yes · DMARC: no · CAA: none

Source

Domain Security

3bar-biologics-domain-security.yml Raw ↑
generated: '2026-09-05'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts
hosts:
- host: www.3barbiologics.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct 21 15:20:23 2026 GMT
  hsts: true
  hsts_max_age: 300
  hsts_note: >-
    300 seconds is five minutes. The RFC 6797 preload threshold and common practice is 31536000 (one
    year); a five-minute max-age gives a returning visitor essentially no protection against an
    SSL-stripping downgrade, because the policy has almost always expired between visits. This is
    the Pantheon platform default for a site that has not enabled full HSTS.
- host: 3barbiologics.com
  https: false
  https_error: tls-certificate-name-mismatch
  hsts: null
  note: >-
    The apex domain is broken over HTTPS. It resolves to Pantheon (23.185.0.2) but the certificate
    presented is CN=pantheonsite.io, whose SANs are *.getpantheon.com, *.gotpantheon.com,
    *.pantheon.io, *.pantheonsite.io, getpantheon.com, gotpantheon.com and pantheonsite.io — none of
    which covers 3barbiologics.com. Every browser shows a certificate warning. Plain HTTP to the
    apex returns 404 rather than redirecting to www, so there is no working path from
    `3barbiologics.com` to the site by either scheme. A visitor who types the domain without `www.`
    does not reach 3Bar Biologics.
domains:
- domain: 3barbiologics.com
  dnssec: false
  caa: []
  spf: true
  dmarc: false
findings:
- id: apex-tls-mismatch
  severity: high
  summary: The apex domain serves a certificate that does not cover it, and does not redirect on HTTP.
  detail: >-
    https://3barbiologics.com/ fails the TLS handshake with a name mismatch; http://3barbiologics.com/
    returns 404 with no Location header. Only https://www.3barbiologics.com/ works.
  evidence:
  - {url: 'https://3barbiologics.com/', http_status: 0, error: certificate name mismatch (CN=pantheonsite.io)}
  - {url: 'http://3barbiologics.com/', http_status: 404, redirect_url: null}
  - {url: 'https://www.3barbiologics.com/', http_status: 200}
  remediation_owner: provider
- id: preproduction-hostname-leak
  severity: medium
  summary: >-
    The production homepage hard-codes 79 absolute URLs pointing at Pantheon platform hostnames,
    including the site's only Privacy Policy link.
  detail: >-
    www.3barbiologics.com serves HTML containing 26 absolute links to
    https://dev-3bar-biologics.pantheonsite.io and 53 to https://live-3bar-biologics.pantheonsite.io.
    The dev host is reachable, returns 200, and serves the same WordPress REST API as production —
    it is a pre-production environment exposed to the public internet and linked to from the
    production site. The Privacy Policy link in the page footer points at
    https://dev-3bar-biologics.pantheonsite.io/privacy-policy/ rather than at the canonical
    www.3barbiologics.com/privacy-policy/, which does exist and returns 200. Font assets are also
    loaded cross-origin from the live-* platform host.
  consequence: >-
    Visitors following the Privacy Policy link land on an unbranded platform hostname. Search engines
    and AI crawlers see duplicate content on three hostnames, splitting canonical signal. Anything
    staged on the dev environment is publicly readable, including through its own REST API.
  evidence:
  - {url: 'https://www.3barbiologics.com/', http_status: 200, finding: '26 dev-* and 53 live-* absolute pantheonsite.io URLs in the served HTML'}
  - {url: 'https://dev-3bar-biologics.pantheonsite.io/privacy-policy/', http_status: 200, finding: 'the target of the production footer Privacy Policy link'}
  - {url: 'https://dev-3bar-biologics.pantheonsite.io/wp-json/', http_status: 200, finding: 'the pre-production environment serves the same REST API'}
  - {url: 'https://www.3barbiologics.com/privacy-policy/', http_status: 200, finding: 'the canonical page exists and is not the one linked'}
  remediation_owner: provider
- id: no-dmarc
  severity: medium
  summary: SPF is published but DMARC is not.
  detail: >-
    An SPF record exists for 3barbiologics.com, but there is no _dmarc TXT record, so there is no
    policy telling receivers what to do with mail that fails authentication and no reporting channel.
    The company publishes a sales address (Sales@3BarBiologics.com) on its site, which is the address
    a spoofing campaign would impersonate.
  remediation_owner: provider
- id: no-dnssec-no-caa
  severity: low
  summary: Neither DNSSEC nor CAA is configured for 3barbiologics.com.
  detail: >-
    No DNSSEC signing and no CAA record restricting which certificate authorities may issue for the
    domain. Both are common absences and neither is exploitable on its own.
  remediation_owner: provider
- id: hsts-max-age-300
  severity: low
  summary: HSTS is present on www but expires after five minutes.
  detail: See the hsts_note on the www host above.
  remediation_owner: provider

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/3bar-biologics-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.