3Bar Biologics Domain Security
Domain security posture for 3Bar Biologics, probed live across 2 host(s) and 1 registrable domain(s). 1 host(s) serve HTTPS (up to TLSv1.3); 1 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC absent.
Transport & Host Security
Domain (DNS/Email) Security
Source
Domain Security
generated: '2026-09-05'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts
hosts:
- host: www.3barbiologics.com
https: true
tls_version: TLSv1.3
cert_expires: Oct 21 15:20:23 2026 GMT
hsts: true
hsts_max_age: 300
hsts_note: >-
300 seconds is five minutes. The RFC 6797 preload threshold and common practice is 31536000 (one
year); a five-minute max-age gives a returning visitor essentially no protection against an
SSL-stripping downgrade, because the policy has almost always expired between visits. This is
the Pantheon platform default for a site that has not enabled full HSTS.
- host: 3barbiologics.com
https: false
https_error: tls-certificate-name-mismatch
hsts: null
note: >-
The apex domain is broken over HTTPS. It resolves to Pantheon (23.185.0.2) but the certificate
presented is CN=pantheonsite.io, whose SANs are *.getpantheon.com, *.gotpantheon.com,
*.pantheon.io, *.pantheonsite.io, getpantheon.com, gotpantheon.com and pantheonsite.io — none of
which covers 3barbiologics.com. Every browser shows a certificate warning. Plain HTTP to the
apex returns 404 rather than redirecting to www, so there is no working path from
`3barbiologics.com` to the site by either scheme. A visitor who types the domain without `www.`
does not reach 3Bar Biologics.
domains:
- domain: 3barbiologics.com
dnssec: false
caa: []
spf: true
dmarc: false
findings:
- id: apex-tls-mismatch
severity: high
summary: The apex domain serves a certificate that does not cover it, and does not redirect on HTTP.
detail: >-
https://3barbiologics.com/ fails the TLS handshake with a name mismatch; http://3barbiologics.com/
returns 404 with no Location header. Only https://www.3barbiologics.com/ works.
evidence:
- {url: 'https://3barbiologics.com/', http_status: 0, error: certificate name mismatch (CN=pantheonsite.io)}
- {url: 'http://3barbiologics.com/', http_status: 404, redirect_url: null}
- {url: 'https://www.3barbiologics.com/', http_status: 200}
remediation_owner: provider
- id: preproduction-hostname-leak
severity: medium
summary: >-
The production homepage hard-codes 79 absolute URLs pointing at Pantheon platform hostnames,
including the site's only Privacy Policy link.
detail: >-
www.3barbiologics.com serves HTML containing 26 absolute links to
https://dev-3bar-biologics.pantheonsite.io and 53 to https://live-3bar-biologics.pantheonsite.io.
The dev host is reachable, returns 200, and serves the same WordPress REST API as production —
it is a pre-production environment exposed to the public internet and linked to from the
production site. The Privacy Policy link in the page footer points at
https://dev-3bar-biologics.pantheonsite.io/privacy-policy/ rather than at the canonical
www.3barbiologics.com/privacy-policy/, which does exist and returns 200. Font assets are also
loaded cross-origin from the live-* platform host.
consequence: >-
Visitors following the Privacy Policy link land on an unbranded platform hostname. Search engines
and AI crawlers see duplicate content on three hostnames, splitting canonical signal. Anything
staged on the dev environment is publicly readable, including through its own REST API.
evidence:
- {url: 'https://www.3barbiologics.com/', http_status: 200, finding: '26 dev-* and 53 live-* absolute pantheonsite.io URLs in the served HTML'}
- {url: 'https://dev-3bar-biologics.pantheonsite.io/privacy-policy/', http_status: 200, finding: 'the target of the production footer Privacy Policy link'}
- {url: 'https://dev-3bar-biologics.pantheonsite.io/wp-json/', http_status: 200, finding: 'the pre-production environment serves the same REST API'}
- {url: 'https://www.3barbiologics.com/privacy-policy/', http_status: 200, finding: 'the canonical page exists and is not the one linked'}
remediation_owner: provider
- id: no-dmarc
severity: medium
summary: SPF is published but DMARC is not.
detail: >-
An SPF record exists for 3barbiologics.com, but there is no _dmarc TXT record, so there is no
policy telling receivers what to do with mail that fails authentication and no reporting channel.
The company publishes a sales address (Sales@3BarBiologics.com) on its site, which is the address
a spoofing campaign would impersonate.
remediation_owner: provider
- id: no-dnssec-no-caa
severity: low
summary: Neither DNSSEC nor CAA is configured for 3barbiologics.com.
detail: >-
No DNSSEC signing and no CAA record restricting which certificate authorities may issue for the
domain. Both are common absences and neither is exploitable on its own.
remediation_owner: provider
- id: hsts-max-age-300
severity: low
summary: HSTS is present on www but expires after five minutes.
detail: See the hsts_note on the www host above.
remediation_owner: provider
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
curl "https://apis.io/api/v1/security/3bar-biologics-domain-security"
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.