Centrexion Therapeutics · Domain Security
Centrexion Therapeutics Domain Security
Domain security
Domain security posture for Centrexion Therapeutics, probed live across 1 host(s) and 1 registrable domain(s). 1 host(s) serve HTTPS (up to TLSv1.3); 0 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC absent.
CompanyBiopharmaceuticalPharmaceuticalsChronic Painnon-opioid-analgesicsImmunologyinflammationClinical TrialsLife Sciencescontent-api
Transport & Host Security
centrexion.com
HTTPS: yes
· TLS: TLSv1.3
· HSTS: no
· cert expires: Oct 23 21:24:08 2026 GMT
Domain (DNS/Email) Security
centrexion.com
DNSSEC: no
· SPF: yes
· DMARC: no
· CAA: none
Source
Domain Security
generated: '2026-08-09'
method: probed
source: live DNS/TLS/HTTP probes of the centrexion.com host and registrable domain
note: >-
Probed 2026-08-09 by the API Evangelist enrichment pipeline. Only Centrexion Therapeutics' own
host and registrable domain are recorded. The apis.yml humanURL for the content API points at
developer.wordpress.org (the upstream WordPress REST handbook that documents the wp/v2 contract);
that host is not operated by Centrexion and its posture is deliberately excluded so it is not
misattributed to this provider. The site is a WordPress deployment served by nginx and hosted on
WP Engine (x-powered-by: WP Engine). HTTPS is enforced by redirect (http:// and www. both 301 to
https://centrexion.com/) but no Strict-Transport-Security header is sent, so the redirect is the
only downgrade protection. No CAA records and no DNSSEC are published; DNS is delegated to
Register.com.
hosts:
- host: centrexion.com
https: true
tls_version: TLSv1.3
cert_expires: Oct 23 21:24:08 2026 GMT
hsts: false
server: nginx
origin: WP Engine (x-powered-by response header observed)
http_to_https_redirect: 301
www_redirect: 301 to apex
domains:
- domain: centrexion.com
dnssec: false
caa: []
spf: true
spf_record: 'v=spf1 include:1xalkvunf.spf.checkpoint-spf.com -all'
dmarc: false
nameservers:
- dns101.register.com
- dns102.register.com
observations:
- >-
No DMARC record is published at _dmarc.centrexion.com (empty TXT response). SPF is present and
strict (-all, delegated to Check Point's hosted email-security SPF service), but with no DMARC
policy there is no alignment enforcement and no aggregate or forensic reporting, so the domain has
neither spoofing enforcement beyond SPF nor any visibility into abuse.
- >-
DANGLING CNAME — investors.centrexion.com is a CNAME to centrexion.gcs-web.com, and that target
has no A record while its parent zone gcs-web.com is live on AWS Route 53 nameservers. The name
therefore resolves as a CNAME but terminates in NXDOMAIN, and nothing answers on 80 or 443. A
CNAME left pointing at a de-provisioned host on a third-party investor-relations platform is the
classic subdomain-takeover precondition; whoever can claim that hostname on the upstream platform
inherits a subdomain of centrexion.com. Recommend deleting the record or reclaiming the target.
- >-
portal.centrexion.com resolves to 72.20.122.198 but both 443 and 80 are closed/filtered — a stale
A record for a host that no longer serves. sharepoint.centrexion.com (66.227.71.31) behaves the
same way. Neither is a live surface; both are residue.
- No Strict-Transport-Security header on the site root.
- No Content-Security-Policy header on the site root.
- No X-Content-Type-Options, X-Frame-Options, Referrer-Policy or Permissions-Policy header on the site root.
- >-
API responses under /wp-json do send x-content-type-options nosniff and x-robots-tag noindex, and
expose Access-Control-Expose-Headers for X-WP-Total, X-WP-TotalPages and Link.
- No /.well-known/security.txt (RFC 9116) published — see well-known/centrexion-therapeutics-well-known.yml.
- >-
No api., developer., docs., status., trust., mcp., support., vpn., intranet., files. or careers.
subdomain resolves for centrexion.com (NXDOMAIN on all eleven), consistent with a company that
runs no developer program and no status or trust surface.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/centrexion-therapeutics-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.