NiKang Therapeutics · Domain Security

Nikang Therapeutics Domain Security

Domain security

Domain security posture for NiKang Therapeutics, probed live across 1 host(s) and 1 registrable domain(s). 1 host(s) serve HTTPS (up to TLSv1.3); 0 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=reject).

CompanyBiotechnologyPharmaceuticalsOncologyPrecision MedicineDrug DiscoveryTargeted Protein DegradationClinical TrialsLife Sciencescontent-api

Transport & Host Security

www.nikangtx.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Nov 8 04:56:30 2026 GMT

Domain (DNS/Email) Security

nikangtx.com
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none

Source

Domain Security

Raw ↑
generated: '2026-08-26'
method: probed
source: >-
  Live DNS/TLS/HTTP probes of the hosts NiKang Therapeutics controls, run 2026-08-26 by
  0-working/probe-domain-security.py and then trimmed by hand. The tool also probed
  developer.wordpress.org and oembed.com because those are the humanURL hosts on the API entries;
  both were removed, because they are upstream specification/documentation hosts that NiKang does
  not operate and their posture must not be credited to NiKang.
note: >-
  www.nikangtx.com terminates TLS at Cloudflare in front of a WP Engine origin. HSTS is NOT set on
  either the site HTML or the /wp-json responses, and no CAA record is published for nikangtx.com,
  so any CA may issue for the zone. Email authentication is the strongest part of the posture:
  SPF is published and DMARC is at policy `reject`. DNSSEC is not enabled on the zone.
hosts:
- host: www.nikangtx.com
  https: true
  tls_version: TLSv1.3
  cert_expires: 'Nov  8 04:56:30 2026 GMT'
  hsts: false
  edge: >-
    Cloudflare (server header `cloudflare`, cf-ray present) in front of a WP Engine origin
    (x-powered-by header `WP Engine`).
  notes: >-
    /wp-json responses carry `x-content-type-options: nosniff` and `x-robots-tag: noindex`. No
    Strict-Transport-Security, no Content-Security-Policy and no Referrer-Policy header was
    returned on either the HTML root or the JSON API.
domains:
- domain: nikangtx.com
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/nikang-therapeutics-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.