Nirmidas Biotech · Domain Security

Nirmidas Biotech Domain Security

Domain security

Domain security posture for Nirmidas Biotech, probed live across 1 host(s) and 1 registrable domain(s). 1 host(s) serve HTTPS; 0 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC absent.

CompanyBiotechnologyDiagnosticsLife SciencesMedical ImagingIn Vitro DiagnosticsLaboratory InstrumentsResearch ReagentsNanotechnology

Transport & Host Security

www.nirmidas.com
HTTPS: yes · HSTS: no

Domain (DNS/Email) Security

nirmidas.com
DNSSEC: no · SPF: yes · DMARC: no · CAA: none

Source

Domain Security

nirmidas-biotech-domain-security.yml Raw ↑
generated: '2026-08-26'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts
hosts:
- host: www.nirmidas.com
  https: true
  tls_cert_error: '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate has
    expired (_ssl.c:1082)'
  hsts: null
  tls_certificate:
    subject: CN=www.nirmidas.com
    issuer: 'C=CN, O=WoTrus CA Limited, CN=WoTrus DV Server CA'
    not_before: '2025-05-20'
    not_after: '2026-06-20'
    expired: true
    days_expired_at_probe: 67
  http_to_https_redirect: 301
domains:
- domain: nirmidas.com
  dnssec: false
  caa: []
  spf: true
  dmarc: false
notes: >-
  MATERIAL FINDING — the public website of Nirmidas Biotech cannot be reached by a standards-compliant
  HTTPS client. The leaf certificate served on www.nirmidas.com and nirmidas.com expired on 2026-06-20
  and was still being served on 2026-08-26, so every browser and every automated client presents or
  raises a certificate error before any content is delivered. Every probe recorded in this repository
  therefore had to disable certificate verification. Compounding it, the issuing CA is WoTrus CA Limited
  (the successor of WoSign), whose roots are distrusted by the major browser trust stores — so even a
  freshly reissued certificate from the same chain would not validate. The hosting is Alibaba/Wanwang
  (www.nirmidas.com resolves via wh-au3su8zmnldkkubdddb.my3w.com to 198.11.174.219). No HSTS header is
  served, DNSSEC is not enabled, no CAA records are published, and there is no DMARC record; an SPF
  record is present.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/nirmidas-biotech-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.