Website profiles · Technology insights · Alternatives

codepen.io Paid content

Categories: Development

Build, share & learn with CodePen 2.0, the best community for developers with an all new online code editor featuring a file system, compiler, realtime & async collaboration, deployment, and more.

Visit website

Updated: 2026-09-03 16:19 Language: English (default) Access: Normal

Profile views 16 Outbound visits 7
CodePen Full homepage screenshot

Website Overview

An established domain and managed infrastructure suggest continuity of operations and may support dependable delivery, although neither guarantees service quality.

Domain and Registration

Registered in 2012, this domain has about 14 years of history. That suggests continuity, although ownership and purpose may have changed. Transfer-protection status is present, helping reduce the risk of unauthorized domain transfers. The registrar is Gandi SAS, a widely used domain service provider. The domain uses the common .io extension, which is not an independent safety signal.

DNS and Email

Nameservers are provided by Cloudflare, indicating managed DNS hosting. MX records point to the Google Workspace email service. DNSSEC is enabled, allowing validating resolvers to authenticate signed DNS data. No CNAME was found; the observed records resolve directly to addresses. SPF and DMARC are configured. DKIM status is unknown.

TLS and Certificates

The public key uses EC with 256 bits. The server supplied a complete certificate chain. No organization name is present in the certificate; the available fields are consistent with domain validation. The certificate was issued within the Google Trust Services cloud or CDN ecosystem. The certificate's total validity is about 90 days, consistent with a short renewal cycle.

HTTP and Browser Security

The response lacks these common security headers: X-Content-Type-Options, Referrer-Policy, Permissions-Policy, clickjacking protection. No X-Powered-By header was found, reducing one common source of backend fingerprinting information. The cf-ray response header indicates a CDN or caching proxy in the delivery path. No obvious internal addresses or debug information were found in the headers. The Server header identifies cloudflare without an exact version.

Technology Stack Analysis

The public page identifies Cloudflare without precise versions, leaving fewer clues for version-specific scanning.

Search and Social Sharing

Unknown

Hosting and Email

DNSCloudflare
HostingCloudflare
EmailGoogle Workspace
Location United States flagUnited States 2606:4700::6810:9320

Pages, Search and Sharing

Meta descriptionBuild, share & learn with CodePen 2.0, the best community for developers with an all new online code editor featuring a file system, compiler, realtime & async collaboration, deployment, and more.
Canonical URLNot detected
LanguageEnglish (default)
Twitter CardNot detected
All bots 1 allowed · 0 disallowed
  • Allow/
amazonbot 0 allowed · 1 disallowed
  • Disallow/
applebot-extended 0 allowed · 1 disallowed
  • Disallow/
bytespider 0 allowed · 1 disallowed
  • Disallow/
ccbot 0 allowed · 1 disallowed
  • Disallow/
claudebot 0 allowed · 1 disallowed
  • Disallow/
cloudflarebrowserrenderingcrawler 0 allowed · 1 disallowed
  • Disallow/
google-extended 0 allowed · 1 disallowed
  • Disallow/
gptbot 0 allowed · 1 disallowed
  • Disallow/
meta-externalagent 0 allowed · 1 disallowed
  • Disallow/

No sitemaps found

Registration details RDAP / WHOIS

RegistrarGandi SAS
Registered2012-02-26
Expires2028-02-26
Domain statusclientTransferProhibited https://icann.org/epp#clientTransferProhibited
Nameserversalbert.ns.cloudflare.com、kristin.ns.cloudflare.com
DNSSECsigned

DNS records

TypeNameValueTTLPriority
Acodepen.io104.16.147.32300
Acodepen.io104.16.163.32300
AAAAcodepen.io2606:4700::6810:9320300
AAAAcodepen.io2606:4700::6810:a320300
MXcodepen.ioaspmx.l.google.com3001
MXcodepen.ioalt1.aspmx.l.google.com3005
MXcodepen.ioalt2.aspmx.l.google.com3005
MXcodepen.ioaspmx2.googlemail.com30010
MXcodepen.ioaspmx3.googlemail.com30010
NScodepen.ioalbert.ns.cloudflare.com86400
NScodepen.iokristin.ns.cloudflare.com86400
TXTcodepen.iogoogle-site-verification=ee6yZSYLRMH7NdG8DSox4-fH0btH7GdMbMyY7zHenxY300
TXTcodepen.iov=spf1 include:s43465759.fdmarc.net ~all300
DScodepen.io2371 13 2 b8d4185e08c97db614e5aba82cd4a9372a7ad474c35ad2b752d6dc2e5c579ab63600
DMARC_dmarc.codepen.iov=DMARC1; p=quarantine; rua=mailto:[email protected]; aspf=s; adkim=s300

TLS and certificates

AssessmentNormal configuration
Supported protocolsTLSv1.2、TLSv1.3
Negotiated protocolTLSv1.3
Certificate subjectcodepen.io
IssuerGoogle Trust Services
Valid until2026-10-12T03:43 · Remaining when checked: 38 days
Verification detailsCertificate trust: Passed · Hostname match: Passed

HTTP response headers

HeaderValue
content-typetext/html; charset=utf-8
cache-controlprivate, no-cache, no-store, max-age=0, must-revalidate
servercloudflare
strict-transport-securitymax-age=31536000; includeSubDomains; preload
content-security-policydefault-src 'self'; base-uri 'self'; block-all-mixed-content; connect-src blob: *; font-src data: *; frame-src data: blob: *; img-src 'self' data: blob: public.codepenassets.com cpwebassets.codepen.io assets.codepen.io production-codepen-email-assets.codepenassets.com *.codepen.dev *.codepen.io shots.codepen.io *.activemetering.com *.adsafeprotected.com *.adtrafficquality.google *.buysellads.com *.buysellads.net *.hsforms.net *.carbonads.net *.doubleclick.net *.google.com *.googleadservices.com *.googlesyndication.com *.googleusercontent.com *.gstatic.com *.unsplash.com *.wp.com avatars.githubusercontent.com ovh.commander1.com *.paypal.com *.paypalobjects.com gravatar.com secure.adnxs.com segment.prod.bidr.io static.filestackapi.com; form-action 'self'; media-src 'self' blog.codepen.io assets.codepen.io; object-src 'none'; script-src 'self' 'unsafe-eval' 'nonce-tcBpXL78a7E=' cpwebassets.codepen.io *.codepen.io *.adtrafficquality.google *.braintreegateway.com *.buysellads.com *.buysellads.net challenges.cloudflare.com *.hsforms.net *.carbonads.com *.carbonads.net *.doubleclick.net *.filestackapi.com *.firebaseio.com *.google.com *.googleadservices.com *.googlesyndication.com *.gstatic.com *.paypal.com *.paypalobjects.com *.stripe.com *.wufoo.com secure.adnxs.com segment.prod.bidr.io wufoo.com www.google.com www.gstatic.com; style-src 'unsafe-inline' *; report-uri /cpe/csp
set-cookieRedacted

Identified technologies

Cloudflare

Recent Updates

Related questions

More questions →

No related questions yet.

User reviews (0)