Website profiles · Technology insights · Alternatives

getstark.co Paid content

Categories: Resources & Utilities

The suite of integrated accessibility tools for your product design and development team • Making the world’s products accessible.

Visit website

Updated: 2026-09-29 12:53 Language: English (default) Access: Normal

Profile views 2 Outbound visits 0
Stark: The suite of integrated accessibility tools Full homepage screenshot

Related questions

More questions →
What Is Sketchful.io and How Do You Play the Multiplayer Drawing Game?

Sketchful.io is a free browser-based multiplayer drawing and guessing game — a Pictionary-style contest where players take turns sketching a word while everyone else races to type the correct guess. You play it at sketchful.io, and to join a lobby your network needs a Google account, so sign in with Google once before you start. From there you can jump into a public room or create your own with custom rules.

How a Round Works

The game runs in rounds. Each round, one player is given a word to draw and a countdown timer; everyone else types guesses into the chat. The faster you guess, the more points you earn, and the drawer scores when people guess their word. After the drawing time runs out or the word is guessed, the next player takes a turn.

The default room settings shown in the lobby are:

Setting Default Options
Rounds 3 1–10, 15, 20, 25
Drawing Time 90 seconds 15–300 seconds in set steps
Max Players — 2–16, then 24, 32, 64, 128, 256
Visibility Public Public or Private
Game Mode Pictionary Pictionary, Free Draw, Co-Op, Flashlight, Knock Out

Getting Into a Game

  1. Open sketchful.io in your browser.
  2. Sign in with Google when prompted — the site states your network needs a Google account to join a lobby, and one sign-in is enough.
  3. Join a public lobby, or create your own room and share the room link with friends so they can join.
  4. When it's your turn, draw the word shown to you. When it isn't, type guesses as fast as you can.

If you create a private room, only people with the link can get in, which is the usual way to play with a specific group.

Drawing Controls

The in-game tutorial lists these controls:

  • F — flood fill
  • B — brush
  • E — erase
  • C — clear
  • Z — undo
  • Mouse wheel — change brush size

There's also a drawing menu with Share, Download, Edit, and Delete, and a gallery you can log in to save drawings to.

Room Customization

When you host, you can set the lobby name, visibility (public or private), drawing time, max players, number of rounds, a welcome message, and the game mode. You can also load a custom word list — the site ships with themed lists such as 3–6 letter words, shapes, AI words, advanced English, and many more — or upload your own file.

House Rules and Moderation

The game asks players to follow a few basic rules:

  • Don't write the word you're drawing, and don't spoil the word or type it in chat.
  • Keep content PG-13 and be nice to others.
  • Protect your privacy.

You can click on players to see their stats, kick them, or report them. Reports cover inappropriate drawings, chat abuse or harassment, cheating or auto-guessing, and other issues, and they send the reported player's drawing and recent chat to moderators. Reporting players and turning off the profanity filter both require logging in.

Common Snags

  • Kicked for inactivity — if you stop playing, a warning appears and you'll be removed after about 15 seconds unless you confirm you're still there.
  • Can't join a lobby — you likely haven't signed in with Google yet.
  • Can't report or disable the profanity filter — both need you to be logged in.
  • Want to keep a drawing — use Download or Save Recording from the drawing menu, or log in to save to your gallery.
What Is a Browser Plugin and How Do You Install One Safely?

A browser plugin is a small piece of software that adds a specific capability to your browser — most often media playback, document viewing, or a specialized tool that the browser can't handle on its own. You install one safely by getting it from your browser's official store or the developer's own trusted site, checking that it supports your browser version, and reviewing the permissions it requests before you confirm. The catch: in modern browsers, the classic "plugin" model (NPAPI/PPAPI) has been almost entirely retired, so what most people call a plugin today is actually an extension or add-on. That distinction matters because it changes where you find the software and how you install it.

Plugin vs. extension vs. add-on: what's the difference?

The three words get used interchangeably, but they describe different things technically.

| Term | What it is | How it runs | Current status | |---|---|---|---|---| | Plugin | External code that handles content the browser can't (e.g., Flash, Java, PDF viewers) | Loaded into the page as a separate binary | Largely removed from Chrome, Firefox, and Edge | | Extension | Code that modifies browser behavior or UI (ad blockers, password managers, tab tools) | Runs inside the browser's extension system | The standard today | | Add-on | A general umbrella term, most associated with Firefox | Can be an extension, theme, or (historically) plugin | Still used as Firefox's label for extensions |

So when a site says "install our plugin," it almost always means an extension. If you're asked to download a separate .exe, .dmg, or .dll file to make a browser feature work, treat that as a red flag — legitimate browser add-ons install through the browser itself.

What kinds of browser plugins and extensions exist?

Most fall into a few practical categories:

  • Content blocking — ad blockers, tracker blockers, script managers.
  • Privacy and security — VPNs, password managers, cookie cleaners.
  • Productivity — tab managers, note-takers, screenshot tools, translators.
  • Media and documents — PDF readers, video downloaders, codecs (increasingly built into browsers now).
  • Developer tools — JavaScript debuggers, framework inspectors, API testers.
  • Appearance — themes and UI tweaks.

MyBrowserAddon describes itself as a community for open-source projects, focused on "free browser-based projects (add-on, plug-in, etc.)" across Chrome, Firefox, Opera, Safari, and Yandex. That's a useful example of where open-source add-ons get documented and reported — but note that a community site is a place to learn about and report bugs on projects, not automatically a store that installs them for you.

How do you check compatibility and permissions before installing?

Do these three checks before you click install:

  1. Browser and version match. Confirm the listing names your browser (Chrome, Firefox, Edge, Opera, Safari, Yandex) and a version range that includes yours. An extension built for an old manifest version may not load at all.
  2. Read the permissions list. The install prompt shows what the extension can access. Ask whether each request fits the job:
    • "Read and change all your data on all websites" — reasonable for an ad blocker, suspicious for a calculator.
    • "Read your browsing history" — needed by some tab tools, not by a theme.
    • "Access your data on specific sites" — narrower and generally safer.
  3. Check the source and reputation. Prefer the official store listing, look at the developer name, review count, last-update date, and whether the project is open source (so the code can be inspected).

A permission that doesn't match the stated purpose is the single most common warning sign.

How do you install a plugin safely?

The steps are the same across major browsers, with different menu names:

  1. Open the official store — Chrome Web Store, Firefox Add-ons (AMO), Microsoft Edge Add-ons, or Opera Add-ons. For Safari, use the App Store or the Extensions pane in Safari settings.
  2. Search for the add-on and open its detail page.
  3. Review the description, permissions, ratings, and update history (see the checks above).
  4. Click Add / Install. The browser shows a confirmation listing permissions — read it, then confirm.
  5. Verify it loaded. Look for the extension's icon in the toolbar, or open the extensions manager (chrome://extensions, about:addons in Firefox, edge://extensions in Edge) and confirm it's enabled.
  6. Test the actual function — open a page where it should work and confirm it does what you expected.

If a site offers a download outside a store, only proceed if you trust the developer and understand you're bypassing the store's review. Sideloading is a common way malicious code gets in.

How do you update, remove, or troubleshoot one?

  • Update: Store-installed extensions update automatically. You can force a check in the extensions manager ("Update" button in Chrome, or just restart the browser). Manual installs usually need manual updates.
  • Remove: Open the extensions manager, find the entry, and click Remove/Uninstall. Disabling first is a quick way to test whether an extension is causing a problem.
  • Won't load or stopped working? Common causes:
    • The extension is disabled or was removed by the browser after an update.
    • A permission change requires you to re-approve it.
    • It conflicts with another extension — disable others and retest.
    • The site it targets changed, or the extension is outdated.
    • For older "plugin" content (like legacy media), the browser may have dropped support entirely — the fix is usually a modern extension or a built-in browser feature.

Quick decision guide

  • Need to block ads, manage tabs, or save passwords? Install an extension from your browser's official store.
  • A site says "install our plugin" and offers an installer file? Pause — verify the developer and prefer a store version if one exists.
  • Looking for open-source add-ons and their documentation? Community hubs like MyBrowserAddon are a reasonable place to read about projects and report bugs, then install through the official store.
  • Something broke after installing? Disable the newest extension first, then remove it if the problem clears.

The short version: "plugin" today means extension, install it from an official store, match it to your browser, and read the permissions before you confirm.

Website Overview

Identifiable technologies and additional version or configuration signals make the service easier to fingerprint, which may help targeted scanners narrow their checks. An established domain and managed infrastructure suggest continuity of operations and may support dependable delivery, although neither guarantees service quality.

Domain and Registration

Registered in 2017, this domain has about 9 years of history. That suggests continuity, although ownership and purpose may have changed. Transfer-protection status is present, helping reduce the risk of unauthorized domain transfers. The registrar is Porkbun, a widely used domain service provider. The domain uses the common .co extension, which is not an independent safety signal.

DNS and Email

Nameservers are provided by porkbun.com, indicating managed DNS hosting. MX records point to the Google Workspace email service. DNSSEC is enabled, allowing validating resolvers to authenticate signed DNS data. SPF and DMARC are configured. DKIM status is unknown. TXT records include verification markers for Google, Apple, Microsoft. Such markers may also remain after a service stops being used.

TLS and Certificates

The public key uses EC with 256 bits. The server supplied a complete certificate chain. No organization name is present in the certificate; the available fields are consistent with domain validation. The certificate was issued by Let's Encrypt, commonly associated with automated certificate services. The certificate's total validity is about 89 days, consistent with a short renewal cycle.

HTTP and Browser Security

The response lacks these common security headers: Permissions-Policy. CORS permits any origin to read this response. This is common for public resources; sensitive responses need narrower handling. No X-Powered-By header was found, reducing one common source of backend fingerprinting information. No obvious internal addresses or debug information were found in the headers. The Server header contains the custom value Netlify.

Technology Stack Analysis

The public page identifies Gatsby 5.16.1, Tailwind CSS, Netlify, with exact versions exposed for 1 technologies. These details can narrow vulnerability checks, although exposure alone is not a vulnerability.

Search and Social Sharing

The Generator tag identifies Gatsby 5.16.1, making the publishing system easier to fingerprint. No homepage canonical URL was detected. If duplicate URLs exist, consolidation may be less explicit. Twitter Card metadata is configured. The title has 50 characters, within a common display range. A meta description is present, with 130 characters.

Hosting and Email

DNSporkbun.com
HostingNetlify
EmailGoogle Workspace
Location United States flagAshburn, Virginia, United States 18.208.88.157

User reviews (0)

  • No reviews yet.

Pages, Search and Sharing

Meta descriptionThe suite of integrated accessibility tools for your product design and development team • Making the world’s products accessible.
Canonical URLNot detected
LanguageEnglish (default)
Twitter Cardsummary_large_image

No robots.txt found

No sitemaps found

Registration details RDAP / WHOIS

RegistrarPorkbun
Registered2017-03-08
Expires2027-03-07
Domain statusclientDeleteProhibited https://icann.org/epp#clientDeleteProhibited、clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Nameserverscuritiba.ns.porkbun.com、fortaleza.ns.porkbun.com、maceio.ns.porkbun.com、salvador.ns.porkbun.com
DNSSECsigned

DNS records

TypeNameValueTTLPriority
Astark-marketing-website.netlify.app18.208.88.157120—
Astark-marketing-website.netlify.app98.84.224.111120—
AAAAstark-marketing-website.netlify.app2600:1f18:16e:df01::258311—
AAAAstark-marketing-website.netlify.app2600:1f18:16e:df01::259311—
MXgetstark.coaspmx.l.google.com3001
MXgetstark.coalt1.aspmx.l.google.com3005
MXgetstark.coalt2.aspmx.l.google.com3005
MXgetstark.coalt3.aspmx.l.google.com30010
MXgetstark.coalt4.aspmx.l.google.com30010
NSgetstark.cocuritiba.ns.porkbun.com86400—
NSgetstark.cofortaleza.ns.porkbun.com86400—
NSgetstark.comaceio.ns.porkbun.com86400—
NSgetstark.cosalvador.ns.porkbun.com86400—
TXTgetstark.coMS=ms12468053300—
TXTgetstark.coapple-domain-verification=PpIC8tk8kbX3EHOT300—
TXTgetstark.cog1kpooktoz300—
TXTgetstark.cogoogle-site-verification=05UJ7ORHQMBTw-bPaI1FL8wtiS4NEp0Fxs6s4IPtGa8300—
TXTgetstark.cogoogle-site-verification=9kV6uJJce8i_pIIG2aml2mXPQrrUstDXS1LaE32c_mQ300—
TXTgetstark.cogoogle-site-verification=iyBLG5bO9LgKiu0-tSNfFHLl9Tb2UwimuFHLTaHdZII300—
TXTgetstark.coslack-domain-verification=7QqCB3y2ejilYFTNXWNnAFVGN8MWaquXvu9HI1NM300—
TXTgetstark.costatus-page-domain-verification=9pqs22dyptb1300—
TXTgetstark.cov=spf1 a mx include:_spf.mlsend.com include:_spf.google.com ~all300—
CNAMEwww.getstark.costark-marketing-website.netlify.app300—
DSgetstark.co2371 13 2 34c33de63e002038683dd456287cb854802b60263e0d043b9a9477999596edb33600—
DMARC_dmarc.getstark.cov=DMARC1; p=reject; rua=mailto:[email protected]; pct=10; adkim=r; aspf=r600—

TLS and certificates

AssessmentNormal configuration
Supported protocolsTLSv1.2、TLSv1.3
Negotiated protocolTLSv1.3
Certificate subjectwww.getstark.co
IssuerLet's Encrypt
Valid until2026-12-22T03:33 · Remaining when checked: 83 days
Verification detailsCertificate trust: Passed · Hostname match: Passed

HTTP response headers

HeaderValue
content-typetext/html; charset=UTF-8
cache-controlpublic,max-age=0,must-revalidate
serverNetlify
strict-transport-securitymax-age=63072000; includeSubDomains; preload
content-security-policyframe-ancestors 'self' https://house-stark-staging.herokuapp.com https://account.getstark.co https://app.getstark.co
x-frame-optionsDENY
x-content-type-optionsnosniff
referrer-policyno-referrer
access-control-allow-origin*

Identified technologies

Gatsby 5.16.1Tailwind CSSNetlify