See: https://aw-snap.info/file-viewer/?tgt=https%3A%2F%2Fwww.ipage.com&ref_sel=GSP2&ua_sel=ff&fs=1
This link Flagged URL(s)? will open a utility that will list out any URL(s) from your domain that are listed in Phishing DBs and tell you if Google is currently flagging the URLURLs from OpenPhish URL Is Flagged? Status htxps://elgroupsco2.ipage.com/paypal/paypal_transaction_refund/paypal.php?login flagged SOCIAL_ENGINEERING 200 OK
These guys should learn you to build your own website, but are they above board themselves? polonus has serious doubts…
Re: https://observatory.mozilla.org/analyze.html?host=www.ipage.com
Retirable code: -https://www.ipage.com
Detected libraries:
jquery - 1.11.2 : (active1) -https://ajax.googleapis.com/ajax/libs/jquery/1.11.2/jquery.min.js
Info: Severity: medium
https://github.com/jquery/jquery/issues/2432
http://blog.jquery.com/2016/01/08/jquery-2-2-and-1-12-released/
(active) - the library was also found to be active by running code
1 vulnerable library detected
Then is it “same origin”? Re: https://sritest.io/#report/5113bc0c-efcf-47bb-823c-a0a7c766a106
And it is just one of the 6 script issues there with a missing sri-hash!
Quite some scripts on that page should better be blocked by script- or adblockers!
se dot monetate dot net, static dot criteo dot net and various others.
Insecure Tracking Detected.
100% of the trackers on this site could be protecting you from NSA snooping. Tell ipage dot com to fix it.
Identifiers | All Trackers
Insecure Identifiers
Unique IDs about your web browsing habits have been insecurely sent to third parties.
-www.ipage.com session_id
-Google aid
-v1%3a145803498743501667 Twitter guest_id
OWL Carousel plug-in insecurity: http://www.pickplugins.com/question/post-grid-pro-ssl-insecure-url/
Typekit insecurities: http://www.domxssscanner.com/scan?url=https%3A%2F%2Fwww.ipage.com%2F
So All that Glitters is not Gold, folks.
polonus (volunteer website security analyst and website error-hunter)