capital.new
https://capital.new/mcp
57
trust
0.55
confidence
medium
risk
trust-2026-08-12.2
observed 1h ago
Why this score
| tls_present_and_valid | +4 |
| mcp_capabilities_discoverable | +4 |
| headers.missing_hsts | -3 |
| reachable | +2 |
Findings (2)
| low | No Strict-Transport-Security header headers.missing_hsts @ 1.0.0 |
| info | CORS allows any origin cors.wildcard_origin @ 1.0.0 |
Evidence (8)
| Type | Observed | SHA-256 |
|---|---|---|
| dns_resolution_observation | 1h ago | 9aaab22c97cf10a1… |
| http_response_observation | 1h ago | c93a481cd608c683… |
| availability_observation | 1h ago | 9a4560b61ba7c4cf… |
| hosting_provider_observation | 1h ago | e7292135d1d3f6bd… |
| tls_certificate_observation | 1h ago | ed7ed174855290c7… |
| oauth_metadata_observation | 1h ago | a8f4001553b0acd9… |
| mcp_protocol_observation | 1h ago | a99af6690355ed25… |
| mcp_capability_observation | 1h ago | b5b6635e2086800f… |
Every record is append-only and content-hashed. Corrections supersede; nothing is overwritten.
Operate this service?
Prove control of capital.new to correct the record and request a rescan after fixing a finding. One DNS record — no account needed.