Website reputation report

lolipop.jp

Last checked 1 day ago · Point-in-time assessment

● Evidence is limited

What is this website?

Public pages were observed on lolipop.jp, but their subject was not confidently classified. An About page was also found. The sampled pages were marked as Japanese-language. Recurring page-metadata topics include ロリポップ レンタルサーバー, 令和 年台風第, 一部地域を対象としたサービス停止の一時回避を行います.

No listed local patterns observedHomepage-only analysis is not a malware clearance. Read the scope and findings below.

65/100Safety Score
70%Evidence Confidence
Trust Radar evidence profile Eight evidence dimensions from zero to one hundred. Exact values surround the chart. Threat Intelligence55 Domain History0 Infrastructure92 Website Security95 Security Hygiene70 Transparency49 Reputation50 Operational Stability84
Trust RadarEight observed factors. Select one to inspect its evidence.

How to read this report

Safety Score evaluates observed signals. Evidence Confidence measures how complete, direct, fresh, and consistent those signals are.

No automated scan can guarantee that a website is safe.

Independent evidence brief

What we observed about lolipop.jp

Updated Sep 30, 2026

The latest scan examined 10 public pages on lolipop.jp. Website descriptions below come from the site itself. Registration, connection and threat findings were checked separately.

Purpose and visible content

On its About page, the site says: WordPress (ワードプレス) とはそもそも何か?概要・特徴をご紹介します。

Registrar and domain history

A reliable creation date was not returned by the registration lookup. The report leaves domain age unverified rather than guessing.

Connection and hosting evidence

The checked homepage returned HTTP 200 in about 2000 ms.

A valid TLS certificate was observed, expiring Oct 29, 2026.

Threat checks and score context

External malware-provider coverage was unavailable. The report does not treat this missing check as a clean result.

Safety Score: 65/100. Evidence Confidence: 70%. These measure different things.

Public content profile

Pages reviewed on lolipop.jp

10 of up to 10 pages

We sampled public pages from this website to understand its subject and contact paths. The titles and short descriptions below come from the website itself. They are not endorsements or independent safety findings.

ロリポップ!レンタルサーバー|WordPressの表示速度No.1【WordPressの表示速度No.1】のレンタルサーバー「ロリポップ!」月額660円から高速WordPressが使える!初期費用・ドメインも無料!今すぐ10日間の無料お試し WordPress(ワードプレス)とは - ロリポップ!レンタルサーバーWordPress (ワードプレス) とはそもそも何か?概要・特徴をご紹介します。 お問合せ - ロリポップ!レンタルサーバーロリポップご利用についてのご質問はお問合せAIチャットにてお問い合わせください。24時間自動応答でご回答いたします。 設定おまかせサポート - ロリポップ!レンタルサーバー「設定おまかせサポート」は、ロリポップの設定・操作の困りごとに対応する専門サポートです。他社からのホームページ移転や大量メールの一括削除などにも対応します。 令和8年台風第18号に伴う災害に伴い、一部地域を対象としたサービス停止の一時回避を行います - ロリポップ!レンタルサーバー令和8年台風第18号に伴う災害に伴い、一部地域を対象としたサービス停止の一時回避を行います 「Google Workspace」で、ご契約中のライセンス数を契約期間の途中から追加できるようになりました - ロリポップ!レンタルサーバーロリポップ!レンタルサーバーのオプション「Google Workspace」で、ご契約中のライセンス数を契約期間の途中から追加できるようになりました。追加分の料金は日割りでお支払いいただき、次回の更新からは追加後のライセンス数でご請求します。 WordPress本体の重大な脆弱性(CVE-2026-87902)に関するセキュリティアップデートのお願い - ロリポップ!レンタルサーバーWordPress本体に重大な脆弱性が確認されました。WordPress 4.7.0から7.1.1をご利用の方は修正バージョンへの更新をお願いします。 令和8年台風第25号による大雨に伴う災害により、一部地域を対象としたサービス停止の一時回避を行います - ロリポップ!レンタルサーバーロリポップ!レンタルサーバー 2026年09月24日 新着情報「令和8年台風第25号による大雨に伴う災害により、一部地域を対象としたサービス停止の一時回避を行います」についてのページです。 ロリポップ!レンタルサーバー|WordPress高速表示・充実サポートロリポップはWordPressをたった60秒で始められ、安定したレスポンスと高速表示、充実したサポートで、ビジネスに最適なレンタルサーバーです。 取次店制度 - ロリポップ!レンタルサーバーロリポップのサービスをご紹介いただいた制作会社・フリーランスの方に、取次報酬をお支払いする制度です。レンタルサーバー・SSL・MEO Dash!・固定IPアクセス・ゼロトラストリンクが対象。

Public page evidence

Topics and keywords observed on lolipop.jp

4 phrases

These phrases were extracted locally from sampled public page metadata. They are observations, not search-volume or ranking estimates.

ロリポップ レンタルサーバーTitle, Meta description10 sampled pages
令和 年台風第Title, H1, Meta description2 sampled pages
一部地域を対象としたサービス停止の一時回避を行いますTitle, H1, Meta description2 sampled pages
wordpressTitle, H1, Meta description2 sampled pages

At a glance

Key findings

✓

Report is current

The displayed evidence comes from the published immutable scan.

i

Confidence is separate

Unavailable evidence is shown as missing and never counted as clean.

!

Verify before sensitive actions

Check the exact URL and context before payments, credentials, or downloads.

Fully explainable

Why this score?

Versioned weights
Threat IntelligenceWeight 25%
55/100

Threat providers were unavailable. The neutral uncertainty baseline is not a clean verdict.

Domain HistoryWeight 10%
0/100

Evidence is unavailable.

InfrastructureWeight 10%
92/100

Observed DNS records and network address were checked.

Website SecurityWeight 15%
95/100

Observed certificate validity and TLS protocol were checked.

Security HygieneWeight 15%
70/100

Observed security header values were checked for basic protective settings. Empty values, disabled HSTS and unrecognized values receive no credit. This is not a complete browser-policy validation.

TransparencyWeight 5%
49/100

Observed site metadata and About page were checked. Publisher-supplied details are not independently verified.

ReputationWeight 5%
50/100

Popularity is weak context, not proof of safety. Unranked sites use a neutral baseline.

Operational StabilityWeight 15%
84/100

Observed HTTP status and final connection scheme were checked.

Server-side analysis

Automated security checks

Local antivirus and phishing checks

ClamAV · homepage HTMLNo signature match in the sampled HTML
Engine version1.5.4
Signature database date (UTC)2026-09-30T06:24:18+00:00
HTML bytes submitted149,147
Phishing.Database · exact hostnameNot listed in this snapshot
Feed downloaded (UTC)2026-09-30T12:00:07+00:00
Hosts in local snapshot386,027

Sampled scripts and pages

Resource analysis incomplete

6 resources checked · 12 script links observed on the homepage. Partial resource coverage.

ClamAV inspects the fetched homepage HTML on our server. New scans also sample up to four linked scripts and two collected internal pages, with size and time limits. Scripts are not executed. Other downloads, private server files and logged-in pages remain outside this check. A signature match needs investigation and can be a false positive. No match is not a whole-site safety guarantee.

Exact hostname lookup uses a downloaded Phishing.Database snapshot. It does not send this domain to an external lookup API or mark sibling subdomains as harmful. Not listed does not mean safe. Snapshot age is download age, not proof that every entry was recently revalidated.

Homepage HTML only · Eight local rule families · local-security-v2

Checks use the fetched page and redirect chain. Scripts are not executed, forms are not submitted, and linked files are not downloaded. This is not a malware clearance.

Page resource inventory

Linked scripts12
Inline scripts1
Embedded frames0
External script hosts4

Counts describe the sampled HTML, not every resource loaded by the browser. External resources are common and are not automatically harmful.

No listed local patterns observed. The limited rule set cannot detect every threat or behavior.

External threat intelligence

Provider coverageNot checked

Local checks do not query external reputation databases. An unavailable check is never a clean result.

Registration

Domain information

Public RDAP observation
Canonical domainlolipop.jp
RegistrarUnavailable
RegisteredUnavailable
Domain ageUnavailable
ExpiresUnavailable
Registry statusesUnavailable
Report statePublished

Infrastructure

Network & hosting

Observed endpoint, not legal location
IP address133.130.34.142
Autonomous systemUnavailable
Network organizationUnavailable
Observed countryUnavailable
CDNNot detected
Web application firewallNot detected

At a glance

Infrastructure summary

Observed during this scan

A compact view of the connection, DNS and security surface. These observations describe what the scanner could verify at scan time and do not prove ownership or ongoing availability.

HTTP response200 · https://lolipop.jp/
Endpoint133.130.34.142
NetworkUnavailable
CDN and WAFNot detected · Not detected
DNS surface20 records · 2 nameservers · 1 mail exchangers
Protection signals3 security headers · 4 technologies · DNSSEC unknown

Page telemetry

Observed page statistics

Safe metadata only

These counters describe the fetched response and sampled HTML. Script counts describe references in the markup, not a complete browser network log. Cookie counts cover observed response headers.

Response size149,147 bytes
HTTP check duration2,000 ms
Cookies observed7
Script resources12 · 4 external hosts
Frames and sampled checks0 frames · 6 resources checked

Encrypted transport

TLS certificate

Valid when observed
StatusValid when observed
ProtocolTLSv1.3
IssuercountryName=BE, organizationName=GlobalSign nv-sa, commonName=GlobalSign GCC R3 DV TLS CA 2020
Valid fromApr 13, 2026
Valid untilOct 29, 2026
Certificate names*.lolipop.jp · lolipop.jp

Resolution

DNS footprint

DNSKEY status unknown

DNSKEY presence does not verify the DNSSEC signature chain. Missing records can mean no record was returned or the lookup was unavailable.

A133.130.34.142TTL —
NSdns2.lolipop.jpTTL —
NSsv.madame.jpTTL —
MX10 mail.lolipop.jpTTL —
TXT_globalsign-domain-verification=WmlOPPVkQ7Hhpp9xHznjLBkYv-CREjnG4YYOwP6VHRTTL —
TXTabuseipdb-verification=K0lYQGLUTTL —
TXTglobalsign-domain-verification=jBOa_Jqe6tku_MGh8GUT9pcNt9KXuB3D6cxctLpgIFTTL —
TXTglobalsign-domain-verification=MPl_zv354PGu8WUyXFuz9WB73RH886FOaRVSma07L4TTL —
TXTglobalsign-domain-verification=RNktfNlTD98_rZeHNU-OuC59X6WfzmABtIRcoy1pgQTTL —
TXTgoogle-site-verification=_bKI4OsJKWM890xjIw76lpQtuFkfvKgsh0Vi5xQQIM0TTL —
TXTgoogle-site-verification=-y4K32Fhz9q_8TKO4ETYG53UGTTIX2_UrTtH0nhJJxETTL —
TXTgoogle-site-verification=AnW5kRmyCidkQ-rgby9qHw-BkSqkv-PwtMCc3LRALksTTL —
TXTgoogle-site-verification=D62jShEHD27tf0YAlj7qYNG-Ca1rS8V0QMXdvo6IOs0TTL —
TXTgoogle-site-verification=DMlPkq8X_blRGbQSp-IK9A-u6QotZmLJGlhtrCPSj_QTTL —
TXTgoogle-site-verification=Rd3MvVqns-yRVEmFR0TKBS0UzMhbpMsD0ySiBDne5scTTL —
TXTgoogle-site-verification=T5qy3PzQfTulQFrbGBPdMC8SU3yFmH0QOlXmwM-U504TTL —
TXTgoogle-site-verification=UKCUjMt4VUoscC9sy85j0jDWabX02W1ncwsJ8-TNiaITTL —
TXTgoogle-site-verification=Zj3i0H8sr7qWQOSDyAgyb7Jxsz59tYiKG3ysR9lMGSYTTL —
TXTgoogle-site-verification=zzO_AyJEU6QP2M0TkmUFCZpxJrp-oAVXB9pzACFujTQTTL —
TXTv=spf1 include:gym02.spf.lolipop.jp include:amazonses.com include:mail.zendesk.com include:spf.satorimail.net include:fc99251.cuenote.jp include:23544039.spf10.hubspotemail.net ~allTTL —

DNS observations · no external lookup API

Domain email protection

Exact-host SPF and DMARC observations help the owner investigate email impersonation risks. They are separate from website malware checks and do not change the Safety Score.

SPFPolicy record observed, not fully validated
DMARCPolicy record observed, not fully validated

What to do next

Review the records with your mail administrator. Inventory legitimate senders and test SPF and DKIM alignment before enforcing a stricter DMARC policy. Fix duplicate records and investigate overly permissive SPF rules.

This bounded check does not send email, probe SMTP, evaluate recursive SPF includes, verify DKIM signatures or apply organizational-domain DMARC inheritance. A missing subdomain record does not prove that no inherited protection exists. A DNS timeout is unknown, not an absent record. A policy record is not proof that messages authenticate successfully.

Responsible disclosure

security.txt

RFC 9116 observation
StatusPublished and readable
Security contacts1
Policy linkObserved
ExpiryValid when observed

This is a public vulnerability-reporting contact file. Its presence does not prove that the website is safe and does not change the independent Safety Score.

Browser protections

Security headers

3 observed
strict-transport-securitypresent max-age=15724800
x-content-type-optionspresent nosniff
x-frame-optionspresent SAMEORIGIN

Response headers

Cookie protections

Passive observation
Cookies observed7
Missing Secure7
Missing HttpOnly7
Missing SameSite7

Only cookie attribute counts are retained. Cookie names and values are never stored. These observations are not proof of compromise and do not independently change the Safety Score.

Detected stack

Technologies

Bootstrap 80% Google Analytics 94% jQuery 3.7.1 82% Tailwind CSS 72%

Versions are shown only when publicly exposed by the page or response headers. An observed version is not, by itself, proof of a vulnerability.

JavaScript library advisories

4 sampled JavaScript files checked locally with Retire.js. Database snapshot: 2026-09-30T02:40:06.930Z.

No supported library version was identified in the sampled files. This does not establish that the scripts are safe.

A version match is not proof that the website is infected or that an issue is exploitable here. Owners should review the advisory, check whether their code is affected and test an update. Up to four external script files are sampled, not every dependency, inline script or dynamically loaded resource.

Recommended maintenance checks

jQueryConfirm the observed jQuery version is supported by your application and update it through your normal dependency process.

About this website

What the site says about itself

WordPress (ワードプレス) とはそもそも何か?概要・特徴をご紹介します。

View the site's About page ↗

This is publisher supplied information. The independent safety findings are shown separately.

Structured facts

Website identity & response

Public page metadata
Page titleロリポップ!レンタルサーバー|WordPressの表示速度No.1
First heading必要になったその日に公開。
Description【WordPressの表示速度No.1】のレンタルサーバー「ロリポップ!」月額660円から高速WordPressが使える!初期費用・ドメインも無料!今すぐ10日間の無料お試し
Canonical URLhttps://lolipop.jp/
Final URLhttps://lolipop.jp/
HTTP response200 · text/html; charset=UTF-8 · 2000 ms
Languageja
Structured typesBreadcrumbList · ListItem
Page page detectedhttps://lolipop.jp/info/news/8221/About page detectedhttps://lolipop.jp/manual/hp/wordpress-about/Support page detectedhttps://lolipop.jp/support-chat/
present100% evidence confidence
1100% evidence confidence
Security txt.has canonical100% evidence confidence
1100% evidence confidence
1100% evidence confidence
1100% evidence confidence
1100% evidence confidence
ja100% evidence confidence
1100% evidence confidence
Local headers.cors present100% evidence confidence
Local headers.cors credentials with wildcard100% evidence confidence
7100% evidence confidence
7100% evidence confidence
7100% evidence confidence
7100% evidence confidence
Local headers.cors wildcard origin100% evidence confidence
20100% evidence confidence
2100% evidence confidence
1100% evidence confidence
unavailable100% evidence confidence
Dns consistency.cname present100% evidence confidence
1100% evidence confidence
Local headers.permissions policy present100% evidence confidence
1100% evidence confidence
Local headers.hsts preload100% evidence confidence
15724800100% evidence confidence
Local headers.hsts include subdomains100% evidence confidence
Local headers.csp present100% evidence confidence

Connection path

Redirect chain

0 recorded hops

No redirect hop was recorded for the sampled homepage.

Premium monitoring

Catch downtime and security changes automatically

Regular checks, availability history, and alert emails are reserved for Premium websites. Free reports remain point-in-time scans and do not create recurring server work.

Enable monitoring for this website

Compared with the previous scan

What changed

Safety Score0 points
HTTP status200 → 200
Final URL changedNo
Technologies addedNone observed
Technologies removedNone observed

This comparison uses persisted scan evidence only. A changed signal can reflect a real website change, a different response or newly available evidence.

Explainable matching

Digital fingerprint

fingerprint-v1
clear-signal-wave-163

Comparable components help find technically related websites. A match does not prove common ownership.

DnsHashed private comparison value
TechnologiesHashed private comparison value

Material changes only

Change history

No meaningful changes recorded yet.

Website icon for lolipop.jp

Visual evidence

Website screenshot

Screenshot of lolipop.jp
Captured once in an isolated browser during this scan. Visual tint is an interface overlay. The original evidence is not duplicated.

For site owners

Show your verified trust report

Place this lightweight badge in your footer to show visitors an independent, dated WebsiteVirusScanner report. It can increase visitor confidence, but it never changes or guarantees the score.

Choose a badge style
Preview on your site
WebsiteVirusScanner trust badge preview

Use the current report link so visitors can verify the evidence. A badge is a transparency signal, not a paid ranking boost.

Questions about lolipop.jp

FAQ

Still have questions? Contact us →
Is lolipop.jp safe to visit?

The latest Safety Score is 65/100 with 70% Evidence Confidence. This is a point-in-time assessment of observed technical signals, not a guarantee. Check the exact address and avoid entering payment details if anything looks unusual.

Did the scan detect malware on lolipop.jp?

ClamAV found no signature match in the sampled homepage HTML. External scripts, downloads and private server files were not checked. This is not a whole-site malware clearance.

When was lolipop.jp registered?

The registry lookup did not provide a reliable creation date in this scan.

Did lolipop.jp have a valid TLS certificate?

The scanner observed a valid TLS certificate using TLSv1.3. A valid certificate alone does not establish that the site is safe.

How does lolipop.jp describe itself?

The website's About page describes its purpose in the report above. This is publisher-supplied information and is separate from independent security findings.

Can a paid listing change this website's score?

No. Premium placement and owner-supplied pages are labelled separately. Technical evidence, the Safety Score and moderation decisions remain independent.