Skip to main content

wdfl.co

May 8th 2027 11:59 PM

1API GmbH

unsigned

No

Jun 4th 2026 10:26 AM

wdfl.co appears to be a domain with unknown purpose, as no information is available about its intended use. It's been registered since 2018 but has an unsigned DNSSEC status and is client-transfer prohibited, indicating potential security risks.

Data on this page is collected by cside's crawler, which monitors third-party scripts across the public web.

Copy Summary
Copy Link
Helpful
Not Helpful
Rarely seen
Vendor

Rewardful

Category: marketing

Description

Rewardful is an affiliate and referral tracking platform for SaaS companies, integrating with Stripe to track commissions and manage affiliate programs. The domain wdfl.co hosts Rewardful's tracking script at r.wdfl.co/rw.js, which is the script tag inserted on customer websites to track affiliate referrals.

AI Review

Rewardful's scripts focus on referral marketing, utilizing cookies and URL parameters to track user interactions while effectively modifying the Document Object Model (DOM) to embed referral data into forms and links. This behavior allows for comprehensive recording of user journeys for marketing attribution, but it raises concerns about data minimization and user privacy, as the ongoing collection of behavioral data can occur across multiple sessions without the user's informed consent. Although these scripts do not handle sensitive payment information directly, their tracking mechanisms operate close to user touchpoints that influence payment interactions, which underscores the need for stringent controls on the data collected and the implied surveillance over user actions. Alert activity across domains was nonexistent in recent days, suggesting that the current implementations do not trigger security concerns according to existing monitoring parameters. However, the reliance on cookies for tracking referral tokens must be carefully assessed given potential privacy infringements and the broader implications of user tracking under regional data protection laws. Maintaining a balance between operational functionality and privacy rights will be essential to mitigate risks associated with the scripts' activities.

Script hostnames

wdfl.co
WHOIS Information
Registrar 1API GmbH
Registration: May 9th, 2017
Expires: May 8th, 2027
Updated: June 4th, 2026
Nameservers
ns1.dnsimple-edge.com. 199.247.152.53
ns2.dnsimple-edge.net. 199.247.153.53
ns3.dnsimple-edge.io. 199.247.154.53
ns4.dnsimple-edge.org. 199.247.155.53
Meta Tags

No meta tags found.

wdfl.co is one of thousands of third-party scripts on the web.

Most sites run dozens of third-party scripts and can't say what each one does. cside monitors every script on your site and catches the ones that change or turn malicious.

DNS Records
Hostname Type TTL Priority Content
wdfl.co NS 3600
ns1.dnsimple-edge.com.
wdfl.co NS 3600
ns2.dnsimple-edge.net.
wdfl.co NS 3600
ns3.dnsimple-edge.io.
wdfl.co NS 3600
ns4.dnsimple-edge.org.
wdfl.co SOA 3600
ns1.dnsimple-edge.com. admin.dnsimple.com. 1519843249 86400 7200 604800 300

FAQ

Frequently Asked Questions

View all

This domain is analyzed as part of cside's domain directory to identify third-party scripts and their purposes. The summary provides information about what services, tools, or scripts this domain hosts, helping website owners understand which third-party services are being loaded on their sites.

The risk score is calculated based on multiple security factors including SSL certificate validity, DNSSEC status, domain registration details, and historical security data. A higher score indicates lower risk, while a lower score suggests potential security concerns that should be investigated.

The SSL certificate information shows whether the domain uses HTTPS encryption, when the certificate was issued, when it expires, and who issued it. This helps verify the domain's security posture and identify potential certificate-related vulnerabilities that could affect your website's security.

Third-party script domains can be compromised or used maliciously. By monitoring domain information like registration details, SSL certificates, and DNS records, you can identify suspicious changes, expired certificates, or domains that may pose security risks to your website and users.

Domain information is regularly scanned and updated to provide the most current security intelligence. The last scanned timestamp shows when the most recent analysis was performed, ensuring you have up-to-date information about the domain's security status.

If you identify a high-risk domain loading scripts on your website, you should investigate why it's being used, verify its legitimacy, and consider removing or replacing it if it's not essential. Use cside's platform to monitor and block suspicious third-party scripts to protect your users from potential security threats.

Subscribe to our newsletter to get the full picture

Stay updated with our latest news, offers and blog posts. Subscribe for exclusive updates delivered straight to your inbox.

Your inbox stays chill, we pop in monthly.

A pixelated, glitchy rendition of the cside shield
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

Book a personalized demo to see:

How to achieve PCI DSS requirement 6.4.3 & 11.6.1 compliance in 1 day
Why third-party scripts are a security risk for you and your visitors
Monitoring privacy and consent leakage (GDPR, CCPA) across every third party
Stopping signup abuse, account sharing, and chargeback fraud with device intelligence
Detecting and controlling AI agents and bots hitting your site in real time

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead