Skip to main content

windyapp.co

May 11th 2027 11:59 PM

Name.com, Inc.

signedDelegation

No

Apr 21st 2026 04:22 PM

Windyapp.co appears to be a domain with limited information available. It's registered through Name.com, Inc. and hosted on Cloudflare's nameservers. Caution is advised due to its limited registration history and transfer restrictions.

Data on this page is collected by cside's crawler, which monitors third-party scripts across the public web.

Copy Summary
Copy Link
Helpful
Not Helpful
Rarely seen
Vendor

Windy.app

Category: other

Description

Windy.app is a professional weather and wind-forecast application and platform for water and wind sports, also offering B2B hyperlocal weather data services. The windyapp.co domain 301-redirects to the primary windy.app site.

AI Review

Windy.app's scripts, particularly on windyapp.co, engage in extensive user interaction tracking, specifically targeting ecommerce analytics and performance metrics. The Snowplow Analytics tracker collects detailed information, such as page views, session details, and user interactions within payment portals, suggesting a high volume of potentially sensitive data being monitored. The reliance on both localStorage and cookies for persistence implies ongoing user tracking, which raises significant concerns around data consent and privacy, particularly within the context of sensitive payment information. Obfuscation techniques used in these scripts further complicate the ability to assess data handling practices, introducing additional risks related to supply chain integrity and data misuse. Though there have been no alerts in the past week, indicating the absence of known vulnerabilities or significant anomalies, the sheer breadth of data collection and the implications of tracking interactions during payment processes necessitate careful oversight. Ensuring that the scope of data collection does not exceed what is necessary for analytics and does not capture sensitive input values is critical for maintaining compliance with data protection standards. Organizations should prioritize confirming that user consent practices align with the extensive monitoring reflected in these scripts, particularly in light of privacy risks associated with such robust data harvesting, even if it is aimed at enhancing user experience and ensuring compliance.

Script hostnames

windyapp.co
WHOIS Information
Registrar Name.com, Inc.
Registration: May 12th, 2015
Expires: May 11th, 2027
Updated: April 21st, 2026
Nameservers
will.ns.cloudflare.com. 108.162.193.149
jamie.ns.cloudflare.com. 173.245.58.168
Meta Tags

No meta tags found.

windyapp.co is one of thousands of third-party scripts on the web.

Most sites run dozens of third-party scripts and can't say what each one does. cside monitors every script on your site and catches the ones that change or turn malicious.

DNS Records
Hostname Type TTL Priority Content
windyapp.co NS 86400
will.ns.cloudflare.com.
windyapp.co NS 86400
jamie.ns.cloudflare.com.
windyapp.co A 275
172.66.162.159
windyapp.co A 275
104.20.33.9
windyapp.co AAAA 300
2606:4700:10::6814:2109
windyapp.co AAAA 300
2606:4700:10::ac42:a29f
windyapp.co MX 300 1
aspmx.l.google.com.
windyapp.co MX 300 5
alt1.aspmx.l.google.com.
windyapp.co MX 300 5
alt2.aspmx.l.google.com.
windyapp.co MX 300 10
aspmx2.googlemail.com.
windyapp.co MX 300 10
aspmx3.googlemail.com.
windyapp.co TXT 300
"mailru-verification: 1a7cde3952dd04b7"
windyapp.co TXT 300
"spf2.0/mfrom,pra include:senderid.unisender.com ~all"
windyapp.co TXT 300
"google-site-verification=M53VxfnPFnTaYbDIDMXIJv3NKWQwpBGDu66uJkO--AA"
windyapp.co TXT 300
"google-site-verification=emPKnE2eY-jNbM81OMeX_3yxvdWy1a2fhICywvPopHQ"
windyapp.co TXT 300
"google-site-verification=hb900DS_69hZeDkcvIqU4xdytZS7g1BL4VJg2sxQFkw"
windyapp.co TXT 300
"google-site-verification=jTU_QrDx8dYrXe8zlQaXsccW0-LPIuzHQESk37a2Lnk"
windyapp.co TXT 300
"google-site-verification=jiyMNnpG-g4C5rtHQx6VUD9rKuZ-d_mY_R8MX0n-UH4"
windyapp.co TXT 300
"google-site-verification=omaBQ9Yafi5iWEiO2er5zVCrHDG0asfBD1XVkFBGjwM"
windyapp.co TXT 300
"v=DMARC1; p=none; adkim=r; aspf=r; rua=mailto:windypostmaster@gmail.com"
windyapp.co TXT 300
"v=spf1 include:spf.unisender.com include:_spf.yandex.net include:_spf.google.com include:_spf.google.com ~all"
windyapp.co SOA 1800
jamie.ns.cloudflare.com. dns.cloudflare.com. 2409790154 10000 2400 604800 1800

FAQ

Frequently Asked Questions

View all

This domain is analyzed as part of cside's domain directory to identify third-party scripts and their purposes. The summary provides information about what services, tools, or scripts this domain hosts, helping website owners understand which third-party services are being loaded on their sites.

The risk score is calculated based on multiple security factors including SSL certificate validity, DNSSEC status, domain registration details, and historical security data. A higher score indicates lower risk, while a lower score suggests potential security concerns that should be investigated.

The SSL certificate information shows whether the domain uses HTTPS encryption, when the certificate was issued, when it expires, and who issued it. This helps verify the domain's security posture and identify potential certificate-related vulnerabilities that could affect your website's security.

Third-party script domains can be compromised or used maliciously. By monitoring domain information like registration details, SSL certificates, and DNS records, you can identify suspicious changes, expired certificates, or domains that may pose security risks to your website and users.

Domain information is regularly scanned and updated to provide the most current security intelligence. The last scanned timestamp shows when the most recent analysis was performed, ensuring you have up-to-date information about the domain's security status.

If you identify a high-risk domain loading scripts on your website, you should investigate why it's being used, verify its legitimacy, and consider removing or replacing it if it's not essential. Use cside's platform to monitor and block suspicious third-party scripts to protect your users from potential security threats.

Subscribe to our newsletter to get the full picture

Stay updated with our latest news, offers and blog posts. Subscribe for exclusive updates delivered straight to your inbox.

Your inbox stays chill, we pop in monthly.

A pixelated, glitchy rendition of the cside shield
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

Book a personalized demo to see:

How to achieve PCI DSS requirement 6.4.3 & 11.6.1 compliance in 1 day
Why third-party scripts are a security risk for you and your visitors
Monitoring privacy and consent leakage (GDPR, CCPA) across every third party
Stopping signup abuse, account sharing, and chargeback fraud with device intelligence
Detecting and controlling AI agents and bots hitting your site in real time

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead