Terms of Service
Last updated: 23 July 2026
These Terms govern use of the free checks available at scan.majhenlabs.com and of the website majhenlabs.com (together, the “Service”), provided by Lunar j.d.o.o.
The Service currently comprises four checks:
- the legitimacy check — scan.majhenlabs.com/validacija;
- the website vulnerability check — scan.majhenlabs.com;
- the email source check — scan.majhenlabs.com/harpun;
- the GDPR check — scan.majhenlabs.com/gdpr.
These Terms apply to all of them, subject to the differences expressly stated in individual clauses. The list of checks may change and grow over time; these Terms apply to every new check as well.
By starting any check you accept these Terms. If you do not agree with them, do not start one.
1. Who provides the Service
Bana Jelačića 14, 42230 Ludbreg, Croatia
Company ID (OIB): 47232633853
Email: privacy@majhenlabs.com
MajhenLabs is a project of Lunar j.d.o.o. The check is operated by, and is the responsibility of, Lunar j.d.o.o.
2. Statement of authorisation
This is the most important provision in these Terms, and whether you may use the Service at all depends on it.
2.1 Checks started by entering a domain
This applies to the website check and to the GDPR check.
By entering a domain you declare that you own it, or that its owner has expressly authorised you to request a check for it.
The check runs from our servers. In the logs of the server hosting the domain you entered, our traffic will appear as inbound traffic from our IP address. If you enter a domain you are not authorised for, you have caused our server to direct traffic at someone else's system without its owner's authorisation.
You alone are responsible for such an entry, including any damage, report, complaint or cost that arises for us from it.
Before those checks run, we require confirmation of an email address on the domain being checked. By confirming the code, you confirm the declaration in this clause.
2.2 The email source check
By submitting a message for checking you declare that it was received by you or by the organisation you act for, or that you are otherwise authorised to have it analysed.
That check directs no traffic at anyone else’s system, so it requires no email confirmation. The message you submit may contain personal data of third parties — the sender’s address and name, recipient addresses and the like. You are responsible for the basis on which you process that data.
2.3 The legitimacy check
This check reads only the publicly available data of the entered site, passively — like an ordinary browser visitor — and does NOT require you to own that site. That is why it needs no email confirmation: it is intended for checking other sites too (for example a shop before buying, or a supplier before paying).
It performs no active probing of anyone's system. The findings are a risk assessment from public signals, not a statement that a person or company is a fraudster. You alone are responsible for how you use the findings — in particular for any public claim or decision you base on them.
2.4 Age and authority
The Service may only be used by persons over 18. For the checks in clause 2.1, the user must be authorised to act on behalf of the organisation that owns the domain.
3. What the checks do
3.1 The website check
The check retrieves and analyses data the entered website already serves to every visitor, along with data available in public registries. Specifically:
- publicly served files that reveal the platform and the versions of plugins and themes;
- TLS certificate configuration and supported ciphers;
- security headers in HTTP responses;
- public DNS records, including SPF, DKIM and DMARC;
- subdomains recorded in public sources (certificate logs, public DNS archives, and the like);
- open network ports and server platform fingerprinting.
Detected versions are compared against a local copy of a public known-vulnerability database (Wordfence Intelligence Community Edition, alongside the MITRE CVE catalogue).
3.2 The email source check
Analyses the source text of a message that you paste in or attach as an .eml file. The check:
- determines from the headers which server the message came from and whether that matches what the sender’s domain permits (SPF, DKIM, DMARC, the transfer record);
- compares the sender’s display name with the address the message was sent from;
- compares the text of a link with its actual destination;
- determines whether the sender domain or a link domain imitates a well-known name;
- recognises risky file types from attachment names.
The check opens no link from the message and neither opens nor decodes attachments — attachments are stripped in your browser before sending, and only their name and size are transmitted.
3.3 The GDPR check
Loads the home page of the entered domain with an automated browser, as an ordinary visitor, without any interaction. The check:
- records which cookies are set before any user action is taken;
- determines whether a consent banner is present on the page;
- looks for a link to the privacy policy;
- determines whether the page contains a form collecting personal data with no link to the policy;
- compares the statements in the privacy policy with the observed state.
On the page being checked, the check changes nothing, deletes nothing and sets nothing — it only reads.
3.4 The legitimacy check
From publicly available data, it assesses whether the entered site stands out on indicators typical of fraud. The check:
- loads the page with an automated browser, as an ordinary visitor, without any interaction;
- determines the domain's registration age and term and its registrar from public registries;
- for Croatian shops, checks whether a company ID (OIB) is published and mathematically valid;
- detects the payment methods offered and the trader's published details (contact, mandatory pages);
- determines whether the domain imitates a known name, and reads the TLS certificate and the public web archive.
The check is strictly passive — it performs no active probing and changes nothing on the page being checked. The best possible outcome is “nothing obvious stands out”, never a statement that a site is safe.
4. What the checks do not do
The free check performs no active testing against the entered system. It does not attempt to:
- inject data into forms, databases or parameters (SQL injection and related tests);
- access content behind a login;
- bypass access control or escalate privileges;
- exhaust system resources or affect availability.
Such tests are never performed automatically under any circumstances. They are arranged separately, with the system owner's written authorisation and a scope agreed in advance.
In addition: the email source check opens no links from the message, does not open attachments and does not look for malicious content in them. The GDPR check removes and alters no cookies, nor any other content of the page being checked.
5. What the findings are not
The findings describe only what was visible from the outside, at the moment the check ran, using the tools the check employs. Please note:
- Findings with no warnings do not mean the system is secure. They mean only that the check did not find what it looks for.
- External detection does not identify every installed component. Some remain unseen.
- Version-number comparison may report a vulnerability that has already been patched in your system without that number changing (for example, by a hosting provider's backported patch).
- A system's state changes after the check. The findings hold for the moment they were produced.
The findings are information — not a risk assessment, an audit, or a certification of compliance with any standard.
5.1 The email source check
From the source of a message it is possible to prove that a message is a fraud, but never that it is not. The outcome “no obvious alarms” means only that the check found none of the signs it looks for — it is not confirmation that the message is genuine, nor that its attachments and links are harmless. Before acting on a message with financial or security consequences, confirm it through another channel.
5.2 The GDPR check
The findings are a technical observation, not legal advice, a legal opinion or confirmation of compliance. An absence of findings does not mean the page complies with the General Data Protection Regulation or any other rule — only that on the points checked no obvious discrepancy was observed. The check is external and cannot see the legal basis for processing, processor agreements or internal records. Only a person who knows the legal and business context can assess compliance.
6. The findings are yours
You may freely use, store, print and forward the findings you receive to anyone, without further permission from us and at no charge. We claim no rights over the content of the findings about your system.
The Service's source code, design, texts and logo are the property of Lunar j.d.o.o.
7. Prohibited use
You agree that you will not:
- enter domains you are not authorised for;
- use the Service to reconnoitre other people's systems, prepare an attack, or for any other unlawful purpose;
- circumvent limits on the number of checks, automate calls to the Service, or embed it in another product;
- enter other people's email addresses in order to send them unwanted messages;
- submit for checking any message you did not receive and are not authorised to have analysed;
- attempt unauthorised access to the Service or the servers it runs on, disrupt their operation, or overload them.
The number of checks per user and per period is limited. We reserve the right to refuse, interrupt or block a check without giving reasons.
8. Availability
The Service is provided “as is” and “as available”. We do not warrant that it will run without interruption or without error. The Service is free of charge and we may modify, limit or discontinue it at any time without prior notice.
9. Limitation of liability
To the fullest extent permitted by Croatian law, Lunar j.d.o.o. is not liable for indirect, incidental or consequential damage, including lost profit, loss of data or business interruption, arising from use of the Service or reliance on the findings.
Nothing in these Terms excludes liability that cannot be excluded under Croatian law, including liability for intent and gross negligence.
10. Indemnity
You agree to indemnify us for any damage, cost and third-party claim arising from your breach of these Terms, and in particular from entering a domain you were not authorised for — including legal costs and the consequences of action taken against us by a hosting provider or competent authority.
11. Changes to these Terms
We may amend these Terms from time to time. The “Last updated” date shows when they were last changed. Starting a new check after a change means you accept the amended Terms.
12. Governing law
These Terms are governed by the law of the Republic of Croatia. The competent court in Varaždin has jurisdiction over disputes. If you are a consumer, this does not deprive you of the protection of mandatory rules of your country of habitual residence.
13. Severability
If any provision of these Terms is found invalid or unenforceable, the remaining provisions stay in force.
Contact
Questions about these Terms:
Bana Jelačića 14, 42230 Ludbreg, Croatia
Company ID (OIB): 47232633853
Email: privacy@majhenlabs.com
See also the Privacy Policy.