Ascend Bio Labs scored F.
A peptide storefront with human dosing copy, Ozempic comparisons, and a website that cannot stop session theft. This is a partial public record of the August 31, 2026 assessment.
The grade.
The August 31, 2026 assessment graded this surface F, with a risk score of 100 out of 100.
Niro confirmed 132 findings: 5 critical and 35 high, plus medium, low, and informational items. This public article covers about half of that record.
What the storefront is.
Ascend Bio Labs sells peptide and research-use-only chemicals direct to consumers at ascendbiolabs.com.
The public site uses human-use language while labeling the goods as research materials. That combination is the core of the record.
The five criticals.
These are the highest-severity items in the reviewed record. Each one is a public-site fact with a real-world cost.
- Human dosing and administration guidance on a research-only productDosing and injection language on a research-only listing is the evidence a regulator uses to prove intended human use. A buyer who follows that copy can be harmed, and the research-use disclaimer does not survive it.
- Disease / structure-function claims on an unapproved substanceClaims that a product affects the body or treats a condition make it a drug under US law. On an unapproved peptide, that language is the pattern cited in FDA warning letters.
- Equivalence claims to Ozempic, Wegovy, and MounjaroComparing the listing to approved GLP-1 drugs is an unapproved-new-drug and misbranding problem. It also creates Lanham exposure against the brand owners.
- Direct-to-consumer sale of FDA-targeted substancesOffering these substances to the public, disclaimer or not, is the fact pattern that has triggered recent FDA warning letters.
- Language that implies FDA approval for an unapproved productImplying FDA approval for a research chemical is misbranding and false advertising. Facility registration is not product approval.
The website.
The storefront also failed basic web security. These are grouped findings, not an attack map.
- Confirmed cross-site scripting on a public image endpointA confirmed script injection on a public image endpoint can run in a customer's browser. That is a path to session theft, a checkout skimmer, and stolen account or card data.
- Credentials found in client-side URLsAuthentication material was found in client-side URLs more than once. Anything shipped to the browser is public and can be used to take over accounts.
- No brute-force protection on loginLogin accepted rapid automated attempts with no throttling, lockout, or challenge. That leaves customer accounts open to stuffing and takeover.
- No bot protection on signupSignup accepted rapid automated registration with no challenge. Attackers can flood the storefront with fake accounts and abuse the customer surface.
- No Content-Security-PolicyWithout a content policy, a single injected script runs with no browser-side brake. A contained bug becomes a customer-data breach.
- No Web Application Firewall detectedCommon attack payloads were not blocked at the edge. The higher-severity web issues have no outer filter.
- Missing X-Frame-OptionsThe storefront can be embedded in another site. That is a clickjacking path onto login and checkout.
- Missing browser isolation headersX-Content-Type-Options, Referrer-Policy, Cross-Origin-Opener-Policy, and Permissions-Policy were absent. Those gaps make injected content easier to run and easier to leak.
- Sensitive path patterns on the public surfaceThe public surface exposed patterns associated with logs, dumps, exports, storage, and data. Those names are a map of places operators forget to lock.
- Third-party scripts without Subresource IntegrityVendor scripts load without an integrity hash. If a third-party file is poisoned, the storefront runs that code automatically.
- Server technology leaked through X-Powered-ByThe stack announces itself to every client. That shortens the time an attacker spends choosing tools.
- Email can be spoofedDMARC is monitor-only, common DKIM selectors are missing, and there is no MTA-STS policy. Anyone can send mail that looks like it came from the storefront.
- No CAA recordAny certificate authority can be asked to issue a certificate for the domain. That makes impersonation cheaper.
- No security.txtThere is no published path for responsible disclosure. Researchers have nowhere official to send a report.
- Archived historical URLs still expand the surfaceHundreds of archived addresses keep old endpoints and parameters in circulation. Retired routes that still respond remain in play.
- Tracking without a consent gateVisitor data is shared with third parties with no consent banner. That is a privacy and class-action exposure on top of the security failures.
What it costs.
A customer who follows the dosing copy can be injured. A customer who trusts the checkout can lose a session, an account, or a card.
The same public pages create FDA, FTC, Lanham, and state attorney general or pharmacy-board exposure. A spoofed storefront domain can phish the same buyers. Privacy claims sit on the tracking stack.
The reviewed record contains 73 reportable compliance items. This article does not publish that directory.
The rest of the file.
This is a partial public record. About half of the reviewed file is not published here.
Exact locations, evidence, remaining findings, and remediation stay with Niro. Clients receive the complete record for their own sites.
