This doesn't detect Cloudflare CNAME clients.
For ex. It says uber.com is not vulnerable - because the homepage isn't, while the app is consitantly one of the most impacted in the caches I've seen
I don't think anyone has really nailed the methodology here - and I think that is important (as is erring towards false positives rather than false negatives) for security mitigation advice