Deutsch | English Header test API About WebForensik

WebForensik

Results for https://bbsovg.de/

Scan time: 2026-09-04 13:31:00

93

Overall Score

Score history for this domain View full history →

GDPR Summary

✔ This website meets basic data protection requirements.

Note: This automated analysis does not replace legal advice. For a complete GDPR assessment, consult a data protection officer.

↓ See detailed results for each category below.

Show:
100 HTTPS / Encryption

The website uses an encrypted connection (HTTPS).

Latest encryption active (TLS 1.3 — TLSv1.3).

The security certificate is valid (expires 2027-02-15).

Strong encryption method (TLS_AES_256_GCM_SHA384, 256 bit).

80 Enforced Encryption (HSTS)

HSTS is enabled — the browser is instructed to always use the encrypted connection.

HSTS duration: 31536000 seconds (at least 1 year) — very good.

75 Content Security Policy (CSP)

Content Security Policy present (via HTTP-Header).

Script sources are properly restricted.

Embedding protection (frame-ancestors) is configured — protects against clickjacking.

Good base rule: only own content is allowed by default (default-src: self).

100 Referrer Policy

Referrer-Policy: strict-origin-when-cross-origin (via HTTP-Header).

Strict setting "strict-origin-when-cross-origin" — no path leak, no HTTP downgrade leak. Best practice.

100 MIME Type Protection

MIME type protection active (nosniff) — browsers will not misinterpret files.

100 Clickjacking Protection

Clickjacking protection active via CSP frame-ancestors.

100 Permissions (Camera, Microphone, etc.)

Permissions-Policy is configured — access to sensitive device APIs is controlled.

5 of 6 sensitive APIs restricted — very good.

100 Cookies

No cookies set — exemplary for privacy.

100 Local Storage (Web Storage)

No local storage (Web Storage) used — no tracking risk.

100 Third-Party Requests

No third-party requests detected — all content comes from the website's own server.

100 Tracker Detection

No known trackers detected.

100 External Resource Integrity (SRI)

No external scripts or stylesheets loaded.

100 DNS Security

CAA records present: sectigo.com — only specified certificate authorities may issue certificates.

4 nameservers present — good redundancy.

IPv6 support present (AAAA records).

SPF record present: v=spf1 include:_spf-eu.ionos.com ~all — protects against email spoofing.

DMARC record present: v=DMARC1; p=none; — email authentication active.

100 Security Contact (security.txt)

security.txt found: https://bbsovg.de/.well-known/security.txt

Contact field present (required) — security researchers can report vulnerabilities.

Expires field present (required).

Preferred languages specified.

100 External Reporting Endpoints

No external reporting endpoints detected.

80 Cookie Consent

No consent banner needed — no trackers or third-party cookies detected.

80 Privacy Policy & Legal Notice

Privacy policy linked: "Datenschutz" (/datenschutz/).

Legal notice linked: "Impressum" (/impressum/).

Privacy policy link is broken: HTTP/1.1 503 Service Temporarily Unavailable.

☛ Action needed: The privacy policy link leads to an error. Check the URL and ensure the page is accessible.
▸ How to fix this — step-by-step guide

The privacy policy link returns an error (HTTP HTTP/1.1 503 Service Temporarily Unavailable). Effectively the same as no privacy policy — same legal status as missing.

WordPress Special for WordPress: where to add this

WordPress plugin: Step 1: check the footer menu (Appearance → Menus → Footer menu → which URL does the "Privacy" item link to?). Step 2: does the target page still exist? Pages → All Pages. Step 3: if the page was renamed: update the menu link. Step 4: if deleted: create a new one. Step 5: on permalink issues, visit Settings → Permalinks → Save (no changes — rewrites .htaccess).

✓ How to verify it works: Privacy link in footer → opens the page with status 200, content visible.

HTTP Response Headers
HeaderValue
content-encoding gzip
content-security-policy default-src 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; font-src 'self' data:; connect-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'; form-action 'self'; upgrade-insecure-requests
content-type text/html
date Fri, 04 Sep 2026 11:30:57 GMT
etag W/"6382-65a90f0dbefc0"
last-modified Thu, 03 Sep 2026 09:40:23 GMT
permissions-policy camera=(), microphone=(), geolocation=(), payment=(), usb=()
referrer-policy strict-origin-when-cross-origin
server Apache
strict-transport-security max-age=31536000
x-content-type-options nosniff
x-frame-options SAMEORIGIN
x-ws-origin available
x-ws-ratelimit-limit 1000
x-ws-ratelimit-remaining 999

New Scan · Compare

Embed your score on your website

Show your WebForensik score publicly. The badge is a lightweight SVG, loads fast, and respects your visitors' privacy (no tracking).

WebForensik Score Badge

HTML code to embed (this specific scan)

<a href="https://webforensik.de/results.php?id=1348" target="_blank" rel="noopener">
  <img src="https://webforensik.de/badge.php?id=1348" alt="WebForensik Score" width="174" height="28">
</a>

Or dynamically — always shows the latest scan of this domain

<a href="https://webforensik.de/?url=https://bbsovg.de" target="_blank" rel="noopener">
  <img src="https://webforensik.de/badge.php?domain=bbsovg.de" alt="WebForensik Score" width="174" height="28">
</a>