Scan time: 2026-09-04 13:31:00
Overall Score
✔ This website meets basic data protection requirements.
Note: This automated analysis does not replace legal advice. For a complete GDPR assessment, consult a data protection officer.
↓ See detailed results for each category below.
The website uses an encrypted connection (HTTPS).
Latest encryption active (TLS 1.3 — TLSv1.3).
The security certificate is valid (expires 2027-02-15).
Strong encryption method (TLS_AES_256_GCM_SHA384, 256 bit).
HSTS is enabled — the browser is instructed to always use the encrypted connection.
HSTS duration: 31536000 seconds (at least 1 year) — very good.
Content Security Policy present (via HTTP-Header).
Script sources are properly restricted.
Embedding protection (frame-ancestors) is configured — protects against clickjacking.
Good base rule: only own content is allowed by default (default-src: self).
Referrer-Policy: strict-origin-when-cross-origin (via HTTP-Header).
Strict setting "strict-origin-when-cross-origin" — no path leak, no HTTP downgrade leak. Best practice.
MIME type protection active (nosniff) — browsers will not misinterpret files.
Clickjacking protection active via CSP frame-ancestors.
Permissions-Policy is configured — access to sensitive device APIs is controlled.
5 of 6 sensitive APIs restricted — very good.
No cookies set — exemplary for privacy.
No local storage (Web Storage) used — no tracking risk.
No third-party requests detected — all content comes from the website's own server.
No known trackers detected.
No external scripts or stylesheets loaded.
CAA records present: sectigo.com — only specified certificate authorities may issue certificates.
4 nameservers present — good redundancy.
IPv6 support present (AAAA records).
SPF record present: v=spf1 include:_spf-eu.ionos.com ~all — protects against email spoofing.
DMARC record present: v=DMARC1; p=none; — email authentication active.
security.txt found: https://bbsovg.de/.well-known/security.txt
Contact field present (required) — security researchers can report vulnerabilities.
Expires field present (required).
Preferred languages specified.
No external reporting endpoints detected.
No consent banner needed — no trackers or third-party cookies detected.
Privacy policy linked: "Datenschutz" (/datenschutz/).
Legal notice linked: "Impressum" (/impressum/).
Privacy policy link is broken: HTTP/1.1 503 Service Temporarily Unavailable.
The privacy policy link returns an error (HTTP HTTP/1.1 503 Service Temporarily Unavailable). Effectively the same as no privacy policy — same legal status as missing.
WordPress plugin: Step 1: check the footer menu (Appearance → Menus → Footer menu → which URL does the "Privacy" item link to?). Step 2: does the target page still exist? Pages → All Pages. Step 3: if the page was renamed: update the menu link. Step 4: if deleted: create a new one. Step 5: on permalink issues, visit Settings → Permalinks → Save (no changes — rewrites .htaccess).
✓ How to verify it works: Privacy link in footer → opens the page with status 200, content visible.
| Header | Value |
|---|---|
| content-encoding | gzip |
| content-security-policy | default-src 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; font-src 'self' data:; connect-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'; form-action 'self'; upgrade-insecure-requests |
| content-type | text/html |
| date | Fri, 04 Sep 2026 11:30:57 GMT |
| etag | W/"6382-65a90f0dbefc0" |
| last-modified | Thu, 03 Sep 2026 09:40:23 GMT |
| permissions-policy | camera=(), microphone=(), geolocation=(), payment=(), usb=() |
| referrer-policy | strict-origin-when-cross-origin |
| server | Apache |
| strict-transport-security | max-age=31536000 |
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| x-ws-origin | available |
| x-ws-ratelimit-limit | 1000 |
| x-ws-ratelimit-remaining | 999 |