Deutsch | English Header test API About WebForensik

WebForensik

Results for https://itsua.com/

Scan time: 2026-10-09 10:09:26

88

Overall Score

Score history for this domain View full history →

GDPR Summary

✔ This website meets basic data protection requirements.

Note: This automated analysis does not replace legal advice. For a complete GDPR assessment, consult a data protection officer.

↓ See detailed results for each category below.

Show:
100 HTTPS / Encryption

The website uses an encrypted connection (HTTPS).

Latest encryption active (TLS 1.3 — TLSv1.3).

The security certificate is valid (expires 2026-11-14).

Strong encryption method (TLS_AES_256_GCM_SHA384, 256 bit).

80 Enforced Encryption (HSTS)

HSTS is enabled — the browser is instructed to always use the encrypted connection.

HSTS duration: 31536000 seconds (at least 1 year) — very good.

60 Content Security Policy (CSP)

Content Security Policy present (via HTTP-Header).

Inline scripts allowed (unsafe-inline). Weakens XSS protection for inline code; the other CSP directives still protect.⚠ Mandatory when running WORDPRESS — required by WordPress itself.

☛ Action needed: Remove 'unsafe-inline' from your CSP and use nonces or hashes for inline scripts instead. Your web developer can implement this.
▸ How to fix this — step-by-step guide

Your CSP allows "unsafe-inline" for scripts — this largely defeats XSS protection. Solution: sign inline scripts with a nonce or hash instead of allowing them wholesale. This is technically demanding — a job for your web developer.

WordPress Special for WordPress: where to add this

WordPress plugin: WordPress themes often emit inline scripts via wp_localize_script() or plugin output. Pragmatic interim step: keep "unsafe-inline" for now, but gradually externalize inline scripts to .js files. Pro solution: plugin "WP Content Security Policy & Headers" with nonce support.

✓ How to verify it works: Once nonce-based CSP is active: F12 → Console — no more "Refused to execute inline script…" messages.

Embedding protection (frame-ancestors) is configured — protects against clickjacking.

Good base rule: only own content is allowed by default (default-src: self).

↓ SHOW COMPLETE SOLUTION All missing security headers bundled at the end of the report — ready to copy.
100 Referrer Policy

Referrer-Policy: strict-origin-when-cross-origin (via HTTP-Header).

Strict setting "strict-origin-when-cross-origin" — no path leak, no HTTP downgrade leak. Best practice.

100 MIME Type Protection

MIME type protection active (nosniff) — browsers will not misinterpret files.

100 Clickjacking Protection

Clickjacking protection active via CSP frame-ancestors.

100 Permissions (Camera, Microphone, etc.)

Permissions-Policy is configured — access to sensitive device APIs is controlled.

5 of 6 sensitive APIs restricted — very good.

100 Cookies

No cookies set — exemplary for privacy.

100 Local Storage (Web Storage)

No local storage (Web Storage) used — no tracking risk.

75 Third-Party Requests

1 request(s) to 1 different third-party servers.

1 third-party server(s) within the EU/EEA.

static.cloudflareinsights.com 1 Requests · Canada (CA) · EU/EEA

Requested URLs:

https://static.cloudflareinsights.com/beacon.min.js/v4bc70e2c01a94c73b74392e4234840661791215815920

100 Tracker Detection

No known trackers detected.

100 External Resource Integrity (SRI)

1 of 1 external resource(s) use integrity verification (SRI).

100 DNS Security

CAA records present: mailto:privacy@itsua.com, comodoca.com, digicert.com; cansignhttpexchanges=yes, letsencrypt.org, pki.goog; cansignhttpexchanges=yes, ssl.com, comodoca.com, digicert.com; cansignhttpexchanges=yes, letsencrypt.org, pki.goog; cansignhttpexchanges=yes, ssl.com — only specified certificate authorities may issue certificates.

2 nameservers present — good redundancy.

IPv6 support present (AAAA records).

SPF record present: v=spf1 include:_spf.google.com include:relay.mailchannels.net ~all — protects against email spoofing.

DMARC record present: v=DMARC1; p=reject; pct=100; adkim=s; aspf=s — email authentication active.

100 Security Contact (security.txt)

security.txt found: https://itsua.com/.well-known/security.txt

Contact field present (required) — security researchers can report vulnerabilities.

Expires field present (required).

Preferred languages specified.

75 External Reporting Endpoints

Network Error Logging (NEL) active — network errors are reported to an external service.

☛ Action needed: Network Error Logging sends error data to external servers. Ensure this data transfer is mentioned in your privacy policy and that the recipient operates in compliance with GDPR.
▸ How to fix this — step-by-step guide

Network Error Logging (NEL) reports network errors to an external server. As with external reporting: mention in privacy policy and verify GDPR compliance of the recipient.

Apache server (classic hosting at most providers)

File: .htaccess in the web root

<IfModule mod_headers.c>
    Header always unset NEL
    Header always unset Report-To
</IfModule>

⚠ If you don’t actively need NEL: these two lines remove both reporting headers. If you do: document it in the privacy policy.

WordPress Special for WordPress: where to add this

Option 1: via .htaccess (recommended — no theme editing)

File: .htaccess in the WordPress root

<IfModule mod_headers.c>
    Header always unset NEL
    Header always unset Report-To
</IfModule>

⚠ If headers come from a plugin, configure the plugin instead.

✓ How to verify it works: F12 → Network → first request → Response Header: NO "nel" or "report-to" anymore (or deliberately documented).

Data is reported to external service: Report-To: a.nel.cloudflare.com

☛ Action needed: Your website sends reports to external services. Check whether your privacy policy covers this data transfer and whether the external service is GDPR-compliant. If the service is outside the EU, the same rules apply as for third-party servers.
▸ How to fix this — step-by-step guide

Your site sends error or CSP reports to an external service (Report-To: a.nel.cloudflare.com). GDPR-relevant: at least IP address and URL are transmitted. Verify (a) the recipient is GDPR-compliant, (b) the transfer is mentioned in your privacy policy, (c) a data processing agreement (DPA) exists.

WordPress Special for WordPress: where to add this

WordPress plugin: If you didn’t set up the reporting endpoint yourself, it usually comes from a plugin (e.g. Sentry, Rollbar, Datadog). Check the plugin configuration — either disable, replace with an EU vendor, or gate behind consent.

✓ How to verify it works: Privacy policy contains an entry about error reporting + DPA is in place. In incognito: F12 → Network → no unintended reporting requests.

80 Cookie Consent

No consent banner needed — no trackers or third-party cookies detected.

70 Privacy Policy & Legal Notice

Privacy policy linked: "PRIVACY" (/privacy/).

No legal notice (Impressum) found — required under German law (§ 5 DDG).

☛ Action needed: Create a legal notice (Impressum) and link it prominently. Required under § 5 DDG for commercial websites. Required information: name, address, email, and where applicable, trade register and VAT ID.
▸ How to fix this — step-by-step guide

No imprint (legal notice) found — mandatory in Germany under § 5 DDG for all business-grade websites (and effectively for many other commercial sites in the EU). Even private blogs with ad or affiliate revenue typically require one. Violations are commonly targeted by warning letters.

WordPress Special for WordPress: where to add this

WordPress plugin: Step 1: create an imprint. Free generator (German law): https://www.e-recht24.de/impressum-generator.html. Mandatory information includes: full legal name, postal address (no P.O. box), phone OR another second contact, email, for companies: trade register + VAT ID, supervisory authority if applicable, professional liability insurance if applicable. Step 2: in WordPress → Pages → Add New → title "Imprint" → publish. Step 3: footer menu → add "Imprint". IMPORTANT: the imprint must be "easily recognizable, directly accessible, permanently available" — a footer link satisfies this, an "About us" → "then imprint" does NOT.

✓ How to verify it works: Footer on every page → link "Imprint" or "Legal notice" visible → opens the imprint page with all mandatory information.

Privacy policy page is accessible (HTTP 200).

⚙ Your ready-to-use security .htaccess

All missing security headers combined into one block. Append this block to the end of your .htaccess — done. 1 headers will be set.

⚠ Why this recommendation does NOT give a 100% score — and why that's how it is with WordPress

The Content-Security-Policy above deliberately includes 'unsafe-inline' for both style-src and script-src. This does NOT provide full XSS protection — it's a pragmatic trade-off, not a bug.

Why? A typical WordPress setup (theme + 5-15 plugins) emits 10-50 different inline <script> blocks into the HTML: jQuery init, slider init, cookie banner, tracking, GTM, web vitals, lazy-load, speculation rules and so on. A strict script-src 'self' blocks them all — the site becomes visually and functionally broken (blank slider, broken cookie banner, dead plugins).

Consequence for scoring: Sites running WordPress with plugins can score at most ~75-85 points in the CSP category in this app — the full 100% rating is only achievable when inline code is signed via nonce or hash (technically demanding, breaks on every theme/plugin update).

Paths to full XSS protection (in increasing complexity):

  • Plugin "WP Content Security Policy & Headers" — automatically adds nonces to inline scripts (medium effort, cleanest WP solution).
  • Hash-based CSP — whitelist every inline script via SHA-256 in the CSP (fragile, breaks on updates).
  • Externalize inline scripts — rebuild theme/plugins so no inline JS is emitted (huge effort, often impossible).

Anyone who doesn't take one of these paths lives with 'unsafe-inline' — like about 95% of all production WordPress sites on the web. The other CSP directives still protect: default-src 'self' blocks external resources, object-src 'none' bans Flash/Java, frame-ancestors 'self' prevents clickjacking, base-uri 'self' prevents base-tag hijacking. Not maximum protection, but realistic protection for WP reality.

Apache Standard Apache (any host, without WordPress)

Append this block to the end of your .htaccess in the web root — done.

<IfModule mod_headers.c>
    Header always set Content-Security-Policy "default-src 'self'; img-src 'self' data: https:; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline'; font-src 'self' https: data:; object-src 'none'; frame-ancestors 'self'; base-uri 'self'; upgrade-insecure-requests"
</IfModule>

WordPress WordPress: .htaccess in WP root

Insert this block ABOVE the "# BEGIN WordPress" line, otherwise WP overwrites it on permalink changes.

# BEGIN WebForensik Security
<IfModule mod_headers.c>
    Header always set Content-Security-Policy "default-src 'self'; img-src 'self' data: https:; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline'; font-src 'self' https: data:; object-src 'none'; frame-ancestors 'self'; base-uri 'self'; upgrade-insecure-requests"
</IfModule>
# END WebForensik Security

WordPress Alternative for WordPress: functions.php in child theme

If your host disallows .htaccess changes: append this PHP snippet to the end of your CHILD theme's functions.php. Back up first — NEVER edit the parent theme, it gets overwritten on updates.

add_action('send_headers', function () {
    header("Content-Security-Policy: default-src 'self'; img-src 'self' data: https:; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline'; font-src 'self' https: data:; object-src 'none'; frame-ancestors 'self'; base-uri 'self'; upgrade-insecure-requests");
});
Dry-run — we re-load your site with the proposed headers and show which resources would be blocked. Takes about 30 seconds.
HTTP Response Headers
HeaderValue
alt-svc h3=":443"; ma=86400
cache-control public, max-age=0, must-revalidate
cf-cache-status HIT
cf-ray a47be71ddd823573-CDG
content-encoding zstd
content-security-policy default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.google.com https://challenges.cloudflare.com https://app.cal.com https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inl
content-type text/html
date Fri, 09 Oct 2026 08:09:22 GMT
link </llms.txt>; rel="describedby"; type="text/plain", </sitemap-index.xml>; rel="sitemap"
nel {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
permissions-policy camera=(), microphone=(), geolocation=(), payment=(), usb=()
priority u=0,i
referrer-policy strict-origin-when-cross-origin
report-to {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=V2Bjfdk86QUgmlADOQ0D3f2geSnA32tvT%2Bcx3tvSnE%2BiS1PQGKl6%2BhOfqMd1EabJFZRj%2F%2FsI7I5I1N4Y57%2BWl%2FTs6AqQcgmoUn4mhbTqS0B2KtrcoXaZt5vTnxVnpXneSO6evw%2BTY9U%3D"}]}
server cloudflare
server-timing cfCacheStatus;desc="HIT" cfEdge;dur=17,cfOrigin;dur=0,cfWorker;dur=13 cfExtPri
strict-transport-security max-age=31536000
x-content-type-options nosniff
x-frame-options SAMEORIGIN

New Scan · Compare

Embed your score on your website

Show your WebForensik score publicly. The badge is a lightweight SVG, loads fast, and respects your visitors' privacy (no tracking).

WebForensik Score Badge

HTML code to embed (this specific scan)

<a href="https://webforensik.de/results.php?id=2726" target="_blank" rel="noopener">
  <img src="https://webforensik.de/badge.php?id=2726" alt="WebForensik Score" width="174" height="28">
</a>

Or dynamically — always shows the latest scan of this domain

<a href="https://webforensik.de/?url=https://itsua.com" target="_blank" rel="noopener">
  <img src="https://webforensik.de/badge.php?domain=itsua.com" alt="WebForensik Score" width="174" height="28">
</a>