← new scan
~/scans/wptest.kaideutsch.de.report
⇣ export pdf
target wptest.kaideutsch.de
resolved159.69.224.3
scanned 2026-05-25 16:22:52
modules 7 of 7 completed
// overall risk
MEDIUM Risk
11 issues across 7 modules — 2 high, 3 medium, 6 low
0 critical
2 high
3 medium
6 low
0 ok
01
WHOIS & DNS
DNS records retrieved — SPF & DMARC present
· LOW
// whois

          
// dns records
A 159.69.224.3
AAAA 2a01:4f8:d0a:650e::2
www A 159.69.224.3
www AAAA 2a01:4f8:d0a:650e::2
MX 10 www521.your-server.de
// ip whois (1)
159.69.224.3 SSL unavailable for this endpoint, order a key at https://members.ip-api.com/ whois ↗
// lookup on dnsarchive.net
// email security
// findings (6)
  • ok SPF record present
  • ok DMARC record present
  • ok 1 MX record(s) configured
  • · low No CAA records — any certificate authority can issue certs for this domain
  • · low No MTA-STS DNS record at _mta-sts — inbound mail can be downgraded
  • · low No TLS-RPT record at _smtp._tls — no visibility into TLS delivery failures
02
SSL / TLS Certificate
Valid certificate, expires in 63 days — TLSv1.3
OK
// raw output
issuer R12
subject wptest.kaideutsch.de
valid from Apr 28 15:08:24 2026 UTC
valid to Jul 27 15:08:23 2026 UTC
tls version TLSv1.3
// findings (3)
  • ok Certificate valid for 63 more days
  • ok TLS 1.3 in use — best available protocol
  • ok HTTP redirects to HTTPS in 1 hop(s)
03
CMS Detection
WordPress detected — 5 plugins found
OK
// raw output
platform WordPress
theme bricks
plugins 5 detected
plugin.01 contact-form-7
plugin.02 ultimate-addons-for-contact-form-7
plugin.03 woocommerce
plugin.04 woocommerce-germanized
plugin.05 wp-vanguard
xmlrpc.php not accessible
login path /wp-login.php
user enum protected
// findings (1)
  • ok WordPress hardening looks reasonable
04
Security Headers
1 of 7 headers missing
MEDIUM
// raw output
HSTS ok (max-age=15768000; includeSubDomains; pre)
CSP ok (default-src 'self'; script-src 'self' 'u)
X-Frame-Options ok (SAMEORIGIN)
X-Content-Type-Options ok (nosniff)
Referrer-Policy ok (strict-origin-when-cross-origin)
Permissions-Policy ok (accelerometer=(), camera=(), geolocation)
Cross-Origin-Opener MISSING
// findings (11)
  • · low Cross-Origin-Opener-Policy not set
  • ok Referrer-Policy is configured
  • ok X-Frame-Options is configured
  • ok Permissions-Policy is configured
  • ok X-Content-Type-Options is configured
  • ok Content-Security-Policy is configured
  • ok Strict-Transport-Security is configured
  • medium CSP weakness — 'unsafe-inline' in script-src — defeats most XSS protection
  • medium CSP weakness — 'unsafe-eval' in script-src — allows eval() and increases XSS risk
  • medium CSP weakness — no frame-ancestors — clickjacking only protected by X-Frame-Options
  • · low No /.well-known/security.txt — researchers cannot find a contact for vulnerability reports
05
Raw HTTP Headers
HTTP/3 · 13 headers · Apache
· LOW
// detected
Apache Web server: Apache
HTTP/3 HTTP/3 (QUIC) in use — fastest available protocol, low latency and connection migration
// raw headers (13)
status HTTP/3 200
date Mon, 25 May 2026 16:22:07 GMT
link <https://wptest.kaideutsch.de/wp-json/>; rel="https://api.w.org/", <https://wpte…
vary Accept-Encoding
server Apache
content-type text/html; charset=UTF-8
cache-control max-age=0, no-cache
referrer-policy strict-origin-when-cross-origin
x-frame-options SAMEORIGIN
permissions-policy accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), micr…
x-content-type-options nosniff
content-security-policy default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://wpte…
strict-transport-security max-age=15768000; includeSubDomains; preload
// findings (4)
  • ok Web server: Apache
  • ok HTTP/3 enabled — best available
  • · low No response compression detected — consider enabling GZIP or Brotli
  • ok Cache-Control: max-age=0, no-cache
06
External JS Libraries
No external JS libraries detected
OK
// raw output
external scripts 0 detected
// findings (1)
  • ok No third-party JavaScript files loaded
07
Malware & Blocklists
Threats detected — 2 suspicious indicator(s)
MEDIUM
// raw output
Google Safe Browsing clean
VirusTotal clean
injected scripts 2 detected
malware patterns 2 matches
// findings (4)
  • ok Google Safe Browsing — clean
  • ok VirusTotal — clean
  • high Malware pattern detected: Suspicious eval usage
  • high Malware pattern detected: Hidden div with suspicious content
// end of report · wptest.kaideutsch.de · 2026-05-25 16:22:52 ↻ scan again