Comprehensive vulnerability analysis including actionable recommendations
What gets checked?
All essential security areas of your website in one structured evaluation.
Comprehensive audit to WCAG 4.x & current best practices β including automated WCAG checks for all pages, contrast analysis with specific color suggestions, and color blindness simulation for multiple visual impairments (red-green, blue weakness, achromatopsia, etc.). Each finding includes location details and prioritized remediation steps.
Dr. DSGVO
Leading blog for digital data protection & secure solutionsIn Detail
Expand a section to view all check points and guidance.
The Security Check analyses all security-relevant areas of your website. Every finding comes with a diagnosis, plain-language explanation and concrete remediation guidance.
DNS configuration, SPF, DKIM, DMARC β with security diagnosis and recommendations.
Provider, mail server, CDN, ASN β including mail provider security analysis.
Cross-referenced with vulnerability databases β filtered by detected technologies, with remediation guides.
Detection of WordPress, TYPO3, Magento etc. β plugins checked for known vulnerabilities.
DOM analysis and cross-site scripting checks β with locations and explanations.
Contact forms checked for insecure handlers and vulnerable input fields.
IPv4/IPv6 analysis, URL reputation, abuse database check and tracking ID comparison.
Extended checks for revealing server responses and security-critical HTTP headers.
Every finding includes a plain-language explanation, a risk rating and concrete remediation steps β with links to further resources and guides.
The Accessibility Check tests your website against international WCAG standards and delivers concrete measures to better reach all user groups.
The homepage is simulated for multiple types of visual impairment β e.g. red-green deficiency, blue blindness, achromatopsia, etc.
Contrast ratios are measured and issues listed β including suggestions for better color combinations.
Hundreds of automated WCAG checks for every page of the website β with locations and remediation hints.
Newer WCAG checks and best practices are also covered and considered.
Alt texts, ARIA labels, keyboard navigation, semantics and further accessibility features are evaluated.
Every finding includes an explanation and concrete improvement suggestions β prioritised by impact on accessibility.
The SEO and Speed Check provides a complete picture of your website's findability and performance β from technical basics to content and structured data.
Analysis of deployed keywords plus suggestions for new, relevant search terms to improve visibility.
Heading hierarchy, internal links, URL structure and crawlability are analysed and rated.
Assessment of text length, readability and content relevance β with improvement suggestions.
Analysis of existing Schema.org markup plus suggestions and an integrated editor for new structured data.
Suggestions for file sizes, formats and missing alt texts β for faster loading times and better SEO.
Load times, HTTP response times and performance metrics are measured and supplied with optimisation hints.
Every finding contains actionable recommendations β from concrete keyword ideas to the integrated editor for structured data.
How it works
No effort, no installation β just enter the URL and receive your report.
Enter your website URL. The scan starts automatically β done.
The scanner checks DNS, software, JavaScript, forms, vulnerabilities and more β fully automatically.
All findings are compiled into a structured report with explanations and remediation guidance.
You receive a secure link to the finished report β accessible and printable at any time.
Why our Security Check?
No raw data dump β a report that truly moves you forward.
Comprehensive analysis and results with explanations, diagnoses and tailored guidance β presented in plain language.
Known security gaps are identified β with filter function and concrete step-by-step remediation guide.
Optional: check for accessibility to current standards, including concrete remediation measures.
Deployed tools, plugins and technologies are detected and analysed β including backend infrastructure such as server software, frameworks and CDN.
For WordPress, TYPO3, Magento and other common systems, installed plugins are identified and specifically checked for known vulnerabilities β where reliable detection and CVE data are available.
Embedded JavaScript is examined for XSS (Cross-Site Scripting) vulnerabilities. A DOM analysis reveals where insecure code could serve as an entry point for attackers.
Forms on your website are systematically tested for vulnerabilities β both the processing logic (form handler) and individual input fields for typical attack vectors.
Available as an add-on: SEO checks and speed test provide a complete picture of your website quality.
Checks & Services
Every scan delivers an extensive, structured report with concrete recommendations β organised by criticality and topic area.
Detection of known CVE security gaps in deployed technologies. Includes a diagnosis guide (am I really affected?) and step-by-step solution for every vulnerability found.
Web server configuration check, detection of unfavourable or dangerous configurations. A/AAAA record checks (redundancy, existence). Explanations & remediation guides.
Cookie consent banners are automatically accepted to reliably capture all deployed plugins. Numerous consent providers are supported and the detection list is continuously updated.
Comprehensive check of DNS configuration and email security records: SPF, DKIM, DMARC, MX configuration and more β protecting against phishing and email spoofing.
Reputation of the URL, domain and IP address, known ABUSE reports from a global database.
Certificate check, TLS protocol versions, cipher suites and HSTS configuration. Plus: DANE validation (DNS-based Authentication of Named Entities) β a unique selling point.
Check for active TRACE method, plus full analysis of all security-relevant HTTP headers: CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy and more.
Comprehensive accessibility audit to WCAG standards β mandatory for many businesses since the European Accessibility Act (June 2025). Significantly cheaper than a standalone accessibility audit.
Detection of contrast violations per WCAG with concrete color fix suggestions. Plus: simulation for the most common color blindness types (deuteranopia, protanopia, tritanopia).
Analysis of your website's current color scheme with concrete suggestions for an optimised palette β for better readability, aesthetics and WCAG compliance.
Cookies, Local Storage and Session Storage are examined for potentially sensitive data that could be passed on by JavaScript code.
Analysis of erroneous and revealing configurations, banner texts, open ports, backend software and more.
Examples of included information
Structured, clear, actionable β with distinct sections, expandable guidance and multiple perspectives on your website.
The following display is purely for illustrating the structure and depth of a real report. All domains, findings and values shown are fictional.
v=DMARC1; p=quarantine; rua=mailto:dmarc@your-domain.com. Start with p=none for monitoring.| Name | Source | Purpose | Risk |
|---|---|---|---|
| _ga | Google Analytics | Tracking | Medium |
| user_token | Own App | Session | β Sensitive |
| ls:email | LocalStorage | Email stored | β Sensitive |
nav a { color: #4a6a8a; }rel="preload" in the <head>. Recommendation: Squoosh.app for lossless compression.
One-time price Β· No subscription Β· No IT expertise required
Highlight
Your report includes an analysis of the color scheme in use β with contrast ratios, color blindness simulation and concrete suggestions for an improved design.
Your current palette
Yellow on white: ratio 1.9:1 (minimum: 4.5:1) β WCAG violation
Recommended new palette
All color combinations with contrast β₯ 4.5:1 β incl. color blindness check
Color blindness simulation
How color-blind users see your site β your report shows all 3 types
Why a Security Check?
Most attacks on websites don't exploit exotic vulnerabilities β they hit known, avoidable weaknesses that were simply never discovered.
Whether you're a small business or a mid-sized company: attackers automatically scan millions of websites daily for known vulnerabilities. Outdated plugins, insecure form handlers or missing DNS records are found within hours β regardless of company size.
Contact forms are the most common attack target on websites. Without proper server-side validation or CSRF protection, attackers can abuse forms to send spam, exfiltrate data or execute arbitrary code.
Our check examines both the processing logic (form handler) and every individual input field for typical attack vectors such as SQL injection and command injection.
Cross-Site Scripting (XSS) is one of the most common web vulnerabilities. If user input is written unsanitised directly to the DOM, an attacker can inject their own JavaScript β stealing session tokens, redirecting users or siphoning data.
Our scanner analyses embedded JavaScript and performs a DOM inspection to find dangerous innerHTML assignments and insecure eval() calls.
If DMARC is missing, SPF is set incorrectly or DKIM is not configured, attackers can send emails in your name. Customers receive phishing emails that appear to come from you β with devastating consequences for trust.
Our DNS check verifies all security-relevant records β SPF, DKIM, DMARC, DNSSEC β and delivers concrete configuration recommendations.
Many websites conveniently store email addresses, session tokens or even password hashes in cookies or the browser's LocalStorage. This data can be read by injected JavaScript (e.g. via XSS or a compromised third-party script).
Our cookie scan captures all browser storage entries and automatically assesses which contain personal or security-critical data.
An expired certificate or insecure TLS versions (TLS 1.0/1.1) endanger the encryption of communication between user and server. Browsers show warnings that drive visitors away β and Google uses HTTPS quality as a ranking factor.
Our SSL check verifies certificate validity, certificate chain, supported TLS versions, cipher suites and HTTP Strict Transport Security (HSTS).
Apache 2.4.49, PHP 7.2, WordPress 5.8 β older software versions are the most common way attackers break into servers. CVE databases list known vulnerabilities publicly β attackers exploit them systematically.
Our software scan detects all deployed components and cross-references them with current CVE databases. Every gap includes a CVSS risk rating and a remediation guide.
HTTP headers like Content-Security-Policy (CSP), X-Frame-Options or Referrer-Policy are easy to configure β and yet forgotten on the majority of all websites. They prevent clickjacking, data leakage and significantly facilitate XSS attacks when missing.
Our web server check verifies all security-relevant HTTP response headers and delivers ready-to-use configuration lines for Apache, nginx and IIS.
If your server IP or domain is on an abuse or spam blacklist, mail servers reject your emails or simply don't deliver them β often without any error message. This can happen even if you've never sent spam, if your host runs other customers on the same IP range.
Our IP check verifies your domain and IP against multiple leading blacklist and reputation services and shows you where and why an entry exists.
WordPress, TYPO3 and Magento are particularly attractive targets due to their widespread use. Outdated plugins are responsible for the majority of all CMS compromises. Especially dangerous: plugins that are no longer actively maintained (abandoned plugins).
Our CMS check reliably detects installed plugins and cross-references them against current CVE data β with a direct link to the official vulnerability description.
Many web servers inadvertently reveal in HTTP headers or error messages which software and version they run. This gives attackers valuable information about which targeted CVE exploits to use.
Server: Apache/2.4.49 (Unix). An automated scanner finds this header, searches for matching CVEs β and launches the targeted attack within seconds.Our web server check analyses all HTTP response headers for unintended information disclosure and delivers concrete configuration recommendations for hardening.
Do you know which of these gaps affect your website?
Our Security Check finds them all β with plain-language explanations and concrete remediation steps.
Pricing
One-time price β no subscription, no follow-up costs.
Security Check
excl. VAT Β· one-time Β· base price
Optional add-ons can be selected during booking.
Order now βSecurity and data protection go hand in hand. Our GDPR Website Check audits your site for cookie compliance, tracking services and data protection violations β with a concrete report and action recommendations. Over 50,000 checks. Proven since 2017.
To the GDPR Check βFull scan of all cookies and tracking services with GDPR assessment
Text suggestions and completeness & currency checks
Technical expertise combined with data protection law knowledge
From β¬2.70/website/month β scalable for DPOs and agencies
Frequently Asked Questions
Answers to the most important questions about the Security Check.
Contact
Use the form for questions about the Security Check. For booking, please use the booking button.
Do you have questions about the scope of services, optional add-ons or your individual needs? Get in touch β we typically reply within one business day.