Website Security Check
Secure. Clear.

Comprehensive vulnerability analysis including actionable recommendations

All-in-One Security Analysis – From Domain to Cookies

Analysis
Risk Assessment
Solutions
Software Scan
CVE Vulnerability Analysis
Accessibility Check
SEO Check
Plugin Detection
Cookie Scan

What gets checked?

Comprehensive Analysis –
One Report

All essential security areas of your website in one structured evaluation.

  • Domain Analysis
  • CMS, Technology & Plugin Detection
  • Software Scan (low load, no downtime)
  • Infrastructure Checks (web server, OS, firewall…)
  • Web Server Configuration & revealing responses
  • DNS Analysis with security diagnosis & guidance
  • Hosting Analysis (provider, mail, CDN, ASN)
  • Mail Provider Security Analysis
  • Tracking ID comparison with risk assessment
  • IP Analysis, IPv6, URL/IP reputation, abuse check
  • SSL Check, certificate verification, HTTP trace…
  • Cookie Scan incl. Local Storage and Session Storage
  • Cookie values: analysis for sensitive data
  • CVE Vulnerability Analysis incl. diagnosis & remediation guide
  • JavaScript Analysis: XSS vulnerabilities & DOM inspection
  • Contact Form Check (form handler & input fields)
  • Extensive explanations & guidance in the report

Your report contains

  • Clear diagnoses in plain language
  • Concrete action recommendations
  • Links to useful resources
  • CVE filter by detected technology
  • Step-by-step remediation guides
Pro Check
Accessibility Check to Current Standards

Comprehensive audit to WCAG 4.x & current best practices – including automated WCAG checks for all pages, contrast analysis with specific color suggestions, and color blindness simulation for multiple visual impairments (red-green, blue weakness, achromatopsia, etc.). Each finding includes location details and prioritized remediation steps.

Powered by

Dr. DSGVO

Leading blog for digital data protection & secure solutions
Data Protection DE German Providers Only Made in Germany

In Detail

What gets checked?

Expand a section to view all check points and guidance.

Security Security Check – Full Security Analysis

The Security Check analyses all security-relevant areas of your website. Every finding comes with a diagnosis, plain-language explanation and concrete remediation guidance.

Domain & DNS

DNS configuration, SPF, DKIM, DMARC – with security diagnosis and recommendations.

Hosting & Infrastructure

Provider, mail server, CDN, ASN – including mail provider security analysis.

CVE Vulnerabilities

Cross-referenced with vulnerability databases – filtered by detected technologies, with remediation guides.

CMS & Plugins

Detection of WordPress, TYPO3, Magento etc. – plugins checked for known vulnerabilities.

JavaScript & XSS

DOM analysis and cross-site scripting checks – with locations and explanations.

Forms

Contact forms checked for insecure handlers and vulnerable input fields.

IP & Reputation

IPv4/IPv6 analysis, URL reputation, abuse database check and tracking ID comparison.

Web Server Responses

Extended checks for revealing server responses and security-critical HTTP headers.

Guidance in the Report

Every finding includes a plain-language explanation, a risk rating and concrete remediation steps – with links to further resources and guides.

Accessibility Accessibility Check – WCAG, Colors, Visual Impairments

The Accessibility Check tests your website against international WCAG standards and delivers concrete measures to better reach all user groups.

Color Blindness Simulation

The homepage is simulated for multiple types of visual impairment – e.g. red-green deficiency, blue blindness, achromatopsia, etc.

Color Contrast Analysis

Contrast ratios are measured and issues listed – including suggestions for better color combinations.

WCAG Check Points

Hundreds of automated WCAG checks for every page of the website – with locations and remediation hints.

WCAG up to 4.x & Best Practices

Newer WCAG checks and best practices are also covered and considered.

Structural Checks

Alt texts, ARIA labels, keyboard navigation, semantics and further accessibility features are evaluated.

Remediation Measures Included

Every finding includes an explanation and concrete improvement suggestions – prioritised by impact on accessibility.

Optional SEO Check & Speed Check – Visibility, Performance, Structure

The SEO and Speed Check provides a complete picture of your website's findability and performance – from technical basics to content and structured data.

Keyword Check

Analysis of deployed keywords plus suggestions for new, relevant search terms to improve visibility.

Page Structure

Heading hierarchy, internal links, URL structure and crawlability are analysed and rated.

Content Quality

Assessment of text length, readability and content relevance – with improvement suggestions.

Structured Data

Analysis of existing Schema.org markup plus suggestions and an integrated editor for new structured data.

Image Optimisation

Suggestions for file sizes, formats and missing alt texts – for faster loading times and better SEO.

HTTP Timings & Speed

Load times, HTTP response times and performance metrics are measured and supplied with optimisation hints.

Practical Optimisation Suggestions

Every finding contains actionable recommendations – from concrete keyword ideas to the integrated editor for structured data.

How it works

Your Security Report in 4 Steps

No effort, no installation – just enter the URL and receive your report.

1
https://your-website.com
Start β†’

Enter your website

Enter your website URL. The scan starts automatically – done.

2
CVE cross-reference running…

Automated Deep Scan

The scanner checks DNS, software, JavaScript, forms, vulnerabilities and more – fully automatically.

3
βœ“Summary
πŸ”CVE Vulnerabilities
⚠Action Recommendations
πŸ“‹DNS & Hosting

Report is generated

All findings are compiled into a structured report with explanations and remediation guidance.

4

Report by E-Mail

You receive a secure link to the finished report – accessible and printable at any time.

Book now β†’

Why our Security Check?

More than just a scan

No raw data dump – a report that truly moves you forward.

Detailed Report

Comprehensive analysis and results with explanations, diagnoses and tailored guidance – presented in plain language.

CVE Vulnerabilities

Known security gaps are identified – with filter function and concrete step-by-step remediation guide.

Accessibility Check

Optional: check for accessibility to current standards, including concrete remediation measures.

Software Scan

Deployed tools, plugins and technologies are detected and analysed – including backend infrastructure such as server software, frameworks and CDN.

CMS-Specific Checks

For WordPress, TYPO3, Magento and other common systems, installed plugins are identified and specifically checked for known vulnerabilities – where reliable detection and CVE data are available.

JavaScript Security Analysis

Embedded JavaScript is examined for XSS (Cross-Site Scripting) vulnerabilities. A DOM analysis reveals where insecure code could serve as an entry point for attackers.

Contact Form Check

Forms on your website are systematically tested for vulnerabilities – both the processing logic (form handler) and individual input fields for typical attack vectors.

SEO & Performance

Available as an add-on: SEO checks and speed test provide a complete picture of your website quality.

What the Audit Report Contains (excerpt)

Every scan delivers an extensive, structured report with concrete recommendations – organised by criticality and topic area.

πŸ›‘οΈ

CVE Vulnerability Scanner

Detection of known CVE security gaps in deployed technologies. Includes a diagnosis guide (am I really affected?) and step-by-step solution for every vulnerability found.

CVE DatabaseAffected AnalysisDiagnosis & Remedy
🌍

Global Vulnerabilities

Web server configuration check, detection of unfavourable or dangerous configurations. A/AAAA record checks (redundancy, existence). Explanations & remediation guides.

PoliciesSoftware ScanGuides
πŸͺ

Auto-Consent & Technology Detection

Cookie consent banners are automatically accepted to reliably capture all deployed plugins. Numerous consent providers are supported and the detection list is continuously updated.

PluginsTechnologiesAuto Consent
πŸ“§

DNS & Email Security

Comprehensive check of DNS configuration and email security records: SPF, DKIM, DMARC, MX configuration and more – protecting against phishing and email spoofing.

SPFDKIMDMARCMX
⚠️

URL Reputation & ABUSE Score

Reputation of the URL, domain and IP address, known ABUSE reports from a global database.

ReputationRisk ScoreReports
πŸ”

SSL/TLS & DANE

Certificate check, TLS protocol versions, cipher suites and HSTS configuration. Plus: DANE validation (DNS-based Authentication of Named Entities) – a unique selling point.

TLS 1.3Cipher SuitesHSTSDANETLSA
🌐

HTTP TRACE & Security Headers

Check for active TRACE method, plus full analysis of all security-relevant HTTP headers: CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy and more.

HTTP TRACECSPX-Frame-OptionsReferrer-Policy
β™Ώ

Accessibility (WCAG 2.2 + Best Practices)

Comprehensive accessibility audit to WCAG standards – mandatory for many businesses since the European Accessibility Act (June 2025). Significantly cheaper than a standalone accessibility audit.

WCAG 2.2 AAKeyboard NavigationARIA
🎨

WCAG Color Analysis & Fixes

Detection of contrast violations per WCAG with concrete color fix suggestions. Plus: simulation for the most common color blindness types (deuteranopia, protanopia, tritanopia).

Contrast RatiosFix SuggestionsColor Blindness
🎨

Color Scheme Analysis & Design Suggestions

Analysis of your website's current color scheme with concrete suggestions for an optimised palette – for better readability, aesthetics and WCAG compliance.

Palette AnalysisDesign RecommendationsWCAG Compliance
πŸ”‘

Data Analysis

Cookies, Local Storage and Session Storage are examined for potentially sensitive data that could be passed on by JavaScript code.

CookiesStoragesSensitive Data
βš™οΈ

Further Checks

Analysis of erroneous and revealing configurations, banner texts, open ports, backend software and more.

robots.txtsitemap.xmlRedirects
Book now β†’

Examples of included information

What a Security Report looks like

Structured, clear, actionable – with distinct sections, expandable guidance and multiple perspectives on your website.

View sample report β†’

The following display is purely for illustrating the structure and depth of a real report. All domains, findings and values shown are fictional.

Security Check – Report
https://your-website.com
Website Security Check
Created: 02.04.2025 Β· IT Logic & Dr. DSGVO
D
Risk Score
C+
SSL / TLS
F
HTTP Headers
B
DNS
Global Infrastructure & Global Vulnerabilities 8 Findings
Critical WordPress 6.1.1 – critical vulnerability (CVE-2023-22622)
The detected WordPress version contains a known security gap that allows unauthorised access to administrative functions. An attacker can read or modify critical data without authentication.
CVE-2023-22622 WordPress Core CVSS 9.8 – Critical
High DMARC policy missing – email spoofing possible
High Contact form – missing CSRF protection
+ 5 more findings in the full report
Page-spec. Page-Specific Findings & JavaScript Analysis 5 pages Β· 12 findings
Cookies Cookie Scan & Local Storage 14 entries Β· 3 sensitive
Accessibility Check – Report
https://your-website.com
Accessibility Check
WCAG 2.1 Β· Level AA
38
Overall Score
12
Contrast
64
Structure
WCAG Contrast & Color Blindness 7 Issues
Critical Insufficient contrast: navigation text #8a9bb2 on #ffffff (2.8:1)
WCAG 2.1 minimum requirement: 4.5:1 for normal text. The measured value of 2.8:1 meets neither Level AA nor Level A. Affects all navigation links in the main navigation.
Color blindness simulations & more findings in the full report
SEO & Speed Check – Report
https://your-website.com
SEO & Performance Check
Core Web Vitals Β· Structure Β· Keywords
C
SEO Score
3.8s
LCP
A
Meta Tags
SEO Performance & Core Web Vitals 4 Issues
High LCP 3.8s – Largest Contentful Paint too slow (target: < 2.5s)
The largest visible element on the page (hero image, 1.2 MB) loads too late. Google penalises this in ranking evaluations.
+ 3 more performance findings in the full report
Order my report now β†’

One-time price Β· No subscription Β· No IT expertise required

Color Analysis & New Color Scheme Suggestions

Your report includes an analysis of the color scheme in use – with contrast ratios, color blindness simulation and concrete suggestions for an improved design.

Your current palette

Contrast issue detected

Yellow on white: ratio 1.9:1 (minimum: 4.5:1) – WCAG violation

Recommended new palette

WCAG AA compliant

All color combinations with contrast β‰₯ 4.5:1 – incl. color blindness check

Color blindness simulation

Deuteranopia view

How color-blind users see your site – your report shows all 3 types

Why a Security Check?

10 Critical Areas Putting Your Website at Risk

Most attacks on websites don't exploit exotic vulnerabilities – they hit known, avoidable weaknesses that were simply never discovered.

Attackers don't need an invitation – they find the door themselves.

Whether you're a small business or a mid-sized company: attackers automatically scan millions of websites daily for known vulnerabilities. Outdated plugins, insecure form handlers or missing DNS records are found within hours – regardless of company size.

43%
of all attacks target SMBs
94%
of WordPress sites run outdated plugins
< 15 min
until a new gap is automatically exploited
72%
of operators are unaware of their vulnerability
Critical

Insecure Form Handlers

Critical

XSS – JavaScript as Entry Point

High

Misconfigured DNS Records

Critical

Sensitive Data in Cookies & LocalStorage

High

Weak SSL / Outdated TLS Configuration

Critical

Outdated Backend Software & CVE Gaps

High

Missing Security HTTP Headers

High

IP Reputation & Blacklist Entries

Critical

Vulnerable Plugins & CMS Versions

Medium

Information Leakage via Server Responses

Do you know which of these gaps affect your website?

Our Security Check finds them all – with plain-language explanations and concrete remediation steps.

Book Security Check now β†’

Pricing

Transparent and fair

One-time price – no subscription, no follow-up costs.

Security Check

€59

excl. VAT Β· one-time Β· base price

  • Comprehensive security report
  • All core checks included
  • CVE vulnerability analysis
  • Cookie scan
  • Explanations, diagnosis & action recommendations
  • Accessibility (100+ checks)
  • Optional: accessibility, SEO, speed

Optional add-ons can be selected during booking.

Order now β†’
Book online instantlyNo long lead times, no coordination required.
Clear, readable reportUnderstandable even without an IT background.
High reliabilityThanks to concrete check logic and deliberately no AI in the analysis.
Powered by Dr. DSGVO & IT LogicVerified quality from data protection and IT security experts.
Fast resultsPromptly after booking confirmation – no weeks-long process.
πŸ”’ Complementary Service

Also thought about data protection?

Security and data protection go hand in hand. Our GDPR Website Check audits your site for cookie compliance, tracking services and data protection violations – with a concrete report and action recommendations. Over 50,000 checks. Proven since 2017.

To the GDPR Check β†’
πŸͺ

Cookie Analysis

Full scan of all cookies and tracking services with GDPR assessment

πŸ“„

Privacy Policy

Text suggestions and completeness & currency checks

βš–οΈ

Legal Compliance

Technical expertise combined with data protection law knowledge

πŸ“¦

Agency Packages

From €2.70/website/month – scalable for DPOs and agencies

Frequently Asked Questions

FAQ

Answers to the most important questions about the Security Check.

What do I receive after the Security Check?
You receive a comprehensive report with plain-language explanations, diagnoses and concrete action recommendations. Where useful, helpful resources and links are included. The report is structured so you understand where action is needed even without deep IT knowledge.
Who is the Security Check suitable for?
For businesses of any size, freelancers, associations and anyone operating a publicly accessible website. The report is understandable for technically versed users as well as non-technical ones.
Will my website be affected by the scan?
No. The software scan runs at low load and is designed not to disrupt your website's normal operation. No changes whatsoever are made to your website.
What does "German providers only" mean?
The companies involved in providing the service are based in Germany and are independent of non-European entities. In particular, we do not use Microsoft Azure or AWS. For processing online payments (unless paying by bank transfer), we use European and non-European providers – you have the choice of payment method.
What does "data protection" mean as a quality feature?
Your personal data is not passed on to third parties unless required by law (e.g. for tax purposes) or permitted under GDPR. We use this data only for purposes necessary to fulfil the contract.
How long does it take to receive my report?
For directly bookable scans, you receive your report promptly after booking confirmation and payment – typically within 30 minutes or, during high demand, within a few hours.
What does the cookie scan do?
The cookie scan captures all cookies set as well as entries in LocalStorage and SessionStorage – presenting results clearly in table form. For numerous known cookies, purpose and plugin assignment are automatically added, so you can see at a glance where a cookie comes from and what it does. Additionally, the scan identifies sensitive data in browser storage that could be personal or potentially readable by third-party JavaScript – an often underestimated data protection and security risk.
What exactly does the software scan analyse?
The software scan detects deployed tools, plugins, frameworks and technologies on your website – including backend infrastructure such as web server software and CDN. The detected components are then cross-referenced against known vulnerability databases, so you can see exactly which software versions pose a security risk and what to do about it.
Are CMS like WordPress or TYPO3 specifically considered?
Yes. For widespread systems such as WordPress, TYPO3 and Magento, installed plugins can be reliably detected and specifically checked for known vulnerabilities (CVEs). CMS-specific checks are applied where reliable plugin detection and corresponding vulnerability data are available – for less widespread or heavily customised systems, this part of the analysis is naturally more limited.
Is JavaScript also checked for security issues?
Yes. The scanner analyses embedded JavaScript for XSS (Cross-Site Scripting) vulnerabilities – one of the most common attack methods on the web. A DOM analysis is also performed, revealing where insecure code exists in the page structure and how attackers could exploit it. The report includes specific locations and remediation guidance.
Are contact forms on my website checked?
Yes. Forms are a frequently underestimated attack target. The Security Check examines both the processing logic in the background (form handler) and individual input fields for typical vulnerabilities such as missing validation, injection susceptibility or insecure data transmission. Issues found are explained clearly in the report with guidance on how to secure them.
What is tested in the accessibility check?
The accessibility check covers two levels: For the homepage, a color blindness simulation is run covering multiple types of visual impairment (e.g. red-green deficiency, blue blindness, etc.). Additionally, color contrasts are analysed and concrete improvement suggestions including alternative color values are listed. For all pages of the website, hundreds of WCAG check points are evaluated – with locations and remediation hints. Best practices are also considered. Heuristic and static checks for improved accessibility are additionally performed.
How long does a full scan take?
Typically around 15 minutes – including the optional accessibility check. The time results from several parallel check steps: software scan, cross-referencing with vulnerability databases, visual analysis of the homepage, color blindness simulation, color contrast evaluation and page-by-page WCAG checks. Duration may vary slightly depending on website size.
Does the scanner use artificial intelligence?
No – deliberately not. For the technical analysis of your website we forgo AI, because AI-based checks in this area are error-prone and can lead to unreliable results. Instead, the scanner uses specially developed, targeted check routines designed precisely for each analysis area. Our own tests have shown: this minimally invasive, rule-based approach delivers more precise, faster and more reproducible results – without the imprecision that AI systems bring to technical security checks.
What distinguishes this check from free online scanners?
Free services usually deliver raw data without context and check depth is limited. Our check provides a structured report with diagnoses, explanations and action recommendations – developed by experts in data protection and IT security. The audited website is analysed in depth, including the underlying technical infrastructure.

Contact

Questions? Write to us

Use the form for questions about the Security Check. For booking, please use the booking button.

We're happy to help

Do you have questions about the scope of services, optional add-ons or your individual needs? Get in touch – we typically reply within one business day.

Reply within one business day
IT Logic – Secure Solutions
Go to booking form β†’
* Required fields
Thank you! Your message was sent successfully. We'll be in touch shortly.