Scan-Fakten als JSON anzeigen
{
"schema": "https://saferpage.de/schemas/public-scan-facts.v1",
"claim_boundary": "Öffentliche Rohdaten enthalten nur Scan-Fakten, Statuswerte, Evidence-Grenzen und feste Detail-/Hintergrund-Links. Betreiber-Hintergrund, Planungen, Checklisten, Code und allgemeine Empfehlungen stehen auf separaten Seiten.",
"current_evidence_policy": {
"schema": "https://saferpage.de/schemas/public-scan-current-evidence-policy.v1",
"status": "current_scan_fields_only",
"summary": "Der Fakten-JSON exportiert nur Felder, die im gespeicherten aktuellen Scan wirklich vorhanden sind. Fehlende neue Evidence wird nicht aus alten Testergebnisformaten nachgebaut.",
"guardrails": [
"Keine synthetischen Boundary-Fallbacks fuer alte Scans",
"Keine Nachbewertung alter Testergebnisse im Fakten-JSON",
"Keine Betreiber-Empfehlung im Report-JSON"
]
},
"host": "abo.mittelbayerische.de",
"normalized_url": "https://abo.mittelbayerische.de/",
"score": 54,
"verdict": {
"color": "orange",
"label": "auffällig",
"score": 54
},
"scan_id": "60edf869-3cd6-4753-a588-81984c8c8d87",
"created_at": "2026-06-19 22:06:30.238058+02",
"evidence": {
"dns": {
"ok": true,
"addresses": [
"2600:9000:2204:1c00:1b:59a2:6600:93a1",
"2600:9000:2204:4000:1b:59a2:6600:93a1",
"2600:9000:2204:6400:1b:59a2:6600:93a1",
"2600:9000:2204:7a00:1b:59a2:6600:93a1",
"2600:9000:2204:8600:1b:59a2:6600:93a1",
"2600:9000:2204:a000:1b:59a2:6600:93a1",
"2600:9000:2204:e600:1b:59a2:6600:93a1",
"2600:9000:2204:ec00:1b:59a2:6600:93a1",
"52.222.136.100",
"52.222.136.126",
"52.222.136.2",
"52.222.136.39"
],
"duration_ms": 1
},
"tls": {
"ok": true,
"cipher": "TLS_AES_128_GCM_SHA256",
"issuer": [
[
[
"countryName",
"US"
]
],
[
[
"organizationName",
"Amazon"
]
],
[
[
"commonName",
"Amazon RSA 2048 M04"
]
]
],
"subject": [
[
[
"commonName",
"*.mittelbayerische.de"
]
]
],
"version": "TLSv1.3",
"not_after": "Dec 29 23:59:59 2026 GMT",
"hostname_matches": true,
"days_until_expiry": 193,
"subject_alt_names": [
"*.mittelbayerische.de",
"*.pnp.de",
"*.donaukurier.de",
"*.m2-prod.mol-servers.de"
],
"issuer_common_name": "Amazon RSA 2048 M04"
},
"http": {
"ok": true,
"status": 200,
"headers": {
"via": "1.1 641c321eb6b63a682c557ddfe51be768.cloudfront.net (CloudFront)",
"date": "Fri, 19 Jun 2026 20:05:59 GMT",
"vary": "Accept-Encoding",
"pragma": "no-cache",
"server": "nginx",
"expires": "Thu, 19 Jun 2025 20:05:59 GMT",
"x-cache": "Miss from cloudfront",
"connection": "close",
"set-cookie": "PHPSESSID=0f39f81cdf96bed78c71f5e1fcadbcfe; expires=Fri, 19-Jun-2026 21:05:59 GMT; Max-Age=3600; path=/; domain=abo.mittelbayerische.de; secure; HttpOnly; SameSite=Lax",
"x-amz-cf-id": "OsTQyTh5NmrGUvLN68yi-Xz9KhDbOTXTRC5kJYR2haG9JwAPLr7UxQ==",
"content-type": "text/html; charset=UTF-8",
"x-amz-cf-pop": "FRA50-P2",
"cache-control": "max-age=0, must-revalidate, no-cache, no-store",
"x-magento-tags": "FPC",
"x-frame-options": "SAMEORIGIN",
"x-xss-protection": "1; mode=block",
"transfer-encoding": "chunked",
"x-content-type-options": "nosniff",
"content-security-policy-report-only": "font-src fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d2wu036mkcz52n.cloudfront.net https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com www.gstatic.com cdn.opencmp.net cdn.matomo.cloud pnpabo.matomo.cloud mbv.slgnt.eu files.upscore.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com cdn.opencmp.net cdn.matomo.cloud pnpabo.matomo.cloud *.upscore.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline';"
},
"body_size": 71899,
"final_url": "https://abo.mittelbayerische.de/abos",
"duration_ms": 1086
},
"scanner": {
"bot_url": "https://saferpage.de/bot",
"context": "crawler",
"user_agent": "SaferPageCrawler/0.3 (+https://saferpage.de/bot; schedules passive DACH website checks; report examples: https://saferpage.de/tests; kostenloser Report: <a href=\"https://saferpage.de/abo.mittelbayerische.de\">https://saferpage.de/abo.mittelbayerische.de</a>)",
"default_user_agent": "SaferPageBot/0.2 (+https://saferpage.de/bot; passive website safety check; no attack tests)"
},
"domain_records": {
"mx": true,
"caa": true,
"spf": false,
"dmarc": false,
"dnssec": true,
"records": {
"mx": [
"d3jau5qcn15ifs.cloudfront.net."
],
"ns": [
"d3jau5qcn15ifs.cloudfront.net.",
"ns-702.awsdns-23.net.",
"ns-1368.awsdns-43.org.",
"ns-1724.awsdns-23.co.uk.",
"ns-209.awsdns-26.com."
],
"caa": [
"d3jau5qcn15ifs.cloudfront.net."
],
"txt": [
"d3jau5qcn15ifs.cloudfront.net."
],
"cname": [
"d3jau5qcn15ifs.cloudfront.net."
],
"dmarc": [],
"dnskey_present": true
},
"spf_includes": [],
"verifications": []
},
"googlebot_http": {
"ok": true,
"status": 200,
"headers": {
"via": "1.1 1ff9ce989cf7cac5366389a5419a6d38.cloudfront.net (CloudFront)",
"date": "Fri, 19 Jun 2026 20:05:59 GMT",
"vary": "Accept-Encoding",
"pragma": "no-cache",
"server": "nginx",
"expires": "Thu, 19 Jun 2025 20:05:59 GMT",
"x-cache": "Miss from cloudfront",
"connection": "close",
"set-cookie": "PHPSESSID=4d4c441846de0aa9c395c22950d555e4; expires=Fri, 19-Jun-2026 21:05:59 GMT; Max-Age=3600; path=/; domain=abo.mittelbayerische.de; secure; HttpOnly; SameSite=Lax",
"x-amz-cf-id": "0Qdt3QzClymmt7gA-yKW6eiZu_83Bd6sHG0K-SCPB4EWBdfNRcKCMQ==",
"content-type": "text/html; charset=UTF-8",
"x-amz-cf-pop": "FRA50-P2",
"cache-control": "max-age=0, must-revalidate, no-cache, no-store",
"x-magento-tags": "FPC",
"x-frame-options": "SAMEORIGIN",
"x-xss-protection": "1; mode=block",
"transfer-encoding": "chunked",
"x-content-type-options": "nosniff",
"content-security-policy-report-only": "font-src fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'; form-action geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.com www.sandbox.paypal.com *.cardinalcommerce.com *.paypal.com 3ds-secure.cardcomplete.com www.clicksafe.lloydstsb.com pay.activa-card.com *.wirecard.com acs.sia.eu *.touchtechpayments.com www.securesuite.co.uk rsa3dsauth.com *.monzo.com *.arcot.com *.wlp-acs.com * 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com https://www.google.com/recaptcha/ c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com *.paypal.com * 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid.g.doubleclick.net analytics.google.com www.googletagmanager.com *.ftcdn.net *.behance.net t.paypal.com www.paypal.com www.paypalobjects.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com *.youtube.com validator.swagger.io d2wu036mkcz52n.cloudfront.net https://firebasestorage.googleapis.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.paypal.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com www.paypal.com www.sandbox.paypal.com www.paypalobjects.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com *.youtube.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.google.com www.gstatic.com cdn.opencmp.net cdn.matomo.cloud pnpabo.matomo.cloud mbv.slgnt.eu files.upscore.com *.avada.io *.shopify.com js.braintreegateway.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.paypal.com songbirdstag.cardinalcommerce.com 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com pilot-payflowlink.paypal.com cdn.opencmp.net cdn.matomo.cloud pnpabo.matomo.cloud *.upscore.com https://get.geojs.io *.avada.io api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com *.braintree-api.com *.paypal.com *.cardinalcommerce.com *.google.com google.com 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline';"
},
"body_size": 71899,
"final_url": "https://abo.mittelbayerische.de/abos",
"duration_ms": 1151
},
"ai_search_policy_evidence": {
"files": [
{
"id": "robots_txt",
"url": "https://abo.mittelbayerische.de/robots.txt",
"label": "robots.txt",
"reason": "",
"status": "found",
"body_size": 2404,
"truncated": false,
"body_sha256": "88540bb2818f55ad7363901ddb9b2db795bd4e6d6bd02ff16319225606277f1a",
"duration_ms": 559,
"http_status": 200,
"ai_bot_policy": {
"bot_directives": {
"CCBot": [
{
"value": "/",
"directive": "disallow"
}
],
"GPTBot": [
{
"value": "/",
"directive": "disallow"
}
],
"ChatGPT-User": [
{
"value": "/",
"directive": "disallow"
}
],
"PerplexityBot": [
{
"value": "/",
"directive": "disallow"
}
],
"Google-Extended": [
{
"value": "/",
"directive": "disallow"
}
]
},
"explicit_ai_bots": [
"GPTBot",
"ChatGPT-User",
"Google-Extended",
"PerplexityBot",
"CCBot"
],
"explicit_ai_bot_count": 5,
"wildcard_directive_count": 0,
"wildcard_directives_sample": []
},
"relevant_lines": [
"Disallow: /lib/",
"Disallow: /*.php$",
"Disallow: /pkginfo/",
"Disallow: /report/",
"Disallow: /var/",
"Disallow: /catalog/",
"Disallow: /customer/",
"Disallow: /sendfriend/",
"Disallow: /review/",
"Disallow: /*SID=",
"Disallow: /*?",
"Disallow: /checkout/",
"Disallow: /onestepcheckout/",
"Disallow: /customer/",
"Disallow: /customer/account/",
"Disallow: /customer/account/login/"
]
},
{
"id": "llms_txt",
"url": "https://abo.mittelbayerische.de/llms.txt",
"label": "llms.txt",
"reason": "http_error",
"status": "missing",
"body_size": 0,
"truncated": false,
"body_sha256": "",
"duration_ms": 1138,
"http_status": 404,
"relevant_lines": []
},
{
"id": "ai_txt",
"url": "https://abo.mittelbayerische.de/.well-known/ai.txt",
"label": "AI Policy",
"reason": "http_error",
"status": "missing",
"body_size": 0,
"truncated": false,
"body_sha256": "",
"duration_ms": 1988,
"http_status": 404,
"relevant_lines": []
},
{
"id": "ai_policy_txt",
"url": "https://abo.mittelbayerische.de/.well-known/ai-policy.txt",
"label": "AI Policy",
"reason": "http_error",
"status": "missing",
"body_size": 0,
"truncated": false,
"body_sha256": "",
"duration_ms": 2267,
"http_status": 404,
"relevant_lines": []
},
{
"id": "ward_txt",
"url": "https://abo.mittelbayerische.de/.well-known/ward.txt",
"label": "WARD Policy",
"reason": "http_error",
"status": "missing",
"body_size": 0,
"truncated": false,
"body_sha256": "",
"duration_ms": 2579,
"http_status": 404,
"relevant_lines": []
}
],
"origin": "https://abo.mittelbayerische.de",
"schema": "https://saferpage.de/schemas/ai-search-policy-evidence.v1",
"status": "checked",
"metrics": {
"file_count": 5,
"found_file_count": 1,
"policy_file_count": 0,
"explicit_ai_bot_count": 5
},
"summary": "1 von 5 Policy-Datei(en) gefunden; 5 explizite KI-Bot-Regel(n) in robots.txt.",
"available": true,
"guardrails": [
"Nur feste Same-Origin-Policy-Dateien",
"Keine Off-Host-Redirects",
"64-KB-Body-Limit",
"Öffentlich nur Hash, Status und kurze relevante Zeilen"
],
"known_ai_bots": [
"GPTBot",
"ChatGPT-User",
"Google-Extended",
"ClaudeBot",
"PerplexityBot",
"CCBot"
],
"explicit_ai_bots": [
"GPTBot",
"ChatGPT-User",
"Google-Extended",
"PerplexityBot",
"CCBot"
],
"policy_file_count": 0,
"llms_ward_policy_status": "not_publicly_verified",
"robots_ai_policy_status": "explicit_ai_bot_policy"
},
"adtech_transparency_evidence": {
"files": [
{
"id": "ads_txt",
"url": "https://abo.mittelbayerische.de/ads.txt",
"label": "ads.txt",
"reason": "http_error",
"status": "missing",
"body_size": 0,
"truncated": false,
"body_sha256": "",
"duration_ms": 597,
"http_status": 404,
"ads_txt_policy": [],
"relevant_lines": [],
"sellers_json_policy": []
},
{
"id": "app_ads_txt",
"url": "https://abo.mittelbayerische.de/app-ads.txt",
"label": "app-ads.txt",
"reason": "http_error",
"status": "missing",
"body_size": 0,
"truncated": false,
"body_sha256": "",
"duration_ms": 1170,
"http_status": 404,
"ads_txt_policy": [],
"relevant_lines": [],
"sellers_json_policy": []
},
{
"id": "sellers_json",
"url": "https://abo.mittelbayerische.de/sellers.json",
"label": "sellers.json",
"reason": "http_error",
"status": "missing",
"body_size": 0,
"truncated": false,
"body_sha256": "",
"duration_ms": 2196,
"http_status": 404,
"ads_txt_policy": [],
"relevant_lines": [],
"sellers_json_policy": []
}
],
"origin": "https://abo.mittelbayerische.de",
"schema": "https://saferpage.de/schemas/adtech-transparency-evidence.v1",
"status": "checked",
"metrics": {
"file_count": 3,
"direct_count": 0,
"reseller_count": 0,
"found_file_count": 0,
"ads_txt_entry_count": 0,
"exchange_domain_count": 0,
"app_ads_txt_entry_count": 0,
"sellers_json_seller_count": 0
},
"summary": "0 von 3 AdTech-Transparenzdatei(en) gefunden; 0 DIRECT- und 0 RESELLER-Zeile(n).",
"available": true,
"guardrails": [
"Nur feste Same-Origin-AdTech-Dateien",
"Keine Off-Host-Redirects",
"64-KB-Body-Limit",
"Öffentlich nur Hash, Status, Zähler und kurze relevante Zeilen"
],
"direct_count": 0,
"ads_txt_found": false,
"reseller_count": 0,
"app_ads_txt_found": false,
"sellers_json_found": false,
"ads_txt_entry_count": 0,
"exchange_domain_count": 0,
"sellers_json_parse_ok": false,
"app_ads_txt_entry_count": 0,
"sellers_json_seller_count": 0
},
"security_trust_policy_evidence": {
"files": [
{
"id": "security_txt",
"url": "https://abo.mittelbayerische.de/.well-known/security.txt",
"label": "security.txt",
"reason": "http_error",
"status": "missing",
"body_size": 0,
"truncated": false,
"body_sha256": "",
"duration_ms": 1000,
"http_status": 404,
"relevant_lines": [],
"security_txt_policy": []
},
{
"id": "security_txt_legacy",
"url": "https://abo.mittelbayerische.de/security.txt",
"label": "security.txt legacy",
"reason": "http_error",
"status": "missing",
"body_size": 0,
"truncated": false,
"body_sha256": "",
"duration_ms": 1316,
"http_status": 404,
"relevant_lines": [],
"security_txt_policy": []
}
],
"origin": "https://abo.mittelbayerische.de",
"schema": "https://saferpage.de/schemas/security-trust-policy-evidence.v1",
"status": "checked",
"metrics": {
"file_count": 2,
"field_count": 0,
"contact_count": 0,
"found_file_count": 0,
"preferred_well_known_found": 0
},
"summary": "0 von 2 security.txt-Ziel(en) gefunden; 0 Kontaktfeld(er), 0 strukturierte Feld(er).",
"available": true,
"guardrails": [
"Nur feste Same-Origin-security.txt-Ziele",
"Keine Off-Host-Redirects",
"64-KB-Body-Limit",
"Öffentlich nur Hash, Status und kurze relevante Zeilen"
],
"field_count": 0,
"contact_count": 0,
"fields_present": [],
"policy_present": false,
"expires_present": false,
"encryption_present": false,
"security_txt_found": false,
"preferred_well_known_found": false
}
},
"findings": [
{
"id": "pre_consent_tracking_cookies",
"title": "Tracking-Cookies vor Einwilligung gesetzt",
"public": true,
"source": "chromium_cookie_inventory",
"cookies": [
"_pk_id.4.12ad",
"_pk_ses.4.12ad"
],
"audience": "nutzer",
"category": "privacy",
"severity": "warning",
"evidence_items": [
"_pk_id.4.12ad",
"_pk_ses.4.12ad"
],
"user_importance": 128,
"importance_label": "Wichtig für Nutzer"
},
{
"id": "long_lived_tracking_cookie",
"count": 1,
"title": "Langlebige Tracking-/Marketing-Cookies",
"public": true,
"audience": "nutzer",
"category": "privacy",
"severity": "warning",
"evidence_items": [
"1 im Scan gezählt"
],
"user_importance": 122,
"importance_label": "Wichtig für Nutzer"
},
{
"id": "consent_no_reject_option",
"title": "Cookie-Hinweis ohne klare Ablehnen-Option",
"public": true,
"audience": "nutzer",
"category": "privacy",
"severity": "warning",
"evidence_items": [
"Sichtbare Banner-Controls: Akzeptieren 0, Ablehnen 0, Einstellungen 0"
],
"user_importance": 121,
"importance_label": "Wichtig für Nutzer"
},
{
"id": "tracking_pixel_detected",
"count": 1,
"title": "Tracking-Pixel oder pixelnahe Requests erkannt",
"public": true,
"audience": "nutzer",
"category": "privacy",
"severity": "warning",
"evidence_items": [
"abo.mittelbayerische.de",
"pnpabo.matomo.cloud",
"d2wu036mkcz52n.cloudfront.net"
],
"user_importance": 119,
"importance_label": "Wichtig für Nutzer"
},
{
"id": "third_party_page_url_parameter",
"count": 3,
"title": "Seiten-URL wird in Drittanbieter-Requests übertragen",
"public": true,
"audience": "nutzer",
"category": "privacy",
"severity": "warning",
"evidence_items": [
"pnpabo.matomo.cloud",
"d2wu036mkcz52n.cloudfront.net"
],
"user_importance": 118,
"importance_label": "Wichtig für Nutzer"
},
{
"id": "pii_tracking_on_data_entry_page",
"title": "Dateneingabe und datenschutzrelevante Drittanbieter im selben Browseraufruf",
"public": true,
"audience": "nutzer",
"category": "privacy",
"severity": "warning",
"evidence_items": [
"Tracking-Signale auf einer Seite mit Dateneingabe/Formular erkannt"
],
"user_importance": 118,
"importance_label": "Wichtig für Nutzer",
"third_party_count": 2
},
{
"id": "gpc_privacy_domains_present",
"count": 2,
"title": "Datenschutzrelevante Kontakte trotz GPC-Signal",
"public": true,
"audience": "nutzer",
"category": "privacy",
"severity": "info",
"evidence_items": [
"Trotz GPC: 2 Datenschutz-Domain(s), 0 Drittanbieter-Cookie(s)"
],
"user_importance": 116,
"importance_label": "Wichtig für Nutzer"
},
{
"id": "beacon_api_usage",
"count": 2,
"title": "Beacon-/Keepalive-Telemetrie erkannt",
"public": true,
"audience": "nutzer",
"category": "privacy",
"severity": "warning",
"evidence_items": [
"Beacon-/Keepalive-Telemetrie im Browser-Lauf erkannt"
],
"user_importance": 116,
"importance_label": "Wichtig für Nutzer"
},
{
"id": "privacy_policy_provider_disclosure_gap",
"title": "Erkannte Anbieter fehlen in der Datenschutzerklärung",
"public": true,
"audience": "nutzer",
"category": "privacy",
"severity": "warning",
"evidence_items": [
"Erkannte Anbieter sind nicht alle in der Datenschutzerklärung erwähnt"
],
"user_importance": 116,
"importance_label": "Wichtig für Nutzer",
"missing_providers": [
"Matomo"
]
},
{
"id": "operator_identity_unclear",
"title": "Betreiberidentität wirkt unklar",
"public": true,
"audience": "nutzer",
"category": "privacy",
"severity": "info",
"evidence_items": [
"Betreiberangaben im geprüften HTML uneindeutig oder unvollständig"
],
"user_importance": 114,
"importance_label": "Wichtig für Nutzer"
},
{
"id": "consent_state_gpc_evidence_review",
"title": "Consent-Zustand: GPC mit Tracking-Hinweisen",
"public": true,
"audience": "nutzer",
"category": "privacy",
"severity": "info",
"evidence_items": [
"GPC-Signal (Global Privacy Control) gesetzt – tatsächliche Wirkung manuell prüfen"
],
"user_importance": 112,
"importance_label": "Wichtig für Nutzer"
},
{
"id": "browser_keystroke_listener_signals",
"count": 36,
"title": "Viele Tastatur-/Eingabe-Listener im Browser erkannt",
"public": true,
"audience": "nutzer",
"category": "privacy",
"severity": "info",
"evidence_items": [
"Tastatur-Eingabe-Listener (Session-Replay-nah) im Browser-Lauf erkannt"
],
"user_importance": 110,
"importance_label": "Wichtig für Nutzer"
},
{
"id": "pii_sensitive_link_query",
"links": [
{
"href": "https://sso.pnp.de/OAuthLogin.php",
"params": [
"client_id"
],
"external": true
},
{
"href": "https://sso.pnp.de/OAuthLogin.php",
"params": [
"client_id"
],
"external": true
}
],
"title": "Links mit sensiblen Query-Parametern erkannt",
"public": true,
"audience": "nutzer",
"category": "privacy",
"severity": "info",
"evidence_items": [
"pnpabo.matomo.cloud",
"d2wu036mkcz52n.cloudfront.net"
],
"user_importance": 108,
"importance_label": "Wichtig für Nutzer"
},
{
"id": "csp_unsafe_inline",
"title": "CSP erlaubt unsafe-inline für Skripte",
"public": true,
"audience": "nutzer",
"category": "security_headers",
"severity": "warning",
"user_importance": 96,
"importance_label": "Wichtig für Nutzer"
},
{
"id": "csp_unsafe_eval",
"title": "CSP erlaubt eval-nahe Skriptausführung",
"public": true,
"audience": "nutzer",
"category": "security_headers",
"severity": "warning",
"user_importance": 94,
"importance_label": "Wichtig für Nutzer"
},
{
"id": "csp_permissive_script_sources",
"title": "CSP erlaubt sehr breite Skriptquellen",
"public": true,
"sources": [
"*.adobe.com",
"*.newrelic.com",
"*.nr-data.net",
"*.vimeocdn.com",
"*.youtube.com",
"*.avada.io",
"*.shopify.com",
"*.paypal.com"
],
"audience": "nutzer",
"category": "security_headers",
"severity": "info",
"user_importance": 88,
"importance_label": "Wichtig für Nutzer"
},
{
"id": "important_pages_not_discovered",
"title": "Wichtige Betreiberseiten nicht vollständig in der Linkstruktur gefunden",
"public": true,
"audience": "nutzer",
"category": "crawl",
"severity": "warning",
"evidence_items": [
"Wichtige Seiten in der Linkstruktur gefunden: keine"
],
"user_importance": 88,
"importance_label": "Wichtig für Nutzer"
},
{
"id": "external_script_without_sri",
"count": 1,
"title": "Externe Skripte ohne Subresource Integrity",
"public": true,
"audience": "nutzer",
"category": "security_headers",
"severity": "info",
"evidence_items": [
"https://cdn.opencmp.net/tcf-v2/cmp-stub-latest.js"
],
"user_importance": 84,
"importance_label": "Wichtig für Nutzer"
},
{
"id": "missing_meta_description",
"title": "Meta-Description fehlt",
"public": true,
"audience": "nutzer",
"category": "content",
"severity": "info",
"evidence_items": [
"Im HTML kein <meta name=\"description\"> gefunden"
],
"user_importance": 84,
"importance_label": "Wichtig für Nutzer"
},
{
"id": "tcf_decoder_tc_string_missing",
"title": "TCF-Decoder: TC-String fehlt",
"public": true,
"audience": "nutzer",
"category": "privacy",
"severity": "info",
"user_importance": 82,
"importance_label": "Wichtig für Nutzer"
},
{
"id": "cmp_tcf_string_missing",
"title": "TCF-API ohne sichtbaren TC-String",
"public": true,
"audience": "nutzer",
"category": "privacy",
"severity": "info",
"user_importance": 82,
"importance_label": "Wichtig für Nutzer"
},
{
"id": "image_alt_missing",
"count": 6,
"title": "Bilder ohne Alternativtext",
"public": true,
"audience": "nutzer",
"category": "accessibility",
"severity": "info",
"evidence_items": [
"https://abo.mittelbayerische.de/media/.renditions/wysiwyg/home/MZ/MZ_iMac_iPad_iPhone_1200x673.png",
"https://abo.mittelbayerische.de/media/.renditions/wysiwyg/home/MZ/MZ_3_Zeitungen_gefaltet_1200_x_673pix.png",
"https://abo.mittelbayerische.de/media/.renditions/wysiwyg/home/teaser-support-image.png",
"https://abo.mittelbayerische.de/media/wysiwyg/home/phone.svg",
"https://abo.mittelbayerische.de/media/wysiwyg/home/mail.svg",
"https://abo.mittelbayerische.de/media/wysiwyg/home/faq.svg"
],
"user_importance": 82,
"importance_label": "Wichtig für Nutzer"
},
{
"id": "missing_hsts",
"title": "HSTS fehlt",
"public": true,
"audience": "betreiber",
"category": "security_headers",
"severity": "warning",
"evidence_items": [
"HTTP-Header „Strict-Transport-Security\" fehlt in der Antwort der Startseite"
],
"user_importance": 78,
"importance_label": "Technischer Hinweis"
},
{
"id": "csp_report_only_only",
"title": "CSP nur im Report-Only-Modus",
"public": true,
"audience": "betreiber",
"category": "security_headers",
"severity": "info",
"user_importance": 74,
"importance_label": "Technischer Hinweis"
},
{
"id": "missing_csp",
"title": "Content-Security-Policy fehlt",
"public": true,
"audience": "betreiber",
"category": "security_headers",
"severity": "warning",
"evidence_items": [
"HTTP-Header „Content-Security-Policy\" fehlt in der Antwort der Startseite"
],
"user_importance": 72,
"importance_label": "Technischer Hinweis"
},
{
"id": "missing_cross_origin_embedder_policy",
"title": "Cross-Origin-Embedder-Policy fehlt",
"public": true,
"audience": "betreiber",
"category": "security_headers",
"severity": "info",
"evidence_items": [
"HTTP-Header „Cross-Origin-Embedder-Policy\" fehlt in der Antwort der Startseite"
],
"user_importance": 68,
"importance_label": "Technischer Hinweis"
},
{
"id": "missing_cross_origin_opener_policy",
"title": "Cross-Origin-Opener-Policy fehlt",
"public": true,
"audience": "betreiber",
"category": "security_headers",
"severity": "info",
"evidence_items": [
"HTTP-Header „Cross-Origin-Opener-Policy\" fehlt in der Antwort der Startseite"
],
"user_importance": 66,
"importance_label": "Technischer Hinweis"
},
{
"id": "missing_cross_origin_resource_policy",
"title": "Cross-Origin-Resource-Policy fehlt",
"public": true,
"audience": "betreiber",
"category": "security_headers",
"severity": "info",
"evidence_items": [
"HTTP-Header „Cross-Origin-Resource-Policy\" fehlt in der Antwort der Startseite"
],
"user_importance": 64,
"importance_label": "Technischer Hinweis"
},
{
"id": "browser_privacy_relevant_third_parties",
"title": "Datenschutzrelevante Drittanbieter im Browseraufruf",
"public": true,
"audience": "betreiber",
"category": "privacy",
"severity": "warning",
"evidence_items": [
"cdn.matomo.cloud",
"pnpabo.matomo.cloud"
],
"user_importance": 60,
"importance_label": "Technischer Hinweis"
},
{
"id": "consent_banner_dark_pattern_risk",
"count": 1,
"title": "Consent-Banner mit Dark-Pattern-/UX-Risiko",
"public": true,
"audience": "betreiber",
"category": "privacy",
"severity": "warning",
"evidence_items": [
"Banner-UX: Akzeptieren 0 vs. Ablehnen 0 – Ablehnen weniger prominent/gleichwertig"
],
"user_importance": 60,
"importance_label": "Technischer Hinweis"
},
{
"id": "missing_referrer_policy",
"title": "Referrer-Policy fehlt",
"public": true,
"audience": "betreiber",
"category": "security_headers",
"severity": "info",
"evidence_items": [
"HTTP-Header „Referrer-Policy\" fehlt in der Antwort der Startseite"
],
"user_importance": 40,
"importance_label": "Technischer Hinweis"
},
{
"id": "missing_permissions_policy",
"title": "Permissions-Policy fehlt",
"public": true,
"audience": "betreiber",
"category": "security_headers",
"severity": "info",
"evidence_items": [
"HTTP-Header „Permissions-Policy\" fehlt in der Antwort der Startseite"
],
"user_importance": 40,
"importance_label": "Technischer Hinweis"
},
{
"id": "many_browser_third_parties",
"title": "Viele Drittanbieter-Domains beim Laden",
"public": true,
"audience": "betreiber",
"category": "privacy",
"severity": "info",
"evidence_items": [
"cdn.matomo.cloud",
"pnpabo.matomo.cloud"
],
"user_importance": 30,
"importance_label": "Technischer Hinweis"
},
{
"id": "unknown_vendor_jurisdiction",
"title": "Anbieter-Jurisdiktion nicht klar ableitbar",
"public": true,
"audience": "betreiber",
"category": "privacy",
"severity": "info",
"evidence_items": [
"cdn.matomo.cloud",
"pnpabo.matomo.cloud"
],
"user_importance": 30,
"importance_label": "Technischer Hinweis"
}
],
"audit_modules": [
{
"id": "browser_evidence",
"color": "red",
"score": 0,
"title": "Browser-Nachweis",
"source": "Headless Chromium mit Screenshot- und Request-Telemetrie",
"status": "kritisch",
"evidence": "275 Request(s), 8 Drittanbieter-Domain(s), davon 2 datenschutzrelevant, 13 Browser-Cookie(s), Transfer-Prüfbedarf: 0, Referrer-/URL-Leaks: 2, Fingerprinting-/Replay-Hinweise: 1."
},
{
"id": "privacy_consent",
"color": "red",
"score": 16,
"title": "Datenschutz, Cookies & Consent",
"source": "Browser, HTTP-Header, HTML und Consent-/Cookie-Heuristik",
"status": "kritisch",
"evidence": "0 Tracking-Script(s), 13 Cookie(s) vor Einwilligung, 2 Tracking-Cookie(s), Ablehnen-Option: nein, Consent-Audit: 16."
},
{
"id": "security_tls",
"color": "red",
"score": 34,
"title": "Sicherheit, TLS & Header",
"source": "DNS, TLS, HTTP-Status, Zertifikat und Security-Header",
"status": "kritisch",
"evidence": "1 Infrastruktur-Hinweis(e), Security-Header: 2/9 vorhanden, 7 fehlen, externe Skript-Hosts: 1."
},
{
"id": "cookie_inventory",
"color": "orange",
"score": 60,
"title": "Cookie-Inventar",
"source": "HTTP-Set-Cookie und Chromium-Cookies beim ersten Seitenaufruf",
"status": "auffällig",
"evidence": "13 Cookie(s), 2 Tracking-/Werbe-Cookie(s), 0 Drittanbieter-Cookie(s), 1 langlebig, 0 sehr lang."
},
{
"id": "site_coverage",
"color": "orange",
"score": 63,
"title": "Seitenabdeckung & Crawl",
"source": "Startseiten-Links, Compliance-Links und begrenzter interner Zusatzabruf",
"status": "auffällig",
"evidence": "17 interne Linkziele erkannt, 4 priorisierte Unterseite(n) abgerufen."
},
{
"id": "referrer_url_leaks",
"color": "orange",
"score": 65,
"title": "Referrer & URL-Leaks",
"source": "Chromium-Request-Telemetrie ohne gespeicherte Parameterwerte",
"status": "auffällig",
"evidence": "2 Drittanbieter-Domain(s) mit Referrer-/URL-Leak-Prüfbedarf, 0 sensible Query-Kontexte."
},
{
"id": "tracking_pixels_beacons",
"color": "orange",
"score": 66,
"title": "Tracking-Pixel & Beacons",
"source": "HTML-Pixel, Link-Ping-Attribute, Chromium-Requests und Browser-API-Instrumentierung",
"status": "auffällig",
"evidence": "1 Pixel-/Bildtracking-Hinweis(e), 2 Beacon-/Telemetry-Hinweis(e), 0 Link-Ping(s)."
},
{
"id": "forms_payments",
"color": "orange",
"score": 74,
"title": "Formulare, Login & Zahlung",
"source": "HTML-Formulare, Eingabefelder, Zahlungsanbieter und Kontextlinks",
"status": "auffällig",
"evidence": "Aus diesem Rohfeld wird im Report keine zusätzliche Scan-Feststellung abgeleitet; Betreiberkontext und Umsetzungshinweise stehen auf separaten Seiten."
},
{
"id": "pii_exposure",
"color": "orange",
"score": 74,
"title": "PII, URL-Parameter & Datenleck-Schutz",
"source": "URL-Parameter, interne Links, HTML-Formulare, Browser-Drittanbieter und Dateneingabe-Kontext",
"status": "auffällig",
"evidence": "2 PII-/Datenleck-Hinweis(e) aus URL-, Formular- und Browserkontext."
},
{
"id": "accessibility_usability",
"color": "yellow",
"score": 76,
"title": "Barrierefreiheit & Usability",
"source": "Passives HTML-Sample: Bilder, Formulare, Buttons, Sprache, Headings und Viewport",
"status": "prüfen",
"evidence": "6 Bild(er) ohne alt, 0 Formularfeld(er) ohne Beschriftung, 0 Button(s) ohne Namen."
},
{
"id": "google_third_parties",
"color": "green",
"score": 100,
"title": "Google-Dienste & Drittanbieter",
"source": "Chromium-Requests, Anbieterklassifikation und Google Consent Mode Heuristik",
"status": "unauffällig",
"evidence": "Keine Google-Domain, keine Google-Tracking-ID und keine datenschutzrelevanten Drittanbieter im passiven Check erkannt."
},
{
"id": "consent_journey",
"color": "yellow",
"score": 84,
"title": "Consent-Journey-Matrix",
"source": "Chromium-Zustände: Erstaufruf, Reject, Accept und GPC",
"status": "prüfen",
"evidence": "Consent-Journey: 0 neue Datenschutz-Domain(s) nach Ablehnen, 0 nach Akzeptieren, 2 im GPC-Aufruf."
},
{
"id": "operator_transparency",
"color": "yellow",
"score": 85,
"title": "Impressum, Kontakt & Datenschutzerklärung",
"source": "Deutschsprachige Betreiber- und Datenschutzhinweis-Erkennung",
"status": "prüfen",
"evidence": "Impressum: ja, Datenschutz: ja, Kontakt: ja."
},
{
"id": "script_supply_chain",
"color": "green",
"score": 96,
"title": "Externe Skripte & SRI",
"source": "HTML-Script-Tags, Anbieterklassifikation und SRI-Attribute",
"status": "unauffällig",
"evidence": "1 externe Skript(e) von 1 Host(s), 1 ohne SRI, 0 Tracking-/Tag-nahe Skript(e)."
},
{
"id": "embedded_content",
"color": "green",
"score": 100,
"title": "Externe Inhalte & Widgets",
"source": "HTML-Embeds und Chromium-Drittanbieter-Requests",
"status": "unauffällig",
"evidence": "0 externe Embed-/Widget-Dienst(e), 0 davon im ersten Browseraufruf geladen."
},
{
"id": "performance_mobile",
"color": "green",
"score": 100,
"title": "Performance & mobile Nutzbarkeit",
"source": "HTTP-Antwort, HTML-Größe, Komprimierung und mobile Basis",
"status": "unauffällig",
"evidence": "Performance-Score 100, Antwortzeit 1086 ms."
},
{
"id": "seo_integrity",
"color": "green",
"score": 100,
"title": "SEO-Integrität & Cloaking",
"source": "HTML-Inhalt, strukturierte Daten, Links und Googlebot-Vergleich",
"status": "unauffällig",
"evidence": "0 SEO-Spam-Hinweis(e), 0 Cloaking-Hinweis(e)."
}
],
"ai_search_policy_evidence": {
"files": [
{
"id": "robots_txt",
"url": "https://abo.mittelbayerische.de/robots.txt",
"label": "robots.txt",
"reason": "",
"status": "found",
"body_size": 2404,
"truncated": false,
"body_sha256": "88540bb2818f55ad7363901ddb9b2db795bd4e6d6bd02ff16319225606277f1a",
"duration_ms": 559,
"http_status": 200,
"ai_bot_policy": {
"bot_directives": {
"CCBot": [
{
"value": "/",
"directive": "disallow"
}
],
"GPTBot": [
{
"value": "/",
"directive": "disallow"
}
],
"ChatGPT-User": [
{
"value": "/",
"directive": "disallow"
}
],
"PerplexityBot": [
{
"value": "/",
"directive": "disallow"
}
],
"Google-Extended": [
{
"value": "/",
"directive": "disallow"
}
]
},
"explicit_ai_bots": [
"GPTBot",
"ChatGPT-User",
"Google-Extended",
"PerplexityBot",
"CCBot"
],
"explicit_ai_bot_count": 5,
"wildcard_directive_count": 0,
"wildcard_directives_sample": []
},
"relevant_lines": [
"Disallow: /lib/",
"Disallow: /*.php$",
"Disallow: /pkginfo/",
"Disallow: /report/",
"Disallow: /var/",
"Disallow: /catalog/",
"Disallow: /customer/",
"Disallow: /sendfriend/",
"Disallow: /review/",
"Disallow: /*SID=",
"Disallow: /*?",
"Disallow: /checkout/",
"Disallow: /onestepcheckout/",
"Disallow: /customer/",
"Disallow: /customer/account/",
"Disallow: /customer/account/login/"
]
},
{
"id": "llms_txt",
"url": "https://abo.mittelbayerische.de/llms.txt",
"label": "llms.txt",
"reason": "http_error",
"status": "missing",
"body_size": 0,
"truncated": false,
"body_sha256": "",
"duration_ms": 1138,
"http_status": 404,
"relevant_lines": []
},
{
"id": "ai_txt",
"url": "https://abo.mittelbayerische.de/.well-known/ai.txt",
"label": "AI Policy",
"reason": "http_error",
"status": "missing",
"body_size": 0,
"truncated": false,
"body_sha256": "",
"duration_ms": 1988,
"http_status": 404,
"relevant_lines": []
},
{
"id": "ai_policy_txt",
"url": "https://abo.mittelbayerische.de/.well-known/ai-policy.txt",
"label": "AI Policy",
"reason": "http_error",
"status": "missing",
"body_size": 0,
"truncated": false,
"body_sha256": "",
"duration_ms": 2267,
"http_status": 404,
"relevant_lines": []
},
{
"id": "ward_txt",
"url": "https://abo.mittelbayerische.de/.well-known/ward.txt",
"label": "WARD Policy",
"reason": "http_error",
"status": "missing",
"body_size": 0,
"truncated": false,
"body_sha256": "",
"duration_ms": 2579,
"http_status": 404,
"relevant_lines": []
}
],
"origin": "https://abo.mittelbayerische.de",
"schema": "https://saferpage.de/schemas/ai-search-policy-evidence.v1",
"status": "checked",
"metrics": {
"file_count": 5,
"found_file_count": 1,
"policy_file_count": 0,
"explicit_ai_bot_count": 5
},
"summary": "1 von 5 Policy-Datei(en) gefunden; 5 explizite KI-Bot-Regel(n) in robots.txt.",
"available": true,
"guardrails": [
"Nur feste Same-Origin-Policy-Dateien",
"Keine Off-Host-Redirects",
"64-KB-Body-Limit",
"Öffentlich nur Hash, Status und kurze relevante Zeilen"
],
"known_ai_bots": [
"GPTBot",
"ChatGPT-User",
"Google-Extended",
"ClaudeBot",
"PerplexityBot",
"CCBot"
],
"explicit_ai_bots": [
"GPTBot",
"ChatGPT-User",
"Google-Extended",
"PerplexityBot",
"CCBot"
],
"policy_file_count": 0,
"llms_ward_policy_status": "not_publicly_verified",
"robots_ai_policy_status": "explicit_ai_bot_policy"
},
"adtech_transparency_evidence": {
"files": [
{
"id": "ads_txt",
"url": "https://abo.mittelbayerische.de/ads.txt",
"label": "ads.txt",
"reason": "http_error",
"status": "missing",
"body_size": 0,
"truncated": false,
"body_sha256": "",
"duration_ms": 597,
"http_status": 404,
"ads_txt_policy": [],
"relevant_lines": [],
"sellers_json_policy": []
},
{
"id": "app_ads_txt",
"url": "https://abo.mittelbayerische.de/app-ads.txt",
"label": "app-ads.txt",
"reason": "http_error",
"status": "missing",
"body_size": 0,
"truncated": false,
"body_sha256": "",
"duration_ms": 1170,
"http_status": 404,
"ads_txt_policy": [],
"relevant_lines": [],
"sellers_json_policy": []
},
{
"id": "sellers_json",
"url": "https://abo.mittelbayerische.de/sellers.json",
"label": "sellers.json",
"reason": "http_error",
"status": "missing",
"body_size": 0,
"truncated": false,
"body_sha256": "",
"duration_ms": 2196,
"http_status": 404,
"ads_txt_policy": [],
"relevant_lines": [],
"sellers_json_policy": []
}
],
"origin": "https://abo.mittelbayerische.de",
"schema": "https://saferpage.de/schemas/adtech-transparency-evidence.v1",
"status": "checked",
"metrics": {
"file_count": 3,
"direct_count": 0,
"reseller_count": 0,
"found_file_count": 0,
"ads_txt_entry_count": 0,
"exchange_domain_count": 0,
"app_ads_txt_entry_count": 0,
"sellers_json_seller_count": 0
},
"summary": "0 von 3 AdTech-Transparenzdatei(en) gefunden; 0 DIRECT- und 0 RESELLER-Zeile(n).",
"available": true,
"guardrails": [
"Nur feste Same-Origin-AdTech-Dateien",
"Keine Off-Host-Redirects",
"64-KB-Body-Limit",
"Öffentlich nur Hash, Status, Zähler und kurze relevante Zeilen"
],
"direct_count": 0,
"ads_txt_found": false,
"reseller_count": 0,
"app_ads_txt_found": false,
"sellers_json_found": false,
"ads_txt_entry_count": 0,
"exchange_domain_count": 0,
"sellers_json_parse_ok": false,
"app_ads_txt_entry_count": 0,
"sellers_json_seller_count": 0
},
"security_trust_policy_evidence": {
"files": [
{
"id": "security_txt",
"url": "https://abo.mittelbayerische.de/.well-known/security.txt",
"label": "security.txt",
"reason": "http_error",
"status": "missing",
"body_size": 0,
"truncated": false,
"body_sha256": "",
"duration_ms": 1000,
"http_status": 404,
"relevant_lines": [],
"security_txt_policy": []
},
{
"id": "security_txt_legacy",
"url": "https://abo.mittelbayerische.de/security.txt",
"label": "security.txt legacy",
"reason": "http_error",
"status": "missing",
"body_size": 0,
"truncated": false,
"body_sha256": "",
"duration_ms": 1316,
"http_status": 404,
"relevant_lines": [],
"security_txt_policy": []
}
],
"origin": "https://abo.mittelbayerische.de",
"schema": "https://saferpage.de/schemas/security-trust-policy-evidence.v1",
"status": "checked",
"metrics": {
"file_count": 2,
"field_count": 0,
"contact_count": 0,
"found_file_count": 0,
"preferred_well_known_found": 0
},
"summary": "0 von 2 security.txt-Ziel(en) gefunden; 0 Kontaktfeld(er), 0 strukturierte Feld(er).",
"available": true,
"guardrails": [
"Nur feste Same-Origin-security.txt-Ziele",
"Keine Off-Host-Redirects",
"64-KB-Body-Limit",
"Öffentlich nur Hash, Status und kurze relevante Zeilen"
],
"field_count": 0,
"contact_count": 0,
"fields_present": [],
"policy_present": false,
"expires_present": false,
"encryption_present": false,
"security_txt_found": false,
"preferred_well_known_found": false
},
"site_coverage_analysis": {
"color": "orange",
"pages": [
{
"url": "https://abo.mittelbayerische.de/customer/account",
"path": "/customer/account",
"text": "Mein Konto",
"source": "homepage_link",
"category": "login",
"priority": 72
},
{
"url": "https://abo.mittelbayerische.de/checkout/cart",
"path": "/checkout/cart",
"text": "Mein Warenkorb Artikel",
"source": "homepage_link",
"category": "checkout",
"priority": 70
},
{
"url": "https://abo.mittelbayerische.de/",
"path": "/",
"text": "",
"source": "homepage_link",
"category": "newsletter",
"priority": 64
},
{
"url": "https://abo.mittelbayerische.de/abos",
"path": "/abos",
"text": "Abos",
"source": "homepage_link",
"category": "newsletter",
"priority": 64
},
{
"url": "https://abo.mittelbayerische.de/abos/aktions-abo",
"path": "/abos/aktions-abo",
"text": "Aktions-Abos",
"source": "homepage_link",
"category": "newsletter",
"priority": 64
},
{
"url": "https://abo.mittelbayerische.de/abos/digital",
"path": "/abos/digital",
"text": "Digitale Angebote",
"source": "homepage_link",
"category": "newsletter",
"priority": 64
},
{
"url": "https://abo.mittelbayerische.de/abos/gedruckt",
"path": "/abos/gedruckt",
"text": "Gedruckte Angebote",
"source": "homepage_link",
"category": "newsletter",
"priority": 64
},
{
"url": "https://abo.mittelbayerische.de/abos/geschenk-abo",
"path": "/abos/geschenk-abo",
"text": "Geschenk-Abo",
"source": "homepage_link",
"category": "newsletter",
"priority": 64
},
{
"url": "https://abo.mittelbayerische.de/e-paper-bundle-ohne-print",
"path": "/e-paper-bundle-ohne-print",
"text": "zum Angebot",
"source": "homepage_link",
"category": "newsletter",
"priority": 64
},
{
"url": "https://abo.mittelbayerische.de/epaper-bundle",
"path": "/epaper-bundle",
"text": "Bleiben Sie am Ball! Alle News zur WM und darüber hinaus – jederzeit und überall",
"source": "homepage_link",
"category": "newsletter",
"priority": 64
},
{
"url": "https://abo.mittelbayerische.de/jahresendelesen",
"path": "/jahresendelesen",
"text": "Früh starten lohnt sich Montag bis Samstag bequem im Briefkasten Jetzt bis Jahre",
"source": "homepage_link",
"category": "newsletter",
"priority": 64
},
{
"url": "https://abo.mittelbayerische.de/landingpages/bestandskunden",
"path": "/landingpages/bestandskunden",
"text": "Zu den Vorteilsangeboten",
"source": "homepage_link",
"category": "newsletter",
"priority": 64
}
],
"score": 63,
"status": "auffällig",
"summary": "17 interne Linkziele erkannt (0 aus Sitemap), 4 priorisierte Unterseite(n) zusätzlich abgerufen.",
"findings": [
{
"id": "important_pages_not_discovered",
"title": "Wichtige Betreiberseiten nicht vollständig in der Linkstruktur gefunden",
"public": true,
"category": "crawl",
"severity": "warning"
},
{
"id": "privacy_policy_provider_disclosure_gap",
"title": "Erkannte Anbieter fehlen in der Datenschutzerklärung",
"public": true,
"category": "privacy",
"severity": "warning",
"missing_providers": [
"Matomo"
]
}
],
"robots_ok": true,
"categories": {
"login": 1,
"checkout": 1,
"newsletter": 15
},
"sample_limit": 4,
"sampled_count": 4,
"sampled_pages": [
{
"ok": true,
"url": "https://abo.mittelbayerische.de/customer/account",
"path": "/customer/account",
"audit": {
"form_count": 2,
"finding_ids": [
"operator_identity_unclear",
"privacy_policy_too_thin",
"consent_no_reject_option"
],
"cookie_count": 1,
"imprint_found": true,
"consent_hint_found": true,
"reject_option_found": false,
"privacy_policy_found": true,
"tracking_script_count": 0,
"pre_consent_cookie_count": 1,
"pre_consent_tracking_cookie_count": 0
},
"forms": 2,
"title": "Kundenlogin",
"status": 200,
"category": "login",
"duration_ms": 1459,
"privacy_hint": true,
"privacy_policy_audit": []
},
{
"ok": true,
"url": "https://abo.mittelbayerische.de/checkout/cart",
"path": "/checkout/cart",
"audit": {
"form_count": 2,
"finding_ids": [
"operator_identity_unclear",
"consent_no_reject_option"
],
"cookie_count": 1,
"imprint_found": true,
"consent_hint_found": true,
"reject_option_found": false,
"privacy_policy_found": true,
"tracking_script_count": 0,
"pre_consent_cookie_count": 1,
"pre_consent_tracking_cookie_count": 0
},
"forms": 2,
"title": "Warenkorb",
"status": 200,
"category": "checkout",
"duration_ms": 784,
"privacy_hint": true,
"privacy_policy_audit": []
},
{
"ok": true,
"url": "https://abo.mittelbayerische.de/",
"path": "/",
"audit": {
"form_count": 2,
"finding_ids": [
"operator_identity_unclear",
"consent_no_reject_option"
],
"cookie_count": 1,
"imprint_found": true,
"consent_hint_found": true,
"reject_option_found": false,
"privacy_policy_found": true,
"tracking_script_count": 0,
"pre_consent_cookie_count": 1,
"pre_consent_tracking_cookie_count": 0
},
"forms": 2,
"title": "Aboshop MZ | Mittelbayerische Zeitung im Abo lesen!",
"status": 200,
"category": "newsletter",
"duration_ms": 1083,
"privacy_hint": true,
"privacy_policy_audit": []
},
{
"ok": true,
"url": "https://abo.mittelbayerische.de/abos",
"path": "/abos",
"audit": {
"form_count": 2,
"finding_ids": [
"operator_identity_unclear",
"consent_no_reject_option"
],
"cookie_count": 1,
"imprint_found": true,
"consent_hint_found": true,
"reject_option_found": false,
"privacy_policy_found": true,
"tracking_script_count": 0,
"pre_consent_cookie_count": 1,
"pre_consent_tracking_cookie_count": 0
},
"forms": 2,
"title": "Aboshop MZ | Mittelbayerische Zeitung im Abo lesen!",
"status": 200,
"category": "newsletter",
"duration_ms": 566,
"privacy_hint": true,
"privacy_policy_audit": []
}
],
"robots_checked": true,
"sitemap_sources": [],
"sitemap_available": false,
"sitemap_url_count": 0,
"homepage_link_count": 38,
"internal_link_count": 17,
"privacy_policy_audit": [],
"sitemap_source_count": 0,
"provider_disclosure_audit": {
"color": "red",
"found": [],
"score": 0,
"checks": [
{
"id": "analytics_matomo",
"found": false,
"category": "analytics",
"evidence": [
"cdn.matomo.cloud",
"pnpabo.matomo.cloud",
"_pk_id.4.12ad"
],
"keywords": [
"matomo",
"piwik"
],
"provider": "Matomo",
"category_label": "Analytics"
}
],
"reason": "no_policy_text",
"status": "kritisch",
"missing": [
"Matomo"
],
"summary": "1 technische Anbieter erkannt, aber keine Datenschutzerklärung im Sample ausgewertet.",
"available": true,
"missing_count": 1,
"detected_count": 1,
"mentioned_count": 0
},
"important_categories_found": [],
"sampled_tracking_page_count": 0,
"sampled_form_privacy_gap_count": 0,
"sitemap_candidate_source_count": 1
},
"page_analysis": {
"h1": [
"<span class=\"base\" data-ui-id=\"page-title-wrapper\" >Abos</span>"
],
"h2": [],
"title": "Aboshop MZ | Mittelbayerische Zeitung im Abo lesen!",
"keywords": [
[
"lesen",
10
],
[
"angebot",
6
],
[
"mittelbayerische",
5
],
[
"mein",
5
],
[
"zeitung",
4
],
[
"digitale",
4
],
[
"angebote",
4
],
[
"block",
4
],
[
"artikel",
4
],
[
"konto",
3
]
],
"language": "de",
"description": "",
"favicon_url": "https://abo.mittelbayerische.de/media/favicon/stores/3/favicon_mz.png",
"link_counts": {
"external": 12,
"internal": 26
},
"preview_image": "/cache/screenshots/abo.mittelbayerische.de-160x150-e3e8d325a998e4a2f8.png",
"screenshot_url": "/cache/screenshots/abo.mittelbayerische.de-160x150-e3e8d325a998e4a2f8.png",
"external_scripts": [
"https://cdn.opencmp.net/tcf-v2/cmp-stub-latest.js"
],
"browser_final_url": "https://abo.mittelbayerische.de/abos",
"meta_preview_image": "",
"screenshot_renderer": "playwright-chromium",
"external_link_targets": [
{
"host": "mittelbayerische.de",
"count": 4,
"examples": [
{
"href": "https://www.mittelbayerische.de/verlag/kundenservice",
"text": "Zum Kontakt"
},
{
"href": "https://www.mittelbayerische.de/datenschutz",
"text": "Datenschutz"
},
{
"href": "https://www.mittelbayerische.de/impressum",
"text": "Impressum"
}
],
"nofollow": 0,
"strength": "strong",
"follow_count": 4
},
{
"host": "id.mittelbayerische.de",
"count": 2,
"examples": [
{
"href": "https://id.mittelbayerische.de/kuendigung",
"text": "Kündigen"
},
{
"href": "https://id.mittelbayerische.de/kuendigung",
"text": "Abo widerrufen"
}
],
"nofollow": 0,
"strength": "strong",
"follow_count": 2
},
{
"host": "sso.pnp.de",
"count": 2,
"examples": [
{
"href": "https://sso.pnp.de/OAuthLogin.php?client_id=abo_shop&client_title=mz&response_type=code&redirect_uri=https://abo.mittelbayerische.de/rest/V1/evolver/hub&action=login&state=283e68be5180647c2e1ff6b3a7ef45ff",
"text": "Anmelden"
},
{
"href": "https://sso.pnp.de/OAuthLogin.php?client_id=abo_shop&client_title=mz&response_type=code&redirect_uri=https://abo.mittelbayerische.de/rest/V1/evolver/hub&action=login&state=283e68be5180647c2e1ff6b3a7ef45ff",
"text": "Anmelden"
}
],
"nofollow": 0,
"strength": "strong",
"follow_count": 2
},
{
"host": "support.mittelbayerische.de",
"count": 2,
"examples": [
{
"href": "https://support.mittelbayerische.de/",
"text": "Zu den FAQ's"
},
{
"href": "https://support.mittelbayerische.de/",
"text": "FAQ"
}
],
"nofollow": 0,
"strength": "strong",
"follow_count": 2
},
{
"host": "kundenservice.mittelbayerische.de",
"count": 1,
"examples": [
{
"href": "https://kundenservice.mittelbayerische.de",
"text": "Mein Abo!"
}
],
"nofollow": 0,
"strength": "strong",
"follow_count": 1
},
{
"host": "marketing.mgbayern.de",
"count": 1,
"examples": [
{
"href": "https://marketing.mgbayern.de/abo/Bezugspreise_MZ_Nov2025.pdf",
"text": "Preise"
}
],
"nofollow": 0,
"strength": "weak",
"follow_count": 1
}
]
},
"browser_analysis": {
"cookies": {
"items": [
{
"name": "PHPSESSID",
"domain": ".abo.mittelbayerische.de",
"secure": true,
"expires": 1781903160.933816,
"http_only": true,
"same_site": "Lax"
},
{
"name": "_pk_id.4.12ad",
"domain": ".mittelbayerische.de",
"secure": false,
"expires": 1815854761,
"http_only": false,
"same_site": "Lax"
},
{
"name": "_pk_ses.4.12ad",
"domain": ".mittelbayerische.de",
"secure": false,
"expires": 1781901361,
"http_only": false,
"same_site": "Lax"
},
{
"name": "form_key",
"domain": "abo.mittelbayerische.de",
"secure": true,
"expires": 1781985961,
"http_only": false,
"same_site": "Lax"
},
{
"name": "mage-cache-storage",
"domain": "abo.mittelbayerische.de",
"secure": true,
"expires": 1781903161,
"http_only": false,
"same_site": "Lax"
},
{
"name": "mage-cache-storage-section-invalidation",
"domain": "abo.mittelbayerische.de",
"secure": true,
"expires": 1781903161,
"http_only": false,
"same_site": "Lax"
},
{
"name": "mage-cache-sessid",
"domain": "abo.mittelbayerische.de",
"secure": true,
"expires": 1781903161,
"http_only": false,
"same_site": "Lax"
},
{
"name": "mage-messages",
"domain": "abo.mittelbayerische.de",
"secure": true,
"expires": 1781903161,
"http_only": false,
"same_site": "Strict"
},
{
"name": "recently_viewed_product",
"domain": "abo.mittelbayerische.de",
"secure": true,
"expires": 1781903161,
"http_only": false,
"same_site": "Lax"
},
{
"name": "recently_viewed_product_previous",
"domain": "abo.mittelbayerische.de",
"secure": true,
"expires": 1781903161,
"http_only": false,
"same_site": "Lax"
},
{
"name": "recently_compared_product",
"domain": "abo.mittelbayerische.de",
"secure": true,
"expires": 1781903161,
"http_only": false,
"same_site": "Lax"
},
{
"name": "recently_compared_product_previous",
"domain": "abo.mittelbayerische.de",
"secure": true,
"expires": 1781903161,
"http_only": false,
"same_site": "Lax"
},
{
"name": "product_data_storage",
"domain": "abo.mittelbayerische.de",
"secure": true,
"expires": 1781903161,
"http_only": false,
"same_site": "Lax"
}
],
"total": 13,
"third_party": 0
},
"storage": {
"total": 16,
"local_storage_keys": [
"recently_viewed_product",
"mage-cache-storage",
"mage-cache-storage-section-invalidation",
"recently_viewed_product_previous",
"product_data_storage",
"opencmp_a",
"mage-cache-timeout",
"recently_compared_product_previous",
"recently_compared_product"
],
"tracking_key_hints": [],
"local_storage_total": 9,
"session_storage_keys": [
"recently_viewed_product",
"mage-cache-storage",
"mage-cache-storage-section-invalidation",
"recently_viewed_product_previous",
"product_data_storage",
"recently_compared_product",
"recently_compared_product_previous"
],
"session_storage_total": 7
},
"findings": [
{
"id": "browser_privacy_relevant_third_parties",
"title": "Datenschutzrelevante Drittanbieter im Browseraufruf",
"public": true,
"category": "privacy",
"severity": "warning"
},
{
"id": "tcf_decoder_tc_string_missing",
"title": "TCF-Decoder: TC-String fehlt",
"public": true,
"category": "privacy",
"severity": "info"
},
{
"id": "cmp_tcf_string_missing",
"title": "TCF-API ohne sichtbaren TC-String",
"public": true,
"category": "privacy",
"severity": "info"
},
{
"id": "gpc_privacy_domains_present",
"count": 2,
"title": "Datenschutzrelevante Kontakte trotz GPC-Signal",
"public": true,
"category": "privacy",
"severity": "info"
},
{
"id": "many_browser_third_parties",
"title": "Viele Drittanbieter-Domains beim Laden",
"public": true,
"category": "privacy",
"severity": "info"
},
{
"id": "unknown_vendor_jurisdiction",
"title": "Anbieter-Jurisdiktion nicht klar ableitbar",
"public": true,
"category": "privacy",
"severity": "info"
},
{
"id": "third_party_page_url_parameter",
"count": 3,
"title": "Seiten-URL wird in Drittanbieter-Requests übertragen",
"public": true,
"category": "privacy",
"severity": "warning"
},
{
"id": "browser_keystroke_listener_signals",
"count": 36,
"title": "Viele Tastatur-/Eingabe-Listener im Browser erkannt",
"public": true,
"category": "privacy",
"severity": "info"
},
{
"id": "consent_state_gpc_evidence_review",
"title": "Consent-Zustand: GPC mit Tracking-Hinweisen",
"public": true,
"category": "privacy",
"severity": "info"
},
{
"id": "tracking_pixel_detected",
"count": 1,
"title": "Tracking-Pixel oder pixelnahe Requests erkannt",
"public": true,
"category": "privacy",
"severity": "warning"
},
{
"id": "beacon_api_usage",
"count": 2,
"title": "Beacon-/Keepalive-Telemetrie erkannt",
"public": true,
"category": "privacy",
"severity": "warning"
}
],
"renderer": "playwright-chromium",
"final_url": "https://abo.mittelbayerische.de/abos",
"consent_ui": {
"accept_controls": [],
"accept_max_area": 0,
"reject_controls": [],
"reject_max_area": 0,
"settings_controls": [],
"first_layer_summary": "Akzeptieren 0 / Ablehnen 0 / Einstellungen 0",
"cookie_context_found": true,
"reject_less_prominent": false,
"visible_control_count": 14,
"reject_prominence_ratio": 0
},
"gpc_signal": {
"error": "",
"enabled": true,
"storage": {
"total": 16,
"tracking_key_hints": [],
"local_storage_total": 9,
"session_storage_total": 7
},
"cookie_count": 13,
"request_count": 274,
"sec_gpc_header": true,
"navigator_value": true,
"contacted_domains": [
{
"host": "abo.mittelbayerische.de",
"count": 257,
"category": "other",
"provider": "abo.mittelbayerische.de",
"third_party": false,
"category_label": "Sonstige",
"resource_types": {
"xhr": 11,
"font": 5,
"image": 20,
"script": 217,
"document": 1,
"stylesheet": 3
}
},
{
"host": "cdn.opencmp.net",
"count": 8,
"category": "other",
"provider": "cdn.opencmp.net",
"third_party": true,
"category_label": "Sonstige",
"resource_types": {
"fetch": 5,
"script": 3
}
},
{
"host": "cdntrf.com",
"count": 2,
"category": "other",
"provider": "cdntrf.com",
"third_party": true,
"category_label": "Sonstige",
"resource_types": {
"xhr": 2
}
},
{
"host": "d2wu036mkcz52n.cloudfront.net",
"count": 2,
"category": "other",
"provider": "d2wu036mkcz52n.cloudfront.net",
"third_party": true,
"category_label": "Sonstige",
"resource_types": {
"image": 2
}
},
{
"host": "cdn.matomo.cloud",
"count": 1,
"category": "analytics",
"provider": "Matomo",
"third_party": true,
"category_label": "Analytics",
"resource_types": {
"script": 1
}
},
{
"host": "files.upscore.com",
"count": 1,
"category": "other",
"provider": "files.upscore.com",
"third_party": true,
"category_label": "Sonstige",
"resource_types": {
"script": 1
}
},
{
"host": "mbv.slgnt.eu",
"count": 1,
"category": "other",
"provider": "mbv.slgnt.eu",
"third_party": true,
"category_label": "Sonstige",
"resource_types": {
"script": 1
}
},
{
"host": "npmtecpublic.s3.eu-central-1.amazonaws.com",
"count": 1,
"category": "other",
"provider": "npmtecpublic.s3.eu-central-1.amazonaws.com",
"third_party": true,
"category_label": "Sonstige",
"resource_types": {
"image": 1
}
},
{
"host": "pnpabo.matomo.cloud",
"count": 1,
"category": "analytics",
"provider": "Matomo",
"third_party": true,
"category_label": "Analytics",
"resource_types": {
"ping": 1
}
}
],
"contacted_domain_count": 9,
"privacy_relevant_domains": [
{
"host": "cdn.matomo.cloud",
"count": 1,
"category": "analytics",
"provider": "Matomo",
"third_party": true,
"category_label": "Analytics",
"resource_types": {
"script": 1
}
},
{
"host": "pnpabo.matomo.cloud",
"count": 1,
"category": "analytics",
"provider": "Matomo",
"third_party": true,
"category_label": "Analytics",
"resource_types": {
"ping": 1
}
}
],
"third_party_cookie_count": 0,
"third_party_domain_count": 8,
"privacy_relevant_domain_count": 2
},
"screenshot": {
"fit": "contain",
"width": 160,
"height": 150,
"source_width": 1024,
"source_height": 960,
"source_capture": "full_page",
"capture_version": "contain-v4-viewport-transparency-160x150"
},
"consent_apis": {
"cmpapi": false,
"tcfapi": true,
"onetrust": false,
"cookiebot": false,
"data_layer": true,
"cmp_detected": true,
"usercentrics": false,
"google_tag_data": false
},
"accept_signal": {
"error": "",
"enabled": false,
"storage": {
"total": 0,
"tracking_key_hints": [],
"local_storage_total": 0,
"session_storage_total": 0
},
"clicked_text": "",
"accept_clicked": false,
"accept_available": false,
"contacted_domains": [],
"contacted_domain_count": 0,
"new_domains_after_accept": [],
"privacy_relevant_domains": [],
"third_party_domain_count": 0,
"cookie_count_after_accept": 0,
"cookie_count_before_accept": 0,
"request_count_after_accept": 0,
"storage_count_after_accept": 0,
"request_count_before_accept": 0,
"new_cookie_count_after_accept": 0,
"privacy_relevant_domain_count": 0,
"new_request_count_after_accept": 0,
"third_party_cookie_count_after_accept": 0,
"storage_tracking_hint_count_after_accept": 0,
"new_privacy_relevant_domains_after_accept": [],
"new_privacy_relevant_domain_count_after_accept": 0
},
"request_count": 275,
"top_providers": [
{
"provider": "cdn.opencmp.net",
"request_count": 8
},
{
"provider": "cdntrf.com",
"request_count": 2
},
{
"provider": "d2wu036mkcz52n.cloudfront.net",
"request_count": 2
},
{
"provider": "Matomo",
"request_count": 2
},
{
"provider": "files.upscore.com",
"request_count": 1
},
{
"provider": "mbv.slgnt.eu",
"request_count": 1
},
{
"provider": "npmtecpublic.s3.eu-central-1.amazonaws.com",
"request_count": 1
}
],
"request_samples": [
{
"host": "cdn.opencmp.net",
"method": "GET",
"referrer": {
"host": "abo.mittelbayerische.de",
"has_path": false,
"has_query": false,
"same_site": true,
"path_depth": 0,
"query_keys": [],
"sensitive_query_key_count": 0
},
"has_query": false,
"path_depth": 2,
"query_keys": [],
"third_party": true,
"resource_type": "script",
"query_key_count": 0,
"url_value_param_count": 0,
"sensitive_query_key_count": 0,
"target_url_value_param_count": 0
},
{
"host": "cdn.opencmp.net",
"method": "GET",
"referrer": {
"host": "abo.mittelbayerische.de",
"has_path": false,
"has_query": false,
"same_site": true,
"path_depth": 0,
"query_keys": [],
"sensitive_query_key_count": 0
},
"has_query": false,
"path_depth": 4,
"query_keys": [],
"third_party": true,
"resource_type": "script",
"query_key_count": 0,
"url_value_param_count": 0,
"sensitive_query_key_count": 0,
"target_url_value_param_count": 0
},
{
"host": "cdn.matomo.cloud",
"method": "GET",
"referrer": {
"host": "abo.mittelbayerische.de",
"has_path": false,
"has_query": false,
"same_site": true,
"path_depth": 0,
"query_keys": [],
"sensitive_query_key_count": 0
},
"has_query": false,
"path_depth": 2,
"query_keys": [],
"third_party": true,
"resource_type": "script",
"query_key_count": 0,
"url_value_param_count": 0,
"sensitive_query_key_count": 0,
"target_url_value_param_count": 0
},
{
"host": "mbv.slgnt.eu",
"method": "GET",
"referrer": {
"host": "abo.mittelbayerische.de",
"has_path": false,
"has_query": false,
"same_site": true,
"path_depth": 0,
"query_keys": [],
"sensitive_query_key_count": 0
},
"has_query": false,
"path_depth": 2,
"query_keys": [],
"third_party": true,
"resource_type": "script",
"query_key_count": 0,
"url_value_param_count": 0,
"sensitive_query_key_count": 0,
"target_url_value_param_count": 0
},
{
"host": "files.upscore.com",
"method": "GET",
"referrer": {
"host": "abo.mittelbayerische.de",
"has_path": false,
"has_query": false,
"same_site": true,
"path_depth": 0,
"query_keys": [],
"sensitive_query_key_count": 0
},
"has_query": false,
"path_depth": 2,
"query_keys": [],
"third_party": true,
"resource_type": "script",
"query_key_count": 0,
"url_value_param_count": 0,
"sensitive_query_key_count": 0,
"target_url_value_param_count": 0
},
{
"host": "pnpabo.matomo.cloud",
"method": "POST",
"referrer": {
"host": "abo.mittelbayerische.de",
"has_path": false,
"has_query": false,
"same_site": true,
"path_depth": 0,
"query_keys": [],
"sensitive_query_key_count": 0
},
"has_query": true,
"path_depth": 1,
"query_keys": [
"action_name",
"idsite",
"rec",
"r",
"h",
"m",
"s",
"url",
"_id",
"_idn",
"send_image",
"_refts"
],
"third_party": true,
"resource_type": "ping",
"query_key_count": 27,
"url_value_param_count": 1,
"sensitive_query_key_count": 0,
"target_url_value_param_count": 1
},
{
"host": "d2wu036mkcz52n.cloudfront.net",
"method": "GET",
"referrer": {
"host": "abo.mittelbayerische.de",
"has_path": false,
"has_query": false,
"same_site": true,
"path_depth": 0,
"query_keys": [],
"sensitive_query_key_count": 0
},
"has_query": true,
"path_depth": 1,
"query_keys": [
"v",
"sr",
"vp",
"cd",
"md",
"h",
"t",
"d",
"u",
"do",
"type",
"pr"
],
"third_party": true,
"resource_type": "image",
"query_key_count": 20,
"url_value_param_count": 0,
"sensitive_query_key_count": 0,
"target_url_value_param_count": 2
},
{
"host": "cdn.opencmp.net",
"method": "GET",
"referrer": {
"host": "abo.mittelbayerische.de",
"has_path": false,
"has_query": false,
"same_site": true,
"path_depth": 0,
"query_keys": [],
"sensitive_query_key_count": 0
},
"has_query": false,
"path_depth": 4,
"query_keys": [],
"third_party": true,
"resource_type": "fetch",
"query_key_count": 0,
"url_value_param_count": 0,
"sensitive_query_key_count": 0,
"target_url_value_param_count": 0
},
{
"host": "cdntrf.com",
"method": "GET",
"referrer": {
"host": "abo.mittelbayerische.de",
"has_path": false,
"has_query": false,
"same_site": true,
"path_depth": 0,
"query_keys": [],
"sensitive_query_key_count": 0
},
"has_query": false,
"path_depth": 2,
"query_keys": [],
"third_party": true,
"resource_type": "xhr",
"query_key_count": 0,
"url_value_param_count": 0,
"sensitive_query_key_count": 0,
"target_url_value_param_count": 0
},
{
"host": "cdntrf.com",
"method": "GET",
"referrer": {
"host": "abo.mittelbayerische.de",
"has_path": false,
"has_query": false,
"same_site": true,
"path_depth": 0,
"query_keys": [],
"sensitive_query_key_count": 0
},
"has_query": false,
"path_depth": 2,
"query_keys": [],
"third_party": true,
"resource_type": "xhr",
"query_key_count": 0,
"url_value_param_count": 0,
"sensitive_query_key_count": 0,
"target_url_value_param_count": 0
},
{
"host": "cdn.opencmp.net",
"method": "GET",
"referrer": {
"host": "abo.mittelbayerische.de",
"has_path": false,
"has_query": false,
"same_site": true,
"path_depth": 0,
"query_keys": [],
"sensitive_query_key_count": 0
},
"has_query": false,
"path_depth": 4,
"query_keys": [],
"third_party": true,
"resource_type": "fetch",
"query_key_count": 0,
"url_value_param_count": 0,
"sensitive_query_key_count": 0,
"target_url_value_param_count": 0
},
{
"host": "cdn.opencmp.net",
"method": "GET",
"referrer": {
"host": "abo.mittelbayerische.de",
"has_path": false,
"has_query": false,
"same_site": true,
"path_depth": 0,
"query_keys": [],
"sensitive_query_key_count": 0
},
"has_query": false,
"path_depth": 4,
"query_keys": [],
"third_party": true,
"resource_type": "fetch",
"query_key_count": 0,
"url_value_param_count": 0,
"sensitive_query_key_count": 0,
"target_url_value_param_count": 0
},
{
"host": "cdn.opencmp.net",
"method": "GET",
"referrer": {
"host": "abo.mittelbayerische.de",
"has_path": false,
"has_query": false,
"same_site": true,
"path_depth": 0,
"query_keys": [],
"sensitive_query_key_count": 0
},
"has_query": false,
"path_depth": 4,
"query_keys": [],
"third_party": true,
"resource_type": "script",
"query_key_count": 0,
"url_value_param_count": 0,
"sensitive_query_key_count": 0,
"target_url_value_param_count": 0
},
{
"host": "d2wu036mkcz52n.cloudfront.net",
"method": "GET",
"referrer": {
"host": "abo.mittelbayerische.de",
"has_path": false,
"has_query": false,
"same_site": true,
"path_depth": 0,
"query_keys": [],
"sensitive_query_key_count": 0
},
"has_query": true,
"path_depth": 1,
"query_keys": [
"v",
"sr",
"vp",
"cd",
"md",
"h",
"t",
"d",
"u",
"do",
"type",
"pr"
],
"third_party": true,
"resource_type": "image",
"query_key_count": 20,
"url_value_param_count": 0,
"sensitive_query_key_count": 0,
"target_url_value_param_count": 2
},
{
"host": "npmtecpublic.s3.eu-central-1.amazonaws.com",
"method": "GET",
"referrer": {
"host": "abo.mittelbayerische.de",
"has_path": false,
"has_query": false,
"same_site": true,
"path_depth": 0,
"query_keys": [],
"sensitive_query_key_count": 0
},
"has_query": false,
"path_depth": 3,
"query_keys": [],
"third_party": true,
"resource_type": "image",
"query_key_count": 0,
"url_value_param_count": 0,
"sensitive_query_key_count": 0,
"target_url_value_param_count": 0
},
{
"host": "cdn.opencmp.net",
"method": "GET",
"referrer": {
"host": "abo.mittelbayerische.de",
"has_path": false,
"has_query": false,
"same_site": true,
"path_depth": 0,
"query_keys": [],
"sensitive_query_key_count": 0
},
"has_query": false,
"path_depth": 4,
"query_keys": [],
"third_party": true,
"resource_type": "fetch",
"query_key_count": 0,
"url_value_param_count": 0,
"sensitive_query_key_count": 0,
"target_url_value_param_count": 0
},
{
"host": "cdn.opencmp.net",
"method": "GET",
"referrer": {
"host": "abo.mittelbayerische.de",
"has_path": false,
"has_query": false,
"same_site": true,
"path_depth": 0,
"query_keys": [],
"sensitive_query_key_count": 0
},
"has_query": false,
"path_depth": 4,
"query_keys": [],
"third_party": true,
"resource_type": "fetch",
"query_key_count": 0,
"url_value_param_count": 0,
"sensitive_query_key_count": 0,
"target_url_value_param_count": 0
}
],
"cmp_consent_state": {
"tcf": {
"api_found": true,
"vendor_li": [],
"cmp_loaded": true,
"cmp_status": "loaded",
"purpose_li": [],
"event_status": "cmpuishown",
"gdpr_applies": true,
"ping_success": true,
"policy_version": "5",
"vendor_consents": [],
"vendor_li_count": 0,
"purpose_consents": [],
"purpose_li_count": 0,
"tc_string_length": 0,
"tc_string_present": false,
"vendor_consent_count": 0,
"purpose_consent_count": 0
},
"onetrust": {
"found": false,
"active_groups": [],
"active_group_count": 0
},
"cookiebot": {
"found": false,
"declined": false,
"consented": false,
"has_response": false,
"consent_marketing": null,
"consent_statistics": null,
"consent_preferences": null
},
"usercentrics": {
"found": false,
"has_response": false,
"services_count": 0,
"accepted_services_count": 0
}
},
"contacted_domains": [
{
"host": "abo.mittelbayerische.de",
"count": 258,
"category": "other",
"provider": "abo.mittelbayerische.de",
"third_party": false,
"category_label": "Sonstige",
"resource_types": {
"xhr": 11,
"font": 5,
"image": 21,
"script": 217,
"document": 1,
"stylesheet": 3
}
},
{
"host": "cdn.opencmp.net",
"count": 8,
"category": "other",
"provider": "cdn.opencmp.net",
"third_party": true,
"category_label": "Sonstige",
"resource_types": {
"fetch": 5,
"script": 3
}
},
{
"host": "cdntrf.com",
"count": 2,
"category": "other",
"provider": "cdntrf.com",
"third_party": true,
"category_label": "Sonstige",
"resource_types": {
"xhr": 2
}
},
{
"host": "d2wu036mkcz52n.cloudfront.net",
"count": 2,
"category": "other",
"provider": "d2wu036mkcz52n.cloudfront.net",
"third_party": true,
"category_label": "Sonstige",
"resource_types": {
"image": 2
}
},
{
"host": "cdn.matomo.cloud",
"count": 1,
"category": "analytics",
"provider": "Matomo",
"third_party": true,
"category_label": "Analytics",
"resource_types": {
"script": 1
}
},
{
"host": "files.upscore.com",
"count": 1,
"category": "other",
"provider": "files.upscore.com",
"third_party": true,
"category_label": "Sonstige",
"resource_types": {
"script": 1
}
},
{
"host": "mbv.slgnt.eu",
"count": 1,
"category": "other",
"provider": "mbv.slgnt.eu",
"third_party": true,
"category_label": "Sonstige",
"resource_types": {
"script": 1
}
},
{
"host": "npmtecpublic.s3.eu-central-1.amazonaws.com",
"count": 1,
"category": "other",
"provider": "npmtecpublic.s3.eu-central-1.amazonaws.com",
"third_party": true,
"category_label": "Sonstige",
"resource_types": {
"image": 1
}
},
{
"host": "pnpabo.matomo.cloud",
"count": 1,
"category": "analytics",
"provider": "Matomo",
"third_party": true,
"category_label": "Analytics",
"resource_types": {
"ping": 1
}
}
],
"privacy_api_metrics": {
"api_calls": {
"beacon_count": 1,
"mutation_observer_count": 2,
"keyboard_input_listener_count": 36
},
"beacon_count": 1,
"webgl_read_count": 0,
"canvas_read_count": 0,
"audio_context_count": 0,
"canvas_export_count": 0,
"fetch_keepalive_count": 0,
"webgl_parameter_count": 0,
"mutation_observer_count": 2,
"keyboard_input_listener_count": 36
},
"tcf_consent_analysis": {
"color": "yellow",
"score": 82,
"status": "prüfen",
"summary": "TCF-Decoder: 0 Zweck(e) mit Consent/LI-Signal, 0 Vendor-Consent(s), 0 Vendor-LI-Signal(e).",
"findings": [
{
"id": "tcf_decoder_tc_string_missing",
"title": "TCF-Decoder: TC-String fehlt",
"public": true,
"category": "privacy",
"severity": "info"
}
],
"api_found": true,
"available": true,
"cmp_loaded": true,
"cmp_status": "loaded",
"event_status": "cmpuishown",
"gdpr_applies": true,
"ping_success": true,
"purpose_rows": [
{
"id": 1,
"label": "Informationen auf einem Gerät speichern und/oder abrufen",
"status": "nicht_erlaubt",
"risk_level": "niedrig",
"consent_granted": false,
"legitimate_interest_granted": false
},
{
"id": 2,
"label": "Einfache Anzeigen auswählen",
"status": "nicht_erlaubt",
"risk_level": "niedrig",
"consent_granted": false,
"legitimate_interest_granted": false
},
{
"id": 3,
"label": "Personalisiertes Anzeigen-Profil erstellen",
"status": "nicht_erlaubt",
"risk_level": "niedrig",
"consent_granted": false,
"legitimate_interest_granted": false
},
{
"id": 4,
"label": "Personalisierte Anzeigen auswählen",
"status": "nicht_erlaubt",
"risk_level": "niedrig",
"consent_granted": false,
"legitimate_interest_granted": false
},
{
"id": 5,
"label": "Personalisiertes Inhalts-Profil erstellen",
"status": "nicht_erlaubt",
"risk_level": "niedrig",
"consent_granted": false,
"legitimate_interest_granted": false
},
{
"id": 6,
"label": "Personalisierte Inhalte auswählen",
"status": "nicht_erlaubt",
"risk_level": "niedrig",
"consent_granted": false,
"legitimate_interest_granted": false
},
{
"id": 7,
"label": "Anzeigen-Leistung messen",
"status": "nicht_erlaubt",
"risk_level": "niedrig",
"consent_granted": false,
"legitimate_interest_granted": false
},
{
"id": 8,
"label": "Inhalte-Leistung messen",
"status": "nicht_erlaubt",
"risk_level": "niedrig",
"consent_granted": false,
"legitimate_interest_granted": false
},
{
"id": 9,
"label": "Marktforschung zur Generierung von Erkenntnissen nutzen",
"status": "nicht_erlaubt",
"risk_level": "niedrig",
"consent_granted": false,
"legitimate_interest_granted": false
},
{
"id": 10,
"label": "Produkte entwickeln und verbessern",
"status": "nicht_erlaubt",
"risk_level": "niedrig",
"consent_granted": false,
"legitimate_interest_granted": false
},
{
"id": 11,
"label": "Begrenzte Daten zur Anzeigen-Auswahl verwenden",
"status": "nicht_erlaubt",
"risk_level": "niedrig",
"consent_granted": false,
"legitimate_interest_granted": false
}
],
"vendor_li_ids": [],
"policy_version": "5",
"vendor_li_count": 0,
"purpose_li_count": 0,
"tc_string_length": 0,
"tc_string_present": false,
"vendor_consent_ids": [],
"granted_purpose_rows": [],
"vendor_consent_count": 0,
"purpose_consent_count": 0,
"high_risk_purpose_count": 0,
"medium_risk_purpose_count": 0
},
"viewport_transparency": {
"samples": [],
"available": true,
"sample_count": 0,
"claim_boundary": "Sichtbarkeits-Evidence aus dem ersten Headless-Chromium-Viewport; keine Aussage ueber Footer nach Scrollen, Loginbereiche oder rechtliche Vollstaendigkeit.",
"viewport_width": 1024,
"category_counts": [],
"contact_visible": false,
"imprint_visible": false,
"viewport_height": 960,
"cookie_consent_visible": false,
"privacy_notice_visible": false
},
"consent_journey_matrix": {
"color": "yellow",
"items": [
{
"host": "cdn.matomo.cloud",
"states": {
"gpc": 1,
"default": 1
},
"category": "analytics",
"provider": "Matomo",
"category_label": "Analytics",
"privacy_relevant": true,
"total_request_count": 2
},
{
"host": "pnpabo.matomo.cloud",
"states": {
"gpc": 1,
"default": 1
},
"category": "analytics",
"provider": "Matomo",
"category_label": "Analytics",
"privacy_relevant": true,
"total_request_count": 2
},
{
"host": "cdn.opencmp.net",
"states": {
"gpc": 8,
"default": 8
},
"category": "other",
"provider": "cdn.opencmp.net",
"category_label": "Sonstige",
"privacy_relevant": false,
"total_request_count": 16
},
{
"host": "cdntrf.com",
"states": {
"gpc": 2,
"default": 2
},
"category": "other",
"provider": "cdntrf.com",
"category_label": "Sonstige",
"privacy_relevant": false,
"total_request_count": 4
},
{
"host": "d2wu036mkcz52n.cloudfront.net",
"states": {
"gpc": 2,
"default": 2
},
"category": "other",
"provider": "d2wu036mkcz52n.cloudfront.net",
"category_label": "Sonstige",
"privacy_relevant": false,
"total_request_count": 4
},
{
"host": "files.upscore.com",
"states": {
"gpc": 1,
"default": 1
},
"category": "other",
"provider": "files.upscore.com",
"category_label": "Sonstige",
"privacy_relevant": false,
"total_request_count": 2
},
{
"host": "mbv.slgnt.eu",
"states": {
"gpc": 1,
"default": 1
},
"category": "other",
"provider": "mbv.slgnt.eu",
"category_label": "Sonstige",
"privacy_relevant": false,
"total_request_count": 2
},
{
"host": "npmtecpublic.s3.eu-central-1.amazonaws.com",
"states": {
"gpc": 1,
"default": 1
},
"category": "other",
"provider": "npmtecpublic.s3.eu-central-1.amazonaws.com",
"category_label": "Sonstige",
"privacy_relevant": false,
"total_request_count": 2
}
],
"score": 84,
"states": [
{
"id": "default",
"label": "Erstaufruf",
"description": "Kontakte ohne Nutzeraktion",
"domain_count": 8,
"request_count": 17,
"privacy_relevant_domain_count": 2
},
{
"id": "reject_new",
"label": "Nach Ablehnen neu",
"description": "Neue Kontakte nach Ablehnen-Klick",
"domain_count": 0,
"request_count": 0,
"privacy_relevant_domain_count": 0
},
{
"id": "accept_new",
"label": "Nach Akzeptieren neu",
"description": "Neue Kontakte nach Akzeptieren-Klick",
"domain_count": 0,
"request_count": 0,
"privacy_relevant_domain_count": 0
},
{
"id": "gpc",
"label": "GPC-Aufruf",
"description": "Kontakte bei Global Privacy Control",
"domain_count": 8,
"request_count": 17,
"privacy_relevant_domain_count": 2
}
],
"status": "prüfen",
"summary": "Consent-Journey: 0 neue Datenschutz-Domain(s) nach Ablehnen, 0 nach Akzeptieren, 2 im GPC-Aufruf.",
"gpc_privacy_relevant_domain_count": 2,
"accept_privacy_relevant_domain_count": 0,
"reject_privacy_relevant_domain_count": 0
},
"consent_state_evidence": {
"rows": [
{
"id": "default",
"label": "Erstaufruf",
"status": "ohne Nutzeraktion",
"evidence": "Baseline aus erstem Chromium-Aufruf ohne Banner-Interaktion.",
"risk_level": "mittel",
"cookie_count": 13,
"domain_count": 9,
"request_count": 275,
"storage_total": 16,
"new_cookie_count": 13,
"third_party_cookie_count": 0,
"storage_tracking_hint_count": 0,
"privacy_relevant_domain_count": 2
},
{
"id": "reject",
"label": "Nach Ablehnen",
"status": "nicht verfügbar",
"evidence": "",
"risk_level": "niedrig",
"cookie_count": 13,
"domain_count": 0,
"request_count": 0,
"storage_total": 16,
"new_cookie_count": 0,
"third_party_cookie_count": 0,
"storage_tracking_hint_count": 0,
"privacy_relevant_domain_count": 0
},
{
"id": "accept",
"label": "Nach Akzeptieren",
"status": "nicht ausgeführt",
"evidence": "",
"risk_level": "niedrig",
"cookie_count": 0,
"domain_count": 0,
"request_count": 0,
"storage_total": 0,
"new_cookie_count": 0,
"third_party_cookie_count": 0,
"storage_tracking_hint_count": 0,
"privacy_relevant_domain_count": 0
},
{
"id": "gpc",
"label": "GPC-Aufruf",
"status": "aktiv",
"evidence": "Navigator-GPC und Sec-GPC wurden im gesonderten Browserlauf gesetzt.",
"risk_level": "mittel",
"cookie_count": 13,
"domain_count": 9,
"request_count": 274,
"storage_total": 16,
"new_cookie_count": 0,
"third_party_cookie_count": 0,
"storage_tracking_hint_count": 0,
"privacy_relevant_domain_count": 2
}
],
"color": "yellow",
"score": 80,
"status": "prüfen",
"summary": "Consent-State-Evidence: 4 Zustände verglichen, 0 hoch auffällig, 2 mittel auffällig.",
"findings": [
{
"id": "consent_state_gpc_evidence_review",
"title": "Consent-Zustand: GPC mit Tracking-Hinweisen",
"public": true,
"category": "privacy",
"severity": "info"
}
],
"available": true,
"high_count": 0,
"medium_count": 2
},
"contacted_domain_count": 9,
"fingerprinting_analysis": {
"color": "yellow",
"score": 88,
"checks": [
{
"id": "canvas",
"ok": true,
"count": 0,
"label": "Canvas-Auslese",
"detail": "0 Pixel-Lesezugriff(e), 0 Export(e)."
},
{
"id": "webgl",
"ok": true,
"count": 0,
"label": "WebGL-Merkmale",
"detail": "0 Parameterzugriff(e), 0 Pixel-Lesezugriff(e)."
},
{
"id": "audio",
"ok": true,
"count": 0,
"label": "AudioContext",
"detail": "0 AudioContext/OfflineAudioContext-Aufruf(e)."
},
{
"id": "session_replay",
"ok": true,
"count": 0,
"label": "Session-Replay-Anbieter",
"detail": "Keine bekannten Anbieter erkannt."
},
{
"id": "input_listeners",
"ok": false,
"count": 36,
"label": "Tastatur-/Eingabe-Listener",
"detail": "36 Tastatur-/Input-Listener, 51 Interaktions-Listener, 2 MutationObserver."
}
],
"status": "prüfen",
"metrics": {
"webgl_read_count": 0,
"canvas_read_count": 0,
"audio_context_count": 0,
"canvas_export_count": 0,
"webgl_parameter_count": 0,
"mutation_observer_count": 2,
"keyboard_input_listener_count": 36
},
"summary": "1 Fingerprinting-/Session-Replay-Hinweis(e) aus dem Browserlauf.",
"findings": [
{
"id": "browser_keystroke_listener_signals",
"count": 36,
"title": "Viele Tastatur-/Eingabe-Listener im Browser erkannt",
"public": true,
"category": "privacy",
"severity": "info"
}
],
"finding_count": 1,
"session_replay_domains": []
},
"privacy_relevant_domains": [
{
"host": "cdn.matomo.cloud",
"count": 1,
"category": "analytics",
"provider": "Matomo",
"third_party": true,
"category_label": "Analytics",
"resource_types": {
"script": 1
}
},
{
"host": "pnpabo.matomo.cloud",
"count": 1,
"category": "analytics",
"provider": "Matomo",
"third_party": true,
"category_label": "Analytics",
"resource_types": {
"ping": 1
}
}
],
"provider_category_counts": {
"other": 6,
"analytics": 2
},
"provider_category_labels": {
"other": "other",
"analytics": "Analytics"
},
"third_party_domain_count": 8,
"embedded_content_analysis": {
"color": "green",
"items": [],
"score": 100,
"status": "unauffällig",
"summary": "0 externe Embed-/Widget-Dienst(e), 0 davon im ersten Browseraufruf geladen.",
"findings": [],
"map_count": 0,
"total_count": 0,
"video_count": 0,
"captcha_count": 0,
"category_counts": [],
"social_widget_count": 0,
"loaded_pre_consent_count": 0,
"request_count_by_provider": []
},
"referrer_leakage_analysis": {
"color": "orange",
"items": [
{
"host": "pnpabo.matomo.cloud",
"category": "analytics",
"provider": "Matomo",
"query_keys": [
"action_name",
"idsite",
"rec",
"r",
"h",
"m",
"s",
"url"
],
"risk_reason": "Seiten-URL oder URL-Wert in Drittanbieter-Requestparametern",
"resource_type": "ping",
"category_label": "Analytics",
"referrer_query_keys": [],
"url_value_param_count": 1,
"target_url_value_param_count": 1
},
{
"host": "d2wu036mkcz52n.cloudfront.net",
"category": "other",
"provider": "d2wu036mkcz52n.cloudfront.net",
"query_keys": [
"v",
"sr",
"vp",
"cd",
"md",
"h",
"t",
"d"
],
"risk_reason": "Seiten-URL oder URL-Wert in Drittanbieter-Requestparametern",
"resource_type": "image",
"category_label": "Sonstige",
"referrer_query_keys": [],
"url_value_param_count": 0,
"target_url_value_param_count": 2
},
{
"host": "d2wu036mkcz52n.cloudfront.net",
"category": "other",
"provider": "d2wu036mkcz52n.cloudfront.net",
"query_keys": [
"v",
"sr",
"vp",
"cd",
"md",
"h",
"t",
"d"
],
"risk_reason": "Seiten-URL oder URL-Wert in Drittanbieter-Requestparametern",
"resource_type": "image",
"category_label": "Sonstige",
"referrer_query_keys": [],
"url_value_param_count": 0,
"target_url_value_param_count": 2
}
],
"score": 65,
"status": "auffällig",
"summary": "2 Drittanbieter-Domain(s) mit Referrer-/URL-Leak-Prüfbedarf, 0 sensible Query-Kontexte.",
"findings": [
{
"id": "third_party_page_url_parameter",
"count": 3,
"title": "Seiten-URL wird in Drittanbieter-Requests übertragen",
"public": true,
"category": "privacy",
"severity": "warning"
}
],
"sample_count": 17,
"full_referrer_count": 0,
"page_url_param_count": 3,
"affected_domain_count": 2,
"sensitive_query_count": 0
},
"third_party_contact_matrix": {
"color": "red",
"items": [
{
"host": "cdn.matomo.cloud",
"region": "EU/selbst gehostet möglich",
"status": "dokumentieren",
"category": "analytics",
"provider": "Matomo",
"risk_level": "mittel",
"request_count": 1,
"transfer_risk": "mittel",
"category_label": "Analytics",
"resource_types": [
{
"type": "script",
"count": 1
}
],
"transfer_label": "EU/EWR oder selbst gehostet",
"privacy_relevant": true
},
{
"host": "pnpabo.matomo.cloud",
"region": "EU/selbst gehostet möglich",
"status": "dokumentieren",
"category": "analytics",
"provider": "Matomo",
"risk_level": "mittel",
"request_count": 1,
"transfer_risk": "mittel",
"category_label": "Analytics",
"resource_types": [
{
"type": "ping",
"count": 1
}
],
"transfer_label": "EU/EWR oder selbst gehostet",
"privacy_relevant": true
},
{
"host": "cdn.opencmp.net",
"region": "unbekannt",
"status": "prüfen",
"category": "other",
"provider": "cdn.opencmp.net",
"risk_level": "niedrig",
"request_count": 8,
"transfer_risk": "mittel",
"category_label": "Sonstige",
"resource_types": [
{
"type": "fetch",
"count": 5
},
{
"type": "script",
"count": 3
}
],
"transfer_label": "Jurisdiktion unklar",
"privacy_relevant": false
},
{
"host": "cdntrf.com",
"region": "unbekannt",
"status": "prüfen",
"category": "other",
"provider": "cdntrf.com",
"risk_level": "niedrig",
"request_count": 2,
"transfer_risk": "mittel",
"category_label": "Sonstige",
"resource_types": [
{
"type": "xhr",
"count": 2
}
],
"transfer_label": "Jurisdiktion unklar",
"privacy_relevant": false
},
{
"host": "d2wu036mkcz52n.cloudfront.net",
"region": "unbekannt",
"status": "prüfen",
"category": "other",
"provider": "d2wu036mkcz52n.cloudfront.net",
"risk_level": "niedrig",
"request_count": 2,
"transfer_risk": "mittel",
"category_label": "Sonstige",
"resource_types": [
{
"type": "image",
"count": 2
}
],
"transfer_label": "Jurisdiktion unklar",
"privacy_relevant": false
},
{
"host": "files.upscore.com",
"region": "unbekannt",
"status": "prüfen",
"category": "other",
"provider": "files.upscore.com",
"risk_level": "niedrig",
"request_count": 1,
"transfer_risk": "mittel",
"category_label": "Sonstige",
"resource_types": [
{
"type": "script",
"count": 1
}
],
"transfer_label": "Jurisdiktion unklar",
"privacy_relevant": false
},
{
"host": "mbv.slgnt.eu",
"region": "EU/EWR",
"status": "prüfen",
"category": "other",
"provider": "mbv.slgnt.eu",
"risk_level": "niedrig",
"request_count": 1,
"transfer_risk": "niedrig",
"category_label": "Sonstige",
"resource_types": [
{
"type": "script",
"count": 1
}
],
"transfer_label": "EU/EWR",
"privacy_relevant": false
},
{
"host": "npmtecpublic.s3.eu-central-1.amazonaws.com",
"region": "unbekannt",
"status": "prüfen",
"category": "other",
"provider": "npmtecpublic.s3.eu-central-1.amazonaws.com",
"risk_level": "niedrig",
"request_count": 1,
"transfer_risk": "mittel",
"category_label": "Sonstige",
"resource_types": [
{
"type": "image",
"count": 1
}
],
"transfer_label": "Jurisdiktion unklar",
"privacy_relevant": false
}
],
"score": 45,
"status": "kritisch",
"summary": "8 Drittanbieter-Domain(s) beim ersten Browseraufruf, davon 2 datenschutzrelevant.",
"category_counts": {
"Sonstige": 6,
"Analytics": 2
},
"total_domain_count": 8,
"total_request_count": 17,
"privacy_relevant_count": 2,
"transfer_risk_analysis": {
"color": "yellow",
"items": [
{
"host": "cdn.matomo.cloud",
"region": "EU/selbst gehostet möglich",
"provider": "Matomo",
"request_count": 1,
"transfer_risk": "mittel",
"category_label": "Analytics",
"transfer_label": "EU/EWR oder selbst gehostet",
"privacy_relevant": true
},
{
"host": "pnpabo.matomo.cloud",
"region": "EU/selbst gehostet möglich",
"provider": "Matomo",
"request_count": 1,
"transfer_risk": "mittel",
"category_label": "Analytics",
"transfer_label": "EU/EWR oder selbst gehostet",
"privacy_relevant": true
},
{
"host": "cdn.opencmp.net",
"region": "unbekannt",
"provider": "cdn.opencmp.net",
"request_count": 8,
"transfer_risk": "mittel",
"category_label": "Sonstige",
"transfer_label": "Jurisdiktion unklar",
"privacy_relevant": false
},
{
"host": "cdntrf.com",
"region": "unbekannt",
"provider": "cdntrf.com",
"request_count": 2,
"transfer_risk": "mittel",
"category_label": "Sonstige",
"transfer_label": "Jurisdiktion unklar",
"privacy_relevant": false
},
{
"host": "d2wu036mkcz52n.cloudfront.net",
"region": "unbekannt",
"provider": "d2wu036mkcz52n.cloudfront.net",
"request_count": 2,
"transfer_risk": "mittel",
"category_label": "Sonstige",
"transfer_label": "Jurisdiktion unklar",
"privacy_relevant": false
},
{
"host": "files.upscore.com",
"region": "unbekannt",
"provider": "files.upscore.com",
"request_count": 1,
"transfer_risk": "mittel",
"category_label": "Sonstige",
"transfer_label": "Jurisdiktion unklar",
"privacy_relevant": false
},
{
"host": "mbv.slgnt.eu",
"region": "EU/EWR",
"provider": "mbv.slgnt.eu",
"request_count": 1,
"transfer_risk": "niedrig",
"category_label": "Sonstige",
"transfer_label": "EU/EWR",
"privacy_relevant": false
},
{
"host": "npmtecpublic.s3.eu-central-1.amazonaws.com",
"region": "unbekannt",
"provider": "npmtecpublic.s3.eu-central-1.amazonaws.com",
"request_count": 1,
"transfer_risk": "mittel",
"category_label": "Sonstige",
"transfer_label": "Jurisdiktion unklar",
"privacy_relevant": false
}
],
"score": 76,
"status": "prüfen",
"summary": "8 Drittanbieter für Transfer-/Jurisdiktionsprüfung, 0 mit hohem Prüfbedarf, 5 unklar.",
"findings": [
{
"id": "unknown_vendor_jurisdiction",
"title": "Anbieter-Jurisdiktion nicht klar ableitbar",
"public": true,
"category": "privacy",
"severity": "info"
}
],
"unknown_count": 5,
"high_risk_count": 0,
"total_vendor_count": 8,
"third_country_count": 0
}
},
"privacy_relevant_domain_count": 2,
"tracking_pixel_beacon_analysis": {
"color": "orange",
"items": [
{
"url": "",
"host": "abo.mittelbayerische.de",
"kind": "beacon_api",
"reason": "sendBeacon API 1 Aufruf(e), 0 Code-Hinweis(e); keepalive 0 Aufruf(e), 0 Code-Hinweis(e).",
"source": "javascript_api",
"category": "telemetry",
"provider": "Beacon-/Keepalive-API",
"third_party": false,
"resource_type": "beacon",
"category_label": "Telemetry"
},
{
"url": "",
"host": "pnpabo.matomo.cloud",
"kind": "browser_tracking_request",
"reason": "ping-Request mit 27 Query-Schlüssel(n).",
"source": "chromium_request",
"category": "analytics",
"provider": "Matomo",
"query_keys": [
"action_name",
"idsite",
"rec",
"r",
"h",
"m",
"s",
"url"
],
"third_party": true,
"resource_type": "ping",
"category_label": "Analytics"
},
{
"url": "",
"host": "d2wu036mkcz52n.cloudfront.net",
"kind": "browser_tracking_request",
"reason": "image-Request mit 20 Query-Schlüssel(n).",
"source": "chromium_request",
"category": "other",
"provider": "d2wu036mkcz52n.cloudfront.net",
"query_keys": [
"v",
"sr",
"vp",
"cd",
"md",
"h",
"t",
"d"
],
"third_party": true,
"resource_type": "image",
"category_label": "Sonstige"
}
],
"score": 66,
"status": "auffällig",
"summary": "1 Pixel-/Bildtracking-Hinweis(e), 2 Beacon-/Telemetry-Hinweis(e), 0 Link-Ping(s).",
"findings": [
{
"id": "tracking_pixel_detected",
"count": 1,
"title": "Tracking-Pixel oder pixelnahe Requests erkannt",
"public": true,
"category": "privacy",
"severity": "warning"
},
{
"id": "beacon_api_usage",
"count": 2,
"title": "Beacon-/Keepalive-Telemetrie erkannt",
"public": true,
"category": "privacy",
"severity": "warning"
}
],
"pixel_count": 1,
"link_ping_count": 0,
"telemetry_count": 1,
"beacon_api_count": 1,
"third_party_count": 2,
"fetch_keepalive_count": 0,
"privacy_relevant_count": 1,
"beacon_code_reference_count": 0,
"fetch_keepalive_reference_count": 0
}
},
"privacy_analysis": {
"cookies": {
"items": [
{
"name": "PHPSESSID",
"secure": true,
"samesite": true,
"tracking": false,
"pre_consent": true,
"likely_essential": true
}
],
"total": 1,
"tracking": [],
"pre_consent": [
"PHPSESSID"
],
"missing_secure": [],
"missing_samesite": [],
"pre_consent_tracking": [],
"pre_consent_nonessential": []
},
"findings": [],
"tracking_ids": [],
"tracking_scripts": [],
"consent_hint_found": false,
"privacy_policy_hint_found": true
},
"consent_audit": {
"color": "red",
"score": 16,
"checks": [
{
"id": "banner_visible",
"ok": true,
"label": "Cookie-/Consent-Hinweis sichtbar",
"detail": "Ein Hinweis mit Cookie-/Einwilligungsbezug wurde im sichtbaren Text erkannt."
},
{
"id": "reject_visible",
"ok": false,
"label": "Ablehnen gleichwertig erreichbar",
"detail": "Ablehnen oder nur notwendige Cookies wurde im Text oder Browser erkannt. Browser-Buttons: 0."
},
{
"id": "settings_visible",
"ok": true,
"label": "Einstellungen oder Auswahl vorhanden",
"detail": "Eine Einstellungs- oder Auswahlmoeglichkeit wurde im Text oder Browser erkannt. Browser-Buttons: 0."
},
{
"id": "browser_reject_visible",
"ok": true,
"label": "Ablehnen im sichtbaren Banner",
"detail": "Sichtbare Banner-Controls: Akzeptieren 0, Ablehnen 0, Einstellungen 0."
},
{
"id": "browser_settings_visible",
"ok": true,
"label": "Einstellungen im sichtbaren Banner",
"detail": "Sichtbare Banner-Controls: Akzeptieren 0, Ablehnen 0, Einstellungen 0."
},
{
"id": "reject_equally_prominent",
"ok": true,
"label": "Ablehnen nicht deutlich schwaecher dargestellt",
"detail": "Groessen-Verhältnis Ablehnen/Akzeptieren: nicht messbar."
},
{
"id": "reject_button_clickable",
"ok": true,
"label": "Ablehnen technisch klickbar",
"detail": "Wenn ein Ablehnen-Button sichtbar ist, klickt SaferPage ihn im Chromium-Browser einmal an."
},
{
"id": "no_new_cookies_after_reject",
"ok": true,
"label": "Keine neuen Cookies nach Ablehnen",
"detail": "0 neue Cookie(s) nach dem Ablehnen-Klick."
},
{
"id": "no_tracking_storage_after_reject",
"ok": true,
"label": "Kein Tracking-Storage nach Ablehnen",
"detail": "0 Tracking-Hinweis(e) im Web Storage nach Ablehnen."
},
{
"id": "no_privacy_domains_after_reject",
"ok": true,
"label": "Keine neuen Tracking-Kontakte nach Ablehnen",
"detail": "0 neue datenschutzrelevante Domain(s) nach Ablehnen."
},
{
"id": "gpc_signal_respected",
"ok": false,
"label": "GPC-Signal ohne Tracking-Hinweise",
"detail": "GPC-Aufruf: 2 datenschutzrelevante Domain(s), 0 Drittanbieter-Cookie(s), 0 Storage-Hinweis(e)."
},
{
"id": "no_tracking_cookies_before_consent",
"ok": false,
"label": "Keine Tracking-Cookies vor Einwilligung",
"detail": "2 Tracking-Cookie(s) im Erstaufruf."
},
{
"id": "no_nonessential_cookies_before_consent",
"ok": false,
"label": "Keine nicht notwendigen Cookies vor Einwilligung",
"detail": "11 moeglicherweise nicht notwendige Cookie(s) im Erstaufruf."
},
{
"id": "third_parties_explained",
"ok": true,
"label": "Drittanbieter begrenzt und erklaerbar",
"detail": "0 datenschutzrelevante Drittanbieter-Domain(s), 8 Drittanbieter insgesamt."
},
{
"id": "storage_without_tracking_hints",
"ok": true,
"label": "Web Storage ohne Tracking-Hinweise",
"detail": "16 Storage-Key(s), 0 Tracking-Hinweis(e)."
},
{
"id": "cmp_api_detected_when_needed",
"ok": true,
"label": "CMP-/TCF-Signal bei Tracking erkennbar",
"detail": "Gängige CMP-/TCF-Indikatoren: __tcfapi, __cmp, Cookiebot, OneTrust oder Usercentrics."
},
{
"id": "accept_click_documented",
"ok": true,
"label": "Akzeptieren-Klick nachvollziehbar",
"detail": "Accept-Test: nicht ausgefuehrt, neue Requests 0, neue Cookies 0, neue Datenschutz-Domains 0."
},
{
"id": "cmp_state_readable",
"ok": false,
"label": "CMP-/TCF-Zustand auslesbar",
"detail": "TCF TC-String: nein, Cookiebot: nein, OneTrust: nein, Usercentrics: nein."
},
{
"id": "cmp_default_restrictive",
"ok": true,
"label": "CMP-Default wirkt restriktiv",
"detail": "TCF Purposes erlaubt: 0, TCF Vendors erlaubt: 0, Cookiebot Statistik/Marketing: nein."
}
],
"status": "kritisch",
"summary": "Consent, Tracking oder Drittanbieter wirken im Erstaufruf deutlich nachbesserungsbeduerftig.",
"evidence": [
"13 Cookie(s) beim ersten Aufruf aus HTTP-Headern und Chromium",
"0 Tracking-Script(s) im HTML",
"0 datenschutzrelevante Drittanbieter-Domain(s)",
"16 Storage-Key(s), 0 Tracking-Hinweis(e)",
"Consent-Banner-Controls: Akzeptieren 0, Ablehnen 0, Einstellungen 0",
"Ablehnen/Akzeptieren-Prominenz: nicht messbar",
"Reject-Test: nicht ausgefuehrt, neue Cookies 0, Tracking-Storage 0, neue Datenschutz-Domains 0",
"Accept-Test: nicht ausgefuehrt, neue Requests 0, neue Cookies 0, neue Datenschutz-Domains 0, Drittanbieter-Cookies 0",
"CMP-State: TCF-String nein, TCF Purposes 0, TCF Vendors 0, Cookiebot nein, OneTrust-Gruppen 0, Usercentrics-Services 0",
"GPC-Test: aktiv, Datenschutz-Domains 2, Drittanbieter-Cookies 0, Storage-Hinweise 0",
"CMP-/TCF-Signal: ja",
"Google Consent Default: nein"
],
"gpc_enabled": true,
"cmp_detected": true,
"blocking_plan": {
"items": [
{
"kind": "cookie",
"level": "hoch",
"source": "Matomo",
"target": "_pk_id.4.12ad",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Cookiebot"
},
{
"tool": "Usercentrics"
},
{
"tool": "OneTrust"
},
{
"tool": "Developer-Fallback"
}
],
"category": "analytics",
"evidence": "vor Consent gesetzt · mittelbayerische.de · lang (392 Tage)",
"category_label": "Analytics"
},
{
"kind": "cookie",
"level": "hoch",
"source": "Matomo",
"target": "_pk_ses.4.12ad",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Cookiebot"
},
{
"tool": "Usercentrics"
},
{
"tool": "OneTrust"
},
{
"tool": "Developer-Fallback"
}
],
"category": "analytics",
"evidence": "vor Consent gesetzt · mittelbayerische.de · kurz (0 Tage)",
"category_label": "Analytics"
},
{
"kind": "third_party_request",
"level": "hoch",
"source": "Matomo",
"target": "cdn.matomo.cloud",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Cookiebot"
},
{
"tool": "Usercentrics"
},
{
"tool": "OneTrust"
},
{
"tool": "Developer-Fallback"
}
],
"category": "analytics",
"evidence": "1 Request(s) im Erstaufruf · Analytics",
"category_label": "Analytics"
},
{
"kind": "third_party_request",
"level": "hoch",
"source": "Matomo",
"target": "pnpabo.matomo.cloud",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Cookiebot"
},
{
"tool": "Usercentrics"
},
{
"tool": "OneTrust"
},
{
"tool": "Developer-Fallback"
}
],
"category": "analytics",
"evidence": "1 Request(s) im Erstaufruf · Analytics",
"category_label": "Analytics"
},
{
"kind": "cookie",
"level": "mittel",
"source": "abo.mittelbayerische.de",
"target": "form_key",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Cookiebot"
},
{
"tool": "Usercentrics"
},
{
"tool": "OneTrust"
},
{
"tool": "Developer-Fallback"
}
],
"category": "unknown",
"evidence": "vor Consent gesetzt · abo.mittelbayerische.de · kurz (0 Tage)",
"category_label": "Unklar"
},
{
"kind": "cookie",
"level": "mittel",
"source": "abo.mittelbayerische.de",
"target": "mage-cache-storage",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Cookiebot"
},
{
"tool": "Usercentrics"
},
{
"tool": "OneTrust"
},
{
"tool": "Developer-Fallback"
}
],
"category": "unknown",
"evidence": "vor Consent gesetzt · abo.mittelbayerische.de · kurz (0 Tage)",
"category_label": "Unklar"
},
{
"kind": "cookie",
"level": "mittel",
"source": "abo.mittelbayerische.de",
"target": "mage-cache-storage-section-invalidation",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Cookiebot"
},
{
"tool": "Usercentrics"
},
{
"tool": "OneTrust"
},
{
"tool": "Developer-Fallback"
}
],
"category": "unknown",
"evidence": "vor Consent gesetzt · abo.mittelbayerische.de · kurz (0 Tage)",
"category_label": "Unklar"
},
{
"kind": "cookie",
"level": "mittel",
"source": "abo.mittelbayerische.de",
"target": "mage-messages",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Cookiebot"
},
{
"tool": "Usercentrics"
},
{
"tool": "OneTrust"
},
{
"tool": "Developer-Fallback"
}
],
"category": "unknown",
"evidence": "vor Consent gesetzt · abo.mittelbayerische.de · kurz (0 Tage)",
"category_label": "Unklar"
},
{
"kind": "cookie",
"level": "mittel",
"source": "abo.mittelbayerische.de",
"target": "product_data_storage",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Cookiebot"
},
{
"tool": "Usercentrics"
},
{
"tool": "OneTrust"
},
{
"tool": "Developer-Fallback"
}
],
"category": "unknown",
"evidence": "vor Consent gesetzt · abo.mittelbayerische.de · kurz (0 Tage)",
"category_label": "Unklar"
},
{
"kind": "cookie",
"level": "mittel",
"source": "abo.mittelbayerische.de",
"target": "recently_compared_product",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Cookiebot"
},
{
"tool": "Usercentrics"
},
{
"tool": "OneTrust"
},
{
"tool": "Developer-Fallback"
}
],
"category": "unknown",
"evidence": "vor Consent gesetzt · abo.mittelbayerische.de · kurz (0 Tage)",
"category_label": "Unklar"
},
{
"kind": "cookie",
"level": "mittel",
"source": "abo.mittelbayerische.de",
"target": "recently_compared_product_previous",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Cookiebot"
},
{
"tool": "Usercentrics"
},
{
"tool": "OneTrust"
},
{
"tool": "Developer-Fallback"
}
],
"category": "unknown",
"evidence": "vor Consent gesetzt · abo.mittelbayerische.de · kurz (0 Tage)",
"category_label": "Unklar"
},
{
"kind": "cookie",
"level": "mittel",
"source": "abo.mittelbayerische.de",
"target": "recently_viewed_product",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Cookiebot"
},
{
"tool": "Usercentrics"
},
{
"tool": "OneTrust"
},
{
"tool": "Developer-Fallback"
}
],
"category": "unknown",
"evidence": "vor Consent gesetzt · abo.mittelbayerische.de · kurz (0 Tage)",
"category_label": "Unklar"
},
{
"kind": "cookie",
"level": "mittel",
"source": "abo.mittelbayerische.de",
"target": "recently_viewed_product_previous",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Cookiebot"
},
{
"tool": "Usercentrics"
},
{
"tool": "OneTrust"
},
{
"tool": "Developer-Fallback"
}
],
"category": "unknown",
"evidence": "vor Consent gesetzt · abo.mittelbayerische.de · kurz (0 Tage)",
"category_label": "Unklar"
},
{
"kind": "storage",
"level": "mittel",
"source": "localStorage",
"target": "mage-cache-storage",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Usercentrics"
},
{
"tool": "Developer-Fallback"
}
],
"category": "unknown",
"evidence": "localStorage · Unklar · dauerhaft bis Löschung durch Nutzer/Browser",
"category_label": "Unklar"
},
{
"kind": "storage",
"level": "mittel",
"source": "localStorage",
"target": "mage-cache-storage-section-invalidation",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Usercentrics"
},
{
"tool": "Developer-Fallback"
}
],
"category": "unknown",
"evidence": "localStorage · Unklar · dauerhaft bis Löschung durch Nutzer/Browser",
"category_label": "Unklar"
},
{
"kind": "storage",
"level": "mittel",
"source": "localStorage",
"target": "mage-cache-timeout",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Usercentrics"
},
{
"tool": "Developer-Fallback"
}
],
"category": "unknown",
"evidence": "localStorage · Unklar · dauerhaft bis Löschung durch Nutzer/Browser",
"category_label": "Unklar"
},
{
"kind": "storage",
"level": "mittel",
"source": "localStorage",
"target": "product_data_storage",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Usercentrics"
},
{
"tool": "Developer-Fallback"
}
],
"category": "unknown",
"evidence": "localStorage · Unklar · dauerhaft bis Löschung durch Nutzer/Browser",
"category_label": "Unklar"
},
{
"kind": "storage",
"level": "mittel",
"source": "localStorage",
"target": "recently_compared_product",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Usercentrics"
},
{
"tool": "Developer-Fallback"
}
],
"category": "unknown",
"evidence": "localStorage · Unklar · dauerhaft bis Löschung durch Nutzer/Browser",
"category_label": "Unklar"
},
{
"kind": "storage",
"level": "mittel",
"source": "localStorage",
"target": "recently_compared_product_previous",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Usercentrics"
},
{
"tool": "Developer-Fallback"
}
],
"category": "unknown",
"evidence": "localStorage · Unklar · dauerhaft bis Löschung durch Nutzer/Browser",
"category_label": "Unklar"
},
{
"kind": "storage",
"level": "mittel",
"source": "localStorage",
"target": "recently_viewed_product",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Usercentrics"
},
{
"tool": "Developer-Fallback"
}
],
"category": "unknown",
"evidence": "localStorage · Unklar · dauerhaft bis Löschung durch Nutzer/Browser",
"category_label": "Unklar"
},
{
"kind": "storage",
"level": "mittel",
"source": "localStorage",
"target": "recently_viewed_product_previous",
"recipes": [
{
"tool": "Google Tag Manager"
},
{
"tool": "Usercentrics"
},
{
"tool": "Developer-Fallback"
}
],
"category": "unknown",
"evidence": "localStorage · Unklar · dauerhaft bis Löschung durch Nutzer/Browser",
"category_label": "Unklar"
}
],
"summary": "21 Blockier-/Consent-Maßnahme(n) abgeleitet: 4 hoch, 17 mittel.",
"available": true,
"high_count": 4,
"total_count": 21,
"type_counts": {
"cookie": 11,
"storage": 8,
"third_party_request": 2
},
"medium_count": 17
},
"tcf_api_found": true,
"cookiebot_found": false,
"accept_test_enabled": false,
"browser_cookie_count": 13,
"accept_button_clicked": false,
"browser_storage_count": 16,
"reject_button_clicked": false,
"reject_less_prominent": false,
"tcf_tc_string_present": false,
"tracking_script_count": 0,
"accept_button_available": false,
"reject_button_available": false,
"reject_prominence_ratio": 0,
"pre_consent_cookie_count": 13,
"pre_consent_cookie_names": [
"PHPSESSID",
"_pk_id.4.12ad",
"_pk_ses.4.12ad",
"mage-cache-sessid",
"form_key",
"mage-cache-storage",
"mage-cache-storage-section-invalidation",
"mage-messages",
"product_data_storage",
"recently_compared_product",
"recently_compared_product_previous",
"recently_viewed_product",
"recently_viewed_product_previous"
],
"tcf_vendor_consent_count": 0,
"third_party_domain_count": 8,
"tcf_purpose_consent_count": 0,
"onetrust_active_group_count": 0,
"usercentrics_services_count": 0,
"browser_accept_control_count": 0,
"browser_cookie_context_found": true,
"browser_reject_control_count": 0,
"gpc_third_party_cookie_count": 0,
"post_accept_new_cookie_count": 0,
"post_reject_new_cookie_count": 0,
"post_accept_new_request_count": 0,
"browser_settings_control_count": 0,
"gpc_storage_tracking_hint_count": 0,
"cookiebot_marketing_or_statistics": false,
"gpc_privacy_relevant_domain_count": 2,
"pre_consent_tracking_cookie_count": 2,
"pre_consent_tracking_cookie_names": [
"_pk_id.4.12ad",
"_pk_ses.4.12ad"
],
"privacy_relevant_third_party_count": 0,
"browser_storage_tracking_hint_count": 0,
"post_accept_third_party_cookie_count": 0,
"pre_consent_nonessential_cookie_count": 11,
"pre_consent_nonessential_cookie_names": [
"_pk_id.4.12ad",
"_pk_ses.4.12ad",
"form_key",
"mage-cache-storage",
"mage-cache-storage-section-invalidation",
"mage-messages",
"product_data_storage",
"recently_compared_product",
"recently_compared_product_previous",
"recently_viewed_product",
"recently_viewed_product_previous"
],
"post_accept_storage_tracking_hint_count": 0,
"post_reject_storage_tracking_hint_count": 0,
"post_accept_privacy_relevant_domain_count": 0,
"post_reject_privacy_relevant_domain_count": 0
},
"cookie_inventory": {
"color": "orange",
"items": [
{
"name": "_pk_id.4.12ad",
"domain": "mittelbayerische.de",
"secure": false,
"sources": [
"browser_first_load"
],
"category": "analytics",
"provider": "Matomo",
"tracking": true,
"http_only": false,
"same_site": "Lax",
"expires_at": "2027-07-17T20:06:01+00:00",
"long_lived": true,
"persistent": true,
"first_party": true,
"origin_host": "abo.mittelbayerische.de",
"pre_consent": true,
"source_label": "Chromium-Erstaufruf",
"category_label": "Analytics",
"retention_risk": "hoch",
"expires_in_days": 392,
"origin_evidence": "Vom geprüften Host oder aus dem Browser-Erstaufruf abgeleitet.",
"origin_provider": "Matomo",
"retention_class": "long",
"retention_label": "lang (392 Tage)",
"likely_essential": false,
"origin_script_url": "",
"origin_resource_type": ""
},
{
"name": "_pk_ses.4.12ad",
"domain": "mittelbayerische.de",
"secure": false,
"sources": [
"browser_first_load"
],
"category": "analytics",
"provider": "Matomo",
"tracking": true,
"http_only": false,
"same_site": "Lax",
"expires_at": "2026-06-19T20:36:01+00:00",
"long_lived": false,
"persistent": true,
"first_party": true,
"origin_host": "abo.mittelbayerische.de",
"pre_consent": true,
"source_label": "Chromium-Erstaufruf",
"category_label": "Analytics",
"retention_risk": "niedrig",
"expires_in_days": 0,
"origin_evidence": "Vom geprüften Host oder aus dem Browser-Erstaufruf abgeleitet.",
"origin_provider": "Matomo",
"retention_class": "short",
"retention_label": "kurz (0 Tage)",
"likely_essential": false,
"origin_script_url": "",
"origin_resource_type": ""
},
{
"name": "PHPSESSID",
"domain": "abo.mittelbayerische.de",
"secure": true,
"sources": [
"http_set_cookie",
"browser_first_load"
],
"category": "necessary",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"http_only": true,
"same_site": "Lax",
"expires_at": "2026-06-19T21:06:00+00:00",
"long_lived": false,
"persistent": true,
"first_party": true,
"origin_host": "abo.mittelbayerische.de",
"pre_consent": true,
"source_label": "HTTP Set-Cookie, Chromium-Erstaufruf",
"category_label": "Notwendig",
"retention_risk": "niedrig",
"expires_in_days": 0,
"origin_evidence": "258 Browser-Request(s) · document:1, font:5, image:21, script:217",
"origin_provider": "abo.mittelbayerische.de",
"retention_class": "short",
"retention_label": "kurz (0 Tage)",
"likely_essential": true,
"origin_script_url": "",
"origin_resource_type": ""
},
{
"name": "mage-cache-sessid",
"domain": "abo.mittelbayerische.de",
"secure": true,
"sources": [
"browser_first_load"
],
"category": "necessary",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"http_only": false,
"same_site": "Lax",
"expires_at": "2026-06-19T21:06:01+00:00",
"long_lived": false,
"persistent": true,
"first_party": true,
"origin_host": "abo.mittelbayerische.de",
"pre_consent": true,
"source_label": "Chromium-Erstaufruf",
"category_label": "Notwendig",
"retention_risk": "niedrig",
"expires_in_days": 0,
"origin_evidence": "258 Browser-Request(s) · document:1, font:5, image:21, script:217",
"origin_provider": "abo.mittelbayerische.de",
"retention_class": "short",
"retention_label": "kurz (0 Tage)",
"likely_essential": true,
"origin_script_url": "",
"origin_resource_type": ""
},
{
"name": "form_key",
"domain": "abo.mittelbayerische.de",
"secure": true,
"sources": [
"browser_first_load"
],
"category": "unknown",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"http_only": false,
"same_site": "Lax",
"expires_at": "2026-06-20T20:06:01+00:00",
"long_lived": false,
"persistent": true,
"first_party": true,
"origin_host": "abo.mittelbayerische.de",
"pre_consent": true,
"source_label": "Chromium-Erstaufruf",
"category_label": "Unklar",
"retention_risk": "niedrig",
"expires_in_days": 0,
"origin_evidence": "258 Browser-Request(s) · document:1, font:5, image:21, script:217",
"origin_provider": "abo.mittelbayerische.de",
"retention_class": "short",
"retention_label": "kurz (0 Tage)",
"likely_essential": false,
"origin_script_url": "",
"origin_resource_type": ""
},
{
"name": "mage-cache-storage",
"domain": "abo.mittelbayerische.de",
"secure": true,
"sources": [
"browser_first_load"
],
"category": "unknown",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"http_only": false,
"same_site": "Lax",
"expires_at": "2026-06-19T21:06:01+00:00",
"long_lived": false,
"persistent": true,
"first_party": true,
"origin_host": "abo.mittelbayerische.de",
"pre_consent": true,
"source_label": "Chromium-Erstaufruf",
"category_label": "Unklar",
"retention_risk": "niedrig",
"expires_in_days": 0,
"origin_evidence": "258 Browser-Request(s) · document:1, font:5, image:21, script:217",
"origin_provider": "abo.mittelbayerische.de",
"retention_class": "short",
"retention_label": "kurz (0 Tage)",
"likely_essential": false,
"origin_script_url": "",
"origin_resource_type": ""
},
{
"name": "mage-cache-storage-section-invalidation",
"domain": "abo.mittelbayerische.de",
"secure": true,
"sources": [
"browser_first_load"
],
"category": "unknown",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"http_only": false,
"same_site": "Lax",
"expires_at": "2026-06-19T21:06:01+00:00",
"long_lived": false,
"persistent": true,
"first_party": true,
"origin_host": "abo.mittelbayerische.de",
"pre_consent": true,
"source_label": "Chromium-Erstaufruf",
"category_label": "Unklar",
"retention_risk": "niedrig",
"expires_in_days": 0,
"origin_evidence": "258 Browser-Request(s) · document:1, font:5, image:21, script:217",
"origin_provider": "abo.mittelbayerische.de",
"retention_class": "short",
"retention_label": "kurz (0 Tage)",
"likely_essential": false,
"origin_script_url": "",
"origin_resource_type": ""
},
{
"name": "mage-messages",
"domain": "abo.mittelbayerische.de",
"secure": true,
"sources": [
"browser_first_load"
],
"category": "unknown",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"http_only": false,
"same_site": "Strict",
"expires_at": "2026-06-19T21:06:01+00:00",
"long_lived": false,
"persistent": true,
"first_party": true,
"origin_host": "abo.mittelbayerische.de",
"pre_consent": true,
"source_label": "Chromium-Erstaufruf",
"category_label": "Unklar",
"retention_risk": "niedrig",
"expires_in_days": 0,
"origin_evidence": "258 Browser-Request(s) · document:1, font:5, image:21, script:217",
"origin_provider": "abo.mittelbayerische.de",
"retention_class": "short",
"retention_label": "kurz (0 Tage)",
"likely_essential": false,
"origin_script_url": "",
"origin_resource_type": ""
},
{
"name": "product_data_storage",
"domain": "abo.mittelbayerische.de",
"secure": true,
"sources": [
"browser_first_load"
],
"category": "unknown",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"http_only": false,
"same_site": "Lax",
"expires_at": "2026-06-19T21:06:01+00:00",
"long_lived": false,
"persistent": true,
"first_party": true,
"origin_host": "abo.mittelbayerische.de",
"pre_consent": true,
"source_label": "Chromium-Erstaufruf",
"category_label": "Unklar",
"retention_risk": "niedrig",
"expires_in_days": 0,
"origin_evidence": "258 Browser-Request(s) · document:1, font:5, image:21, script:217",
"origin_provider": "abo.mittelbayerische.de",
"retention_class": "short",
"retention_label": "kurz (0 Tage)",
"likely_essential": false,
"origin_script_url": "",
"origin_resource_type": ""
},
{
"name": "recently_compared_product",
"domain": "abo.mittelbayerische.de",
"secure": true,
"sources": [
"browser_first_load"
],
"category": "unknown",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"http_only": false,
"same_site": "Lax",
"expires_at": "2026-06-19T21:06:01+00:00",
"long_lived": false,
"persistent": true,
"first_party": true,
"origin_host": "abo.mittelbayerische.de",
"pre_consent": true,
"source_label": "Chromium-Erstaufruf",
"category_label": "Unklar",
"retention_risk": "niedrig",
"expires_in_days": 0,
"origin_evidence": "258 Browser-Request(s) · document:1, font:5, image:21, script:217",
"origin_provider": "abo.mittelbayerische.de",
"retention_class": "short",
"retention_label": "kurz (0 Tage)",
"likely_essential": false,
"origin_script_url": "",
"origin_resource_type": ""
},
{
"name": "recently_compared_product_previous",
"domain": "abo.mittelbayerische.de",
"secure": true,
"sources": [
"browser_first_load"
],
"category": "unknown",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"http_only": false,
"same_site": "Lax",
"expires_at": "2026-06-19T21:06:01+00:00",
"long_lived": false,
"persistent": true,
"first_party": true,
"origin_host": "abo.mittelbayerische.de",
"pre_consent": true,
"source_label": "Chromium-Erstaufruf",
"category_label": "Unklar",
"retention_risk": "niedrig",
"expires_in_days": 0,
"origin_evidence": "258 Browser-Request(s) · document:1, font:5, image:21, script:217",
"origin_provider": "abo.mittelbayerische.de",
"retention_class": "short",
"retention_label": "kurz (0 Tage)",
"likely_essential": false,
"origin_script_url": "",
"origin_resource_type": ""
},
{
"name": "recently_viewed_product",
"domain": "abo.mittelbayerische.de",
"secure": true,
"sources": [
"browser_first_load"
],
"category": "unknown",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"http_only": false,
"same_site": "Lax",
"expires_at": "2026-06-19T21:06:01+00:00",
"long_lived": false,
"persistent": true,
"first_party": true,
"origin_host": "abo.mittelbayerische.de",
"pre_consent": true,
"source_label": "Chromium-Erstaufruf",
"category_label": "Unklar",
"retention_risk": "niedrig",
"expires_in_days": 0,
"origin_evidence": "258 Browser-Request(s) · document:1, font:5, image:21, script:217",
"origin_provider": "abo.mittelbayerische.de",
"retention_class": "short",
"retention_label": "kurz (0 Tage)",
"likely_essential": false,
"origin_script_url": "",
"origin_resource_type": ""
},
{
"name": "recently_viewed_product_previous",
"domain": "abo.mittelbayerische.de",
"secure": true,
"sources": [
"browser_first_load"
],
"category": "unknown",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"http_only": false,
"same_site": "Lax",
"expires_at": "2026-06-19T21:06:01+00:00",
"long_lived": false,
"persistent": true,
"first_party": true,
"origin_host": "abo.mittelbayerische.de",
"pre_consent": true,
"source_label": "Chromium-Erstaufruf",
"category_label": "Unklar",
"retention_risk": "niedrig",
"expires_in_days": 0,
"origin_evidence": "258 Browser-Request(s) · document:1, font:5, image:21, script:217",
"origin_provider": "abo.mittelbayerische.de",
"retention_class": "short",
"retention_label": "kurz (0 Tage)",
"likely_essential": false,
"origin_script_url": "",
"origin_resource_type": ""
}
],
"score": 60,
"total": 13,
"status": "auffällig",
"summary": "13 Cookie(s) inventarisiert: 2 Tracking-/Werbe-Cookie(s), 0 Drittanbieter-Cookie(s), 1 langlebige Cookie(s), 0 sehr lange Laufzeit(en).",
"findings": [
{
"id": "long_lived_tracking_cookie",
"count": 1,
"title": "Langlebige Tracking-/Marketing-Cookies",
"public": true,
"category": "privacy",
"severity": "warning"
}
],
"categories": {
"unknown": 9,
"analytics": 2,
"necessary": 2
},
"tracking_count": 2,
"category_labels": {
"consent": "Consent",
"payment": "Zahlung",
"unknown": "Unklar",
"security": "Sicherheit",
"analytics": "Analytics",
"necessary": "Notwendig",
"functional": "Funktional",
"advertising": "Werbung"
},
"long_lived_count": 1,
"persistent_count": 13,
"first_party_count": 13,
"pre_consent_count": 13,
"retention_classes": {
"long": 1,
"short": 12
},
"third_party_count": 0,
"missing_secure_count": 2,
"retention_risk_count": 1,
"retention_risk_items": [
{
"name": "_pk_id.4.12ad",
"domain": "mittelbayerische.de",
"secure": false,
"sources": [
"browser_first_load"
],
"category": "analytics",
"provider": "Matomo",
"tracking": true,
"http_only": false,
"same_site": "Lax",
"expires_at": "2027-07-17T20:06:01+00:00",
"long_lived": true,
"persistent": true,
"first_party": true,
"origin_host": "abo.mittelbayerische.de",
"pre_consent": true,
"source_label": "Chromium-Erstaufruf",
"category_label": "Analytics",
"retention_risk": "hoch",
"expires_in_days": 392,
"origin_evidence": "Vom geprüften Host oder aus dem Browser-Erstaufruf abgeleitet.",
"origin_provider": "Matomo",
"retention_class": "long",
"retention_label": "lang (392 Tage)",
"likely_essential": false,
"origin_script_url": "",
"origin_resource_type": ""
}
],
"very_long_lived_count": 0,
"missing_samesite_count": 0,
"persistent_unknown_count": 0,
"long_lived_tracking_count": 1
},
"security_header_analysis": {
"color": "red",
"score": 34,
"checks": [
{
"ok": false,
"note": "Fehlt in der HTTP-Antwort.",
"label": "HSTS",
"value": "",
"header": "strict-transport-security",
"present": false,
"purpose": "Erzwingt HTTPS nach dem ersten sicheren Aufruf.",
"severity": "warning"
},
{
"ok": false,
"note": "Fehlt in der HTTP-Antwort.",
"label": "Content-Security-Policy",
"value": "",
"header": "content-security-policy",
"present": false,
"purpose": "Begrenzt Skript-, Frame- und Ressourcenquellen im Browser.",
"severity": "warning"
},
{
"ok": true,
"note": "",
"label": "X-Frame-Options",
"value": "SAMEORIGIN",
"header": "x-frame-options",
"present": true,
"purpose": "Reduziert Clickjacking-Risiken bei älteren Browsern.",
"severity": "warning"
},
{
"ok": true,
"note": "",
"label": "X-Content-Type-Options",
"value": "nosniff",
"header": "x-content-type-options",
"present": true,
"purpose": "Verhindert MIME-Sniffing bei Skripten und Stylesheets.",
"severity": "warning"
},
{
"ok": false,
"note": "Fehlt in der HTTP-Antwort.",
"label": "Referrer-Policy",
"value": "",
"header": "referrer-policy",
"present": false,
"purpose": "Begrenzt, welche URL-Informationen an Zielseiten weitergegeben werden.",
"severity": "info"
},
{
"ok": false,
"note": "Fehlt in der HTTP-Antwort.",
"label": "Permissions-Policy",
"value": "",
"header": "permissions-policy",
"present": false,
"purpose": "Begrenzt sensible Browser-Funktionen pro Seite.",
"severity": "info"
},
{
"ok": false,
"note": "Fehlt in der HTTP-Antwort.",
"label": "Cross-Origin-Opener-Policy",
"value": "",
"header": "cross-origin-opener-policy",
"present": false,
"purpose": "Isoliert Top-Level-Fenster und reduziert Cross-Origin-Seiteneffekte.",
"severity": "info"
},
{
"ok": false,
"note": "Fehlt in der HTTP-Antwort.",
"label": "Cross-Origin-Resource-Policy",
"value": "",
"header": "cross-origin-resource-policy",
"present": false,
"purpose": "Begrenzt, welche fremden Seiten Ressourcen einbetten dürfen.",
"severity": "info"
},
{
"ok": false,
"note": "Fehlt in der HTTP-Antwort.",
"label": "Cross-Origin-Embedder-Policy",
"value": "",
"header": "cross-origin-embedder-policy",
"present": false,
"purpose": "Erzwingt kontrollierte Cross-Origin-Einbettungen und kann Cross-Origin Isolation ermöglichen.",
"severity": "info"
}
],
"status": "kritisch",
"missing": [
"HSTS",
"Content-Security-Policy",
"Referrer-Policy",
"Permissions-Policy",
"Cross-Origin-Opener-Policy",
"Cross-Origin-Resource-Policy",
"Cross-Origin-Embedder-Policy"
],
"summary": "2 von 9 wichtigen Security-Headern vorhanden, 2 korrekt bewertet. CSP nur Report-Only mit 14 Direktive(n), 2 Warnung(en), 2 Hinweis(e).",
"findings": [
{
"id": "csp_report_only_only",
"title": "CSP nur im Report-Only-Modus",
"public": true,
"category": "security_headers",
"severity": "info"
},
{
"id": "csp_unsafe_inline",
"title": "CSP erlaubt unsafe-inline für Skripte",
"public": true,
"category": "security_headers",
"severity": "warning"
},
{
"id": "csp_unsafe_eval",
"title": "CSP erlaubt eval-nahe Skriptausführung",
"public": true,
"category": "security_headers",
"severity": "warning"
},
{
"id": "csp_permissive_script_sources",
"title": "CSP erlaubt sehr breite Skriptquellen",
"public": true,
"sources": [
"*.adobe.com",
"*.newrelic.com",
"*.nr-data.net",
"*.vimeocdn.com",
"*.youtube.com",
"*.avada.io",
"*.shopify.com",
"*.paypal.com"
],
"category": "security_headers",
"severity": "info"
}
],
"ok_count": 2,
"weak_count": 0,
"csp_analysis": {
"color": "red",
"score": 34,
"status": "kritisch",
"summary": "CSP nur Report-Only mit 14 Direktive(n), 2 Warnung(en), 2 Hinweis(e).",
"enforced": false,
"findings": [
{
"id": "csp_report_only_only",
"title": "CSP nur im Report-Only-Modus",
"public": true,
"category": "security_headers",
"severity": "info"
},
{
"id": "csp_unsafe_inline",
"title": "CSP erlaubt unsafe-inline für Skripte",
"public": true,
"category": "security_headers",
"severity": "warning"
},
{
"id": "csp_unsafe_eval",
"title": "CSP erlaubt eval-nahe Skriptausführung",
"public": true,
"category": "security_headers",
"severity": "warning"
},
{
"id": "csp_permissive_script_sources",
"title": "CSP erlaubt sehr breite Skriptquellen",
"public": true,
"sources": [
"*.adobe.com",
"*.newrelic.com",
"*.nr-data.net",
"*.vimeocdn.com",
"*.youtube.com",
"*.avada.io",
"*.shopify.com",
"*.paypal.com"
],
"category": "security_headers",
"severity": "info"
}
],
"available": true,
"directives": [
{
"name": "base-uri",
"value": "'self' 'unsafe-inline'",
"values": [
"'self'",
"'unsafe-inline'"
]
},
{
"name": "child-src",
"value": "assets.braintreegateway.com c.paypal.com *.paypal.com http: https: blob: 'self' 'unsafe-inline'",
"values": [
"assets.braintreegateway.com",
"c.paypal.com",
"*.paypal.com",
"http:",
"https:",
"blob:",
"'self'",
"'unsafe-inline'"
]
},
{
"name": "connect-src",
"value": "dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.googleadservices.com analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net vimeo.com geostag.cardinalcommerce.com geo.cardinalcomme",
"values": [
"dpm.demdex.net",
"amcglobal.sc.omtrdc.net",
"www.google-analytics.com",
"www.googleadservices.com",
"analytics.google.com",
"www.googletagmanager.com",
"*.newrelic.com",
"*.nr-data.net",
"vimeo.com",
"geostag.cardinalcommerce.com",
"geo.cardinalcommerce.com",
"1eafstag.cardinalcommerce.com",
"1eaf.cardinalcommerce.com",
"centinelapistag.cardinalcommerce.com",
"centinelapi.cardinalcommerce.com",
"www.sandbox.paypal.com"
]
},
{
"name": "default-src",
"value": "'self' 'unsafe-inline' 'unsafe-eval'",
"values": [
"'self'",
"'unsafe-inline'",
"'unsafe-eval'"
]
},
{
"name": "font-src",
"value": "fonts.gstatic.com *.fontawesome.com https://fonts.bunny.net data: 'self' 'unsafe-inline'",
"values": [
"fonts.gstatic.com",
"*.fontawesome.com",
"https://fonts.bunny.net",
"data:",
"'self'",
"'unsafe-inline'"
]
},
{
"name": "form-action",
"value": "geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com pilot-payflowlink.paypal.com www.paypal.",
"values": [
"geostag.cardinalcommerce.com",
"geo.cardinalcommerce.com",
"1eafstag.cardinalcommerce.com",
"1eaf.cardinalcommerce.com",
"centinelapistag.cardinalcommerce.com",
"centinelapi.cardinalcommerce.com",
"pilot-payflowlink.paypal.com",
"www.paypal.com",
"www.sandbox.paypal.com",
"*.cardinalcommerce.com",
"*.paypal.com",
"3ds-secure.cardcomplete.com",
"www.clicksafe.lloydstsb.com",
"pay.activa-card.com",
"*.wirecard.com",
"acs.sia.eu"
]
},
{
"name": "frame-ancestors",
"value": "'self'",
"values": [
"'self'"
]
},
{
"name": "frame-src",
"value": "fast.amc.demdex.net *.adobe.com bid.g.doubleclick.net *.youtube.com *.youtube-nocookie.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.car",
"values": [
"fast.amc.demdex.net",
"*.adobe.com",
"bid.g.doubleclick.net",
"*.youtube.com",
"*.youtube-nocookie.com",
"geostag.cardinalcommerce.com",
"geo.cardinalcommerce.com",
"1eafstag.cardinalcommerce.com",
"1eaf.cardinalcommerce.com",
"centinelapistag.cardinalcommerce.com",
"centinelapi.cardinalcommerce.com",
"www.paypal.com",
"www.sandbox.paypal.com",
"pilot-payflowlink.paypal.com",
"player.vimeo.com",
"https://www.google.com/recaptcha/"
]
},
{
"name": "img-src",
"value": "assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net www.google.com bid",
"values": [
"assets.adobedtm.com",
"amcglobal.sc.omtrdc.net",
"dpm.demdex.net",
"cm.everesttech.net",
"*.adobe.com",
"widgets.magentocommerce.com",
"data:",
"www.googleadservices.com",
"www.google-analytics.com",
"googleads.g.doubleclick.net",
"www.google.com",
"bid.g.doubleclick.net",
"analytics.google.com",
"www.googletagmanager.com",
"*.ftcdn.net",
"*.behance.net"
]
},
{
"name": "manifest-src",
"value": "'self' 'unsafe-inline'",
"values": [
"'self'",
"'unsafe-inline'"
]
},
{
"name": "media-src",
"value": "*.adobe.com 'self' 'unsafe-inline'",
"values": [
"*.adobe.com",
"'self'",
"'unsafe-inline'"
]
},
{
"name": "object-src",
"value": "'self' 'unsafe-inline'",
"values": [
"'self'",
"'unsafe-inline'"
]
},
{
"name": "script-src",
"value": "assets.adobedtm.com *.adobe.com www.googleadservices.com www.google-analytics.com googleads.g.doubleclick.net analytics.google.com www.googletagmanager.com *.newrelic.com *.nr-data.net geostag.cardinalcommerce.com 1eafst",
"values": [
"assets.adobedtm.com",
"*.adobe.com",
"www.googleadservices.com",
"www.google-analytics.com",
"googleads.g.doubleclick.net",
"analytics.google.com",
"www.googletagmanager.com",
"*.newrelic.com",
"*.nr-data.net",
"geostag.cardinalcommerce.com",
"1eafstag.cardinalcommerce.com",
"geoapi.cardinalcommerce.com",
"1eafapi.cardinalcommerce.com",
"songbird.cardinalcommerce.com",
"includestest.ccdc02.com",
"www.paypal.com"
]
},
{
"name": "style-src",
"value": "*.adobe.com fonts.googleapis.com *.fontawesome.com https://fonts.bunny.net unsafe-inline assets.braintreegateway.com 'self' 'unsafe-inline'",
"values": [
"*.adobe.com",
"fonts.googleapis.com",
"*.fontawesome.com",
"https://fonts.bunny.net",
"unsafe-inline",
"assets.braintreegateway.com",
"'self'",
"'unsafe-inline'"
]
}
],
"info_count": 2,
"report_only": true,
"finding_count": 4,
"warning_count": 2
},
"missing_count": 7,
"present_count": 2,
"missing_info_count": 5,
"missing_warning_count": 2
},
"infrastructure_analysis": {
"signals": {
"caa": true,
"dnssec": true,
"final_https": true,
"tls_version": "TLSv1.3",
"hsts_enabled": false,
"address_count": 12,
"ipv6_available": true,
"email_protection": {
"mx": true,
"spf": false,
"dmarc": false
},
"certificate_valid": true,
"certificate_issuer": "Amazon RSA 2048 M04",
"certificate_alt_names": [
"*.mittelbayerische.de",
"*.pnp.de",
"*.donaukurier.de",
"*.m2-prod.mol-servers.de"
],
"multiple_ip_addresses": true,
"certificate_expires_at": "Dec 29 23:59:59 2026 GMT",
"certificate_days_remaining": 193,
"certificate_hostname_matches": true
},
"findings": [
{
"id": "dmarc_missing",
"title": "DMARC fehlt",
"public": true,
"category": "email",
"severity": "info"
}
],
"risk_level": "low",
"positive_signals": [
"Mehrere IP-Adressen gefunden: Hinweis auf redundante Infrastruktur oder CDN.",
"IPv6 ist vorhanden.",
"Moderne TLS-Version aktiv: TLSv1.3.",
"CAA-Records begrenzen Zertifikatsaussteller."
]
},
"performance_analysis": {
"score": 100,
"signals": {
"compressed": false,
"duration_ms": 1086,
"image_count": 15,
"script_count": 5,
"cache_control": "max-age=0, must-revalidate, no-cache, no-store",
"content_length": 0,
"viewport_found": true,
"stylesheet_count": 3
},
"findings": [],
"risk_level": "low"
},
"accessibility_analysis": {
"color": "yellow",
"score": 76,
"status": "prüfen",
"signals": {
"h1_count": 1,
"image_count": 15,
"button_count": 2,
"heading_count": 1,
"viewport_found": true,
"html_lang_found": true,
"form_field_count": 2,
"image_missing_alt_count": 6,
"buttons_without_name_count": 0,
"form_fields_without_label_count": 0
},
"summary": "15 Bild(er), 2 Formularfeld(er), 2 Button(s) im passiven HTML-Sample auf Basis-Barrierefreiheit geprüft.",
"findings": [
{
"id": "image_alt_missing",
"count": 6,
"title": "Bilder ohne Alternativtext",
"public": true,
"category": "accessibility",
"severity": "info",
"evidence_items": [
"https://abo.mittelbayerische.de/media/.renditions/wysiwyg/home/MZ/MZ_iMac_iPad_iPhone_1200x673.png",
"https://abo.mittelbayerische.de/media/.renditions/wysiwyg/home/MZ/MZ_3_Zeitungen_gefaltet_1200_x_673pix.png",
"https://abo.mittelbayerische.de/media/.renditions/wysiwyg/home/teaser-support-image.png",
"https://abo.mittelbayerische.de/media/wysiwyg/home/phone.svg",
"https://abo.mittelbayerische.de/media/wysiwyg/home/mail.svg",
"https://abo.mittelbayerische.de/media/wysiwyg/home/faq.svg"
]
}
],
"wcag_matrix": {
"rows": [
{
"id": "wcag_non_text_content",
"ok": false,
"wcag": "WCAG 1.1.1 Non-text Content",
"title": "Alternativtexte für Bilder",
"impact": "mittel",
"status": "prüfen",
"evidence": "6 von 15 Bild(er) ohne alt-Text im HTML-Sample."
},
{
"id": "wcag_form_labels",
"ok": true,
"wcag": "WCAG 1.3.1 Info and Relationships / 3.3.2 Labels or Instructions",
"title": "Formularfelder beschriften",
"impact": "niedrig",
"status": "ok",
"evidence": "0 von 2 Formularfeld(er) ohne erkennbare Beschriftung."
},
{
"id": "wcag_button_names",
"ok": true,
"wcag": "WCAG 4.1.2 Name, Role, Value",
"title": "Buttons mit Namen versehen",
"impact": "niedrig",
"status": "ok",
"evidence": "0 von 2 Button(s) ohne erkennbaren Namen."
},
{
"id": "wcag_page_language",
"ok": true,
"wcag": "WCAG 3.1.1 Language of Page",
"title": "Seitensprache auszeichnen",
"impact": "niedrig",
"status": "ok",
"evidence": "HTML-lang-Attribut gefunden."
},
{
"id": "wcag_heading_structure",
"ok": true,
"wcag": "WCAG 1.3.1 Info and Relationships / 2.4.6 Headings and Labels",
"title": "Überschriftenstruktur",
"impact": "niedrig",
"status": "ok",
"evidence": "1 H1 und 1 Überschrift(en) im HTML-Sample."
},
{
"id": "wcag_mobile_reflow",
"ok": true,
"wcag": "WCAG 1.4.10 Reflow",
"title": "Mobile Viewport-Basis",
"impact": "niedrig",
"status": "ok",
"evidence": "Viewport-Meta-Tag gefunden."
}
],
"summary": "1 WCAG-/EAA-Prüfpunkt(e) auffällig, davon 0 mit hoher Auswirkung.",
"standard": "WCAG 2.2 orientierte Basisprüfung",
"available": true,
"issue_count": 1,
"high_impact_count": 0
}
},
"domain_history": {
"summary": "Domainhistorie konnte per RDAP nicht zuverlässig abgerufen werden.",
"findings": [],
"available": false,
"risk_level": "unknown"
},
"data_entry_analysis": {
"forms": [
{
"method": "GET",
"purpose": "Newsletter",
"data_types": [
{
"id": "newsletter",
"label": "Newsletter"
},
{
"id": "search",
"label": "Suche"
}
],
"field_count": 1
},
{
"method": "GET",
"purpose": "Newsletter",
"data_types": [
{
"id": "newsletter",
"label": "Newsletter"
},
{
"id": "search",
"label": "Suche"
}
],
"field_count": 1
},
{
"url": "https://abo.mittelbayerische.de/customer/account",
"path": "/customer/account",
"method": "UNBEKANNT",
"source": "crawl",
"purpose": "Login-Formular",
"data_types": [
{
"id": "login",
"label": "Login/Passwort"
}
],
"field_count": 0
},
{
"url": "https://abo.mittelbayerische.de/checkout/cart",
"path": "/checkout/cart",
"method": "UNBEKANNT",
"source": "crawl",
"purpose": "Formular",
"data_types": [],
"field_count": 0
},
{
"url": "https://abo.mittelbayerische.de/",
"path": "/",
"method": "UNBEKANNT",
"source": "crawl",
"purpose": "Formular",
"data_types": [],
"field_count": 0
},
{
"url": "https://abo.mittelbayerische.de/abos",
"path": "/abos",
"method": "UNBEKANNT",
"source": "crawl",
"purpose": "Formular",
"data_types": [],
"field_count": 0
},
{
"purpose": "Login-Formular",
"field_count": 0,
"source": "crawl",
"path": "/customer/account",
"url": "https://abo.mittelbayerische.de/customer/account"
},
{
"purpose": "Formular",
"field_count": 0,
"source": "crawl",
"path": "/checkout/cart",
"url": "https://abo.mittelbayerische.de/checkout/cart"
},
{
"purpose": "Formular",
"field_count": 0,
"source": "crawl",
"path": "/",
"url": "https://abo.mittelbayerische.de/"
},
{
"purpose": "Formular",
"field_count": 0,
"source": "crawl",
"path": "/abos",
"url": "https://abo.mittelbayerische.de/abos"
}
],
"score": 84,
"summary": "Crawl fand 8 Formular(e) auf 4 geprüften Seite(n), u. a. /customer/account, /checkout/cart, /, /abos.",
"findings": [],
"form_count": 8,
"risk_level": "medium",
"field_count": 2,
"asks_for_data": true,
"crawl_form_pages": [
{
"url": "https://abo.mittelbayerische.de/customer/account",
"path": "/customer/account",
"category": "login",
"form_count": 2
},
{
"url": "https://abo.mittelbayerische.de/checkout/cart",
"path": "/checkout/cart",
"category": "checkout",
"form_count": 2
},
{
"url": "https://abo.mittelbayerische.de/",
"path": "/",
"category": "newsletter",
"form_count": 2
},
{
"url": "https://abo.mittelbayerische.de/abos",
"path": "/abos",
"category": "newsletter",
"form_count": 2
}
],
"payment_providers": [],
"detected_data_types": [
{
"id": "newsletter",
"count": 3,
"label": "Newsletter"
},
{
"id": "payment",
"count": 1,
"label": "Zahlung"
},
{
"id": "contact",
"count": 1,
"label": "Kontaktformular"
},
{
"id": "login",
"count": 1,
"label": "Login/Passwort"
}
],
"crawl_form_page_count": 4,
"privacy_context_found": true,
"operator_context_found": true
},
"pii_exposure_analysis": {
"color": "orange",
"score": 74,
"checks": [
{
"id": "current_url",
"ok": true,
"count": 0,
"label": "Aktuelle URL",
"detail": "Keine sensiblen Query-Parameter erkannt."
},
{
"id": "link_queries",
"ok": false,
"count": 2,
"label": "Link-Parameter",
"detail": "2 Link(s) mit sensiblen Parametern."
},
{
"id": "get_forms",
"ok": true,
"count": 0,
"label": "GET-Formulare",
"detail": "Keine personenbezogenen GET-Formulare erkannt."
},
{
"id": "external_forms",
"ok": true,
"count": 0,
"label": "Externe Formularziele",
"detail": "Keine externen Formularziele mit personenbezogenen Feldern erkannt."
},
{
"id": "tracking_context",
"ok": false,
"count": 2,
"label": "Tracking neben Dateneingabe",
"detail": "2 datenschutzrelevante Drittanbieter."
}
],
"status": "auffällig",
"summary": "2 PII-/Datenleck-Hinweis(e) aus URL-, Formular- und Browserkontext.",
"findings": [
{
"id": "pii_sensitive_link_query",
"links": [
{
"href": "https://sso.pnp.de/OAuthLogin.php",
"params": [
"client_id"
],
"external": true
},
{
"href": "https://sso.pnp.de/OAuthLogin.php",
"params": [
"client_id"
],
"external": true
}
],
"title": "Links mit sensiblen Query-Parametern erkannt",
"public": true,
"category": "privacy",
"severity": "info"
},
{
"id": "pii_tracking_on_data_entry_page",
"title": "Dateneingabe und datenschutzrelevante Drittanbieter im selben Browseraufruf",
"public": true,
"category": "privacy",
"severity": "warning",
"third_party_count": 2
}
],
"link_hits": [
{
"href": "https://sso.pnp.de/OAuthLogin.php",
"params": [
"client_id"
],
"external": true
},
{
"href": "https://sso.pnp.de/OAuthLogin.php",
"params": [
"client_id"
],
"external": true
}
],
"finding_count": 2,
"current_url_hits": [],
"tracking_context": true,
"sensitive_get_forms": []
},
"scan_history_analysis": {
"available": false,
"summary": "Noch kein früherer gespeicherter Scan für diese Domain vorhanden.",
"total_scan_count": 1,
"previous_scan_count": 0,
"history": [
{
"scan_id": "60edf869-3cd6-4753-a588-81984c8c8d87",
"created_at": "2026-06-19 22:06:30.238058+02",
"score": 54,
"verdict": "auffällig",
"finding_count": 34,
"integrity_root_hash": "7beb9f452d10b8a6053ede2fcf50ffd17c0112ab857ff2879289c57e65860a0e",
"integrity_available_hash_count": 9,
"current": true
}
],
"new_findings": [],
"resolved_findings": [],
"technical_changes": {
"available": false,
"summary": "Noch kein früherer Scan für technische Änderungen vorhanden."
}
},
"benchmark_analysis": {
"host": "abo.mittelbayerische.de",
"rank": 1,
"score": 54,
"status": "im_mittelfeld",
"summary": "abo.mittelbayerische.de liegt mit 54 Punkten ungefähr im gespeicherten Vergleichsfeld.",
"available": true,
"peer_count": 7808,
"percentile": 0,
"query_mode": "php_ttl_cache_refresh",
"distribution": {
"0_39": 1241,
"40_59": 3170,
"60_79": 3380,
"80_100": 17
},
"median_score": 58,
"average_score": 52.7,
"comparison_basis": "Neuester gespeicherter SaferPage-Scan je Domain; überwiegend deutschsprachige gespeicherte Checks.",
"same_score_count": 0,
"better_than_count": 0,
"qualified_peer_count": 7505,
"zero_score_count": 303,
"top_quartile_score": 64,
"top_decile_score": 68,
"qualified_average_score": 54.9,
"qualified_median_score": 59,
"qualified_top_quartile_score": 65,
"qualified_top_decile_score": 68,
"thresholds": [
{
"id": "critical",
"label": "Kritisch",
"range": "0-39",
"met": false
},
{
"id": "basic",
"label": "Basis stabilisieren",
"range": "40-59",
"met": true
},
{
"id": "managed",
"label": "Gesteuert",
"range": "60-79",
"met": false
},
{
"id": "strong",
"label": "Stark",
"range": "80-100",
"met": false
}
],
"risk_tier": "basis",
"target_score": 60,
"aspirational_target_score": 68,
"gap_to_target": 6,
"gap_to_top_quartile": 11,
"gap_to_strong": 26,
"cache_ttl_seconds": 300
},
"audit_receipt": {
"url": "https://abo.mittelbayerische.de/",
"host": "abo.mittelbayerische.de",
"status": "verfügbar",
"bot_url": "https://saferpage.de/bot",
"summary": "Prüfbeleg für abo.mittelbayerische.de: kontrollierter HTTP-/Browser-Kurzcheck mit 275 Request(s), 4 Consent-Zustand/Zuständen und 7 Artefakt(en).",
"renderer": "playwright-chromium",
"artifacts": [
{
"label": "Öffentlicher Kurzreport",
"detail": "https://saferpage.de/abo.mittelbayerische.de",
"status": "verfügbar"
},
{
"label": "JSON-Export",
"detail": "Maschinenlesbarer Report mit Modulen, Nachweisen und Tabellen.",
"status": "verfügbar"
},
{
"label": "CSV-Export",
"detail": "Tabellarische Prüfzeilen für Betreiber, Datenschutz und Technik.",
"status": "verfügbar"
},
{
"label": "160x150 Seitenvorschau",
"detail": "/cache/screenshots/abo.mittelbayerische.de-160x150-e3e8d325a998e4a2f8.png",
"status": "verfügbar"
},
{
"label": "Cookie-Erklärung",
"detail": "29 Cookie-/Storage-Eintrag/Einträge.",
"status": "auffällig"
},
{
"label": "Empfänger-/Anbieterinventar",
"detail": "8 Anbieterzeile(n), 7 AVV-/Rollenprüfung(en).",
"status": "kritisch"
},
{
"label": "Barrierefreiheitserklärung-Entwurf",
"detail": "1 bekannte Barrierefreiheits-Punkt(e).",
"status": "Teilweise konform im automatischen Basischeck"
}
],
"available": true,
"final_url": "https://abo.mittelbayerische.de/abos",
"checked_at": "2026-06-19T20:06:29+00:00",
"share_text": "SaferPage Prüfbeleg abo.mittelbayerische.de: 275 Browser-Request(s), 8 Drittanbieter, 29 Cookie-/Storage-Einträge, geprüft am 2026-06-19T20:06:29.",
"user_agent": "SaferPageCrawler/0.3 (+https://saferpage.de/bot; schedules passive DACH website checks; report examples: https://saferpage.de/tests; kostenloser Report: <a href=\"https://saferpage.de/abo.mittelbayerische.de\">https://saferpage.de/abo.mittelbayerische.de</a>)",
"limitations": [
"Öffentliche Nachweise enthalten keine Cookie-Werte und keine vollständigen Request-URLs.",
"Der Scan ist ein passiver Browser- und HTTP-Kurzcheck; rechtliche Bewertung bleibt Betreiberaufgabe.",
"Dynamische Inhalte können sich je nach Region, Zeit, Gerät und Consent-Auswahl ändern."
],
"scan_context": "crawler",
"coverage_items": [
{
"label": "HTTP/DNS/TLS",
"value": "HTTP 200 · DNS ok · TLS ok"
},
{
"label": "Browserlauf",
"value": "275 Request(s), 8 Drittanbieter-Domain(s), 13 Browser-Cookie(s)."
},
{
"label": "Consent-Zustände",
"value": "4 Zustand/Zustände: Default, Ablehnen, Akzeptieren und GPC soweit verfügbar."
},
{
"label": "Seitenabdeckung",
"value": "8 priorisierte Unterseite(n) im Nachweispack."
},
{
"label": "Drittanbieter-Auszug",
"value": "8 Anbieterzeile(n) im öffentlichen Nachweis."
},
{
"label": "Cookie-Auszug",
"value": "12 Cookie-Zeile(n) im öffentlichen Nachweis."
}
],
"confidence_score": 46,
"browser_final_url": "https://abo.mittelbayerische.de/abos"
},
"evidence_integrity_manifest": {
"host": "abo.mittelbayerische.de",
"status": "verfügbar",
"summary": "Integritätsmanifest für abo.mittelbayerische.de: 9/9 Nachweisbereich(e) mit SHA-256-Hash dokumentiert.",
"sections": [
{
"id": "audit_receipt",
"hash": "c97249f507611f4fdd5fd6b2eaa59c2f5cb0b9b32fead57353df270b7b1d21d0",
"count": 18,
"label": "Prüfbeleg",
"detail": "Kanonischer JSON-Hash des kompakten Prüfbelegs.",
"status": "verfügbar"
},
{
"id": "protocol",
"hash": "e372d9e9db6ccb8dee79575094d177d85792cbc91279cbbbeea76269246b3b8f",
"count": 15,
"label": "Scan-Protokoll",
"detail": "URL, Endziel, User-Agent, Zeitstempel, HTTP/DNS/TLS und Renderer.",
"status": "verfügbar"
},
{
"id": "checkpoints",
"hash": "d5dc330907018965b4ee50d0fbe9e491ec625cccb9ee2e0a46d6d21fa4029c83",
"count": 6,
"label": "Prüfschritte",
"detail": "Kanonischer JSON-Hash der dokumentierten Prüfstationen.",
"status": "verfügbar"
},
{
"id": "consent_states",
"hash": "c537e04961d99b29307b946d16d334af58b524a333d1776ef4c0a78c5e7d0ebd",
"count": 4,
"label": "Consent-Zustände",
"detail": "Default-, Ablehnen-, Akzeptieren- und GPC-Nachweise soweit verfügbar.",
"status": "verfügbar"
},
{
"id": "third_party_evidence",
"hash": "f38b3a21f50c9998a053d6eb4eb6190eb0acc77da736f0c29d3908a97fdf7209",
"count": 8,
"label": "Drittanbieter-Auszug",
"detail": "Sanitisierte Anbieter-, Kategorie-, Transfer- und Request-Zählwerte.",
"status": "verfügbar"
},
{
"id": "cookie_evidence",
"hash": "7050f65ede0776df210a1efaa19a8606df8c43ccae56613771356759cd958563",
"count": 12,
"label": "Cookie-Auszug",
"detail": "Sanitisierte Cookie-Metadaten ohne Cookie-Werte.",
"status": "verfügbar"
},
{
"id": "request_samples",
"hash": "9e69aa4966c81997fb98a72379c857bed9065a43ac3b84c4ca08be4a34b9191a",
"count": 10,
"label": "Request-Samples",
"detail": "Sanitisierte Drittanbieter-Samples ohne vollständige Request-URLs.",
"status": "verfügbar"
},
{
"id": "checked_pages",
"hash": "568b1827f6dd079cc6378afa56eaa708c801070ea21e612bb33ca527755d08d0",
"count": 8,
"label": "Geprüfte Unterseiten",
"detail": "Priorisierte Pfade aus Sitemap, Pflichtseiten und interner Linkstruktur.",
"status": "verfügbar"
},
{
"id": "screenshot_file",
"hash": "3b1ef12c98305bf5bb53894b212e42acaabbeba846aeff6f4584e8c1e1499a93",
"count": 10578,
"label": "160x150 Seitenvorschau-Datei",
"detail": "/cache/screenshots/abo.mittelbayerische.de-160x150-e3e8d325a998e4a2f8.png",
"status": "verfügbar"
}
],
"algorithm": "sha256",
"available": true,
"root_hash": "7beb9f452d10b8a6053ede2fcf50ffd17c0112ab857ff2879289c57e65860a0e",
"checked_at": "2026-06-19T20:06:29+00:00",
"limitations": [
"Das Manifest schützt die im Report veröffentlichten/sanitisierten Nachweise, nicht verdeckte Cookie-Werte oder vollständige Request-URLs.",
"Ohne externe qualifizierte Zeitstempelung beweist der Hash Integrität des exportierten Artefakts, aber keine amtliche Zustellung."
],
"section_count": 9,
"canonicalization": "JSON UTF-8, sort_keys=true, kompakte Separatoren; Screenshot als rohe Datei-Bytes.",
"available_hash_count": 9
},
"audit_evidence_pack": {
"status": "verfügbar",
"summary": "Nachweisprotokoll mit 275 Browser-Request(s), 12 Cookie-Nachweis(en), 8 Drittanbieter-Auszug/auszügen und 4 Consent-Zustand/Zuständen.",
"protocol": {
"host": "abo.mittelbayerische.de",
"dns_ok": true,
"tls_ok": true,
"bot_url": "https://saferpage.de/bot",
"renderer": "playwright-chromium",
"final_url": "https://abo.mittelbayerische.de/abos",
"input_url": "https://abo.mittelbayerische.de/",
"checked_at": "2026-06-19T20:06:29+00:00",
"user_agent": "SaferPageCrawler/0.3 (+https://saferpage.de/bot; schedules passive DACH website checks; report examples: https://saferpage.de/tests; kostenloser Report: <a href=\"https://saferpage.de/abo.mittelbayerische.de\">https://saferpage.de/abo.mittelbayerische.de</a>)",
"http_status": 200,
"scan_context": "crawler",
"screenshot_url": "/cache/screenshots/abo.mittelbayerische.de-160x150-e3e8d325a998e4a2f8.png",
"googlebot_status": 200,
"browser_final_url": "https://abo.mittelbayerische.de/abos",
"dns_address_count": 12
},
"checkpoints": [
{
"label": "DNS",
"detail": "12 Adresse(n) aufgelöst.",
"status": "ok"
},
{
"label": "TLS/HTTPS",
"detail": "TLSv1.3",
"status": "ok"
},
{
"label": "HTTP-Abruf",
"detail": "Status 200, Endziel https://abo.mittelbayerische.de/abos.",
"status": "ok"
},
{
"label": "Browserlauf",
"detail": "275 Request(s), 8 Drittanbieter-Domain(s).",
"status": "ok"
},
{
"label": "Consent-Zustände",
"detail": "Default, Ablehnen, Akzeptieren und GPC werden soweit möglich gegenübergestellt.",
"status": "prüfen"
},
{
"label": "Exports",
"detail": "PDF/Druck, JSON und CSV enthalten die wesentlichen Prüfnachweise.",
"status": "verfügbar"
}
],
"limitations": [
"Öffentliche Nachweise enthalten keine Cookie-Werte und keine vollständigen Request-URLs.",
"Der Scan ist ein passiver Browser- und HTTP-Kurzcheck; rechtliche Bewertung bleibt Betreiberaufgabe.",
"Dynamische Inhalte können sich je nach Region, Zeit, Gerät und Consent-Auswahl ändern."
],
"checked_pages": [
{
"path": "/customer/account",
"source": "homepage_link",
"status": 0,
"category": "login"
},
{
"path": "/checkout/cart",
"source": "homepage_link",
"status": 0,
"category": "checkout"
},
{
"path": "/",
"source": "homepage_link",
"status": 0,
"category": "newsletter"
},
{
"path": "/abos",
"source": "homepage_link",
"status": 0,
"category": "newsletter"
},
{
"path": "/abos/aktions-abo",
"source": "homepage_link",
"status": 0,
"category": "newsletter"
},
{
"path": "/abos/digital",
"source": "homepage_link",
"status": 0,
"category": "newsletter"
},
{
"path": "/abos/gedruckt",
"source": "homepage_link",
"status": 0,
"category": "newsletter"
},
{
"path": "/abos/geschenk-abo",
"source": "homepage_link",
"status": 0,
"category": "newsletter"
}
],
"cookie_evidence": [
{
"name": "_pk_id.4.12ad",
"domain": "mittelbayerische.de",
"secure": false,
"category": "Analytics",
"provider": "Matomo",
"tracking": true,
"retention": "lang (392 Tage)",
"same_site": "Lax",
"pre_consent": true
},
{
"name": "_pk_ses.4.12ad",
"domain": "mittelbayerische.de",
"secure": false,
"category": "Analytics",
"provider": "Matomo",
"tracking": true,
"retention": "kurz (0 Tage)",
"same_site": "Lax",
"pre_consent": true
},
{
"name": "PHPSESSID",
"domain": "abo.mittelbayerische.de",
"secure": true,
"category": "Notwendig",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"retention": "kurz (0 Tage)",
"same_site": "Lax",
"pre_consent": true
},
{
"name": "mage-cache-sessid",
"domain": "abo.mittelbayerische.de",
"secure": true,
"category": "Notwendig",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"retention": "kurz (0 Tage)",
"same_site": "Lax",
"pre_consent": true
},
{
"name": "form_key",
"domain": "abo.mittelbayerische.de",
"secure": true,
"category": "Unklar",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"retention": "kurz (0 Tage)",
"same_site": "Lax",
"pre_consent": true
},
{
"name": "mage-cache-storage",
"domain": "abo.mittelbayerische.de",
"secure": true,
"category": "Unklar",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"retention": "kurz (0 Tage)",
"same_site": "Lax",
"pre_consent": true
},
{
"name": "mage-cache-storage-section-invalidation",
"domain": "abo.mittelbayerische.de",
"secure": true,
"category": "Unklar",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"retention": "kurz (0 Tage)",
"same_site": "Lax",
"pre_consent": true
},
{
"name": "mage-messages",
"domain": "abo.mittelbayerische.de",
"secure": true,
"category": "Unklar",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"retention": "kurz (0 Tage)",
"same_site": "Strict",
"pre_consent": true
},
{
"name": "product_data_storage",
"domain": "abo.mittelbayerische.de",
"secure": true,
"category": "Unklar",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"retention": "kurz (0 Tage)",
"same_site": "Lax",
"pre_consent": true
},
{
"name": "recently_compared_product",
"domain": "abo.mittelbayerische.de",
"secure": true,
"category": "Unklar",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"retention": "kurz (0 Tage)",
"same_site": "Lax",
"pre_consent": true
},
{
"name": "recently_compared_product_previous",
"domain": "abo.mittelbayerische.de",
"secure": true,
"category": "Unklar",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"retention": "kurz (0 Tage)",
"same_site": "Lax",
"pre_consent": true
},
{
"name": "recently_viewed_product",
"domain": "abo.mittelbayerische.de",
"secure": true,
"category": "Unklar",
"provider": "abo.mittelbayerische.de",
"tracking": false,
"retention": "kurz (0 Tage)",
"same_site": "Lax",
"pre_consent": true
}
],
"browser_evidence": {
"gpc_enabled": true,
"request_count": 275,
"storage_total": 16,
"accept_clicked": false,
"reject_clicked": false,
"browser_cookie_count": 13,
"contacted_domain_count": 9,
"third_party_domain_count": 8,
"storage_tracking_hint_count": 0,
"privacy_relevant_domain_count": 2
},
"storage_evidence": {
"tracking_key_hints": [],
"local_storage_total": 9,
"session_storage_total": 7
},
"third_party_evidence": [
{
"host": "cdn.matomo.cloud",
"category": "Analytics",
"provider": "Matomo",
"transfer": "EU/EWR oder selbst gehostet",
"risk_level": "mittel",
"request_count": 1,
"resource_types": [
"script"
],
"privacy_relevant": true
},
{
"host": "pnpabo.matomo.cloud",
"category": "Analytics",
"provider": "Matomo",
"transfer": "EU/EWR oder selbst gehostet",
"risk_level": "mittel",
"request_count": 1,
"resource_types": [
"ping"
],
"privacy_relevant": true
},
{
"host": "cdn.opencmp.net",
"category": "Sonstige",
"provider": "cdn.opencmp.net",
"transfer": "Jurisdiktion unklar",
"risk_level": "niedrig",
"request_count": 8,
"resource_types": [
"fetch",
"script"
],
"privacy_relevant": false
},
{
"host": "cdntrf.com",
"category": "Sonstige",
"provider": "cdntrf.com",
"transfer": "Jurisdiktion unklar",
"risk_level": "niedrig",
"request_count": 2,
"resource_types": [
"xhr"
],
"privacy_relevant": false
},
{
"host": "d2wu036mkcz52n.cloudfront.net",
"category": "Sonstige",
"provider": "d2wu036mkcz52n.cloudfront.net",
"transfer": "Jurisdiktion unklar",
"risk_level": "niedrig",
"request_count": 2,
"resource_types": [
"image"
],
"privacy_relevant": false
},
{
"host": "files.upscore.com",
"category": "Sonstige",
"provider": "files.upscore.com",
"transfer": "Jurisdiktion unklar",
"risk_level": "niedrig",
"request_count": 1,
"resource_types": [
"script"
],
"privacy_relevant": false
},
{
"host": "mbv.slgnt.eu",
"category": "Sonstige",
"provider": "mbv.slgnt.eu",
"transfer": "EU/EWR",
"risk_level": "niedrig",
"request_count": 1,
"resource_types": [
"script"
],
"privacy_relevant": false
},
{
"host": "npmtecpublic.s3.eu-central-1.amazonaws.com",
"category": "Sonstige",
"provider": "npmtecpublic.s3.eu-central-1.amazonaws.com",
"transfer": "Jurisdiktion unklar",
"risk_level": "niedrig",
"request_count": 1,
"resource_types": [
"image"
],
"privacy_relevant": false
}
],
"external_script_count": 1,
"consent_state_evidence": [
{
"label": "Erstaufruf",
"cookie_count": 0,
"domain_count": 8,
"request_count": 17,
"storage_tracking_hint_count": 0,
"privacy_relevant_domain_count": 2
},
{
"label": "Nach Ablehnen neu",
"cookie_count": 0,
"domain_count": 0,
"request_count": 0,
"storage_tracking_hint_count": 0,
"privacy_relevant_domain_count": 0
},
{
"label": "Nach Akzeptieren neu",
"cookie_count": 0,
"domain_count": 0,
"request_count": 0,
"storage_tracking_hint_count": 0,
"privacy_relevant_domain_count": 0
},
{
"label": "GPC-Aufruf",
"cookie_count": 0,
"domain_count": 8,
"request_count": 17,
"storage_tracking_hint_count": 0,
"privacy_relevant_domain_count": 2
}
],
"request_sample_evidence": [
{
"host": "cdn.opencmp.net",
"query_keys": [],
"resource_type": "script",
"query_key_count": 0,
"referrer_has_path": false,
"referrer_has_query": false,
"sensitive_query_key_count": 0
},
{
"host": "cdn.opencmp.net",
"query_keys": [],
"resource_type": "script",
"query_key_count": 0,
"referrer_has_path": false,
"referrer_has_query": false,
"sensitive_query_key_count": 0
},
{
"host": "cdn.matomo.cloud",
"query_keys": [],
"resource_type": "script",
"query_key_count": 0,
"referrer_has_path": false,
"referrer_has_query": false,
"sensitive_query_key_count": 0
},
{
"host": "mbv.slgnt.eu",
"query_keys": [],
"resource_type": "script",
"query_key_count": 0,
"referrer_has_path": false,
"referrer_has_query": false,
"sensitive_query_key_count": 0
},
{
"host": "files.upscore.com",
"query_keys": [],
"resource_type": "script",
"query_key_count": 0,
"referrer_has_path": false,
"referrer_has_query": false,
"sensitive_query_key_count": 0
},
{
"host": "pnpabo.matomo.cloud",
"query_keys": [
"action_name",
"idsite",
"rec",
"r",
"h",
"m",
"s",
"url"
],
"resource_type": "ping",
"query_key_count": 27,
"referrer_has_path": false,
"referrer_has_query": false,
"sensitive_query_key_count": 0
},
{
"host": "d2wu036mkcz52n.cloudfront.net",
"query_keys": [
"v",
"sr",
"vp",
"cd",
"md",
"h",
"t",
"d"
],
"resource_type": "image",
"query_key_count": 20,
"referrer_has_path": false,
"referrer_has_query": false,
"sensitive_query_key_count": 0
},
{
"host": "cdn.opencmp.net",
"query_keys": [],
"resource_type": "fetch",
"query_key_count": 0,
"referrer_has_path": false,
"referrer_has_query": false,
"sensitive_query_key_count": 0
},
{
"host": "cdntrf.com",
"query_keys": [],
"resource_type": "xhr",
"query_key_count": 0,
"referrer_has_path": false,
"referrer_has_query": false,
"sensitive_query_key_count": 0
},
{
"host": "cdntrf.com",
"query_keys": [],
"resource_type": "xhr",
"query_key_count": 0,
"referrer_has_path": false,
"referrer_has_query": false,
"sensitive_query_key_count": 0
}
]
},
"consent_visual_salience_evidence": {
"schema": "https://saferpage.de/schemas/consent-visual-salience-evidence.v1",
"status": "measured_dom_viewport_signal",
"available": true,
"evidence_level": "dom_viewport_signal_only",
"summary": "Der erste Headless-Chromium-Viewport liefert sichtbare Consent-Control-Signale mit Text, Position, Groesse und typografischen Hinweisen.",
"sample_status": "visible_controls_without_classified_samples",
"classified_sample_count": 0,
"accept_control_count": 0,
"reject_control_count": 0,
"settings_control_count": 0,
"visible_control_count": 14,
"accept_max_area": 0,
"reject_max_area": 0,
"reject_prominence_ratio": "nicht messbar",
"samples": [],
"sample_boundary": "Samples enthalten nur klassifizierte Accept-/Reject-/Settings-Controls. Weitere sichtbare Consent-Controls bleiben als Zaehler erhalten, werden aber ohne Klassifizierung nicht als Ablehnen-, Akzeptieren- oder Einstellungsprobe behauptet.",
"claim_boundary": "Consent-Visual-Salienz ist ein DOM-/Viewport-Signal aus dem ersten Browserlauf. Sie ist keine Rechtsbewertung, kein Dark-Pattern-Endurteil und kein Nachweis fuer spaetere Consent-Zustaende, Scrollbereiche, Loginbereiche oder manuelle Betreiberkontexte."
}
}