1,5 sLaufzeit
11Prüfgruppen
9nur im großen Scan
jaScreenshot
Browser-Erstaufruf
Welche Kontakte sah der Screenshot-Lauf?
287 Request(s) · 39 Drittanbieter-Domain(s) · 7 datenschutzrelevante Domain(s). Ablehnen-, Akzeptieren- und GPC-Zustände sind dem großen Scan vorbehalten.
cdn.shopify.comSonstige · 17 Request(s) · font, imagestatic.klaviyo.comSonstige · 13 Request(s) · scriptstatic-tracking.klaviyo.comSonstige · 10 Request(s) · scriptotlp-http-production.shopifysvc.comSonstige · 9 Request(s) · ping, fetchPayPalZahlung · 9 Request(s) · xhr, pingmonorail-edge.shopifysvc.comSonstige · 7 Request(s) · fetchGoogle Tag ManagerTag-Manager · 5 Request(s) · scriptGoogle FontsSchriften · 4 Request(s) · fontTikTokSocial/Tracking · 3 Request(s) · fetch, othershop.appSonstige · 3 Request(s) · fetch, script
Cookies im Erstaufruf
Was wurde vor einer Interaktion gespeichert?
20 Cookie(s) inventarisiert: 3 Tracking-/Werbe-Cookie(s), 2 Drittanbieter-Cookie(s), 14 langlebige Cookie(s), 0 sehr lange Laufzeit(en).
_fbpWerbung · First-Party · Meta/Facebook · ohne Secure, SameSite Lax, mittel (89 Tage), Laufzeitrisiko mittel · Chromium-Erstaufruf · Quelle: vespire.de · 168 Browser-Request(s) · document:5, fetch:20, font:3, image:33_gaAnalytics · First-Party · Google · ohne Secure, SameSite Lax, lang (399 Tage), Laufzeitrisiko hoch · Chromium-Erstaufruf · Quelle: vespire.de · 168 Browser-Request(s) · document:5, fetch:20, font:3, image:33_ga_FQKCNGXSYRAnalytics · First-Party · Google · ohne Secure, SameSite Lax, lang (399 Tage), Laufzeitrisiko hoch · Chromium-Erstaufruf · Quelle: vespire.de · 168 Browser-Request(s) · document:5, fetch:20, font:3, image:33cart_currencyNotwendig · First-Party · vespire.de · ohne Secure, SameSite Lax, kurz (13 Tage), Laufzeitrisiko niedrig · HTTP Set-Cookie, Chromium-Erstaufruf · Quelle: vespire.de · 168 Browser-Request(s) · document:5, fetch:20, font:3, image:33X-ABUnklar · Drittanbieter · sc-static.net · Secure, SameSite None, kurz (0 Tage), Laufzeitrisiko niedrig · Chromium-Erstaufruf · Quelle: sc-static.net · 1 Browser-Request(s) · other:1_shop_app_essentialUnklar · Drittanbieter · shop.app · Secure, SameSite None, lang (364 Tage), Laufzeitrisiko mittel · Chromium-Erstaufruf · Quelle: shop.app · 3 Browser-Request(s) · document:1, fetch:1, script:1__kla_idUnklar · First-Party · vespire.de · ohne Secure, SameSite Lax, lang (399 Tage), Laufzeitrisiko mittel · Chromium-Erstaufruf · Quelle: vespire.de · 168 Browser-Request(s) · document:5, fetch:20, font:3, image:33_gcl_auUnklar · First-Party · vespire.de · ohne Secure, SameSite Lax, mittel (89 Tage), Laufzeitrisiko niedrig · Chromium-Erstaufruf · Quelle: vespire.de · 168 Browser-Request(s) · document:5, fetch:20, font:3, image:33_scidUnklar · First-Party · vespire.de · ohne Secure, SameSite Lax, lang (395 Tage), Laufzeitrisiko mittel · Chromium-Erstaufruf · Quelle: vespire.de · 168 Browser-Request(s) · document:5, fetch:20, font:3, image:33_scid_rUnklar · First-Party · vespire.de · ohne Secure, SameSite Lax, lang (395 Tage), Laufzeitrisiko mittel · Chromium-Erstaufruf · Quelle: vespire.de · 168 Browser-Request(s) · document:5, fetch:20, font:3, image:33_scsrid_rUnklar · First-Party · vespire.de · ohne Secure, SameSite Lax, lang (395 Tage), Laufzeitrisiko mittel · Chromium-Erstaufruf · Quelle: vespire.de · 168 Browser-Request(s) · document:5, fetch:20, font:3, image:33_shopify_analyticsUnklar · First-Party · vespire.de · Secure, SameSite Lax, lang (364 Tage), Laufzeitrisiko mittel · HTTP Set-Cookie, Chromium-Erstaufruf · Quelle: vespire.de · 168 Browser-Request(s) · document:5, fetch:20, font:3, image:33
Technische Basis
Security-Header und Skriptquellen
4 von 6 Basis-Security-Headern vorhanden, 4 korrekt bewertet; 0 von 3 kontextabhängigen Isolations-Headern vorhanden. CSP wirksam mit 3 Direktive(n), 0 Warnung(en), 2 Hinweis(e).
HSTSok · max-age=7889238Content-Security-Policyok · block-all-mixed-content; frame-ancestors 'none'; upgrade-insecure-requests;X-Frame-Optionsok · DENYX-Content-Type-Optionsok · nosniffReferrer-PolicyfehltPermissions-PolicyfehltCross-Origin-Opener-PolicyfehltCross-Origin-Resource-PolicyfehltCross-Origin-Embedder-Policyfehlt
shop.appSonstige · shop.app · SRI fehltcdn.shopify.comSonstige · cdn.shopify.com · SRI vorhandenconfig.gorgias.chatSonstige · config.gorgias.chat · SRI fehltcontent.9gtb.comSonstige · content.9gtb.com · SRI fehltconfig.gorgias.helpSonstige · config.gorgias.help · SRI fehltcdn.shopify.comSonstige · cdn.shopify.com · SRI fehltcdn.shopify.comSonstige · cdn.shopify.com · SRI fehltstatic.klaviyo.comSonstige · static.klaviyo.com · SRI fehltcdn.shopify.comSonstige · cdn.shopify.com · SRI fehltcdn.shopify.comSonstige · cdn.shopify.com · SRI fehltGoogle TranslateÜbersetzung · translate.google.com · SRI fehltstatic-tracking.klaviyo.comSonstige · static-tracking.klaviyo.com · SRI fehlt