3,9 sLaufzeit
11Prüfgruppen
9nur im großen Scan
jaScreenshot
Browser-Erstaufruf
Welche Kontakte sah der Screenshot-Lauf?
286 Request(s) · 39 Drittanbieter-Domain(s) · 10 datenschutzrelevante Domain(s). Ablehnen-, Akzeptieren- und GPC-Zustände sind dem großen Scan vorbehalten.
static.klaviyo.comSonstige · 14 Request(s) · scriptcdn.shopify.comSonstige · 11 Request(s) · script, stylesheetstatic-tracking.klaviyo.comSonstige · 10 Request(s) · scriptGoogle Tag ManagerTag-Manager · 7 Request(s) · scriptspfy-pxl.archive-digger.comSonstige · 7 Request(s) · fetch, scriptotlp-http-production.shopifysvc.comSonstige · 5 Request(s) · ping, fetchgoogle.deSonstige · 4 Request(s) · fetch, imageGoogle AnalyticsAnalytics · 4 Request(s) · fetchTikTokSocial/Tracking · 3 Request(s) · fetch, otherMeta/FacebookSocial/Tracking · 3 Request(s) · script
Cookies im Erstaufruf
Was wurde vor einer Interaktion gespeichert?
12 Cookie(s) inventarisiert: 3 Tracking-/Werbe-Cookie(s), 2 Drittanbieter-Cookie(s), 8 langlebige Cookie(s), 0 sehr lange Laufzeit(en).
_fbpWerbung · First-Party · Meta/Facebook · ohne Secure, SameSite Lax, mittel (89 Tage), Laufzeitrisiko mittel · Chromium-Erstaufruf · Quelle: weearth.de · 159 Browser-Request(s) · document:5, fetch:9, font:5, image:29_gaAnalytics · First-Party · Google · ohne Secure, SameSite Lax, lang (399 Tage), Laufzeitrisiko hoch · Chromium-Erstaufruf · Quelle: weearth.de · 159 Browser-Request(s) · document:5, fetch:9, font:5, image:29_ga_YJ88MWS760Analytics · First-Party · Google · ohne Secure, SameSite Lax, lang (399 Tage), Laufzeitrisiko hoch · Chromium-Erstaufruf · Quelle: weearth.de · 159 Browser-Request(s) · document:5, fetch:9, font:5, image:29cart_currencyNotwendig · First-Party · weearth.de · ohne Secure, SameSite Lax, kurz (13 Tage), Laufzeitrisiko niedrig · HTTP Set-Cookie, Chromium-Erstaufruf · Quelle: weearth.de · 159 Browser-Request(s) · document:5, fetch:9, font:5, image:29X-ABUnklar · Drittanbieter · sc-static.net · Secure, SameSite None, kurz (0 Tage), Laufzeitrisiko niedrig · Chromium-Erstaufruf · Quelle: sc-static.net · Cookie-Domain ist Drittanbieter; konkreter Request wurde im Sample nicht eindeutig zugeordnet._shop_app_essentialUnklar · Drittanbieter · shop.app · Secure, SameSite None, lang (364 Tage), Laufzeitrisiko mittel · Chromium-Erstaufruf · Quelle: shop.app · 2 Browser-Request(s) · fetch:1, script:1_gcl_auUnklar · First-Party · weearth.de · ohne Secure, SameSite Lax, mittel (89 Tage), Laufzeitrisiko niedrig · Chromium-Erstaufruf · Quelle: weearth.de · 159 Browser-Request(s) · document:5, fetch:9, font:5, image:29_scidUnklar · First-Party · weearth.de · ohne Secure, SameSite Lax, lang (395 Tage), Laufzeitrisiko mittel · Chromium-Erstaufruf · Quelle: weearth.de · 159 Browser-Request(s) · document:5, fetch:9, font:5, image:29_scid_rUnklar · First-Party · weearth.de · ohne Secure, SameSite Lax, lang (395 Tage), Laufzeitrisiko mittel · Chromium-Erstaufruf · Quelle: weearth.de · 159 Browser-Request(s) · document:5, fetch:9, font:5, image:29_shopify_essentialUnklar · First-Party · weearth.de · Secure, SameSite Lax, lang (364 Tage), Laufzeitrisiko mittel · HTTP Set-Cookie, Chromium-Erstaufruf · Quelle: weearth.de · 159 Browser-Request(s) · document:5, fetch:9, font:5, image:29eabUserIdUnklar · First-Party · weearth.de · ohne Secure, SameSite Lax, lang (364 Tage), Laufzeitrisiko mittel · Chromium-Erstaufruf · Quelle: weearth.de · 159 Browser-Request(s) · document:5, fetch:9, font:5, image:29localizationUnklar · First-Party · weearth.de · ohne Secure, SameSite Lax, lang (364 Tage), Laufzeitrisiko mittel · HTTP Set-Cookie, Chromium-Erstaufruf · Quelle: weearth.de · 159 Browser-Request(s) · document:5, fetch:9, font:5, image:29
Technische Basis
Security-Header und Skriptquellen
4 von 6 Basis-Security-Headern vorhanden, 4 korrekt bewertet; 0 von 3 kontextabhängigen Isolations-Headern vorhanden. CSP wirksam mit 3 Direktive(n), 0 Warnung(en), 2 Hinweis(e).
HSTSok · max-age=7889238Content-Security-Policyok · block-all-mixed-content; frame-ancestors 'none'; upgrade-insecure-requests;X-Frame-Optionsok · DENYX-Content-Type-Optionsok · nosniffReferrer-PolicyfehltPermissions-PolicyfehltCross-Origin-Opener-PolicyfehltCross-Origin-Resource-PolicyfehltCross-Origin-Embedder-Policyfehlt
a.klaviyo.comSonstige · a.klaviyo.com · SRI fehltjsDelivrCDN · cdn.jsdelivr.net · SRI fehltshop.appSonstige · shop.app · SRI fehltcdn.shopify.comSonstige · cdn.shopify.com · SRI vorhandenajax.googleapis.comSonstige · ajax.googleapis.com · SRI fehltstatic.klaviyo.comSonstige · static.klaviyo.com · SRI fehltt.adcell.comSonstige · t.adcell.com · SRI fehltMicrosoft ClaritySession-Replay · clarity.ms · SRI fehltapp.sealsubscriptions.comSonstige · app.sealsubscriptions.com · SRI fehltstatic-tracking.klaviyo.comSonstige · static-tracking.klaviyo.com · SRI fehltGoogle Tag ManagerTag-Manager · googletagmanager.com · SRI fehltspfy-pxl.archive-digger.comSonstige · spfy-pxl.archive-digger.com · SRI fehlt