What the website check covers
- Web server and PHP: from the
ServerandX-Powered-Byresponse headers. If the server reveals its PHP version, the tool also shows how long that version still gets security updates. - CMS, shop and plugins: WordPress, TYPO3, Joomla, Drupal, Contao, Shopware, Magento, Shopify, Wix and more, detected by generator tags, typical paths, cookies and headers. For WordPress also page builders, SEO and cache plugins.
- External resources: everything the browser fetches from other servers on page load: fonts, scripts, videos, maps, images and widgets. The tool also scans up to six of the site's own stylesheets for embedded Google Fonts.
- Security headers: HSTS, Content-Security-Policy, X-Content-Type-Options, clickjacking protection, Referrer-Policy and Permissions-Policy.
- HTTPS and certificate: redirect chain, HTTP to HTTPS redirect, issuer, validity, names in the certificate and TLS version.
- SEO basics: title, meta description, robots directives, canonical, language and H1.
External resources and the question of consent
Every file a website loads from another server sends the visitor's IP address to that provider. The best-known example is Google Fonts: in 2022 the Munich Regional Court ruled that embedding them directly from Google without consent violates the GDPR (3 O 17493/20), which triggered a wave of warning letters in Germany. Analytics and advertising services may only load after consent anyway.
That is why the tool distinguishes how a resource is embedded:
- loads immediately: as a script, stylesheet, image or iframe directly in the HTML. The browser fetches it before the visitor can click anything.
- loaded by script: a script on the page contains the address, typical for Google Tag Manager. Whether it waits for consent depends on the setup.
- early connection:
preconnectopens a connection in advance, which already sends the IP address to the provider. - waits for consent: embedded as a blocked script (
type="text/plain") or as a placeholder withdata-src. That is how consent tools such as Borlabs, Complianz, Cookiebot or Usercentrics work.
A hint, not legal advice: the tool shows technical facts. Whether a particular embed is lawful, for example because of a data processing agreement or a legitimate interest, is beyond what it can judge.
Limits of a static check
The website check fetches the page like a search engine crawler and analyzes the delivered HTML. It does not run JavaScript. Anything a script loads later stays invisible: tags from Google Tag Manager, widgets that inject themselves, or content of single-page apps. A result of "no external resources" therefore means: nothing found in the HTML. For the full picture you need a real browser, for example the network tab of the developer tools (F12) in a private window without giving consent.
Some sites block automated requests or show a captcha page first. The tool detects this and points it out, the analysis is then only partly meaningful.
Hide versions: less attack surface
A header like Server: Apache/2.4.41 (Ubuntu) or X-Powered-By: PHP/8.1.2 helps nobody except attackers looking for known flaws in a specific version. Hiding versions does not replace updates, but it only takes one line:
# PHP (php.ini, or in Plesk: PHP settings, additional directives)
expose_php = Off
# nginx (http block)
server_tokens off;
# Apache (e.g. /etc/apache2/conf-available/security.conf)
ServerTokens Prod
ServerSignature OffCheck the result in the shell with the one-liner detect web server and PHP version from the HTTP header.
Adding security headers
Most headers take just a few lines, in Plesk under "Apache & nginx Settings" in the additional nginx directives. A solid start that rarely breaks anything:
add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always;The Content-Security-Policy is more powerful but also trickier: a rule that is too strict blocks your own scripts, forms or the consent tool. Test it as Content-Security-Policy-Report-Only first. Whether HSTS is active shows the one-liner check whether a website sends the HSTS header.
More one-liners for checking a website in the shell
- Check the SSL certificate expiry of a website
- Show the redirect chain of a URL with status codes
- Find mixed content in the HTML of an HTTPS page
- Update WordPress core including the database
- Show the PHP version of the command line
Privacy
The check runs on the myline.de server. It fetches the page you enter, just like any browser, and openly identifies itself as "myline-website-check". Your IP address is not passed to the checked site, and the addresses you enter and the results are not stored. To prevent abuse there is a limit of 20 checks per hour, for which only an encrypted check value is kept briefly, never an IP address. The tool never fetches internal networks or ports other than 80 and 443.
Location data: IP Geolocation by DB-IP, license CC BY 4.0.