↑ ↓ select, Enter open, Esc close

Website Check

Enter a URL to see what runs on the site: web server, PHP version, CMS and plugins. Plus which external resources load before any consent, how security headers and the certificate look, and whether the SEO basics are in place.

Check a website

For example example.com or https://www.example.com/contact/. The exact page you enter is checked.

Examples

What the website check covers

  • Web server and PHP: from the Server and X-Powered-By response headers. If the server reveals its PHP version, the tool also shows how long that version still gets security updates.
  • CMS, shop and plugins: WordPress, TYPO3, Joomla, Drupal, Contao, Shopware, Magento, Shopify, Wix and more, detected by generator tags, typical paths, cookies and headers. For WordPress also page builders, SEO and cache plugins.
  • External resources: everything the browser fetches from other servers on page load: fonts, scripts, videos, maps, images and widgets. The tool also scans up to six of the site's own stylesheets for embedded Google Fonts.
  • Security headers: HSTS, Content-Security-Policy, X-Content-Type-Options, clickjacking protection, Referrer-Policy and Permissions-Policy.
  • HTTPS and certificate: redirect chain, HTTP to HTTPS redirect, issuer, validity, names in the certificate and TLS version.
  • SEO basics: title, meta description, robots directives, canonical, language and H1.

External resources and the question of consent

Every file a website loads from another server sends the visitor's IP address to that provider. The best-known example is Google Fonts: in 2022 the Munich Regional Court ruled that embedding them directly from Google without consent violates the GDPR (3 O 17493/20), which triggered a wave of warning letters in Germany. Analytics and advertising services may only load after consent anyway.

That is why the tool distinguishes how a resource is embedded:

  • loads immediately: as a script, stylesheet, image or iframe directly in the HTML. The browser fetches it before the visitor can click anything.
  • loaded by script: a script on the page contains the address, typical for Google Tag Manager. Whether it waits for consent depends on the setup.
  • early connection: preconnect opens a connection in advance, which already sends the IP address to the provider.
  • waits for consent: embedded as a blocked script (type="text/plain") or as a placeholder with data-src. That is how consent tools such as Borlabs, Complianz, Cookiebot or Usercentrics work.

A hint, not legal advice: the tool shows technical facts. Whether a particular embed is lawful, for example because of a data processing agreement or a legitimate interest, is beyond what it can judge.

Limits of a static check

The website check fetches the page like a search engine crawler and analyzes the delivered HTML. It does not run JavaScript. Anything a script loads later stays invisible: tags from Google Tag Manager, widgets that inject themselves, or content of single-page apps. A result of "no external resources" therefore means: nothing found in the HTML. For the full picture you need a real browser, for example the network tab of the developer tools (F12) in a private window without giving consent.

Some sites block automated requests or show a captcha page first. The tool detects this and points it out, the analysis is then only partly meaningful.

Hide versions: less attack surface

A header like Server: Apache/2.4.41 (Ubuntu) or X-Powered-By: PHP/8.1.2 helps nobody except attackers looking for known flaws in a specific version. Hiding versions does not replace updates, but it only takes one line:

# PHP (php.ini, or in Plesk: PHP settings, additional directives)
expose_php = Off

# nginx (http block)
server_tokens off;

# Apache (e.g. /etc/apache2/conf-available/security.conf)
ServerTokens Prod
ServerSignature Off

Check the result in the shell with the one-liner detect web server and PHP version from the HTTP header.

Adding security headers

Most headers take just a few lines, in Plesk under "Apache & nginx Settings" in the additional nginx directives. A solid start that rarely breaks anything:

add_header Strict-Transport-Security "max-age=31536000" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always;

The Content-Security-Policy is more powerful but also trickier: a rule that is too strict blocks your own scripts, forms or the consent tool. Test it as Content-Security-Policy-Report-Only first. Whether HSTS is active shows the one-liner check whether a website sends the HSTS header.

More one-liners for checking a website in the shell

Privacy

The check runs on the myline.de server. It fetches the page you enter, just like any browser, and openly identifies itself as "myline-website-check". Your IP address is not passed to the checked site, and the addresses you enter and the results are not stored. To prevent abuse there is a limit of 20 checks per hour, for which only an encrypted check value is kept briefly, never an IP address. The tool never fetches internal networks or ports other than 80 and 443.

Location data: IP Geolocation by DB-IP, license CC BY 4.0.

For the websites on your server

Free SEO and PageSpeed check

GENLOC.SEO analyzes any domain for load time, Core Web Vitals and on-page issues and tells you in plain words what is going on. Available in 11 languages.

by GENLOC.NETWORK, the team behind myline.de

Bookmark it: press Ctrl + D (Mac: ⌘ + D) to have the website check ready for the next client project.

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.