Summary of api.whatsapp.com [Mobile version] Website Security Test
Provided "as is" without any warranty of any kind.
Date/Time:Mar 28th, 2026 02:54 GMT+0
Server IP:31.13.71.49
Reverse DNS:whatsapp-cdn-shv-01-lga3.fbcdn.net
Location:New York, United States
Version:for iPhone 6
Your final score:
- A
- B
- C
- F
A
It appears that system is not responding or blocking software fingerprinting attempts, performed from the following IP ranges: 192.175.111.224/27, 64.15.129.96/27, 70.38.27.240/28, 72.55.136.144/28. Please whitelist them for successful continuation of the test.
Misconfiguration or weakness
Executive Summary for api.whatsapp.com
- No third-party web software dependancies were identified. Show details.
- No obvious GDPR-related compliance issues were detected across Privacy Policy, Website Security, TLS Encryption, Cookie Protection, Cookie Disclaimer. The following checks were not performed, as no corresponding cookies with personal or tracking information seem to be sent by the website: Website Security, Cookie Protection, Cookie Disclaimer. Show details.
- The website is non-compliant with PCI DSS Requirement 6.4. The assessment of PCI DSS Requirement 6.3 may be incomplete due to limited software fingerprinting. Show details.
- Issues were identified with key security headers: missing X-Frame-Options; misconfigured Content-Security-Policy. Some optional HTTP headers may not be properly configured: Permissions-Policy, Report-To. Deprecated HTTP headers detected: X-XSS-Protection. Show details.
- Content-Security-Policy is enforced but configuration issues were identified: directive errors. A report-only Content-Security-Policy is not present. Show details.
- One cookie detected; wa_lang_pref has security or privacy-related configuration issues. Show details.
- 16 external requests detected; all requests completed successfully. SRI is not used for 11 third-party JavaScript and CSS files. Show details.
- 1 meta restriction and 1 bot protection mechanism detected. No protection detected via robots.txt rules or User-Agent blocks. Show details.
- DNS CNAME record detected; DNSSEC signatures are not present. Show details.


