Summary of chat.whatsapp.com [Mobile version] Website Security Test
Provided "as is" without any warranty of any kind.
Date/Time:Mar 27th, 2025 16:37 GMT+0
Server IP:157.240.254.60
Reverse DNS:whatsapp-cdn-shv-02-ord5.fbcdn.net
Location:Chicago, United States
Version:for iPhone 6
Your final score:
- A
- B
- C
- F
A
This test was made 369 days ago and may be outdated
Refresh Test
Executive Summary for chat.whatsapp.com
- No third-party web software dependancies were identified. Show details.
- No obvious GDPR-related compliance issues were detected across Privacy Policy, Website Security, TLS Encryption, Cookie Protection, Cookie Disclaimer. The following checks were not performed, as no corresponding cookies with personal or tracking information seem to be sent by the website: Website Security, Cookie Protection, Cookie Disclaimer. Show details.
- The website is compliant with PCI DSS Requirement 6.3, while being non-compliant with Requirement 6.4. Show details.
- Issues were identified with key security headers: misconfigured Strict-Transport-Security, Content-Security-Policy. Some optional HTTP headers may not be properly configured: Content-Security-Policy-Report-Only, Permissions-Policy, Report-To. Deprecated HTTP headers detected: X-XSS-Protection. Show details.
- Content-Security-Policy is enforced but configuration issues were identified: directive errors, overly permissive directives, deprecated directives. The report-only Content-Security-Policy contains issues: directive errors, overly permissive directives, deprecated directives. Show details.
- One cookie detected; wa_lang_pref has security or privacy-related configuration issues. Show details.
- 16 external requests detected; all requests completed successfully. SRI is not used for 11 third-party JavaScript and CSS files. Show details.
- No significant anti-scraping protections were detected. Show details.
- DNS CNAME record detected; DNSSEC signatures are not present. Show details.


