Summary of exchangesumo.com [Desktop version] Website Security Test
Provided "as is" without any warranty of any kind.
Date/Time:Sep 25th, 2024 08:49 GMT+0
Server IP:51.68.29.38
Reverse DNS:ip38.ip-51-68-29.eu
Location:Paris, France
Version:for desktop
Your final score:
- A
- B
- C
- F
B+
This test was made 555 days ago and may be outdated
Refresh Test
It appears that system is not responding or blocking software fingerprinting attempts, performed from the following IP ranges: 192.175.111.224/27, 64.15.129.96/27, 70.38.27.240/28, 72.55.136.144/28. Please whitelist them for successful continuation of the test.
Misconfiguration or weakness
Executive Summary for exchangesumo.com
- 3 third-party web software dependancies were identified, including 2 outdated dependancies. No known vulnerabilities were detected. One identified third-party web software dependancy has an unknown version. The identified CMS (WordPress) appears to be up to date. The following CMS components, JS-libraries or frameworks were identified: jquery, bootstrap. Software fingerprinting may be restricted by the system, so the results could be incomplete. Show details.
- Potential GDPR compliance issues were identified related to Cookie Protection. Website Security check may be incomplete because fingerprinting attempts appear to be blocked. Show details.
- The website is compliant with PCI DSS Requirement 6.4. The assessment of PCI DSS Requirement 6.3 may be incomplete due to limited software fingerprinting. Show details.
- All key security headers are missing. An optional HTTP header may not be properly configured: X-Powered-By. Show details.
- Content-Security-Policy headers are not present. Show details.
- 18 cookies detected; PHPSESSID, vwlp_ltkey, country_iso, vwa-client, isAuth, userId, ZZexSumo-referral, ZZexSumo-first-visit, wordpress_test_cookie, vwa-uuid, vwa-ref, vwa-cashbacks, vwa-clicks, uxt_pg_featureFlags have security or privacy-related configuration issues. Show details.
- 270 external requests detected; 2 requests failed. SRI is not used for 36 third-party JavaScript and CSS files. Show details.
- No significant anti-scraping protections were detected. Show details.
- DNS A record detected; DNSSEC signatures are not present. Show details.