Website Security Test of lichess.org

Test your website security vulnerabilities, privacy issues, GDPR and PCI DSS compliance
Free online tool with PDF report
  • Web Software Detection
  • Website Privacy Check
  • Website Vulnerability Scan
  • HTTP Headers & CSP Test
  • WordPress & Drupal Scanning
  • AI Bot Protection Test
Free online tool with PDF report
188,018,387 tests performed
Provided "as is" without any warranty of any kind
117
tests
running
29,312
tests
in 24 hours
Tests in 24 Hours

Summary of lichess.org [Desktop version] Website Security Test

Provided "as is" without any warranty of any kind.
Date/Time:Mar 10th, 2025 21:38 GMT+0
Server IP:37.187.205.99
Reverse DNS:lichess.org
Location:N/A, FranceFrance
Version:for desktop
Your final score:
  • A
  • B
  • C
  • F
A
This test was made 387 days ago and may be outdated
Refresh Test

Executive Summary for lichess.org

  • Web Software Security Test
    One third-party web software dependancy was identified. It appears to be outdated, but no known vulnerabilities were detected. No Content Management System (CMS) was identified. Show details.
  • GDPR Compliance Test
    Potential GDPR compliance issues were identified related to Cookie Disclaimer. Show details.
  • PCI DSS Compliance Test
    The website is compliant with PCI DSS Requirement 6.3, while being non-compliant with Requirement 6.4. Show details.
  • HTTP Headers Security Test
    Issues were identified with key security headers: missing Content-Security-Policy, X-Content-Type-Options. Optional HTTP headers appear to be properly configured: Server, Permissions-Policy. Show details.
  • Content Security Policy (CSP) Test
    Content-Security-Policy is enforced but configuration issues were identified: directive errors. A report-only Content-Security-Policy is not present. Show details.
  • Cookies Privacy and Security Test
    One detected cookie appears to be properly configured from a security perspective. Show details.
  • External Content Security Test
    55 external requests detected; all requests completed successfully. SRI is not used for 48 third-party JavaScript and CSS files. Show details.
  • Protection from Data Scraping Test
    No significant anti-scraping protections were detected. Show details.
  • DNSSEC Configuration Test
    DNS A record detected; DNSSEC signatures are present and fully validated. Show details.
Please wait. Data is loading...