oliweb.ch

Scanned:

Want one of these looked at properly?

This scan is broad and passive — it reads what your site shows everyone, across all five areas. A deep audit takes one of those areas and goes all the way down on your site specifically.

No email, no sign-up. Pick the one you care about.

Watch this site's security

We'll email you if its security slips: a new vulnerability, an expiring certificate, a blacklisting. No account needed.

Security alerts only. Nothing else, and no email unless something is wrong. Unsubscribe anytime.

Want more than security alerts?

Coming soon

Monitor: daily re-scans across all five axes, instant alerts on new and cert expiry, Telegram & web push, and full history.

Fix what matters first

  1. 1
    TLS certificate validityHow to fix this →

    Renew the certificate soon, or enable auto-renewal.

    +5
  2. 2
    Content-Security-PolicyHow to fix this →

    Add a Content-Security-Policy to mitigate and injection.

    +2
  3. 3
    Cache-Control

    Set Cache-Control to control caching of HTML and static assets.

    +3

Recommendations are ranked by their impact on your score.

All checks

Security

80/ 100
  • Pass

    HTTPS & HTTP→HTTPS redirect

    HTTPS available; HTTP redirects to HTTPS

  • Warn

    TLS certificate validity

    Certificate expires in 27 days

    expires 2026-09-08 · YR1

    Good: valid certificate with 30 days or more to expiry

    Renew the certificate soon, or enable auto-renewal.

  • Pass

    HSTS (Strict-Transport-Security)

    Present

    max-age=31536000; includeSubDomains; preload
  • Warn

    Content-Security-Policy

    No Content-Security-Policy header

    Add a Content-Security-Policy to mitigate and injection.

  • Pass

    Core security headers

    All present

    present: X-Content-Type-Options, X-Frame-Options, Referrer-Policy
  • Pass

    Mixed content (HTTP on HTTPS)

    No insecure (http://) subresources

  • Pass

    SPF email anti-spoofing

    record present

    v=spf1 include:mailgun.org include:spf.infomaniak.ch ~all
  • Pass

    DMARC email anti-spoofing

    record present

    v=DMARC1; p=quarantine; fo=1; pct=100; adkim=s; aspf=s
  • N/A

    Vulnerable front-end libraries

    No recognizable front-end library versions detected

  • N/A

    CMS known vulnerabilities

    No CMS detected

Performance

85/ 100
  • Pass

    Time to First Byte

    Fast

    163 ms

    Fast: under 800 ms · Moderate: 800–1800 ms · Slow: over 1800 ms

  • Pass

    Text compression

    Enabled

    gzip
  • Pass

    HTTP/2 or HTTP/3

    Modern

    HTTP/2.0

    Modern: HTTP/2 or HTTP/3 · Outdated: HTTP/1.1 or older

  • Warn

    Cache-Control

    No Cache-Control header

    Set Cache-Control to control caching of HTML and static assets.

  • N/A

    Core Web Vitals (PageSpeed)

    PageSpeed Insights timed out / unavailable

SEO

100/ 100
  • Pass

    Page title

    65 characters

    Développeur Web à Genève — Statamic, WordPress & Laravel | Oliweb

    Good: 10–70 characters

  • Pass

    Meta description

    152 characters

    Expert en création de sites web avec Statamic, WordPress et Laravel. Maintenance, SEO et solutions digitales pour PME et indépendants en Suisse romande.

    Good: 50–160 characters

  • Pass

    Canonical URL

    Present

    https://oliweb.ch
  • Pass

    robots.txt

    Present and not blocking

    https://oliweb.ch/robots.txt
  • Pass
  • Pass

    Single H1

    1 H1 tag(s)

    Développeur Web & Digital à Genève
  • Pass

    Image alt text

    13/13 images have alt (100%)

    Good: 90% or more with alt text · Poor: under 50%

  • Pass

    Structured data (JSON-LD)

    present

    ImageObject, Person, PostalAddress, GeoCoordinates, City, AdministrativeArea

This page is clean. What about the rest of the site?

A clean page is a good sign and not a verdict on the site. The faults that cost the most traffic only exist between pages, so a single-page check cannot see them at all.

A full audit crawls up to 100 pages and checks

  • Indexability and crawling
  • On-page and content
  • Technical
  • Structured data and social previews
  • Links
  • Site-wide configuration

Free while in beta ($19 after launch). No domain verification — we only read pages your site already shows everyone.

Infrastructure

100/ 100
  • N/A

    CMS detection

    No CMS fingerprint detected

  • Pass

    Web server

    Identified

    Apache
  • N/A

    CDN detection

    No CDN fingerprint detected

  • Pass

    TLS version

    Up to date

    TLS 1.3

    Up to date: TLS 1.2 or 1.3 · Deprecated: TLS 1.0 or 1.1

  • Pass

    IPv6 (AAAA record)

    AAAA record present

    2001:1600:4:11::507

Reputation

90/ 100
  • Pass

    Google Safe Browsing

    Not flagged

    checked: Google Safe Browsing
  • Pass

    Domain blacklist status

    Not on major blocklists

    checked: Spamhaus DBL, SURBL
  • N/A

    Domain age

    Registration date unavailable

  • N/A

    Domain expiry

    Expiry date unavailable

Want one of these looked at properly?

This scan is broad and passive — it reads what your site shows everyone, across all five areas. A deep audit takes one of those areas and goes all the way down on your site specifically.

No email, no sign-up. Pick the one you care about.

Go deeper

This scan is passive. An attacker won't be.

The free scan reads what your site shows everyone. A Deep Audit does what an attacker does: it actively probes your verified site for what's really exposed.

This free scan (passive)

  • Security score
  • Known-CVE counts
  • Security headers
  • TLS & certificate
  • Blacklist & Safe Browsing

Deep Audit: active scan of your verified site

  • Per-CVE breakdown: IDs, severity, exploit availability, fix version
  • Exposed files (.git, .env, backups)
  • Directory listing
  • Open admin panels
  • Open ports
  • Subdomain exposure
  • Prioritized fix plan
  • Full PDF report

What we can't check without your permission

These need active probing of your site: exposed .git/.env/backups, open admin panels, open ports, forgotten subdomains. Verify your domain and we'll show you what an attacker would find.

How it works

  1. Verify your domain: a file or DNS record, about 2 minutes.
  2. We actively scan it: a few minutes; we email you when it's ready.
  3. Get your full report + PDF.

The deep scan is live and free while we're in beta. Verify your domain and run it now.

Active checks run only on a domain you've verified as yours, with your consent. We detect, never exploit. Free in beta; $39 one-time after launch, no subscription, and early adopters keep the deep scan free.

Run a free deep scan

Share this report

Request removal of this report

Recently checked

See all reports →