Note: This is not a stable API during the beta. Providing highlighted JSON instead of raw JSON data is therefore intentional.
{
"flashcookies_count": null,
"mx_a_records_reverse": [],
"third_parties": [],
"final_url_is_https": true,
"web_has_hsts_header": true,
"requests": [
{
"headers": null,
"method": null,
"referrer": null,
"url": "http://max-winter-platz.schule.wien.at/"
},
{
"headers": null,
"method": null,
"referrer": null,
"url": "https://max-winter-platz.schule.wien.at/"
}
],
"web_has_protocol_tls1_3": false,
"web_ciphers": {
"std_HIGH": {
"severity": "MEDIUM",
"finding": "High encryption (AES+Camellia, no AEAD) not offered"
}
},
"requests_count": 2,
"web_cert_trusted": true,
"a_locations": [
"Austria"
],
"initial_url": "http://max-winter-platz.schule.wien.at/",
"flashcookies": [],
"web_has_hpkp_header": false,
"web_has_ssl": true,
"mx_records": [],
"web_vulnerabilities": {
"breach": {
"cve": "CVE-2013-3587",
"severity": "HIGH",
"finding": "BREACH: potentially VULNERABLE, uses gzip HTTP compression. - only supplied '/' tested ( Can be ignored for static pages or if no secrets in the page)"
},
"sec_client_renego": {
"cve": "CVE-2009-3555",
"severity": "HIGH",
"finding": "Secure Client-Initiated Renegotiation : VULNERABLE, DoS threat"
}
},
"redirected_to_https": true,
"mx_ssl_finished": true,
"openwpm_final_url": "https://max-winter-platz.schule.wien.at/",
"mixed_content": false,
"headerchecks": {
"x-content-type-options": {
"status": "OK",
"value": "nosniff"
},
"x-frame-options": {
"status": "INFO",
"value": "SAMEORIGIN"
},
"content-security-policy": {
"status": "INFO",
"value": "default-src 'self' data: blob: *.wien.gv.at *.vorarlberg.at *.cookiebot.com *.wien.at *.kavedo.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: siteimproveanalytics.com *.siteimproveanalytics.io siteimproveanalytics.io *.vorarlberg.at *.youtube.com *.vimeo.com consentcdn.cookiebot.com consent.cookiebot.com *.wien.gv.at *.wien.at www.gstatic.com *.kavedo.com; style-src 'self' 'unsafe-inline' *.vorarlberg.at *.wien.gv.at *.kavedo.com; img-src 'self' data: blob: *.wien.gv.at *.siteimproveanalytics.io siteimproveanalytics.io *.vorarlberg.at *.youtube.com *.ytimg.com *.wien.at *.kavedo.com; frame-src 'self' api-mp.adrom.net basemap.at consentcdn.cookiebot.com *.vorarlberg.at e.issuu.com experience.arcgis.com issuu.com lvg.maps.arcgis.com public.tableau.com vimeo.com *.youtube.com kalender.digital *.wien.at *.wien.gv.at;"
},
"x-xss-protection": {
"status": "OK",
"value": "1; mode=block"
},
"referrer-policy": {
"status": "MISSING",
"value": ""
}
},
"mx_has_ssl": false,
"web_ssl_finished": true,
"cookie_stats": {
"first_party_flash": 0,
"first_party_long": 1,
"third_party_track_domains": [],
"third_party_track_uniq": 0,
"first_party_short": 1,
"third_party_long": 0,
"third_party_short": 0,
"third_party_track": 0,
"third_party_flash": 0
},
"tracker_requests": [],
"web_has_hsts_header_sufficient_time": true,
"third_parties_count": 0,
"final_url": "https://max-winter-platz.schule.wien.at/",
"google_analytics_present": false,
"web_has_hsts_preload_header": false,
"web_cert_trusted_reason": "",
"final_https_url": "https://max-winter-platz.schule.wien.at/",
"web_has_protocol_sslv3": false,
"web_has_protocol_tls1": false,
"profilecookies": [
{
"baseDomain": "wien.at",
"isHttpOnly": true,
"value": "true",
"lifetime": 31536001.28161502,
"path": "/",
"name": "COOKIE_SUPPORT",
"expiry": 1727032979.281615,
"isSecure": true,
"host": "max-winter-platz.schule.wien.at"
},
{
"baseDomain": "wien.at",
"isHttpOnly": true,
"value": "6FD309E70AEA8E4D0AFE1C7E3A3D5E51",
"lifetime": -1,
"path": "/",
"name": "JSESSIONID",
"expiry": -1,
"isSecure": true,
"host": "max-winter-platz.schule.wien.at"
}
],
"cname_records": [],
"success": true,
"https": true,
"mx_locations": [],
"cookies_count": 2,
"third_party_requests_count": 0,
"web_pfs": true,
"leaks": [],
"web_has_protocol_tls1_1": false,
"web_has_hsts_preload": false,
"reachable": true,
"a_records": [
"217.149.229.204"
],
"a_records_reverse": [
[
"sslhost204.wien.gv.at"
]
],
"mx_a_records": [],
"responses": null,
"web_has_protocol_tls1_2": true
}