Skip to content
Audit service & seal – Home

This translation has not been editorially reviewed yet. The German version is authoritative. German version →

Currency

Software Status: What Your Website Reveals About Itself

Obsolete software is the most common cause of intrusion on the web – and a website reveals more about its status from the outside than most operators are aware of. We evaluate what your page reveals: system used, extensions, frontend libraries and version signatures. Without access data, without scan, without a single additional retrieval.

  • Rule set software-v1, purely passiveScope and rule set are stated in the report, countable.
  • Human reviewClear decisions in the gold standard: a person judges disputed cases.
  • TraceableEvery finding with reasoning, source and location.
  • Publicly verifiableVia audit ID, QR code and an open verification page.

What is checked in detail

  • Recognized system and version (WordPress, Joomla, Drupal, TYPO3, Contao, Shopware, Magento, PrestaShop, OXID, OpenCart, phpBB, Moodle and others)
  • Extensions and themes including version, as far as they become visible in asset paths
  • Frontend libraries with published maintenance end (for example jQuery 1.x/2.x, AngularJS, Bootstrap 3/4, Vue 2)
  • Version signatures in response headers (server, X-Powered-By and related)
  • Hosted kits (Shopify, Wix, Squarespace, Webflow, Jimdo) are recognized as provider-maintained and not faulted

How your partial seal comes about

  1. Prove the domainDNS TXT record or file in the .well-known path.
  2. Choose the scopeBy page tier, up to 1,000 pages.
  3. Automated auditEverything technically decidable is measured.
  4. Auditor judgementA person judges disputed cases, in the gold standard.
  5. Partial sealFrom 90 of 100 points in this audit area.

Why we do not want access data – and what that means for the statement

Other providers require FTP or database access to create a full inventory. We deliberately do not do this: Our test regulations agree to work exclusively passively and reading. An auditor who collects server access data is itself a risk – and a seal based on indoor access could not be traced from the outside.

The price of this attitude is honesty over the border: recognizable from the outside is always only part of the installed software. A result of 100 therefore means “nothing disadvantageous is recognizable from the outside” – not “the installation is safe”. If you need a full inventory, it is better to install your own tool in your environment instead of handing over access data.

The result: a verifiable partial seal

If your website reaches the target in this audit area, you receive a partial seal with its own audit ID and a public verification page with result, audit date and validity. How the audit proceeds is described in the audit procedure, the conditions under pricing.

Topics in detail

10 pages along the guidelines of the rule set, each with the associated checkpoints and its own questions.

What a result looks like

Every criterion receives exactly one of three judgements. A criterion is never considered met just because the measurement found nothing.

  • Met: demonstrably, with evidence
  • Still open: awaits an auditor judgement
  • Still to be met: location, rule and remedy named

A partial seal is issued from 90 of 100 points in this audit area.

Our own website currently reaches 70 of 100.

Good to know

  • Purely passive: no scan, no access, no additional access.
  • We report missing manufacturer care and visible versions — not vulnerability.
  • If nothing is recognized, this explicitly means "no proof" - no carte blanche.
  • Seal Digitale Barrierefreiheit
  • Seal Daten & Recht
  • Seal Technische Qualität
  • Seal Digital Excellence
  • Seal Cyberversicherung

Audited. For a better digital future.euid.com →