SSL Verification Bypassed

The server's SSL certificate could not be verified. The analysis was completed using insecure mode. Data may be less reliable.

Reason:

Unknown Certificate Authority - the server's certificate is not trusted

Cached · just now
14 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Good
SAMEORIGIN
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Good
strict-origin-when-cross-origin
Permissions-Policy
Missing
Not configured
Recommendations
  • Consider adding 'preload' to HSTS for maximum security
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Content-Type-Options: nosniff
  • Consider adding Permissions-Policy to control browser features

Performance Headers

1 headers
Vary
Performance
User-Agent,Accept-Encoding

Caching Headers

4 headers
Cache-Control
Caching
max-age=600, private, must-revalidate
Expires
Caching
Wed, 17 Aug 2005 00:00:00 GMT
Last-Modified
Caching
Thu, 29 Jan 2026 17:59:14 GMT
Pragma
Caching
no-cache

Content Headers

1 headers
Content-Type
Content
text/html; charset=utf-8

Server Headers

1 headers
Server
Server
Apache

CORS Headers

0 headers
No CORS headers found

Cookies Headers

1 headers
Set-Cookie
Cookies
92bc9ac6f76e56df364cdf67ab21387a=pik5p3hjnnj74tu6a5vv3uf34v; path=/; secure; HttpOnly

Other Headers

2 headers
Content-Security-Policy-Report-Only
Other
report-uri /report/csp-report.php?source=baumueller.com; default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://googleads.g.doubleclick.net/ https://www.googletagmanager.com https://www.googletagmanager.com/ https://salesviewer.org https://*.leadlab.click/ https://*.google-analytics.com https://www.google.com https://*.gstatic.com https://*.googleapis.com https://*.leadlab.click https://cdn.jsdelivr.net/ https://*.cookiefirst.com/ *.tawk.to cdn.jsdelivr.net; script-src-elem 'self' 'unsafe-inline' https://digital.baumueller.com/ https://pi.pardot.com/ https://www.googletagmanager.com/ https://www.google-analytics.com/ https://consent.cookiefirst.com/; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com/ https://*.cookiefirst.com/ https://salesviewer.org *.tawk.to fonts.googleapis.com cdn.jsdelivr.net; frame-src 'self' https://*.youtube.com https://www.google.com https://*.youtube-nocookie.com *.tawk.to https://www.googletagmanager.com/; connect-src 'self' https://stats.g.doubleclick.net/ https://*.leadlab.click/ https://www.google-analytics.com https://translate.googleapis.com/ https://salesviewer.org/ https://*.google-analytics.com https://googleads.g.doubleclick.net https://www.googletagmanager.com https://www.google.com/pagead/ https://consent.cookiefirst.com/ https://edge.cookiefirst.com/ https://salesviewer.org http://salesviewer.org *.tawk.to wss://*.tawk.to https://www.google.com/ccm/; img-src 'self' https://www.google.de/ads/* https://www.google.de https://www.google.com https://www.baumueller.de/ https://*.ytimg.com https://*.googleapis.com https://*.google-analytics.com https://*.leadlab.click https://*.gstatic.com/ https://*.googleapis.com/ https://img.youtube.com *.tawk.to cdn.jsdelivr.net tawk.link; font-src 'self' https://fonts.gstatic.com/ https://fonts.googleapis.com/ *.tawk.to fonts.gstatic.com; form-action *.tawk.to https://digital.baumueller.com/; frame-ancestors 'self'
Date
Other
Thu, 29 Jan 2026 17:59:12 GMT

Recommendations

Enable compression (gzip/brotli) to improve performance