======================================================================
WORDPRESS SECURITY SCAN REPORT
======================================================================
Scan-ID : 20260319_080442
Ziel :
https://www.stoerti.com
Scan-Zeit : Thu Mar 19 08:04:42 2026
Status : ABGESCHLOSSEN
----------------------------------------------------------------------
ZUSAMMENFASSUNG
----------------------------------------------------------------------
Kritisch : 0
Hoch : 2
Mittel : 53
Niedrig : 4
Warnungen : 1
Information : 13
----------------------------------------------------------------------
THEMES
----------------------------------------------------------------------
Theme: minimalistblogger
- author: ThemeEverest
- css_url:
//www.stoerti.com/wp-content/themes/minimalistblogger/css/font-awesome.min.css?ver=6.9.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/themes/minimalistblogger/css/font-awesome.min.css?ver=6.9.4
- detected_from: css_link
- full_name: MinimalistBlogger
- has_readme: 1
- theme_uri:
https://superbthemes.com/minimalistblogger/minimalistblogger-info/
- version: 9.1
Theme: dark-minimalistblogger
- author: Superbthemescom
- css_url:
//www.stoerti.com/wp-content/themes/dark-minimalistblogger/style.css?ver=6.9.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/themes/dark-minimalistblogger/style.css?ver=6.9.4
- detected_from: css_link
- full_name: Dark Minimalistblogger
- has_readme: 1
- theme_uri:
https://superbthemes.com/child-theme/dark-minimalistblogger/
- version: 3.1
Gefundene Plugins: wordpress-popular-posts, contact-form-7-image-captcha, woocommerce, book-preview-for-woocommerce, contact-form-7, eventprime-event-calendar-management, superb-blocks, superb-social-share-and-follow-buttons, wp-stats-manager, woocommerce-germanized, stop-user-enumeration, *
----------------------------------------------------------------------
SICHERHEITS-SCORE: 0/100
----------------------------------------------------------------------
🚨 UNGENÜGEND - Kritische Sicherheitslücken!
----------------------------------------------------------------------
SCHWACHSTELLEN
----------------------------------------------------------------------
[high] Mögliche Prototype Pollution Schwachstelle
URL:
https://www.stoerti.com/?__proto__[admin]=true
[high] jquery . ist anfällig für Prototype Pollution
----------------------------------------------------------------------
WARNUNGEN
----------------------------------------------------------------------
* Fehlender Security Header: X-XSS-Protection - XSS-Schutz
* Trackbacks/Pingbacks sind aktiviert - Kann für DDOS-Angriffe missbraucht werden
URL:
//www.stoerti.com/wp-trackback.php" target="_blank" class="report-link">https://www.stoerti.com/wp-trackback.php
* CSP fehlen wichtige Direktiven (default-src oder script-src)
* Kein SPF Record gefunden - E-Mail Spoofing möglich
* Kein DMARC Record gefunden
* CSP fehlt default-src - Unvollständiger Schutz
* CSP fehlt script-src - Unvollständiger Schutz
* CSP fehlt object-src - Unvollständiger Schutz
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-content/plugins/wordpress-popular-posts/assets/js/wpp.min.js?ver=7.3.8" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/wordpress-popular-posts/assets/js/wpp.min.js?ver=7.3.8
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1" target="_blank" class="report-link">https://www.stoerti.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1" target="_blank" class="report-link">https://www.stoerti.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/js/eventprime-event-calendar-management-public.js?ver=4.3.1.0" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/js/eventprime-event-calendar-management-public.js?ver=4.3.1.0
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/js/jquery.toast.min.js?ver=4.3.1.0" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/js/jquery.toast.min.js?ver=4.3.1.0
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/js/toast-message.js?ver=4.3.1.0" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/js/toast-message.js?ver=4.3.1.0
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/js/ep-common-script.js?ver=4.3.1.0" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/js/ep-common-script.js?ver=4.3.1.0
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-content/plugins/stop-user-enumeration/frontend/js/frontend.js?ver=1.7.7" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/stop-user-enumeration/frontend/js/frontend.js?ver=1.7.7
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.9.5.4
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=9.5.4
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.9.5.4
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=9.5.4
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-content/plugins/book-preview-for-woocommerce/assets/js/wbps-script.js?ver=1773904112" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/book-preview-for-woocommerce/assets/js/wbps-script.js?ver=1773904112
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-includes/js/dist/hooks.min.js?ver=dd5603f07f9220ed27f1" target="_blank" class="report-link">https://www.stoerti.com/wp-includes/js/dist/hooks.min.js?ver=dd5603f07f9220ed27f1
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-includes/js/dist/i18n.min.js?ver=c26c3dc7bed366793375" target="_blank" class="report-link">https://www.stoerti.com/wp-includes/js/dist/i18n.min.js?ver=c26c3dc7bed366793375
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-content/plugins/contact-form-7/includes/swv/js/index.js?ver=6.1.5" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/contact-form-7/includes/swv/js/index.js?ver=6.1.5
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-content/plugins/contact-form-7/includes/js/index.js?ver=6.1.5" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/contact-form-7/includes/js/index.js?ver=6.1.5
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-content/themes/minimalistblogger/js/navigation.js?ver=20170823" target="_blank" class="report-link">https://www.stoerti.com/wp-content/themes/minimalistblogger/js/navigation.js?ver=20170823
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-content/themes/minimalistblogger/js/skip-link-focus-fix.js?ver=20170823" target="_blank" class="report-link">https://www.stoerti.com/wp-content/themes/minimalistblogger/js/skip-link-focus-fix.js?ver=20170823
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-content/themes/minimalistblogger/js/script.js?ver=20160720" target="_blank" class="report-link">https://www.stoerti.com/wp-content/themes/minimalistblogger/js/script.js?ver=20160720
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-content/plugins/woocommerce/assets/js/flexslider/jquery.flexslider.min.js?ver=2.7.2-wc.9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/js/flexslider/jquery.flexslider.min.js?ver=2.7.2-wc.9.5.4
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-content/themes/minimalistblogger/js/accessibility.js?ver=20160720" target="_blank" class="report-link">https://www.stoerti.com/wp-content/themes/minimalistblogger/js/accessibility.js?ver=20160720
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-content/plugins/woocommerce/assets/js/sourcebuster/sourcebuster.min.js?ver=9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/js/sourcebuster/sourcebuster.min.js?ver=9.5.4
* Externes Skript ohne Subresource Integrity - CDN-Kompromittierung riskant
URL:
//www.stoerti.com/wp-content/plugins/woocommerce/assets/js/frontend/order-attribution.min.js?ver=9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/js/frontend/order-attribution.min.js?ver=9.5.4
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/plugins/contact-form-7-image-captcha/css/cf7ic-style.css?ver=3.3.7" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/contact-form-7-image-captcha/css/cf7ic-style.css?ver=3.3.7
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-includes/css/dist/block-library/style.min.css?ver=6.9.4" target="_blank" class="report-link">https://www.stoerti.com/wp-includes/css/dist/block-library/style.min.css?ver=6.9.4
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/plugins/woocommerce/assets/client/blocks/wc-blocks.css?ver=wc-9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/client/blocks/wc-blocks.css?ver=wc-9.5.4
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/plugins/book-preview-for-woocommerce/assets/css/wbps-style.css?ver=1773904112" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/book-preview-for-woocommerce/assets/css/wbps-style.css?ver=1773904112
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=6.1.5" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=6.1.5
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/css/eventprime-event-calendar-management-public.css?ver=4.3.1.0" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/css/eventprime-event-calendar-management-public.css?ver=4.3.1.0
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/css/em-front-common-utility.css?ver=4.3.1.0" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/css/em-front-common-utility.css?ver=4.3.1.0
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/css/ep-material-fonts-icon.css?ver=4.3.1.0" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/css/ep-material-fonts-icon.css?ver=4.3.1.0
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/css/jquery.toast.min.css?ver=4.3.1.0" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/css/jquery.toast.min.css?ver=4.3.1.0
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/css/em-front-common-utility.css?ver=4.3.1.0" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/eventprime-event-calendar-management/public/css/em-front-common-utility.css?ver=4.3.1.0
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/plugins/superb-blocks/assets/css/patterns.min.css?ver=3.7.1" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/superb-blocks/assets/css/patterns.min.css?ver=3.7.1
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/plugins/superb-blocks/assets/css/enhancements.min.css?ver=3.7.1" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/superb-blocks/assets/css/enhancements.min.css?ver=3.7.1
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/plugins/superb-social-share-and-follow-buttons//assets/css/frontend.css?ver=1.2.5" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/superb-social-share-and-follow-buttons//assets/css/frontend.css?ver=1.2.5
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/plugins/superb-social-share-and-follow-buttons//assets/lato/styles.css?ver=1.2.5" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/superb-social-share-and-follow-buttons//assets/lato/styles.css?ver=1.2.5
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/plugins/woocommerce/assets/css/woocommerce-layout.css?ver=9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/css/woocommerce-layout.css?ver=9.5.4
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/plugins/woocommerce/assets/css/woocommerce-smallscreen.css?ver=9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/css/woocommerce-smallscreen.css?ver=9.5.4
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/plugins/woocommerce/assets/css/woocommerce.css?ver=9.5.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce/assets/css/woocommerce.css?ver=9.5.4
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/plugins/wp-stats-manager/css/style.css?ver=1.2" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/wp-stats-manager/css/style.css?ver=1.2
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/plugins/wordpress-popular-posts/assets/css/wpp.css?ver=7.3.8" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/wordpress-popular-posts/assets/css/wpp.css?ver=7.3.8
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/themes/minimalistblogger/style.css?ver=6.9.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/themes/minimalistblogger/style.css?ver=6.9.4
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/themes/minimalistblogger/css/font-awesome.min.css?ver=6.9.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/themes/minimalistblogger/css/font-awesome.min.css?ver=6.9.4
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/themes/dark-minimalistblogger/style.css?ver=6.9.4" target="_blank" class="report-link">https://www.stoerti.com/wp-content/themes/dark-minimalistblogger/style.css?ver=6.9.4
* Externes Stylesheet ohne Subresource Integrity
URL:
//www.stoerti.com/wp-content/plugins/woocommerce-germanized/build/static/layout-styles.css?ver=3.20.7" target="_blank" class="report-link">https://www.stoerti.com/wp-content/plugins/woocommerce-germanized/build/static/layout-styles.css?ver=3.20.7
* COEP mit schwacher Konfiguration: unsafe-none; report-to='default'
* COOP mit schwacher Konfiguration: unsafe-none
----------------------------------------------------------------------
EMPFEHLUNGEN
----------------------------------------------------------------------
🔴 Hohe Priorität:
- Hochriskante Schwachstellen schnellstmöglich beheben
- Alle Komponenten updaten
📋 Allgemeine Empfehlungen:
- Regelmäßige Updates durchführen
- Backups erstellen
- HTTPS erzwingen
- Security Headers implementieren
- XML-RPC deaktivieren wenn nicht benötigt
======================================================================
SCAN ABGESCHLOSSEN
======================================================================