onvista.com Website Overview & Technology Report
🤖 AI Summary
We performed a comprehensive analysis of onvista.com on 2026-06-28. The website returned an HTTP 200 status code with a server response time of 29117ms. The page is served over HTTP/2 protocol with Gzip compression enabled, achieving approximately 60.0% size reduction. The total page weight is 982 KB.
Warning: The website does not have a valid SSL certificate. Visitors may see security warnings in their browser, and data transmitted to and from this website is not encrypted.
The security headers analysis reveals a score of 35/100 (below average). The following security headers are properly configured: Strict-Transport-Security (HSTS) and X-Frame-Options. However, the site is missing Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy, which could expose the site and its users to cross-site scripting (XSS), clickjacking, and other web-based attacks.
Our technology detection scan identified 4 technologies across 4 categories powering onvista.com. The detected stack includes Next.js css, React, Webpack, and Google Analytics 4. The site uses Next.js as its primary framework (version css). The UI is built with React.
Based on our comprehensive analysis of domain age, SSL configuration, email authentication, security headers, and blacklist status, onvista.com receives an overall trust score of 62/100, classified as "Likely Safe".
HTTP Response
Status200 OK
Response Time29117ms
ProtocolHTTP/2
Page Size982 KB
CompressionGzip
Compression Savings~60.0%
CDNNo
ServerVercel
Total Requests538
3rd Party Domains18
Redirect2 hop(s)
Detected Technologies (4)
🔧 Next.js
⚛️ React
🔨 Webpack
📊 Google Analytics 4
Security Headers
✗
Content-Security-Policy
Not set
✓
Strict-Transport-Security (HSTS)
Set ✓
✗
X-Content-Type-Options
Not set
✗
Referrer-Policy
Not set
✗
Permissions-Policy
Not set
SSL Certificate
IssuerLet's Encrypt
Issuer FullcountryName=US, organizationName=Let's Encrypt, commonName=YR1
SubjectcommonName=onvista.com
Type—
TLS VersionTLS 1.3
Cipher SuiteTLS_AES_128_GCM_SHA256
Algorithm—
Issued—
Expires— (? days)
SANs—
onvista.com Trust Score & Safety Analysis
🤖 AI Summary
After conducting a thorough safety and legitimacy analysis, onvista.com receives a trust score of 62/100, which places it in the "Likely Safe" category. This score is calculated by evaluating multiple factors including SSL certificate validity, domain registration history, email authentication protocols, security header configuration, and blacklist status across major threat intelligence databases.
The analysis identified several positive trust signals: a valid HTTPS connection protecting data in transit and HSTS (HTTP Strict Transport Security) enforcement preventing protocol downgrade attacks.
Areas of concern include: the absence of a Content-Security-Policy header, which leaves the site more vulnerable to cross-site scripting (XSS) attacks, missing Referrer-Policy, potentially leaking URL information to third parties, the domain's WHOIS information is hidden behind a privacy service, making it harder to verify the owner's identity, and DNSSEC is not enabled, leaving DNS queries vulnerable to spoofing attacks. While these issues don't necessarily indicate malicious intent, they represent areas where the website's security posture could be improved.
We checked onvista.com against 8 major blacklist databases including Google Safe Browsing, Phishtank, Urlhaus, Openphish, Dnsfilter, Spamhaus Dbl, Surbl, and Virustotal. The domain passed all 8 checks with a clean status, meaning it has not been flagged for phishing, malware distribution, spam, or other malicious activities by any of the tested threat intelligence providers.
Trust Signals
✅ Valid HTTPS
✅ HSTS enabled
⚠️ DNSSEC not enabled
⚠️ Missing Content-Security-Policy
⚠️ Missing Referrer-Policy
Blacklist Checks (8/8 clean)
✓
Google Safe Browsing
clean
✓
Phishtank
clean
✓
Urlhaus
clean
✓
Openphish
clean
✓
Dnsfilter
clean
✓
Spamhaus Dbl
clean
✓
Surbl
clean
✓
Virustotal
clean
onvista.com Technology Stack & Detected Technologies
🤖 AI Summary
Our technology detection engine scanned onvista.com and identified 4 distinct technologies across 4 categories. This analysis is performed by examining HTTP response headers, HTML source code patterns, JavaScript library fingerprints, CSS framework signatures, and DNS records.
Framework: Next.js (version css) — provides the application framework and routing for onvista.com.
UI Library: React — handles the user interface rendering and component management for onvista.com.
Build Tool: Webpack — bundles and optimizes the JavaScript and CSS assets for onvista.com.
Analytics: Google Analytics 4 — tracks visitor behavior and provides traffic insights for onvista.com.
We also extracted the following tracking identifiers: Google Analytics 4 Measurement ID G-DEVICES. These IDs can be used to identify other websites operated by the same organization.
Framework
UI Library
Build Tool
Analytics
📊 Google Analytics 4(95%)
Tracking IDs
onvista.com Performance, Speed & Core Web Vitals
🤖 AI Summary
onvista.com delivers its homepage in 29117ms (server response time), which is considered slow by industry standards. The total page weight is 982 KB, and we detected 538 resource requests loading assets from 18 third-party domains. A high number of third-party domains can significantly impact page load time due to additional DNS lookups and TLS handshakes required for each domain.
The website uses Gzip compression for text-based assets, achieving an estimated 60.0% reduction in transfer size. This reduces bandwidth usage and improves page load times, especially for visitors on slower connections.
Asset minification status: 0 out of 3 CSS files and 0 out of 67 JavaScript files are minified. Minifying the remaining 70 unminified file(s) could further reduce page weight by 10-30% for those assets. Minification is a best practice that reduces download sizes without affecting functionality.
From an environmental perspective, each page view of onvista.com produces approximately 0.48g of CO₂, earning a carbon rating of D. The website's carbon footprint could be reduced by optimizing images, enabling compression, reducing third-party scripts, and leveraging caching. For reference, the average web page produces about 0.5g of CO₂ per page view. The page weight of 982 KB is the primary factor in this calculation.
Core Web Vitals data from the Chrome User Experience Report (CrUX) is not available for onvista.com. This typically means the site doesn't have enough real-world Chrome user traffic to generate statistically significant field data, or the domain is not included in the CrUX dataset. Core Web Vitals (LCP, INP, CLS) are important Google ranking factors that measure real user experience.
Core Web Vitals data not available
Requires CrUX API key configuration
Carbon Footprint
CO₂ per page view0.48g
RatingD
Page Weight & Optimization
HTML Size982 KB
CompressionGzip
Compression Savings~60.0%
CDNNo
Total Requests538
3rd Party Domains18
CSS Minified0/3
JS Minified0/67
onvista.com DNS Records, Email Authentication & Domain Registration
🤖 AI Summary
onvista.com resolves to the IPv4 address 64.239.109.1, but does not support IPv6. IPv6 adoption is increasingly important as IPv4 address space becomes exhausted, and some ISPs and regions are transitioning to IPv6-only connectivity. The domain has 1 A record(s) configured.
The domain name system is managed by 4 name servers: ns-114.awsdns-14.com, ns-1201.awsdns-22.org, ns-1585.awsdns-06.co.uk, and ns-825.awsdns-39.net. Having 4 name servers provides good redundancy — if one fails, the others can continue serving DNS queries. The choice of name servers often indicates the DNS hosting provider or CDN service being used.
Email for onvista.com is handled by Microsoft 365 with 1 MX records configured: onvista-com.mail.protection.outlook.com. Multiple MX records provide failover redundancy — if the primary mail server is unavailable, email will be routed to the next available server.
SPF is not configured, meaning any server could potentially send emails pretending to be from this domain. This is a significant email security concern. DMARC is not configured, leaving the domain vulnerable to email spoofing and phishing attacks that impersonate this domain. DKIM was not detected. Without DKIM, recipients cannot cryptographically verify that emails claiming to be from this domain are authentic.
DNSSEC is not enabled for onvista.com. While not critical for most websites, DNSSEC adds an important security layer by ensuring DNS responses haven't been tampered with during transit. Enabling DNSSEC is recommended for domains handling sensitive data or financial transactions.
Our subdomain enumeration scan discovered 2 active subdomains for onvista.com: static.onvista.com and www.onvista.com. Active subdomains can reveal the organization's infrastructure, including development environments, API endpoints, and third-party service integrations.
DNS Records
NS
ns-114.awsdns-14.com
ns-1201.awsdns-22.org
ns-1585.awsdns-06.co.uk
ns-825.awsdns-39.net
MX
onvista-com.mail.protection.outlook.com
Email & Authentication
MX ProviderMicrosoft 365
Registrar—
Organisation—
Country—
Contact—
Registered—
Expires—
Domain Age—
IPv6 SupportNo
Subdomains (2 found)
static.onvista.com www.onvista.com
onvista.com Page Content, Images & Accessibility
🤖 AI Summary
The homepage of onvista.com contains 2,985 words of visible text content. This is a substantial amount of content that provides good opportunities for search engine indexing. The page is structured with 21 H2 headings, 7 H3 headings, 1 H4 headings, 1 H5, and 0 H6 headings.
The page includes 68 images. All images have proper alt text attributes ✓, which is excellent for both accessibility (screen readers) and SEO (search engines can understand image content).
The link structure consists of 335 internal links pointing to other pages on the same domain and 34 external links pointing to third-party websites. The high number of internal links suggests a well-interconnected site structure, which helps search engines discover and crawl all pages efficiently. There are 67 external JavaScript files, 3 CSS stylesheets, and 0 iframes on the page.
The site implements the following web standards and features: Progressive Web App (PWA) manifest (enabling app-like installation).
Notable missing features: XML Sitemap, robots.txt, and Schema.org structured data. Adding these could improve search engine discoverability and rich result eligibility.
The website has social media presence across 3 platforms: Facebook (@people), Instagram (@onvistameinfinanzportal), and Youtube (@UCHZa-ouaCwwNeBNIy0sADqQ). An active social media presence is a positive trust indicator and helps build brand awareness and customer engagement.
Content Structure
H1Top-News: Börse und Wirtschaft
H2 Tags21
H3 Tags7
H4 Tags1
H5 Tags1
H6 Tags0
Internal Links335
External Links34
Assets & Features
JavaScript Files67
JS Minified0/67
CSS Files3
CSS Minified0/3
Iframes0
Images68
Missing Alt0
SitemapNo
Robots.txtNo
PWAYes ✓
AMPNo
RSS FeedNo
Social Media Presence
Facebook: @peopleInstagram: @onvistameinfinanzportalYoutube: @UCHZa-ouaCwwNeBNIy0sADqQ
onvista.com SEO Analysis, Meta Tags & Open Graph
🤖 AI Summary
The title tag for onvista.com is too long at 84 characters: "onvista Börsenportal • Aktuelle Börsenkurse, News, Tools & deine Depots an einem...". At 84 characters, the title will likely be truncated in Google search results (recommended: 50-60 characters). Consider shortening it while keeping the most important keywords at the beginning.
The meta description is 190 characters (slightly long): "Informiere dich über Börsennews & Kurse ➤ Teste Strategien mit dem Musterdepot ➤ Triff fundierte Entscheidungen ➤ Handle...". Google typically displays up to 155-160 characters of the meta description in search results. A compelling meta description with a clear call-to-action can significantly improve click-through rates from search results.
The canonical url is correctly set to https://www.onvista.de/, preventing duplicate content issues, the page language is declared as de, the meta robots directive is set to index, follow, and a favicon is configured.
Open Graph meta tags are configured with 3/4 recommended fields: OG title ("onvista Börsenportal • Aktuelle Börsenkurse, News, Tools & d..."), OG description, OG type (website). These tags control how the page appears when shared on Facebook, LinkedIn, and other social media platforms that support the Open Graph protocol.
Google SERP Preview
onvista Börsenportal • Aktuelle Börsenkurse, News, Tools & deine Depots an einem Ort
https://onvista.com
Informiere dich über Börsennews & Kurse ➤ Teste Strategien mit dem Musterdepot ➤ Triff fundierte Entscheidungen ➤ Handle über mehrere Broker ➤ Analysiere deine Depots mit dem Portfolio-Tool.
Meta Tags
Titleonvista Börsenportal • Aktuelle Börsenkurse, News, Tools & d...
Title Length84 chars
Meta Desc Length190 chars
H1Top-News: Börse und Wirtschaft
Languagede
Canonicalhttps://www.onvista.de/
Meta Robotsindex, follow
Meta Keywordsnot set
Schema.org & Social
Schema Types—
OG Typewebsite
OG ImageNot set
Twitter Card—
FaviconSet ✓
onvista.com Data Breaches, History, Green Hosting & Mobile Apps
🤖 AI Summary
This section shows additional intelligence about onvista.com including data breach history (via HaveIBeenPwned), web archive history (Wayback Machine), green/eco-friendly hosting status, and mobile app presence in the iOS App Store.
✅No Data Breaches Found
This domain has not appeared in any known data breaches.