penny.at Website Overview & Technology Report
🤖 AI Summary
We performed a comprehensive analysis of penny.at on 2026-06-28. The website returned an HTTP 200 status code with a server response time of 43075ms. The page is served over HTTP/2 protocol, however no compression (Gzip or Brotli) is enabled, which means the page is transferred at its full uncompressed size. The total page weight is 566 KB.
Warning: The website does not have a valid SSL certificate. Visitors may see security warnings in their browser, and data transmitted to and from this website is not encrypted.
The security headers analysis reveals a score of 100/100 (excellent). The following security headers are properly configured: Content-Security-Policy, Strict-Transport-Security (HSTS), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy. All recommended security headers are in place, providing comprehensive protection against common web attacks.
Our technology detection scan identified 3 technologies across 3 categories powering penny.at. The detected stack includes Nuxt.js, React, and reCAPTCHA v3. The site uses Nuxt.js as its primary framework. The UI is built with React.
Based on our comprehensive analysis of domain age, SSL configuration, email authentication, security headers, and blacklist status, penny.at receives an overall trust score of 73/100, classified as "Likely Safe".
HTTP Response
Status200 OK
Response Time43075ms
ProtocolHTTP/2
Page Size566 KB
CompressionNone
Compression SavingsN/A
CDNNo
Serveristio-envoy
Total Requests361
3rd Party Domains12
Redirect1 hop(s)
Detected Technologies (3)
🔧 Nuxt.js
⚛️ React
🔒 reCAPTCHA v3
Security Headers
✓
Content-Security-Policy
Set ✓
✓
Strict-Transport-Security (HSTS)
Set ✓
✓
X-Content-Type-Options
Set ✓
✓
Permissions-Policy
Set ✓
SSL Certificate
IssuerGoogle Trust Services
Issuer FullcountryName=US, organizationName=Google Trust Services, commonName=WR3
SubjectcommonName=penny.at
Type—
TLS VersionTLS 1.3
Cipher SuiteTLS_AES_256_GCM_SHA384
Algorithm—
Issued—
Expires— (? days)
SANs—
penny.at Trust Score & Safety Analysis
🤖 AI Summary
After conducting a thorough safety and legitimacy analysis, penny.at receives a trust score of 73/100, which places it in the "Likely Safe" category. This score is calculated by evaluating multiple factors including SSL certificate validity, domain registration history, email authentication protocols, security header configuration, and blacklist status across major threat intelligence databases.
The analysis identified several positive trust signals: a valid HTTPS connection protecting data in transit, HSTS (HTTP Strict Transport Security) enforcement preventing protocol downgrade attacks, SPF (Sender Policy Framework) email authentication preventing email spoofing, and DMARC email authentication with a none policy.
Areas of concern include: the domain's WHOIS information is hidden behind a privacy service, making it harder to verify the owner's identity and DNSSEC is not enabled, leaving DNS queries vulnerable to spoofing attacks. While these issues don't necessarily indicate malicious intent, they represent areas where the website's security posture could be improved.
We checked penny.at against 8 major blacklist databases including Google Safe Browsing, Phishtank, Urlhaus, Openphish, Dnsfilter, Spamhaus Dbl, Surbl, and Virustotal. The domain passed all 8 checks with a clean status, meaning it has not been flagged for phishing, malware distribution, spam, or other malicious activities by any of the tested threat intelligence providers.
Trust Signals
✅ Valid HTTPS
✅ HSTS enabled
✅ SPF configured
✅ DMARC configured (p=none)
⚠️ DNSSEC not enabled
Blacklist Checks (8/8 clean)
✓
Google Safe Browsing
clean
✓
Phishtank
clean
✓
Urlhaus
clean
✓
Openphish
clean
✓
Dnsfilter
clean
✓
Spamhaus Dbl
clean
✓
Surbl
clean
✓
Virustotal
clean
penny.at Technology Stack & Detected Technologies
🤖 AI Summary
Our technology detection engine scanned penny.at and identified 3 distinct technologies across 3 categories. This analysis is performed by examining HTTP response headers, HTML source code patterns, JavaScript library fingerprints, CSS framework signatures, and DNS records.
Framework: Nuxt.js — provides the application framework and routing for penny.at.
UI Library: React — handles the user interface rendering and component management for penny.at.
Security: reCAPTCHA v3 — provides security features like bot detection and CAPTCHA for penny.at.
Framework
UI Library
Security
penny.at Performance, Speed & Core Web Vitals
🤖 AI Summary
penny.at delivers its homepage in 43075ms (server response time), which is considered slow by industry standards. The total page weight is 566 KB, and we detected 361 resource requests loading assets from 12 third-party domains. A high number of third-party domains can significantly impact page load time due to additional DNS lookups and TLS handshakes required for each domain.
No compression is currently enabled on penny.at. Enabling Brotli or Gzip compression could reduce page size by 60-80% for text-based assets (HTML, CSS, JavaScript), significantly improving load times and reducing bandwidth costs. This is one of the simplest and most impactful performance optimizations available.
Asset minification status: 0 out of 31 CSS files and 0 out of 2 JavaScript files are minified. Minifying the remaining 33 unminified file(s) could further reduce page weight by 10-30% for those assets. Minification is a best practice that reduces download sizes without affecting functionality.
From an environmental perspective, each page view of penny.at produces approximately 0.28g of CO₂, earning a carbon rating of C. This is an average carbon footprint. Optimizing images and reducing unnecessary scripts could further improve this score. For reference, the average web page produces about 0.5g of CO₂ per page view. The page weight of 566 KB is the primary factor in this calculation.
Core Web Vitals data from the Chrome User Experience Report (CrUX) is not available for penny.at. This typically means the site doesn't have enough real-world Chrome user traffic to generate statistically significant field data, or the domain is not included in the CrUX dataset. Core Web Vitals (LCP, INP, CLS) are important Google ranking factors that measure real user experience.
Core Web Vitals data not available
Requires CrUX API key configuration
Carbon Footprint
CO₂ per page view0.28g
RatingC
Page Weight & Optimization
HTML Size566 KB
CompressionNone
Compression SavingsN/A
CDNNo
Total Requests361
3rd Party Domains12
CSS Minified0/31
JS Minified0/2
penny.at DNS Records, Email Authentication & Domain Registration
🤖 AI Summary
penny.at resolves to the IPv4 address 34.49.253.169, but does not support IPv6. IPv6 adoption is increasingly important as IPv4 address space becomes exhausted, and some ISPs and regions are transitioning to IPv6-only connectivity. The domain has 1 A record(s) configured.
The domain name system is managed by 4 name servers: ns-cloud-e1.googledomains.com, ns-cloud-e2.googledomains.com, ns-cloud-e3.googledomains.com, and ns-cloud-e4.googledomains.com. Having 4 name servers provides good redundancy — if one fails, the others can continue serving DNS queries. The choice of name servers often indicates the DNS hosting provider or CDN service being used.
Email for penny.at is handled by pphosted.com with 2 MX records configured: mxa-009d0501.gslb.pphosted.com and mxb-009d0501.gslb.pphosted.com. Multiple MX records provide failover redundancy — if the primary mail server is unavailable, email will be routed to the next available server.
SPF (Sender Policy Framework) is configured, which specifies which mail servers are authorized to send email on behalf of this domain. This helps prevent email spoofing and improves email deliverability. DMARC (Domain-based Message Authentication, Reporting and Conformance) is configured with a none policy — a monitoring-only setting that doesn't enforce any action on unauthorized emails. DKIM was not detected. Without DKIM, recipients cannot cryptographically verify that emails claiming to be from this domain are authentic.
DNSSEC is not enabled for penny.at. While not critical for most websites, DNSSEC adds an important security layer by ensuring DNS responses haven't been tampered with during transit. Enabling DNSSEC is recommended for domains handling sensitive data or financial transactions.
Our subdomain enumeration scan discovered 5 active subdomains for penny.at: admin.penny.at, cdn.penny.at, dev.penny.at, shop.penny.at, and www.penny.at. Active subdomains can reveal the organization's infrastructure, including development environments, API endpoints, and third-party service integrations.
DNS Records
NS
ns-cloud-e1.googledomains.com
ns-cloud-e2.googledomains.com
ns-cloud-e3.googledomains.com
ns-cloud-e4.googledomains.com
MX
mxa-009d0501.gslb.pphosted.com
mxb-009d0501.gslb.pphosted.com
Email & Authentication
MX Providerpphosted.com
Registrar—
Organisation—
Country—
Contact—
Registered—
Expires—
Domain Age—
IPv6 SupportNo
Subdomains (5 found)
admin.penny.at cdn.penny.at dev.penny.at shop.penny.at www.penny.at
penny.at Page Content, Images & Accessibility
🤖 AI Summary
The homepage of penny.at contains 511 words of visible text content. This is a moderate amount of content. The page is structured with 4 H2 headings, 15 H3 headings, 8 H4 headings.
The page includes 66 images. 37 images (56%) are missing alt text attributes, which is a significant concern for both accessibility and SEO. Screen readers rely on alt text to describe images to visually impaired users, and search engines use alt text to understand image content. Only 44% of images have proper alt text — we recommend adding descriptive alt attributes to all images.
The link structure consists of 82 internal links pointing to other pages on the same domain and 15 external links pointing to third-party websites. There are 2 external JavaScript files, 31 CSS stylesheets, and 0 iframes on the page.
Notable missing features: XML Sitemap, robots.txt, and Schema.org structured data. Adding these could improve search engine discoverability and rich result eligibility.
We detected the following payment methods accepted on penny.at: Discover. Offering multiple payment options including credit cards and digital wallets improves customer trust and can increase conversion rates.
The website has social media presence across 3 platforms: Facebook (@pennyoesterreich), Instagram (@pennyoesterreich), and Linkedin (@penny-markt-%C3%B6sterreich). An active social media presence is a positive trust indicator and helps build brand awareness and customer engagement.
Content Structure
H1—
H2 Tags4
H3 Tags15
H4 Tags8
H5 Tags0
H6 Tags0
Internal Links82
External Links15
Assets & Features
JavaScript Files2
JS Minified0/2
CSS Files31
CSS Minified0/31
Iframes0
Images66
Missing Alt37
SitemapNo
Robots.txtNo
PWANo
AMPNo
RSS FeedNo
Payment Methods Detected
Social Media Presence
Facebook: @pennyoesterreichInstagram: @pennyoesterreichLinkedin: @penny-markt-%C3%B6sterreich
penny.at SEO Analysis, Meta Tags & Open Graph
🤖 AI Summary
The title tag for penny.at is well-optimized at 32 characters: "PENNY Österreich | Da schau her.". The length falls within the ideal range for Google search results, ensuring the full title is displayed without truncation.
The meta description is 136 characters (well-optimized): "Da schau her | PENNY Österreich ist dein Lebensmitteldiskonter mit eigenem Fleischhauer und großem Markenanteil. Verpass...". Google typically displays up to 155-160 characters of the meta description in search results. A compelling meta description with a clear call-to-action can significantly improve click-through rates from search results.
The canonical url is correctly set to https://www.penny.at/, preventing duplicate content issues, the page language is declared as de, and a favicon is configured.
Open Graph meta tags are configured with 4/4 recommended fields: OG title ("PENNY Österreich | Da schau her...."), OG description, OG image (social sharing thumbnail), OG type (website). These tags control how the page appears when shared on Facebook, LinkedIn, and other social media platforms that support the Open Graph protocol.
Google SERP Preview
PENNY Österreich | Da schau her.
https://penny.at
Da schau her | PENNY Österreich ist dein Lebensmitteldiskonter mit eigenem Fleischhauer und großem Markenanteil. Verpasse keine Angebote
Meta Tags
TitlePENNY Österreich | Da schau her....
Title Length32 chars
Meta Desc Length136 chars
H1—
Languagede
Canonicalhttps://www.penny.at/
Meta Robotsnot set
Meta Keywordsnot set
Schema.org & Social
Schema Types—
OG Typewebsite
OG ImageSet ✓
Twitter Card—
FaviconSet ✓
Open Graph Preview
penny.at
PENNY Österreich | Da schau her.
Da schau her | PENNY Österreich ist dein Lebensmitteldiskonter mit eigenem Fleischhauer und großem Markenanteil. Verpasse keine Angebote
penny.at Data Breaches, History, Green Hosting & Mobile Apps
🤖 AI Summary
This section shows additional intelligence about penny.at including data breach history (via HaveIBeenPwned), web archive history (Wayback Machine), green/eco-friendly hosting status, and mobile app presence in the iOS App Store.
✅No Data Breaches Found
This domain has not appeared in any known data breaches.