Guides Create account 🇬🇧 🇩🇪
  • Guides
  • Create account
  • Sign in
  • 🇬🇧 🇩🇪
  • Guides

    Guides for accessible, secure and privacy-friendly websites

    Practical explainers on the accessibility requirements of the BFSG and on the technical signals we check, written for website owners rather than lawyers or engineers.

    Start with the BFSG check

    01 Accessibility & BFSG

    The BFSG guides

    The German Accessibility Strengthening Act (Barrierefreiheitsstärkungsgesetz, BFSG) has applied since 28 June 2025. These guides explain who is affected, which barriers matter and what to do about them, with dedicated pages for the industries that ask us most often.

    Is your website affected?

    Work out whether the BFSG applies to your website, which exemptions exist and what your next step should be.

    Read guide

    BFSG check

    The free instant check: test your website against WCAG 2.1 AA in seconds and see where it meets the requirements and where it does not.

    Read guide

    Accessibility statement

    The mandatory content of an accessibility statement, where it belongs on your site and a template structure you can adapt.

    Read guide

    BFSG for online shops

    Shops are expressly covered by the BFSG. The typical barriers in checkout, filters and product pages, and how to check yours.

    Read guide

    BFSG for medical practices

    Online appointment booking can bring a practice website into scope. What that means and which barriers matter most.

    Read guide

    BFSG for hotels

    Booking and ticketing services fall within scope. The typical barriers on a hotel site and how accommodation businesses can check theirs.

    Read guide

    BFSG for tradespeople

    Contact forms, reference galleries and simple booking functions: what craft businesses with a website need to look at.

    Read guide

    02 Technology

    Security and privacy explained

    Two of the six dimensions in every scan, unpacked: what we look for, why it matters and how to fix the findings you get.

    HTTP security headers

    What each response header does, which ones your site should send and how to configure them correctly.

    Read guide

    Privacy signals

    Cookies, trackers and third-party requests: which signals we read from a page and what they say about your privacy setup.

    Read guide

    03 Security headers in depth

    The security header topics

    The header hub gives you the overview. These pages go one level deeper into the eight topics that take the most work to get right, each with the directives that matter, a copy-paste starting point and the questions we get asked most. Two more cover the part after go-live: noticing when a header or a policy changes without anyone deciding it should.

    Content Security Policy

    The strongest defence against cross-site scripting: which directives to set, how to roll a policy out in report-only mode and how to reach an enforcing policy without breaking your site.

    Read guide

    HSTS

    Strict-Transport-Security explained: what max-age, includeSubDomains and preload actually do, and why the preload list is a decision you cannot quickly undo.

    Read guide

    Cookie security

    Secure, HttpOnly and SameSite: the cookie attributes that keep a session out of reach of scripts and cross-site requests, with the settings for a typical stack.

    Read guide

    Clickjacking and X-Frame-Options

    How an invisible overlay turns a visitor click into an action on your site, and the two headers that stop it: X-Frame-Options for older clients, frame-ancestors for everything else.

    Read guide

    Referrer-Policy

    Which part of your URLs travels to other sites when a visitor clicks away: the five policy values that matter, what each one gives up and the one to set by default.

    Read guide

    Permissions-Policy

    Switch off camera, microphone, geolocation and payment for your site and everything it embeds: the allow-list syntax, and why a feature you did not name is not a feature you turned off.

    Read guide

    SPF, DMARC and DNSSEC

    The records that stop someone sending mail in your name, and the one that keeps your DNS answers honest: what each does and the order to introduce them in.

    Read guide

    security.txt

    The file that tells a researcher where to report a vulnerability. Two mandatory fields, ten minutes of work, and the difference between a private report and a public one.

    Read guide

    Monitoring security headers

    A header that is right today can be gone after the next deploy. Three ways to notice: a cron job with curl, a check in your CI pipeline and a scheduled scan, with what each of them catches and misses.

    Read guide

    Detecting CSP changes

    How a policy changes quietly through deploys, plugins and CDN rules, and how to catch it: a header diff, violation reports through report-to, and what a scan comparison can and cannot show.

    Read guide

    04 Server recipes

    Configuration you can copy

    The topic guides explain what to set and why. These pages give you the finished block for your stack, line by line, with the mistakes that make a configuration look right and send nothing.

    Security headers in nginx

    A complete server block to paste, what each add_header line does, and the inheritance rule that silently removes every header as soon as one location defines its own.

    Read guide

    Security headers in Apache

    The .htaccess block to paste, why mod_headers has to be enabled first and what the difference between set and always means for your error pages.

    Read guide

    Security headers in WordPress

    Every header with a few lines and no plugin, in a place a theme update cannot remove, plus the one policy that will break your block editor.

    Read guide

    Security headers in IIS

    The web.config block to paste, what each customHeaders entry does and why a web.config in a subfolder leaves you with the same header twice.

    Read guide

    Security headers in TYPO3

    Every header from one configuration array and no extension, why the backend needs a policy of its own and which files never reach TYPO3 at all.

    Read guide

    Security headers in Shopware 6

    A response subscriber that covers the whole storefront, why the administration has to be excluded and what a strict policy does to your payment providers.

    Read guide

    Security headers in Plesk

    The one field where your directives survive, why editing the generated vhost file is pointless and what proxy mode changes about duplicates.

    Read guide

    05 Tool

    Generate your accessibility statement

    A guided form walks you through every mandatory field and produces a ready-to-adapt statement text block. The preview is free.

    Open the generator

    Ready to see where your website stands?

    Run a free scan and get a plain-language report on accessibility, security, privacy, sustainability, SEO and performance.

    Scan a website
    Recent scans Guides Local leagues Pricing Methodology For hosters API Data protection Imprint Accessibility Terms Cancel contracts here © 2026 Erseni