
Is ccm19.de Safe? Security Analysis for Papoo Software & Media GmbH
Check if ccm19.de is a scam or legitimate. Free security scan and reviews.

AI Summary
Papoo Software & Media GmbH operates CCM19, a European-focused cookie consent management software solution designed to help website owners comply with GDPR, TDDDG, and other privacy regulations. The company positions itself as a German alternative to major international CMP providers, emphasizing data hosting exclusively in Germany and compliance with European privacy laws. CCM19 offers both cloud and on-premise deployment options, catering to a broad range of customers including agencies and hosting providers. The website demonstrates a strong market presence with over 228,000 websites served and a comprehensive suite of features including cookie scanning, Google Fonts checking, and multi-language support. Technically, the website employs modern web technologies such as jQuery, Foundation CSS framework, and FontAwesome, ensuring a responsive and accessible user experience. The infrastructure is hosted on German servers with DNS pointing to ns5.kasserver.com and ns6.kasserver.com, consistent with the company's claims. The site is well-optimized for performance and SEO, with clear navigation and professional design. From a security perspective, the site uses HTTPS and enforces privacy best practices, including no data transfer to US servers and detailed consent logging. However, explicit security headers are not detected, and no formal security policy or incident response contacts are published. The company holds memberships in recognized privacy and security organizations, enhancing trustworthiness. Overall, CCM19 presents a mature, trustworthy, and compliant cookie consent solution with strong business credibility and technical maturity. The website is professional, content-rich, and fully accessible without any blocking or WAF interference.
Detected Technologies
🧠AI Business Intelligence
Technology stack, business insights, and market analysis powered by AI.
Business Intelligence
Market & Strategic Analysis
CCM19 targets website operators, agencies, and hosting providers seeking GDPR-compliant cookie consent solutions. Its business model combines SaaS cloud offerings with downloadable on-premise software, enabling flexibility and data sovereignty. The company leverages a multi-tier pricing strategy including free trials and agency-specific versions with multi-tenancy and white-label capabilities. CCM19's competitive advantage lies in its German hosting, comprehensive compliance features, and strong customer support. The affiliate program and partnerships with privacy organizations indicate a well-developed ecosystem. Growth indicators include a large customer base and frequent updates. The company maintains transparency through detailed documentation, changelogs, and open communication channels.
Extracted Contact Information
Marketing Intelligence Data
Email Addresses (1)
Phone Numbers (2)
Physical Addresses (1)
Security Posture Analysis
Comprehensive Security Assessment
The security posture of CCM19 is solid, with HTTPS enforced and a clear commitment to data protection by hosting all data in Germany and avoiding US data transfers. The cookie consent tool includes consent logging and compliance with GDPR and TDDDG. However, the absence of explicit security headers and a published security policy or incident response contacts suggests room for improvement. No vulnerabilities or exposed sensitive data were detected in the analysis. The use of automatic updates and changelog notifications supports ongoing security maintenance. Overall, the security maturity is high but could benefit from formalized policies and enhanced header configurations.
Strategic Recommendations
Priority Actions for Security Improvement
Implement and publish standard security headers such as Content-Security-Policy, X-Frame-Options, and Strict-Transport-Security.
✨Observations
AI-powered comprehensive website and business analysis.
AI-Enhanced Website Analysis
Business Insights
Papoo Software & Media GmbH
Das europäische / deutsche Cookie Consent Tool | Consent Management Software | CMP als DOWNLOAD oder als Cloud - alles auf deutschen Servern. Mandantenfähig und multidomain - klicken und mehr erfahren ...
excellent
consistent
Technical Stack
fast
excellent
good
good
Security Assessment
- HTTPS enforced (implied by https URLs)
- No data transfer to US servers
- Consent logging and compliance with GDPR and TDDDG
- Automatic updates and changelog notifications
- No external data leakage in download version
Analytics & Tracking
Advertising & Marketing
Website Quality Assessment
Key Observations
Website is fully accessible with rich content and no blocking detected.
🛡️Security Headers
HTTP security headers analysis and recommendations.
Security Headers
HTTP security headers analysis
Missing Content-Security-Policy header
HIGHControls resources the browser is allowed to load
Missing Referrer-Policy header
LOWControls referrer information sent with requests
Missing Permissions-Policy header
MEDIUMControls browser features and APIs
👤GDPR Compliance
Privacy and data protection assessment under GDPR regulations.
GDPR Compliance
Privacy and data protection assessment
No Data Protection Officer mentioned
LOWLarge organizations may need to designate a DPO under GDPR
GDPR Compliance Analysis
🛡️NIS2 Compliance
Network & Information Security Directive compliance assessment.
NIS2 Compliance
Network & Information Security Directive
No information security framework found
HIGHNIS2 requires documented cybersecurity and information security measures
No vulnerability disclosure policy
MEDIUMNIS2 encourages coordinated vulnerability disclosure
No security policy documentation found
HIGHNIS2 requires documented cybersecurity governance and risk management
No incident response procedures found
HIGHNIS2 requires documented incident response and business continuity plans
No business continuity planning found
MEDIUMNIS2 emphasizes operational resilience and business continuity
No security contact information
HIGHNIS2 requires clear incident reporting channels
No vulnerability reporting mechanism
MEDIUMClear vulnerability reporting supports coordinated disclosure
No NIS2 reference found
LOWConsider explicitly mentioning NIS2 compliance efforts
📧Email Security
SPF, DKIM, and DMARC validation and email security assessment.
Email Security
SPF, DKIM, and DMARC validation
No DMARC reporting
LOWDMARC aggregate reports not configured
No DKIM record found
MEDIUMDKIM adds cryptographic signatures to emails
No BIMI Record
LOWBIMI displays brand logos in email clients
No MTA-STS Policy
MEDIUMMTA-STS enforces TLS for email delivery
No TLS-RPT Record
LOWTLS-RPT provides reporting for email TLS issues
SPF Details
DMARC Details
🏆SSL/TLS Security
Certificate validity and encryption analysis.
SSL/TLS Security
Certificate validity and encryption analysis
SSL Certificate Expires Within 90 Days
MEDIUMSSL certificate expires in 30 days
Partial SSL/TLS Assessment
LOWCompleted 2 of 4 security checks due to time constraints
Certificate Details
OCSP Status
📊DNS Health
DNS configuration and security assessment.
DNS Health
DNS configuration and security assessment
DNSSEC Not Enabled
MEDIUMDNSSEC is not configured for this domain
Domain Transfer Lock Not Enabled
MEDIUMDomain can be transferred without authorization
Domain Delete Lock Not Enabled
LOWDomain can be deleted without additional verification
Domain Registration Details
- •No domain protection locks enabled
DNS Records
DNSSEC Status
DNS Performance
SPF Analysis
⚡Network Security
Port scanning and network exposure analysis.
Network Security
Port scanning and network exposure analysis
High-Risk Service Exposed: FTP
HIGHPort 21 (FTP) is publicly accessible - FTP - Often unencrypted file transfer
Service Exposed: SSH
MEDIUMPort 22 (SSH) is publicly accessible - SSH - Secure but can be brute-forced
🔧Technical Analysis
Detailed technical findings and analysis from AI assessment.
Technical Analysis
Comprehensive security assessment findings