Vai al contenuto principale
822288 siti analizzati

Panorama tecnologico del web UE

CMS, provider di hosting e piattaforme di consenso su 822288 siti web europei

WordPress

CMS principali (56.4%)

31884

Siti con CMS

Apache

Server principali (39.4%)

55%

Provider con hosting nell'UE

CMS Distribution

31884 sites with detected CMS

CMS choice directly affects security posture — outdated CMS versions are a leading attack vector. Plugin ecosystems, update frequency, and default security configurations vary significantly between platforms, impacting vulnerability exposure and patch cycles.

WordPress
56.4% (17969)
TYPO3
8.5% (2710)
Wix
5.7% (1818)
Jimdo Creator
4.7% (1497)
Joomla
4.5% (1448)
IONOS MyWebsite
2.9% (919)
Magento
2.8% (899)
Next.js
2.3% (722)
Shopify
1.8% (583)
MyWebsite NOW
1.5% (483)
Jimdo Dolphin
1.2% (393)
Drupal
1.0% (328)
Squarespace
1.0% (327)

Server Technology

49067 sites with detected server

Web server software and runtime frameworks. Server version disclosure can aid attackers — but also helps identify outdated, vulnerable infrastructure. End-of-life PHP versions receive no security patches.

Web server

Apache
39.4%
nginx
24.3%
Cloudflare
13.8%
Apache 2.4
12.5%
Pepyaka
2.3%
IONOS Webserver
2.1%
LiteSpeed
1.2%
openresty
0.8%
Squarespace
0.8%
HTTP Server
0.7%
Vercel
0.6%
openresty/1.31.1.1
0.6%
Microsoft-IIS 10.0
0.5%
Caddy
0.3%
CM4all Webserver
0.3%

Frameworks & PHP Versions

PHP 8.2
22.5%
PHP 8.3
18.2%
PHP 8.4
18.2%
PHP 7.4 ⚠
12.6%
PHP 8.1
10.1%
PHP 8.0 ⚠
4.0%
ASP.NET
2.9%
PHP 8.5
2.8%
PHP 7.3 ⚠
2.2%
PHP 5.6 ⚠
1.9%
PHP 7.2 ⚠
1.9%
Express (Node.js)
1.1%
PHP 5.3 ⚠
0.7%
PHP 7.0 ⚠
0.5%
PHP 5.2 ⚠
0.3%

Hosting Provider Landscape

862992 sites with hosting data

GDPR Art. 28 requires data processing agreements specifying where data is stored. Art. 44-49 regulate international transfers — hosting with US-headquartered providers triggers Schrems II (CJEU C-311/18) and CLOUD Act considerations, requiring SCCs with supplementary measures.

55%

Provider con sede nell’UE

45%

Provider extra-UE (CLOUD Act / Schrems II)

Top hosting providers

Cloudflare (US · non-EU) 90468 10.5%
IONOS (1&1) (DE · EU) 65223 7.6%
Amazon Web Services (US · non-EU) 55536 6.4%
Hetzner (DE · EU) 50216 5.8%
OVHcloud (FR · EU) 45173 5.2%
Google Cloud (US · non-EU) 37671 4.4%
Strato (DE · EU) 28576 3.3%
Wix (IL · non-EU) 26619 3.1%
Aruba S.p.A. (IT · EU) 14337 1.7%
GoDaddy (US · non-EU) 12790 1.5%

Top hosting countries

DE
29.4%
US
21.1%
FR
9.7%
NL
6.2%
GB
4.5%
IT
3.7%
PL
3.7%
CH
2.3%
DK
2.3%
IE
2.1%

Posizione del server tramite geolocalizzazione IP (MaxMind GeoLite2). Sede aziendale dal registro ASN. Un sito può essere fisicamente ospitato nell'UE ma utilizzare un provider statunitense soggetto al CLOUD Act — secondo Schrems II (CJEU C-311/18), ciò richiede SCCs con misure supplementari. · GDPR Art. 44–49

Metodologia

Come sono stati raccolti questi dati e cosa rappresentano.

Il rilevamento CMS utilizza più segnali: header di risposta HTTP (X-Powered-By, X-Generator), meta tag generator HTML, pattern URL caratteristici, convenzioni di denominazione delle classi CSS e variabili globali JavaScript. Il rilevamento copre WordPress, Joomla, Drupal, Typo3, Shopify, Wix, Squarespace e oltre 40 altre piattaforme.

Il rilevamento CMP identifica le piattaforme di gestione del consenso tramite sorgenti degli script, nomi dei cookie, elementi DOM e presenza dell'API IAB TCF (window.__tcfapi). Vengono monitorati oltre 33 vendor CMP, tra cui Cookiebot, OneTrust, Usercentrics, Borlabs Cookie e Complianz.

L'identificazione del provider di hosting combina la geolocalizzazione IP (MaxMind GeoLite2) per la posizione del server con i dati ASN/WHOIS per l'identificazione del provider e la mappatura della sede aziendale.

Nessun sito individuale viene identificato. Tutte le statistiche sono aggregate e anonimizzate. I dati rappresentano un'istantanea e vengono aggiornati continuamente man mano che vengono completate nuove scansioni.

Dove si posiziona il tuo sito web?

Esegui una scansione di sicurezza gratuita e scopri come ti posizioni — TLS, header, e-mail, DNS, accessibilità, cookie — in 30 secondi, senza account.

Basato su scansioni automatizzate di 822288 siti web europei. Aggiornato continuamente.