You can test your own Jimdo website for security issues without requesting approval beforehand. Jimdo also automatically applies security headers to help protect your website.
Can I scan or pen test my website for security issues?
Yes. You can run a security scan or penetration test against your own Jimdo website at any time. You don't need to register, request approval, or ask us to whitelist anything beforehand.
A few things to keep in mind:
- Your test must stay scoped to your own website, not Jimdo's broader infrastructure or other customers' sites.
- We don't pause or weaken our defenses for your test. If your test traffic looks malicious, expect it to be challenged, rate limited, or blocked. This is by design and not a sign that something is wrong.
- (Distributed) Denial of Service testing and load testing are not permitted, even as part of an otherwise legitimate test.
Security headers
Jimdo automatically applies security headers to help protect your website, for example to prevent clickjacking and other common attacks. This happens on our side; there's nothing for you to set up or configure.