Ads for Breakfast
← All posts

Essay Landing pages & CRO · 9 min read

German business websites 2026: 50,000 companies checked

A random sample of 50,000 German business homepages, checked for the basics: does it open without a warning, can a visitor reach you, is the legal notice linked at all.

44%

have a tappable phone link

Originally written in German — read it on visnakovs.de.

For most businesses, the website is the digital business card. Whoever finds you through Google usually lands there first. For that to turn into a call or an inquiry, the page has to clear a few basics: it opens without a warning, it shows a way to get in touch, and it links the legal notice and privacy policy.

After my Google Fonts study and the study on tracking before consent, I looked at the same 50,000 randomly drawn website addresses of German businesses a third time. This time, just the basics.

In short:

  • 5.1% of the addresses have a broken certificate. Anyone opening one of these pages generally sees a warning instead of the homepage: of the 100 addresses with a broken certificate that I opened in Chrome, 99 got the warning. On a further 2.7%, no encrypted connection comes through at all.
  • 6.6% of homepages offer none of the usual clickable ways to get in touch. On 3.8%, there isn’t even a phone number or email address written as plain text.
  • 7% of homepages don’t link a legal notice at all. On roughly 4.9%, my follow-up search found no legal notice at five common addresses or on the homepage itself.

That sounds like small numbers. But among the 350,146 businesses with a website address listed in OpenStreetMap, that would still mean many thousands of pages where customers can get stuck at a genuinely simple point.

1. The homepage check: how easily customers can reach you

The single most important job of a business website is that someone gets in touch. Many visitors arrive on their phone. There, a phone number you can tap is the easiest route to a call.

Here’s how it looks across the 37,393 homepages whose content could actually be analyzed. What’s counted is what’s present in the homepage’s source code:

  • Link to a contact page: 78.3%
  • Email address as a link: 48.2%
  • Phone number as a tappable link: 44%
  • Inquiry form directly on the homepage: roughly 17.6% (verified in-browser)
  • Mention of a known online booking or appointment provider: 4.6%
  • WhatsApp link: 4.5%

Anything loaded later via JavaScript doesn’t show up in the source code, so some pages likely do have these options anyway. Whether a link actually works and where it leads wasn’t tested.

The striking part is the phone number. Only 44% of homepages have a number in the source code that you can tap on a phone. Even allowing for some of the rest loading it via JavaScript, it’s simply absent from a large share. Some phones recognize a number written as plain text on their own, but you shouldn’t rely on that.

How large the differences are between industries shows up once you break it down:

IndustryHomepagesPhone linkWhatsApp linkBooking provider
Pharmacies93478.2%6.1%0.4%
Travel agencies22263.5%26.1%3.6%
Dental practices83861.9%3.5%29.1%
Plumbing & heating16561.2%2.4%3.6%
Car dealerships58460.3%11.1%0.2%
Real estate agents26760.3%5.6%0.7%
Electricians17659.1%1.1%0.6%
Car repair shops71357.4%8.6%0.3%
Driving schools32753.2%13.5%1.2%
Hotels1,51853.2%3.0%14.1%
Opticians36153.2%6.1%1.7%
Furniture stores19949.2%7.5%4.0%
Law firms35748.2%2.0%0.8%
Restaurants4,51747.5%3.5%7.9%
Doctors’ practices1,53147.0%1.4%21.9%
Beauty salons29446.6%15.6%12.2%
Hairdressers68946.0%6.4%7.1%
IT service providers39945.9%2.0%1.5%
Tax advisors18945.5%0.5%0.5%
Physiotherapy practices43945.3%3.6%3.9%
Carpentry workshops20244.1%4.5%0.5%
Florists23342.1%3.9%0.4%
Companies (general)2,41542.0%3.4%0.9%
Fast food stands56035.2%2.0%0.9%
Bakeries32433.0%1.9%0.0%
Clothing stores51932.2%5.2%2.1%
Cafés92131.2%3.1%4.2%
Guesthouses63630.5%2.2%6.6%
Butcher shops27030.4%1.5%0.0%

These figures show what was detected in each homepage’s source code. Pharmacies come out on top for phone links at 78.2%, butcher shops sit at the bottom at 30.4%. WhatsApp links show up mostly among travel agencies (26.1%), beauty salons (15.6%) and driving schools (13.5%). Mentions of a booking provider are common among dental practices (29.1%) and doctors’ practices (21.9%); for the trade businesses in the table, they sit under four percent.

And then there are homepages with none of the usual contact routes at all. In the source code, every one of the usual contact routes was missing on 9% of homepages. I opened 174 of those in a browser and scrolled all the way down. Extrapolated, roughly 6.6% of homepages offer none of the checked, clickable routes (range 4.4% to 8.5%): no phone link, no email link, no form, no WhatsApp link, and no link to a contact page. On roughly 3.8% of homepages, there wasn’t even a phone number or an email address as plain text. A postal address or links to social networks weren’t counted here.

2. Certificate and upkeep: where visitors get stuck first

Before anyone can look for your contact details, the page has to open at all. Out of 49,628 website addresses, 38,958 (78.5%) delivered an encrypted page with no error. The rest splits like this:

  • 2,554 addresses (5.1%): certificate errors. On 1,544 of them the name in the certificate doesn’t match the address, 627 certificates have expired, 383 are self-signed. Whether visitors actually see a warning, I checked on 100 randomly selected addresses from this group in an ordinary Chrome browser: Chrome rejected 99 of them. Instead of the homepage, you get “Your connection is not private,” and the only way through is “Advanced.”
  • 1,333 addresses (2.7%): no encrypted connection comes through, but the server answers unencrypted. In a sample, 43 of 60 of these addresses showed a page with meaningful text (more than 200 characters) over plain HTTP; the rest showed almost nothing. Extrapolated, that means roughly 955 addresses (1.9%) show a page only unencrypted. Chrome flags these pages as “Not secure” in the address bar.

An obvious hunch: maybe the “www.” version works instead. Of the 100 addresses with a certificate error, Chrome loaded the “www.” version without a warning in 23 cases.

Why a certificate has expired or doesn’t match the address isn’t visible from outside. Possible reasons include an auto-renewal that stopped running, or a provider switch that left an old setting in place.

14,891 homepages name a fixed year next to the copyright symbol in the source code, something like “© 2026.” 19.8% of them show 2023 or earlier, 9.7% show 2020 or earlier. Legally that’s irrelevant, and some businesses deliberately show their founding year there. Still, to a visitor, an old year can look like nobody’s touched the site in a long time.

Consistent with that: 6.2% of homepages are missing the viewport tag that adapts a page to phone screens. Without it, many mobile browsers render a page in a wider, virtual view and then shrink it to fit the screen, according to Mozilla’s own developer documentation.

By the way, by far the most common way these sites are built is WordPress, on 39.9% of reachable homepages. That’s neither good nor bad. It just means updates and plugins need regular maintenance.

Anyone running a website commercially generally has to carry an Impressum, the legal notice German law requires. Under §5 of the Digitale-Dienste-Gesetz (Germany’s Digital Services Act implementation), that information has to be “easily recognizable and directly accessible.” The usual solution is a link in the footer of every page.

In the source code, this link was missing on 9.5% of homepages. Because some pages only load their footer via JavaScript, I opened 80 of them in a browser and scrolled to the bottom. 59 really had no link, even on a second, slower pass. On the flip side, all 246 checked pages with a detected link actually had one too. From that:

  • Roughly 7% of homepages don’t link a legal notice (range 6% to 9.2%).
  • Some of them have one anyway: of 59 confirmed cases, 8 had a legal notice page at a common address like “/impressum,” just without a link. On 10, typical legal notice details sat directly on the homepage.
  • On roughly 4.9% of homepages, this follow-up search found nothing either (range 3.9% to 7.3%). I searched five common addresses and looked for typical details on the homepage itself, not across the whole site. Whether a legal notice exists somewhere else, or whether a legal requirement is being violated, isn’t something I’m judging here.

Privacy looks similar: roughly 10.9% of homepages have no link to a privacy policy (verified in-browser, range 8.7% to 14.7%).

How to check your own site in ten minutes

All you need is your phone and a computer. If you don’t maintain your own website, send this list to whoever does.

  1. Type in the address without “www.” Exactly as it appears on your business card. If you get a warning like “Your connection is not private,” the certificate needs renewing or setting up for that address. Repeat with “www.” in front.
  2. Check the certificate’s expiry date. On a computer in Chrome, click the icon left of the address bar, then “Connection is secure” and “Certificate is valid.” It shows how long it’s valid for. If it’s expiring soon, ask whether it renews automatically.
  3. Tap your phone number on your phone. If the phone app opens with your number, you’re fine. If nothing happens, the phone link is missing.
  4. Scroll all the way down. Do you see “Impressum” (legal notice) and “Datenschutz” (privacy policy) as links? And does the copyright line show a current year?
  5. Look at the page on your phone. If everything looks tiny and you have to zoom in, the mobile setting is probably missing.

Part of this, the phone number, the call to action, and mobile-friendliness, gets checked in a few seconds by my free landing page check (in German).

For the technically curious: how I measured this

You can skip this part. It’s for anyone who wants to check the numbers. All the figures are also available as an open data set, downloadable as CSV and JSON (in German), for citing and further analysis.

  • Addresses: the same random sample as the other two studies. 50,000 entries out of 350,146 German businesses with a website address in OpenStreetMap: restaurants, medical practices, trades, hotels, shops and many more. No hand-picked selection, no list from search results.
  • Fetch: on 24 September 2026, one request per address over HTTP (to see the redirect to HTTPS) and one over HTTPS with normal certificate validation, each plus any redirects, from a server in Germany. What got analyzed was the homepage’s source code: links, forms, website-builder fingerprints, copyright year, viewport tag.
  • Excluded: 372 addresses that are parked or redirect to an auto-generated profile page on a third-party provider. The remaining 49,628 addresses are the basis for the encryption figures, including the ones that don’t answer at all anymore.
  • Certificates: addresses where the request failed at certificate-chain validation (129) don’t count as certificate errors; I didn’t check those in a browser. 1,116 addresses with a failed HTTPS connection whose HTTP request also didn’t return a 200 status count as unreachable or unanalyzable.
  • Basis for contact and legal disclosures: 37,393 homepages with analyzable source code. 1,565 pages with very little text in the source code and script tags, likely building their content via JavaScript, aren’t included here.
  • Browser follow-up: on 27 September 2026, random samples were opened in a real browser, scrolled to the end, and re-checked. Without a legal notice link: 59 of 80 confirmed. With a link: 246 of 246 confirmed. Without a privacy link: 44 of 58 confirmed. With a link: 147 of 148 confirmed. Without a contact route: 128 of 174 checked, out of 3 independent samples. The samples varied noticeably (61.8%, 88.2%, 72.1% confirmed), so the range there runs from the lowest to the highest confidence bound of the individual samples. Pages that showed barely any content in the browser aren’t counted.
  • Forms: the source-code check picks up form plugins that often sit in the code on every page, even though the actual form only lives on the contact page. In the browser, only 24 of 40 such homepages actually had a form. That’s why the figure above is the corrected 17.6%, instead of the raw 27.3%.
  • Correction: the overall figures are extrapolated using the confirmed rates. The ranges come from the samples’ 95% confidence intervals. Industry-level figures only exist for traits detected in the source code (phone link, WhatsApp link, booking provider); they aren’t corrected the same way.
  • What the test doesn’t see: subpages, and anything that only appears after an interaction. A missing link on the homepage doesn’t necessarily mean the information is missing from the whole site.

The bottom line

  • 5.1% of website addresses have a broken certificate. On almost all of them, Chrome shows a warning instead of the page (99 of 100 checked broken addresses). On roughly 1.9%, a page shows up only unencrypted.
  • Only 44% of homepages have a tappable phone number in the source code. Roughly 6.6% offer none of the usual clickable contact routes.
  • Roughly 7% of homepages don’t link a legal notice, roughly 10.9% don’t link a privacy policy.
  • Nearly one in five homepages with a copyright year shows 2023 or earlier.
  • Checking your own site takes ten minutes.

Data as of 27 September 2026. I’m not a lawyer, and this article isn’t legal advice. It only shows you what’s technically happening on your own site.