{
  "data": {
    "slug": "8cc320e5",
    "url": "https://www.eset.com",
    "domain": "eset.com",
    "overall_score": 67,
    "scores_json": {
      "seo": {
        "score": 87,
        "checks": [
          {
            "name": "Meta Title",
            "value": "72 chars (optimal: 30-60)",
            "status": "warning",
            "howToFix": "Shorten your title to under 60 characters. Google truncates longer titles with '…' which loses your message.",
            "whyMatters": "Truncated titles reduce click-through rate by 10-20% according to Moz research."
          },
          {
            "name": "Meta Description",
            "value": "152 chars",
            "status": "pass"
          },
          {
            "name": "H1 Heading",
            "value": "\"AI-Native Prevention for Tomorrow's Threats\"",
            "status": "pass"
          },
          {
            "name": "Content Structure (H2 Headings)",
            "value": "3 H2 subheadings found",
            "status": "pass"
          },
          {
            "name": "Open Graph Tags",
            "value": "og:title, og:description, og:image",
            "status": "pass"
          },
          {
            "name": "Open Graph Image Format",
            "value": "image/jpeg",
            "status": "pass"
          },
          {
            "name": "Twitter/X Cards",
            "status": "warning",
            "howToFix": "Add <meta name='twitter:card' content='summary_large_image'>, twitter:title, and twitter:image tags.",
            "whyMatters": "Twitter Cards make your links stand out in X/Twitter feeds. Without them, shared links appear as plain text URLs."
          },
          {
            "name": "Canonical URL",
            "value": "https://www.eset.com/us/",
            "status": "pass"
          },
          {
            "name": "Structured Data (JSON-LD)",
            "value": "2 block(s): BreadcrumbList, ListItem, Organization, ContactPoint",
            "status": "pass"
          },
          {
            "name": "robots.txt",
            "value": "Present, references sitemap",
            "status": "pass"
          },
          {
            "name": "XML Sitemap",
            "value": "Found with ~214+ URLs",
            "status": "pass"
          },
          {
            "name": "HTML Language Attribute",
            "value": "lang=\"en-US\"",
            "status": "pass"
          },
          {
            "name": "Hreflang Tags (Multilingual)",
            "value": "85 language(s): en-US, sk-SK, cs-CZ, en-CA, fr-CA",
            "status": "pass"
          },
          {
            "name": "Image Alt Attributes",
            "value": "Only 60% of 5 images have alt text",
            "status": "warning",
            "howToFix": "2 images are missing alt attributes. Add descriptive, keyword-rich alt text to every image.",
            "whyMatters": "Missing alt text means zero visibility in Google Image Search (which drives 20%+ of total search traffic for e-commerce)."
          },
          {
            "name": "Meta Robots Tag",
            "value": "index,follow",
            "status": "pass"
          },
          {
            "name": "Text-to-HTML Ratio",
            "value": "3% — very thin content (4414 words)",
            "status": "fail",
            "howToFix": "Your page is almost entirely HTML/CSS/JS with very little actual content. Add substantial product descriptions, content blocks, and informational text.",
            "whyMatters": "Google's Helpful Content Update specifically targets thin content pages. This significantly hurts your rankings."
          },
          {
            "name": "Favicon",
            "value": "Favicon detected",
            "status": "pass"
          },
          {
            "name": "Image Format Optimization",
            "value": "0% next-gen formats — 0 JPEG, 4 PNG images",
            "status": "warning",
            "howToFix": "Convert all images to WebP format. Most CMS platforms have plugins for automatic WebP conversion. Use AVIF for even better compression.",
            "whyMatters": "Your images are using legacy formats only. Switching to WebP typically reduces page weight by 30-50% — one of the highest-impact performance optimizations."
          },
          {
            "name": "Semantic HTML Structure",
            "value": "4/6 semantic elements: <nav>, <header>, <footer>, <aside>",
            "status": "pass"
          },
          {
            "name": "Canonical URL Consistency",
            "value": "Canonical points to different URL: https://www.eset.com/us/",
            "status": "warning",
            "howToFix": "Your canonical URL doesn't match the current page URL. Ensure the canonical points to the preferred version (with or without trailing slash, www vs non-www). Inconsistent canonicals confuse search engines.",
            "whyMatters": "A mismatched canonical tells Google this page is a duplicate of another URL. If unintentional, Google may ignore this page entirely in favor of the canonical target."
          },
          {
            "name": "Content Depth",
            "value": "4414 words — sufficient content",
            "status": "pass"
          },
          {
            "name": "Deep Heading Hierarchy",
            "value": "H2: 3, H3: 6 — well-structured content",
            "status": "pass"
          },
          {
            "name": "Internal Linking",
            "value": "87 internal links — strong site navigation",
            "status": "pass"
          },
          {
            "name": "Accessibility Fundamentals",
            "value": "3/4 a11y signals: 112 ARIA roles, 17 ARIA labels, lang=\"en-US\"",
            "status": "pass"
          }
        ]
      },
      "gdpr": {
        "score": 84,
        "checks": [
          {
            "name": "Cookie Consent Banner (CMP)",
            "value": "TrustArc detected",
            "status": "pass",
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7"
              ],
              "czLaw": [
                "§ 5"
              ],
              "skLaw": [
                "§ 14"
              ]
            }
          },
          {
            "name": "Tracking Scripts & Consent",
            "value": "No tracking scripts detected",
            "status": "pass",
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7",
                "EDPB Opinion 5/2019"
              ],
              "skLaw": [
                "§ 14"
              ]
            }
          },
          {
            "name": "Privacy Policy Page",
            "value": "/us/home/digital-privacy-protection/",
            "status": "pass",
            "legalRefs": {
              "gdpr": [
                "Art. 12",
                "Art. 13",
                "Art. 14"
              ],
              "czLaw": [
                "§ 8",
                "§ 9"
              ],
              "skLaw": [
                "§ 19",
                "§ 20"
              ]
            }
          },
          {
            "name": "Cookie Policy",
            "status": "warning",
            "howToFix": "Create a separate cookie policy page listing every cookie by: name, provider, purpose, category (necessary/analytics/marketing), and expiration. Most CMPs auto-generate this.",
            "legalRefs": {
              "gdpr": [
                "Art. 12",
                "Art. 13(1)(c)-(e)"
              ],
              "czLaw": [
                "§ 8"
              ],
              "skLaw": [
                "§ 19"
              ]
            },
            "whyMatters": "The ePrivacy Directive requires transparent cookie disclosure. Vague statements like 'we use cookies for functionality' don't meet the specificity requirement."
          },
          {
            "name": "Legal Contact / Imprint Page",
            "status": "warning",
            "howToFix": "Add an imprint/about-us page with: company name, registered address, contact email, VAT number, and trade register info. In Germany/Austria/Switzerland this is legally required (Impressumspflicht).",
            "whyMatters": "In DACH countries, a missing Impressum can result in €50K+ fines and competitor cease-and-desist letters. For all EU stores, identifying the data controller is a GDPR Article 13 requirement."
          },
          {
            "name": "Terms & Conditions Page",
            "status": "warning",
            "howToFix": "Create Terms & Conditions (AGB) covering: ordering process, payment, delivery, returns, warranty, and dispute resolution. Link it from the footer and checkout.",
            "whyMatters": "EU Consumer Rights Directive requires clear terms before purchase. Missing T&C means customers can claim they weren't informed, giving them extended cancellation rights."
          },
          {
            "name": "Data Encryption (No Mixed Content)",
            "value": "All resources loaded over HTTPS",
            "status": "pass"
          },
          {
            "name": "Third-party Data Sharing",
            "value": "3 third-party domain(s)",
            "status": "pass"
          },
          {
            "name": "Right to Erasure (Data Deletion)",
            "status": "warning",
            "howToFix": "Provide a clear mechanism for users to request data deletion — either a dedicated page, a form, or explicit instructions in your privacy policy. Include a 'Delete my account' option in user settings.",
            "legalRefs": {
              "gdpr": [
                "Art. 17"
              ],
              "czLaw": [
                "§ 10"
              ],
              "skLaw": [
                "§ 23"
              ]
            },
            "whyMatters": "GDPR Article 17 gives users the 'right to be forgotten.' EU regulators expect a clear, accessible process. Italian DPA fined companies €20M+ for obstructing erasure requests."
          },
          {
            "name": "Newsletter Consent",
            "value": "Newsletter form with consent mechanism detected",
            "status": "pass",
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7",
                "ePrivacy Art. 13"
              ],
              "skLaw": [
                "§ 14",
                "§ 116 zák. 452/2021"
              ]
            }
          },
          {
            "name": "Data Protection Officer Contact",
            "value": "DPO / data protection contact found",
            "status": "pass"
          },
          {
            "name": "Withdrawal of Consent Mechanism",
            "value": "Consent withdrawal / opt-out mechanism found",
            "status": "pass",
            "legalRefs": {
              "gdpr": [
                "Art. 7(3)"
              ],
              "skLaw": [
                "§ 14(4)"
              ]
            }
          }
        ]
      },
      "nis2": {
        "score": -1,
        "checks": [
          {
            "name": "NIS2 Compliance",
            "value": "Scope undetermined — IČO/company enrichment unavailable for this domain.",
            "status": "info",
            "howToFix": "",
            "whyMatters": ""
          }
        ]
      },
      "mobile": {
        "score": 57,
        "checks": [
          {
            "name": "Viewport Configuration",
            "value": "width=device-width, initial-scale=1",
            "status": "pass"
          },
          {
            "name": "Mobile Performance Score",
            "value": "45/100 — critically slow",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Mobile Optimization →"
            },
            "howToFix": "Your mobile experience is severely degraded. Priority fixes: 1) Reduce JavaScript by 50%+, 2) Convert all images to WebP with responsive sizing, 3) Enable aggressive caching, 4) Use a CDN.",
            "whyMatters": "A mobile score below 50 means your store takes 5+ seconds to become usable on a phone. 53% of mobile users abandon sites that take over 3 seconds. You're losing the majority of mobile visitors."
          },
          {
            "name": "Touch Target Size",
            "status": "warning",
            "howToFix": "Ensure ALL interactive elements (buttons, links, form fields) are at least 48×48px with 8px minimum spacing between them. Pay special attention to: navigation menus, filter buttons, product variant selectors, and footer links.",
            "whyMatters": "Small tap targets cause 37% more mis-taps on mobile (Google UX research). In e-commerce, a mis-tap on 'Remove from cart' instead of 'Checkout' directly loses revenue."
          },
          {
            "name": "Font Size Readability",
            "status": "warning",
            "howToFix": "Set minimum 16px font size for body text. Use relative units (rem/em) instead of px for scalability. Product titles: 18px+, prices: 20px+, CTAs: 16px+ with bold.",
            "whyMatters": "Text smaller than 16px forces mobile users to pinch-zoom. This breaks the responsive layout and creates a frustrating experience. Users over 40 are especially affected — and they have the highest purchasing power."
          },
          {
            "name": "Content Fits Viewport",
            "value": "No horizontal scrolling needed",
            "status": "pass"
          },
          {
            "name": "Responsive Design Techniques",
            "value": "Flexbox, Media queries detected",
            "status": "pass"
          },
          {
            "name": "PWA Features",
            "value": "Has manifest, missing service worker",
            "status": "warning",
            "howToFix": "Add a service worker to enable PWA features. Register a service worker for offline caching and faster repeat visits.",
            "whyMatters": "PWA-enabled stores see 52% higher engagement and 36% higher conversion rates (Google case studies). Users can install the store as an app on their home screen."
          },
          {
            "name": "Theme Color",
            "value": "theme-color meta tag present",
            "status": "pass"
          },
          {
            "name": "Mobile Navigation (Semantic)",
            "value": "<nav> element present — proper navigation landmark",
            "status": "pass"
          },
          {
            "name": "Inline CSS Size",
            "value": "81 KB of inline CSS",
            "status": "warning",
            "howToFix": "Extract inline styles to external CSS files. Inline CSS larger than 50 KB increases HTML payload and cannot be cached separately. Keep only critical above-the-fold CSS inline.",
            "whyMatters": "Large inline CSS blocks increase initial HTML download and parsing time — especially painful on mobile with limited CPU and slower connections."
          },
          {
            "name": "Responsive Images (srcset)",
            "value": "6 image(s) use srcset for responsive sizing",
            "status": "pass"
          },
          {
            "name": "Apple Mobile Web App",
            "value": "2/3 Apple mobile meta tags configured",
            "status": "pass"
          },
          {
            "name": "Print Stylesheet",
            "value": "Order/invoice page without print styles",
            "status": "warning",
            "howToFix": "Add @media print CSS rules to hide navigation, ads, and non-essential elements. Ensure order details, prices, and company info are visible when printed.",
            "whyMatters": "Customers print order confirmations and invoices. Without print styles, they get navigation bars, cookie banners, and broken layouts. This is a common usability complaint for e-commerce."
          },
          {
            "name": "Fixed Width Elements",
            "value": "Large fixed-width elements detected — may cause horizontal scroll",
            "status": "warning",
            "howToFix": "Replace fixed pixel widths with max-width: 100% or use relative units (%, vw). Add 'overflow-x: hidden' to body as a safety net.",
            "whyMatters": "Fixed-width elements wider than the viewport cause horizontal scrolling on mobile. Google's mobile-friendly test specifically checks for this."
          },
          {
            "name": "Payment Methods Detected",
            "value": "Žiadna známa platobná brána nedetekovaná na homepage",
            "status": "info",
            "howToFix": "Payment gateway detection scanuje iba homepage. Ak sú platby na /checkout alebo sú načítané JS-om až po interakcii, neuvidíme ich. Zváž pridať platobné ikony do footer-u.",
            "whyMatters": "Viditeľné platobné ikony (Apple Pay, Google Pay, Klarna, Tatra Pay) v headeri/footeri zvyšujú conversion o 5-10 %. Trust signal pred checkoutom."
          },
          {
            "name": "Express Checkout (Apple Pay + Google Pay)",
            "status": "warning",
            "howToFix": "Pridaj Apple Pay + Google Pay cez Stripe/Adyen/Mollie. Biometric auth = -1 click checkout = vyšší conversion.",
            "whyMatters": "Mobile conversion pri express checkout je +15-25 % oproti klasickej karte. V SK/CZ trend roku 2025+."
          },
          {
            "name": "Form Input Labels (WCAG 3.3.2)",
            "value": "Iba 9/12 inputs má label (75%)",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Accessibility audit — Inger"
            },
            "howToFix": "3 input elementov nemá label. Každý input musí mať priradený <label for=\"id\">Text</label> alebo aria-label. Placeholder NIE je label (WCAG 3.3.2). Ak je checkout/registrácia formulár — toto znižuje konverziu a porušuje EN 301 549 (EAA 2026).",
            "whyMatters": "EAA 2026 (European Accessibility Act) vstupuje do platnosti 28.6.2025. E-shopy nad 10 zamestnancov alebo €2M obrat musia byť WCAG 2.1 AA kompatibilné — chýbajúce labely sú jedna z najčastejších žalovateľných chýb."
          },
          {
            "name": "Heading Hierarchy (WCAG 1.3.1)",
            "value": "Žiadne preskočené úrovne",
            "status": "pass"
          },
          {
            "name": "Link Text Quality (WCAG 2.4.4)",
            "value": "Všetky odkazy majú popisný text",
            "status": "pass"
          }
        ]
      },
      "company": {
        "nis2": {
          "annex": 2,
          "sector": "Digital Providers",
          "category": "important",
          "in_scope": true,
          "priority_tier": "warm",
          "priority_score": 56
        },
        "financials": {
          "year": 2021,
          "equity": 164468825,
          "profit": 84845073,
          "turnover": 564482011
        },
        "percentile": {
          "metrics": {
            "equity": 54,
            "turnover": 45,
            "net_profit": 54,
            "credit_limit": 54,
            "credit_score": 80,
            "total_assets": 54,
            "debt_to_equity": 26,
            "employee_count": 100
          },
          "nace_section": "J",
          "peer_group_size": 44107
        },
        "in_insolvency": false,
        "credit_grade_full": "A+"
      },
      "modules": [],
      "security": {
        "score": 57,
        "checks": [
          {
            "name": "SSL/TLS Certificate",
            "value": "Valid HTTPS connection established",
            "status": "pass"
          },
          {
            "name": "DNSSEC",
            "value": "No DNSKEY records — zone is unsigned",
            "status": "warning",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "DNSSEC setup help →"
            },
            "howToFix": "Enable DNSSEC at your DNS host (most modern registrars offer 1-click activation: Cloudflare, Route 53, Google Cloud DNS, web.sk, websupport.sk). Verify via dnsviz.net afterwards.",
            "whyMatters": "Without DNSSEC, attackers controlling intermediate resolvers can forge responses for your domain — sending users to phishing sites with valid HTTPS that match your name. EU national CSIRTs (SK-CERT, NÚKIB) recommend DNSSEC for all in-scope entities."
          },
          {
            "name": "CAA DNS Record",
            "value": "No CAA records — any CA can issue certificates for this domain",
            "status": "warning",
            "howToFix": "Publish CAA TXT records pinning your CA. For Let's Encrypt: `0 issue \"letsencrypt.org\"`. For multiple CAs add additional `0 issue \"...\"` records. Add `0 iodef \"mailto:security@yourdomain.tld\"` for misissuance reports.",
            "whyMatters": "CAA records limit which Certificate Authorities can issue certificates for your domain. Without CAA, a compromised or rogue CA can issue valid certs that browsers will trust — a documented breach pattern (DigiNotar 2011, Symantec 2017)."
          },
          {
            "name": "HTTP → HTTPS Redirect",
            "value": "HTTP properly redirects to HTTPS",
            "status": "pass"
          },
          {
            "name": "HSTS (Strict-Transport-Security)",
            "value": "missing includeSubDomains",
            "status": "warning",
            "howToFix": "Set: Strict-Transport-Security: max-age=31536000; includeSubDomains; preload — then submit to hstspreload.org for browser preloading.",
            "whyMatters": "Weak HSTS can still allow SSL stripping attacks in the first connection. Full HSTS with preload makes your site HTTPS-only in every browser."
          },
          {
            "name": "Content-Security-Policy (CSP)",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Security Hardening →"
            },
            "howToFix": "Implement a CSP header. Start with: Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: — then gradually tighten.",
            "whyMatters": "CSP is the most powerful defense against XSS attacks. Without it, any injected script runs with full privileges. CSP blocks inline script injection, the #1 web attack vector."
          },
          {
            "name": "Clickjacking Protection",
            "status": "fail",
            "howToFix": "Add X-Frame-Options: DENY (or SAMEORIGIN if iframes are needed). Better: use CSP frame-ancestors 'self'.",
            "whyMatters": "Clickjacking overlays your site in a hidden iframe. Attackers trick users into clicking buttons (like 'Confirm Purchase') without knowing it."
          },
          {
            "name": "X-Content-Type-Options",
            "status": "warning",
            "howToFix": "Add header: X-Content-Type-Options: nosniff",
            "whyMatters": "Without nosniff, browsers may execute uploaded files as scripts. An attacker could upload a .jpg that's actually JavaScript and trick the browser into running it."
          },
          {
            "name": "Referrer-Policy",
            "status": "warning",
            "howToFix": "Add header: Referrer-Policy: strict-origin-when-cross-origin — this is the best balance between functionality and privacy.",
            "whyMatters": "Without a referrer policy, browsers send the full URL to third parties. This can leak sensitive data like session tokens in URLs or internal page paths."
          },
          {
            "name": "Permissions-Policy",
            "status": "warning",
            "howToFix": "Add: Permissions-Policy: camera=(), microphone=(), geolocation=(), payment=() — disable APIs your site doesn't need.",
            "whyMatters": "Without Permissions-Policy, any third-party script (ads, analytics, chat widgets) can access camera, microphone, and geolocation without your knowledge."
          },
          {
            "name": "Cookie Security Flags",
            "value": "No cookies set on initial response",
            "status": "pass"
          },
          {
            "name": "Technology Disclosure",
            "value": "Server identity hidden",
            "status": "pass"
          },
          {
            "name": "Subresource Integrity (SRI)",
            "value": "Only 0/11 external scripts have integrity hashes",
            "status": "warning",
            "howToFix": "Add integrity='sha384-...' and crossorigin='anonymous' attributes to all third-party <script> tags. Use srihash.org to generate hashes.",
            "whyMatters": "Without SRI, if a third-party CDN is compromised, attackers can inject malicious code into your site. The British Airways breach (£20M fine) was exactly this attack vector."
          },
          {
            "name": "security.txt (RFC 9116)",
            "status": "warning",
            "howToFix": "Create /.well-known/security.txt with Contact, Expires, and Preferred-Languages fields. See securitytxt.org for the generator.",
            "whyMatters": "security.txt lets ethical hackers report vulnerabilities responsibly. Without it, they may disclose publicly or not report at all. Required by ISO 27001 and SOC 2."
          },
          {
            "name": "CDN / WAF Protection",
            "status": "warning",
            "howToFix": "Add a CDN/WAF like Cloudflare (free tier), Sucuri, or Fastly. They provide DDoS protection, bot filtering, and SSL management.",
            "whyMatters": "Without a CDN/WAF, your origin server is directly exposed to DDoS attacks, bot traffic, and brute-force attempts. Cloudflare blocks 150+ billion daily threats."
          },
          {
            "name": "Iframe Sandboxing",
            "value": "2/2 iframe(s) without sandbox attribute",
            "status": "warning",
            "howToFix": "Add sandbox attribute to all <iframe> elements. Use sandbox='allow-scripts allow-same-origin' for third-party embeds. This restricts iframe capabilities to only what's needed.",
            "whyMatters": "Unsandboxed iframes can access your DOM, run scripts, and navigate the top window. Third-party iframes (ads, widgets) should always be sandboxed to prevent clickjacking and XSS."
          }
        ]
      },
      "tech_stack": [
        {
          "name": "jQuery",
          "category": "js-library"
        },
        {
          "name": "Swiper",
          "category": "js-library"
        },
        {
          "name": "Vite",
          "category": "js-library"
        }
      ],
      "performance": {
        "score": 55,
        "checks": [
          {
            "name": "Server Response Time (TTFB)",
            "value": "16ms",
            "status": "pass"
          },
          {
            "name": "First Contentful Paint (FCP)",
            "value": "1.07s",
            "status": "pass"
          },
          {
            "name": "Largest Contentful Paint (LCP)",
            "value": "3.56s (good: <2.5s) — Core Web Vital",
            "status": "warning",
            "howToFix": "Optimize your largest element (usually hero image or product image): preload it with <link rel='preload'>, use WebP/AVIF format, set explicit width/height, and serve from CDN.",
            "whyMatters": "LCP is a Core Web Vital that directly impacts Google rankings. Sites failing LCP are demoted in search results. The #1 cause of slow LCP is unoptimized hero images."
          },
          {
            "name": "Total Blocking Time (TBT)",
            "value": "5918ms (good: <200ms)",
            "status": "fail",
            "howToFix": "Critical: audit all JavaScript. 1) Remove unused plugins/modules, 2) Defer analytics and chat widgets, 3) Code-split large bundles, 4) Move heavy computation to web workers.",
            "whyMatters": "TBT over 600ms means your page is unresponsive for over half a second. Users who can't interact within 100ms perceive the site as broken. This kills conversions."
          },
          {
            "name": "Cumulative Layout Shift (CLS)",
            "value": "0.030 — Core Web Vital ✓",
            "status": "pass"
          },
          {
            "name": "Speed Index",
            "value": "1.97s",
            "status": "pass"
          },
          {
            "name": "Total Page Weight",
            "value": "5.8 MB, 161 requests — too heavy!",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Performance Optimization →"
            },
            "howToFix": "Critical: your page is over 3 MB. 1) Convert all images to WebP/AVIF, 2) Lazy load everything below the fold, 3) Remove unused plugins, 4) Combine and minify CSS/JS, 5) Enable brotli compression.",
            "whyMatters": "Pages over 3 MB take 12+ seconds on 3G. The average e-commerce page is 2.2 MB — you're well above that. Amazon found every 100ms of latency costs 1% of sales."
          },
          {
            "name": "Render-blocking Resources",
            "value": "No render-blocking resources found",
            "status": "pass"
          },
          {
            "name": "Unused Code (CSS + JS)",
            "value": "1305 KB wasted on unused code!",
            "status": "fail",
            "howToFix": "You're loading 1305 KB of code that isn't used on this page. 1) Audit plugins and remove unused ones, 2) Use code-splitting for page-specific JS, 3) Run PurgeCSS on your stylesheets.",
            "whyMatters": "Over 200 KB of unused code significantly slows parsing and execution. This is one of the easiest performance wins — removing dead code requires no trade-offs."
          },
          {
            "name": "Text Compression (gzip/brotli)",
            "value": "All text resources properly compressed",
            "status": "pass"
          },
          {
            "name": "Resource Hints (Preload/Preconnect)",
            "status": "warning",
            "howToFix": "Add resource hints: <link rel='preconnect' href='https://fonts.googleapis.com'> for third-party origins, <link rel='preload' as='image' href='hero.webp'> for critical resources.",
            "whyMatters": "Preconnect saves 100-500ms per third-party origin by establishing connections early. Preload starts downloading critical resources before the browser discovers them in CSS/JS."
          },
          {
            "name": "Lazy Loading",
            "value": "80% of images use native lazy loading (4/5)",
            "status": "pass"
          },
          {
            "name": "Script Loading Strategy",
            "value": "Only 18% of 11 scripts optimized — most are render-blocking",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Performance Optimization →"
            },
            "howToFix": "Add defer or async to all <script src='...'> tags. Render-blocking scripts are the #1 cause of slow FCP. Defer maintains execution order, async does not.",
            "whyMatters": "9 render-blocking scripts can add 1-3 seconds to page load. Each synchronous script creates a sequential download-parse-execute chain."
          },
          {
            "name": "CSS File Count",
            "value": "2 CSS file(s) — well consolidated",
            "status": "pass"
          },
          {
            "name": "Inline JavaScript Size",
            "value": "544 KB of inline JavaScript",
            "status": "warning",
            "howToFix": "Move large inline scripts to external files. Inline JS over 100 KB inflates HTML, prevents caching, and blocks the parser. External files can be cached, compressed, and deferred.",
            "whyMatters": "Large inline scripts cannot be cached separately — they're re-downloaded with every page load. Moving them to external files with defer enables HTTP caching and parallel downloads."
          }
        ]
      },
      "ai_readiness": {
        "score": 63,
        "checks": [
          {
            "name": "AI Bot Access Policy",
            "value": "No AI bot restrictions (allowed by default)",
            "status": "pass"
          },
          {
            "name": "llms.txt (AI Site Descriptor)",
            "status": "fail",
            "fixLink": {
              "url": "https://llmstxt.org",
              "label": "Learn about llms.txt →"
            },
            "howToFix": "Create /llms.txt in Markdown format:\n# Your Store Name\n> One-line summary of your business and key offerings.\n\nDetailed description paragraph.\n\n## Products\n- [Product Category](URL): Description\n\n## About\n- [About Us](URL): Company history and values\n\nSee llmstxt.org for the full specification.",
            "whyMatters": "llms.txt is the emerging standard for AI-readable site descriptions — like robots.txt was for search engines. Early adopters (Yoast, Cloudflare, Stripe) are already using it. Without it, AI assistants have no guided overview of your store."
          },
          {
            "name": "llms-full.txt (Complete AI Content)",
            "status": "warning",
            "howToFix": "Create /llms-full.txt containing your complete site documentation in a single Markdown file — product catalog summaries, FAQs, policies, brand story. This gives AI models maximum context about your store.",
            "whyMatters": "llms-full.txt provides AI models with your entire site content in one parseable file. It's the difference between an AI having a brief overview vs. deep knowledge of your products and services."
          },
          {
            "name": "Content Accessibility for AI",
            "value": "Only 4414 words visible in HTML — content may be JS-dependent",
            "status": "fail",
            "howToFix": "Your page has very little content in the HTML source. If you're using a JavaScript framework (React, Vue, Angular), implement Server-Side Rendering (SSR) or Static Site Generation (SSG).",
            "whyMatters": "AI crawlers see only raw HTML. The LLMClicks audit tool found that JS-dependent pages score 70% lower in AI readiness. Server-rendered content is the #1 prerequisite for AI visibility."
          },
          {
            "name": "Structured Data Foundation",
            "value": "2 JSON-LD blocks with 5 schema types: BreadcrumbList, ListItem, Organization, ContactPoint, PostalAddress",
            "status": "pass"
          },
          {
            "name": "Product Schema Completeness",
            "status": "fail",
            "fixLink": {
              "url": "https://zulien.sk",
              "label": "Add Product schema →"
            },
            "howToFix": "Add complete Product JSON-LD schema: name, description, image, sku, brand, offers (price, priceCurrency, availability, seller), aggregateRating, review. This is mandatory for AI-powered commerce.",
            "whyMatters": "No Product schema = invisible to AI shopping. 58% of consumers now use AI for product discovery (Adobe 2025). Without Product schema, your products don't exist in this channel."
          },
          {
            "name": "Organization Schema + Entity Linking",
            "value": "Organization found with 6 sameAs links — strong entity identity",
            "status": "pass"
          },
          {
            "name": "FAQ Schema (Direct AI Answers)",
            "status": "warning",
            "howToFix": "Add FAQPage schema to every product page and category page. Include 3-5 Q&As per page covering: product specifications, shipping, returns, usage instructions. Format: question (full sentence) + answer (75-150 words).",
            "whyMatters": "FAQ schema provides 30% higher AI citation rates (LLMClicks research). ChatGPT, Perplexity, and Google AI Overviews pull FAQ answers verbatim. It's the fastest way to get your content cited by AI."
          },
          {
            "name": "Breadcrumb Schema",
            "value": "BreadcrumbList structured data found — clear navigation hierarchy",
            "status": "pass"
          },
          {
            "name": "Site Search Schema (SearchAction)",
            "status": "warning",
            "howToFix": "Add WebSite schema with potentialAction: SearchAction. Define your search URL template so AI assistants and Google can search your store programmatically.",
            "whyMatters": "SearchAction enables Google's sitelinks search box and allows AI shopping assistants to search your catalog directly. It's how AI agents find specific products in your store."
          },
          {
            "name": "Content Depth for AI",
            "value": "4414 words — rich content for AI analysis and citation",
            "status": "pass"
          },
          {
            "name": "Answer-First Content Format",
            "value": "First paragraph: 25 words — good content density above the fold",
            "status": "pass"
          },
          {
            "name": "Heading Hierarchy for AI",
            "value": "Proper structure: 1 H1 → 3 H2s → 6 H3s — clear content outline",
            "status": "pass"
          },
          {
            "name": "Semantic HTML Structure",
            "value": "4/6 semantic elements: <nav>, <header>, <footer>, <aside>",
            "status": "pass"
          },
          {
            "name": "Structured Content (Lists & Tables)",
            "value": "29 lists found — consider adding comparison tables",
            "status": "warning",
            "howToFix": "Add comparison tables to your content. Use <ul>/<ol> for feature lists, specifications, and benefits. Use <table> for product comparisons, pricing tiers, and specifications. AI extracts structured content exponentially faster than paragraphs.",
            "whyMatters": "AI models are biased toward extracting data from HTML lists and tables. Perplexity and ChatGPT pull bullet points and table data with much higher accuracy than paragraph text. Structured content = more AI citations."
          },
          {
            "name": "Content Freshness Signals",
            "status": "fail",
            "howToFix": "Add dateModified and datePublished to your JSON-LD schema, and display a visible 'Last updated' date on the page. Update content quarterly at minimum. AI heavily favors fresh, maintained content.",
            "whyMatters": "No freshness signals = AI assumes your content is stale. ChatGPT and Perplexity both weight recency in their citation algorithms. Competitors who show recent updates will be cited instead of your static pages."
          },
          {
            "name": "Entity Clarity & Brand Signals",
            "value": "OG tags complete + 6 sameAs links: Facebook, X/Twitter, LinkedIn, Instagram, YouTube, Wikipedia",
            "status": "pass"
          },
          {
            "name": "Author Expertise Signals (E-E-A-T)",
            "status": "warning",
            "howToFix": "For content pages (blog, guides, about): add Article/BlogPosting schema with author property linking to Person schema. Include the author's jobTitle, credentials, and social profiles.",
            "whyMatters": "AI models weight author expertise heavily. Pages from identified experts get cited 3x more than anonymous content. This is especially important for product guides, reviews, and advice content."
          },
          {
            "name": "Reviews & Ratings Schema",
            "status": "warning",
            "howToFix": "Add AggregateRating schema (ratingValue, reviewCount, bestRating) and individual Review schemas. AI shopping assistants prioritize products with verified reviews and ratings.",
            "whyMatters": "Products with star ratings appear in Google's rich results and get 35% more clicks. AI shopping assistants (ChatGPT, Bing Copilot) rank products with reviews significantly higher in recommendations."
          },
          {
            "name": "AI Plugin Manifest",
            "status": "warning",
            "howToFix": "Create /.well-known/ai-plugin.json if you have an API. This enables direct AI agent integration (ChatGPT Actions, custom GPTs). Include: name_for_model, description_for_model, auth config, and link to OpenAPI spec.",
            "whyMatters": "ai-plugin.json enables AI agents to interact with your store programmatically — search products, check prices, process orders. This is the bridge between AI assistants and your e-commerce functionality."
          },
          {
            "name": "Product Feed (AI Commerce)",
            "status": "warning",
            "howToFix": "Create a Google Merchant Center / product feed (XML or CSV). Expose it at a consistent URL and reference it in your sitemap. AI shopping assistants and comparison engines use product feeds for catalog discovery.",
            "whyMatters": "Product feeds power Google Shopping, Bing Shopping, and increasingly AI commerce. Without a structured product feed, AI agents can't efficiently index your full catalog for product recommendations."
          },
          {
            "name": "Speakable Content (Voice AI)",
            "status": "warning",
            "howToFix": "Add SpeakableSpecification schema to identify content sections suitable for voice assistants (Google Assistant, Alexa, Siri). Mark your product summaries and FAQs as speakable.",
            "whyMatters": "Voice AI commerce is growing rapidly. SpeakableSpecification tells voice assistants which content to read aloud. Early adoption positions your store for the voice shopping wave."
          },
          {
            "name": "Extractable Answer Blocks",
            "value": "81 paragraphs, avg 52 words — optimal for AI extraction",
            "status": "pass"
          },
          {
            "name": "Statistics & Data Presence",
            "value": "8 data points found — strong citation magnet",
            "status": "pass"
          },
          {
            "name": "Section Length Optimization",
            "value": "Avg section: 530 words — only 0% in 80-200 word optimal range",
            "status": "warning",
            "howToFix": "Restructure content into sections of 120-180 words between H2/H3 headings. Each section should cover one topic completely. Split sections over 300 words, expand sections under 80 words.",
            "whyMatters": "Pages with 120-180 word sections earn 70% more AI citations (Otterly Citation Economy 2026). For Google AI Overviews specifically, 100-150 words per section is the sweet spot."
          },
          {
            "name": "Q&A Format Headings",
            "value": "1 question heading(s) — add more",
            "status": "warning",
            "howToFix": "Phrase H2/H3 headings as questions: 'How does...?', 'What is...?', 'Why should...?' followed by a direct 1-2 sentence answer. This is the #1 format AI assistants use to generate responses.",
            "whyMatters": "AI search engines like Perplexity and ChatGPT match user questions to heading-answer pairs. Q&A format headings are directly extractable by AI and trigger FAQ-style rich results."
          },
          {
            "name": "Internal Link Density",
            "value": "20 contextual internal links per 1,000 words — strong knowledge graph signal",
            "status": "pass"
          },
          {
            "name": "Canonical Tag for AI Deduplication",
            "value": "Canonical points to different URL: https://www.eset.com/us/",
            "status": "warning",
            "howToFix": "Verify this canonical is intentional. AI models cluster near-duplicate URLs and choose one representative page. If canonical points to a different URL, AI will only index that target URL, not this page.",
            "whyMatters": "AI search engines (ChatGPT, Perplexity, Bing Copilot) use canonicals to deduplicate content. A wrong canonical means AI may cite the wrong page version or ignore this page entirely."
          },
          {
            "name": "Return Policy Schema",
            "status": "warning",
            "howToFix": "Add MerchantReturnPolicy schema with: returnPolicyCategory (e.g., MerchantReturnFiniteReturnWindow), merchantReturnDays, returnMethod, returnFees. Link it from Product/Offer via hasMerchantReturnPolicy.",
            "whyMatters": "AI shopping agents (Google Shopping, ChatGPT, Bing Copilot) filter by return flexibility. Products with return policy schema get priority placement in AI product comparisons."
          },
          {
            "name": "Shipping Details Schema",
            "status": "warning",
            "howToFix": "Add OfferShippingDetails schema with: shippingRate, shippingDestination, deliveryTime (handlingTime + transitTime). AI agents deprioritize products without shipping info.",
            "whyMatters": "Fulfillment speed now factors into AI product recommendations. Complete shipping schema means AI can show 'Free shipping, delivers in 2-3 days' — a massive conversion driver."
          },
          {
            "name": "Knowledge Graph Readiness",
            "value": "3/4 entity signals — strong Knowledge Graph presence",
            "status": "pass"
          },
          {
            "name": "Content Readability for AI",
            "value": "Grade 15 — too complex for broad AI citation (technical threshold: 14)",
            "status": "warning",
            "howToFix": "Simplify sentences (target 15-20 words average), use common words, break complex ideas into shorter paragraphs. AI extracts content for general audiences — if it's too academic, AI skips it.",
            "whyMatters": "Content above grade 12 readability is harder for AI to extract as clear, concise answers. Pages using clear headers and approachable language are 28% more likely to be cited by AI."
          },
          {
            "name": "Image Alt Text Quality for AI",
            "value": "60% good, 0 poor, 2 missing",
            "status": "warning",
            "howToFix": "Improve alt text: use 3-15 descriptive words per image. Include product name, key feature, and context. Bad: 'image1' or 'photo'. Good: 'Red leather wallet with RFID protection — front view'.",
            "whyMatters": "Google Lens processes 12B+ visual searches/month. AI uses alt text to understand images for visual search, product recommendations, and accessibility. Quality alt text = more discovery channels."
          },
          {
            "name": "Expert Quotations & Citations",
            "status": "warning",
            "howToFix": "Add 2-3 expert quotes or data citations per major page. Use <blockquote> for quotes and link to authoritative sources (.gov, .edu, Wikipedia, industry reports).",
            "whyMatters": "Content without citations or expert quotes appears unverified to AI. AI assistants prefer content backed by named sources, data references, and expert opinions."
          },
          {
            "name": "ai.txt (AI Permissions)",
            "status": "warning",
            "howToFix": "Create /ai.txt or /.well-known/ai.txt to declare granular AI permissions per content type: which AI actions (summarization, training, extraction) are allowed for which content sections.",
            "whyMatters": "ai.txt is an emerging standard (proposed May 2025) for fine-grained AI permissions beyond robots.txt. Early adoption signals AI-forward thinking and gives you control over how AI uses your content."
          },
          {
            "name": "WebMCP Agentic Readiness",
            "status": "warning",
            "howToFix": "WebMCP (W3C Community Group standard, Chrome 146+) lets pages declare structured tools for AI agents. Add toolname and tooldescription attributes to <form> elements, or include a <script type='application/webmcp+json'> manifest.",
            "whyMatters": "WebMCP is called 'the new Schema.org moment' — it's how AI agents will interact with your store (search products, add to cart, check availability). Google and Microsoft are co-developing this standard."
          },
          {
            "name": "Content-to-Boilerplate Ratio",
            "value": "No <main> or <article> elements — AI can't isolate content from boilerplate",
            "status": "warning",
            "howToFix": "Add <main> around your primary content and <article> around self-contained content blocks. This creates clear boundaries for AI content extraction.",
            "whyMatters": "Without semantic containers, AI crawlers must guess where content starts and navigation ends. This leads to poor content extraction and fewer citations."
          },
          {
            "name": "Trust Widget",
            "value": "Trustpilot widget detected",
            "status": "pass"
          },
          {
            "name": "Customer Reviews — Aggregate",
            "value": "1 source: Trustpilot",
            "status": "warning",
            "howToFix": "Single review source detected without published reviewCount. Add AggregateRating JSON-LD (ratingValue + reviewCount + bestRating) so the count is machine-readable, and add a second source (Heureka Ověřeno + Trustpilot is the SK/CZ standard).",
            "whyMatters": "Without a second review source and a machine-readable reviewCount, AI assistants can't verify scale of social proof — single-source ratings are routinely deweighted as potentially curated."
          }
        ]
      },
      "vulnerability": {
        "score": 65,
        "checks": [
          {
            "name": "CMS Version Disclosure",
            "value": "No generator tag — CMS identity hidden",
            "status": "pass"
          },
          {
            "name": "Sensitive Files Exposed",
            "value": ".env, .git, composer.json — all properly blocked",
            "status": "pass"
          },
          {
            "name": "Install Script Exposed",
            "value": "No /install/ or /setup/ paths accessible",
            "status": "pass"
          },
          {
            "name": "Directory Listing",
            "value": "Disabled — file structure hidden",
            "status": "pass"
          },
          {
            "name": "Admin Panel at Default URL",
            "value": "Not found at common paths (/admin, /wp-admin, /administrator, /backoffice)",
            "status": "pass"
          },
          {
            "name": "Debug Mode / Error Exposure",
            "value": "No debug indicators found in page output",
            "status": "pass"
          },
          {
            "name": "Inline JavaScript Exposure",
            "value": "544 KB of inline JavaScript",
            "status": "warning",
            "howToFix": "Move inline scripts to external files. Inline JavaScript expands the attack surface for XSS and makes CSP harder to implement (requires unsafe-inline).",
            "whyMatters": "Large amounts of inline JavaScript prevent proper CSP implementation and increase the risk of XSS. External scripts can be protected with SRI hashes."
          },
          {
            "name": "Suspicious Inline Script Patterns",
            "value": "Detected: Dynamic script injection",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Malware Scan →"
            },
            "howToFix": "Review all inline scripts for obfuscated code. Magecart attackers inject payment skimmers disguised as analytics or GTM scripts. Compare your current HTML with a known-good version. Consider using CSP with strict nonces.",
            "whyMatters": "These patterns (Base64 decode, eval with encoding, dynamic script injection) are hallmarks of Magecart payment skimmers. The 2024 Akamai report found skimmers disguised as Google Tag Manager on thousands of e-commerce sites."
          },
          {
            "name": "SPF Record (Email Security)",
            "value": "SPF configured: v=spf1 a:a.mx.eset.com a:b.mx.eset.com a:smtpout.eset.com a:branchsmtp.eset.com ",
            "status": "pass"
          },
          {
            "name": "DMARC Policy (Email Auth)",
            "value": "DMARC enforced: p=quarantine",
            "status": "pass"
          },
          {
            "name": "DKIM Signing (Email Auth)",
            "status": "warning",
            "howToFix": "Configure DKIM signing through your email provider (Google Workspace, Microsoft 365, Mailchimp, SendGrid). Publish the DKIM public key as a TXT record at <selector>._domainkey.yourdomain.com.",
            "whyMatters": "DKIM cryptographically signs outgoing email to prove it comes from your domain. Without DKIM, email providers downgrade trust score — transactional emails land in spam. Gmail and Yahoo require DKIM since 2024 for bulk senders."
          },
          {
            "name": "BIMI Brand Indicators",
            "status": "info",
            "howToFix": "Once DMARC is set to p=quarantine or p=reject with 100% enforcement, publish a BIMI record: v=BIMI1; l=https://yourdomain.com/logo.svg — adds your brand logo to recipient inboxes in Gmail and Yahoo.",
            "whyMatters": "BIMI requires VMC (Verified Mark Certificate, ~€1,500/year) but increases open rates by 10-20% and acts as trust signal. Optional but high-impact for brand-focused shops."
          },
          {
            "name": "Cross-Origin Isolation",
            "status": "warning",
            "howToFix": "Add Cross-Origin-Opener-Policy: same-origin and Cross-Origin-Resource-Policy: same-origin headers. These protect against Spectre-type side-channel attacks.",
            "whyMatters": "Without cross-origin isolation headers, your site is vulnerable to Spectre attacks that can leak sensitive data across browser tabs. These headers are required for SharedArrayBuffer and high-resolution timers."
          },
          {
            "name": "Payment Page Security",
            "value": "Payment page missing: No CSP, No X-Content-Type-Options, No clickjacking protection",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get PCI Compliance Audit →"
            },
            "howToFix": "CRITICAL: Your payment page is missing security headers: No CSP, No X-Content-Type-Options, No clickjacking protection. PCI DSS Requirement 6.5 mandates protection against common vulnerabilities on pages handling card data.",
            "whyMatters": "Payment pages without proper security headers violate PCI DSS. This can result in fines of $5,000-$100,000/month from payment processors, and makes card data theft significantly easier."
          },
          {
            "name": "Clickjacking on Sensitive Page",
            "value": "Login/payment page without X-Frame-Options or CSP frame-ancestors",
            "status": "fail",
            "howToFix": "URGENT: Add X-Frame-Options: DENY and CSP frame-ancestors 'none' to pages with login forms or payment fields. Attackers can overlay your page in a transparent iframe.",
            "whyMatters": "Clickjacking on payment/login pages is a high-severity vulnerability. Users unknowingly submit credentials or payments through invisible iframes. PCI DSS requires frame-busting on payment pages."
          }
        ]
      },
      "opendata_security": null
    },
    "created_at": "2026-06-18T08:57:06.976262+00:00",
    "status": "complete",
    "platform_detected": null,
    "company_ico": "31333532",
    "company_name": "ESET, spol. s r.o.",
    "company_country": "SK",
    "company_nace": "6209",
    "company_size": "large",
    "nis2_scope": "important",
    "nis2_sector": "Digital Providers",
    "company_risk_score": 5,
    "company_risk_level": "low"
  }
}