{
  "data": {
    "slug": "015d6517",
    "url": "https://globalfamilyoffices.netlify.app/",
    "domain": "globalfamilyoffices.netlify.app",
    "overall_score": 65,
    "scores_json": {
      "seo": {
        "score": 38,
        "checks": [
          {
            "name": "Meta Title",
            "value": "50 chars — \"Global Family Offices – Cesta za doživotnou rentou\"",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Meta Description",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Write a compelling meta description (120-160 chars) with a call-to-action. Include your target keyword naturally.",
            "whyMatters": "Without a meta description, Google auto-generates one — often poorly. Custom descriptions can boost CTR by 5.8% (Backlinko study)."
          },
          {
            "name": "H1 Heading",
            "value": "\"Global Family Offices — Cesta za doživotnou rentou\"",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Content Structure (H2 Headings)",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add H2 subheadings to structure your content. Each major section should have a descriptive H2.",
            "whyMatters": "Pages without heading structure have 30% lower time-on-page and miss long-tail ranking opportunities."
          },
          {
            "name": "Open Graph Tags",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add og:title, og:description, og:image (1200×630px), and og:type meta tags to every page.",
            "whyMatters": "Without OG tags, social platforms show ugly auto-generated previews. Proper OG tags increase social engagement by 2-3x."
          },
          {
            "name": "Twitter/X Cards",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add <meta name='twitter:card' content='summary_large_image'>, twitter:title, and twitter:image tags.",
            "whyMatters": "Twitter Cards make your links stand out in X/Twitter feeds. Without them, shared links appear as plain text URLs."
          },
          {
            "name": "Canonical URL",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add a <link rel='canonical'> tag pointing to the preferred URL. For a single-page site this is a one-line addition in <head>.",
            "whyMatters": "Canonical tags prevent search engines from treating URL variants (with/without trailing slash, tracking params) as duplicate pages."
          },
          {
            "name": "Structured Data (JSON-LD)",
            "status": "fail",
            "fixLink": {
              "url": "https://zulien.sk",
              "label": "Add with Schema module →"
            },
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Add JSON-LD structured data: Product (with price, availability, reviews), Organization, BreadcrumbList, and WebSite schemas.",
            "whyMatters": "Pages with structured data get rich snippets in Google — star ratings, prices, availability — increasing CTR by 20-30%."
          },
          {
            "name": "robots.txt",
            "status": "warning",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Create a robots.txt file at your domain root. Include a Sitemap directive pointing to your XML sitemap.",
            "whyMatters": "robots.txt guides search engine crawling. Without it, crawlers may waste budget on irrelevant pages (admin, cart, checkout)."
          },
          {
            "name": "XML Sitemap",
            "status": "fail",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Generate an XML sitemap at /sitemap.xml listing all important pages. Exclude noindex pages, filters, and duplicate URLs. Reference it in robots.txt.",
            "whyMatters": "Sitemaps help Google discover and index pages 3-5x faster, especially for large stores with deep category structures."
          },
          {
            "name": "HTML Language Attribute",
            "value": "lang=\"sk\"",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Image Alt Attributes",
            "value": "No images found",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add relevant images with descriptive alt attributes to improve engagement and image search visibility.",
            "whyMatters": "Images drive 22% of all Google searches. Missing images means missing ranking opportunities."
          },
          {
            "name": "Text-to-HTML Ratio",
            "value": "2% — very thin content (212 words)",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Your page is almost entirely HTML/CSS/JS with very little actual content. Add substantial product descriptions, content blocks, and informational text.",
            "whyMatters": "Google's Helpful Content Update specifically targets thin content pages. This significantly hurts your rankings."
          },
          {
            "name": "Favicon",
            "status": "warning",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Add a favicon: <link rel='icon' href='/favicon.ico'>. Include multiple sizes for different devices (16x16, 32x32, 180x180).",
            "whyMatters": "Favicons appear in browser tabs, bookmarks, and Google search results. Missing favicons look unprofessional and reduce brand recognition."
          },
          {
            "name": "Title/H1 Differentiation",
            "value": "Title and H1 are identical",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Make your title tag and H1 heading different but complementary. The title should include your brand and be click-optimized for SERP. The H1 should be content-focused for on-page experience.",
            "whyMatters": "Identical title and H1 wastes an opportunity to target additional keywords. Different but related title/H1 combinations increase ranking for more keyword variations."
          },
          {
            "name": "Semantic HTML Structure",
            "value": "1/6 semantic elements — poor structure",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Your page lacks semantic HTML5 elements. Replace generic <div> wrappers with <header>, <nav>, <main>, <article>, <aside>, and <footer> to give search engines and screen readers proper content signals.",
            "whyMatters": "Without semantic structure, search engines treat your page as an undifferentiated blob of content. Semantic HTML is essential for featured snippets, voice search, and AI-powered search."
          },
          {
            "name": "Content Depth",
            "value": "Only 212 words — thin content",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add more unique, valuable content. Product pages should have 150+ word descriptions. Category pages benefit from 200+ word introductions. Blog posts need 800+ words to rank.",
            "whyMatters": "Google's Helpful Content Update targets thin content pages. Pages with <300 words rarely rank for competitive keywords. More content = more keyword opportunities."
          },
          {
            "name": "Internal Linking",
            "value": "No internal links found",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add internal links to other pages on your site. Every page should link to related content, categories, and key landing pages.",
            "whyMatters": "A page with zero internal links is isolated from your site's link graph. Google may treat it as low-priority or not index it at all."
          },
          {
            "name": "Accessibility Fundamentals",
            "value": "1/4 a11y signals — missing: ARIA roles, ARIA labels, skip navigation link",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add: ARIA landmark roles (role='navigation', role='main'), aria-label on interactive elements, a 'Skip to content' link, and lang attribute on <html>.",
            "whyMatters": "The European Accessibility Act (EAA) takes effect June 2025 for e-commerce. Non-compliant sites face fines. Accessibility also improves SEO — Google confirms a11y as a ranking signal."
          },
          {
            "name": "Keyboard Navigation (Focus)",
            "value": "outline:none detected without :focus-visible replacement",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Don't remove focus outlines with outline:none. Instead, use :focus-visible to show focus indicators only for keyboard users. This is a WCAG 2.1 AA requirement (2.4.7 Focus Visible).",
            "whyMatters": "Removing focus indicators makes your site unusable for keyboard-only users (3.5% of population). This violates WCAG 2.1 AA and the EAA. Use :focus-visible for a clean solution."
          }
        ]
      },
      "gdpr": {
        "score": 48,
        "checks": [
          {
            "name": "Cookie Consent Banner (CMP)",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get GDPR Compliance →"
            },
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Install a certified consent management platform: Cookiebot, OneTrust, Usercentrics, or CookieYes. The CMP must block ALL non-essential cookies and scripts until explicit consent is given (opt-in, not opt-out).",
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7"
              ],
              "czLaw": [
                "§ 5"
              ],
              "skLaw": [
                "§ 14"
              ]
            },
            "whyMatters": "Since 2024, EU regulators actively enforce cookie consent. CNIL fined Google €150M and Amazon €35M for non-compliant cookie banners. Fines can reach 4% of global annual revenue."
          },
          {
            "name": "Tracking Scripts & Consent",
            "value": "No tracking scripts detected",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7",
                "EDPB Opinion 5/2019"
              ],
              "skLaw": [
                "§ 14"
              ]
            }
          },
          {
            "name": "Privacy Policy Page",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Create a comprehensive privacy policy covering: what data you collect, why (legal basis), how long you store it, who you share it with, and how users can exercise their GDPR rights (access, deletion, portability).",
            "legalRefs": {
              "gdpr": [
                "Art. 12",
                "Art. 13",
                "Art. 14"
              ],
              "czLaw": [
                "§ 8",
                "§ 9"
              ],
              "skLaw": [
                "§ 19",
                "§ 20"
              ]
            },
            "whyMatters": "A missing privacy policy is the #1 most cited GDPR violation. Every EU data protection authority considers this a basic requirement — and fines start at €5,000 for small businesses."
          },
          {
            "name": "Cookie Policy",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Create a separate cookie policy page listing every cookie by: name, provider, purpose, category (necessary/analytics/marketing), and expiration. Most CMPs auto-generate this.",
            "legalRefs": {
              "gdpr": [
                "Art. 12",
                "Art. 13(1)(c)-(e)"
              ],
              "czLaw": [
                "§ 8"
              ],
              "skLaw": [
                "§ 19"
              ]
            },
            "whyMatters": "The ePrivacy Directive requires transparent cookie disclosure. Vague statements like 'we use cookies for functionality' don't meet the specificity requirement."
          },
          {
            "name": "Legal Contact / Imprint Page",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add an imprint/about-us page with: company name, registered address, contact email, VAT number, and trade register info. In Germany/Austria/Switzerland this is legally required (Impressumspflicht).",
            "whyMatters": "In DACH countries, a missing Impressum can result in €50K+ fines and competitor cease-and-desist letters. For all EU stores, identifying the data controller is a GDPR Article 13 requirement."
          },
          {
            "name": "Terms & Conditions Page",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Create Terms & Conditions (AGB) covering: ordering process, payment, delivery, returns, warranty, and dispute resolution. Link it from the footer and checkout.",
            "whyMatters": "EU Consumer Rights Directive requires clear terms before purchase. Missing T&C means customers can claim they weren't informed, giving them extended cancellation rights."
          },
          {
            "name": "Data Encryption (No Mixed Content)",
            "value": "All resources loaded over HTTPS",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Third-party Data Sharing",
            "value": "1 third-party domain(s)",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Right to Erasure (Data Deletion)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Provide a clear mechanism for users to request data deletion — either a dedicated page, a form, or explicit instructions in your privacy policy. Include a 'Delete my account' option in user settings.",
            "legalRefs": {
              "gdpr": [
                "Art. 17"
              ],
              "czLaw": [
                "§ 10"
              ],
              "skLaw": [
                "§ 23"
              ]
            },
            "whyMatters": "GDPR Article 17 gives users the 'right to be forgotten.' EU regulators expect a clear, accessible process. Italian DPA fined companies €20M+ for obstructing erasure requests."
          },
          {
            "name": "Data Protection Officer Contact",
            "value": "DPO / data protection contact found",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Withdrawal of Consent Mechanism",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Provide a clear way to withdraw consent: an 'unsubscribe' link in emails, a 'cookie settings' button in the footer, and a 'revoke consent' section in your privacy policy.",
            "legalRefs": {
              "gdpr": [
                "Art. 7(3)"
              ],
              "skLaw": [
                "§ 14(4)"
              ]
            },
            "whyMatters": "GDPR Article 7(3): 'It shall be as easy to withdraw as to give consent.' If users can subscribe in one click, unsubscribing must be equally simple. Missing this is a common regulatory finding."
          }
        ]
      },
      "nis2": {
        "score": -1,
        "checks": [
          {
            "name": "NIS2 Compliance",
            "value": "Scope undetermined — IČO/company enrichment unavailable for this domain.",
            "status": "info",
            "howToFix": "",
            "whyMatters": ""
          }
        ]
      },
      "mobile": {
        "score": 86,
        "checks": [
          {
            "name": "Viewport Configuration",
            "value": "width=device-width, initial-scale=1",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Mobile Performance Score",
            "value": "95/100 — excellent",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "name": "Touch Target Size",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Ensure ALL interactive elements (buttons, links, form fields) are at least 48×48px with 8px minimum spacing between them. Pay special attention to: navigation menus, filter buttons, product variant selectors, and footer links.",
            "whyMatters": "Small tap targets cause 37% more mis-taps on mobile (Google UX research). In e-commerce, a mis-tap on 'Remove from cart' instead of 'Checkout' directly loses revenue."
          },
          {
            "name": "Font Size Readability",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Set minimum 16px font size for body text. Use relative units (rem/em) instead of px for scalability. Product titles: 18px+, prices: 20px+, CTAs: 16px+ with bold.",
            "whyMatters": "Text smaller than 16px forces mobile users to pinch-zoom. This breaks the responsive layout and creates a frustrating experience. Users over 40 are especially affected — and they have the highest purchasing power."
          },
          {
            "name": "Content Fits Viewport",
            "value": "No horizontal scrolling needed",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Responsive Design Techniques",
            "value": "Flexbox, CSS Grid, Media queries detected",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Theme Color",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add <meta name='theme-color' content='#your-brand-color'> to match your brand. Browsers use this to color the address bar, task switcher, and PWA chrome.",
            "whyMatters": "Theme-color creates a polished, branded mobile experience. It makes your site look native and professional — small detail, big perception impact."
          },
          {
            "name": "Mobile Navigation (Semantic)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Wrap your navigation in a <nav> element. This helps mobile screen readers offer 'skip to navigation' and improves voice navigation (e.g., 'Siri, show me the menu').",
            "whyMatters": "Semantic <nav> elements are essential for mobile accessibility. Screen readers use them to let users jump directly to navigation — critical on small screens where content is long."
          },
          {
            "name": "Print Stylesheet",
            "value": "Order/invoice page without print styles",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add @media print CSS rules to hide navigation, ads, and non-essential elements. Ensure order details, prices, and company info are visible when printed.",
            "whyMatters": "Customers print order confirmations and invoices. Without print styles, they get navigation bars, cookie banners, and broken layouts. This is a common usability complaint for e-commerce."
          },
          {
            "name": "Form Input Labels (WCAG 3.3.2)",
            "value": "Iba 0/7 inputs má label (0%)",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Accessibility audit — Inger"
            },
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "7 input elementov nemá label. Každý input musí mať priradený <label for=\"id\">Text</label> alebo aria-label. Placeholder NIE je label (WCAG 3.3.2). Ak je checkout/registrácia formulár — toto znižuje konverziu a porušuje EN 301 549 (EAA 2026).",
            "whyMatters": "EAA 2026 (European Accessibility Act) vstupuje do platnosti 28.6.2025. E-shopy nad 10 zamestnancov alebo €2M obrat musia byť WCAG 2.1 AA kompatibilné — chýbajúce labely sú jedna z najčastejších žalovateľných chýb."
          },
          {
            "name": "Heading Hierarchy (WCAG 1.3.1)",
            "value": "Žiadne preskočené úrovne",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          }
        ]
      },
      "company": null,
      "modules": [],
      "security": {
        "score": 63,
        "checks": [
          {
            "name": "SSL/TLS Certificate",
            "value": "Valid HTTPS connection established",
            "status": "pass",
            "evidence": {
              "source": "SSL"
            }
          },
          {
            "name": "DNSSEC",
            "value": "No DNSKEY records — zone is unsigned",
            "status": "warning",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "DNSSEC setup help →"
            },
            "evidence": {
              "source": "DNS"
            },
            "howToFix": "Enable DNSSEC at your DNS host (most modern registrars offer 1-click activation: Cloudflare, Route 53, Google Cloud DNS, web.sk, websupport.sk). Verify via dnsviz.net afterwards.",
            "whyMatters": "Without DNSSEC, attackers controlling intermediate resolvers can forge responses for your domain — sending users to phishing sites with valid HTTPS that match your name. EU national CSIRTs (SK-CERT, NÚKIB) recommend DNSSEC for all in-scope entities."
          },
          {
            "name": "CAA DNS Record",
            "value": "No CAA records — any CA can issue certificates for this domain",
            "status": "warning",
            "evidence": {
              "source": "DNS"
            },
            "howToFix": "Publish CAA TXT records pinning your CA. For Let's Encrypt: `0 issue \"letsencrypt.org\"`. For multiple CAs add additional `0 issue \"...\"` records. Add `0 iodef \"mailto:security@yourdomain.tld\"` for misissuance reports.",
            "whyMatters": "CAA records limit which Certificate Authorities can issue certificates for your domain. Without CAA, a compromised or rogue CA can issue valid certs that browsers will trust — a documented breach pattern (DigiNotar 2011, Symantec 2017)."
          },
          {
            "name": "HTTP → HTTPS Redirect",
            "value": "HTTP properly redirects to HTTPS",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "name": "HSTS (Strict-Transport-Security)",
            "value": "max-age=31536000, preload, includeSubDomains",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "name": "Content-Security-Policy (CSP)",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Security Hardening →"
            },
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Implement a CSP header. Start with: Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: — then gradually tighten.",
            "whyMatters": "CSP is the most powerful defense against XSS attacks. Without it, any injected script runs with full privileges. CSP blocks inline script injection, the #1 web attack vector."
          },
          {
            "name": "Clickjacking Protection",
            "status": "fail",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Add X-Frame-Options: DENY (or SAMEORIGIN if iframes are needed). Better: use CSP frame-ancestors 'self'.",
            "whyMatters": "Clickjacking overlays your site in a hidden iframe. Attackers trick users into clicking buttons (like 'Confirm Purchase') without knowing it."
          },
          {
            "name": "X-Content-Type-Options",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Add header: X-Content-Type-Options: nosniff",
            "whyMatters": "Without nosniff, browsers may execute uploaded files as scripts. An attacker could upload a .jpg that's actually JavaScript and trick the browser into running it."
          },
          {
            "name": "Referrer-Policy",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Add header: Referrer-Policy: strict-origin-when-cross-origin — this is the best balance between functionality and privacy.",
            "whyMatters": "Without a referrer policy, browsers send the full URL to third parties. This can leak sensitive data like session tokens in URLs or internal page paths."
          },
          {
            "name": "Permissions-Policy",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Add: Permissions-Policy: camera=(), microphone=(), geolocation=(), payment=() — disable APIs your site doesn't need.",
            "whyMatters": "Without Permissions-Policy, any third-party script (ads, analytics, chat widgets) can access camera, microphone, and geolocation without your knowledge."
          },
          {
            "name": "Cookie Security Flags",
            "value": "No cookies set on initial response",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "name": "Technology Disclosure",
            "value": "Server: Netlify (no version)",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "name": "Subresource Integrity (SRI)",
            "value": "Only 0/1 SRI-eligible third-party scripts have integrity hashes",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add integrity='sha384-...' and crossorigin='anonymous' to version-pinned third-party <script> tags (use srihash.org). Auto-updating provider scripts (analytics, payment SDKs, consent tools) are correctly excluded — they can't use SRI.",
            "whyMatters": "Without SRI, if a version-pinned third-party CDN is compromised, attackers can inject malicious code into your site. The British Airways breach (£20M fine) was exactly this attack vector."
          },
          {
            "name": "security.txt (RFC 9116)",
            "status": "warning",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Create /.well-known/security.txt with Contact, Expires, and Preferred-Languages fields. See securitytxt.org for the generator.",
            "whyMatters": "security.txt lets ethical hackers report vulnerabilities responsibly. Without it, they may disclose publicly or not report at all. Required by ISO 27001 and SOC 2."
          },
          {
            "name": "Server Version Disclosure",
            "value": "Netlify — version hidden",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "name": "CDN / WAF Protection",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Add a CDN/WAF like Cloudflare (free tier), Sucuri, or Fastly. They provide DDoS protection, bot filtering, and SSL management.",
            "whyMatters": "Without a CDN/WAF, your origin server is directly exposed to DDoS attacks, bot traffic, and brute-force attempts. Cloudflare blocks 150+ billion daily threats."
          },
          {
            "name": "SSL Certificate on Alternate Hostname",
            "value": "www.globalfamilyoffices.netlify.app has an invalid or expired SSL certificate",
            "status": "warning",
            "evidence": {
              "source": "SSL",
              "probedUrl": "https://www.globalfamilyoffices.netlify.app"
            },
            "howToFix": "Your SSL certificate doesn't cover www.globalfamilyoffices.netlify.app. Install a certificate that covers both www and non-www variants, or use a wildcard certificate (*.globalfamilyoffices.netlify.app). Users visiting www.globalfamilyoffices.netlify.app will see a browser security warning.",
            "whyMatters": "If either www or non-www variant has an invalid certificate, visitors who type that version will see a scary browser warning and leave immediately. Search engines may also flag this as a security issue."
          }
        ]
      },
      "tech_stack": [
        {
          "name": "Chart.js",
          "category": "js-library"
        },
        {
          "name": "Netlify",
          "category": "server"
        }
      ],
      "performance": {
        "score": 95,
        "checks": [
          {
            "name": "Server Response Time (TTFB)",
            "value": "86ms",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "name": "First Contentful Paint (FCP)",
            "value": "0.70s",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "name": "Largest Contentful Paint (LCP)",
            "value": "0.70s — Core Web Vital ✓",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "name": "Total Blocking Time (TBT)",
            "value": "0ms",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "name": "Cumulative Layout Shift (CLS)",
            "value": "0.000 — Core Web Vital ✓",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "name": "Speed Index",
            "value": "0.72s",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "name": "Total Page Weight",
            "value": "96 KB (3 requests)",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "name": "Render-blocking Resources",
            "value": "Not measured — PageSpeed did not return the render-blocking audit for this URL",
            "status": "info",
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "Re-run the scan, or test directly at PageSpeed Insights. This metric needs a successful Lighthouse lab run."
          },
          {
            "name": "Unused Code (CSS + JS)",
            "value": "Only 33 KB of unused code — well optimized",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "name": "Text Compression (gzip/brotli)",
            "value": "All text resources properly compressed",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "name": "Resource Hints (Preload/Preconnect)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add resource hints: <link rel='preconnect' href='https://fonts.googleapis.com'> for third-party origins, <link rel='preload' as='image' href='hero.webp'> for critical resources.",
            "whyMatters": "Preconnect saves 100-500ms per third-party origin by establishing connections early. Preload starts downloading critical resources before the browser discovers them in CSS/JS."
          },
          {
            "name": "Script Loading Strategy",
            "value": "Only 0% of 1 scripts optimized — most are render-blocking",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Performance Optimization →"
            },
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add defer or async to all <script src='...'> tags. Render-blocking scripts are the #1 cause of slow FCP. Defer maintains execution order, async does not.",
            "whyMatters": "1 render-blocking scripts can add 1-3 seconds to page load. Each synchronous script creates a sequential download-parse-execute chain."
          }
        ]
      },
      "ai_readiness": {
        "score": 33,
        "checks": [
          {
            "name": "AI Bot Access Policy",
            "value": "No AI bot restrictions (allowed by default)",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "llms.txt (AI Site Descriptor)",
            "status": "fail",
            "fixLink": {
              "url": "https://llmstxt.org",
              "label": "Learn about llms.txt →"
            },
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Create /llms.txt in Markdown format:\n# Your Store Name\n> One-line summary of your business and key offerings.\n\nDetailed description paragraph.\n\n## Products\n- [Product Category](URL): Description\n\n## About\n- [About Us](URL): Company history and values\n\nSee llmstxt.org for the full specification.",
            "whyMatters": "llms.txt is the emerging standard for AI-readable site descriptions — like robots.txt was for search engines. Early adopters (Yoast, Cloudflare, Stripe) are already using it. Without it, AI assistants have no guided overview of your store."
          },
          {
            "name": "llms-full.txt (Complete AI Content)",
            "status": "warning",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Create /llms-full.txt containing your complete site documentation in a single Markdown file — product catalog summaries, FAQs, policies, brand story. This gives AI models maximum context about your store.",
            "whyMatters": "llms-full.txt provides AI models with your entire site content in one parseable file. It's the difference between an AI having a brief overview vs. deep knowledge of your products and services."
          },
          {
            "name": "Content Accessibility for AI",
            "value": "212 words in raw HTML (2.2% text ratio) — readable by AI crawlers without executing JS",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Structured Data Foundation",
            "status": "fail",
            "fixLink": {
              "url": "https://zulien.sk",
              "label": "Add structured data →"
            },
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Add JSON-LD structured data immediately. Priority order: 1) Organization, 2) Product (with offers), 3) BreadcrumbList, 4) WebSite+SearchAction, 5) FAQPage. Use JSON-LD format exclusively — not Microdata or RDFa.",
            "whyMatters": "Without structured data, your store is invisible to AI commerce. Google AI Overviews, ChatGPT Shopping, Perplexity, and Bing Copilot all rely on schema markup to understand and recommend products."
          },
          {
            "name": "Organization Schema + Entity Linking",
            "status": "fail",
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Add Organization (or LocalBusiness for physical stores) schema with: name, logo, url, description, contactPoint, address, and sameAs linking to all your official profiles (LinkedIn, Facebook, Wikipedia if available).",
            "whyMatters": "Organization schema is the foundation of your AI identity. Without it, AI assistants can't confidently attribute information to your brand, verify your legitimacy, or show your Knowledge Panel."
          },
          {
            "name": "FAQ Schema (Direct AI Answers)",
            "status": "warning",
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Add FAQPage schema to every product page and category page. Include 3-5 Q&As per page covering: product specifications, shipping, returns, usage instructions. Format: question (full sentence) + answer (75-150 words).",
            "whyMatters": "FAQ schema provides 30% higher AI citation rates (LLMClicks research). ChatGPT, Perplexity, and Google AI Overviews pull FAQ answers verbatim. It's the fastest way to get your content cited by AI."
          },
          {
            "name": "Content Depth for AI",
            "value": "212 words — add more for better AI citations",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Expand to 500+ words: add detailed product descriptions, use cases, benefits, specifications, comparison info, and buying guides. AI needs substantial content to summarize and cite.",
            "whyMatters": "76.4% of ChatGPT's top 1000 cited pages have 500+ words. AI assistants skip thin pages in favor of content-rich competitors. Aim for the depth that makes your page the definitive resource."
          },
          {
            "name": "Answer-First Content Format",
            "value": "Content doesn't start with a strong summary paragraph",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Place your most important information in the first 100 words of the page. Use the BLUF method (Bottom Line Up Front): start with what the product IS and why it matters, then elaborate.",
            "whyMatters": "AI assistants extract content from the first 100 words to generate summaries. The LLMClicks analyzer found pages with answer-first format get 40% more AI citations. Most AI systems read top-down."
          },
          {
            "name": "Heading Hierarchy for AI",
            "value": "1 H1, 0 H2, 0 H3 — poor structure",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Use exactly 1 H1 (page title), then organize content with H2 sections and H3 subsections. Each heading should describe the content that follows. Never skip heading levels (H1→H3 without H2).",
            "whyMatters": "AI extracts information based on heading structure. Pages with proper H1→H2→H3 hierarchy are more accurately parsed by ChatGPT, Perplexity, and Google AI Overviews. Without it, AI may misinterpret your content."
          },
          {
            "name": "Semantic HTML Structure",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Replace <div> wrappers with: <header> (site header), <nav> (navigation), <main> (primary content), <article> (self-contained content), <aside> (sidebar), <footer>. This is the foundation of AI-readable HTML.",
            "whyMatters": "Without semantic HTML, AI must guess content boundaries. This leads to navigation text mixed into product descriptions, footer content cited as main content, and overall poor AI understanding of your pages."
          },
          {
            "name": "Structured Content (Lists & Tables)",
            "value": "No structured content elements found",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add bulleted lists for features/benefits, numbered lists for steps/rankings, and tables for comparisons/specifications. These are the content formats AI extracts most reliably.",
            "whyMatters": "Unstructured paragraph-only content is harder for AI to parse and cite. Pages with lists and tables get cited 30-40% more in AI-generated answers because AI can extract specific facts more reliably."
          },
          {
            "name": "Content Freshness Signals",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add dateModified and datePublished to your JSON-LD schema, and display a visible 'Last updated' date on the page. Update content quarterly at minimum. AI heavily favors fresh, maintained content.",
            "whyMatters": "No freshness signals = AI assumes your content is stale. ChatGPT and Perplexity both weight recency in their citation algorithms. Competitors who show recent updates will be cited instead of your static pages."
          },
          {
            "name": "Entity Clarity & Brand Signals",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Your brand has weak entity signals. Add: 1) Complete OG meta tags, 2) Organization schema with sameAs linking to all official profiles, 3) Consistent NAP (Name, Address, Phone) across the web.",
            "whyMatters": "AI assistants must be confident about entity identity before making recommendations. Without clear brand signals, AI defaults to better-known competitors. This is a fundamental AI visibility requirement."
          },
          {
            "name": "Author Expertise Signals (E-E-A-T)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "For content pages (blog, guides, about): add Article/BlogPosting schema with author property linking to Person schema. Include the author's jobTitle, credentials, and social profiles.",
            "whyMatters": "AI models weight author expertise heavily. Pages from identified experts get cited 3x more than anonymous content. This is especially important for product guides, reviews, and advice content."
          },
          {
            "name": "Extractable Answer Blocks",
            "value": "Too few content paragraphs for AI to extract",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add structured content with clear, focused paragraphs (40-80 words each). Each paragraph should answer one question or make one claim that AI can quote directly.",
            "whyMatters": "AI assistants extract individual paragraphs as citations. Without clear, self-contained content blocks, your page can't be quoted in AI-generated answers."
          },
          {
            "name": "Statistics & Data Presence",
            "value": "No statistical data found in content",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add numbers: pricing comparisons, performance metrics, customer statistics, industry benchmarks. Specific data (e.g., '99.9% uptime', '4.8/5 rating from 2,400 reviews') is what AI quotes most.",
            "whyMatters": "Content without data is 41% less likely to be cited by AI. Perplexity and ChatGPT specifically seek pages with quantified claims and verifiable statistics."
          },
          {
            "name": "Q&A Format Headings",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add H2/H3 headings phrased as questions your customers ask: 'How much does shipping cost?', 'What sizes are available?', 'How do I return an item?' Follow each with a direct, concise answer.",
            "whyMatters": "Q&A content format matches how people query AI assistants. Without question-format headings, your content is harder for AI to map to user queries."
          },
          {
            "name": "Internal Link Density",
            "value": "Almost no internal links in content",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add contextual internal links throughout your content: link to related products, categories, guides, and FAQs. Use descriptive anchor text (not 'click here'). Target 3-5 links per 1,000 words.",
            "whyMatters": "Without internal links, AI crawlers treat each page as isolated content. Internal linking creates a semantic web that helps AI understand your product catalog, categories, and content relationships."
          },
          {
            "name": "Canonical Tag for AI Deduplication",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add <link rel='canonical' href='https://your-absolute-url'> to every page. This tells AI engines which URL is the authoritative version of this content.",
            "whyMatters": "Without a canonical tag, AI models may index multiple versions of the same page (with/without trailing slash, with parameters, etc.), diluting your AI visibility across duplicate URLs."
          },
          {
            "name": "Knowledge Graph Readiness",
            "value": "1/4 signals — missing: @id in JSON-LD, sameAs links (Wikipedia, LinkedIn), Organization schema",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add: @id in JSON-LD, sameAs links (Wikipedia, LinkedIn), Organization schema. Use @id in JSON-LD to create a unique node identifier. Ensure your brand name is identical in title, schema, and OG tags. Link to Wikipedia/Wikidata via sameAs.",
            "whyMatters": "Brands with verified Knowledge Graph presence receive 3.1x more AI citations. @id creates a persistent entity identifier that connects your schema across pages and platforms."
          },
          {
            "name": "Content Readability for AI",
            "value": "Grade 20 — too complex for broad AI citation",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Simplify sentences (target 15-20 words average), use common words, break complex ideas into shorter paragraphs. AI extracts content for general audiences — if it's too academic, AI skips it.",
            "whyMatters": "Content above grade 12 readability is harder for AI to extract as clear, concise answers. Pages using clear headers and approachable language are 28% more likely to be cited by AI."
          },
          {
            "name": "Expert Quotations & Citations",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add 2-3 expert quotes or data citations per major page. Use <blockquote> for quotes and link to authoritative sources (.gov, .edu, Wikipedia, industry reports).",
            "whyMatters": "Content without citations or expert quotes appears unverified to AI. AI assistants prefer content backed by named sources, data references, and expert opinions."
          },
          {
            "name": "ai.txt (AI Permissions)",
            "status": "warning",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Create /ai.txt or /.well-known/ai.txt to declare granular AI permissions per content type: which AI actions (summarization, training, extraction) are allowed for which content sections.",
            "whyMatters": "ai.txt is an emerging standard (proposed May 2025) for fine-grained AI permissions beyond robots.txt. Early adoption signals AI-forward thinking and gives you control over how AI uses your content."
          },
          {
            "name": "WebMCP Agentic Readiness",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "WebMCP (W3C Community Group standard, Chrome 146+) lets pages declare structured tools for AI agents. Add toolname and tooldescription attributes to <form> elements, or include a <script type='application/webmcp+json'> manifest.",
            "whyMatters": "WebMCP is called 'the new Schema.org moment' — it's how AI agents will interact with your store (search products, add to cart, check availability). Google and Microsoft are co-developing this standard."
          },
          {
            "name": "Content-to-Boilerplate Ratio",
            "value": "No <main> or <article> elements — AI can't isolate content from boilerplate",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add <main> around your primary content and <article> around self-contained content blocks. This creates clear boundaries for AI content extraction.",
            "whyMatters": "Without semantic containers, AI crawlers must guess where content starts and navigation ends. This leads to poor content extraction and fewer citations."
          },
          {
            "name": "Social Proof (Testimonials / Case Studies)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add at least one form of social proof: 1) Client testimonials as <blockquote> with attribution, 2) Case study / portfolio section with past work, 3) 'Trusted by' client logo strip. For B2B, this is the #1 credibility lever.",
            "whyMatters": "Without visible social proof, B2B prospects can't verify your track record before reaching out. Missing testimonials/case studies is the #1 reason consultancy sites lose qualified leads at the contact stage."
          }
        ]
      },
      "vulnerability": {
        "score": 79,
        "checks": [
          {
            "name": "CMS Version Disclosure",
            "value": "No generator tag — CMS identity hidden",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Sensitive Files Exposed",
            "value": ".env, .git, composer.json — all properly blocked",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "Install Script Exposed",
            "value": "No /install/ or /setup/ paths accessible",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "Directory Listing",
            "value": "Disabled — file structure hidden",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "Admin Panel at Default URL",
            "value": "Not found at common paths (/admin, /wp-admin, /administrator, /backoffice)",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "Debug Mode / Error Exposure",
            "value": "No debug indicators found in page output",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "SPF Record (Email Security)",
            "status": "fail",
            "evidence": {
              "source": "DNS"
            },
            "howToFix": "Add an SPF TXT record to your DNS: v=spf1 include:_spf.google.com ~all (adjust for your email provider). This tells receiving servers which IPs can send email for your domain.",
            "whyMatters": "Without SPF, anyone can send emails that appear to come from your domain. Since 2024, Google and Yahoo reject email from domains without SPF. Your transactional emails may land in spam."
          },
          {
            "name": "DMARC Policy (Email Auth)",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Email Security Setup →"
            },
            "evidence": {
              "source": "DNS"
            },
            "howToFix": "Add a DMARC TXT record at _dmarc.yourdomain.com: v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com — start with quarantine, then move to reject.",
            "whyMatters": "Without DMARC, attackers can send perfectly spoofed emails as your brand. Since May 2025, Google, Yahoo, and Microsoft require DMARC for bulk senders. Missing DMARC = email deliverability problems."
          },
          {
            "name": "Email Infrastructure",
            "value": "No MX records — domain does not receive email",
            "status": "info",
            "evidence": {
              "source": "DNS"
            }
          },
          {
            "name": "Cross-Origin Isolation",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Add Cross-Origin-Opener-Policy: same-origin and Cross-Origin-Resource-Policy: same-origin headers. These protect against Spectre-type side-channel attacks.",
            "whyMatters": "Without cross-origin isolation headers, your site is vulnerable to Spectre attacks that can leak sensitive data across browser tabs. These headers are required for SharedArrayBuffer and high-resolution timers."
          },
          {
            "name": "CDN Script Integrity (SRI)",
            "value": "1 CDN script(s) without Subresource Integrity",
            "status": "warning",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Add integrity='sha384-...' crossorigin='anonymous' to CDN scripts from: cdn.jsdelivr.net. Generate hashes at srihash.org.",
            "whyMatters": "CDN scripts without SRI can be tampered with if the CDN is compromised. The polyfill.io attack (2024, 380K+ sites) and British Airways breach (£20M fine) were both CDN supply chain attacks."
          }
        ]
      },
      "opendata_security": null
    },
    "created_at": "2026-06-22T12:22:33.908211+00:00",
    "status": "complete",
    "platform_detected": null,
    "company_ico": null,
    "company_name": null,
    "company_country": null,
    "company_nace": null,
    "company_size": null,
    "nis2_scope": null,
    "nis2_sector": null,
    "company_risk_score": null,
    "company_risk_level": null
  }
}