{
  "data": {
    "slug": "ccf24e0c",
    "url": "https://hetzner.truckershop.sk/",
    "domain": "hetzner.truckershop.sk",
    "overall_score": 79,
    "scores_json": {
      "seo": {
        "score": 89,
        "checks": [
          {
            "i18n": {
              "key": "seo.meta-title.pass",
              "params": {
                "chars": 47,
                "title": "TRUCKERSHOP.SK - Vybavenie pre nákladnú dopravu"
              }
            },
            "name": "Meta Title",
            "value": "47 chars — \"TRUCKERSHOP.SK - Vybavenie pre nákladnú dopravu\"",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.meta-desc.pass",
              "params": {
                "chars": 157
              }
            },
            "name": "Meta Description",
            "value": "157 chars",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.h1.pass",
              "params": {
                "text": "TRUCKERSHOP.SK – Vybavenie, doplnky a náhradné diely pre kam…"
              }
            },
            "name": "H1 Heading",
            "value": "\"TRUCKERSHOP.SK – Vybavenie, doplnky a náhradné diely pre kam…\"",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.h2.pass",
              "params": {
                "count": 7
              }
            },
            "name": "Content Structure (H2 Headings)",
            "value": "7 H2 subheadings found",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.og.pass",
              "params": {
                "tags": "og:title, og:description, og:image, og:type"
              }
            },
            "name": "Open Graph Tags",
            "value": "og:title, og:description, og:image, og:type",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.og-format.pass",
              "params": {
                "contentType": "image/jpeg"
              }
            },
            "name": "Open Graph Image Format",
            "value": "image/jpeg",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.twitter.pass",
              "params": {
                "card": "summary_large_image"
              }
            },
            "name": "Twitter/X Cards",
            "value": "Card type: summary_large_image",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.canonical.pass",
              "params": {
                "url": "https://hetzner.truckershop.sk/"
              }
            },
            "name": "Canonical URL",
            "value": "https://hetzner.truckershop.sk/",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.jsonld.pass",
              "params": {
                "count": 6,
                "types": "Organization, ImageObject, WebPage, WebSite"
              }
            },
            "name": "Structured Data (JSON-LD)",
            "value": "6 block(s): Organization, ImageObject, WebPage, WebSite",
            "status": "pass",
            "evidence": {
              "source": "schema"
            }
          },
          {
            "i18n": {
              "key": "seo.jsonld-valid.pass",
              "params": {
                "count": 6
              }
            },
            "name": "JSON-LD Validity",
            "value": "6 block(s) parse cleanly",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.robots.pass-sitemap"
            },
            "name": "robots.txt",
            "value": "Present, references sitemap",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "i18n": {
              "key": "seo.sitemap.fail"
            },
            "name": "XML Sitemap",
            "status": "fail",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Generate an XML sitemap at /sitemap.xml listing all important pages. Exclude noindex pages, filters, and duplicate URLs. Reference it in robots.txt.",
            "whyMatters": "Sitemaps help Google discover and index pages faster, especially for large stores with deep category structures."
          },
          {
            "i18n": {
              "key": "seo.html-lang.pass",
              "params": {
                "lang": "sk-SK"
              }
            },
            "name": "HTML Language Attribute",
            "value": "lang=\"sk-SK\"",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.img-alt.pass",
              "params": {
                "rate": 100,
                "total": 218
              }
            },
            "name": "Image Alt Attributes",
            "value": "100% of 218 images have alt text",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.text-ratio.info",
              "params": {
                "ratio": 3,
                "words": 2722
              }
            },
            "name": "Text-to-HTML Ratio",
            "value": "3% ratio but 2722 words — content is substantial; the low ratio is markup/inline-JS bloat, not thin content",
            "status": "info",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Your text content is sufficient. To raise the ratio, move inline <script>/<style> to external files and trim template bloat — this is a performance/cleanliness win, not a content gap.",
            "whyMatters": "Text-to-HTML ratio is only a thin-content signal when actual word count is also low. With 500+ words, search engines have plenty to rank on."
          },
          {
            "i18n": {
              "key": "seo.favicon.pass"
            },
            "name": "Favicon",
            "value": "Favicon detected",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "i18n": {
              "key": "seo.img-format.warning-partial",
              "params": {
                "rate": 13,
                "legacy": 189
              }
            },
            "name": "Image Format Optimization",
            "value": "Only 13% next-gen formats — 189 legacy images remain",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Convert remaining JPEG/PNG images to WebP (30-50% smaller) or AVIF (50-70% smaller). Use the <picture> element for browser fallback.",
            "whyMatters": "WebP/AVIF images are 30-70% smaller than JPEG/PNG at the same quality. This directly improves page speed, LCP, and mobile experience."
          },
          {
            "i18n": {
              "key": "seo.semantic.pass",
              "params": {
                "used": "<article>, <nav>, <main>, <header>, <footer>",
                "count": 5
              }
            },
            "name": "Semantic HTML Structure",
            "value": "5/6 semantic elements: <article>, <nav>, <main>, <header>, <footer>",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.content-depth.pass",
              "params": {
                "words": 2722
              }
            },
            "name": "Content Depth",
            "value": "2722 words — sufficient content",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.deep-heading.pass",
              "params": {
                "h2": 7,
                "h3": 6
              }
            },
            "name": "Deep Heading Hierarchy",
            "value": "H2: 7, H3: 6 — well-structured content",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.internal-links.pass",
              "params": {
                "count": 307
              }
            },
            "name": "Internal Linking",
            "value": "307 internal links — strong site navigation",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.dead-links.warning",
              "params": {
                "hash": 3,
                "empty": 7,
                "total": 10,
                "jsvoid": 0
              }
            },
            "name": "Empty/Dead Links",
            "value": "10 dead links (7 empty, 3 hash-only, 0 javascript:void)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Replace empty href='', href='#', and href='javascript:void(0)' with actual URLs. If interactive, use <button> instead of <a>.",
            "whyMatters": "Dead links waste crawl budget and confuse search engines. They also create poor user experience — users click expecting navigation and nothing happens."
          },
          {
            "i18n": {
              "key": "seo.a11y.pass",
              "params": {
                "detail": "125 ARIA roles, 175 ARIA labels, lang=\"sk-SK\"",
                "signals": 3
              }
            },
            "name": "Accessibility Fundamentals",
            "value": "3/4 a11y signals: 125 ARIA roles, 175 ARIA labels, lang=\"sk-SK\"",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.broken-images.warning",
              "params": {
                "count": 1
              }
            },
            "name": "Broken Image Sources",
            "value": "1 image(s) with empty src attribute",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Fix images with empty src=''. Either add proper URLs or use loading='lazy' with valid data-src for lazy-loaded images.",
            "whyMatters": "Empty src attributes cause extra HTTP requests to the page URL, waste bandwidth, and show broken image icons to users."
          },
          {
            "i18n": {
              "key": "seo.sitemap-host.warning",
              "params": {
                "pageHost": "hetzner.truckershop.sk",
                "sitemapHost": "truckershop.sk"
              }
            },
            "name": "Sitemap Host Consistency",
            "value": "robots.txt Sitemap points to truckershop.sk (page is hetzner.truckershop.sk)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Update the Sitemap: line in robots.txt to your canonical host. A staging/dev hostname (new., staging., dev.) leaks pre-production to Google and feeds crawlers URLs that 404 or duplicate the live site.",
            "whyMatters": "Google fetches the sitemap from the host declared in robots.txt. A staging domain there either exposes an environment that must not be indexed, or sends every crawl to the wrong host — splitting ranking signals and burning crawl budget."
          }
        ]
      },
      "gdpr": {
        "score": 80,
        "checks": [
          {
            "i18n": {
              "key": "gdpr.cmp.pass",
              "params": {
                "provider": "CookieYes"
              }
            },
            "name": "Cookie Consent Banner (CMP)",
            "value": "CookieYes detected",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7"
              ],
              "skLaw": [
                "§ 14"
              ],
              "verified": [
                {
                  "title": "Zákonnosť spracúvania",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 6 — Zákonnosť spracúvania 1. Spracúvanie je zákonné iba vtedy a iba v tom rozsahu, keď je splnená aspoň jedna z týchto podmienok: Písmeno f) prvého pododseku sa nevzťahuje na spracúvanie vykonávané orgánmi verejnej moci pri výkone i",
                  "citation": "čl. 6 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky vyjadrenia súhlasu",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 7 — Podmienky vyjadrenia súhlasu 1. Ak je spracúvanie založené na súhlase, prevádzkovateľ musí vedieť preukázať, že dotknutá osoba vyjadrila súhlas so spracúvaním svojich osobných údajov. 2. Ak dá dotknutá osoba súhlas v rámci písom",
                  "citation": "čl. 7 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky poskytnutia súhlasu so spracúvaním osobných údajov",
                  "excerpt": "§ 14 Podmienky poskytnutia súhlasu so spracúvaním osobných údajov (1) Ak je spracúvanie osobných údajov založené na súhlase dotknutej osoby, prevádzkovateľ je povinný kedykoľvek vedieť preukázať, že dotknutá osoba poskytla súhlas so spracúv",
                  "citation": "§14 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            }
          },
          {
            "i18n": {
              "key": "gdpr.tracking.pass",
              "params": {
                "count": 1,
                "trackers": "Google Analytics/GTM"
              }
            },
            "name": "Tracking Scripts & Consent",
            "value": "1 tracker(s) detected with CMP: Google Analytics/GTM",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7",
                "EDPB Opinion 5/2019"
              ],
              "skLaw": [
                "§ 14"
              ],
              "verified": [
                {
                  "title": "Zákonnosť spracúvania",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 6 — Zákonnosť spracúvania 1. Spracúvanie je zákonné iba vtedy a iba v tom rozsahu, keď je splnená aspoň jedna z týchto podmienok: Písmeno f) prvého pododseku sa nevzťahuje na spracúvanie vykonávané orgánmi verejnej moci pri výkone i",
                  "citation": "čl. 6 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky vyjadrenia súhlasu",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 7 — Podmienky vyjadrenia súhlasu 1. Ak je spracúvanie založené na súhlase, prevádzkovateľ musí vedieť preukázať, že dotknutá osoba vyjadrila súhlas so spracúvaním svojich osobných údajov. 2. Ak dá dotknutá osoba súhlas v rámci písom",
                  "citation": "čl. 7 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky poskytnutia súhlasu so spracúvaním osobných údajov",
                  "excerpt": "§ 14 Podmienky poskytnutia súhlasu so spracúvaním osobných údajov (1) Ak je spracúvanie osobných údajov založené na súhlase dotknutej osoby, prevádzkovateľ je povinný kedykoľvek vedieť preukázať, že dotknutá osoba poskytla súhlas so spracúv",
                  "citation": "§14 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            }
          },
          {
            "i18n": {
              "key": "gdpr.consent-mode.pass"
            },
            "name": "Google Consent Mode v2",
            "value": "Consent mode signals detected (ad_storage, analytics_storage)",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7"
              ],
              "skLaw": [
                "§ 14"
              ],
              "verified": [
                {
                  "title": "Zákonnosť spracúvania",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 6 — Zákonnosť spracúvania 1. Spracúvanie je zákonné iba vtedy a iba v tom rozsahu, keď je splnená aspoň jedna z týchto podmienok: Písmeno f) prvého pododseku sa nevzťahuje na spracúvanie vykonávané orgánmi verejnej moci pri výkone i",
                  "citation": "čl. 6 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky vyjadrenia súhlasu",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 7 — Podmienky vyjadrenia súhlasu 1. Ak je spracúvanie založené na súhlase, prevádzkovateľ musí vedieť preukázať, že dotknutá osoba vyjadrila súhlas so spracúvaním svojich osobných údajov. 2. Ak dá dotknutá osoba súhlas v rámci písom",
                  "citation": "čl. 7 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky poskytnutia súhlasu so spracúvaním osobných údajov",
                  "excerpt": "§ 14 Podmienky poskytnutia súhlasu so spracúvaním osobných údajov (1) Ak je spracúvanie osobných údajov založené na súhlase dotknutej osoby, prevádzkovateľ je povinný kedykoľvek vedieť preukázať, že dotknutá osoba poskytla súhlas so spracúv",
                  "citation": "§14 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            }
          },
          {
            "i18n": {
              "key": "gdpr.privacy-policy.pass",
              "params": {
                "url": "//hetzner.truckershop.sk/content/2-ochrana-osobnych-udajov"
              }
            },
            "name": "Privacy Policy Page",
            "value": "//hetzner.truckershop.sk/content/2-ochrana-osobnych-udajov",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "legalRefs": {
              "gdpr": [
                "Art. 12",
                "Art. 13",
                "Art. 14"
              ],
              "skLaw": [
                "§ 19",
                "§ 20"
              ],
              "verified": [
                {
                  "title": "Transparentnosť informácií, oznámenia a postupy výkonu práv dotknutej osoby",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 12 — Transparentnosť informácií, oznámenia a postupy výkonu práv dotknutej osoby 3. Prevádzkovateľ poskytne dotknutej osobe informácie o opatreniach, ktoré sa prijali na základe žiadosti podľa článkov 15 až 22, bez zbytočného odklad",
                  "citation": "čl. 12 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Informácie, ktoré sa majú poskytovať pri získavaní osobných údajov od dotknutej osoby",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 13 — Informácie, ktoré sa majú poskytovať pri získavaní osobných údajov od dotknutej osoby 2. Okrem informácií, ktoré sa uvádzajú v odseku 1, prevádzkovateľ poskytne dotknutej osobe pri získavaní osobných údajov tieto ďalšie informá",
                  "citation": "čl. 13 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Informácie, ktoré sa majú poskytnúť, ak osobné údaje neboli získané od dotknutej osoby",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 14 — Informácie, ktoré sa majú poskytnúť, ak osobné údaje neboli získané od dotknutej osoby 2. Okrem informácií uvedených v odseku 1 prevádzkovateľ poskytne dotknutej osobe tieto ďalšie informácie potrebné na zabezpečenie spravodliv",
                  "citation": "čl. 14 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Poskytované informácie, ak osobné údaje sú získané od dotknutej osoby",
                  "excerpt": "§ 19 Poskytované informácie, ak osobné údaje sú získané od dotknutej osoby (4) Odseky 1 až 3 sa neuplatňujú v rozsahu, v akom boli informácie dotknutej osobe poskytnuté pred spracúvaním osobných údajov.",
                  "citation": "§19 ods. 4 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                },
                {
                  "title": "Poskytované informácie, ak osobné údaje nie sú získané od dotknutej osoby",
                  "excerpt": "§ 20 Poskytované informácie, ak osobné údaje nie sú získané od dotknutej osoby (5) d) ak osobné údaje musia zostať dôverné na základe povinnosti mlčanlivosti podľa osobitného predpisu. 15 )",
                  "citation": "§20 ods. 5 písm. d) zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            }
          },
          {
            "i18n": {
              "key": "gdpr.cookie-policy.warning"
            },
            "name": "Cookie Policy",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Create a separate cookie policy page listing every cookie by: name, provider, purpose, category (necessary/analytics/marketing), and expiration. Most CMPs auto-generate this.",
            "legalRefs": {
              "gdpr": [
                "Art. 12",
                "Art. 13(1)(c)-(e)"
              ],
              "skLaw": [
                "§ 19"
              ],
              "verified": [
                {
                  "title": "Transparentnosť informácií, oznámenia a postupy výkonu práv dotknutej osoby",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 12 — Transparentnosť informácií, oznámenia a postupy výkonu práv dotknutej osoby 3. Prevádzkovateľ poskytne dotknutej osobe informácie o opatreniach, ktoré sa prijali na základe žiadosti podľa článkov 15 až 22, bez zbytočného odklad",
                  "citation": "čl. 12 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Informácie, ktoré sa majú poskytovať pri získavaní osobných údajov od dotknutej osoby",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 13 — Informácie, ktoré sa majú poskytovať pri získavaní osobných údajov od dotknutej osoby 2. Okrem informácií, ktoré sa uvádzajú v odseku 1, prevádzkovateľ poskytne dotknutej osobe pri získavaní osobných údajov tieto ďalšie informá",
                  "citation": "čl. 13 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Poskytované informácie, ak osobné údaje sú získané od dotknutej osoby",
                  "excerpt": "§ 19 Poskytované informácie, ak osobné údaje sú získané od dotknutej osoby (4) Odseky 1 až 3 sa neuplatňujú v rozsahu, v akom boli informácie dotknutej osobe poskytnuté pred spracúvaním osobných údajov.",
                  "citation": "§19 ods. 4 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            },
            "whyMatters": "The ePrivacy Directive requires transparent cookie disclosure. Vague statements like 'we use cookies for functionality' don't meet the specificity requirement."
          },
          {
            "i18n": {
              "key": "gdpr.imprint.pass",
              "params": {
                "url": "//hetzner.truckershop.sk/content/4-o-nas"
              }
            },
            "name": "Legal Contact / Imprint Page",
            "value": "//hetzner.truckershop.sk/content/4-o-nas",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "gdpr.terms.pass",
              "params": {
                "url": "//hetzner.truckershop.sk/content/3-obchodne-podmienky"
              }
            },
            "name": "Terms & Conditions Page",
            "value": "//hetzner.truckershop.sk/content/3-obchodne-podmienky",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "gdpr.mixed-content.pass"
            },
            "name": "Data Encryption (No Mixed Content)",
            "value": "All resources loaded over HTTPS",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "gdpr.third-party.pass",
              "params": {
                "count": 3
              }
            },
            "name": "Third-party Data Sharing",
            "value": "3 third-party domain(s)",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "gdpr.erasure.warning"
            },
            "name": "Right to Erasure (Data Deletion)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Provide a clear mechanism for users to request data deletion — either a dedicated page, a form, or explicit instructions in your privacy policy. Include a 'Delete my account' option in user settings.",
            "legalRefs": {
              "gdpr": [
                "Art. 17"
              ],
              "skLaw": [
                "§ 23"
              ],
              "verified": [
                {
                  "title": "Právo na vymazanie (právo „na zabudnutie“)",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 17 — Právo na vymazanie (právo „na zabudnutie“) 1. Dotknutá osoba má tiež právo dosiahnuť u prevádzkovateľa bez zbytočného odkladu vymazanie osobných údajov, ktoré sa jej týkajú, a prevádzkovateľ je povinný bez zbytočného odkladu vy",
                  "citation": "čl. 17 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Právo na výmaz osobných údajov",
                  "excerpt": "§ 23 Právo na výmaz osobných údajov (1) Dotknutá osoba má právo na to, aby prevádzkovateľ bez zbytočného odkladu vymazal osobné údaje, ktoré sa jej týkajú.",
                  "citation": "§23 ods. 1 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            },
            "whyMatters": "GDPR Article 17 gives users the 'right to be forgotten.' EU regulators expect a clear, accessible process, and obstructing erasure requests is a documented enforcement finding."
          },
          {
            "i18n": {
              "key": "gdpr.newsletter.pass"
            },
            "name": "Newsletter Consent",
            "value": "Newsletter form with consent mechanism detected",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7",
                "ePrivacy Art. 13"
              ],
              "skLaw": [
                "§ 14",
                "§ 109 zák. 452/2021"
              ],
              "verified": [
                {
                  "title": "Zákonnosť spracúvania",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 6 — Zákonnosť spracúvania 1. Spracúvanie je zákonné iba vtedy a iba v tom rozsahu, keď je splnená aspoň jedna z týchto podmienok: Písmeno f) prvého pododseku sa nevzťahuje na spracúvanie vykonávané orgánmi verejnej moci pri výkone i",
                  "citation": "čl. 6 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky vyjadrenia súhlasu",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 7 — Podmienky vyjadrenia súhlasu 1. Ak je spracúvanie založené na súhlase, prevádzkovateľ musí vedieť preukázať, že dotknutá osoba vyjadrila súhlas so spracúvaním svojich osobných údajov. 2. Ak dá dotknutá osoba súhlas v rámci písom",
                  "citation": "čl. 7 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky poskytnutia súhlasu so spracúvaním osobných údajov",
                  "excerpt": "§ 14 Podmienky poskytnutia súhlasu so spracúvaním osobných údajov (1) Ak je spracúvanie osobných údajov založené na súhlase dotknutej osoby, prevádzkovateľ je povinný kedykoľvek vedieť preukázať, že dotknutá osoba poskytla súhlas so spracúv",
                  "citation": "§14 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                },
                {
                  "title": "—",
                  "excerpt": "§ 109 — (8) Každý, kto ukladá alebo získava prístup k informáciám uloženým v koncovom zariadení užívateľa, je na to oprávnený iba ak užívateľ udelil preukázateľný súhlas spĺňajúci náležitosti podľa osobitného predpisu. 126 ) Povinnosť získa",
                  "citation": "§109 ods. 8 zákona č. 452/2021 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            }
          },
          {
            "i18n": {
              "key": "gdpr.dpo.pass"
            },
            "name": "Data Protection Officer Contact",
            "value": "DPO / data protection contact found",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "gdpr.withdrawal.warning"
            },
            "name": "Withdrawal of Consent Mechanism",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Provide a clear way to withdraw consent: an 'unsubscribe' link in emails, a 'cookie settings' button in the footer, and a 'revoke consent' section in your privacy policy.",
            "legalRefs": {
              "gdpr": [
                "Art. 7(3)"
              ],
              "skLaw": [
                "§ 14(4)"
              ],
              "verified": [
                {
                  "title": "Podmienky vyjadrenia súhlasu",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 7 — Podmienky vyjadrenia súhlasu 1. Ak je spracúvanie založené na súhlase, prevádzkovateľ musí vedieť preukázať, že dotknutá osoba vyjadrila súhlas so spracúvaním svojich osobných údajov. 2. Ak dá dotknutá osoba súhlas v rámci písom",
                  "citation": "čl. 7 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky poskytnutia súhlasu so spracúvaním osobných údajov",
                  "excerpt": "§ 14 Podmienky poskytnutia súhlasu so spracúvaním osobných údajov (1) Ak je spracúvanie osobných údajov založené na súhlase dotknutej osoby, prevádzkovateľ je povinný kedykoľvek vedieť preukázať, že dotknutá osoba poskytla súhlas so spracúv",
                  "citation": "§14 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            },
            "whyMatters": "GDPR Article 7(3): 'It shall be as easy to withdraw as to give consent.' If users can subscribe in one click, unsubscribing must be equally simple. Missing this is a common regulatory finding."
          },
          {
            "i18n": {
              "key": "gdpr.cookie-lifetime.warning",
              "params": {
                "count": 1
              }
            },
            "name": "Cookie Lifetime Compliance",
            "value": "1 cookie(s) with >1 year expiry",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Reduce cookie lifetimes to maximum 13 months (CNIL recommendation) or 6 months for marketing cookies. Session cookies should expire when the browser closes.",
            "legalRefs": {
              "gdpr": [
                "Art. 5(1)(c)",
                "Art. 5(1)(e)"
              ],
              "skLaw": [
                "§ 8",
                "§ 10"
              ],
              "verified": [
                {
                  "title": "Zásady spracúvania osobných údajov",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 5 — Zásady spracúvania osobných údajov 1. Osobné údaje musia byť: (a) spracúvané zákonným spôsobom, spravodlivo a transparentne vo vzťahu k dotknutej osobe („zákonnosť, spravodlivosť a transparentnosť“); (b) získavané na konkrétne u",
                  "citation": "čl. 5 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Zásada minimalizácie osobných údajov",
                  "excerpt": "§ 8 Zásada minimalizácie osobných údajov Spracúvané osobné údaje musia byť primerané, relevantné a obmedzené na nevyhnutný rozsah daný účelom, na ktorý sa spracúvajú.",
                  "citation": "§8 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                },
                {
                  "title": "Zásada minimalizácie uchovávania",
                  "excerpt": "§ 10 Zásada minimalizácie uchovávania Osobné údaje musia byť uchovávané vo forme, ktorá umožňuje identifikáciu dotknutej osoby najneskôr dovtedy, kým je to potrebné na účel, na ktorý sa osobné údaje spracúvajú; osobné údaje sa môžu uchováva",
                  "citation": "§10 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            },
            "whyMatters": "French CNIL and other EU DPAs recommend a maximum 13-month cookie lifetime. Excessive cookie durations violate data minimization (GDPR Art. 5c)."
          },
          {
            "i18n": {
              "key": "gdpr.omnibus.warning"
            },
            "name": "Omnibus Price Disclosure (30-day low)",
            "value": "Discounts shown without a visible 'lowest price in last 30 days' reference",
            "status": "warning",
            "fixLink": {
              "url": "https://zulien.sk",
              "label": "Omnibus price-history module →"
            },
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Whenever you advertise a price reduction, display the lowest price applied in the 30 days before the discount, next to the new price. In PrestaShop add a 30-day price-history anchor (e.g. our zu_pricehistory module) so every sale label is compliant automatically.",
            "legalRefs": {
              "gdpr": [
                "Smernica (EÚ) 2019/2161 (Omnibus)",
                "Smernica 98/6/ES čl. 6a"
              ],
              "czLaw": [
                "zák. 634/1992 Sb. § 12a"
              ],
              "skLaw": [
                "zák. 108/2024 Z.z."
              ]
            },
            "confidence": "low",
            "whyMatters": "The EU Omnibus Directive (2019/2161), enacted in SK as zák. 108/2024 and CZ via zák. 634/1992, makes the 30-day reference price MANDATORY on every advertised discount. ŠOI/ČOI actively inspect for missing disclosures — and a '−40%' off an inflated base is exactly what they target."
          },
          {
            "i18n": {
              "key": "gdpr.dispute-resolution.warning-no-odr"
            },
            "name": "Consumer Dispute Resolution Links",
            "value": "Authority link present but no EU ODR platform link",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add BOTH the EU ODR platform link (https://ec.europa.eu/consumers/odr) and your national supervisory authority (SK: ŠOI / soi.sk, CZ: ČOI / coi.cz) to the footer and Terms.",
            "legalRefs": {
              "gdpr": [
                "Nariadenie (EÚ) 524/2013 (ODR)",
                "Smernica 2013/11/EÚ (ADR)"
              ],
              "czLaw": [
                "zák. 634/1992 Sb. § 14"
              ],
              "skLaw": [
                "zák. 391/2015 Z.z."
              ]
            },
            "whyMatters": "EU Regulation 524/2013 and the Consumer ADR Directive require online traders to link the ODR platform and name the competent supervisory authority. Missing links are a documented inspection finding (ŠOI/ČOI) and void parts of your Terms."
          },
          {
            "i18n": {
              "key": "gdpr.withdrawal-complaints.warning",
              "params": {
                "missing": "complaints procedure (reklamačný poriadok)"
              }
            },
            "name": "Withdrawal & Complaints Policy",
            "value": "Missing: complaints procedure (reklamačný poriadok)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Publish and footer-link a Withdrawal policy (14-day right of withdrawal + model withdrawal form) and a Complaints procedure (reklamačný poriadok / reklamační řád). Reference them at checkout.",
            "legalRefs": {
              "gdpr": [
                "Smernica 2011/83/EÚ čl. 6(1)(h),(9)"
              ],
              "czLaw": [
                "zák. 89/2012 Sb. § 1829"
              ],
              "skLaw": [
                "zák. 108/2024 Z.z."
              ]
            },
            "whyMatters": "The Consumer Rights Directive (2011/83/EU) and SK zák. 108/2024 / CZ zák. 89/2012 require pre-contractual disclosure of the 14-day withdrawal right and an accessible complaints procedure. Missing them extends customers' cancellation rights and is a standard ŠOI/ČOI finding."
          },
          {
            "i18n": {
              "key": "gdpr.withdrawal-function.info"
            },
            "name": "Online Withdrawal Function",
            "value": "No explicit online withdrawal button in the server HTML — it may live in the logged-in account/order area, which this scan can't reach. Verify it's present.",
            "status": "info",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add a clearly labelled withdrawal function to your online interface (SK label: 'odstúpiť od zmluvy tu'), easy to find and continuously available during the 14-day withdrawal window — e.g. in the customer account / order detail plus a footer link. A logged-in customer must be able to submit a withdrawal declaration without re-identifying.",
            "confidence": "low",
            "whyMatters": "Directive (EU) 2023/2673 (amending 2011/83/EU), transposed in SK as § 20a zák. 108/2024, requires online traders to provide an easy-to-use withdrawal function — a clearly labelled button, continuously available during the withdrawal period — effective 19 June 2026 for all distance contracts with a right of withdrawal. Orientation only — verify placement manually."
          }
        ]
      },
      "nis2": {
        "score": -1,
        "checks": [
          {
            "i18n": {
              "key": "nis2.scope.none"
            },
            "name": "NIS2 Compliance",
            "value": "Not in scope — your business is below NIS2 thresholds (Annex I/II sector + 50+ employees / €10M+ turnover).",
            "status": "info",
            "howToFix": "",
            "whyMatters": ""
          }
        ]
      },
      "mobile": {
        "score": 67,
        "checks": [
          {
            "i18n": {
              "key": "mob.viewport.pass"
            },
            "name": "Viewport Configuration",
            "value": "width=device-width, initial-scale=1",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "mob.perf.warning",
              "params": {
                "score": 57
              }
            },
            "name": "Mobile Performance Score",
            "value": "57/100 (target: 90+)",
            "status": "warning",
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "Optimize for mobile: compress images to WebP, defer non-critical JS, reduce CSS file size. Mobile CPUs are several times slower than desktop — what's fast on desktop is slow on mobile.",
            "whyMatters": "Most e-commerce traffic is mobile. Google ranks based on mobile performance, not desktop."
          },
          {
            "i18n": {
              "key": "mob.taptarget.warning",
              "params": {
                "detail": "Some tappable targets are too small or too close together (Lighthouse tap-targets audit)"
              }
            },
            "name": "Touch Target Size",
            "value": "Some tappable targets are too small or too close together (Lighthouse tap-targets audit)",
            "status": "warning",
            "evidence": {
              "source": "PSI-lab",
              "measured": "Some tappable targets are too small or too close together (Lighthouse tap-targets audit)"
            },
            "howToFix": "Ensure ALL interactive elements (buttons, links, form fields) are at least 48×48px with 8px minimum spacing between them. Pay special attention to: navigation menus, filter buttons, product variant selectors, and footer links.",
            "whyMatters": "Small tap targets cause mis-taps on mobile. In e-commerce, a mis-tap on 'Remove from cart' instead of 'Checkout' directly loses revenue."
          },
          {
            "i18n": {
              "key": "mob.fontsize.warning",
              "params": {
                "detail": "Some text renders below the 12px legibility threshold (Lighthouse font-size audit)"
              }
            },
            "name": "Font Size Readability",
            "value": "Some text renders below the 12px legibility threshold (Lighthouse font-size audit)",
            "status": "warning",
            "evidence": {
              "source": "PSI-lab",
              "measured": "Some text renders below the 12px legibility threshold (Lighthouse font-size audit)"
            },
            "howToFix": "Google's font-size audit flags text under 12px. Find the small text (often footer fine-print, captions, or cookie notices) and raise it; aim for a 16px+ body base with relative units (rem/em) so all text scales legibly on mobile.",
            "whyMatters": "Text below the legibility threshold forces mobile users to pinch-zoom. This measures the actual rendered page (Lighthouse), so it catches sub-12px nodes even when the base font looks fine."
          },
          {
            "i18n": {
              "key": "mob.contentwidth.pass"
            },
            "name": "Content Fits Viewport",
            "value": "No horizontal scrolling needed",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "mob.responsive.pass",
              "params": {
                "techniques": "Media queries"
              }
            },
            "name": "Responsive Design Techniques",
            "value": "Media queries detected",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "mob.pwa.warning"
            },
            "name": "PWA Features",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Consider adding Progressive Web App features: 1) Create manifest.json with app name, icons, and theme color, 2) Register a service worker for offline caching. This makes your store installable on mobile.",
            "whyMatters": "PWAs combine the best of web and native apps. For e-commerce, PWAs enable push notifications, offline browsing, and home screen access."
          },
          {
            "i18n": {
              "key": "mob.themecolor.pass"
            },
            "name": "Theme Color",
            "value": "theme-color meta tag present",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "mob.nav.pass"
            },
            "name": "Mobile Navigation (Semantic)",
            "value": "<nav> element present — proper navigation landmark",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "mob.srcset.pass",
              "params": {
                "count": 56
              }
            },
            "name": "Responsive Images (srcset)",
            "value": "56 image(s) use srcset for responsive sizing",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "mob.inputtypes.warning",
              "params": {
                "issues": "phone fields use type='text' instead of type='tel'"
              }
            },
            "name": "Form Input Types",
            "value": "phone fields use type='text' instead of type='tel'",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Use semantic input types: type='email' for email (shows @ keyboard), type='tel' for phone (shows number pad), type='search' for search (shows search button). These trigger optimized mobile keyboards.",
            "whyMatters": "Correct input types show specialized mobile keyboards — email keyboard with @, phone with number pad. This reduces input errors and speeds up form completion."
          },
          {
            "i18n": {
              "key": "mob.textoverflow.warning"
            },
            "name": "Text Overflow Handling",
            "value": "No word-break/overflow-wrap CSS detected",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add 'overflow-wrap: break-word' to your body or main content container. Without it, long URLs, product SKUs, or German compound words can break mobile layouts.",
            "whyMatters": "Long strings without word-break cause horizontal overflow on mobile — a common cause of 'content wider than viewport' failures. Compound words and URLs are frequent culprits."
          },
          {
            "i18n": {
              "key": "mob.print.warning"
            },
            "name": "Print Stylesheet",
            "value": "Order/invoice page without print styles",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add @media print CSS rules to hide navigation, ads, and non-essential elements. Ensure order details, prices, and company info are visible when printed.",
            "whyMatters": "Customers print order confirmations and invoices. Without print styles, they get navigation bars, cookie banners, and broken layouts. This is a common usability complaint for e-commerce."
          },
          {
            "i18n": {
              "key": "mob.payments.pass",
              "params": {
                "list": "Stripe",
                "count": 1
              }
            },
            "name": "Payment Methods Detected",
            "value": "1 method(s): Stripe",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "mob.express.info"
            },
            "name": "Express Checkout (Apple Pay + Google Pay)",
            "value": "Apple Pay / Google Pay nedetekované na homepage — express checkout sa zvyčajne zobrazí až v košíku/checkoute",
            "status": "info",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Ak express checkout nemáš, pridaj Apple Pay + Google Pay cez Stripe/Adyen/Mollie. Biometric auth = -1 click checkout = vyšší conversion.",
            "whyMatters": "Mobile conversion pri express checkout je vyšší oproti klasickej karte. V SK/CZ rastúci trend. (Sken vidí iba homepage, takže toto je hint, nie verdikt.)"
          },
          {
            "i18n": {
              "key": "mob.skczpay.info"
            },
            "name": "SK/CZ Local Payment Methods",
            "value": "Žiadna SK/CZ local payment metóda nedetekovaná na homepage — bankové tlačidlá/QR sa zvyčajne zobrazia až v checkoute",
            "status": "info",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Integrovať SK payments — Inger"
            },
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Ak SK/CZ local platby nemáš, integruj GoPay alebo ComGate — obe podporujú Tatra Pay, VÚB Pay, ČSOB Pay, Raiffeisen, QR platba v jednom API. Alternatívne Barion pre CZ trh.",
            "whyMatters": "SK/CZ shop bez bankových tlačidiel a QR platby = masívny cart abandonment. Priemerný SK e-shop má viacero payment metód. (Sken vidí iba homepage — over manuálne v checkoute.)"
          },
          {
            "i18n": {
              "key": "mob.wcaglabels.pass",
              "params": {
                "total": 31
              }
            },
            "name": "Form Input Labels (WCAG 3.3.2)",
            "value": "31/31 inputs majú label",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "mob.wcagheading.warning",
              "params": {
                "skips": "h1→h3"
              }
            },
            "name": "Heading Hierarchy (WCAG 1.3.1)",
            "value": "Preskočené úrovne: h1→h3",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Dodržuj poradie nadpisov h1 → h2 → h3 → h4 bez preskočenia. Screen readers používajú hierarchiu nadpisov na navigáciu. Ak potrebuješ menšie písmo ale rovnakú úroveň, použi CSS triedu, nie nižší heading tag.",
            "whyMatters": "Preskočené heading levely (napr. h1 priamo na h3) zlomia navigáciu pre screen reader používateľov a signalizujú Googlu zlú štruktúru dokumentu. Aj SEO je negatívne ovplyvnené."
          },
          {
            "i18n": {
              "key": "mob.wcaglinks.pass"
            },
            "name": "Link Text Quality (WCAG 2.4.4)",
            "value": "Všetky odkazy majú popisný text",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          }
        ]
      },
      "company": {
        "nis2": {
          "annex": null,
          "sector": null,
          "category": "none",
          "in_scope": false,
          "priority_tier": null,
          "priority_score": null
        },
        "financials": {
          "year": 2025,
          "equity": 17680,
          "profit": 3609,
          "turnover": 1015066
        },
        "percentile": {
          "metrics": {
            "equity": 20,
            "turnover": 27,
            "net_profit": 25,
            "credit_limit": 26,
            "credit_score": 22,
            "total_assets": 32,
            "debt_to_equity": 1,
            "employee_count": 97
          },
          "nace_section": "G",
          "peer_group_size": 116383
        },
        "in_insolvency": false,
        "credit_grade_full": "C"
      },
      "modules": [
        "revsliderprestashop",
        "ph_simpleblog"
      ],
      "security": {
        "score": 82,
        "checks": [
          {
            "i18n": {
              "key": "sec.ssl.pass"
            },
            "name": "SSL/TLS Certificate",
            "value": "Valid HTTPS connection established",
            "status": "pass",
            "evidence": {
              "source": "SSL"
            }
          },
          {
            "i18n": {
              "key": "sec.dnssec.warning"
            },
            "name": "DNSSEC",
            "value": "No DNSKEY records — zone is unsigned",
            "status": "warning",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "DNSSEC setup help →"
            },
            "evidence": {
              "source": "DNS"
            },
            "howToFix": "Enable DNSSEC at your DNS host (most modern registrars offer 1-click activation: Cloudflare, Route 53, Google Cloud DNS, web.sk, websupport.sk). Verify via dnsviz.net afterwards.",
            "whyMatters": "Without DNSSEC, attackers controlling intermediate resolvers can forge responses for your domain — sending users to phishing sites with valid HTTPS that match your name. EU national CSIRTs (SK-CERT, NÚKIB) recommend DNSSEC for all in-scope entities."
          },
          {
            "i18n": {
              "key": "sec.caa.warning"
            },
            "name": "CAA DNS Record",
            "value": "No CAA records — any CA can issue certificates for this domain",
            "status": "warning",
            "evidence": {
              "source": "DNS"
            },
            "howToFix": "Publish CAA TXT records pinning your CA. For Let's Encrypt: `0 issue \"letsencrypt.org\"`. For multiple CAs add additional `0 issue \"...\"` records. Add `0 iodef \"mailto:security@yourdomain.tld\"` for misissuance reports.",
            "whyMatters": "CAA records limit which Certificate Authorities can issue certificates for your domain. Without CAA, a compromised or rogue CA can issue valid certs that browsers will trust — a documented breach pattern (DigiNotar 2011, Symantec 2017)."
          },
          {
            "i18n": {
              "key": "sec.https-redirect.pass"
            },
            "name": "HTTP → HTTPS Redirect",
            "value": "HTTP properly redirects to HTTPS",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "i18n": {
              "key": "sec.hsts.pass",
              "params": {
                "detail": "max-age=31536000, includeSubDomains"
              }
            },
            "name": "HSTS (Strict-Transport-Security)",
            "value": "max-age=31536000, includeSubDomains",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "i18n": {
              "key": "sec.csp.warning",
              "params": {
                "detail": "'unsafe-inline' and 'unsafe-eval'"
              }
            },
            "name": "Content-Security-Policy (CSP)",
            "value": "Present but uses 'unsafe-inline' and 'unsafe-eval'",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Remove 'unsafe-inline' by using nonces or hashes for inline scripts. Remove 'unsafe-eval' by eliminating eval() calls. These exceptions weaken CSP significantly.",
            "whyMatters": "'unsafe-inline' allows injected scripts to execute — defeating the main purpose of CSP. Major XSS protection is bypassed."
          },
          {
            "i18n": {
              "key": "sec.clickjacking.pass",
              "params": {
                "detail": "SAMEORIGIN"
              }
            },
            "name": "Clickjacking Protection",
            "value": "X-Frame-Options: SAMEORIGIN",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "i18n": {
              "key": "sec.x-content-type.pass"
            },
            "name": "X-Content-Type-Options",
            "value": "nosniff",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "i18n": {
              "key": "sec.referrer-policy.pass",
              "params": {
                "detail": "strict-origin-when-cross-origin"
              }
            },
            "name": "Referrer-Policy",
            "value": "strict-origin-when-cross-origin",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "i18n": {
              "key": "sec.permissions-policy.pass",
              "params": {
                "detail": "geolocation=(), microphone=(), camera=()"
              }
            },
            "name": "Permissions-Policy",
            "value": "geolocation=(), microphone=(), camera=()",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "i18n": {
              "key": "sec.cookie-flags.pass",
              "params": {
                "count": 2
              }
            },
            "name": "Cookie Security Flags",
            "value": "2 cookie(s) — all have Secure, HttpOnly, SameSite",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "i18n": {
              "key": "sec.tech-disclosure.pass-hidden"
            },
            "name": "Technology Disclosure",
            "value": "Server identity hidden",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "i18n": {
              "key": "sec.sri.warning",
              "params": {
                "eligible": 2,
                "exemptNote": " (1 auto-updating provider script(s) excluded — SRI not applicable)",
                "withIntegrity": 0
              }
            },
            "name": "Subresource Integrity (SRI)",
            "value": "Only 0/2 SRI-eligible third-party scripts have integrity hashes (1 auto-updating provider script(s) excluded — SRI not applicable)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add integrity='sha384-...' and crossorigin='anonymous' to version-pinned third-party <script> tags (use srihash.org). Auto-updating provider scripts (analytics, payment SDKs, consent tools) are correctly excluded — they can't use SRI.",
            "whyMatters": "Without SRI, if a version-pinned third-party CDN is compromised, attackers can inject malicious code into your site — the same vector as the British Airways Magecart breach."
          },
          {
            "i18n": {
              "key": "sec.security-txt.pass"
            },
            "name": "security.txt (RFC 9116)",
            "value": "Present at /.well-known/security.txt",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "i18n": {
              "key": "sec.cdn.warning"
            },
            "name": "CDN / WAF Protection",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Add a CDN/WAF like Cloudflare (free tier), Sucuri, or Fastly. They provide DDoS protection, bot filtering, and SSL management.",
            "whyMatters": "Without a CDN/WAF, your origin server is directly exposed to DDoS attacks, bot traffic, and brute-force attempts."
          },
          {
            "i18n": {
              "key": "sec.iframe-sandbox.info",
              "params": {
                "count": 1
              }
            },
            "name": "Iframe Sandboxing",
            "value": "1 trusted provider embed(s) without sandbox — expected (sandbox would break YouTube/Maps/Stripe/reCAPTCHA)",
            "status": "info",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "confidence": "low"
          },
          {
            "i18n": {
              "key": "sec.cookie-prefix.info",
              "params": {
                "count": 2
              }
            },
            "name": "Cookie Prefix Security",
            "value": "2 session cookie(s) already have Secure + HttpOnly + SameSite; adding the __Host- prefix is a cosmetic hardening nicety",
            "status": "info",
            "evidence": {
              "source": "HTTP-header",
              "measured": "2 session cookie(s), all with Secure+HttpOnly+SameSite"
            },
            "howToFix": "Optional: rename to __Host-session (Secure; Path=/; no Domain) for defence-in-depth against subdomain cookie injection.",
            "confidence": "low",
            "whyMatters": "With Secure, HttpOnly and SameSite already set, the prefix adds only host-only enforcement — low marginal benefit."
          }
        ]
      },
      "tech_stack": [
        {
          "eol": false,
          "name": "PrestaShop",
          "category": "cms",
          "outdated": false
        },
        {
          "name": "jQuery",
          "category": "js-library"
        },
        {
          "name": "Font Awesome",
          "category": "js-library"
        },
        {
          "name": "Toastr",
          "category": "js-library"
        },
        {
          "name": "Turnstile",
          "category": "js-library"
        }
      ],
      "performance": {
        "score": 69,
        "checks": [
          {
            "i18n": {
              "key": "perf.ttfb.pass",
              "params": {
                "ms": 25
              }
            },
            "name": "Server Response Time (TTFB)",
            "value": "25ms",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "i18n": {
              "key": "perf.fcp.pass",
              "params": {
                "s": "1.12"
              }
            },
            "name": "First Contentful Paint (FCP)",
            "value": "1.12s",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "i18n": {
              "key": "perf.lcp.fail",
              "params": {
                "s": "4.86"
              }
            },
            "name": "Largest Contentful Paint (LCP)",
            "value": "4.86s (good: <2.5s) — Core Web Vital FAILING",
            "status": "fail",
            "fixLink": {
              "url": "https://zulien.sk",
              "label": "Fix with Performance module →"
            },
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "Urgent: your largest content element loads too slowly. 1) Preload hero image, 2) Convert to WebP/AVIF, 3) Serve from CDN, 4) Remove render-blocking JS before it, 5) Consider lazy loading all other images.",
            "whyMatters": "LCP >4s fails Core Web Vitals — Google actively demotes these pages. Faster LCP correlates with higher conversion rates."
          },
          {
            "i18n": {
              "key": "perf.tbt.pass",
              "params": {
                "ms": 122
              }
            },
            "name": "Total Blocking Time (TBT)",
            "value": "122ms",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "i18n": {
              "key": "perf.cls.pass",
              "params": {
                "cls": "0.057"
              }
            },
            "name": "Cumulative Layout Shift (CLS)",
            "value": "0.057 — Core Web Vital ✓",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "i18n": {
              "key": "perf.speed-index.pass",
              "params": {
                "s": "1.99"
              }
            },
            "name": "Speed Index",
            "value": "1.99s",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "i18n": {
              "key": "perf.page-weight.fail",
              "params": {
                "mb": "7.0",
                "requests": 183
              }
            },
            "name": "Total Page Weight",
            "value": "7.0 MB, 183 requests — too heavy!",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Performance Optimization →"
            },
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "Critical: your page is over 3 MB. 1) Convert all images to WebP/AVIF, 2) Lazy load everything below the fold, 3) Remove unused plugins, 4) Combine and minify CSS/JS, 5) Enable brotli compression.",
            "whyMatters": "Pages over 3 MB take 12+ seconds on 3G. The average e-commerce page is around 2 MB — you're well above that. Even small latency increases measurably reduce sales."
          },
          {
            "i18n": {
              "key": "perf.render-blocking.info"
            },
            "name": "Render-blocking Resources",
            "value": "Not measured — PageSpeed did not return the render-blocking audit for this URL",
            "status": "info",
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "Re-run the scan, or test directly at PageSpeed Insights. This metric needs a successful Lighthouse lab run."
          },
          {
            "i18n": {
              "key": "perf.unused-code.fail",
              "params": {
                "kb": 653
              }
            },
            "name": "Unused Code (CSS + JS)",
            "value": "653 KB wasted on unused code!",
            "status": "fail",
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "You're loading 653 KB of code that isn't used on this page. 1) Audit plugins and remove unused ones, 2) Use code-splitting for page-specific JS, 3) Run PurgeCSS on your stylesheets.",
            "whyMatters": "Over 200 KB of unused code significantly slows parsing and execution. This is one of the easiest performance wins — removing dead code requires no trade-offs."
          },
          {
            "i18n": {
              "key": "perf.text-compression.pass"
            },
            "name": "Text Compression (gzip/brotli)",
            "value": "All text resources properly compressed",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "i18n": {
              "key": "perf.resource-hints.pass",
              "params": {
                "preload": 0,
                "preconnect": 3
              }
            },
            "name": "Resource Hints (Preload/Preconnect)",
            "value": "0 preload, 3 preconnect hint(s)",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "perf.lazy-load.pass",
              "params": {
                "lazy": 187,
                "rate": 86,
                "total": 218
              }
            },
            "name": "Lazy Loading",
            "value": "86% of images use native lazy loading (187/218)",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "perf.font-display.google-fonts"
            },
            "name": "Font Loading Strategy",
            "value": "Google Fonts detected without font-display",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add &display=swap to your Google Fonts URL, or add font-display: swap to your @font-face declarations.",
            "whyMatters": "Without font-display, custom fonts cause Flash of Invisible Text (FOIT) — text is completely hidden during font download. On slow connections this can last 3+ seconds."
          },
          {
            "i18n": {
              "key": "perf.cache-control.warning",
              "params": {
                "header": "no-store, no-cache, must-revalidate"
              }
            },
            "name": "Cache-Control Strategy",
            "value": "no-store, no-cache, must-revalidate",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Set appropriate cache headers: static assets should have max-age=31536000 with versioned filenames. HTML pages can use max-age=0 with ETag for revalidation.",
            "whyMatters": "no-cache/no-store forces browsers to re-download resources on every visit. Repeat visitors load your entire site from scratch every time."
          },
          {
            "i18n": {
              "key": "perf.http3.pass"
            },
            "name": "HTTP/3 (QUIC) Support",
            "value": "HTTP/3 enabled via Alt-Svc header",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "i18n": {
              "key": "perf.script-strategy.fail",
              "params": {
                "rate": 25,
                "total": 4,
                "blocking": 3
              }
            },
            "name": "Script Loading Strategy",
            "value": "Only 25% of 4 scripts optimized — most are render-blocking",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Performance Optimization →"
            },
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add defer or async to all <script src='...'> tags. Render-blocking scripts are a leading cause of slow FCP. Defer maintains execution order, async does not.",
            "whyMatters": "3 render-blocking scripts can add 1-3 seconds to page load. Each synchronous script creates a sequential download-parse-execute chain."
          },
          {
            "i18n": {
              "key": "perf.css-count.pass",
              "params": {
                "count": 2
              }
            },
            "name": "CSS File Count",
            "value": "2 CSS file(s) — well consolidated",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "perf.font-preload.warning"
            },
            "name": "Font Preloading",
            "value": "Custom fonts detected without preload hints",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Preload your primary font: <link rel='preload' href='/fonts/main.woff2' as='font' type='font/woff2' crossorigin>. For Google Fonts: preconnect to fonts.gstatic.com.",
            "whyMatters": "Fonts are discovered late in the render pipeline (after CSS is parsed). Preloading tells the browser to download them immediately, reducing Flash of Invisible Text (FOIT) by 200-500ms."
          }
        ]
      },
      "ai_readiness": {
        "score": 84,
        "checks": [
          {
            "i18n": {
              "key": "air.bot-access.pass",
              "params": {
                "detail": "Explicitly allowed: GPTBot, ChatGPT-User, anthropic-ai, ClaudeBot, PerplexityBot"
              }
            },
            "name": "AI Bot Access Policy",
            "value": "Explicitly allowed: GPTBot, ChatGPT-User, anthropic-ai, ClaudeBot, PerplexityBot",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "i18n": {
              "key": "air.llms-txt.pass",
              "params": {
                "chars": 4000,
                "extras": "H1, summary"
              }
            },
            "name": "llms.txt (AI Site Descriptor)",
            "value": "Present (4000 chars, H1, summary) — informational; no engine consumes it for citation",
            "status": "info",
            "evidence": {
              "source": "file-probe"
            },
            "whyMatters": "No answer engine consumes llms.txt for AI-search citation today (2026) — adoption is ~8.7% and Google declined to support it. It's optional future-proofing, mainly read by coding/IDE agents. Prioritize AI-crawler access, server-rendered content, statistics and cited sources instead. See /ai-readiness-methodology.md."
          },
          {
            "i18n": {
              "key": "air.llms-full.pass",
              "params": {
                "sizeKB": 4
              }
            },
            "name": "llms-full.txt (Complete AI Content)",
            "value": "Present (4 KB) — informational; no engine consumes it for citation",
            "status": "info",
            "evidence": {
              "source": "file-probe"
            },
            "whyMatters": "No answer engine consumes llms.txt for AI-search citation today (2026) — adoption is ~8.7% and Google declined to support it. It's optional future-proofing, mainly read by coding/IDE agents. Prioritize AI-crawler access, server-rendered content, statistics and cited sources instead. See /ai-readiness-methodology.md."
          },
          {
            "i18n": {
              "key": "air.content-access.pass",
              "params": {
                "ratio": "3.2",
                "words": 2722
              }
            },
            "name": "Content Accessibility for AI",
            "value": "2722 words in raw HTML (3.2% text ratio) — readable by AI crawlers without executing JS",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.schema-foundation.warning-multi",
              "params": {
                "note": " (near-duplicate entity types merged from 4)",
                "count": 3,
                "types": "BusinessEntity, WebPage, WebSite"
              }
            },
            "name": "Structured Data Foundation",
            "value": "3 distinct schema types (near-duplicate entity types merged from 4) (BusinessEntity, WebPage, WebSite) — add more for comprehensive AI coverage",
            "status": "warning",
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Expand your structured data with genuinely different types: Organization, Product, BreadcrumbList, WebSite with SearchAction, and FAQPage. Adding synonyms of the same entity (Store + LocalBusiness + Organization) does not help — variety of meaning does.",
            "whyMatters": "AI assistants (ChatGPT, Perplexity, Google AI Overviews) synthesize answers from structured data. Comprehensive schema markup makes your store easier to cite."
          },
          {
            "i18n": {
              "key": "air.product-schema.info",
              "params": {
                "pageType": "homepage"
              }
            },
            "name": "Product Schema Completeness",
            "value": "No Product schema on this homepage — Product schema lives on product detail pages, which this single-URL scan didn't visit",
            "status": "info",
            "evidence": {
              "source": "schema"
            },
            "howToFix": "To audit Product schema, run the scan on a product detail URL. On product pages add: name, description, image, offers (price, priceCurrency, availability), brand, sku, aggregateRating.",
            "whyMatters": "Product schema only belongs on product pages, so its absence on this page is expected — not a defect. Scan a product URL to evaluate it."
          },
          {
            "i18n": {
              "key": "air.org-schema.pass",
              "params": {
                "count": 4
              }
            },
            "name": "Organization Schema + Entity Linking",
            "value": "Organization found with 4 sameAs links — strong entity identity",
            "status": "pass",
            "evidence": {
              "source": "schema"
            }
          },
          {
            "i18n": {
              "key": "air.faq-schema.warning"
            },
            "name": "FAQ Schema (Direct AI Answers)",
            "status": "warning",
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Add FAQPage schema to every product page and category page. Include 3-5 Q&As per page covering: product specifications, shipping, returns, usage instructions. Format: question (full sentence) + answer (75-150 words).",
            "whyMatters": "ChatGPT, Perplexity, and Google AI Overviews pull FAQ answers verbatim. FAQ schema is one of the fastest ways to get your content cited by AI."
          },
          {
            "i18n": {
              "key": "air.breadcrumb.warning"
            },
            "name": "Breadcrumb Schema",
            "status": "warning",
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Add BreadcrumbList schema reflecting your category hierarchy: Home → Category → Subcategory → Product. Each item needs name and URL.",
            "whyMatters": "AI assistants use breadcrumbs to understand product categorization and site structure. Without it, AI can't contextualize where products fit in your catalog — e.g., 'Running Shoes' under 'Sports > Footwear > Running'."
          },
          {
            "i18n": {
              "key": "air.sitesearch.pass"
            },
            "name": "Site Search Schema (SearchAction)",
            "value": "WebSite SearchAction configured — AI can search your store",
            "status": "pass",
            "evidence": {
              "source": "schema"
            }
          },
          {
            "i18n": {
              "key": "air.content-depth.pass",
              "params": {
                "words": 2722
              }
            },
            "name": "Content Depth for AI",
            "value": "2722 words — rich content for AI analysis and citation",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.answer-first.pass",
              "params": {
                "words": 159
              }
            },
            "name": "Answer-First Content Format",
            "value": "First paragraph: 159 words — good content density above the fold",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.headings.pass",
              "params": {
                "h2": 7,
                "h3": 6
              }
            },
            "name": "Heading Hierarchy for AI",
            "value": "Proper structure: 1 H1 → 7 H2s → 6 H3s — clear content outline",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.semantic-html.pass",
              "params": {
                "count": 5,
                "elements": "<article>, <nav>, <main>, <header>, <footer>"
              }
            },
            "name": "Semantic HTML Structure",
            "value": "5/6 semantic elements: <article>, <nav>, <main>, <header>, <footer>",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.structured-content.warning-partial",
              "params": {
                "what": "96 lists",
                "missing": "comparison tables"
              }
            },
            "name": "Structured Content (Lists & Tables)",
            "value": "96 lists found — consider adding comparison tables",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add comparison tables to your content. Use <ul>/<ol> for feature lists, specifications, and benefits. Use <table> for product comparisons, pricing tiers, and specifications. AI extracts structured content much faster than paragraphs.",
            "whyMatters": "AI models are biased toward extracting data from HTML lists and tables. Perplexity and ChatGPT pull bullet points and table data with higher accuracy than paragraph text."
          },
          {
            "i18n": {
              "key": "air.freshness.pass",
              "params": {
                "modified": ""
              }
            },
            "name": "Content Freshness Signals",
            "value": "Schema dates found + visible date on page",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.entity-clarity.pass",
              "params": {
                "count": 4,
                "platforms": ": Facebook, Instagram, YouTube"
              }
            },
            "name": "Entity Clarity & Brand Signals",
            "value": "OG tags complete + 4 sameAs links: Facebook, Instagram, YouTube",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.eeat.warning-noarticle"
            },
            "name": "Author Expertise Signals (E-E-A-T)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "For content pages (blog, guides, about): add Article/BlogPosting schema with author property linking to Person schema. Include the author's jobTitle, credentials, and social profiles.",
            "whyMatters": "AI models weight author expertise heavily. Pages from identified experts get cited more than anonymous content. This is especially important for product guides, reviews, and advice content."
          },
          {
            "i18n": {
              "key": "air.review-schema.pass"
            },
            "name": "Reviews & Ratings Schema",
            "value": "AggregateRating/Review data found — social proof for AI",
            "status": "pass",
            "evidence": {
              "source": "schema"
            }
          },
          {
            "i18n": {
              "key": "air.ai-plugin.warning"
            },
            "name": "AI Plugin Manifest",
            "value": "Not present — not required (the ChatGPT-plugins manifest was retired in 2024)",
            "status": "info",
            "evidence": {
              "source": "file-probe"
            },
            "whyMatters": "ai-plugin.json belonged to the retired ChatGPT-plugins system. Modern agent integration uses MCP / tool APIs — see the WebMCP / Agent-Commerce Readiness signals instead."
          },
          {
            "i18n": {
              "key": "air.product-feed.warning"
            },
            "name": "Product Feed (AI Commerce)",
            "status": "warning",
            "fixLink": {
              "url": "https://audit.mergado.com/",
              "label": "Free feed audit — Mergado"
            },
            "evidence": {
              "sample": "probed /feed/products.xml, /google-shopping.xml, /export/google-shopping.xml — none returned a product feed",
              "source": "file-probe"
            },
            "howToFix": "Create a Google Merchant Center / product feed (XML or CSV). Expose it at a consistent URL and reference it in your sitemap. AI shopping assistants and comparison engines use product feeds for catalog discovery. Tip: validate your Heureka / Zboží / Glami / Merchant feeds for free with Mergado's audit.",
            "whyMatters": "Product feeds power Google Shopping, Bing Shopping, and increasingly AI commerce. Without a structured product feed, AI agents can't efficiently index your full catalog for product recommendations."
          },
          {
            "i18n": {
              "key": "air.heureka-feed.warning-missing"
            },
            "name": "Heureka XML Feed",
            "status": "warning",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Setup Heureka Feed — Inger"
            },
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Vygeneruj Heureka XML feed na /feed/heureka.xml (alebo /export/heureka.xml). PrestaShop má modul Heureka.cz, WooCommerce má pluginy. Štruktúra: <SHOP><SHOPITEM>...</SHOPITEM></SHOP> s ITEM_ID/PRODUCTNAME/URL/PRICE_VAT/CATEGORYTEXT (povinné) + EAN/PARAM/DELIVERY_DATE (highly recommended pre ranking).",
            "whyMatters": "Heureka.sk a Heureka.cz sú dominantné cenové porovnávače na SK/CZ trhu. Bez XML feedu nie ste viditeľní na hlavnom trhovisku. Žiaden generický audit tool toto nekontroluje."
          },
          {
            "i18n": {
              "key": "air.speakable.warning"
            },
            "name": "Speakable Content (Voice AI)",
            "value": "Not present — optional; SpeakableSpecification has limited assistant adoption",
            "status": "info",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.extractable.warning-short",
              "params": {
                "avg": 16,
                "count": 51
              }
            },
            "name": "Extractable Answer Blocks",
            "value": "51 paragraphs, avg 16 words — too short for citation",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Optimal paragraphs for AI citation are 40-80 words. Break long paragraphs into focused, self-contained answer blocks. Each should make one clear point that AI can extract and quote.",
            "whyMatters": "AI extracts individual paragraphs as answer snippets — dense walls of text get skipped. Focused 40-80 word paragraphs are the most citable."
          },
          {
            "i18n": {
              "key": "air.statistics.pass",
              "params": {
                "count": 6
              }
            },
            "name": "Statistics & Data Presence",
            "value": "6 data points found — strong citation magnet",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.section-length.warning",
              "params": {
                "avg": 116,
                "ratio": 18
              }
            },
            "name": "Section Length Optimization",
            "value": "Avg section: 116 words — only 18% in 80-200 word optimal range",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Restructure content into sections of 120-180 words between H2/H3 headings. Each section should cover one topic completely. Split sections over 300 words, expand sections under 80 words.",
            "whyMatters": "For Google AI Overviews, 100-150 words per section is the sweet spot — long sections get skipped and very short ones lack substance."
          },
          {
            "i18n": {
              "key": "air.qa-headings.pass",
              "params": {
                "count": 3
              }
            },
            "name": "Q&A Format Headings",
            "value": "3 question-format headings — excellent for AI Q&A extraction",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.question-coverage.pass",
              "params": {
                "n": 4,
                "labels": "shipping, returns/refunds, availability, payment"
              }
            },
            "name": "Common Question Coverage",
            "value": "Answers 4/5 key shopper questions: shipping, returns/refunds, availability, payment",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.internal-links.pass",
              "params": {
                "rate": 113
              }
            },
            "name": "Internal Link Density",
            "value": "113 contextual internal links per 1,000 words — strong knowledge graph signal",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.canonical.pass"
            },
            "name": "Canonical Tag for AI Deduplication",
            "value": "Self-referencing canonical — clean signal for AI",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.return-policy.warning"
            },
            "name": "Return Policy Schema",
            "status": "warning",
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Add MerchantReturnPolicy schema with: returnPolicyCategory (e.g., MerchantReturnFiniteReturnWindow), merchantReturnDays, returnMethod, returnFees. Link it from Product/Offer via hasMerchantReturnPolicy.",
            "whyMatters": "AI shopping agents (Google Shopping, ChatGPT, Bing Copilot) filter by return flexibility. Products with return policy schema get priority placement in AI product comparisons."
          },
          {
            "i18n": {
              "key": "air.shipping-schema.warning"
            },
            "name": "Shipping Details Schema",
            "status": "warning",
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Add OfferShippingDetails schema with: shippingRate, shippingDestination, deliveryTime (handlingTime + transitTime). AI agents deprioritize products without shipping info.",
            "whyMatters": "Fulfillment speed factors into AI product recommendations. Complete shipping schema means AI can show 'Free shipping, delivers in 2-3 days' — a strong conversion driver."
          },
          {
            "i18n": {
              "key": "air.kg-readiness.pass",
              "params": {
                "count": 4
              }
            },
            "name": "Knowledge Graph Readiness",
            "value": "4/4 entity signals — strong Knowledge Graph presence",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.readability.warning-high-technical",
              "params": {
                "grade": 20
              }
            },
            "name": "Content Readability for AI",
            "value": "Grade 20 — too complex for broad AI citation (technical threshold: 14)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Simplify sentences (target 15-20 words average), use common words, break complex ideas into shorter paragraphs. AI extracts content for general audiences — if it's too academic, AI skips it.",
            "whyMatters": "Content above grade 12 readability is harder for AI to extract as clear, concise answers. Pages using clear headers and approachable language are cited more often."
          },
          {
            "i18n": {
              "key": "air.alt-text.pass",
              "params": {
                "pct": 88,
                "good": 192,
                "total": 217
              }
            },
            "name": "Image Alt Text Quality for AI",
            "value": "88% quality alt text (192/217 images) — strong visual search signal",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.expert-quotes.warning-none"
            },
            "name": "Expert Quotations & Citations",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add 2-3 expert quotes or data citations per major page. Use <blockquote> for quotes and link to authoritative sources (.gov, .edu, Wikipedia, industry reports).",
            "whyMatters": "Content without citations or expert quotes appears unverified to AI. AI assistants prefer content backed by named sources, data references, and expert opinions."
          },
          {
            "i18n": {
              "key": "air.ai-txt.warning"
            },
            "name": "ai.txt (AI Permissions)",
            "value": "Not present — optional; AI-bot permissions are enforced via robots.txt, not ai.txt",
            "status": "info",
            "evidence": {
              "source": "file-probe"
            },
            "whyMatters": "ai.txt is an emerging fine-grained AI-permissions proposal not yet honored by the major engines. The robots.txt AI-bot rules are the signal that actually gates crawler access."
          },
          {
            "i18n": {
              "key": "air.webmcp.warning"
            },
            "name": "WebMCP Agentic Readiness",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "WebMCP (W3C Community Group standard, Chrome 146+) lets pages declare structured tools for AI agents. Add toolname and tooldescription attributes to <form> elements, or include a <script type='application/webmcp+json'> manifest.",
            "whyMatters": "WebMCP is how AI agents will interact with your store (search products, add to cart, check availability). Google and Microsoft are co-developing this standard."
          },
          {
            "i18n": {
              "key": "air.boilerplate.pass",
              "params": {
                "ratio": 67
              }
            },
            "name": "Content-to-Boilerplate Ratio",
            "value": "67% of text in <main>/<article> — clean content signal",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.aggregate-rating.pass"
            },
            "name": "AggregateRating Schema",
            "value": "Review aggregate rating schema present",
            "status": "pass",
            "evidence": {
              "source": "schema"
            }
          },
          {
            "i18n": {
              "key": "air.reviews-aggregate.pass",
              "params": {
                "detail": "1 source: AggregateRating schema — ★ 4.9 · 123 reviews"
              }
            },
            "name": "Customer Reviews — Aggregate",
            "value": "1 source: AggregateRating schema — ★ 4.9 · 123 reviews",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "whyMatters": "Multi-source reviews with published counts compound trust: AI assistants (ChatGPT/Perplexity) and Google SGE cite shops with verifiable AggregateRating schema first; SK/CZ buyers cross-check Heureka against Trustpilot before purchase."
          },
          {
            "name": "Agent-Commerce Readiness",
            "value": "73/100 — čiastočne pripravené (Prístup 100 · Porozumenie 75 · Objaviteľnosť 67 · Transakcia 50)",
            "status": "info",
            "whyMatters": "Či dokáže autonómny nákupný AI agent (ChatGPT operator, Perplexity, budúce agentické asistenty) na vašom obchode: prísť dnu, prečítať a porozumieť produktom, objaviť celý katalóg a konať (kôš, podmienky). Toto meria málokto — a pre SK/CZ shopy nikto. Skóre spája AI-bot prístup, Product schema, produktové feedy (Merchant/Heureka/Zboží), WebMCP a nákupné podmienky do jedného agent-first pohľadu. Nadväzuje na pripravovaný verejný MCP konektor (\"naskenuj tento obchod\")."
          },
          {
            "name": "Agent: Prístup — dostane sa agent dnu",
            "value": "100/100 (2 signály/-ov)",
            "status": "info"
          },
          {
            "name": "Agent: Porozumenie — rozumie produktom",
            "value": "75/100 (2 signály/-ov)",
            "status": "info"
          },
          {
            "name": "Agent: Objaviteľnosť — nájde celý katalóg",
            "value": "67/100 (3 signály/-ov)",
            "status": "info"
          },
          {
            "name": "Agent: Transakcia — vie konať (kôš/podmienky)",
            "value": "50/100 (3 signály/-ov)",
            "status": "info"
          }
        ]
      },
      "phaseTimings": {
        "tail": 330,
        "total": 1218,
        "phase1": 559,
        "preflight": 143,
        "phase1.dns": 262,
        "phase1.html": 174,
        "phase1.files": 557,
        "phase1.zbozi": 241,
        "phase1.headers": 269,
        "phase1.heureka": 230,
        "phase1.merchant": 202
      },
      "accessibility": {
        "score": 89,
        "checks": [
          {
            "i18n": {
              "key": "a11y.lang.pass",
              "params": {
                "lang": "sk-SK"
              }
            },
            "name": "Page Language",
            "value": "<html lang=\"sk-SK\"> is set",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "a11y.alt.pass",
              "params": {
                "total": 218
              }
            },
            "name": "Image Alt Text",
            "value": "All 218 images have alt attributes",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "a11y.forms.pass",
              "params": {
                "total": 31
              }
            },
            "name": "Form Labels",
            "value": "All 31 form inputs are labelled",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "a11y.headings.structure",
              "params": {
                "h1": 1,
                "skips": "h1→h3"
              }
            },
            "name": "Heading Structure",
            "value": "Heading levels skip: h1→h3",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Use a single <h1> and don't jump heading levels (e.g. <h2> straight to <h4>).",
            "whyMatters": "A clean heading hierarchy is the primary way assistive-tech users skim a page (WCAG 1.3.1 / 2.4.6)."
          },
          {
            "i18n": {
              "key": "a11y.links.pass"
            },
            "name": "Link Text",
            "value": "Links use descriptive text",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "confidence": "low"
          },
          {
            "i18n": {
              "key": "a11y.landmarks.pass"
            },
            "name": "Landmark Regions",
            "value": "Semantic landmarks present (<main>, <nav>/<header>)",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "a11y.zoom.pass"
            },
            "name": "Zoom & Scaling",
            "value": "Pinch-zoom is not disabled",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "a11y.skiplink.missing"
            },
            "name": "Skip Link",
            "value": "No skip-to-content link detected",
            "status": "warning",
            "weight": 1,
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add a visually-hidden \"Skip to content\" link as the first focusable element, targeting <main id=\"main\">.",
            "confidence": "low",
            "whyMatters": "Keyboard and screen-reader users otherwise tab through the whole menu on every page. EN 301 549 § 9.2.4.1 (WCAG 2.4.1)."
          },
          {
            "i18n": {
              "key": "a11y.legal-basis"
            },
            "name": "EAA Legal Basis",
            "value": "In scope for the European Accessibility Act (in force 28.6.2025): SK zákon 351/2022 Z. z., CZ zákon 424/2023 Sb., Dir. (EU) 2019/882 — assessed against EN 301 549. Inger provides EAA remediation audits.",
            "status": "info",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Accessibility audit — Inger →"
            },
            "howToFix": "",
            "isUpsell": true,
            "whyMatters": ""
          }
        ]
      },
      "vulnerability": {
        "score": 79,
        "checks": [
          {
            "i18n": {
              "key": "vuln.cms-version.pass"
            },
            "name": "CMS Version Disclosure",
            "value": "No generator tag — CMS identity hidden",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "vuln.sensitive-files.pass"
            },
            "name": "Sensitive Files Exposed",
            "value": ".env, .git, composer.json — all properly blocked",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "i18n": {
              "key": "vuln.install-script.pass"
            },
            "name": "Install Script Exposed",
            "value": "No /install/ or /setup/ paths accessible",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "i18n": {
              "key": "vuln.directory-listing.pass"
            },
            "name": "Directory Listing",
            "value": "Disabled — file structure hidden",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "i18n": {
              "key": "vuln.admin-url.pass"
            },
            "name": "Admin Panel at Default URL",
            "value": "Not found at common paths (/admin, /wp-admin, /administrator, /backoffice)",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "i18n": {
              "key": "vuln.debug-mode.pass"
            },
            "name": "Debug Mode / Error Exposure",
            "value": "No debug indicators found in page output",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "vuln.csrf.fail",
              "params": {
                "count": 29
              }
            },
            "name": "Form CSRF Protection",
            "value": "29 form(s) without CSRF tokens",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add CSRF token validation to every form. Most CMS frameworks have built-in CSRF protection — make sure it's enabled on all forms, including search and newsletter signup.",
            "confidence": "low",
            "whyMatters": "CSRF is in the OWASP Top 10. Without tokens, attackers can craft pages that automatically submit forms on your site as the victim's browser session."
          },
          {
            "i18n": {
              "key": "vuln.magecart.fail",
              "params": {
                "patterns": "Dynamic script injection"
              }
            },
            "name": "Suspicious Inline Script Patterns",
            "value": "Detected: Dynamic script injection",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Malware Scan →"
            },
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Review all inline scripts for obfuscated code. Magecart attackers inject payment skimmers disguised as analytics or GTM scripts. Compare your current HTML with a known-good version. Consider using CSP with strict nonces.",
            "whyMatters": "These patterns (Base64 decode, eval with encoding, dynamic script injection) are hallmarks of Magecart payment skimmers. Skimmers are commonly disguised as Google Tag Manager on e-commerce sites."
          },
          {
            "i18n": {
              "key": "vuln.source-maps.warning"
            },
            "name": "Source Maps Exposed",
            "value": "JavaScript source maps (.js.map) are publicly accessible",
            "status": "warning",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Remove source maps from production or block access via server config. In Vite/Webpack: set sourcemap: false for production builds.",
            "whyMatters": "Source maps reveal your original source code, variable names, comments, and application logic. Attackers use this to find vulnerabilities, API keys in code, and understand your authentication flow."
          },
          {
            "i18n": {
              "key": "vuln.spf.info-nomx"
            },
            "name": "SPF Record (Email Security)",
            "value": "No SPF record, and no MX — this domain doesn't send/receive email, so deliverability isn't affected",
            "status": "info",
            "evidence": {
              "source": "DNS"
            },
            "howToFix": "Even a non-sending domain should block spoofing: publish an explicit null-sending SPF record — v=spf1 -all — so no server can forge mail as this domain.",
            "confidence": "low",
            "whyMatters": "Attackers spoof unprotected domains (even ones that never send email) in phishing. A hard-fail SPF (v=spf1 -all) plus DMARC p=reject stops your domain being used to impersonate you — this is the M3AAWG/NCSC guidance for non-sending domains."
          },
          {
            "i18n": {
              "key": "vuln.dmarc.info-nomx"
            },
            "name": "DMARC Policy (Email Auth)",
            "value": "No DMARC record, and no MX — this domain doesn't handle email, so deliverability isn't affected",
            "status": "info",
            "evidence": {
              "source": "DNS"
            },
            "howToFix": "Publish an anti-spoofing DMARC record even on a non-sending domain: at _dmarc.yourdomain.com set v=DMARC1; p=reject; — paired with SPF v=spf1 -all it prevents your domain being forged in phishing.",
            "confidence": "low",
            "whyMatters": "Domains with no email are still spoofed by attackers. A DMARC p=reject (with SPF -all) tells receivers to drop any mail claiming to be from this domain — closing the impersonation vector without affecting any real mail (there is none)."
          },
          {
            "i18n": {
              "key": "vuln.email-infra.info"
            },
            "name": "Email Infrastructure",
            "value": "No MX records — domain does not receive email",
            "status": "info",
            "evidence": {
              "source": "DNS"
            }
          },
          {
            "i18n": {
              "key": "vuln.cross-origin.warning"
            },
            "name": "Cross-Origin Isolation",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Add Cross-Origin-Opener-Policy: same-origin and Cross-Origin-Resource-Policy: same-origin headers. These protect against Spectre-type side-channel attacks.",
            "whyMatters": "Without cross-origin isolation headers, your site is vulnerable to Spectre attacks that can leak sensitive data across browser tabs. These headers are required for SharedArrayBuffer and high-resolution timers."
          },
          {
            "i18n": {
              "key": "vuln.inline-handlers.warning",
              "params": {
                "count": 26
              }
            },
            "name": "Inline Event Handlers",
            "value": "26 inline event handlers (onclick, onmouseover, etc.)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Move inline event handlers to external JavaScript files using addEventListener(). Inline handlers prevent proper CSP implementation (require 'unsafe-inline') and increase XSS attack surface.",
            "whyMatters": "Inline event handlers are a legacy pattern that prevents Content Security Policy enforcement. They also make XSS attacks easier — injected HTML attributes can execute JavaScript immediately."
          }
        ]
      },
      "executive_summary": {
        "en": "Your store performs well overall, but security needs attention. Start by creating an XML Sitemap to improve search visibility. Great news: Your site already excels in accessibility and SEO.",
        "sk": "Váš web je v dobrom stave, ale má priestor na zlepšenie v bezpečnosti. Najskôr pridajte XML Sitemap pre lepšiu viditeľnosť v Google. Výborná správa: Váš web je už optimalizovaný pre prístupnosť a SEO."
      },
      "opendata_security": null
    },
    "created_at": "2026-07-29T10:58:47.503147+00:00",
    "status": "complete",
    "platform_detected": "PrestaShop",
    "company_ico": "36310166",
    "company_name": "Auto-Piko, s.r.o.",
    "company_country": "SK",
    "company_nace": "4672",
    "company_size": "small",
    "nis2_scope": "none",
    "nis2_sector": null,
    "company_risk_score": 35,
    "company_risk_level": "medium"
  }
}