{
  "data": {
    "slug": "61fe2d76",
    "url": "https://lunys.sk",
    "domain": "lunys.sk",
    "overall_score": 68,
    "scores_json": {
      "seo": {
        "score": 75,
        "checks": [
          {
            "name": "Meta Title",
            "value": "38 chars — \"Skratka k lepším potravinám | LUNYS.sk\"",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Meta Description",
            "value": "149 chars",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "H1 Heading",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add exactly one H1 tag containing your primary keyword. It should be the most prominent heading on the page.",
            "whyMatters": "The H1 is the primary content signal for search engines. Pages without H1 rank significantly lower for target keywords."
          },
          {
            "name": "Content Structure (H2 Headings)",
            "value": "4 H2 subheadings found",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Open Graph Tags",
            "value": "og:title, og:description, og:image, og:type",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Open Graph Image Format",
            "value": "og:image returned text/html",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Make sure the og:image URL returns an image (Content-Type: image/png or image/jpeg). Common cause: returning HTML or JSON from a broken redirect.",
            "whyMatters": "Social scrapers expect an image at og:image URL. If they get HTML/JSON instead, no preview renders."
          },
          {
            "name": "Twitter/X Cards",
            "value": "Card type: summary_large_image",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Canonical URL",
            "value": "https://www.lunys.sk/",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Structured Data (JSON-LD)",
            "value": "3 block(s): WebSite, Organization, SearchAction",
            "status": "pass",
            "evidence": {
              "source": "schema"
            }
          },
          {
            "name": "JSON-LD Validity",
            "value": "3 block(s) parse cleanly",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "robots.txt",
            "value": "Present",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "XML Sitemap",
            "value": "Found with ~1+ URLs",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "HTML Language Attribute",
            "value": "lang=\"sk\"",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Image Alt Attributes",
            "value": "Only 29% of 306 images have alt text",
            "status": "fail",
            "fixLink": {
              "url": "https://zulien.sk",
              "label": "Fix with SEO module →"
            },
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "217 images lack alt text. Write unique, descriptive alt text for each product image. Include product name and key details.",
            "whyMatters": "Google cannot understand images without alt text. This is both an SEO and accessibility failure — and a legal risk under ADA/EAA."
          },
          {
            "name": "Meta Robots Tag",
            "value": "index, follow",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Text-to-HTML Ratio",
            "value": "4% ratio but 2719 words — content is substantial; the low ratio is markup/inline-JS bloat, not thin content",
            "status": "info",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Your text content is sufficient. To raise the ratio, move inline <script>/<style> to external files and trim template bloat — this is a performance/cleanliness win, not a content gap.",
            "whyMatters": "Text-to-HTML ratio is only a thin-content signal when actual word count is also low. With 500+ words, search engines have plenty to rank on."
          },
          {
            "name": "Favicon",
            "value": "Favicon detected",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "Image Format Optimization",
            "value": "0% next-gen formats — 0 JPEG, 22 PNG images",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Convert all images to WebP format. Most CMS platforms have plugins for automatic WebP conversion. Use AVIF for even better compression.",
            "whyMatters": "Your images are using legacy formats only. Switching to WebP typically reduces page weight by 30-50% — one of the highest-impact performance optimizations."
          },
          {
            "name": "Semantic HTML Structure",
            "value": "Only 3/6 semantic elements — missing: <article>, <nav>, <aside>",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Use semantic HTML5 elements: <header>, <nav>, <main>, <article>, <aside>, <footer>. These help search engines understand page structure and improve accessibility.",
            "whyMatters": "Semantic HTML gives search engines clear signals about content structure. Pages with proper semantic markup earn more featured snippets and knowledge panel appearances."
          },
          {
            "name": "Canonical URL Consistency",
            "value": "Canonical points to different URL: https://www.lunys.sk/",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Your canonical URL doesn't match the current page URL. Ensure the canonical points to the preferred version (with or without trailing slash, www vs non-www). Inconsistent canonicals confuse search engines.",
            "whyMatters": "A mismatched canonical tells Google this page is a duplicate of another URL. If unintentional, Google may ignore this page entirely in favor of the canonical target."
          },
          {
            "name": "Sitemap in robots.txt",
            "value": "robots.txt exists but doesn't reference your sitemap",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add 'Sitemap: https://yourdomain.com/sitemap.xml' to your robots.txt file. This helps search engines discover your sitemap faster.",
            "whyMatters": "While Google can find sitemaps via Search Console, referencing it in robots.txt ensures all search engines (Bing, Yandex, Baidu) can discover it automatically."
          },
          {
            "name": "Content Depth",
            "value": "2719 words — sufficient content",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Deep Heading Hierarchy",
            "value": "H2: 4, H3: 7 — well-structured content",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Internal Linking",
            "value": "77 internal links — strong site navigation",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Empty/Dead Links",
            "value": "2 minor dead link(s) — acceptable",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Accessibility Fundamentals",
            "value": "2/4 a11y signals — missing: ARIA labels, skip navigation link",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add: ARIA landmark roles (role='navigation', role='main'), aria-label on interactive elements, a 'Skip to content' link, and lang attribute on <html>.",
            "whyMatters": "The European Accessibility Act (EAA) takes effect June 2025 for e-commerce. Non-compliant sites face fines. Accessibility also improves SEO — Google confirms a11y as a ranking signal."
          },
          {
            "name": "Image Dimension Attributes",
            "value": "Only 14% of images have width/height attributes",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add width and height attributes to all <img> tags. This prevents layout shifts (CLS) and helps browsers allocate space before images load.",
            "whyMatters": "Missing image dimensions are the #1 cause of Cumulative Layout Shift. Google explicitly uses CLS as a Core Web Vital ranking factor."
          }
        ]
      },
      "gdpr": {
        "score": 72,
        "checks": [
          {
            "name": "Cookie Consent Banner (CMP)",
            "value": "Cookiebot detected",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7"
              ],
              "skLaw": [
                "§ 14"
              ],
              "verified": [
                {
                  "title": "Zákonnosť spracúvania",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 6 — Zákonnosť spracúvania 1. Spracúvanie je zákonné iba vtedy a iba v tom rozsahu, keď je splnená aspoň jedna z týchto podmienok: Písmeno f) prvého pododseku sa nevzťahuje na spracúvanie vykonávané orgánmi verejnej moci pri výkone i",
                  "citation": "čl. 6 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky vyjadrenia súhlasu",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 7 — Podmienky vyjadrenia súhlasu 1. Ak je spracúvanie založené na súhlase, prevádzkovateľ musí vedieť preukázať, že dotknutá osoba vyjadrila súhlas so spracúvaním svojich osobných údajov. 2. Ak dá dotknutá osoba súhlas v rámci písom",
                  "citation": "čl. 7 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky poskytnutia súhlasu so spracúvaním osobných údajov",
                  "excerpt": "§ 14 Podmienky poskytnutia súhlasu so spracúvaním osobných údajov (1) Ak je spracúvanie osobných údajov založené na súhlase dotknutej osoby, prevádzkovateľ je povinný kedykoľvek vedieť preukázať, že dotknutá osoba poskytla súhlas so spracúv",
                  "citation": "§14 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            }
          },
          {
            "name": "Tracking Scripts & Consent",
            "value": "2 tracker(s) detected with CMP: Google Analytics/GTM, Hotjar",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7",
                "EDPB Opinion 5/2019"
              ],
              "skLaw": [
                "§ 14"
              ],
              "verified": [
                {
                  "title": "Zákonnosť spracúvania",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 6 — Zákonnosť spracúvania 1. Spracúvanie je zákonné iba vtedy a iba v tom rozsahu, keď je splnená aspoň jedna z týchto podmienok: Písmeno f) prvého pododseku sa nevzťahuje na spracúvanie vykonávané orgánmi verejnej moci pri výkone i",
                  "citation": "čl. 6 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky vyjadrenia súhlasu",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 7 — Podmienky vyjadrenia súhlasu 1. Ak je spracúvanie založené na súhlase, prevádzkovateľ musí vedieť preukázať, že dotknutá osoba vyjadrila súhlas so spracúvaním svojich osobných údajov. 2. Ak dá dotknutá osoba súhlas v rámci písom",
                  "citation": "čl. 7 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky poskytnutia súhlasu so spracúvaním osobných údajov",
                  "excerpt": "§ 14 Podmienky poskytnutia súhlasu so spracúvaním osobných údajov (1) Ak je spracúvanie osobných údajov založené na súhlase dotknutej osoby, prevádzkovateľ je povinný kedykoľvek vedieť preukázať, že dotknutá osoba poskytla súhlas so spracúv",
                  "citation": "§14 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            }
          },
          {
            "name": "Google Consent Mode v2",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Implement Google Consent Mode v2 with gtag('consent', 'default', { ad_storage: 'denied', analytics_storage: 'denied', ad_user_data: 'denied', ad_personalization: 'denied' }). Required since March 2024 for EU audiences.",
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7"
              ],
              "skLaw": [
                "§ 14"
              ],
              "verified": [
                {
                  "title": "Zákonnosť spracúvania",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 6 — Zákonnosť spracúvania 1. Spracúvanie je zákonné iba vtedy a iba v tom rozsahu, keď je splnená aspoň jedna z týchto podmienok: Písmeno f) prvého pododseku sa nevzťahuje na spracúvanie vykonávané orgánmi verejnej moci pri výkone i",
                  "citation": "čl. 6 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky vyjadrenia súhlasu",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 7 — Podmienky vyjadrenia súhlasu 1. Ak je spracúvanie založené na súhlase, prevádzkovateľ musí vedieť preukázať, že dotknutá osoba vyjadrila súhlas so spracúvaním svojich osobných údajov. 2. Ak dá dotknutá osoba súhlas v rámci písom",
                  "citation": "čl. 7 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky poskytnutia súhlasu so spracúvaním osobných údajov",
                  "excerpt": "§ 14 Podmienky poskytnutia súhlasu so spracúvaním osobných údajov (1) Ak je spracúvanie osobných údajov založené na súhlase dotknutej osoby, prevádzkovateľ je povinný kedykoľvek vedieť preukázať, že dotknutá osoba poskytla súhlas so spracúv",
                  "citation": "§14 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            },
            "whyMatters": "Google requires Consent Mode v2 for all EU traffic since March 2024. Without it, Google Ads remarketing and conversion data will not function, and you lose measurement data."
          },
          {
            "name": "Privacy Policy Page",
            "value": "/ochrana-sukromia",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "legalRefs": {
              "gdpr": [
                "Art. 12",
                "Art. 13",
                "Art. 14"
              ],
              "skLaw": [
                "§ 19",
                "§ 20"
              ],
              "verified": [
                {
                  "title": "Transparentnosť informácií, oznámenia a postupy výkonu práv dotknutej osoby",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 12 — Transparentnosť informácií, oznámenia a postupy výkonu práv dotknutej osoby 3. Prevádzkovateľ poskytne dotknutej osobe informácie o opatreniach, ktoré sa prijali na základe žiadosti podľa článkov 15 až 22, bez zbytočného odklad",
                  "citation": "čl. 12 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Informácie, ktoré sa majú poskytovať pri získavaní osobných údajov od dotknutej osoby",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 13 — Informácie, ktoré sa majú poskytovať pri získavaní osobných údajov od dotknutej osoby 2. Okrem informácií, ktoré sa uvádzajú v odseku 1, prevádzkovateľ poskytne dotknutej osobe pri získavaní osobných údajov tieto ďalšie informá",
                  "citation": "čl. 13 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Informácie, ktoré sa majú poskytnúť, ak osobné údaje neboli získané od dotknutej osoby",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 14 — Informácie, ktoré sa majú poskytnúť, ak osobné údaje neboli získané od dotknutej osoby 2. Okrem informácií uvedených v odseku 1 prevádzkovateľ poskytne dotknutej osobe tieto ďalšie informácie potrebné na zabezpečenie spravodliv",
                  "citation": "čl. 14 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Poskytované informácie, ak osobné údaje sú získané od dotknutej osoby",
                  "excerpt": "§ 19 Poskytované informácie, ak osobné údaje sú získané od dotknutej osoby (4) Odseky 1 až 3 sa neuplatňujú v rozsahu, v akom boli informácie dotknutej osobe poskytnuté pred spracúvaním osobných údajov.",
                  "citation": "§19 ods. 4 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                },
                {
                  "title": "Poskytované informácie, ak osobné údaje nie sú získané od dotknutej osoby",
                  "excerpt": "§ 20 Poskytované informácie, ak osobné údaje nie sú získané od dotknutej osoby (5) d) ak osobné údaje musia zostať dôverné na základe povinnosti mlčanlivosti podľa osobitného predpisu. 15 )",
                  "citation": "§20 ods. 5 písm. d) zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            }
          },
          {
            "name": "Cookie Policy",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Create a separate cookie policy page listing every cookie by: name, provider, purpose, category (necessary/analytics/marketing), and expiration. Most CMPs auto-generate this.",
            "legalRefs": {
              "gdpr": [
                "Art. 12",
                "Art. 13(1)(c)-(e)"
              ],
              "skLaw": [
                "§ 19"
              ],
              "verified": [
                {
                  "title": "Transparentnosť informácií, oznámenia a postupy výkonu práv dotknutej osoby",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 12 — Transparentnosť informácií, oznámenia a postupy výkonu práv dotknutej osoby 3. Prevádzkovateľ poskytne dotknutej osobe informácie o opatreniach, ktoré sa prijali na základe žiadosti podľa článkov 15 až 22, bez zbytočného odklad",
                  "citation": "čl. 12 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Informácie, ktoré sa majú poskytovať pri získavaní osobných údajov od dotknutej osoby",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 13 — Informácie, ktoré sa majú poskytovať pri získavaní osobných údajov od dotknutej osoby 2. Okrem informácií, ktoré sa uvádzajú v odseku 1, prevádzkovateľ poskytne dotknutej osobe pri získavaní osobných údajov tieto ďalšie informá",
                  "citation": "čl. 13 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Poskytované informácie, ak osobné údaje sú získané od dotknutej osoby",
                  "excerpt": "§ 19 Poskytované informácie, ak osobné údaje sú získané od dotknutej osoby (4) Odseky 1 až 3 sa neuplatňujú v rozsahu, v akom boli informácie dotknutej osobe poskytnuté pred spracúvaním osobných údajov.",
                  "citation": "§19 ods. 4 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            },
            "whyMatters": "The ePrivacy Directive requires transparent cookie disclosure. Vague statements like 'we use cookies for functionality' don't meet the specificity requirement."
          },
          {
            "name": "Legal Contact / Imprint Page",
            "value": "https://www.lunys.sk/o-nas",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Terms & Conditions Page",
            "value": "https://www.lunys.sk/vseobecne-obchodne-podmienky-a27",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Data Encryption (No Mixed Content)",
            "value": "All resources loaded over HTTPS",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Third-party Data Sharing",
            "value": "1 third-party domain(s)",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Personal Data Exposure in Source",
            "value": "2 personal email(s) in page source: zakaznik@lunys.sk, objednavkypp@lunys.sk",
            "status": "warning",
            "evidence": {
              "sample": "zakaznik@lunys.sk, objednavkypp@lunys.sk",
              "source": "HTML-heuristic"
            },
            "howToFix": "Remove person-named email addresses (e.g. firstname.lastname@) from the public HTML. Use role mailboxes (info@, sales@) or a contact form instead.",
            "legalRefs": {
              "gdpr": [
                "Art. 5(1)(f)",
                "Art. 32",
                "Art. 33"
              ],
              "skLaw": [
                "§ 39",
                "§ 40"
              ],
              "verified": [
                {
                  "title": "Zásady spracúvania osobných údajov",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 5 — Zásady spracúvania osobných údajov 1. Osobné údaje musia byť: (a) spracúvané zákonným spôsobom, spravodlivo a transparentne vo vzťahu k dotknutej osobe („zákonnosť, spravodlivosť a transparentnosť“); (b) získavané na konkrétne u",
                  "citation": "čl. 5 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Bezpečnosť spracúvania",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 32 — Bezpečnosť spracúvania 1. Prevádzkovateľ a sprostredkovateľ prijmú so zreteľom na najnovšie poznatky, náklady na vykonanie opatrení a na povahu, rozsah, kontext a účely spracúvania, ako aj na riziká s rôznou pravdepodobnosťou a",
                  "citation": "čl. 32 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Oznámenie porušenia ochrany osobných údajov dozornému orgánu",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 33 — Oznámenie porušenia ochrany osobných údajov dozornému orgánu 1. V prípade porušenia ochrany osobných údajov prevádzkovateľ bez zbytočného odkladu a podľa možnosti najneskôr do 72 hodín po tom, čo sa o tejto skutočnosti dozvedel",
                  "citation": "čl. 33 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Bezpečnosť spracúvania",
                  "excerpt": "§ 39 Bezpečnosť spracúvania (1) Prevádzkovateľ a sprostredkovateľ sú povinní prijať so zreteľom na najnovšie poznatky, na náklady na vykonanie opatrení, na povahu, rozsah, kontext a účel spracúvania osobných údajov a na riziká s rôznou prav",
                  "citation": "§39 ods. 1 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                },
                {
                  "title": "Oznámenie porušenia ochrany osobných údajov úradu",
                  "excerpt": "§ 40 Oznámenie porušenia ochrany osobných údajov úradu (4) Oznámenie podľa odseku 1 musí obsahovať najmä a) opis povahy porušenia ochrany osobných údajov vrátane, ak je to možné, kategórií a približného počtu dotknutých osôb, ktorých sa por",
                  "citation": "§40 ods. 4 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            },
            "confidence": "low",
            "whyMatters": "A named individual's email is personal data under GDPR Art. 4(1); publishing it in source breaches data minimisation (Art. 5(1)(c)). Role mailboxes like info@ are intentionally public and are not flagged here."
          },
          {
            "name": "Right to Erasure (Data Deletion)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Provide a clear mechanism for users to request data deletion — either a dedicated page, a form, or explicit instructions in your privacy policy. Include a 'Delete my account' option in user settings.",
            "legalRefs": {
              "gdpr": [
                "Art. 17"
              ],
              "skLaw": [
                "§ 23"
              ],
              "verified": [
                {
                  "title": "Právo na vymazanie (právo „na zabudnutie“)",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 17 — Právo na vymazanie (právo „na zabudnutie“) 1. Dotknutá osoba má tiež právo dosiahnuť u prevádzkovateľa bez zbytočného odkladu vymazanie osobných údajov, ktoré sa jej týkajú, a prevádzkovateľ je povinný bez zbytočného odkladu vy",
                  "citation": "čl. 17 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Právo na výmaz osobných údajov",
                  "excerpt": "§ 23 Právo na výmaz osobných údajov (1) Dotknutá osoba má právo na to, aby prevádzkovateľ bez zbytočného odkladu vymazal osobné údaje, ktoré sa jej týkajú.",
                  "citation": "§23 ods. 1 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            },
            "whyMatters": "GDPR Article 17 gives users the 'right to be forgotten.' EU regulators expect a clear, accessible process. Italian DPA fined companies €20M+ for obstructing erasure requests."
          },
          {
            "name": "Newsletter Consent",
            "value": "Newsletter form with consent mechanism detected",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7",
                "ePrivacy Art. 13"
              ],
              "skLaw": [
                "§ 14",
                "§ 109 zák. 452/2021"
              ],
              "verified": [
                {
                  "title": "Zákonnosť spracúvania",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 6 — Zákonnosť spracúvania 1. Spracúvanie je zákonné iba vtedy a iba v tom rozsahu, keď je splnená aspoň jedna z týchto podmienok: Písmeno f) prvého pododseku sa nevzťahuje na spracúvanie vykonávané orgánmi verejnej moci pri výkone i",
                  "citation": "čl. 6 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky vyjadrenia súhlasu",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 7 — Podmienky vyjadrenia súhlasu 1. Ak je spracúvanie založené na súhlase, prevádzkovateľ musí vedieť preukázať, že dotknutá osoba vyjadrila súhlas so spracúvaním svojich osobných údajov. 2. Ak dá dotknutá osoba súhlas v rámci písom",
                  "citation": "čl. 7 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky poskytnutia súhlasu so spracúvaním osobných údajov",
                  "excerpt": "§ 14 Podmienky poskytnutia súhlasu so spracúvaním osobných údajov (1) Ak je spracúvanie osobných údajov založené na súhlase dotknutej osoby, prevádzkovateľ je povinný kedykoľvek vedieť preukázať, že dotknutá osoba poskytla súhlas so spracúv",
                  "citation": "§14 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                },
                {
                  "title": "—",
                  "excerpt": "§ 109 — (8) Každý, kto ukladá alebo získava prístup k informáciám uloženým v koncovom zariadení užívateľa, je na to oprávnený iba ak užívateľ udelil preukázateľný súhlas spĺňajúci náležitosti podľa osobitného predpisu. 126 ) Povinnosť získa",
                  "citation": "§109 ods. 8 zákona č. 452/2021 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            }
          },
          {
            "name": "Data Protection Officer Contact",
            "value": "DPO / data protection contact found",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Withdrawal of Consent Mechanism",
            "value": "Consent withdrawal / opt-out mechanism found",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "legalRefs": {
              "gdpr": [
                "Art. 7(3)"
              ],
              "skLaw": [
                "§ 14(4)"
              ],
              "verified": [
                {
                  "title": "Podmienky vyjadrenia súhlasu",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 7 — Podmienky vyjadrenia súhlasu 1. Ak je spracúvanie založené na súhlase, prevádzkovateľ musí vedieť preukázať, že dotknutá osoba vyjadrila súhlas so spracúvaním svojich osobných údajov. 2. Ak dá dotknutá osoba súhlas v rámci písom",
                  "citation": "čl. 7 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky poskytnutia súhlasu so spracúvaním osobných údajov",
                  "excerpt": "§ 14 Podmienky poskytnutia súhlasu so spracúvaním osobných údajov (1) Ak je spracúvanie osobných údajov založené na súhlase dotknutej osoby, prevádzkovateľ je povinný kedykoľvek vedieť preukázať, že dotknutá osoba poskytla súhlas so spracúv",
                  "citation": "§14 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            }
          },
          {
            "name": "Age Verification",
            "value": "Age-restricted content detected without age gate",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Implement age verification for alcohol, tobacco, gambling, or adult content. Use a date-of-birth check or age confirmation modal before accessing the site.",
            "whyMatters": "EU member states require age verification for age-restricted products. German JuSchG (Youth Protection Act) and similar laws mandate age gates. Missing them risks regulatory action and marketplace delisting."
          },
          {
            "name": "Omnibus Price Disclosure (30-day low)",
            "value": "Discounts shown without a visible 'lowest price in last 30 days' reference",
            "status": "warning",
            "fixLink": {
              "url": "https://zulien.sk",
              "label": "Omnibus price-history module →"
            },
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Whenever you advertise a price reduction, display the lowest price applied in the 30 days before the discount, next to the new price. In PrestaShop add a 30-day price-history anchor (e.g. our zu_pricehistory module) so every sale label is compliant automatically.",
            "legalRefs": {
              "gdpr": [
                "Smernica (EÚ) 2019/2161 (Omnibus)",
                "Smernica 98/6/ES čl. 6a"
              ],
              "czLaw": [
                "zák. 634/1992 Sb. § 12a"
              ],
              "skLaw": [
                "zák. 108/2024 Z.z."
              ]
            },
            "confidence": "low",
            "whyMatters": "The EU Omnibus Directive (2019/2161), enacted in SK as zák. 108/2024 and CZ via zák. 634/1992, makes the 30-day reference price MANDATORY on every advertised discount. ŠOI/ČOI actively fine missing disclosures — and a '−40%' off an inflated base is exactly what they target."
          },
          {
            "name": "Consumer Dispute Resolution Links",
            "value": "No EU ODR platform or supervisory-authority link found",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add the EU ODR platform link (https://ec.europa.eu/consumers/odr) and your national authority (SK: Slovenská obchodná inšpekcia / soi.sk, CZ: Česká obchodní inspekce / coi.cz) to the footer and Terms & Conditions.",
            "legalRefs": {
              "gdpr": [
                "Nariadenie (EÚ) 524/2013 (ODR)",
                "Smernica 2013/11/EÚ (ADR)"
              ],
              "czLaw": [
                "zák. 634/1992 Sb. § 14"
              ],
              "skLaw": [
                "zák. 391/2015 Z.z."
              ]
            },
            "whyMatters": "EU Regulation 524/2013 makes the ODR link mandatory for every online trader; national law requires naming the supervisory authority. ŠOI/ČOI inspect for exactly this, and its absence is a frequently-fined consumer-law breach."
          },
          {
            "name": "Withdrawal & Complaints Policy",
            "value": "Missing: right of withdrawal (odstúpenie od zmluvy)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Publish and footer-link a Withdrawal policy (14-day right of withdrawal + model withdrawal form) and a Complaints procedure (reklamačný poriadok / reklamační řád). Reference them at checkout.",
            "legalRefs": {
              "gdpr": [
                "Smernica 2011/83/EÚ čl. 6(1)(h),(9)"
              ],
              "czLaw": [
                "zák. 89/2012 Sb. § 1829"
              ],
              "skLaw": [
                "zák. 108/2024 Z.z."
              ]
            },
            "whyMatters": "The Consumer Rights Directive (2011/83/EU) and SK zák. 108/2024 / CZ zák. 89/2012 require pre-contractual disclosure of the 14-day withdrawal right and an accessible complaints procedure. Missing them extends customers' cancellation rights and is a standard ŠOI/ČOI finding."
          }
        ]
      },
      "nis2": {
        "score": -1,
        "checks": [
          {
            "name": "NIS2 Compliance",
            "value": "Scope undetermined — IČO/company enrichment unavailable for this domain.",
            "status": "info",
            "howToFix": "",
            "whyMatters": ""
          }
        ]
      },
      "mobile": {
        "score": 61,
        "checks": [
          {
            "name": "Viewport Configuration",
            "value": "Present, but maximum-scale=1 disables pinch-to-zoom",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Remove 'maximum-scale=1' and 'user-scalable=no' from your viewport meta tag. Use: <meta name='viewport' content='width=device-width, initial-scale=1'>",
            "whyMatters": "Preventing pinch-to-zoom is an accessibility violation (WCAG 1.4.4). Users with vision impairments need zoom. Google penalizes sites that disable zoom."
          },
          {
            "name": "Mobile Performance Score",
            "value": "60/100 (target: 90+)",
            "status": "warning",
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "Optimize for mobile: compress images to WebP, defer non-critical JS, reduce CSS file size. Mobile CPUs are 3-5x slower than desktop — what's fast on desktop is slow on mobile.",
            "whyMatters": "Over 65% of e-commerce traffic is mobile (Statista 2024). Google ranks based on mobile performance, not desktop. Mobile score <50 means you're penalized in mobile search."
          },
          {
            "name": "Touch Target Size",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Ensure ALL interactive elements (buttons, links, form fields) are at least 48×48px with 8px minimum spacing between them. Pay special attention to: navigation menus, filter buttons, product variant selectors, and footer links.",
            "whyMatters": "Small tap targets cause 37% more mis-taps on mobile (Google UX research). In e-commerce, a mis-tap on 'Remove from cart' instead of 'Checkout' directly loses revenue."
          },
          {
            "name": "Font Size Readability",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Set minimum 16px font size for body text. Use relative units (rem/em) instead of px for scalability. Product titles: 18px+, prices: 20px+, CTAs: 16px+ with bold.",
            "whyMatters": "Text smaller than 16px forces mobile users to pinch-zoom. This breaks the responsive layout and creates a frustrating experience. Users over 40 are especially affected — and they have the highest purchasing power."
          },
          {
            "name": "Content Fits Viewport",
            "value": "No horizontal scrolling needed",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Responsive Design Techniques",
            "value": "Media queries detected",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "PWA Features",
            "value": "Has manifest, missing service worker",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add a service worker to enable PWA features. Register a service worker for offline caching and faster repeat visits.",
            "whyMatters": "PWA-enabled stores see 52% higher engagement and 36% higher conversion rates (Google case studies). Users can install the store as an app on their home screen."
          },
          {
            "name": "Theme Color",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add <meta name='theme-color' content='#your-brand-color'> to match your brand. Browsers use this to color the address bar, task switcher, and PWA chrome.",
            "whyMatters": "Theme-color creates a polished, branded mobile experience. It makes your site look native and professional — small detail, big perception impact."
          },
          {
            "name": "Mobile Navigation (Semantic)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Wrap your navigation in a <nav> element. This helps mobile screen readers offer 'skip to navigation' and improves voice navigation (e.g., 'Siri, show me the menu').",
            "whyMatters": "Semantic <nav> elements are essential for mobile accessibility. Screen readers use them to let users jump directly to navigation — critical on small screens where content is long."
          },
          {
            "name": "Responsive Images (srcset)",
            "value": "42 image(s) use srcset for responsive sizing",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Apple Mobile Web App",
            "value": "Web manifest found but no Apple-specific meta tags",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "iOS Safari doesn't fully support web manifests. Add Apple-specific meta tags for the best iOS experience: apple-mobile-web-app-capable, apple-touch-icon, and status-bar-style.",
            "whyMatters": "Web manifests work for Android but iOS requires separate meta tags. Without them, iOS users get a degraded 'Add to Home Screen' experience."
          },
          {
            "name": "Form Input Types",
            "value": "phone fields use type='text' instead of type='tel'",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Use semantic input types: type='email' for email (shows @ keyboard), type='tel' for phone (shows number pad), type='search' for search (shows search button). These trigger optimized mobile keyboards.",
            "whyMatters": "Correct input types show specialized mobile keyboards — email keyboard with @, phone with number pad. This reduces input errors by 30% and speeds up form completion (Baymard Institute)."
          },
          {
            "name": "Mobile Sticky CTA",
            "value": "Add-to-cart button found but no sticky/fixed positioning detected",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add a sticky add-to-cart bar at the bottom of mobile screens. Use position: sticky or position: fixed with bottom: 0. The CTA should always be visible without scrolling.",
            "whyMatters": "Mobile users scroll extensively. A sticky add-to-cart bar increases mobile conversion by 8-12% (Baymard Institute). Without it, users must scroll back up to purchase — many won't."
          },
          {
            "name": "Text Overflow Handling",
            "value": "No word-break/overflow-wrap CSS detected",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add 'overflow-wrap: break-word' to your body or main content container. Without it, long URLs, product SKUs, or German compound words can break mobile layouts.",
            "whyMatters": "Long strings without word-break cause horizontal overflow on mobile — the #1 cause of 'content wider than viewport' failures. German/Finnish compound words and URLs are common culprits."
          },
          {
            "name": "Print Stylesheet",
            "value": "Order/invoice page without print styles",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add @media print CSS rules to hide navigation, ads, and non-essential elements. Ensure order details, prices, and company info are visible when printed.",
            "whyMatters": "Customers print order confirmations and invoices. Without print styles, they get navigation bars, cookie banners, and broken layouts. This is a common usability complaint for e-commerce."
          },
          {
            "name": "Payment Methods Detected",
            "value": "1 method(s): Apple Pay",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Express Checkout (Apple Pay + Google Pay)",
            "value": "Iba Apple Pay detekovaný — chýba Google Pay",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Pridaj Google Pay cez Stripe, Adyen alebo Mollie. Mobile conversion rate rastie o 10-20 % keď je express checkout dostupný.",
            "whyMatters": "iOS/Android majú 50/50 share. Jeden bez druhého znamená stratený revenue na polovici mobilných používateľov."
          },
          {
            "name": "SK/CZ Local Payment Methods",
            "value": "Žiadna SK/CZ local payment metóda nedetekovaná na homepage — bankové tlačidlá/QR sa zvyčajne zobrazia až v checkoute",
            "status": "info",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Integrovať SK payments — Inger"
            },
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Ak SK/CZ local platby nemáš, integruj GoPay alebo ComGate — obe podporujú Tatra Pay, VÚB Pay, ČSOB Pay, Raiffeisen, QR platba v jednom API. Alternatívne Barion pre CZ trh.",
            "whyMatters": "SK/CZ shop bez bankových tlačidiel a QR platby = masívny cart abandonment. Priemerný SK e-shop má 6-8 payment metód. (Sken vidí iba homepage — over manuálne v checkoute.)"
          },
          {
            "name": "Form Input Labels (WCAG 3.3.2)",
            "value": "Iba 10/45 inputs má label (22%)",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Accessibility audit — Inger"
            },
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "35 input elementov nemá label. Každý input musí mať priradený <label for=\"id\">Text</label> alebo aria-label. Placeholder NIE je label (WCAG 3.3.2). Ak je checkout/registrácia formulár — toto znižuje konverziu a porušuje EN 301 549 (EAA 2026).",
            "whyMatters": "EAA 2026 (European Accessibility Act) vstupuje do platnosti 28.6.2025. E-shopy nad 10 zamestnancov alebo €2M obrat musia byť WCAG 2.1 AA kompatibilné — chýbajúce labely sú jedna z najčastejších žalovateľných chýb."
          },
          {
            "name": "Heading Hierarchy (WCAG 1.3.1)",
            "value": "Preskočené úrovne: h2→h4",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Dodržuj poradie nadpisov h1 → h2 → h3 → h4 bez preskočenia. Screen readers používajú hierarchiu nadpisov na navigáciu. Ak potrebuješ menšie písmo ale rovnakú úroveň, použi CSS triedu, nie nižší heading tag.",
            "whyMatters": "Preskočené heading levely (napr. h1 priamo na h3) zlomia navigáciu pre screen reader používateľov a signalizujú Googlu zlú štruktúru dokumentu. Aj SEO je negatívne ovplyvnené."
          },
          {
            "name": "Link Text Quality (WCAG 2.4.4)",
            "value": "Všetky odkazy majú popisný text",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          }
        ]
      },
      "company": null,
      "modules": [],
      "security": {
        "score": 78,
        "checks": [
          {
            "name": "SSL/TLS Certificate",
            "value": "Valid HTTPS connection established",
            "status": "pass",
            "evidence": {
              "source": "SSL"
            }
          },
          {
            "name": "DNSSEC",
            "value": "Zone is DNSSEC-signed (DNSKEY published)",
            "status": "pass",
            "evidence": {
              "source": "DNS"
            },
            "whyMatters": "DNSSEC protects against DNS cache poisoning and on-path attackers redirecting your domain. Required by some sector regulators for NIS2 essential/important entities."
          },
          {
            "name": "CAA DNS Record",
            "value": "No CAA records — any CA can issue certificates for this domain",
            "status": "warning",
            "evidence": {
              "source": "DNS"
            },
            "howToFix": "Publish CAA TXT records pinning your CA. For Let's Encrypt: `0 issue \"letsencrypt.org\"`. For multiple CAs add additional `0 issue \"...\"` records. Add `0 iodef \"mailto:security@yourdomain.tld\"` for misissuance reports.",
            "whyMatters": "CAA records limit which Certificate Authorities can issue certificates for your domain. Without CAA, a compromised or rogue CA can issue valid certs that browsers will trust — a documented breach pattern (DigiNotar 2011, Symantec 2017)."
          },
          {
            "name": "HTTP → HTTPS Redirect",
            "value": "HTTP properly redirects to HTTPS",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "name": "HSTS (Strict-Transport-Security)",
            "value": "max-age=31536000, preload, includeSubDomains",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "name": "Content-Security-Policy (CSP)",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Security Hardening →"
            },
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Implement a CSP header. Start with: Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: — then gradually tighten.",
            "whyMatters": "CSP is the most powerful defense against XSS attacks. Without it, any injected script runs with full privileges. CSP blocks inline script injection, the #1 web attack vector."
          },
          {
            "name": "Clickjacking Protection",
            "value": "X-Frame-Options: SAMEORIGIN",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "name": "X-Content-Type-Options",
            "value": "nosniff",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "name": "Referrer-Policy",
            "value": "strict-origin-when-cross-origin",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "name": "Permissions-Policy",
            "value": "microphone=(self), camera=(self)",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "name": "Cookie Security Flags",
            "value": "4 cookie(s): 3 missing Secure, 3 missing HttpOnly, 4 missing SameSite",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Set all cookies with: Secure (HTTPS only), HttpOnly (no JS access), SameSite=Lax or Strict (CSRF protection). Session cookies MUST have all three.",
            "whyMatters": "Missing Secure flag = cookies sent over HTTP (stealable on WiFi). Missing HttpOnly = cookies readable by XSS. Missing SameSite = vulnerable to CSRF attacks."
          },
          {
            "name": "Technology Disclosure",
            "value": "Server: nginx (no version)",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "name": "Subresource Integrity (SRI)",
            "value": "All cross-origin scripts are auto-updating provider scripts where SRI does not apply",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "security.txt (RFC 9116)",
            "status": "warning",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Create /.well-known/security.txt with Contact, Expires, and Preferred-Languages fields. See securitytxt.org for the generator.",
            "whyMatters": "security.txt lets ethical hackers report vulnerabilities responsibly. Without it, they may disclose publicly or not report at all. Required by ISO 27001 and SOC 2."
          },
          {
            "name": "Server Version Disclosure",
            "value": "Nginx — version hidden",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "name": "CDN / WAF Protection",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Add a CDN/WAF like Cloudflare (free tier), Sucuri, or Fastly. They provide DDoS protection, bot filtering, and SSL management.",
            "whyMatters": "Without a CDN/WAF, your origin server is directly exposed to DDoS attacks, bot traffic, and brute-force attempts. Cloudflare blocks 150+ billion daily threats."
          },
          {
            "name": "Iframe Sandboxing",
            "value": "1/1 unknown iframe(s) without sandbox attribute",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add a sandbox attribute to non-provider <iframe> elements. Use sandbox='allow-scripts allow-same-origin' for third-party embeds. Trusted media/payment embeds (YouTube, Maps, Stripe, reCAPTCHA) are correctly excluded — they need full privileges to work.",
            "confidence": "low",
            "whyMatters": "Unsandboxed iframes from unknown sources can access your DOM, run scripts, and navigate the top window. They should be sandboxed to prevent clickjacking and XSS."
          },
          {
            "name": "Password Field Security",
            "value": "1 password field(s) — allow password manager autofill",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          }
        ]
      },
      "tech_stack": [
        {
          "eol": false,
          "name": "Magento",
          "category": "cms"
        },
        {
          "name": "jQuery",
          "category": "js-library"
        },
        {
          "name": "Swiper",
          "category": "js-library"
        },
        {
          "name": "reCAPTCHA",
          "category": "js-library"
        },
        {
          "name": "Nginx",
          "category": "server"
        }
      ],
      "performance": {
        "score": 63,
        "checks": [
          {
            "name": "Server Response Time (TTFB)",
            "value": "21ms",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "name": "First Contentful Paint (FCP)",
            "value": "0.67s",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "name": "Largest Contentful Paint (LCP)",
            "value": "1.35s — Core Web Vital ✓",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "name": "Total Blocking Time (TBT)",
            "value": "2056ms (good: <200ms)",
            "status": "fail",
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "Critical: audit all JavaScript. 1) Remove unused plugins/modules, 2) Defer analytics and chat widgets, 3) Code-split large bundles, 4) Move heavy computation to web workers.",
            "whyMatters": "TBT over 600ms means your page is unresponsive for over half a second. Users who can't interact within 100ms perceive the site as broken. This kills conversions."
          },
          {
            "name": "Cumulative Layout Shift (CLS)",
            "value": "0.002 — Core Web Vital ✓",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "name": "Speed Index",
            "value": "2.52s",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "name": "Total Page Weight",
            "value": "4.1 MB, 123 requests — too heavy!",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Performance Optimization →"
            },
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "Critical: your page is over 3 MB. 1) Convert all images to WebP/AVIF, 2) Lazy load everything below the fold, 3) Remove unused plugins, 4) Combine and minify CSS/JS, 5) Enable brotli compression.",
            "whyMatters": "Pages over 3 MB take 12+ seconds on 3G. The average e-commerce page is 2.2 MB — you're well above that. Amazon found every 100ms of latency costs 1% of sales."
          },
          {
            "name": "Render-blocking Resources",
            "value": "Not measured — PageSpeed did not return the render-blocking audit for this URL",
            "status": "info",
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "Re-run the scan, or test directly at PageSpeed Insights. This metric needs a successful Lighthouse lab run."
          },
          {
            "name": "Unused Code (CSS + JS)",
            "value": "1271 KB wasted on unused code!",
            "status": "fail",
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "You're loading 1271 KB of code that isn't used on this page. 1) Audit plugins and remove unused ones, 2) Use code-splitting for page-specific JS, 3) Run PurgeCSS on your stylesheets.",
            "whyMatters": "Over 200 KB of unused code significantly slows parsing and execution. This is one of the easiest performance wins — removing dead code requires no trade-offs."
          },
          {
            "name": "Text Compression (gzip/brotli)",
            "value": "All text resources properly compressed",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "name": "Resource Hints (Preload/Preconnect)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add resource hints: <link rel='preconnect' href='https://fonts.googleapis.com'> for third-party origins, <link rel='preload' as='image' href='hero.webp'> for critical resources.",
            "whyMatters": "Preconnect saves 100-500ms per third-party origin by establishing connections early. Preload starts downloading critical resources before the browser discovers them in CSS/JS."
          },
          {
            "name": "Lazy Loading",
            "value": "3% of images use native lazy loading (10/306)",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Cache-Control Strategy",
            "value": "no-store, no-cache, must-revalidate",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Set appropriate cache headers: static assets should have max-age=31536000 with versioned filenames. HTML pages can use max-age=0 with ETag for revalidation.",
            "whyMatters": "no-cache/no-store forces browsers to re-download resources on every visit. Repeat visitors load your entire site from scratch every time."
          },
          {
            "name": "Script Loading Strategy",
            "value": "Only 25% of 4 scripts optimized — most are render-blocking",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Performance Optimization →"
            },
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add defer or async to all <script src='...'> tags. Render-blocking scripts are the #1 cause of slow FCP. Defer maintains execution order, async does not.",
            "whyMatters": "3 render-blocking scripts can add 1-3 seconds to page load. Each synchronous script creates a sequential download-parse-execute chain."
          },
          {
            "name": "CSS File Count",
            "value": "4 CSS files loaded",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Consolidate CSS files by bundling them into 1-3 files. Each CSS file is a separate HTTP request that blocks rendering until downloaded.",
            "whyMatters": "Each render-blocking CSS file adds network latency. Consolidating CSS from 8 to 2 files can save 200-400ms on first load."
          },
          {
            "name": "Critical CSS Strategy",
            "value": "4 CSS files without critical CSS extraction",
            "status": "warning",
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "Extract critical above-the-fold CSS and inline it in <head>. Load remaining CSS asynchronously: <link rel='preload' href='styles.css' as='style' onload='this.rel=\"stylesheet\"'>.",
            "whyMatters": "Render-blocking CSS delays first paint. Inlining critical CSS eliminates the render-blocking round trip — the biggest FCP improvement for CSS-heavy sites."
          }
        ]
      },
      "ai_readiness": {
        "score": 56,
        "checks": [
          {
            "name": "AI Bot Access Policy",
            "value": "No AI bot restrictions (allowed by default)",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "llms.txt (AI Site Descriptor)",
            "status": "fail",
            "fixLink": {
              "url": "https://llmstxt.org",
              "label": "Learn about llms.txt →"
            },
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Create /llms.txt in Markdown format:\n# Your Store Name\n> One-line summary of your business and key offerings.\n\nDetailed description paragraph.\n\n## Products\n- [Product Category](URL): Description\n\n## About\n- [About Us](URL): Company history and values\n\nSee llmstxt.org for the full specification.",
            "whyMatters": "llms.txt is the emerging standard for AI-readable site descriptions — like robots.txt was for search engines. Early adopters (Yoast, Cloudflare, Stripe) are already using it. Without it, AI assistants have no guided overview of your store."
          },
          {
            "name": "llms-full.txt (Complete AI Content)",
            "status": "warning",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Create /llms-full.txt containing your complete site documentation in a single Markdown file — product catalog summaries, FAQs, policies, brand story. This gives AI models maximum context about your store.",
            "whyMatters": "llms-full.txt provides AI models with your entire site content in one parseable file. It's the difference between an AI having a brief overview vs. deep knowledge of your products and services."
          },
          {
            "name": "Content Accessibility for AI",
            "value": "2719 words in raw HTML (3.8% text ratio) — readable by AI crawlers without executing JS",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Structured Data Foundation",
            "value": "3 schema types found (WebSite, Organization, SearchAction) — add more for comprehensive AI coverage",
            "status": "warning",
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Expand your structured data: add Organization, Product, BreadcrumbList, WebSite with SearchAction, and FAQPage schemas. Sites with 4+ schema types are 36% more likely to appear in AI search summaries.",
            "whyMatters": "AI assistants (ChatGPT, Perplexity, Google AI Overviews) synthesize answers from structured data. Research shows sites with comprehensive schema markup are 36% more likely to be cited by AI."
          },
          {
            "name": "Product Schema Completeness",
            "value": "No Product schema on this homepage — Product schema lives on product detail pages, which this single-URL scan didn't visit",
            "status": "info",
            "evidence": {
              "source": "schema"
            },
            "howToFix": "To audit Product schema, run the scan on a product detail URL. On product pages add: name, description, image, offers (price, priceCurrency, availability), brand, sku, aggregateRating.",
            "whyMatters": "Product schema only belongs on product pages, so its absence on this page is expected — not a defect. Scan a product URL to evaluate it."
          },
          {
            "name": "Organization Schema + Entity Linking",
            "value": "Organization schema found but no sameAs links",
            "status": "warning",
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Add sameAs array to your Organization schema linking to Wikipedia, LinkedIn, Facebook, Instagram, and other official profiles. This creates a Knowledge Graph entity for your brand.",
            "whyMatters": "sameAs links tell AI: 'This is the same entity across the web.' Sites with sameAs to Wikipedia are 3x more likely to appear in AI-generated answers. It's how Google builds Knowledge Panels."
          },
          {
            "name": "FAQ Schema (Direct AI Answers)",
            "status": "warning",
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Add FAQPage schema to every product page and category page. Include 3-5 Q&As per page covering: product specifications, shipping, returns, usage instructions. Format: question (full sentence) + answer (75-150 words).",
            "whyMatters": "FAQ schema provides 30% higher AI citation rates (LLMClicks research). ChatGPT, Perplexity, and Google AI Overviews pull FAQ answers verbatim. It's the fastest way to get your content cited by AI."
          },
          {
            "name": "Breadcrumb Schema",
            "status": "warning",
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Add BreadcrumbList schema reflecting your category hierarchy: Home → Category → Subcategory → Product. Each item needs name and URL.",
            "whyMatters": "AI assistants use breadcrumbs to understand product categorization and site structure. Without it, AI can't contextualize where products fit in your catalog — e.g., 'Running Shoes' under 'Sports > Footwear > Running'."
          },
          {
            "name": "Site Search Schema (SearchAction)",
            "value": "WebSite SearchAction configured — AI can search your store",
            "status": "pass",
            "evidence": {
              "source": "schema"
            }
          },
          {
            "name": "Content Depth for AI",
            "value": "2719 words — rich content for AI analysis and citation",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Answer-First Content Format",
            "value": "First paragraph: 722 words — good content density above the fold",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Heading Hierarchy for AI",
            "value": "0 H1, 4 H2, 7 H3 — poor structure",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Use exactly 1 H1 (page title), then organize content with H2 sections and H3 subsections. Each heading should describe the content that follows. Never skip heading levels (H1→H3 without H2).",
            "whyMatters": "AI extracts information based on heading structure. Pages with proper H1→H2→H3 hierarchy are more accurately parsed by ChatGPT, Perplexity, and Google AI Overviews. Without it, AI may misinterpret your content."
          },
          {
            "name": "Semantic HTML Structure",
            "value": "3/6 elements — missing: <article>, <nav>, <aside>",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add: <article>, <nav>, <aside>. Semantic HTML tells AI what's content (<article>), navigation (<nav>), sidebar (<aside>), etc. — without relying on CSS classes or visual layout.",
            "whyMatters": "AI crawlers don't see your CSS. They rely on semantic HTML to distinguish main content from navigation, ads, and boilerplate. The WordLift AI Audit weights semantic HTML as a primary machine-readability signal."
          },
          {
            "name": "Structured Content (Lists & Tables)",
            "value": "No structured content elements found",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add bulleted lists for features/benefits, numbered lists for steps/rankings, and tables for comparisons/specifications. These are the content formats AI extracts most reliably.",
            "whyMatters": "Unstructured paragraph-only content is harder for AI to parse and cite. Pages with lists and tables get cited 30-40% more in AI-generated answers because AI can extract specific facts more reliably."
          },
          {
            "name": "Content Freshness Signals",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add dateModified and datePublished to your JSON-LD schema, and display a visible 'Last updated' date on the page. Update content quarterly at minimum. AI heavily favors fresh, maintained content.",
            "whyMatters": "No freshness signals = AI assumes your content is stale. ChatGPT and Perplexity both weight recency in their citation algorithms. Competitors who show recent updates will be cited instead of your static pages."
          },
          {
            "name": "Entity Clarity & Brand Signals",
            "value": "OG tags complete but no sameAs entity links",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "For full entity clarity: 1) Complete Open Graph tags (og:title, og:description, og:image, og:type), 2) Add sameAs in Organization schema linking to Wikipedia, LinkedIn, Facebook, and other profiles.",
            "whyMatters": "AI needs to confidently identify your brand entity. Open Graph + sameAs create a cross-platform identity that AI models recognize. The HubSpot AEO Grader found entity clarity is a top-3 factor for AI brand recognition."
          },
          {
            "name": "Author Expertise Signals (E-E-A-T)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "For content pages (blog, guides, about): add Article/BlogPosting schema with author property linking to Person schema. Include the author's jobTitle, credentials, and social profiles.",
            "whyMatters": "AI models weight author expertise heavily. Pages from identified experts get cited 3x more than anonymous content. This is especially important for product guides, reviews, and advice content."
          },
          {
            "name": "Reviews & Ratings Schema",
            "value": "No review schema on this homepage — review/rating schema typically lives on product pages",
            "status": "info",
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Scan a product URL to audit review schema. On product pages add AggregateRating (ratingValue, reviewCount, bestRating) and individual Review schemas.",
            "whyMatters": "Review schema is product-page-specific, so its absence here is expected, not a defect."
          },
          {
            "name": "AI Plugin Manifest",
            "status": "warning",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Create /.well-known/ai-plugin.json if you have an API. This enables direct AI agent integration (ChatGPT Actions, custom GPTs). Include: name_for_model, description_for_model, auth config, and link to OpenAPI spec.",
            "whyMatters": "ai-plugin.json enables AI agents to interact with your store programmatically — search products, check prices, process orders. This is the bridge between AI assistants and your e-commerce functionality."
          },
          {
            "name": "Product Feed (AI Commerce)",
            "status": "warning",
            "fixLink": {
              "url": "https://audit.mergado.com/",
              "label": "Free feed audit — Mergado"
            },
            "evidence": {
              "sample": "probed /feed/products.xml, /google-shopping.xml, /export/google-shopping.xml — none returned a product feed",
              "source": "file-probe"
            },
            "howToFix": "Create a Google Merchant Center / product feed (XML or CSV). Expose it at a consistent URL and reference it in your sitemap. AI shopping assistants and comparison engines use product feeds for catalog discovery. Tip: validate your Heureka / Zboží / Glami / Merchant feeds for free with Mergado's audit.",
            "whyMatters": "Product feeds power Google Shopping, Bing Shopping, and increasingly AI commerce. Without a structured product feed, AI agents can't efficiently index your full catalog for product recommendations."
          },
          {
            "name": "Heureka XML Feed",
            "status": "warning",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Setup Heureka Feed — Inger"
            },
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Vygeneruj Heureka XML feed na /feed/heureka.xml (alebo /export/heureka.xml). PrestaShop má modul Heureka.cz, WooCommerce má pluginy. Štruktúra: <SHOP><SHOPITEM>...</SHOPITEM></SHOP> s ITEM_ID/PRODUCTNAME/URL/PRICE_VAT/CATEGORYTEXT (povinné) + EAN/PARAM/DELIVERY_DATE (highly recommended pre ranking).",
            "whyMatters": "Heureka.sk a Heureka.cz sú dominantné cenové porovnávače na SK/CZ trhu (40%+ all e-com discovery traffic). Bez XML feedu nie ste viditeľní na hlavnom trhovisku — strata 20-30 % potenciálneho traffic. Žiaden generický audit tool toto nekontroluje."
          },
          {
            "name": "Speakable Content (Voice AI)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add SpeakableSpecification schema to identify content sections suitable for voice assistants (Google Assistant, Alexa, Siri). Mark your product summaries and FAQs as speakable.",
            "whyMatters": "Voice AI commerce is growing rapidly. SpeakableSpecification tells voice assistants which content to read aloud. Early adoption positions your store for the voice shopping wave."
          },
          {
            "name": "Extractable Answer Blocks",
            "value": "5 paragraphs, avg 151 words — too long for AI snippets",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Optimal paragraphs for AI citation are 40-80 words. Break long paragraphs into focused, self-contained answer blocks. Each should make one clear point that AI can extract and quote.",
            "whyMatters": "Pages with 40-80 word paragraphs earn 70% more AI citations (Otterly 2026 data). AI extracts individual paragraphs as answer snippets — dense walls of text get skipped."
          },
          {
            "name": "Statistics & Data Presence",
            "value": "30 data points found — strong citation magnet",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Section Length Optimization",
            "value": "Avg section: 203 words — only 0% in 80-200 word optimal range",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Restructure content into sections of 120-180 words between H2/H3 headings. Each section should cover one topic completely. Split sections over 300 words, expand sections under 80 words.",
            "whyMatters": "Pages with 120-180 word sections earn 70% more AI citations (Otterly Citation Economy 2026). For Google AI Overviews specifically, 100-150 words per section is the sweet spot."
          },
          {
            "name": "Q&A Format Headings",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add H2/H3 headings phrased as questions your customers ask: 'How much does shipping cost?', 'What sizes are available?', 'How do I return an item?' Follow each with a direct, concise answer.",
            "whyMatters": "Q&A content format matches how people query AI assistants. Without question-format headings, your content is harder for AI to map to user queries."
          },
          {
            "name": "Internal Link Density",
            "value": "28 contextual internal links per 1,000 words — strong knowledge graph signal",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Canonical Tag for AI Deduplication",
            "value": "Canonical points to different URL: https://www.lunys.sk/",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Verify this canonical is intentional. AI models cluster near-duplicate URLs and choose one representative page. If canonical points to a different URL, AI will only index that target URL, not this page.",
            "whyMatters": "AI search engines (ChatGPT, Perplexity, Bing Copilot) use canonicals to deduplicate content. A wrong canonical means AI may cite the wrong page version or ignore this page entirely."
          },
          {
            "name": "Return Policy Schema",
            "status": "warning",
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Add MerchantReturnPolicy schema with: returnPolicyCategory (e.g., MerchantReturnFiniteReturnWindow), merchantReturnDays, returnMethod, returnFees. Link it from Product/Offer via hasMerchantReturnPolicy.",
            "whyMatters": "AI shopping agents (Google Shopping, ChatGPT, Bing Copilot) filter by return flexibility. Products with return policy schema get priority placement in AI product comparisons."
          },
          {
            "name": "Shipping Details Schema",
            "status": "warning",
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Add OfferShippingDetails schema with: shippingRate, shippingDestination, deliveryTime (handlingTime + transitTime). AI agents deprioritize products without shipping info.",
            "whyMatters": "Fulfillment speed now factors into AI product recommendations. Complete shipping schema means AI can show 'Free shipping, delivers in 2-3 days' — a massive conversion driver."
          },
          {
            "name": "Knowledge Graph Readiness",
            "value": "2/4 signals — missing: @id in JSON-LD, sameAs links (Wikipedia, LinkedIn)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add: @id in JSON-LD, sameAs links (Wikipedia, LinkedIn). Use @id in JSON-LD to create a unique node identifier. Ensure your brand name is identical in title, schema, and OG tags. Link to Wikipedia/Wikidata via sameAs.",
            "whyMatters": "Brands with verified Knowledge Graph presence receive 3.1x more AI citations. @id creates a persistent entity identifier that connects your schema across pages and platforms."
          },
          {
            "name": "Content Readability for AI",
            "value": "Grade 20 — too complex for broad AI citation (technical threshold: 14)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Simplify sentences (target 15-20 words average), use common words, break complex ideas into shorter paragraphs. AI extracts content for general audiences — if it's too academic, AI skips it.",
            "whyMatters": "Content above grade 12 readability is harder for AI to extract as clear, concise answers. Pages using clear headers and approachable language are 28% more likely to be cited by AI."
          },
          {
            "name": "Image Alt Text Quality for AI",
            "value": "Only 11% quality alt text — 217 missing, 54 poor",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Audit all images: add descriptive alt text (3-15 words) to every <img>. Include product names, features, materials, colors. This is critical for visual AI search and accessibility compliance.",
            "whyMatters": "Poor alt text means your product images are invisible to AI visual search (Google Lens, Bing Visual Search). This is also an accessibility requirement (WCAG 2.1 AA) — many regions enforce this legally."
          },
          {
            "name": "Expert Quotations & Citations",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add 2-3 expert quotes or data citations per major page. Use <blockquote> for quotes and link to authoritative sources (.gov, .edu, Wikipedia, industry reports).",
            "whyMatters": "Content without citations or expert quotes appears unverified to AI. AI assistants prefer content backed by named sources, data references, and expert opinions."
          },
          {
            "name": "ai.txt (AI Permissions)",
            "status": "warning",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Create /ai.txt or /.well-known/ai.txt to declare granular AI permissions per content type: which AI actions (summarization, training, extraction) are allowed for which content sections.",
            "whyMatters": "ai.txt is an emerging standard (proposed May 2025) for fine-grained AI permissions beyond robots.txt. Early adoption signals AI-forward thinking and gives you control over how AI uses your content."
          },
          {
            "name": "WebMCP Agentic Readiness",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "WebMCP (W3C Community Group standard, Chrome 146+) lets pages declare structured tools for AI agents. Add toolname and tooldescription attributes to <form> elements, or include a <script type='application/webmcp+json'> manifest.",
            "whyMatters": "WebMCP is called 'the new Schema.org moment' — it's how AI agents will interact with your store (search products, add to cart, check availability). Google and Microsoft are co-developing this standard."
          },
          {
            "name": "Content-to-Boilerplate Ratio",
            "value": "38% in main content area — too much boilerplate",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Move more content into <main> or <article> elements. Reduce navigation text, footer content, and sidebar noise. AI crawlers extract content from semantic containers and discard the rest.",
            "whyMatters": "AI crawlers specifically target <main> and <article> content blocks. If most of your text is in navigation, footers, and sidebars, AI gets noise instead of signal — reducing citation quality."
          },
          {
            "name": "Heureka Ověřeno Widget",
            "value": "Heureka trust widget detected",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "whyMatters": "Heureka Ověřeno is the dominant SK/CZ social-proof program — buyers trust it 2× more than generic ratings. Verified shops with a public obchody.heureka.* profile show stronger long-term provenance than just a widget script."
          },
          {
            "name": "Customer Reviews — Aggregate",
            "value": "1 source: Heureka Ověřeno",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Single review source detected without published reviewCount. Add AggregateRating JSON-LD (ratingValue + reviewCount + bestRating) so the count is machine-readable, and add a second source (Heureka Ověřeno + Trustpilot is the SK/CZ standard).",
            "whyMatters": "Without a second review source and a machine-readable reviewCount, AI assistants can't verify scale of social proof — single-source ratings are routinely deweighted as potentially curated."
          }
        ]
      },
      "phaseTimings": {
        "total": 4086,
        "phase1": 2541,
        "enrichment": 592,
        "sourceMaps": 0,
        "catalogDump": 0
      },
      "vulnerability": {
        "score": 65,
        "checks": [
          {
            "name": "CMS Version Disclosure",
            "value": "No generator tag — CMS identity hidden",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Sensitive Files Exposed",
            "value": ".env, .git, composer.json — all properly blocked",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "Install Script Exposed",
            "value": "No /install/ or /setup/ paths accessible",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "Directory Listing",
            "value": "Disabled — file structure hidden",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "Admin Panel at Default URL",
            "value": "Accessible at: /admin",
            "status": "fail",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Rename your admin directory to a random, non-guessable path (e.g., /admin-x7k9m2). Add IP whitelisting via .htaccess, implement 2FA, and set up brute-force protection (fail2ban or similar).",
            "whyMatters": "Default admin URLs receive thousands of automated brute-force attempts daily. Botnets target /admin, /wp-admin, /administrator relentlessly. A renamed path blocks 99% of automated attacks."
          },
          {
            "name": "Debug Mode / Error Exposure",
            "value": "No debug indicators found in page output",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Form CSRF Protection",
            "value": "31/32 forms have CSRF tokens",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Ensure ALL forms include a CSRF token. In PrestaShop, use {$csrf_token} in templates. In WordPress, use wp_nonce_field().",
            "confidence": "low",
            "whyMatters": "Forms without CSRF tokens allow cross-site request forgery — an attacker's site can submit orders, change settings, or modify data on behalf of your logged-in users."
          },
          {
            "name": "Inline JavaScript Exposure",
            "value": "52 KB of inline JavaScript",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Move inline scripts to external files. Inline JavaScript expands the attack surface for XSS and makes CSP harder to implement (requires unsafe-inline).",
            "confidence": "low",
            "whyMatters": "Large amounts of inline JavaScript prevent proper CSP implementation and increase the risk of XSS. External scripts can be protected with SRI hashes."
          },
          {
            "name": "SPF Record (Email Security)",
            "value": "SPF configured: v=spf1 ip4:185.59.208.196 ip4:5.178.48.82 ip4:213.151.240.75 ip4:185.25.248.40 i",
            "status": "pass",
            "evidence": {
              "source": "DNS"
            }
          },
          {
            "name": "DMARC Policy (Email Auth)",
            "value": "DMARC set to p=none (monitoring only, no enforcement)",
            "status": "warning",
            "evidence": {
              "source": "DNS"
            },
            "howToFix": "Upgrade DMARC policy from p=none to p=quarantine or p=reject. p=none only monitors — it doesn't block spoofed emails. Start with quarantine, then move to reject after verifying legitimate emails pass.",
            "whyMatters": "DMARC p=none provides zero protection against email spoofing. It only generates reports. Move to p=quarantine to actually block forged emails from reaching your customers' inboxes."
          },
          {
            "name": "DKIM Signing (Email Auth)",
            "value": "DKIM configured (selectors: k2, selector1, mail)",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "Cross-Origin Isolation",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Add Cross-Origin-Opener-Policy: same-origin and Cross-Origin-Resource-Policy: same-origin headers. These protect against Spectre-type side-channel attacks.",
            "whyMatters": "Without cross-origin isolation headers, your site is vulnerable to Spectre attacks that can leak sensitive data across browser tabs. These headers are required for SharedArrayBuffer and high-resolution timers."
          },
          {
            "name": "Inline Event Handlers",
            "value": "28 inline event handlers (onclick, onmouseover, etc.)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Move inline event handlers to external JavaScript files using addEventListener(). Inline handlers prevent proper CSP implementation (require 'unsafe-inline') and increase XSS attack surface.",
            "whyMatters": "Inline event handlers are a legacy pattern that prevents Content Security Policy enforcement. They also make XSS attacks easier — injected HTML attributes can execute JavaScript immediately."
          },
          {
            "name": "Login Form Security",
            "value": "Login form blocks password manager autofill",
            "status": "warning",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Remove autocomplete='off' from login forms. Password managers improve security by enabling unique, complex passwords per site.",
            "whyMatters": "NIST guidelines recommend allowing password autofill. Blocking it forces users to choose weak, memorable passwords — a leading cause of credential compromise."
          },
          {
            "name": "Payment Page Security",
            "value": "Payment page missing: No CSP",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get PCI Compliance Audit →"
            },
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "CRITICAL: Your payment page is missing security headers: No CSP. PCI DSS Requirement 6.5 mandates protection against common vulnerabilities on pages handling card data.",
            "whyMatters": "Payment pages without proper security headers violate PCI DSS. This can result in fines of $5,000-$100,000/month from payment processors, and makes card data theft significantly easier."
          }
        ]
      },
      "opendata_security": null
    },
    "created_at": "2026-07-02T13:03:32.005185+00:00",
    "status": "complete",
    "platform_detected": "Magento",
    "company_ico": null,
    "company_name": null,
    "company_country": null,
    "company_nace": null,
    "company_size": null,
    "nis2_scope": null,
    "nis2_sector": null,
    "company_risk_score": null,
    "company_risk_level": null
  }
}