{
  "data": {
    "slug": "f6265921",
    "url": "https://metronet.sk",
    "domain": "metronet.sk",
    "overall_score": 70,
    "scores_json": {
      "seo": {
        "score": 78,
        "checks": [
          {
            "name": "Meta Title",
            "value": "58 chars — \"Optický internet a TV nielen v Banskej Bystrici | Metro…\"",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Meta Description",
            "value": "116 chars (optimal: 120-160)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Expand your description to at least 120 characters. Include benefits, a CTA, and your target keyword.",
            "whyMatters": "Short descriptions waste SERP real estate and miss the chance to persuade searchers to click."
          },
          {
            "name": "H1 Heading",
            "value": "5 H1 tags (should be exactly 1)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Consolidate to exactly one H1 tag per page. Use H2-H6 for subheadings.",
            "whyMatters": "Multiple H1 tags dilute the main topic signal. Google's John Mueller confirmed: one H1 per page is best practice."
          },
          {
            "name": "Content Structure (H2 Headings)",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add H2 subheadings to structure your content. Each major section should have a descriptive H2.",
            "whyMatters": "Pages without heading structure have 30% lower time-on-page and miss long-tail ranking opportunities."
          },
          {
            "name": "Open Graph Tags",
            "value": "og:title, og:description, og:image, og:type",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Open Graph Image Format",
            "value": "image/webp",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Twitter/X Cards",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add <meta name='twitter:card' content='summary_large_image'>, twitter:title, and twitter:image tags.",
            "whyMatters": "Twitter Cards make your links stand out in X/Twitter feeds. Without them, shared links appear as plain text URLs."
          },
          {
            "name": "Canonical URL",
            "value": "https://www.metronet.sk/",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Structured Data (JSON-LD)",
            "value": "1 block(s): WebPage, ReadAction, ImageObject, BreadcrumbList",
            "status": "pass",
            "evidence": {
              "source": "schema"
            }
          },
          {
            "name": "JSON-LD Validity",
            "value": "1 block(s) parse cleanly",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "robots.txt",
            "value": "Present, references sitemap",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "XML Sitemap",
            "status": "fail",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Generate an XML sitemap at /sitemap.xml listing all important pages. Exclude noindex pages, filters, and duplicate URLs. Reference it in robots.txt.",
            "whyMatters": "Sitemaps help Google discover and index pages 3-5x faster, especially for large stores with deep category structures."
          },
          {
            "name": "HTML Language Attribute",
            "value": "lang=\"sk-SK\"",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Image Alt Attributes",
            "value": "97% of 208 images have alt text",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Meta Robots Tag",
            "value": "index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Text-to-HTML Ratio",
            "value": "6% ratio but 3422 words — content is substantial; the low ratio is markup/inline-JS bloat, not thin content",
            "status": "info",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Your text content is sufficient. To raise the ratio, move inline <script>/<style> to external files and trim template bloat — this is a performance/cleanliness win, not a content gap.",
            "whyMatters": "Text-to-HTML ratio is only a thin-content signal when actual word count is also low. With 500+ words, search engines have plenty to rank on."
          },
          {
            "name": "Favicon",
            "value": "Favicon detected",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "Image Format Optimization",
            "value": "Only 1% next-gen formats — 5 legacy images remain",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Convert remaining JPEG/PNG images to WebP (30-50% smaller) or AVIF (50-70% smaller). Use <picture> element for browser fallback.",
            "whyMatters": "WebP/AVIF images are 30-70% smaller than JPEG/PNG with the same quality. This directly improves page speed, LCP, and mobile experience."
          },
          {
            "name": "Semantic HTML Structure",
            "value": "4/6 semantic elements: <nav>, <main>, <header>, <footer>",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Canonical URL Consistency",
            "value": "Canonical points to different URL: https://www.metronet.sk/",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Your canonical URL doesn't match the current page URL. Ensure the canonical points to the preferred version (with or without trailing slash, www vs non-www). Inconsistent canonicals confuse search engines.",
            "whyMatters": "A mismatched canonical tells Google this page is a duplicate of another URL. If unintentional, Google may ignore this page entirely in favor of the canonical target."
          },
          {
            "name": "Content Depth",
            "value": "3422 words — sufficient content",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Internal Linking",
            "value": "Only 3 internal links",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add more internal links to related content. Target 5+ internal links per page for strong site crawlability.",
            "whyMatters": "Internal links help Google discover and rank your pages. Pages with more internal links receive higher PageRank and are crawled more frequently."
          },
          {
            "name": "Empty/Dead Links",
            "value": "9 dead links (0 empty, 9 hash-only, 0 javascript:void)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Replace empty href='', href='#', and href='javascript:void(0)' with actual URLs. If interactive, use <button> instead of <a>.",
            "whyMatters": "Dead links waste crawl budget and confuse search engines. They also create poor user experience — users click expecting navigation and nothing happens."
          },
          {
            "name": "Accessibility Fundamentals",
            "value": "3/4 a11y signals: 28 ARIA roles, 36 ARIA labels, lang=\"sk-SK\"",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Excessive Resource Requests",
            "value": "52 JS + 91 CSS = 143 external requests",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Reduce to under 30 external resources by bundling JS/CSS files, removing unused plugins, and consolidating third-party scripts.",
            "whyMatters": "Google's crawl budget is limited. Sites with excessive resources get crawled less frequently and experience slower indexation of new content."
          }
        ]
      },
      "gdpr": {
        "score": 89,
        "checks": [
          {
            "name": "Cookie Consent Banner (CMP)",
            "value": "Cookiebot detected",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7"
              ],
              "czLaw": [
                "§ 5"
              ],
              "skLaw": [
                "§ 14"
              ]
            }
          },
          {
            "name": "Tracking Scripts & Consent",
            "value": "2 tracker(s) detected with CMP: Google Analytics/GTM, Google Ads",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7",
                "EDPB Opinion 5/2019"
              ],
              "skLaw": [
                "§ 14"
              ]
            }
          },
          {
            "name": "Google Consent Mode v2",
            "value": "Consent mode signals detected (ad_storage, analytics_storage)",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7"
              ],
              "skLaw": [
                "§ 14"
              ]
            }
          },
          {
            "name": "Privacy Policy Page",
            "value": "https://www.metronet.sk/wp-content/plugins/complianz-gdpr/assets/css/c",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "legalRefs": {
              "gdpr": [
                "Art. 12",
                "Art. 13",
                "Art. 14"
              ],
              "czLaw": [
                "§ 8",
                "§ 9"
              ],
              "skLaw": [
                "§ 19",
                "§ 20"
              ]
            }
          },
          {
            "name": "Cookie Policy",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Create a separate cookie policy page listing every cookie by: name, provider, purpose, category (necessary/analytics/marketing), and expiration. Most CMPs auto-generate this.",
            "legalRefs": {
              "gdpr": [
                "Art. 12",
                "Art. 13(1)(c)-(e)"
              ],
              "czLaw": [
                "§ 8"
              ],
              "skLaw": [
                "§ 19"
              ]
            },
            "whyMatters": "The ePrivacy Directive requires transparent cookie disclosure. Vague statements like 'we use cookies for functionality' don't meet the specificity requirement."
          },
          {
            "name": "Legal Contact / Imprint Page",
            "value": "https://www.metronet.sk/o-nas/",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Terms & Conditions Page",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Create Terms & Conditions (AGB) covering: ordering process, payment, delivery, returns, warranty, and dispute resolution. Link it from the footer and checkout.",
            "whyMatters": "EU Consumer Rights Directive requires clear terms before purchase. Missing T&C means customers can claim they weren't informed, giving them extended cancellation rights."
          },
          {
            "name": "Data Encryption (No Mixed Content)",
            "value": "All resources loaded over HTTPS",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Third-party Data Sharing",
            "value": "4 third-party domain(s)",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Right to Erasure (Data Deletion)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Provide a clear mechanism for users to request data deletion — either a dedicated page, a form, or explicit instructions in your privacy policy. Include a 'Delete my account' option in user settings.",
            "legalRefs": {
              "gdpr": [
                "Art. 17"
              ],
              "czLaw": [
                "§ 10"
              ],
              "skLaw": [
                "§ 23"
              ]
            },
            "whyMatters": "GDPR Article 17 gives users the 'right to be forgotten.' EU regulators expect a clear, accessible process. Italian DPA fined companies €20M+ for obstructing erasure requests."
          },
          {
            "name": "Data Protection Officer Contact",
            "value": "DPO / data protection contact found",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Withdrawal of Consent Mechanism",
            "value": "Consent withdrawal / opt-out mechanism found",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "legalRefs": {
              "gdpr": [
                "Art. 7(3)"
              ],
              "skLaw": [
                "§ 14(4)"
              ]
            }
          }
        ]
      },
      "nis2": {
        "score": -1,
        "checks": [
          {
            "name": "NIS2 Compliance",
            "value": "Not in scope — your business is below NIS2 thresholds (Annex I/II sector + 50+ employees / €10M+ turnover).",
            "status": "info",
            "howToFix": "",
            "whyMatters": ""
          }
        ]
      },
      "mobile": {
        "score": 61,
        "checks": [
          {
            "name": "Viewport Configuration",
            "value": "width=device-width, initial-scale=1",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Mobile Performance Score",
            "value": "50/100 (target: 90+)",
            "status": "warning",
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "Optimize for mobile: compress images to WebP, defer non-critical JS, reduce CSS file size. Mobile CPUs are 3-5x slower than desktop — what's fast on desktop is slow on mobile.",
            "whyMatters": "Over 65% of e-commerce traffic is mobile (Statista 2024). Google ranks based on mobile performance, not desktop. Mobile score <50 means you're penalized in mobile search."
          },
          {
            "name": "Touch Target Size",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Ensure ALL interactive elements (buttons, links, form fields) are at least 48×48px with 8px minimum spacing between them. Pay special attention to: navigation menus, filter buttons, product variant selectors, and footer links.",
            "whyMatters": "Small tap targets cause 37% more mis-taps on mobile (Google UX research). In e-commerce, a mis-tap on 'Remove from cart' instead of 'Checkout' directly loses revenue."
          },
          {
            "name": "Font Size Readability",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Set minimum 16px font size for body text. Use relative units (rem/em) instead of px for scalability. Product titles: 18px+, prices: 20px+, CTAs: 16px+ with bold.",
            "whyMatters": "Text smaller than 16px forces mobile users to pinch-zoom. This breaks the responsive layout and creates a frustrating experience. Users over 40 are especially affected — and they have the highest purchasing power."
          },
          {
            "name": "Content Fits Viewport",
            "value": "No horizontal scrolling needed",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Responsive Design Techniques",
            "value": "Flexbox, CSS Grid, Media queries detected",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Theme Color",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add <meta name='theme-color' content='#your-brand-color'> to match your brand. Browsers use this to color the address bar, task switcher, and PWA chrome.",
            "whyMatters": "Theme-color creates a polished, branded mobile experience. It makes your site look native and professional — small detail, big perception impact."
          },
          {
            "name": "Mobile Navigation (Semantic)",
            "value": "<nav> element present — proper navigation landmark",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Inline CSS Size",
            "value": "59 KB of inline CSS",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Extract inline styles to external CSS files. Inline CSS larger than 50 KB increases HTML payload and cannot be cached separately. Keep only critical above-the-fold CSS inline.",
            "whyMatters": "Large inline CSS blocks increase initial HTML download and parsing time — especially painful on mobile with limited CPU and slower connections."
          },
          {
            "name": "Responsive Images (srcset)",
            "value": "1 image(s) use srcset for responsive sizing",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Apple Mobile Web App",
            "value": "Missing: apple-mobile-web-app-capable, status-bar-style",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add: <meta name='apple-mobile-web-app-capable' content='yes'>, <meta name='apple-mobile-web-app-status-bar-style' content='default'>, <link rel='apple-touch-icon' href='/icon-180.png'>.",
            "whyMatters": "These tags enable 'Add to Home Screen' on iOS with a full-screen experience. 45% of mobile shoppers use iOS — a polished home screen presence increases return visits."
          },
          {
            "name": "Form Input Types",
            "value": "Optimized: 1 email, 1 tel",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Fixed Width Elements",
            "value": "Large fixed-width elements detected — may cause horizontal scroll",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Replace fixed pixel widths with max-width: 100% or use relative units (%, vw). Add 'overflow-x: hidden' to body as a safety net.",
            "whyMatters": "Fixed-width elements wider than the viewport cause horizontal scrolling on mobile. Google's mobile-friendly test specifically checks for this."
          },
          {
            "name": "Form Input Labels (WCAG 3.3.2)",
            "value": "15/16 inputs má label (94%)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "1 input elementov nemá <label for=\"id\">, aria-label, aria-labelledby alebo title. Placeholder nie je dostatočný (WCAG 3.3.2). Pridaj <label for=\"email\">Email</label><input id=\"email\"> alebo <input aria-label=\"Email\">.",
            "whyMatters": "Formulárové inputy bez labelov sú nedostupné pre screen reader používateľov a zhoršujú konverziu aj pre bežných používateľov (neviditeľné placeholder texty, stratená informácia pri fokusovaní)."
          },
          {
            "name": "Heading Hierarchy (WCAG 1.3.1)",
            "value": "Preskočené úrovne: h1→h3, h3→h6, h3→h5",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Dodržuj poradie nadpisov h1 → h2 → h3 → h4 bez preskočenia. Screen readers používajú hierarchiu nadpisov na navigáciu. Ak potrebuješ menšie písmo ale rovnakú úroveň, použi CSS triedu, nie nižší heading tag.",
            "whyMatters": "Preskočené heading levely (napr. h1 priamo na h3) zlomia navigáciu pre screen reader používateľov a signalizujú Googlu zlú štruktúru dokumentu. Aj SEO je negatívne ovplyvnené."
          },
          {
            "name": "Link Text Quality (WCAG 2.4.4)",
            "value": "Všetky odkazy majú popisný text",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          }
        ]
      },
      "company": {
        "nis2": {
          "annex": 2,
          "sector": null,
          "category": "none",
          "in_scope": false,
          "priority_tier": null,
          "priority_score": null
        },
        "financials": {
          "year": 2025,
          "equity": 16318,
          "profit": 3191,
          "turnover": 44974
        },
        "percentile": {
          "metrics": {
            "equity": 25,
            "turnover": 20,
            "net_profit": 27,
            "credit_limit": 30,
            "credit_score": 78,
            "total_assets": 30,
            "debt_to_equity": 8,
            "employee_count": 77
          },
          "nace_section": "J",
          "peer_group_size": 44107
        },
        "in_insolvency": false,
        "credit_grade_full": "A+"
      },
      "modules": [
        "go_pricing",
        "Complianz GDPR (complianz-gdpr)",
        "forminator",
        "wp-review-slider-pro",
        "smart-slider-3",
        "Google Site Kit (google-site-kit)",
        "Popup Maker (popup-maker)",
        "visual-form-builder-pro",
        "wp-consent-api"
      ],
      "security": {
        "score": 65,
        "checks": [
          {
            "name": "SSL/TLS Certificate",
            "value": "Valid HTTPS connection established",
            "status": "pass",
            "evidence": {
              "source": "SSL"
            }
          },
          {
            "name": "DNSSEC",
            "value": "Zone is DNSSEC-signed (DNSKEY published)",
            "status": "pass",
            "evidence": {
              "source": "DNS"
            },
            "whyMatters": "DNSSEC protects against DNS cache poisoning and on-path attackers redirecting your domain. Required by some sector regulators for NIS2 essential/important entities."
          },
          {
            "name": "CAA DNS Record",
            "value": "No CAA records — any CA can issue certificates for this domain",
            "status": "warning",
            "evidence": {
              "source": "DNS"
            },
            "howToFix": "Publish CAA TXT records pinning your CA. For Let's Encrypt: `0 issue \"letsencrypt.org\"`. For multiple CAs add additional `0 issue \"...\"` records. Add `0 iodef \"mailto:security@yourdomain.tld\"` for misissuance reports.",
            "whyMatters": "CAA records limit which Certificate Authorities can issue certificates for your domain. Without CAA, a compromised or rogue CA can issue valid certs that browsers will trust — a documented breach pattern (DigiNotar 2011, Symantec 2017)."
          },
          {
            "name": "HTTP → HTTPS Redirect",
            "value": "HTTP properly redirects to HTTPS",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "name": "HSTS (Strict-Transport-Security)",
            "value": "max-age=63072000, preload, includeSubDomains",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "name": "Content-Security-Policy (CSP)",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Security Hardening →"
            },
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Implement a CSP header. Start with: Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: — then gradually tighten.",
            "whyMatters": "CSP is the most powerful defense against XSS attacks. Without it, any injected script runs with full privileges. CSP blocks inline script injection, the #1 web attack vector."
          },
          {
            "name": "Clickjacking Protection",
            "status": "fail",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Add X-Frame-Options: DENY (or SAMEORIGIN if iframes are needed). Better: use CSP frame-ancestors 'self'.",
            "whyMatters": "Clickjacking overlays your site in a hidden iframe. Attackers trick users into clicking buttons (like 'Confirm Purchase') without knowing it."
          },
          {
            "name": "X-Content-Type-Options",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Add header: X-Content-Type-Options: nosniff",
            "whyMatters": "Without nosniff, browsers may execute uploaded files as scripts. An attacker could upload a .jpg that's actually JavaScript and trick the browser into running it."
          },
          {
            "name": "Referrer-Policy",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Add header: Referrer-Policy: strict-origin-when-cross-origin — this is the best balance between functionality and privacy.",
            "whyMatters": "Without a referrer policy, browsers send the full URL to third parties. This can leak sensitive data like session tokens in URLs or internal page paths."
          },
          {
            "name": "Permissions-Policy",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Add: Permissions-Policy: camera=(), microphone=(), geolocation=(), payment=() — disable APIs your site doesn't need.",
            "whyMatters": "Without Permissions-Policy, any third-party script (ads, analytics, chat widgets) can access camera, microphone, and geolocation without your knowledge."
          },
          {
            "name": "Cookie Security Flags",
            "value": "No cookies set on initial response",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "name": "Technology Disclosure",
            "value": "X-Powered-By: PHP/8.3.31",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Hide server version: set ServerTokens Prod (Apache) or server_tokens off (Nginx). Remove X-Powered-By header completely.",
            "whyMatters": "Exposing exact server/PHP versions lets attackers search CVE databases for specific exploits. This is the first step in most automated attacks."
          },
          {
            "name": "Subresource Integrity (SRI)",
            "value": "Only 0/2 SRI-eligible third-party scripts have integrity hashes (2 auto-updating provider script(s) excluded — SRI not applicable)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add integrity='sha384-...' and crossorigin='anonymous' to version-pinned third-party <script> tags (use srihash.org). Auto-updating provider scripts (analytics, payment SDKs, consent tools) are correctly excluded — they can't use SRI.",
            "whyMatters": "Without SRI, if a version-pinned third-party CDN is compromised, attackers can inject malicious code into your site. The British Airways breach (£20M fine) was exactly this attack vector."
          },
          {
            "name": "security.txt (RFC 9116)",
            "status": "warning",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Create /.well-known/security.txt with Contact, Expires, and Preferred-Languages fields. See securitytxt.org for the generator.",
            "whyMatters": "security.txt lets ethical hackers report vulnerabilities responsibly. Without it, they may disclose publicly or not report at all. Required by ISO 27001 and SOC 2."
          },
          {
            "name": "Server Version Disclosure",
            "value": "openresty — version hidden",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "name": "CDN / WAF Protection",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Add a CDN/WAF like Cloudflare (free tier), Sucuri, or Fastly. They provide DDoS protection, bot filtering, and SSL management.",
            "whyMatters": "Without a CDN/WAF, your origin server is directly exposed to DDoS attacks, bot traffic, and brute-force attempts. Cloudflare blocks 150+ billion daily threats."
          },
          {
            "name": "Iframe Sandboxing",
            "value": "2/2 unknown iframe(s) without sandbox attribute",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add a sandbox attribute to non-provider <iframe> elements. Use sandbox='allow-scripts allow-same-origin' for third-party embeds. Trusted media/payment embeds (YouTube, Maps, Stripe, reCAPTCHA) are correctly excluded — they need full privileges to work.",
            "confidence": "low",
            "whyMatters": "Unsandboxed iframes from unknown sources can access your DOM, run scripts, and navigate the top window. They should be sandboxed to prevent clickjacking and XSS."
          }
        ]
      },
      "tech_stack": [
        {
          "eol": false,
          "name": "WordPress",
          "category": "cms",
          "outdated": false
        },
        {
          "name": "jQuery",
          "category": "js-library"
        },
        {
          "name": "Bootstrap",
          "category": "css-framework"
        },
        {
          "name": "Font Awesome",
          "category": "js-library"
        },
        {
          "name": "GSAP",
          "category": "js-library"
        },
        {
          "name": "Video.js",
          "category": "js-library"
        },
        {
          "name": "Lightbox2",
          "category": "js-library"
        },
        {
          "name": "Magnific Popup",
          "category": "js-library"
        },
        {
          "name": "reCAPTCHA",
          "category": "js-library"
        },
        {
          "name": "openresty",
          "category": "server"
        },
        {
          "eol": false,
          "name": "PHP",
          "version": "8.3.31",
          "category": "language",
          "outdated": false
        }
      ],
      "performance": {
        "score": 70,
        "checks": [
          {
            "name": "Server Response Time (TTFB)",
            "value": "89ms",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "name": "First Contentful Paint (FCP)",
            "value": "0.76s",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "name": "Largest Contentful Paint (LCP)",
            "value": "3.73s (good: <2.5s) — Core Web Vital",
            "status": "warning",
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "Optimize your largest element (usually hero image or product image): preload it with <link rel='preload'>, use WebP/AVIF format, set explicit width/height, and serve from CDN.",
            "whyMatters": "LCP is a Core Web Vital that directly impacts Google rankings. Sites failing LCP are demoted in search results. The #1 cause of slow LCP is unoptimized hero images."
          },
          {
            "name": "Total Blocking Time (TBT)",
            "value": "186ms",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "name": "Cumulative Layout Shift (CLS)",
            "value": "0.077 — Core Web Vital ✓",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "name": "Speed Index",
            "value": "2.86s",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "name": "Total Page Weight",
            "value": "3.6 MB, 140 requests — too heavy!",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Performance Optimization →"
            },
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "Critical: your page is over 3 MB. 1) Convert all images to WebP/AVIF, 2) Lazy load everything below the fold, 3) Remove unused plugins, 4) Combine and minify CSS/JS, 5) Enable brotli compression.",
            "whyMatters": "Pages over 3 MB take 12+ seconds on 3G. The average e-commerce page is 2.2 MB — you're well above that. Amazon found every 100ms of latency costs 1% of sales."
          },
          {
            "name": "Render-blocking Resources",
            "value": "Not measured — PageSpeed did not return the render-blocking audit for this URL",
            "status": "info",
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "Re-run the scan, or test directly at PageSpeed Insights. This metric needs a successful Lighthouse lab run."
          },
          {
            "name": "Unused Code (CSS + JS)",
            "value": "180 KB unused (CSS: 45 KB, JS: 135 KB)",
            "status": "warning",
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "Remove unused CSS with PurgeCSS or UnCSS. Code-split JavaScript so only needed code loads per page. Audit plugins — each adds CSS/JS.",
            "whyMatters": "Unused code is downloaded and parsed but never executed — pure waste. Removing it speeds up parse time and reduces bandwidth."
          },
          {
            "name": "Text Compression (gzip/brotli)",
            "value": "All text resources properly compressed",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "name": "Resource Hints (Preload/Preconnect)",
            "value": "1 preload, 0 preconnect hint(s)",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Lazy Loading",
            "value": "49% of images use native lazy loading (102/208)",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Font Loading Strategy",
            "value": "font-display: auto",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Use font-display: swap (shows fallback immediately, swaps when loaded) or font-display: optional (best for performance — may skip custom font on slow connections).",
            "whyMatters": "font-display: block hides text until the font loads (FOIT) — users see a blank page. 'swap' shows text immediately with a fallback font."
          },
          {
            "name": "Script Loading Strategy",
            "value": "Only 40% of 52 scripts use async/defer",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add 'defer' to scripts that don't need to run immediately, 'async' for independent scripts. Use type='module' for modern ES modules. Only critical inline scripts should be synchronous.",
            "whyMatters": "Synchronous scripts block HTML parsing — the browser stops rendering until each script downloads and executes. Async/defer allows parallel downloading without blocking."
          },
          {
            "name": "CSS File Count",
            "value": "91 CSS files — too many!",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Bundle your CSS files into 1-3 files maximum. Use a build tool (Webpack, Vite, Gulp) to concatenate and minify. Critical CSS should be inlined, the rest deferred.",
            "whyMatters": "Each CSS file blocks rendering. With 91 files, the browser must download all of them before painting anything. This can add 1-2+ seconds on mobile networks."
          },
          {
            "name": "Font Preloading",
            "value": "Custom fonts detected without preload hints",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Preload your primary font: <link rel='preload' href='/fonts/main.woff2' as='font' type='font/woff2' crossorigin>. For Google Fonts: preconnect to fonts.gstatic.com.",
            "whyMatters": "Fonts are discovered late in the render pipeline (after CSS is parsed). Preloading tells the browser to download them immediately, reducing Flash of Invisible Text (FOIT) by 200-500ms."
          },
          {
            "name": "Critical CSS Strategy",
            "value": "91 CSS files without critical CSS extraction",
            "status": "warning",
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "Extract critical above-the-fold CSS and inline it in <head>. Load remaining CSS asynchronously: <link rel='preload' href='styles.css' as='style' onload='this.rel=\"stylesheet\"'>.",
            "whyMatters": "Render-blocking CSS delays first paint. Inlining critical CSS eliminates the render-blocking round trip — the biggest FCP improvement for CSS-heavy sites."
          },
          {
            "name": "Connection Hint Coverage",
            "value": "4 external domains without preconnect",
            "status": "warning",
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "Add <link rel='preconnect'> for key third-party domains: cdnjs.cloudflare.com, www.googletagmanager.com, t.contentsquare.net. Preconnect saves 100-300ms per domain by starting DNS+TCP+TLS early.",
            "whyMatters": "Third-party connections require DNS lookup, TCP handshake, and TLS negotiation. Preconnect performs these in parallel with HTML parsing, saving 100-300ms per origin."
          }
        ]
      },
      "ai_readiness": {
        "score": 63,
        "checks": [
          {
            "name": "AI Bot Access Policy",
            "value": "No AI bot restrictions (allowed by default)",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "llms.txt (AI Site Descriptor)",
            "status": "fail",
            "fixLink": {
              "url": "https://llmstxt.org",
              "label": "Learn about llms.txt →"
            },
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Create /llms.txt in Markdown format:\n# Your Store Name\n> One-line summary of your business and key offerings.\n\nDetailed description paragraph.\n\n## Products\n- [Product Category](URL): Description\n\n## About\n- [About Us](URL): Company history and values\n\nSee llmstxt.org for the full specification.",
            "whyMatters": "llms.txt is the emerging standard for AI-readable site descriptions — like robots.txt was for search engines. Early adopters (Yoast, Cloudflare, Stripe) are already using it. Without it, AI assistants have no guided overview of your store."
          },
          {
            "name": "llms-full.txt (Complete AI Content)",
            "status": "warning",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Create /llms-full.txt containing your complete site documentation in a single Markdown file — product catalog summaries, FAQs, policies, brand story. This gives AI models maximum context about your store.",
            "whyMatters": "llms-full.txt provides AI models with your entire site content in one parseable file. It's the difference between an AI having a brief overview vs. deep knowledge of your products and services."
          },
          {
            "name": "Content Accessibility for AI",
            "value": "3422 words in raw HTML (5.8% text ratio) — readable by AI crawlers without executing JS",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Structured Data Foundation",
            "value": "1 JSON-LD blocks with 10 schema types: WebPage, ReadAction, ImageObject, BreadcrumbList, ListItem, WebSite",
            "status": "pass",
            "evidence": {
              "source": "schema"
            }
          },
          {
            "name": "Organization Schema + Entity Linking",
            "value": "Organization schema found but no sameAs links",
            "status": "warning",
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Add sameAs array to your Organization schema linking to Wikipedia, LinkedIn, Facebook, Instagram, and other official profiles. This creates a Knowledge Graph entity for your brand.",
            "whyMatters": "sameAs links tell AI: 'This is the same entity across the web.' Sites with sameAs to Wikipedia are 3x more likely to appear in AI-generated answers. It's how Google builds Knowledge Panels."
          },
          {
            "name": "FAQ Schema (Direct AI Answers)",
            "status": "warning",
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Add FAQPage schema to every product page and category page. Include 3-5 Q&As per page covering: product specifications, shipping, returns, usage instructions. Format: question (full sentence) + answer (75-150 words).",
            "whyMatters": "FAQ schema provides 30% higher AI citation rates (LLMClicks research). ChatGPT, Perplexity, and Google AI Overviews pull FAQ answers verbatim. It's the fastest way to get your content cited by AI."
          },
          {
            "name": "Breadcrumb Schema",
            "value": "BreadcrumbList structured data found — clear navigation hierarchy",
            "status": "pass",
            "evidence": {
              "source": "schema"
            }
          },
          {
            "name": "Site Search Schema (SearchAction)",
            "value": "WebSite SearchAction configured — AI can search your store",
            "status": "pass",
            "evidence": {
              "source": "schema"
            }
          },
          {
            "name": "Content Depth for AI",
            "value": "3422 words — rich content for AI analysis and citation",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Answer-First Content Format",
            "value": "First paragraph: 53 words — good content density above the fold",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Heading Hierarchy for AI",
            "value": "5 H1, 0 H2, 18 H3 — poor structure",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Use exactly 1 H1 (page title), then organize content with H2 sections and H3 subsections. Each heading should describe the content that follows. Never skip heading levels (H1→H3 without H2).",
            "whyMatters": "AI extracts information based on heading structure. Pages with proper H1→H2→H3 hierarchy are more accurately parsed by ChatGPT, Perplexity, and Google AI Overviews. Without it, AI may misinterpret your content."
          },
          {
            "name": "Semantic HTML Structure",
            "value": "4/6 semantic elements: <nav>, <main>, <header>, <footer>",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Structured Content (Lists & Tables)",
            "value": "11 lists found — consider adding comparison tables",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add comparison tables to your content. Use <ul>/<ol> for feature lists, specifications, and benefits. Use <table> for product comparisons, pricing tiers, and specifications. AI extracts structured content exponentially faster than paragraphs.",
            "whyMatters": "AI models are biased toward extracting data from HTML lists and tables. Perplexity and ChatGPT pull bullet points and table data with much higher accuracy than paragraph text. Structured content = more AI citations."
          },
          {
            "name": "Content Freshness Signals",
            "value": "Schema dates found but no visible date on page",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add both: 1) dateModified and datePublished in your Article/Product JSON-LD schema, 2) A visible 'Last updated: [date]' on the page. Both signals reinforce content freshness for AI.",
            "whyMatters": "76.4% of ChatGPT's top 1000 cited pages were updated within 30 days. AI-cited content is 25.7% fresher than traditional organic results. Freshness signals tell AI your content is current and reliable."
          },
          {
            "name": "Entity Clarity & Brand Signals",
            "value": "OG tags complete but no sameAs entity links",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "For full entity clarity: 1) Complete Open Graph tags (og:title, og:description, og:image, og:type), 2) Add sameAs in Organization schema linking to Wikipedia, LinkedIn, Facebook, and other profiles.",
            "whyMatters": "AI needs to confidently identify your brand entity. Open Graph + sameAs create a cross-platform identity that AI models recognize. The HubSpot AEO Grader found entity clarity is a top-3 factor for AI brand recognition."
          },
          {
            "name": "Author Expertise Signals (E-E-A-T)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "For content pages (blog, guides, about): add Article/BlogPosting schema with author property linking to Person schema. Include the author's jobTitle, credentials, and social profiles.",
            "whyMatters": "AI models weight author expertise heavily. Pages from identified experts get cited 3x more than anonymous content. This is especially important for product guides, reviews, and advice content."
          },
          {
            "name": "Extractable Answer Blocks",
            "value": "20 paragraphs, avg 36 words — optimal for AI extraction",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Statistics & Data Presence",
            "value": "4 data points found — strong citation magnet",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Section Length Optimization",
            "value": "Avg section: 224 words — only 0% in 80-200 word optimal range",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Restructure content into sections of 120-180 words between H2/H3 headings. Each section should cover one topic completely. Split sections over 300 words, expand sections under 80 words.",
            "whyMatters": "Pages with 120-180 word sections earn 70% more AI citations (Otterly Citation Economy 2026). For Google AI Overviews specifically, 100-150 words per section is the sweet spot."
          },
          {
            "name": "Q&A Format Headings",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add H2/H3 headings phrased as questions your customers ask: 'How much does shipping cost?', 'What sizes are available?', 'How do I return an item?' Follow each with a direct, concise answer.",
            "whyMatters": "Q&A content format matches how people query AI assistants. Without question-format headings, your content is harder for AI to map to user queries."
          },
          {
            "name": "Internal Link Density",
            "value": "only 1/1000w (target: 3-5)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add 3-5 contextual internal links per 1,000 words using descriptive anchor text. Link to related products, categories, and guides. Replace generic anchors ('click here', 'read more') with descriptive text.",
            "whyMatters": "Internal links create an implicit knowledge graph for AI crawlers. Each contextual link teaches AI about content relationships. AI models navigate internal links to build comprehensive understanding of your store."
          },
          {
            "name": "Canonical Tag for AI Deduplication",
            "value": "Canonical points to different URL: https://www.metronet.sk/",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Verify this canonical is intentional. AI models cluster near-duplicate URLs and choose one representative page. If canonical points to a different URL, AI will only index that target URL, not this page.",
            "whyMatters": "AI search engines (ChatGPT, Perplexity, Bing Copilot) use canonicals to deduplicate content. A wrong canonical means AI may cite the wrong page version or ignore this page entirely."
          },
          {
            "name": "Knowledge Graph Readiness",
            "value": "3/4 entity signals — strong Knowledge Graph presence",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "Content Readability for AI",
            "value": "Grade 18 — too complex for broad AI citation (technical threshold: 14)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Simplify sentences (target 15-20 words average), use common words, break complex ideas into shorter paragraphs. AI extracts content for general audiences — if it's too academic, AI skips it.",
            "whyMatters": "Content above grade 12 readability is harder for AI to extract as clear, concise answers. Pages using clear headers and approachable language are 28% more likely to be cited by AI."
          },
          {
            "name": "Image Alt Text Quality for AI",
            "value": "Only 47% quality alt text — 6 missing, 104 poor",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Audit all images: add descriptive alt text (3-15 words) to every <img>. Include product names, features, materials, colors. This is critical for visual AI search and accessibility compliance.",
            "whyMatters": "Poor alt text means your product images are invisible to AI visual search (Google Lens, Bing Visual Search). This is also an accessibility requirement (WCAG 2.1 AA) — many regions enforce this legally."
          },
          {
            "name": "Expert Quotations & Citations",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add 2-3 expert quotes or data citations per major page. Use <blockquote> for quotes and link to authoritative sources (.gov, .edu, Wikipedia, industry reports).",
            "whyMatters": "Content without citations or expert quotes appears unverified to AI. AI assistants prefer content backed by named sources, data references, and expert opinions."
          },
          {
            "name": "ai.txt (AI Permissions)",
            "status": "warning",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Create /ai.txt or /.well-known/ai.txt to declare granular AI permissions per content type: which AI actions (summarization, training, extraction) are allowed for which content sections.",
            "whyMatters": "ai.txt is an emerging standard (proposed May 2025) for fine-grained AI permissions beyond robots.txt. Early adoption signals AI-forward thinking and gives you control over how AI uses your content."
          },
          {
            "name": "WebMCP Agentic Readiness",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "WebMCP (W3C Community Group standard, Chrome 146+) lets pages declare structured tools for AI agents. Add toolname and tooldescription attributes to <form> elements, or include a <script type='application/webmcp+json'> manifest.",
            "whyMatters": "WebMCP is called 'the new Schema.org moment' — it's how AI agents will interact with your store (search products, add to cart, check availability). Google and Microsoft are co-developing this standard."
          },
          {
            "name": "Content-to-Boilerplate Ratio",
            "value": "Only 2% in main content — mostly boilerplate",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Wrap your primary content in <main> or <article> tags. AI extracts content from these semantic containers — without them, your product descriptions are mixed with navigation and footer text.",
            "whyMatters": "Token density measures useful content vs noise. Pages with <30% content ratio are scored 'not machine-readable' by tools like LLMClicks. AI literally can't find your content in the boilerplate."
          },
          {
            "name": "Social Proof (Testimonials / Case Studies)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add at least one form of social proof: 1) Client testimonials as <blockquote> with attribution, 2) Case study / portfolio section with past work, 3) 'Trusted by' client logo strip. For B2B, this is the #1 credibility lever.",
            "whyMatters": "Without visible social proof, B2B prospects can't verify your track record before reaching out. Missing testimonials/case studies is the #1 reason consultancy sites lose qualified leads at the contact stage."
          }
        ]
      },
      "phaseTimings": {
        "total": 18449,
        "phase1": 9079,
        "enrichment": 435,
        "sourceMaps": 545,
        "catalogDump": 1,
        "gdprCitations": 2502
      },
      "vulnerability": {
        "score": 55,
        "checks": [
          {
            "name": "CMS Version Disclosure",
            "value": "\"Site Kit by Google 1.181.0\" exposed in meta generator",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Security Hardening →"
            },
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Remove the meta generator tag entirely. In PrestaShop: remove from header.tpl. In WordPress: add remove_action('wp_head', 'wp_generator') to functions.php.",
            "whyMatters": "Knowing your exact CMS version lets attackers search CVE databases instantly. E.g., PrestaShop 1.7.8.x is associated with known SQL injection CVEs. Hiding the version forces attackers to guess."
          },
          {
            "name": "Sensitive Files Exposed",
            "value": ".env, .git, composer.json — all properly blocked",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "Install Script Exposed",
            "value": "No /install/ or /setup/ paths accessible",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "Directory Listing",
            "value": "Disabled — file structure hidden",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "Admin Panel at Default URL",
            "value": "Not found at common paths (/admin, /wp-admin, /administrator, /backoffice)",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "Debug Mode / Error Exposure",
            "value": "No debug indicators found in page output",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "name": "CMS Information Files",
            "value": "readme.html accessible — reveals version details",
            "status": "warning",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Delete or block access to readme.html. These files reveal your exact CMS version and update history.",
            "whyMatters": "Even if you hide the generator tag, readme.html and CHANGELOG.txt reveal exact version numbers. Attackers check these as a fallback."
          },
          {
            "name": "Form CSRF Protection",
            "value": "1/2 forms have CSRF tokens",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Ensure ALL forms include a CSRF token. In PrestaShop, use {$csrf_token} in templates. In WordPress, use wp_nonce_field().",
            "confidence": "low",
            "whyMatters": "Forms without CSRF tokens allow cross-site request forgery — an attacker's site can submit orders, change settings, or modify data on behalf of your logged-in users."
          },
          {
            "name": "X-Powered-By Header",
            "value": "PHP/8.3.31",
            "status": "warning",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Remove the X-Powered-By header. PHP: add 'expose_php = Off' to php.ini. Express.js: app.disable('x-powered-by').",
            "whyMatters": "\"PHP/8.3.31\" reveals your server technology and version. Attackers use this to find matching CVEs."
          },
          {
            "name": "PHP Version",
            "value": "PHP 8.3.31 — current",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "Suspicious Inline Script Patterns",
            "value": "Detected: Dynamic script injection",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Malware Scan →"
            },
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Review all inline scripts for obfuscated code. Magecart attackers inject payment skimmers disguised as analytics or GTM scripts. Compare your current HTML with a known-good version. Consider using CSP with strict nonces.",
            "whyMatters": "These patterns (Base64 decode, eval with encoding, dynamic script injection) are hallmarks of Magecart payment skimmers. The 2024 Akamai report found skimmers disguised as Google Tag Manager on thousands of e-commerce sites."
          },
          {
            "name": "Source Maps Exposed",
            "value": "JavaScript source maps (.js.map) are publicly accessible",
            "status": "warning",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Remove source maps from production or block access via server config. In Vite/Webpack: set sourcemap: false for production builds.",
            "whyMatters": "Source maps reveal your original source code, variable names, comments, and application logic. Attackers use this to find vulnerabilities, API keys in code, and understand your authentication flow."
          },
          {
            "name": "SPF Record (Email Security)",
            "value": "SPF configured: v=spf1 ip4:95.47.178.165/32 ip4:92.245.31.66 include:amazonses.com include:_spf.",
            "status": "pass",
            "evidence": {
              "source": "DNS"
            }
          },
          {
            "name": "DMARC Policy (Email Auth)",
            "value": "DMARC set to p=none (monitoring only, no enforcement)",
            "status": "warning",
            "evidence": {
              "source": "DNS"
            },
            "howToFix": "Upgrade DMARC policy from p=none to p=quarantine or p=reject. p=none only monitors — it doesn't block spoofed emails. Start with quarantine, then move to reject after verifying legitimate emails pass.",
            "whyMatters": "DMARC p=none provides zero protection against email spoofing. It only generates reports. Move to p=quarantine to actually block forged emails from reaching your customers' inboxes."
          },
          {
            "name": "DKIM Signing (Email Auth)",
            "value": "DKIM configured (selectors: google, s1, mail)",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "name": "Cross-Origin Isolation",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Add Cross-Origin-Opener-Policy: same-origin and Cross-Origin-Resource-Policy: same-origin headers. These protect against Spectre-type side-channel attacks.",
            "whyMatters": "Without cross-origin isolation headers, your site is vulnerable to Spectre attacks that can leak sensitive data across browser tabs. These headers are required for SharedArrayBuffer and high-resolution timers."
          },
          {
            "name": "Payment Page Security",
            "value": "Payment page missing: No CSP, No X-Content-Type-Options, No clickjacking protection",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get PCI Compliance Audit →"
            },
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "CRITICAL: Your payment page is missing security headers: No CSP, No X-Content-Type-Options, No clickjacking protection. PCI DSS Requirement 6.5 mandates protection against common vulnerabilities on pages handling card data.",
            "whyMatters": "Payment pages without proper security headers violate PCI DSS. This can result in fines of $5,000-$100,000/month from payment processors, and makes card data theft significantly easier."
          },
          {
            "name": "CDN Script Integrity (SRI)",
            "value": "1 CDN script(s) without Subresource Integrity",
            "status": "warning",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Add integrity='sha384-...' crossorigin='anonymous' to CDN scripts from: cdnjs.cloudflare.com. Generate hashes at srihash.org.",
            "whyMatters": "CDN scripts without SRI can be tampered with if the CDN is compromised. The polyfill.io attack (2024, 380K+ sites) and British Airways breach (£20M fine) were both CDN supply chain attacks."
          },
          {
            "name": "Clickjacking on Sensitive Page",
            "value": "Login/payment page without X-Frame-Options or CSP frame-ancestors",
            "status": "fail",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "URGENT: Add X-Frame-Options: DENY and CSP frame-ancestors 'none' to pages with login forms or payment fields. Attackers can overlay your page in a transparent iframe.",
            "whyMatters": "Clickjacking on payment/login pages is a high-severity vulnerability. Users unknowingly submit credentials or payments through invisible iframes. PCI DSS requires frame-busting on payment pages."
          },
          {
            "name": "Server Error Leak",
            "value": "PHP/server error messages visible in page output",
            "status": "fail",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Set display_errors=Off in php.ini and log_errors=On. Configure a custom error page. Never show stack traces, SQL errors, or file paths to users.",
            "whyMatters": "Error messages reveal file paths, database structure, table names, and query logic. This is a goldmine for attackers — it turns a blind SQL injection into a targeted one, reducing attack time from days to minutes."
          }
        ]
      },
      "opendata_security": null
    },
    "created_at": "2026-06-23T09:47:41.458333+00:00",
    "status": "complete",
    "platform_detected": "WordPress",
    "company_ico": "46767061",
    "company_name": "Metronet, s.r.o.",
    "company_country": "SK",
    "company_nace": "6290",
    "company_size": "micro",
    "nis2_scope": "none",
    "nis2_sector": null,
    "company_risk_score": 15,
    "company_risk_level": "low"
  }
}