{
  "data": {
    "slug": "b95321c5",
    "url": "https://www.muziker.sk",
    "domain": "muziker.sk",
    "overall_score": 67,
    "scores_json": {
      "seo": {
        "score": 79,
        "checks": [
          {
            "name": "Meta Title",
            "value": "24 chars (optimal: 30-60)",
            "status": "warning",
            "howToFix": "Your title is very short. Add descriptive keywords and your brand name for better ranking signals.",
            "whyMatters": "Short titles waste valuable ranking real estate in search results."
          },
          {
            "name": "Meta Description",
            "value": "147 chars",
            "status": "pass"
          },
          {
            "name": "H1 Heading",
            "status": "fail",
            "howToFix": "Add exactly one H1 tag containing your primary keyword. It should be the most prominent heading on the page.",
            "whyMatters": "The H1 is the primary content signal for search engines. Pages without H1 rank significantly lower for target keywords."
          },
          {
            "name": "Content Structure (H2 Headings)",
            "value": "37 H2 subheadings found",
            "status": "pass"
          },
          {
            "name": "Open Graph Tags",
            "value": "og:description, og:image, og:type",
            "status": "pass"
          },
          {
            "name": "Open Graph Image Format",
            "value": "image/png",
            "status": "pass"
          },
          {
            "name": "Twitter/X Cards",
            "value": "Card type: summary_large_image",
            "status": "pass"
          },
          {
            "name": "Canonical URL",
            "value": "og:url present (https://www.muziker.sk/) but <link rel=canonical> missing",
            "status": "warning",
            "howToFix": "Add <link rel='canonical' href='https://www.muziker.sk/'> to <head>. og:url covers social sharing; canonical covers Google + AI crawlers explicitly.",
            "whyMatters": "og:url helps social platforms but Google officially ranks the canonical tag higher. With both present, you avoid any duplicate-content ambiguity."
          },
          {
            "name": "Structured Data (JSON-LD)",
            "value": "1 block(s): Organization, PostalAddress, ImageObject, WebSite",
            "status": "pass"
          },
          {
            "name": "robots.txt",
            "value": "Present, references sitemap",
            "status": "pass"
          },
          {
            "name": "XML Sitemap",
            "value": "Found with ~9+ URLs",
            "status": "pass"
          },
          {
            "name": "HTML Language Attribute",
            "value": "lang=\"sk-SK\"",
            "status": "pass"
          },
          {
            "name": "Hreflang Tags (Multilingual)",
            "value": "36 language(s): en-AL, de-AT, sr-BA, nl-BE, bg",
            "status": "pass"
          },
          {
            "name": "Image Alt Attributes",
            "value": "Only 58% of 183 images have alt text",
            "status": "warning",
            "howToFix": "77 images are missing alt attributes. Add descriptive, keyword-rich alt text to every image.",
            "whyMatters": "Missing alt text means zero visibility in Google Image Search (which drives 20%+ of total search traffic for e-commerce)."
          },
          {
            "name": "Text-to-HTML Ratio",
            "value": "5% — low content density (4411 words)",
            "status": "warning",
            "howToFix": "Add more unique text content. Write detailed product descriptions, buying guides, and FAQ sections.",
            "whyMatters": "Low text-to-HTML ratio signals thin content to Google. Pages with more useful text rank higher and convert better."
          },
          {
            "name": "Favicon",
            "value": "Favicon detected",
            "status": "pass"
          },
          {
            "name": "Image Format Optimization",
            "value": "0% next-gen formats — 59 JPEG, 27 PNG images",
            "status": "warning",
            "howToFix": "Convert all images to WebP format. Most CMS platforms have plugins for automatic WebP conversion. Use AVIF for even better compression.",
            "whyMatters": "Your images are using legacy formats only. Switching to WebP typically reduces page weight by 30-50% — one of the highest-impact performance optimizations."
          },
          {
            "name": "Semantic HTML Structure",
            "value": "4/6 semantic elements: <nav>, <main>, <header>, <footer>",
            "status": "pass"
          },
          {
            "name": "Content Depth",
            "value": "4411 words — sufficient content",
            "status": "pass"
          },
          {
            "name": "Deep Heading Hierarchy",
            "value": "H2: 37, H3: 3 — well-structured content",
            "status": "pass"
          },
          {
            "name": "Internal Linking",
            "value": "100 internal links — strong site navigation",
            "status": "pass"
          },
          {
            "name": "Accessibility Fundamentals",
            "value": "3/4 a11y signals: 2823 ARIA roles, 474 ARIA labels, lang=\"sk-SK\"",
            "status": "pass"
          },
          {
            "name": "Color Contrast Signal",
            "value": "15 very light text colors found — potential contrast issues",
            "status": "warning",
            "howToFix": "Ensure text has minimum 4.5:1 contrast ratio against background (WCAG AA). Use tools like WebAIM Contrast Checker. Light gray text on white is the most common violation.",
            "whyMatters": "Low contrast text is the #1 accessibility issue found on 83.6% of home pages (WebAIM Million 2024). It affects 8% of men with color vision deficiency and everyone in bright sunlight."
          }
        ]
      },
      "gdpr": {
        "score": 67,
        "checks": [
          {
            "name": "Cookie Consent Banner (CMP)",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get GDPR Compliance →"
            },
            "howToFix": "Install a certified consent management platform: Cookiebot, OneTrust, Usercentrics, or CookieYes. The CMP must block ALL non-essential cookies and scripts until explicit consent is given (opt-in, not opt-out).",
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7"
              ],
              "czLaw": [
                "§ 5"
              ],
              "skLaw": [
                "§ 14"
              ]
            },
            "whyMatters": "Since 2024, EU regulators actively enforce cookie consent. CNIL fined Google €150M and Amazon €35M for non-compliant cookie banners. Fines can reach 4% of global annual revenue."
          },
          {
            "name": "Tracking Scripts & Consent",
            "value": "No tracking scripts detected",
            "status": "pass",
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7",
                "EDPB Opinion 5/2019"
              ],
              "skLaw": [
                "§ 14"
              ]
            }
          },
          {
            "name": "Privacy Policy Page",
            "value": "/ochrana-osobnych-udajov",
            "status": "pass",
            "legalRefs": {
              "gdpr": [
                "Art. 12",
                "Art. 13",
                "Art. 14"
              ],
              "czLaw": [
                "§ 8",
                "§ 9"
              ],
              "skLaw": [
                "§ 19",
                "§ 20"
              ]
            }
          },
          {
            "name": "Cookie Policy",
            "status": "warning",
            "howToFix": "Create a separate cookie policy page listing every cookie by: name, provider, purpose, category (necessary/analytics/marketing), and expiration. Most CMPs auto-generate this.",
            "legalRefs": {
              "gdpr": [
                "Art. 12",
                "Art. 13(1)(c)-(e)"
              ],
              "czLaw": [
                "§ 8"
              ],
              "skLaw": [
                "§ 19"
              ]
            },
            "whyMatters": "The ePrivacy Directive requires transparent cookie disclosure. Vague statements like 'we use cookies for functionality' don't meet the specificity requirement."
          },
          {
            "name": "Legal Contact / Imprint Page",
            "value": "/o-nas",
            "status": "pass"
          },
          {
            "name": "Terms & Conditions Page",
            "value": "/vseobecne-obchodne-podmienky",
            "status": "pass"
          },
          {
            "name": "Data Encryption (No Mixed Content)",
            "value": "All resources loaded over HTTPS",
            "status": "pass"
          },
          {
            "name": "Third-party Data Sharing",
            "value": "2 third-party domain(s)",
            "status": "pass"
          },
          {
            "name": "Personal Data Exposure in Source",
            "value": "1 email(s) found in page source: meno@domena.sk",
            "status": "warning",
            "howToFix": "Remove plain-text email addresses from HTML source. Use contact forms instead, or obfuscate emails with JavaScript encoding.",
            "legalRefs": {
              "gdpr": [
                "Art. 5(1)(f)",
                "Art. 32",
                "Art. 33"
              ],
              "czLaw": [
                "§ 13",
                "§ 14"
              ],
              "skLaw": [
                "§ 39",
                "§ 40"
              ]
            },
            "whyMatters": "Exposing personal email addresses in HTML violates the data minimization principle (GDPR Art. 5). It also invites spam harvesting."
          },
          {
            "name": "Right to Erasure (Data Deletion)",
            "status": "warning",
            "howToFix": "Provide a clear mechanism for users to request data deletion — either a dedicated page, a form, or explicit instructions in your privacy policy. Include a 'Delete my account' option in user settings.",
            "legalRefs": {
              "gdpr": [
                "Art. 17"
              ],
              "czLaw": [
                "§ 10"
              ],
              "skLaw": [
                "§ 23"
              ]
            },
            "whyMatters": "GDPR Article 17 gives users the 'right to be forgotten.' EU regulators expect a clear, accessible process. Italian DPA fined companies €20M+ for obstructing erasure requests."
          },
          {
            "name": "Newsletter Consent",
            "value": "Newsletter signup found without visible consent checkbox",
            "status": "warning",
            "howToFix": "Add an unchecked consent checkbox to your newsletter form: 'I agree to receive marketing emails and have read the Privacy Policy [link].' Pre-checked boxes are not valid consent under GDPR.",
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7",
                "ePrivacy Art. 13"
              ],
              "skLaw": [
                "§ 14",
                "§ 116 zák. 452/2021"
              ]
            },
            "whyMatters": "GDPR requires 'freely given, specific, informed' consent for marketing emails. A newsletter form without explicit opt-in violates Article 7. Italian DPA fined companies for pre-checked newsletter boxes."
          },
          {
            "name": "Data Protection Officer Contact",
            "value": "DPO / data protection contact found",
            "status": "pass"
          },
          {
            "name": "Withdrawal of Consent Mechanism",
            "status": "warning",
            "howToFix": "Provide a clear way to withdraw consent: an 'unsubscribe' link in emails, a 'cookie settings' button in the footer, and a 'revoke consent' section in your privacy policy.",
            "legalRefs": {
              "gdpr": [
                "Art. 7(3)"
              ],
              "skLaw": [
                "§ 14(4)"
              ]
            },
            "whyMatters": "GDPR Article 7(3): 'It shall be as easy to withdraw as to give consent.' If users can subscribe in one click, unsubscribing must be equally simple. Missing this is a common regulatory finding."
          }
        ]
      },
      "nis2": {
        "score": -1,
        "checks": [
          {
            "name": "NIS2 Compliance",
            "value": "Scope undetermined — IČO/company enrichment unavailable for this domain.",
            "status": "info",
            "howToFix": "",
            "whyMatters": ""
          }
        ]
      },
      "mobile": {
        "score": 70,
        "checks": [
          {
            "name": "Viewport Configuration",
            "value": "width=device-width, initial-scale=1",
            "status": "pass"
          },
          {
            "name": "Mobile Performance Score",
            "value": "68/100 (target: 90+)",
            "status": "warning",
            "howToFix": "Optimize for mobile: compress images to WebP, defer non-critical JS, reduce CSS file size. Mobile CPUs are 3-5x slower than desktop — what's fast on desktop is slow on mobile.",
            "whyMatters": "Over 65% of e-commerce traffic is mobile (Statista 2024). Google ranks based on mobile performance, not desktop. Mobile score <50 means you're penalized in mobile search."
          },
          {
            "name": "Touch Target Size",
            "status": "warning",
            "howToFix": "Ensure ALL interactive elements (buttons, links, form fields) are at least 48×48px with 8px minimum spacing between them. Pay special attention to: navigation menus, filter buttons, product variant selectors, and footer links.",
            "whyMatters": "Small tap targets cause 37% more mis-taps on mobile (Google UX research). In e-commerce, a mis-tap on 'Remove from cart' instead of 'Checkout' directly loses revenue."
          },
          {
            "name": "Font Size Readability",
            "status": "warning",
            "howToFix": "Set minimum 16px font size for body text. Use relative units (rem/em) instead of px for scalability. Product titles: 18px+, prices: 20px+, CTAs: 16px+ with bold.",
            "whyMatters": "Text smaller than 16px forces mobile users to pinch-zoom. This breaks the responsive layout and creates a frustrating experience. Users over 40 are especially affected — and they have the highest purchasing power."
          },
          {
            "name": "Content Fits Viewport",
            "value": "No horizontal scrolling needed",
            "status": "pass"
          },
          {
            "name": "Responsive Design Techniques",
            "value": "Media queries detected",
            "status": "pass"
          },
          {
            "name": "Theme Color",
            "value": "theme-color meta tag present",
            "status": "pass"
          },
          {
            "name": "Mobile Navigation (Semantic)",
            "value": "<nav> element present — proper navigation landmark",
            "status": "pass"
          },
          {
            "name": "Responsive Images (srcset)",
            "value": "111 image(s) use srcset for responsive sizing",
            "status": "pass"
          },
          {
            "name": "Apple Mobile Web App",
            "value": "Missing: apple-mobile-web-app-capable, status-bar-style",
            "status": "warning",
            "howToFix": "Add: <meta name='apple-mobile-web-app-capable' content='yes'>, <meta name='apple-mobile-web-app-status-bar-style' content='default'>, <link rel='apple-touch-icon' href='/icon-180.png'>.",
            "whyMatters": "These tags enable 'Add to Home Screen' on iOS with a full-screen experience. 45% of mobile shoppers use iOS — a polished home screen presence increases return visits."
          },
          {
            "name": "Form Input Types",
            "value": "phone fields use type='text' instead of type='tel'",
            "status": "warning",
            "howToFix": "Use semantic input types: type='email' for email (shows @ keyboard), type='tel' for phone (shows number pad), type='search' for search (shows search button). These trigger optimized mobile keyboards.",
            "whyMatters": "Correct input types show specialized mobile keyboards — email keyboard with @, phone with number pad. This reduces input errors by 30% and speeds up form completion (Baymard Institute)."
          },
          {
            "name": "Print Stylesheet",
            "value": "Order/invoice page without print styles",
            "status": "warning",
            "howToFix": "Add @media print CSS rules to hide navigation, ads, and non-essential elements. Ensure order details, prices, and company info are visible when printed.",
            "whyMatters": "Customers print order confirmations and invoices. Without print styles, they get navigation bars, cookie banners, and broken layouts. This is a common usability complaint for e-commerce."
          },
          {
            "name": "Fixed Width Elements",
            "value": "Large fixed-width elements detected — may cause horizontal scroll",
            "status": "warning",
            "howToFix": "Replace fixed pixel widths with max-width: 100% or use relative units (%, vw). Add 'overflow-x: hidden' to body as a safety net.",
            "whyMatters": "Fixed-width elements wider than the viewport cause horizontal scrolling on mobile. Google's mobile-friendly test specifically checks for this."
          },
          {
            "name": "Form Input Labels (WCAG 3.3.2)",
            "value": "Iba 3/12 inputs má label (25%)",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Accessibility audit — Inger"
            },
            "howToFix": "9 input elementov nemá label. Každý input musí mať priradený <label for=\"id\">Text</label> alebo aria-label. Placeholder NIE je label (WCAG 3.3.2). Ak je checkout/registrácia formulár — toto znižuje konverziu a porušuje EN 301 549 (EAA 2026).",
            "whyMatters": "EAA 2026 (European Accessibility Act) vstupuje do platnosti 28.6.2025. E-shopy nad 10 zamestnancov alebo €2M obrat musia byť WCAG 2.1 AA kompatibilné — chýbajúce labely sú jedna z najčastejších žalovateľných chýb."
          },
          {
            "name": "Heading Hierarchy (WCAG 1.3.1)",
            "value": "Preskočené úrovne: h3→h6",
            "status": "warning",
            "howToFix": "Dodržuj poradie nadpisov h1 → h2 → h3 → h4 bez preskočenia. Screen readers používajú hierarchiu nadpisov na navigáciu. Ak potrebuješ menšie písmo ale rovnakú úroveň, použi CSS triedu, nie nižší heading tag.",
            "whyMatters": "Preskočené heading levely (napr. h1 priamo na h3) zlomia navigáciu pre screen reader používateľov a signalizujú Googlu zlú štruktúru dokumentu. Aj SEO je negatívne ovplyvnené."
          },
          {
            "name": "Link Text Quality (WCAG 2.4.4)",
            "value": "Všetky odkazy majú popisný text",
            "status": "pass"
          }
        ]
      },
      "modules": [],
      "security": {
        "score": 55,
        "checks": [
          {
            "name": "SSL/TLS Certificate",
            "value": "Valid HTTPS connection established",
            "status": "pass"
          },
          {
            "name": "DNSSEC",
            "value": "No DNSKEY records — zone is unsigned",
            "status": "warning",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "DNSSEC setup help →"
            },
            "howToFix": "Enable DNSSEC at your DNS host (most modern registrars offer 1-click activation: Cloudflare, Route 53, Google Cloud DNS, web.sk, websupport.sk). Verify via dnsviz.net afterwards.",
            "whyMatters": "Without DNSSEC, attackers controlling intermediate resolvers can forge responses for your domain — sending users to phishing sites with valid HTTPS that match your name. EU national CSIRTs (SK-CERT, NÚKIB) recommend DNSSEC for all in-scope entities."
          },
          {
            "name": "CAA DNS Record",
            "value": "No CAA records — any CA can issue certificates for this domain",
            "status": "warning",
            "howToFix": "Publish CAA TXT records pinning your CA. For Let's Encrypt: `0 issue \"letsencrypt.org\"`. For multiple CAs add additional `0 issue \"...\"` records. Add `0 iodef \"mailto:security@yourdomain.tld\"` for misissuance reports.",
            "whyMatters": "CAA records limit which Certificate Authorities can issue certificates for your domain. Without CAA, a compromised or rogue CA can issue valid certs that browsers will trust — a documented breach pattern (DigiNotar 2011, Symantec 2017)."
          },
          {
            "name": "HTTP → HTTPS Redirect",
            "value": "HTTP properly redirects to HTTPS",
            "status": "pass"
          },
          {
            "name": "HSTS (Strict-Transport-Security)",
            "status": "fail",
            "howToFix": "Add header: Strict-Transport-Security: max-age=31536000; includeSubDomains; preload — then submit to hstspreload.org.",
            "whyMatters": "Without HSTS, attackers can intercept the first HTTP request and downgrade the connection. This is the #1 way to steal session cookies on public WiFi."
          },
          {
            "name": "Content-Security-Policy (CSP)",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Security Hardening →"
            },
            "howToFix": "Implement a CSP header. Start with: Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: — then gradually tighten.",
            "whyMatters": "CSP is the most powerful defense against XSS attacks. Without it, any injected script runs with full privileges. CSP blocks inline script injection, the #1 web attack vector."
          },
          {
            "name": "Clickjacking Protection",
            "status": "fail",
            "howToFix": "Add X-Frame-Options: DENY (or SAMEORIGIN if iframes are needed). Better: use CSP frame-ancestors 'self'.",
            "whyMatters": "Clickjacking overlays your site in a hidden iframe. Attackers trick users into clicking buttons (like 'Confirm Purchase') without knowing it."
          },
          {
            "name": "X-Content-Type-Options",
            "status": "warning",
            "howToFix": "Add header: X-Content-Type-Options: nosniff",
            "whyMatters": "Without nosniff, browsers may execute uploaded files as scripts. An attacker could upload a .jpg that's actually JavaScript and trick the browser into running it."
          },
          {
            "name": "Referrer-Policy",
            "status": "warning",
            "howToFix": "Add header: Referrer-Policy: strict-origin-when-cross-origin — this is the best balance between functionality and privacy.",
            "whyMatters": "Without a referrer policy, browsers send the full URL to third parties. This can leak sensitive data like session tokens in URLs or internal page paths."
          },
          {
            "name": "Permissions-Policy",
            "status": "warning",
            "howToFix": "Add: Permissions-Policy: camera=(), microphone=(), geolocation=(), payment=() — disable APIs your site doesn't need.",
            "whyMatters": "Without Permissions-Policy, any third-party script (ads, analytics, chat widgets) can access camera, microphone, and geolocation without your knowledge."
          },
          {
            "name": "Cookie Security Flags",
            "value": "No cookies set on initial response",
            "status": "pass"
          },
          {
            "name": "Technology Disclosure",
            "value": "Server: cloudflare (no version)",
            "status": "pass"
          },
          {
            "name": "Subresource Integrity (SRI)",
            "value": "Only 1/12 external scripts have integrity hashes",
            "status": "warning",
            "howToFix": "Add integrity='sha384-...' and crossorigin='anonymous' attributes to all third-party <script> tags. Use srihash.org to generate hashes.",
            "whyMatters": "Without SRI, if a third-party CDN is compromised, attackers can inject malicious code into your site. The British Airways breach (£20M fine) was exactly this attack vector."
          },
          {
            "name": "security.txt (RFC 9116)",
            "status": "warning",
            "howToFix": "Create /.well-known/security.txt with Contact, Expires, and Preferred-Languages fields. See securitytxt.org for the generator.",
            "whyMatters": "security.txt lets ethical hackers report vulnerabilities responsibly. Without it, they may disclose publicly or not report at all. Required by ISO 27001 and SOC 2."
          },
          {
            "name": "CDN / WAF Protection",
            "value": "Cloudflare detected — DDoS protection and edge caching active",
            "status": "pass"
          },
          {
            "name": "Iframe Sandboxing",
            "value": "1/1 iframe(s) without sandbox attribute",
            "status": "warning",
            "howToFix": "Add sandbox attribute to all <iframe> elements. Use sandbox='allow-scripts allow-same-origin' for third-party embeds. This restricts iframe capabilities to only what's needed.",
            "whyMatters": "Unsandboxed iframes can access your DOM, run scripts, and navigate the top window. Third-party iframes (ads, widgets) should always be sandboxed to prevent clickjacking and XSS."
          },
          {
            "name": "Password Field Security",
            "value": "1 password field(s) block autocomplete",
            "status": "warning",
            "howToFix": "Remove autocomplete='off' from password fields. Password managers improve security by enabling unique, strong passwords. Blocking them encourages password reuse.",
            "whyMatters": "NIST SP 800-63B explicitly recommends ALLOWING password paste and autofill. Blocking password managers forces users to choose weaker, memorable passwords — the #1 cause of account compromise."
          }
        ]
      },
      "tech_stack": [
        {
          "name": "Font Awesome",
          "category": "js-library"
        },
        {
          "name": "Swiper",
          "category": "js-library"
        },
        {
          "name": "Stimulus",
          "category": "js-library"
        },
        {
          "name": "Turbo",
          "category": "js-library"
        },
        {
          "name": "Cloudflare",
          "category": "cdn"
        }
      ],
      "performance": {
        "score": 65,
        "checks": [
          {
            "name": "Server Response Time (TTFB)",
            "value": "49ms",
            "status": "pass"
          },
          {
            "name": "First Contentful Paint (FCP)",
            "value": "0.65s",
            "status": "pass"
          },
          {
            "name": "Largest Contentful Paint (LCP)",
            "value": "1.25s — Core Web Vital ✓",
            "status": "pass"
          },
          {
            "name": "Total Blocking Time (TBT)",
            "value": "652ms (good: <200ms)",
            "status": "fail",
            "howToFix": "Critical: audit all JavaScript. 1) Remove unused plugins/modules, 2) Defer analytics and chat widgets, 3) Code-split large bundles, 4) Move heavy computation to web workers.",
            "whyMatters": "TBT over 600ms means your page is unresponsive for over half a second. Users who can't interact within 100ms perceive the site as broken. This kills conversions."
          },
          {
            "name": "Cumulative Layout Shift (CLS)",
            "value": "0.271 (good: <0.1) — Core Web Vital FAILING",
            "status": "fail",
            "howToFix": "Urgent layout stability issues. 1) Add width/height to all <img> and <video>, 2) Reserve space for ads with min-height, 3) Use font-display: swap for web fonts, 4) Don't dynamically inject content above visible area.",
            "whyMatters": "CLS >0.25 fails Core Web Vitals. Users experience constant content jumping — extremely frustrating on mobile where accidental clicks lead to unwanted purchases or page changes."
          },
          {
            "name": "Speed Index",
            "value": "1.43s",
            "status": "pass"
          },
          {
            "name": "Total Page Weight",
            "value": "2.6 MB, 162 requests (optimal: <1.5 MB, <50 req)",
            "status": "warning",
            "howToFix": "Reduce page weight: compress images to WebP (saves 30-50%), enable text compression (gzip/brotli), lazy load below-fold images, remove unused CSS/JS.",
            "whyMatters": "A 3 MB page takes 6+ seconds on 3G mobile. Over 50% of global e-commerce traffic is mobile — heavy pages lose customers in emerging markets and poor connectivity areas."
          },
          {
            "name": "Render-blocking Resources",
            "value": "No render-blocking resources found",
            "status": "pass"
          },
          {
            "name": "Unused Code (CSS + JS)",
            "value": "746 KB wasted on unused code!",
            "status": "fail",
            "howToFix": "You're loading ${unusedTotalKB} KB of code that isn't used on this page. 1) Audit plugins and remove unused ones, 2) Use code-splitting for page-specific JS, 3) Run PurgeCSS on your stylesheets.",
            "whyMatters": "Over 200 KB of unused code significantly slows parsing and execution. This is one of the easiest performance wins — removing dead code requires no trade-offs."
          },
          {
            "name": "Text Compression (gzip/brotli)",
            "value": "All text resources properly compressed",
            "status": "pass"
          },
          {
            "name": "Resource Hints (Preload/Preconnect)",
            "value": "1 preload, 0 preconnect hint(s)",
            "status": "pass"
          },
          {
            "name": "Lazy Loading",
            "value": "69% of images use native lazy loading (126/183)",
            "status": "pass"
          },
          {
            "name": "Cache-Control Strategy",
            "value": "no-store",
            "status": "warning",
            "howToFix": "Set appropriate cache headers: static assets should have max-age=31536000 with versioned filenames. HTML pages can use max-age=0 with ETag for revalidation.",
            "whyMatters": "no-cache/no-store forces browsers to re-download resources on every visit. Repeat visitors load your entire site from scratch every time."
          },
          {
            "name": "HTTP/3 (QUIC) Support",
            "value": "HTTP/3 enabled via Alt-Svc header",
            "status": "pass"
          },
          {
            "name": "Script Loading Strategy",
            "value": "91% of scripts use async/defer/module (0 async, 10 defer, 0 module)",
            "status": "pass"
          },
          {
            "name": "CSS File Count",
            "value": "1 CSS file(s) — well consolidated",
            "status": "pass"
          },
          {
            "name": "Font Preloading",
            "value": "Custom fonts detected without preload hints",
            "status": "warning",
            "howToFix": "Preload your primary font: <link rel='preload' href='/fonts/main.woff2' as='font' type='font/woff2' crossorigin>. For Google Fonts: preconnect to fonts.gstatic.com.",
            "whyMatters": "Fonts are discovered late in the render pipeline (after CSS is parsed). Preloading tells the browser to download them immediately, reducing Flash of Invisible Text (FOIT) by 200-500ms."
          },
          {
            "name": "Critical CSS Strategy",
            "value": "Critical CSS / async CSS loading detected",
            "status": "pass"
          }
        ]
      },
      "ai_readiness": {
        "score": 55,
        "checks": [
          {
            "name": "AI Bot Access Policy",
            "value": "No AI bot restrictions (allowed by default)",
            "status": "pass"
          },
          {
            "name": "llms.txt (AI Site Descriptor)",
            "status": "fail",
            "fixLink": {
              "url": "https://llmstxt.org",
              "label": "Learn about llms.txt →"
            },
            "howToFix": "Create /llms.txt in Markdown format:\n# Your Store Name\n> One-line summary of your business and key offerings.\n\nDetailed description paragraph.\n\n## Products\n- [Product Category](URL): Description\n\n## About\n- [About Us](URL): Company history and values\n\nSee llmstxt.org for the full specification.",
            "whyMatters": "llms.txt is the emerging standard for AI-readable site descriptions — like robots.txt was for search engines. Early adopters (Yoast, Cloudflare, Stripe) are already using it. Without it, AI assistants have no guided overview of your store."
          },
          {
            "name": "llms-full.txt (Complete AI Content)",
            "status": "warning",
            "howToFix": "Create /llms-full.txt containing your complete site documentation in a single Markdown file — product catalog summaries, FAQs, policies, brand story. This gives AI models maximum context about your store.",
            "whyMatters": "llms-full.txt provides AI models with your entire site content in one parseable file. It's the difference between an AI having a brief overview vs. deep knowledge of your products and services."
          },
          {
            "name": "Content Accessibility for AI",
            "value": "Only 4411 words visible in HTML — content may be JS-dependent",
            "status": "fail",
            "howToFix": "Your page has very little content in the HTML source. If you're using a JavaScript framework (React, Vue, Angular), implement Server-Side Rendering (SSR) or Static Site Generation (SSG).",
            "whyMatters": "AI crawlers see only raw HTML. The LLMClicks audit tool found that JS-dependent pages score 70% lower in AI readiness. Server-rendered content is the #1 prerequisite for AI visibility."
          },
          {
            "name": "Structured Data Foundation",
            "value": "1 JSON-LD blocks with 6 schema types: Organization, PostalAddress, ImageObject, WebSite, SearchAction, EntryPoint",
            "status": "pass"
          },
          {
            "name": "Organization Schema + Entity Linking",
            "value": "Organization found with 7 sameAs links — strong entity identity",
            "status": "pass"
          },
          {
            "name": "FAQ Schema (Direct AI Answers)",
            "status": "warning",
            "howToFix": "Add FAQPage schema to every product page and category page. Include 3-5 Q&As per page covering: product specifications, shipping, returns, usage instructions. Format: question (full sentence) + answer (75-150 words).",
            "whyMatters": "FAQ schema provides 30% higher AI citation rates (LLMClicks research). ChatGPT, Perplexity, and Google AI Overviews pull FAQ answers verbatim. It's the fastest way to get your content cited by AI."
          },
          {
            "name": "Site Search Schema (SearchAction)",
            "value": "WebSite SearchAction configured — AI can search your store",
            "status": "pass"
          },
          {
            "name": "Content Depth for AI",
            "value": "4411 words — rich content for AI analysis and citation",
            "status": "pass"
          },
          {
            "name": "Answer-First Content Format",
            "value": "Content doesn't start with a strong summary paragraph",
            "status": "warning",
            "howToFix": "Place your most important information in the first 100 words of the page. Use the BLUF method (Bottom Line Up Front): start with what the product IS and why it matters, then elaborate.",
            "whyMatters": "AI assistants extract content from the first 100 words to generate summaries. The LLMClicks analyzer found pages with answer-first format get 40% more AI citations. Most AI systems read top-down."
          },
          {
            "name": "Heading Hierarchy for AI",
            "value": "0 H1, 37 H2, 3 H3 — poor structure",
            "status": "fail",
            "howToFix": "Use exactly 1 H1 (page title), then organize content with H2 sections and H3 subsections. Each heading should describe the content that follows. Never skip heading levels (H1→H3 without H2).",
            "whyMatters": "AI extracts information based on heading structure. Pages with proper H1→H2→H3 hierarchy are more accurately parsed by ChatGPT, Perplexity, and Google AI Overviews. Without it, AI may misinterpret your content."
          },
          {
            "name": "Semantic HTML Structure",
            "value": "4/6 semantic elements: <nav>, <main>, <header>, <footer>",
            "status": "pass"
          },
          {
            "name": "Structured Content (Lists & Tables)",
            "value": "158 lists found — consider adding comparison tables",
            "status": "warning",
            "howToFix": "Add comparison tables to your content. Use <ul>/<ol> for feature lists, specifications, and benefits. Use <table> for product comparisons, pricing tiers, and specifications. AI extracts structured content exponentially faster than paragraphs.",
            "whyMatters": "AI models are biased toward extracting data from HTML lists and tables. Perplexity and ChatGPT pull bullet points and table data with much higher accuracy than paragraph text. Structured content = more AI citations."
          },
          {
            "name": "Content Freshness Signals",
            "status": "fail",
            "howToFix": "Add dateModified and datePublished to your JSON-LD schema, and display a visible 'Last updated' date on the page. Update content quarterly at minimum. AI heavily favors fresh, maintained content.",
            "whyMatters": "No freshness signals = AI assumes your content is stale. ChatGPT and Perplexity both weight recency in their citation algorithms. Competitors who show recent updates will be cited instead of your static pages."
          },
          {
            "name": "Entity Clarity & Brand Signals",
            "value": "7 sameAs links but incomplete OG tags",
            "status": "warning",
            "howToFix": "For full entity clarity: 1) Complete Open Graph tags (og:title, og:description, og:image, og:type), 2) Add sameAs in Organization schema linking to Wikipedia, LinkedIn, Facebook, and other profiles.",
            "whyMatters": "AI needs to confidently identify your brand entity. Open Graph + sameAs create a cross-platform identity that AI models recognize. The HubSpot AEO Grader found entity clarity is a top-3 factor for AI brand recognition."
          },
          {
            "name": "Author Expertise Signals (E-E-A-T)",
            "status": "warning",
            "howToFix": "For content pages (blog, guides, about): add Article/BlogPosting schema with author property linking to Person schema. Include the author's jobTitle, credentials, and social profiles.",
            "whyMatters": "AI models weight author expertise heavily. Pages from identified experts get cited 3x more than anonymous content. This is especially important for product guides, reviews, and advice content."
          },
          {
            "name": "Extractable Answer Blocks",
            "value": "7 paragraphs, avg 14 words — too short for citation",
            "status": "warning",
            "howToFix": "Optimal paragraphs for AI citation are 40-80 words. Break long paragraphs into focused, self-contained answer blocks. Each should make one clear point that AI can extract and quote.",
            "whyMatters": "Pages with 40-80 word paragraphs earn 70% more AI citations (Otterly 2026 data). AI extracts individual paragraphs as answer snippets — dense walls of text get skipped."
          },
          {
            "name": "Statistics & Data Presence",
            "value": "6 data points found — strong citation magnet",
            "status": "pass"
          },
          {
            "name": "Q&A Format Headings",
            "status": "warning",
            "howToFix": "Add H2/H3 headings phrased as questions your customers ask: 'How much does shipping cost?', 'What sizes are available?', 'How do I return an item?' Follow each with a direct, concise answer.",
            "whyMatters": "Q&A content format matches how people query AI assistants. Without question-format headings, your content is harder for AI to map to user queries."
          },
          {
            "name": "Internal Link Density",
            "value": "23 contextual internal links per 1,000 words — strong knowledge graph signal",
            "status": "pass"
          },
          {
            "name": "Canonical Tag for AI Deduplication",
            "status": "fail",
            "howToFix": "Add <link rel='canonical' href='https://your-absolute-url'> to every page. This tells AI engines which URL is the authoritative version of this content.",
            "whyMatters": "Without a canonical tag, AI models may index multiple versions of the same page (with/without trailing slash, with parameters, etc.), diluting your AI visibility across duplicate URLs."
          },
          {
            "name": "Knowledge Graph Readiness",
            "value": "3/4 entity signals — strong Knowledge Graph presence",
            "status": "pass"
          },
          {
            "name": "Content Readability for AI",
            "value": "Grade 20 — too complex for broad AI citation (technical threshold: 14)",
            "status": "warning",
            "howToFix": "Simplify sentences (target 15-20 words average), use common words, break complex ideas into shorter paragraphs. AI extracts content for general audiences — if it's too academic, AI skips it.",
            "whyMatters": "Content above grade 12 readability is harder for AI to extract as clear, concise answers. Pages using clear headers and approachable language are 28% more likely to be cited by AI."
          },
          {
            "name": "Image Alt Text Quality for AI",
            "value": "Only 5% quality alt text — 77 missing, 97 poor",
            "status": "fail",
            "howToFix": "Audit all images: add descriptive alt text (3-15 words) to every <img>. Include product names, features, materials, colors. This is critical for visual AI search and accessibility compliance.",
            "whyMatters": "Poor alt text means your product images are invisible to AI visual search (Google Lens, Bing Visual Search). This is also an accessibility requirement (WCAG 2.1 AA) — many regions enforce this legally."
          },
          {
            "name": "Expert Quotations & Citations",
            "status": "warning",
            "howToFix": "Add 2-3 expert quotes or data citations per major page. Use <blockquote> for quotes and link to authoritative sources (.gov, .edu, Wikipedia, industry reports).",
            "whyMatters": "Content without citations or expert quotes appears unverified to AI. AI assistants prefer content backed by named sources, data references, and expert opinions."
          },
          {
            "name": "ai.txt (AI Permissions)",
            "status": "warning",
            "howToFix": "Create /ai.txt or /.well-known/ai.txt to declare granular AI permissions per content type: which AI actions (summarization, training, extraction) are allowed for which content sections.",
            "whyMatters": "ai.txt is an emerging standard (proposed May 2025) for fine-grained AI permissions beyond robots.txt. Early adoption signals AI-forward thinking and gives you control over how AI uses your content."
          },
          {
            "name": "WebMCP Agentic Readiness",
            "status": "warning",
            "howToFix": "WebMCP (W3C Community Group standard, Chrome 146+) lets pages declare structured tools for AI agents. Add toolname and tooldescription attributes to <form> elements, or include a <script type='application/webmcp+json'> manifest.",
            "whyMatters": "WebMCP is called 'the new Schema.org moment' — it's how AI agents will interact with your store (search products, add to cart, check availability). Google and Microsoft are co-developing this standard."
          },
          {
            "name": "Content-to-Boilerplate Ratio",
            "value": "Only 10% in main content — mostly boilerplate",
            "status": "fail",
            "howToFix": "Wrap your primary content in <main> or <article> tags. AI extracts content from these semantic containers — without them, your product descriptions are mixed with navigation and footer text.",
            "whyMatters": "Token density measures useful content vs noise. Pages with <30% content ratio are scored 'not machine-readable' by tools like LLMClicks. AI literally can't find your content in the boilerplate."
          },
          {
            "name": "Heureka Ověřeno Widget",
            "value": "Heureka trust widget detected",
            "status": "pass",
            "whyMatters": "Heureka Ověřeno is the dominant SK/CZ social-proof program — buyers trust it 2× more than generic ratings. Verified shops with a public obchody.heureka.* profile show stronger long-term provenance than just a widget script."
          },
          {
            "name": "Customer Reviews — Aggregate",
            "value": "1 source: Heureka Ověřeno",
            "status": "warning",
            "howToFix": "Single review source detected without published reviewCount. Add AggregateRating JSON-LD (ratingValue + reviewCount + bestRating) so the count is machine-readable, and add a second source (Heureka Ověřeno + Trustpilot is the SK/CZ standard).",
            "whyMatters": "Without a second review source and a machine-readable reviewCount, AI assistants can't verify scale of social proof — single-source ratings are routinely deweighted as potentially curated."
          }
        ]
      },
      "vulnerability": {
        "score": 71,
        "checks": [
          {
            "name": "CMS Version Disclosure",
            "value": "No generator tag — CMS identity hidden",
            "status": "pass"
          },
          {
            "name": "Sensitive Files Exposed",
            "value": ".env, .git, composer.json — all properly blocked",
            "status": "pass"
          },
          {
            "name": "Install Script Exposed",
            "value": "No /install/ or /setup/ paths accessible",
            "status": "pass"
          },
          {
            "name": "Directory Listing",
            "value": "Disabled — file structure hidden",
            "status": "pass"
          },
          {
            "name": "Admin Panel at Default URL",
            "value": "Not found at common paths (/admin, /wp-admin, /administrator, /backoffice)",
            "status": "pass"
          },
          {
            "name": "Debug Mode / Error Exposure",
            "value": "No debug indicators found in page output",
            "status": "pass"
          },
          {
            "name": "Form CSRF Protection",
            "value": "4/5 forms have CSRF tokens",
            "status": "warning",
            "howToFix": "Ensure ALL forms include a CSRF token. In PrestaShop, use {$csrf_token} in templates. In WordPress, use wp_nonce_field().",
            "whyMatters": "Forms without CSRF tokens allow cross-site request forgery — an attacker's site can submit orders, change settings, or modify data on behalf of your logged-in users."
          },
          {
            "name": "Suspicious Inline Script Patterns",
            "value": "Detected: Dynamic script injection",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Malware Scan →"
            },
            "howToFix": "Review all inline scripts for obfuscated code. Magecart attackers inject payment skimmers disguised as analytics or GTM scripts. Compare your current HTML with a known-good version. Consider using CSP with strict nonces.",
            "whyMatters": "These patterns (Base64 decode, eval with encoding, dynamic script injection) are hallmarks of Magecart payment skimmers. The 2024 Akamai report found skimmers disguised as Google Tag Manager on thousands of e-commerce sites."
          },
          {
            "name": "SPF Record (Email Security)",
            "value": "SPF configured: v=spf1 ip4:185.2.43.107 ip4:185.115.1.85 ip4:185.115.1.84 ip4:185.115.1.94 inclu",
            "status": "pass"
          },
          {
            "name": "DMARC Policy (Email Auth)",
            "value": "DMARC set to p=none (monitoring only, no enforcement)",
            "status": "warning",
            "howToFix": "Upgrade DMARC policy from p=none to p=quarantine or p=reject. p=none only monitors — it doesn't block spoofed emails. Start with quarantine, then move to reject after verifying legitimate emails pass.",
            "whyMatters": "DMARC p=none provides zero protection against email spoofing. It only generates reports. Move to p=quarantine to actually block forged emails from reaching your customers' inboxes."
          },
          {
            "name": "DKIM Signing (Email Auth)",
            "value": "DKIM configured (selectors: selector1)",
            "status": "pass"
          },
          {
            "name": "Cross-Origin Isolation",
            "status": "warning",
            "howToFix": "Add Cross-Origin-Opener-Policy: same-origin and Cross-Origin-Resource-Policy: same-origin headers. These protect against Spectre-type side-channel attacks.",
            "whyMatters": "Without cross-origin isolation headers, your site is vulnerable to Spectre attacks that can leak sensitive data across browser tabs. These headers are required for SharedArrayBuffer and high-resolution timers."
          },
          {
            "name": "Login Form Security",
            "value": "Login form blocks password manager autofill",
            "status": "warning",
            "howToFix": "Remove autocomplete='off' from login forms. Password managers improve security by enabling unique, complex passwords per site.",
            "whyMatters": "NIST guidelines recommend allowing password autofill. Blocking it forces users to choose weak, memorable passwords — the #1 cause of credential compromise."
          },
          {
            "name": "Clickjacking on Sensitive Page",
            "value": "Login/payment page without X-Frame-Options or CSP frame-ancestors",
            "status": "fail",
            "howToFix": "URGENT: Add X-Frame-Options: DENY and CSP frame-ancestors 'none' to pages with login forms or payment fields. Attackers can overlay your page in a transparent iframe.",
            "whyMatters": "Clickjacking on payment/login pages is a high-severity vulnerability. Users unknowingly submit credentials or payments through invisible iframes. PCI DSS requires frame-busting on payment pages."
          }
        ]
      },
      "opendata_security": null
    },
    "created_at": "2026-06-07T18:52:12.682919+00:00",
    "status": "complete",
    "platform_detected": null,
    "company_ico": null,
    "company_name": null,
    "company_country": null,
    "company_nace": null,
    "company_size": null,
    "nis2_scope": null,
    "nis2_sector": null,
    "company_risk_score": null,
    "company_risk_level": null
  }
}