{
  "data": {
    "slug": "6d1b2c94",
    "url": "https://www.php.net",
    "domain": "php.net",
    "overall_score": 70,
    "scores_json": {
      "seo": {
        "score": 70,
        "checks": [
          {
            "i18n": {
              "key": "seo.meta-title.warning-short",
              "params": {
                "chars": 3
              }
            },
            "name": "Meta Title",
            "value": "3 chars (optimal: 30-60)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Your title is very short. Add descriptive keywords and your brand name for better ranking signals.",
            "whyMatters": "Short titles waste valuable ranking real estate in search results."
          },
          {
            "i18n": {
              "key": "seo.meta-desc.pass",
              "params": {
                "chars": 132
              }
            },
            "name": "Meta Description",
            "value": "132 chars",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.h1.fail"
            },
            "name": "H1 Heading",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add exactly one H1 tag containing your primary keyword. It should be the most prominent heading on the page.",
            "whyMatters": "The H1 is a primary content signal for search engines. Pages without an H1 rank lower for target keywords."
          },
          {
            "i18n": {
              "key": "seo.h2.pass",
              "params": {
                "count": 25
              }
            },
            "name": "Content Structure (H2 Headings)",
            "value": "25 H2 subheadings found",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.og.warning",
              "params": {
                "missing": "og:title"
              }
            },
            "name": "Open Graph Tags",
            "value": "Missing: og:title",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add the missing OG tags: og:title. Use high-quality 1200×630px images for og:image.",
            "whyMatters": "Incomplete OG tags mean broken social previews. Shared links without an image get far fewer clicks on Facebook and LinkedIn."
          },
          {
            "i18n": {
              "key": "seo.og-format.pass",
              "params": {
                "contentType": "image/png"
              }
            },
            "name": "Open Graph Image Format",
            "value": "image/png",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.twitter.pass",
              "params": {
                "card": "summary_large_image"
              }
            },
            "name": "Twitter/X Cards",
            "value": "Card type: summary_large_image",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.canonical.pass",
              "params": {
                "url": "https://www.php.net/index.php"
              }
            },
            "name": "Canonical URL",
            "value": "https://www.php.net/index.php",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.jsonld.fail"
            },
            "name": "Structured Data (JSON-LD)",
            "status": "fail",
            "fixLink": {
              "url": "https://zulien.sk",
              "label": "Add with Schema module →"
            },
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Add JSON-LD structured data: Product (with price, availability, reviews), Organization, BreadcrumbList, and WebSite schemas.",
            "whyMatters": "Pages with structured data can earn rich snippets in Google — star ratings, prices, availability — which lift click-through."
          },
          {
            "i18n": {
              "key": "seo.robots.pass"
            },
            "name": "robots.txt",
            "value": "Present",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "i18n": {
              "key": "seo.sitemap.pass-count",
              "params": {
                "count": 39
              }
            },
            "name": "XML Sitemap",
            "value": "Found with ~39+ URLs",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "i18n": {
              "key": "seo.html-lang.pass",
              "params": {
                "lang": "en"
              }
            },
            "name": "HTML Language Attribute",
            "value": "lang=\"en\"",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.hreflang.pass",
              "params": {
                "count": 1,
                "langs": "x-default"
              }
            },
            "name": "Hreflang Tags (Multilingual)",
            "value": "1 language(s): x-default",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.img-alt.warning",
              "params": {
                "rate": 75,
                "total": 4,
                "missing": 1
              }
            },
            "name": "Image Alt Attributes",
            "value": "Only 75% of 4 images have alt text",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "1 images are missing alt attributes. Add descriptive, keyword-rich alt text to every image.",
            "whyMatters": "Missing alt text means no visibility in Google Image Search, which is a real traffic source for e-commerce."
          },
          {
            "i18n": {
              "key": "seo.text-ratio.pass",
              "params": {
                "ratio": 27,
                "words": 2001
              }
            },
            "name": "Text-to-HTML Ratio",
            "value": "27% (2001 words)",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.favicon.pass"
            },
            "name": "Favicon",
            "value": "Favicon detected",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "i18n": {
              "key": "seo.img-format.warning-none",
              "params": {
                "jpg": 0,
                "png": 1
              }
            },
            "name": "Image Format Optimization",
            "value": "0% next-gen formats — 0 JPEG, 1 PNG images",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Convert all images to WebP format. Most CMS platforms have plugins for automatic WebP conversion. Use AVIF for even better compression.",
            "whyMatters": "Your images use legacy formats only. Switching to WebP typically reduces page weight by 30-50% — one of the highest-impact performance optimizations."
          },
          {
            "i18n": {
              "key": "seo.semantic.pass",
              "params": {
                "used": "<article>, <nav>, <header>, <footer>, <aside>",
                "count": 5
              }
            },
            "name": "Semantic HTML Structure",
            "value": "5/6 semantic elements: <article>, <nav>, <header>, <footer>, <aside>",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.canonical-consistency.warning",
              "params": {
                "url": "https://www.php.net/index.php"
              }
            },
            "name": "Canonical URL Consistency",
            "value": "Canonical points to different URL: https://www.php.net/index.php",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Your canonical URL doesn't match the current page URL. Ensure the canonical points to the preferred version (with or without trailing slash, www vs non-www). Inconsistent canonicals confuse search engines.",
            "whyMatters": "A mismatched canonical tells Google this page is a duplicate of another URL. If unintentional, Google may ignore this page entirely in favor of the canonical target."
          },
          {
            "i18n": {
              "key": "seo.sitemap-in-robots.warning"
            },
            "name": "Sitemap in robots.txt",
            "value": "robots.txt exists but doesn't reference your sitemap",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add 'Sitemap: https://yourdomain.com/sitemap.xml' to your robots.txt file. This helps search engines discover your sitemap faster.",
            "whyMatters": "While Google can find sitemaps via Search Console, referencing it in robots.txt ensures all search engines (Bing, Yandex, Baidu) can discover it automatically."
          },
          {
            "i18n": {
              "key": "seo.content-depth.pass",
              "params": {
                "words": 2001
              }
            },
            "name": "Content Depth",
            "value": "2001 words — sufficient content",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "seo.deep-heading.warning"
            },
            "name": "Deep Heading Hierarchy",
            "value": "No H3 subheadings for long content",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add H3 subheadings under your H2 sections to create a deeper content hierarchy. This helps search engines understand sub-topics and improves featured snippet eligibility.",
            "whyMatters": "Deep heading hierarchies (H2→H3→H4) help Google build a content outline. Pages with three or more heading levels rank for more keywords than flat-structured pages."
          },
          {
            "i18n": {
              "key": "seo.internal-links.warning",
              "params": {
                "count": 4,
                "threshold": 5
              }
            },
            "name": "Internal Linking",
            "value": "Only 4 internal links",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add more internal links to related content. Target 5+ internal links per page for strong site crawlability.",
            "whyMatters": "Internal links help Google discover and rank your pages. Pages with more internal links receive higher PageRank and are crawled more frequently."
          },
          {
            "i18n": {
              "key": "seo.a11y.pass",
              "params": {
                "detail": "3 ARIA roles, 11 ARIA labels, lang=\"en\"",
                "signals": 3
              }
            },
            "name": "Accessibility Fundamentals",
            "value": "3/4 a11y signals: 3 ARIA roles, 11 ARIA labels, lang=\"en\"",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          }
        ]
      },
      "gdpr": {
        "score": 48,
        "checks": [
          {
            "i18n": {
              "key": "gdpr.cmp.fail"
            },
            "name": "Cookie Consent Banner (CMP)",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get GDPR Compliance →"
            },
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Install a certified consent management platform: Cookiebot, OneTrust, Usercentrics, or CookieYes. The CMP must block ALL non-essential cookies and scripts until explicit consent is given (opt-in, not opt-out).",
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7"
              ],
              "skLaw": [
                "§ 14"
              ],
              "verified": [
                {
                  "title": "Zákonnosť spracúvania",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 6 — Zákonnosť spracúvania 1. Spracúvanie je zákonné iba vtedy a iba v tom rozsahu, keď je splnená aspoň jedna z týchto podmienok: Písmeno f) prvého pododseku sa nevzťahuje na spracúvanie vykonávané orgánmi verejnej moci pri výkone i",
                  "citation": "čl. 6 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky vyjadrenia súhlasu",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 7 — Podmienky vyjadrenia súhlasu 1. Ak je spracúvanie založené na súhlase, prevádzkovateľ musí vedieť preukázať, že dotknutá osoba vyjadrila súhlas so spracúvaním svojich osobných údajov. 2. Ak dá dotknutá osoba súhlas v rámci písom",
                  "citation": "čl. 7 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky poskytnutia súhlasu so spracúvaním osobných údajov",
                  "excerpt": "§ 14 Podmienky poskytnutia súhlasu so spracúvaním osobných údajov (1) Ak je spracúvanie osobných údajov založené na súhlase dotknutej osoby, prevádzkovateľ je povinný kedykoľvek vedieť preukázať, že dotknutá osoba poskytla súhlas so spracúv",
                  "citation": "§14 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            },
            "whyMatters": "Since 2024, EU regulators actively enforce cookie consent. A non-compliant cookie banner is one of the most frequently fined GDPR offences."
          },
          {
            "i18n": {
              "key": "gdpr.tracking.fail",
              "params": {
                "count": 1,
                "trackers": "Matomo"
              }
            },
            "name": "Tracking Scripts Without Consent",
            "value": "1 tracker(s) loading without consent: Matomo",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "These tracking scripts fire before user consent: Matomo. Configure your CMP to block them until explicit opt-in. Use Tag Manager's consent mode or CMP script blocking.",
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7"
              ],
              "skLaw": [
                "§ 14"
              ],
              "verified": [
                {
                  "title": "Zákonnosť spracúvania",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 6 — Zákonnosť spracúvania 1. Spracúvanie je zákonné iba vtedy a iba v tom rozsahu, keď je splnená aspoň jedna z týchto podmienok: Písmeno f) prvého pododseku sa nevzťahuje na spracúvanie vykonávané orgánmi verejnej moci pri výkone i",
                  "citation": "čl. 6 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky vyjadrenia súhlasu",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 7 — Podmienky vyjadrenia súhlasu 1. Ak je spracúvanie založené na súhlase, prevádzkovateľ musí vedieť preukázať, že dotknutá osoba vyjadrila súhlas so spracúvaním svojich osobných údajov. 2. Ak dá dotknutá osoba súhlas v rámci písom",
                  "citation": "čl. 7 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky poskytnutia súhlasu so spracúvaním osobných údajov",
                  "excerpt": "§ 14 Podmienky poskytnutia súhlasu so spracúvaním osobných údajov (1) Ak je spracúvanie osobných údajov založené na súhlase dotknutej osoby, prevádzkovateľ je povinný kedykoľvek vedieť preukázať, že dotknutá osoba poskytla súhlas so spracúv",
                  "citation": "§14 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            },
            "whyMatters": "Loading ANY tracking before consent is a direct GDPR/ePrivacy violation. This is one of the most commonly fined offences by EU data protection authorities."
          },
          {
            "i18n": {
              "key": "gdpr.privacy-policy.pass",
              "params": {
                "url": "/privacy.php"
              }
            },
            "name": "Privacy Policy Page",
            "value": "/privacy.php",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "legalRefs": {
              "gdpr": [
                "Art. 12",
                "Art. 13",
                "Art. 14"
              ],
              "skLaw": [
                "§ 19",
                "§ 20"
              ],
              "verified": [
                {
                  "title": "Transparentnosť informácií, oznámenia a postupy výkonu práv dotknutej osoby",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 12 — Transparentnosť informácií, oznámenia a postupy výkonu práv dotknutej osoby 3. Prevádzkovateľ poskytne dotknutej osobe informácie o opatreniach, ktoré sa prijali na základe žiadosti podľa článkov 15 až 22, bez zbytočného odklad",
                  "citation": "čl. 12 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Informácie, ktoré sa majú poskytovať pri získavaní osobných údajov od dotknutej osoby",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 13 — Informácie, ktoré sa majú poskytovať pri získavaní osobných údajov od dotknutej osoby 2. Okrem informácií, ktoré sa uvádzajú v odseku 1, prevádzkovateľ poskytne dotknutej osobe pri získavaní osobných údajov tieto ďalšie informá",
                  "citation": "čl. 13 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Informácie, ktoré sa majú poskytnúť, ak osobné údaje neboli získané od dotknutej osoby",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 14 — Informácie, ktoré sa majú poskytnúť, ak osobné údaje neboli získané od dotknutej osoby 2. Okrem informácií uvedených v odseku 1 prevádzkovateľ poskytne dotknutej osobe tieto ďalšie informácie potrebné na zabezpečenie spravodliv",
                  "citation": "čl. 14 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Poskytované informácie, ak osobné údaje sú získané od dotknutej osoby",
                  "excerpt": "§ 19 Poskytované informácie, ak osobné údaje sú získané od dotknutej osoby (4) Odseky 1 až 3 sa neuplatňujú v rozsahu, v akom boli informácie dotknutej osobe poskytnuté pred spracúvaním osobných údajov.",
                  "citation": "§19 ods. 4 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                },
                {
                  "title": "Poskytované informácie, ak osobné údaje nie sú získané od dotknutej osoby",
                  "excerpt": "§ 20 Poskytované informácie, ak osobné údaje nie sú získané od dotknutej osoby (5) d) ak osobné údaje musia zostať dôverné na základe povinnosti mlčanlivosti podľa osobitného predpisu. 15 )",
                  "citation": "§20 ods. 5 písm. d) zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            }
          },
          {
            "i18n": {
              "key": "gdpr.cookie-policy.warning"
            },
            "name": "Cookie Policy",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Create a separate cookie policy page listing every cookie by: name, provider, purpose, category (necessary/analytics/marketing), and expiration. Most CMPs auto-generate this.",
            "legalRefs": {
              "gdpr": [
                "Art. 12",
                "Art. 13(1)(c)-(e)"
              ],
              "skLaw": [
                "§ 19"
              ],
              "verified": [
                {
                  "title": "Transparentnosť informácií, oznámenia a postupy výkonu práv dotknutej osoby",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 12 — Transparentnosť informácií, oznámenia a postupy výkonu práv dotknutej osoby 3. Prevádzkovateľ poskytne dotknutej osobe informácie o opatreniach, ktoré sa prijali na základe žiadosti podľa článkov 15 až 22, bez zbytočného odklad",
                  "citation": "čl. 12 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Informácie, ktoré sa majú poskytovať pri získavaní osobných údajov od dotknutej osoby",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 13 — Informácie, ktoré sa majú poskytovať pri získavaní osobných údajov od dotknutej osoby 2. Okrem informácií, ktoré sa uvádzajú v odseku 1, prevádzkovateľ poskytne dotknutej osobe pri získavaní osobných údajov tieto ďalšie informá",
                  "citation": "čl. 13 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Poskytované informácie, ak osobné údaje sú získané od dotknutej osoby",
                  "excerpt": "§ 19 Poskytované informácie, ak osobné údaje sú získané od dotknutej osoby (4) Odseky 1 až 3 sa neuplatňujú v rozsahu, v akom boli informácie dotknutej osobe poskytnuté pred spracúvaním osobných údajov.",
                  "citation": "§19 ods. 4 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            },
            "whyMatters": "The ePrivacy Directive requires transparent cookie disclosure. Vague statements like 'we use cookies for functionality' don't meet the specificity requirement."
          },
          {
            "i18n": {
              "key": "gdpr.imprint.warning"
            },
            "name": "Legal Contact / Imprint Page",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add an imprint/about-us page with: company name, registered address, contact email, VAT number, and trade register info. In Germany/Austria/Switzerland this is legally required (Impressumspflicht).",
            "whyMatters": "In DACH countries, a missing Impressum can trigger fines and competitor cease-and-desist letters. For all EU stores, identifying the data controller is a GDPR Article 13 requirement."
          },
          {
            "i18n": {
              "key": "gdpr.terms.warning"
            },
            "name": "Terms & Conditions Page",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Create Terms & Conditions (AGB) covering: ordering process, payment, delivery, returns, warranty, and dispute resolution. Link it from the footer and checkout.",
            "whyMatters": "EU Consumer Rights Directive requires clear terms before purchase. Missing T&C means customers can claim they weren't informed, giving them extended cancellation rights."
          },
          {
            "i18n": {
              "key": "gdpr.mixed-content.pass"
            },
            "name": "Data Encryption (No Mixed Content)",
            "value": "All resources loaded over HTTPS",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "gdpr.personal-data.warning",
              "params": {
                "count": 1,
                "sample": "php@fosstodon.org"
              }
            },
            "name": "Personal Data Exposure in Source",
            "value": "1 personal email(s) in page source: php@fosstodon.org",
            "status": "warning",
            "evidence": {
              "sample": "php@fosstodon.org",
              "source": "HTML-heuristic"
            },
            "howToFix": "Remove person-named email addresses (e.g. firstname.lastname@) from the public HTML. Use role mailboxes (info@, sales@) or a contact form instead.",
            "legalRefs": {
              "gdpr": [
                "Art. 5(1)(f)",
                "Art. 32",
                "Art. 33"
              ],
              "skLaw": [
                "§ 39",
                "§ 40"
              ],
              "verified": [
                {
                  "title": "Zásady spracúvania osobných údajov",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 5 — Zásady spracúvania osobných údajov 1. Osobné údaje musia byť: (a) spracúvané zákonným spôsobom, spravodlivo a transparentne vo vzťahu k dotknutej osobe („zákonnosť, spravodlivosť a transparentnosť“); (b) získavané na konkrétne u",
                  "citation": "čl. 5 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Bezpečnosť spracúvania",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 32 — Bezpečnosť spracúvania 1. Prevádzkovateľ a sprostredkovateľ prijmú so zreteľom na najnovšie poznatky, náklady na vykonanie opatrení a na povahu, rozsah, kontext a účely spracúvania, ako aj na riziká s rôznou pravdepodobnosťou a",
                  "citation": "čl. 32 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Oznámenie porušenia ochrany osobných údajov dozornému orgánu",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 33 — Oznámenie porušenia ochrany osobných údajov dozornému orgánu 1. V prípade porušenia ochrany osobných údajov prevádzkovateľ bez zbytočného odkladu a podľa možnosti najneskôr do 72 hodín po tom, čo sa o tejto skutočnosti dozvedel",
                  "citation": "čl. 33 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Bezpečnosť spracúvania",
                  "excerpt": "§ 39 Bezpečnosť spracúvania (1) Prevádzkovateľ a sprostredkovateľ sú povinní prijať so zreteľom na najnovšie poznatky, na náklady na vykonanie opatrení, na povahu, rozsah, kontext a účel spracúvania osobných údajov a na riziká s rôznou prav",
                  "citation": "§39 ods. 1 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                },
                {
                  "title": "Oznámenie porušenia ochrany osobných údajov úradu",
                  "excerpt": "§ 40 Oznámenie porušenia ochrany osobných údajov úradu (4) Oznámenie podľa odseku 1 musí obsahovať najmä a) opis povahy porušenia ochrany osobných údajov vrátane, ak je to možné, kategórií a približného počtu dotknutých osôb, ktorých sa por",
                  "citation": "§40 ods. 4 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            },
            "confidence": "low",
            "whyMatters": "A named individual's email is personal data under GDPR Art. 4(1); publishing it in source breaches data minimisation (Art. 5(1)(c)). Role mailboxes like info@ are intentionally public and are not flagged here."
          },
          {
            "i18n": {
              "key": "gdpr.erasure.warning"
            },
            "name": "Right to Erasure (Data Deletion)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Provide a clear mechanism for users to request data deletion — either a dedicated page, a form, or explicit instructions in your privacy policy. Include a 'Delete my account' option in user settings.",
            "legalRefs": {
              "gdpr": [
                "Art. 17"
              ],
              "skLaw": [
                "§ 23"
              ],
              "verified": [
                {
                  "title": "Právo na vymazanie (právo „na zabudnutie“)",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 17 — Právo na vymazanie (právo „na zabudnutie“) 1. Dotknutá osoba má tiež právo dosiahnuť u prevádzkovateľa bez zbytočného odkladu vymazanie osobných údajov, ktoré sa jej týkajú, a prevádzkovateľ je povinný bez zbytočného odkladu vy",
                  "citation": "čl. 17 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Právo na výmaz osobných údajov",
                  "excerpt": "§ 23 Právo na výmaz osobných údajov (1) Dotknutá osoba má právo na to, aby prevádzkovateľ bez zbytočného odkladu vymazal osobné údaje, ktoré sa jej týkajú.",
                  "citation": "§23 ods. 1 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            },
            "whyMatters": "GDPR Article 17 gives users the 'right to be forgotten.' EU regulators expect a clear, accessible process, and obstructing erasure requests is a documented enforcement finding."
          },
          {
            "i18n": {
              "key": "gdpr.dpo.warning"
            },
            "name": "Data Protection Officer Contact",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add DPO contact details (or privacy contact if DPO not required) to your privacy policy and footer. Include: name/title, email (e.g., dpo@yourdomain.com), and postal address.",
            "whyMatters": "GDPR Article 37 requires a DPO for organizations processing personal data at scale. Even if not mandatory, having a designated privacy contact builds trust and is expected by regulators."
          },
          {
            "i18n": {
              "key": "gdpr.withdrawal.warning"
            },
            "name": "Withdrawal of Consent Mechanism",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Provide a clear way to withdraw consent: an 'unsubscribe' link in emails, a 'cookie settings' button in the footer, and a 'revoke consent' section in your privacy policy.",
            "legalRefs": {
              "gdpr": [
                "Art. 7(3)"
              ],
              "skLaw": [
                "§ 14(4)"
              ],
              "verified": [
                {
                  "title": "Podmienky vyjadrenia súhlasu",
                  "source": "Zdroj: EUR-Lex (eur-lex.europa.eu), © Európska únia, 1998–2026. Autentické je iba znenie publikované v elektronickom Úradnom vestníku Európskej únie.",
                  "excerpt": "Article 7 — Podmienky vyjadrenia súhlasu 1. Ak je spracúvanie založené na súhlase, prevádzkovateľ musí vedieť preukázať, že dotknutá osoba vyjadrila súhlas so spracúvaním svojich osobných údajov. 2. Ak dá dotknutá osoba súhlas v rámci písom",
                  "citation": "čl. 7 nariadenia (EÚ) 2016/679",
                  "jurisdiction": "eu"
                },
                {
                  "title": "Podmienky poskytnutia súhlasu so spracúvaním osobných údajov",
                  "excerpt": "§ 14 Podmienky poskytnutia súhlasu so spracúvaním osobných údajov (1) Ak je spracúvanie osobných údajov založené na súhlase dotknutej osoby, prevádzkovateľ je povinný kedykoľvek vedieť preukázať, že dotknutá osoba poskytla súhlas so spracúv",
                  "citation": "§14 zákona č. 18/2018 Z.z.",
                  "jurisdiction": "sk"
                }
              ]
            },
            "whyMatters": "GDPR Article 7(3): 'It shall be as easy to withdraw as to give consent.' If users can subscribe in one click, unsubscribing must be equally simple. Missing this is a common regulatory finding."
          }
        ]
      },
      "nis2": {
        "score": -1,
        "checks": [
          {
            "i18n": {
              "key": "nis2.scope.unknown"
            },
            "name": "NIS2 Compliance",
            "value": "Scope undetermined — IČO/company enrichment unavailable for this domain.",
            "status": "info",
            "howToFix": "",
            "whyMatters": ""
          }
        ]
      },
      "mobile": {
        "score": 88,
        "checks": [
          {
            "i18n": {
              "key": "mob.viewport.pass"
            },
            "name": "Viewport Configuration",
            "value": "width=device-width, initial-scale=1",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "mob.perf.pass",
              "params": {
                "score": 99
              }
            },
            "name": "Mobile Performance Score",
            "value": "99/100 — excellent",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "i18n": {
              "key": "mob.taptarget.warning"
            },
            "name": "Touch Target Size",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Ensure ALL interactive elements (buttons, links, form fields) are at least 48×48px with 8px minimum spacing between them. Pay special attention to: navigation menus, filter buttons, product variant selectors, and footer links.",
            "whyMatters": "Small tap targets cause mis-taps on mobile. In e-commerce, a mis-tap on 'Remove from cart' instead of 'Checkout' directly loses revenue."
          },
          {
            "i18n": {
              "key": "mob.fontsize.warning"
            },
            "name": "Font Size Readability",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Set minimum 16px font size for body text. Use relative units (rem/em) instead of px for scalability. Product titles: 18px+, prices: 20px+, CTAs: 16px+ with bold.",
            "whyMatters": "Text smaller than 16px forces mobile users to pinch-zoom. This breaks the responsive layout and creates a frustrating experience."
          },
          {
            "i18n": {
              "key": "mob.contentwidth.pass"
            },
            "name": "Content Fits Viewport",
            "value": "No horizontal scrolling needed",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "mob.responsive.warning"
            },
            "name": "Responsive Design Techniques",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Implement responsive CSS with @media queries for key breakpoints: 480px (small mobile), 768px (tablet), 1024px (laptop). Use Flexbox and CSS Grid for fluid layouts.",
            "whyMatters": "Non-responsive sites are automatically penalized by Google in mobile search results. With mobile-first indexing, this is a critical ranking factor."
          },
          {
            "i18n": {
              "key": "mob.themecolor.warning"
            },
            "name": "Theme Color",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add <meta name='theme-color' content='#your-brand-color'> to match your brand. Browsers use this to color the address bar, task switcher, and PWA chrome.",
            "whyMatters": "Theme-color creates a polished, branded mobile experience. It makes your site look native and professional."
          },
          {
            "i18n": {
              "key": "mob.nav.pass"
            },
            "name": "Mobile Navigation (Semantic)",
            "value": "<nav> element present — proper navigation landmark",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "mob.srcset.warning",
              "params": {
                "count": 4
              }
            },
            "name": "Responsive Images (srcset)",
            "value": "4 images without responsive sizing",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add srcset and sizes attributes to <img> tags to serve appropriately sized images for each screen. Mobile devices shouldn't download 1920px desktop images.",
            "whyMatters": "Without srcset, mobile users download full-size desktop images, wasting bandwidth. Responsive images are the single biggest mobile performance win for image-heavy sites."
          },
          {
            "i18n": {
              "key": "mob.inputtypes.pass",
              "params": {
                "optimized": "2 search"
              }
            },
            "name": "Form Input Types",
            "value": "Optimized: 2 search",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "mob.textoverflow.warning"
            },
            "name": "Text Overflow Handling",
            "value": "No word-break/overflow-wrap CSS detected",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add 'overflow-wrap: break-word' to your body or main content container. Without it, long URLs, product SKUs, or German compound words can break mobile layouts.",
            "whyMatters": "Long strings without word-break cause horizontal overflow on mobile — a common cause of 'content wider than viewport' failures. Compound words and URLs are frequent culprits."
          },
          {
            "i18n": {
              "key": "mob.wcaglabels.pass",
              "params": {
                "total": 2
              }
            },
            "name": "Form Input Labels (WCAG 3.3.2)",
            "value": "2/2 inputs majú label",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "mob.wcaglinks.pass"
            },
            "name": "Link Text Quality (WCAG 2.4.4)",
            "value": "Všetky odkazy majú popisný text",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          }
        ]
      },
      "company": null,
      "modules": [],
      "security": {
        "score": 66,
        "checks": [
          {
            "i18n": {
              "key": "sec.ssl.pass"
            },
            "name": "SSL/TLS Certificate",
            "value": "Valid HTTPS connection established",
            "status": "pass",
            "evidence": {
              "source": "SSL"
            }
          },
          {
            "i18n": {
              "key": "sec.dnssec.warning"
            },
            "name": "DNSSEC",
            "value": "No DNSKEY records — zone is unsigned",
            "status": "warning",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "DNSSEC setup help →"
            },
            "evidence": {
              "source": "DNS"
            },
            "howToFix": "Enable DNSSEC at your DNS host (most modern registrars offer 1-click activation: Cloudflare, Route 53, Google Cloud DNS, web.sk, websupport.sk). Verify via dnsviz.net afterwards.",
            "whyMatters": "Without DNSSEC, attackers controlling intermediate resolvers can forge responses for your domain — sending users to phishing sites with valid HTTPS that match your name. EU national CSIRTs (SK-CERT, NÚKIB) recommend DNSSEC for all in-scope entities."
          },
          {
            "i18n": {
              "key": "sec.caa.warning"
            },
            "name": "CAA DNS Record",
            "value": "No CAA records — any CA can issue certificates for this domain",
            "status": "warning",
            "evidence": {
              "source": "DNS"
            },
            "howToFix": "Publish CAA TXT records pinning your CA. For Let's Encrypt: `0 issue \"letsencrypt.org\"`. For multiple CAs add additional `0 issue \"...\"` records. Add `0 iodef \"mailto:security@yourdomain.tld\"` for misissuance reports.",
            "whyMatters": "CAA records limit which Certificate Authorities can issue certificates for your domain. Without CAA, a compromised or rogue CA can issue valid certs that browsers will trust — a documented breach pattern (DigiNotar 2011, Symantec 2017)."
          },
          {
            "i18n": {
              "key": "sec.https-redirect.pass"
            },
            "name": "HTTP → HTTPS Redirect",
            "value": "HTTP properly redirects to HTTPS",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "i18n": {
              "key": "sec.hsts.warning",
              "params": {
                "detail": "max-age too short (15768000s, need 31536000), missing includeSubDomains"
              }
            },
            "name": "HSTS (Strict-Transport-Security)",
            "value": "max-age too short (15768000s, need 31536000), missing includeSubDomains",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Set: Strict-Transport-Security: max-age=31536000; includeSubDomains; preload — then submit to hstspreload.org for browser preloading.",
            "whyMatters": "Weak HSTS can still allow SSL stripping attacks on the first connection. Full HSTS with preload makes your site HTTPS-only in every browser."
          },
          {
            "i18n": {
              "key": "sec.csp.fail"
            },
            "name": "Content-Security-Policy (CSP)",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Security Hardening →"
            },
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Implement a CSP header. Start with: Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: — then gradually tighten.",
            "whyMatters": "CSP is a strong defense against XSS attacks. Without it, any injected script runs with full privileges. CSP blocks inline script injection."
          },
          {
            "i18n": {
              "key": "sec.clickjacking.pass",
              "params": {
                "detail": "SAMEORIGIN"
              }
            },
            "name": "Clickjacking Protection",
            "value": "X-Frame-Options: SAMEORIGIN",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "i18n": {
              "key": "sec.x-content-type.warning"
            },
            "name": "X-Content-Type-Options",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Add header: X-Content-Type-Options: nosniff",
            "whyMatters": "Without nosniff, browsers may execute uploaded files as scripts. An attacker could upload a .jpg that's actually JavaScript and trick the browser into running it."
          },
          {
            "i18n": {
              "key": "sec.referrer-policy.warning"
            },
            "name": "Referrer-Policy",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Add header: Referrer-Policy: strict-origin-when-cross-origin — this is the best balance between functionality and privacy.",
            "whyMatters": "Without a referrer policy, browsers send the full URL to third parties. This can leak sensitive data like session tokens in URLs or internal page paths."
          },
          {
            "i18n": {
              "key": "sec.permissions-policy.pass",
              "params": {
                "detail": "interest-cohort=()"
              }
            },
            "name": "Permissions-Policy",
            "value": "interest-cohort=()",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "i18n": {
              "key": "sec.cookie-flags.warning",
              "params": {
                "count": 1,
                "missing": "1 missing Secure, 1 missing HttpOnly, 1 missing SameSite"
              }
            },
            "name": "Cookie Security Flags",
            "value": "1 cookie(s): 1 missing Secure, 1 missing HttpOnly, 1 missing SameSite",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Set all cookies with: Secure (HTTPS only), HttpOnly (no JS access), SameSite=Lax or Strict (CSRF protection). Session cookies MUST have all three.",
            "whyMatters": "Missing Secure flag = cookies sent over HTTP (stealable on WiFi). Missing HttpOnly = cookies readable by XSS. Missing SameSite = vulnerable to CSRF attacks."
          },
          {
            "i18n": {
              "key": "sec.tech-disclosure.warning",
              "params": {
                "detail": "Server: BunnyCDN-DE1-1331"
              }
            },
            "name": "Technology Disclosure",
            "value": "Server: BunnyCDN-DE1-1331",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Hide server version: set ServerTokens Prod (Apache) or server_tokens off (Nginx). Remove X-Powered-By header completely.",
            "whyMatters": "Exposing exact server/PHP versions lets attackers search CVE databases for specific exploits. This is the first step in most automated attacks."
          },
          {
            "i18n": {
              "key": "sec.sri.pass-none"
            },
            "name": "Subresource Integrity (SRI)",
            "value": "No SRI-eligible third-party scripts loaded",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "sec.security-txt.pass"
            },
            "name": "security.txt (RFC 9116)",
            "value": "Present at /.well-known/security.txt",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "i18n": {
              "key": "sec.server-version.pass",
              "params": {
                "name": "BunnyCDN-DE1-1331"
              }
            },
            "name": "Server Version Disclosure",
            "value": "BunnyCDN-DE1-1331 — version hidden",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "i18n": {
              "key": "sec.cdn.warning"
            },
            "name": "CDN / WAF Protection",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Add a CDN/WAF like Cloudflare (free tier), Sucuri, or Fastly. They provide DDoS protection, bot filtering, and SSL management.",
            "whyMatters": "Without a CDN/WAF, your origin server is directly exposed to DDoS attacks, bot traffic, and brute-force attempts."
          }
        ]
      },
      "tech_stack": [
        {
          "name": "jQuery",
          "version": "3.6.0",
          "category": "js-library",
          "outdated": false
        },
        {
          "name": "Font Awesome",
          "category": "js-library"
        },
        {
          "name": "Vite",
          "category": "js-library"
        },
        {
          "name": "BunnyCDN-DE1-1331",
          "category": "server"
        }
      ],
      "performance": {
        "score": 91,
        "checks": [
          {
            "i18n": {
              "key": "perf.ttfb.pass",
              "params": {
                "ms": 8
              }
            },
            "name": "Server Response Time (TTFB)",
            "value": "8ms",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "i18n": {
              "key": "perf.fcp.pass",
              "params": {
                "s": "0.26"
              }
            },
            "name": "First Contentful Paint (FCP)",
            "value": "0.26s",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "i18n": {
              "key": "perf.lcp.pass",
              "params": {
                "s": "0.48"
              }
            },
            "name": "Largest Contentful Paint (LCP)",
            "value": "0.48s — Core Web Vital ✓",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "i18n": {
              "key": "perf.tbt.pass",
              "params": {
                "ms": 142
              }
            },
            "name": "Total Blocking Time (TBT)",
            "value": "142ms",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "i18n": {
              "key": "perf.cls.pass",
              "params": {
                "cls": "0.002"
              }
            },
            "name": "Cumulative Layout Shift (CLS)",
            "value": "0.002 — Core Web Vital ✓",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "i18n": {
              "key": "perf.speed-index.pass",
              "params": {
                "s": "0.94"
              }
            },
            "name": "Speed Index",
            "value": "0.94s",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "i18n": {
              "key": "perf.page-weight.pass",
              "params": {
                "size": "925 KB",
                "requests": 26
              }
            },
            "name": "Total Page Weight",
            "value": "925 KB (26 requests)",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "i18n": {
              "key": "perf.render-blocking.info"
            },
            "name": "Render-blocking Resources",
            "value": "Not measured — PageSpeed did not return the render-blocking audit for this URL",
            "status": "info",
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "Re-run the scan, or test directly at PageSpeed Insights. This metric needs a successful Lighthouse lab run."
          },
          {
            "i18n": {
              "key": "perf.unused-code.pass",
              "params": {
                "kb": 34
              }
            },
            "name": "Unused Code (CSS + JS)",
            "value": "Only 34 KB of unused code — well optimized",
            "status": "pass",
            "evidence": {
              "source": "PSI-lab"
            }
          },
          {
            "i18n": {
              "key": "perf.text-compression.pass"
            },
            "name": "Text Compression (gzip/brotli)",
            "value": "All text resources properly compressed",
            "status": "pass",
            "evidence": {
              "source": "HTTP-header"
            }
          },
          {
            "i18n": {
              "key": "perf.resource-hints.warning"
            },
            "name": "Resource Hints (Preload/Preconnect)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add resource hints: <link rel='preconnect' href='https://fonts.googleapis.com'> for third-party origins, <link rel='preload' as='image' href='hero.webp'> for critical resources.",
            "whyMatters": "Preconnect saves 100-500ms per third-party origin by establishing connections early. Preload starts downloading critical resources before the browser discovers them in CSS/JS."
          },
          {
            "i18n": {
              "key": "perf.lazy-load.warning",
              "params": {
                "total": 4
              }
            },
            "name": "Lazy Loading",
            "value": "4 images without lazy loading",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add loading='lazy' to all images below the fold. Keep the hero/LCP image eager-loaded. Native lazy loading is supported by all modern browsers.",
            "whyMatters": "Without lazy loading, ALL images download on page load — even those never scrolled to. On a product page with 20 images, lazy loading can save most of the initial download."
          },
          {
            "i18n": {
              "key": "perf.script-strategy.fail",
              "params": {
                "rate": 14,
                "total": 7,
                "blocking": 6
              }
            },
            "name": "Script Loading Strategy",
            "value": "Only 14% of 7 scripts optimized — most are render-blocking",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Performance Optimization →"
            },
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add defer or async to all <script src='...'> tags. Render-blocking scripts are a leading cause of slow FCP. Defer maintains execution order, async does not.",
            "whyMatters": "6 render-blocking scripts can add 1-3 seconds to page load. Each synchronous script creates a sequential download-parse-execute chain."
          },
          {
            "i18n": {
              "key": "perf.css-count.fail",
              "params": {
                "count": 10
              }
            },
            "name": "CSS File Count",
            "value": "10 CSS files — too many!",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Bundle your CSS files into 1-3 files maximum. Use a build tool (Webpack, Vite, Gulp) to concatenate and minify. Critical CSS should be inlined, the rest deferred.",
            "whyMatters": "Each CSS file blocks rendering. With 10 files, the browser must download all of them before painting anything. This can add 1-2+ seconds on mobile networks."
          },
          {
            "i18n": {
              "key": "perf.critical-css.warning",
              "params": {
                "count": 10
              }
            },
            "name": "Critical CSS Strategy",
            "value": "10 CSS files without critical CSS extraction",
            "status": "warning",
            "evidence": {
              "source": "PSI-lab"
            },
            "howToFix": "Extract critical above-the-fold CSS and inline it in <head>. Load remaining CSS asynchronously: <link rel='preload' href='styles.css' as='style' onload='this.rel=\"stylesheet\"'>.",
            "whyMatters": "Render-blocking CSS delays first paint. Inlining critical CSS eliminates the render-blocking round trip — the biggest FCP improvement for CSS-heavy sites."
          }
        ]
      },
      "ai_readiness": {
        "score": 49,
        "checks": [
          {
            "i18n": {
              "key": "air.bot-access.pass",
              "params": {
                "detail": "No AI bot restrictions (allowed by default)"
              }
            },
            "name": "AI Bot Access Policy",
            "value": "No AI bot restrictions (allowed by default)",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "i18n": {
              "key": "air.llms-txt.fail"
            },
            "name": "llms.txt (AI Site Descriptor)",
            "value": "Not present — not required for AI visibility",
            "status": "info",
            "fixLink": {
              "url": "https://llmstxt.org",
              "label": "About llms.txt →"
            },
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Optional: /llms.txt (a Markdown site descriptor per llmstxt.org) is future-proofing, mainly consumed by coding/IDE agents. It does NOT affect whether ChatGPT/Perplexity/Gemini cite your store. Prioritize AI-crawler access, server-rendered content, statistics and cited sources instead.",
            "whyMatters": "No answer engine consumes llms.txt for AI-search citation today (2026) — adoption is ~8.7% and Google declined to support it. It's optional future-proofing, mainly read by coding/IDE agents. Prioritize AI-crawler access, server-rendered content, statistics and cited sources instead. See /ai-readiness-methodology.md."
          },
          {
            "i18n": {
              "key": "air.llms-full.warning"
            },
            "name": "llms-full.txt (Complete AI Content)",
            "value": "Not present — not required for AI visibility",
            "status": "info",
            "evidence": {
              "source": "file-probe"
            },
            "whyMatters": "No answer engine consumes llms.txt for AI-search citation today (2026) — adoption is ~8.7% and Google declined to support it. It's optional future-proofing, mainly read by coding/IDE agents. Prioritize AI-crawler access, server-rendered content, statistics and cited sources instead. See /ai-readiness-methodology.md."
          },
          {
            "i18n": {
              "key": "air.content-access.pass",
              "params": {
                "ratio": "26.8",
                "words": 2001
              }
            },
            "name": "Content Accessibility for AI",
            "value": "2001 words in raw HTML (26.8% text ratio) — readable by AI crawlers without executing JS",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.schema-foundation.fail"
            },
            "name": "Structured Data Foundation",
            "status": "fail",
            "fixLink": {
              "url": "https://zulien.sk",
              "label": "Add structured data →"
            },
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Add JSON-LD structured data immediately. Priority order: 1) Organization, 2) Product (with offers), 3) BreadcrumbList, 4) WebSite+SearchAction, 5) FAQPage. Use JSON-LD format exclusively — not Microdata or RDFa.",
            "whyMatters": "Without structured data, your store is invisible to AI commerce. Google AI Overviews, ChatGPT Shopping, Perplexity, and Bing Copilot all rely on schema markup to understand and recommend products."
          },
          {
            "i18n": {
              "key": "air.org-schema.fail"
            },
            "name": "Organization Schema + Entity Linking",
            "status": "fail",
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Add Organization (or LocalBusiness for physical stores) schema with: name, logo, url, description, contactPoint, address, and sameAs linking to all your official profiles (LinkedIn, Facebook, Wikipedia if available).",
            "whyMatters": "Organization schema is the foundation of your AI identity. Without it, AI assistants can't confidently attribute information to your brand, verify your legitimacy, or show your Knowledge Panel."
          },
          {
            "i18n": {
              "key": "air.faq-schema.warning"
            },
            "name": "FAQ Schema (Direct AI Answers)",
            "status": "warning",
            "evidence": {
              "source": "schema"
            },
            "howToFix": "Add FAQPage schema to every product page and category page. Include 3-5 Q&As per page covering: product specifications, shipping, returns, usage instructions. Format: question (full sentence) + answer (75-150 words).",
            "whyMatters": "ChatGPT, Perplexity, and Google AI Overviews pull FAQ answers verbatim. FAQ schema is one of the fastest ways to get your content cited by AI."
          },
          {
            "i18n": {
              "key": "air.content-depth.pass",
              "params": {
                "words": 2001
              }
            },
            "name": "Content Depth for AI",
            "value": "2001 words — rich content for AI analysis and citation",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.answer-first.pass",
              "params": {
                "words": 249
              }
            },
            "name": "Answer-First Content Format",
            "value": "First paragraph: 249 words — good content density above the fold",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.headings.fail",
              "params": {
                "h1": 0,
                "h2": 25,
                "h3": 0
              }
            },
            "name": "Heading Hierarchy for AI",
            "value": "0 H1, 25 H2, 0 H3 — poor structure",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Use exactly 1 H1 (page title), then organize content with H2 sections and H3 subsections. Each heading should describe the content that follows. Never skip heading levels (H1→H3 without H2).",
            "whyMatters": "AI extracts information based on heading structure. Pages with proper H1→H2→H3 hierarchy are parsed more accurately by ChatGPT, Perplexity, and Google AI Overviews. Without it, AI may misinterpret your content."
          },
          {
            "i18n": {
              "key": "air.semantic-html.pass",
              "params": {
                "count": 5,
                "elements": "<article>, <nav>, <header>, <footer>, <aside>"
              }
            },
            "name": "Semantic HTML Structure",
            "value": "5/6 semantic elements: <article>, <nav>, <header>, <footer>, <aside>",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.structured-content.warning-partial",
              "params": {
                "what": "7 lists",
                "missing": "comparison tables"
              }
            },
            "name": "Structured Content (Lists & Tables)",
            "value": "7 lists found — consider adding comparison tables",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add comparison tables to your content. Use <ul>/<ol> for feature lists, specifications, and benefits. Use <table> for product comparisons, pricing tiers, and specifications. AI extracts structured content much faster than paragraphs.",
            "whyMatters": "AI models are biased toward extracting data from HTML lists and tables. Perplexity and ChatGPT pull bullet points and table data with higher accuracy than paragraph text."
          },
          {
            "i18n": {
              "key": "air.freshness.warning-novisible"
            },
            "name": "Content Freshness Signals",
            "value": "Visible date found but not in structured data",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add both: 1) dateModified and datePublished in your Article/Product JSON-LD schema, 2) A visible 'Last updated: [date]' on the page. Both signals reinforce content freshness for AI.",
            "whyMatters": "AI models weight recency in their citation algorithms. Freshness signals tell AI your content is current and reliable."
          },
          {
            "i18n": {
              "key": "air.entity-clarity.fail"
            },
            "name": "Entity Clarity & Brand Signals",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Your brand has weak entity signals. Add: 1) Complete OG meta tags, 2) Organization schema with sameAs linking to all official profiles, 3) Consistent NAP (Name, Address, Phone) across the web.",
            "whyMatters": "AI assistants must be confident about entity identity before making recommendations. Without clear brand signals, AI defaults to better-known competitors."
          },
          {
            "i18n": {
              "key": "air.eeat.warning-noarticle"
            },
            "name": "Author Expertise Signals (E-E-A-T)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "For content pages (blog, guides, about): add Article/BlogPosting schema with author property linking to Person schema. Include the author's jobTitle, credentials, and social profiles.",
            "whyMatters": "AI models weight author expertise heavily. Pages from identified experts get cited more than anonymous content. This is especially important for product guides, reviews, and advice content."
          },
          {
            "i18n": {
              "key": "air.extractable.warning-short",
              "params": {
                "avg": 21,
                "count": 82
              }
            },
            "name": "Extractable Answer Blocks",
            "value": "82 paragraphs, avg 21 words — too short for citation",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Optimal paragraphs for AI citation are 40-80 words. Break long paragraphs into focused, self-contained answer blocks. Each should make one clear point that AI can extract and quote.",
            "whyMatters": "AI extracts individual paragraphs as answer snippets — dense walls of text get skipped. Focused 40-80 word paragraphs are the most citable."
          },
          {
            "i18n": {
              "key": "air.statistics.warning-none"
            },
            "name": "Statistics & Data Presence",
            "value": "No statistical data found in content",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add numbers: pricing comparisons, performance metrics, customer statistics, industry benchmarks. Specific data (e.g., '99.9% uptime', '4.8/5 rating from 2,400 reviews') is what AI quotes most.",
            "whyMatters": "Content without data is harder to cite. Perplexity and ChatGPT specifically seek pages with quantified claims and verifiable statistics."
          },
          {
            "i18n": {
              "key": "air.section-length.warning",
              "params": {
                "avg": 69,
                "ratio": 8
              }
            },
            "name": "Section Length Optimization",
            "value": "Avg section: 69 words — only 8% in 80-200 word optimal range",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Restructure content into sections of 120-180 words between H2/H3 headings. Each section should cover one topic completely. Split sections over 300 words, expand sections under 80 words.",
            "whyMatters": "For Google AI Overviews, 100-150 words per section is the sweet spot — long sections get skipped and very short ones lack substance."
          },
          {
            "i18n": {
              "key": "air.qa-headings.warning-none"
            },
            "name": "Q&A Format Headings",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add H2/H3 headings phrased as questions your customers ask: 'How much does shipping cost?', 'What sizes are available?', 'How do I return an item?' Follow each with a direct, concise answer.",
            "whyMatters": "Q&A content format matches how people query AI assistants. Without question-format headings, your content is harder for AI to map to user queries."
          },
          {
            "i18n": {
              "key": "air.question-coverage.fail",
              "params": {
                "n": 1,
                "labels": ": availability"
              }
            },
            "name": "Common Question Coverage",
            "value": "Answers only 1/5 key shopper questions: availability",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Your page barely addresses core shopper questions. Add sections covering price, shipping (options + cost), returns/refunds, availability, and payment methods — as visible text, not just in schema. Link to a dedicated FAQ, Shipping, and Returns page.",
            "whyMatters": "AI assistants answer shopping queries by fanning out into price/shipping/returns/availability/payment sub-questions. A page that answers none of them is invisible in AI shopping answers and reads as untrustworthy to buyers."
          },
          {
            "i18n": {
              "key": "air.internal-links.warning",
              "params": {
                "detail": "only 2/1000w (target: 3-5)"
              }
            },
            "name": "Internal Link Density",
            "value": "only 2/1000w (target: 3-5)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add 3-5 contextual internal links per 1,000 words using descriptive anchor text. Link to related products, categories, and guides. Replace generic anchors ('click here', 'read more') with descriptive text.",
            "whyMatters": "Internal links create an implicit knowledge graph for AI crawlers. Each contextual link teaches AI about content relationships. AI models navigate internal links to build comprehensive understanding of your store."
          },
          {
            "i18n": {
              "key": "air.canonical.warning-different",
              "params": {
                "url": "https://www.php.net/index.php"
              }
            },
            "name": "Canonical Tag for AI Deduplication",
            "value": "Canonical points to different URL: https://www.php.net/index.php",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Verify this canonical is intentional. AI models cluster near-duplicate URLs and choose one representative page. If canonical points to a different URL, AI will only index that target URL, not this page.",
            "whyMatters": "AI search engines (ChatGPT, Perplexity, Bing Copilot) use canonicals to deduplicate content. A wrong canonical means AI may cite the wrong page version or ignore this page entirely."
          },
          {
            "i18n": {
              "key": "air.kg-readiness.fail"
            },
            "name": "Knowledge Graph Readiness",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Build your Knowledge Graph entity: 1) Add @id to Organization JSON-LD, 2) Use identical brand name in title, schema, and OG, 3) Add sameAs to Wikipedia/Wikidata/LinkedIn, 4) Use multiple corroborating schema types.",
            "whyMatters": "Without Knowledge Graph signals, AI treats your brand as unverified. You won't get a Google Knowledge Panel, and AI assistants can't confidently attribute information to your brand."
          },
          {
            "i18n": {
              "key": "air.readability.pass-general",
              "params": {
                "grade": 8
              }
            },
            "name": "Content Readability for AI",
            "value": "Flesch-Kincaid Grade 8 — accessible and clear",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "air.alt-text.fail",
              "params": {
                "pct": 0,
                "poor": 3,
                "missing": 1
              }
            },
            "name": "Image Alt Text Quality for AI",
            "value": "Only 0% quality alt text — 1 missing, 3 poor",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Audit all images: add descriptive alt text (3-15 words) to every <img>. Include product names, features, materials, colors. This is critical for visual AI search and accessibility compliance.",
            "whyMatters": "Poor alt text means your product images are invisible to AI visual search (Google Lens, Bing Visual Search). This is also an accessibility requirement (WCAG 2.1 AA) — many regions enforce this legally."
          },
          {
            "i18n": {
              "key": "air.expert-quotes.warning-none"
            },
            "name": "Expert Quotations & Citations",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add 2-3 expert quotes or data citations per major page. Use <blockquote> for quotes and link to authoritative sources (.gov, .edu, Wikipedia, industry reports).",
            "whyMatters": "Content without citations or expert quotes appears unverified to AI. AI assistants prefer content backed by named sources, data references, and expert opinions."
          },
          {
            "i18n": {
              "key": "air.ai-txt.warning"
            },
            "name": "ai.txt (AI Permissions)",
            "value": "Not present — optional; AI-bot permissions are enforced via robots.txt, not ai.txt",
            "status": "info",
            "evidence": {
              "source": "file-probe"
            },
            "whyMatters": "ai.txt is an emerging fine-grained AI-permissions proposal not yet honored by the major engines. The robots.txt AI-bot rules are the signal that actually gates crawler access."
          },
          {
            "i18n": {
              "key": "air.webmcp.warning"
            },
            "name": "WebMCP Agentic Readiness",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "WebMCP (W3C Community Group standard, Chrome 146+) lets pages declare structured tools for AI agents. Add toolname and tooldescription attributes to <form> elements, or include a <script type='application/webmcp+json'> manifest.",
            "whyMatters": "WebMCP is how AI agents will interact with your store (search products, add to cart, check availability). Google and Microsoft are co-developing this standard."
          },
          {
            "i18n": {
              "key": "air.boilerplate.fail",
              "params": {
                "ratio": 3
              }
            },
            "name": "Content-to-Boilerplate Ratio",
            "value": "Only 3% in main content — mostly boilerplate",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Wrap your primary content in <main> or <article> tags. AI extracts content from these semantic containers — without them, your product descriptions are mixed with navigation and footer text.",
            "whyMatters": "Token density measures useful content vs noise. Pages with under 30% content ratio are hard for AI to parse — it can't find your content in the boilerplate."
          },
          {
            "i18n": {
              "key": "air.social-proof.warning-none"
            },
            "name": "Social Proof (Testimonials / Case Studies)",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add at least one form of social proof: 1) Client testimonials as <blockquote> with attribution, 2) Case study / portfolio section with past work, 3) 'Trusted by' client logo strip. For B2B, this is a leading credibility lever.",
            "whyMatters": "Without visible social proof, B2B prospects can't verify your track record before reaching out. Missing testimonials and case studies is a common reason consultancy sites lose qualified leads at the contact stage."
          },
          {
            "name": "Agent-Commerce Readiness",
            "value": "50/100 — čiastočne pripravené (Prístup 100 · Porozumenie 0 · Transakcia 50)",
            "status": "info",
            "whyMatters": "Či dokáže autonómny nákupný AI agent (ChatGPT operator, Perplexity, budúce agentické asistenty) na vašom obchode: prísť dnu, prečítať a porozumieť produktom, objaviť celý katalóg a konať (kôš, podmienky). Toto meria málokto — a pre SK/CZ shopy nikto. Skóre spája AI-bot prístup, Product schema, produktové feedy (Merchant/Heureka/Zboží), WebMCP a nákupné podmienky do jedného agent-first pohľadu. Nadväzuje na pripravovaný verejný MCP konektor (\"naskenuj tento obchod\")."
          },
          {
            "name": "Agent: Prístup — dostane sa agent dnu",
            "value": "100/100 (2 signály/-ov)",
            "status": "info"
          },
          {
            "name": "Agent: Porozumenie — rozumie produktom",
            "value": "0/100 (2 signály/-ov)",
            "status": "info"
          },
          {
            "name": "Agent: Transakcia — vie konať (kôš/podmienky)",
            "value": "50/100 (1 signál)",
            "status": "info"
          }
        ]
      },
      "phaseTimings": {
        "tail": 77,
        "total": 8298,
        "phase1": 976,
        "preflight": 6202,
        "phase1.dns": 193,
        "phase1.html": 169,
        "phase1.files": 972,
        "phase1.zbozi": 317,
        "phase1.headers": 121,
        "phase1.heureka": 404,
        "phase1.merchant": 421
      },
      "accessibility": {
        "score": 53,
        "checks": [
          {
            "i18n": {
              "key": "a11y.lang.pass",
              "params": {
                "lang": "en"
              }
            },
            "name": "Page Language",
            "value": "<html lang=\"en\"> is set",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "a11y.alt.warning",
              "params": {
                "total": 4,
                "missing": 1
              }
            },
            "name": "Image Alt Text",
            "value": "1 of 4 images missing alt text",
            "status": "warning",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add alt text to the remaining images (alt=\"\" for decorative ones).",
            "whyMatters": "Every image missing alt text is content a screen-reader user cannot access (WCAG 1.1.1 / EN 301 549 § 9.1.1.1)."
          },
          {
            "i18n": {
              "key": "a11y.forms.pass",
              "params": {
                "total": 2
              }
            },
            "name": "Form Labels",
            "value": "All 2 form inputs are labelled",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "a11y.headings.no-h1"
            },
            "name": "Heading Structure",
            "value": "The page has no <h1> heading",
            "status": "fail",
            "weight": 2,
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Accessibility audit — Inger →"
            },
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add exactly one <h1> describing the page, then use <h2>/<h3> in order without skipping levels.",
            "whyMatters": "Screen-reader users navigate by headings; a missing or broken heading outline forces them to read linearly. EN 301 549 § 9.1.3.1 / 9.2.4.6 (WCAG 1.3.1 / 2.4.6)."
          },
          {
            "i18n": {
              "key": "a11y.links.pass"
            },
            "name": "Link Text",
            "value": "Links use descriptive text",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "confidence": "low"
          },
          {
            "i18n": {
              "key": "a11y.landmarks.no-main"
            },
            "name": "Landmark Regions",
            "value": "No <main> landmark region found",
            "status": "fail",
            "weight": 1,
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Accessibility audit — Inger →"
            },
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Wrap the primary content in <main> and use <nav>, <header>, <footer> for the page regions.",
            "whyMatters": "Landmarks let assistive-tech users jump straight to the main content and skip repeated navigation. EN 301 549 § 9.1.3.1 (WCAG 1.3.1)."
          },
          {
            "i18n": {
              "key": "a11y.zoom.pass"
            },
            "name": "Zoom & Scaling",
            "value": "Pinch-zoom is not disabled",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "a11y.skiplink.missing"
            },
            "name": "Skip Link",
            "value": "No skip-to-content link detected",
            "status": "warning",
            "weight": 1,
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add a visually-hidden \"Skip to content\" link as the first focusable element, targeting <main id=\"main\">.",
            "confidence": "low",
            "whyMatters": "Keyboard and screen-reader users otherwise tab through the whole menu on every page. EN 301 549 § 9.2.4.1 (WCAG 2.4.1)."
          },
          {
            "i18n": {
              "key": "a11y.legal-basis"
            },
            "name": "EAA Legal Basis",
            "value": "In scope for the European Accessibility Act (in force 28.6.2025): SK zákon 351/2022 Z. z., CZ zákon 424/2023 Sb., Dir. (EU) 2019/882 — assessed against EN 301 549. Inger provides EAA remediation audits.",
            "status": "info",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Accessibility audit — Inger →"
            },
            "howToFix": "",
            "isUpsell": true,
            "whyMatters": ""
          }
        ]
      },
      "vulnerability": {
        "score": 68,
        "checks": [
          {
            "i18n": {
              "key": "vuln.cms-version.pass"
            },
            "name": "CMS Version Disclosure",
            "value": "No generator tag — CMS identity hidden",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "vuln.sensitive-files.fail",
              "params": {
                "files": "composer.json (dependency map)"
              }
            },
            "name": "Sensitive Files Exposed",
            "value": "composer.json (dependency map) — CRITICAL!",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Emergency Security Fix →"
            },
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "URGENT: Block these files immediately! Apache: add to .htaccess: <FilesMatch '\\.(env|git|json)$'>Require all denied</FilesMatch>. Nginx: location ~ /\\. { deny all; }",
            "whyMatters": ".env contains database passwords and API keys. .git/HEAD allows downloading your entire source code. composer.json reveals all dependencies and their versions. Exposed credentials are one of the most common ways shops get compromised."
          },
          {
            "i18n": {
              "key": "vuln.install-script.fail"
            },
            "name": "Install Script Exposed",
            "value": "/install/, /install.php or /setup/ still accessible — CRITICAL!",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Emergency Security Fix →"
            },
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Delete the install/ and setup/ directories from the web root immediately after CMS installation. Attackers can reset the database or re-run the installer to seize admin access.",
            "whyMatters": "Leftover install scripts are a textbook RCE vector. In PrestaShop, WordPress, and Magento, the installer can overwrite the database, create a new admin account, or inject malicious code. Automated bots constantly scan for /install/ on every e-shop."
          },
          {
            "i18n": {
              "key": "vuln.directory-listing.pass"
            },
            "name": "Directory Listing",
            "value": "Disabled — file structure hidden",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "i18n": {
              "key": "vuln.admin-url.pass"
            },
            "name": "Admin Panel at Default URL",
            "value": "Not found at common paths (/admin, /wp-admin, /administrator, /backoffice)",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "i18n": {
              "key": "vuln.debug-mode.pass"
            },
            "name": "Debug Mode / Error Exposure",
            "value": "No debug indicators found in page output",
            "status": "pass",
            "evidence": {
              "source": "HTML-heuristic"
            }
          },
          {
            "i18n": {
              "key": "vuln.jquery.pass",
              "params": {
                "version": "3.6.0"
              }
            },
            "name": "jQuery Version",
            "value": "jQuery 3.6.0",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "i18n": {
              "key": "vuln.csrf.fail",
              "params": {
                "count": 1
              }
            },
            "name": "Form CSRF Protection",
            "value": "1 form(s) without CSRF tokens",
            "status": "fail",
            "evidence": {
              "source": "HTML-heuristic"
            },
            "howToFix": "Add CSRF token validation to every form. Most CMS frameworks have built-in CSRF protection — make sure it's enabled on all forms, including search and newsletter signup.",
            "confidence": "low",
            "whyMatters": "CSRF is in the OWASP Top 10. Without tokens, attackers can craft pages that automatically submit forms on your site as the victim's browser session."
          },
          {
            "i18n": {
              "key": "vuln.package-json.warning"
            },
            "name": "package.json Exposed",
            "value": "package.json accessible — reveals all dependencies and versions",
            "status": "warning",
            "evidence": {
              "source": "file-probe"
            },
            "howToFix": "Block access to package.json via .htaccess or server config. It should never be served to the public.",
            "whyMatters": "package.json reveals your exact dependency versions, allowing attackers to search for known CVEs in each library. It's a complete vulnerability roadmap."
          },
          {
            "i18n": {
              "key": "vuln.spf.pass",
              "params": {
                "record": "v=spf1 ip4:140.211.15.143 ip4:45.112.84.5 ip4:142.93.197.176 ip6:2604:a880:400:d"
              }
            },
            "name": "SPF Record (Email Security)",
            "value": "SPF configured: v=spf1 ip4:140.211.15.143 ip4:45.112.84.5 ip4:142.93.197.176 ip6:2604:a880:400:d",
            "status": "pass",
            "evidence": {
              "source": "DNS"
            }
          },
          {
            "i18n": {
              "key": "vuln.dmarc.warning-none"
            },
            "name": "DMARC Policy (Email Auth)",
            "value": "DMARC set to p=none (monitoring only, no enforcement)",
            "status": "warning",
            "evidence": {
              "source": "DNS"
            },
            "howToFix": "Upgrade DMARC policy from p=none to p=quarantine or p=reject. p=none only monitors — it doesn't block spoofed emails. Start with quarantine, then move to reject after verifying legitimate emails pass.",
            "whyMatters": "DMARC p=none provides zero protection against email spoofing. It only generates reports. Move to p=quarantine to actually block forged emails from reaching your customers' inboxes."
          },
          {
            "i18n": {
              "key": "vuln.dkim.pass",
              "params": {
                "selectors": "mail"
              }
            },
            "name": "DKIM Signing (Email Auth)",
            "value": "DKIM configured (selectors: mail)",
            "status": "pass",
            "evidence": {
              "source": "file-probe"
            }
          },
          {
            "i18n": {
              "key": "vuln.cross-origin.warning"
            },
            "name": "Cross-Origin Isolation",
            "status": "warning",
            "evidence": {
              "source": "HTTP-header"
            },
            "howToFix": "Add Cross-Origin-Opener-Policy: same-origin and Cross-Origin-Resource-Policy: same-origin headers. These protect against Spectre-type side-channel attacks.",
            "whyMatters": "Without cross-origin isolation headers, your site is vulnerable to Spectre attacks that can leak sensitive data across browser tabs. These headers are required for SharedArrayBuffer and high-resolution timers."
          }
        ]
      },
      "executive_summary": {
        "en": "Your site has basic web health but is missing critical elements. Add an H1 heading to every page immediately. Your SEO foundation is relatively strong, giving you a solid base to build on.",
        "sk": "Váš web má základné webové zdravie, ale chýbajú mu kritické časti. Hneď pridajte H1 nadpis na každú stránku. Vaša SEO je relatívne silná, čím máte dobrý základ na rozvoj."
      },
      "opendata_security": null
    },
    "created_at": "2026-07-16T20:44:26.332158+00:00",
    "status": "complete",
    "platform_detected": null,
    "company_ico": null,
    "company_name": null,
    "company_country": null,
    "company_nace": null,
    "company_size": null,
    "nis2_scope": null,
    "nis2_sector": null,
    "company_risk_score": null,
    "company_risk_level": null
  }
}