{
  "data": {
    "slug": "e8483a40",
    "url": "https://www.zlatnictvohorvath.sk/",
    "domain": "zlatnictvohorvath.sk",
    "overall_score": 64,
    "scores_json": {
      "seo": {
        "score": 91,
        "checks": [
          {
            "name": "Meta Title",
            "value": "46 chars — \"Zlatníctvo Horváth | E-shop a Kamenná Predajňa\"",
            "status": "pass"
          },
          {
            "name": "Meta Description",
            "value": "160 chars",
            "status": "pass"
          },
          {
            "name": "H1 Heading",
            "value": "\"Homepage\"",
            "status": "pass"
          },
          {
            "name": "Content Structure (H2 Headings)",
            "value": "11 H2 subheadings found",
            "status": "pass"
          },
          {
            "name": "Open Graph Tags",
            "value": "og:title, og:description, og:image, og:type",
            "status": "pass"
          },
          {
            "name": "Open Graph Image Format",
            "value": "image/webp",
            "status": "pass"
          },
          {
            "name": "Twitter/X Cards",
            "value": "SPA detected — see note below",
            "status": "info",
            "howToFix": "JS-renderovaná stránka (Nuxt) — obsah sa načítava cez JavaScript a nie je viditeľný nášmu skeneru. Overte manuálne.\n\nJS-rendered site detected (Nuxt) — content is loaded client-side and not visible to our raw-HTML scanner. Verify manually or re-run with a headless browser.",
            "whyMatters": "Twitter Cards make your links stand out in X/Twitter feeds. Without them, shared links appear as plain text URLs."
          },
          {
            "name": "Canonical URL",
            "value": "https://zlatnictvohorvath.sk",
            "status": "pass"
          },
          {
            "name": "Structured Data (JSON-LD)",
            "value": "SPA detected — see note below",
            "status": "info",
            "fixLink": {
              "url": "https://zulien.sk",
              "label": "Add with Schema module →"
            },
            "howToFix": "JS-renderovaná stránka (Nuxt) — obsah sa načítava cez JavaScript a nie je viditeľný nášmu skeneru. Overte manuálne.\n\nJS-rendered site detected (Nuxt) — content is loaded client-side and not visible to our raw-HTML scanner. Verify manually or re-run with a headless browser.",
            "whyMatters": "Pages with structured data get rich snippets in Google — star ratings, prices, availability — increasing CTR by 20-30%."
          },
          {
            "name": "robots.txt",
            "value": "Present",
            "status": "pass"
          },
          {
            "name": "XML Sitemap",
            "status": "fail",
            "howToFix": "Generate an XML sitemap at /sitemap.xml listing all important pages. Exclude noindex pages, filters, and duplicate URLs. Reference it in robots.txt.",
            "whyMatters": "Sitemaps help Google discover and index pages 3-5x faster, especially for large stores with deep category structures."
          },
          {
            "name": "HTML Language Attribute",
            "value": "lang=\"sk\"",
            "status": "pass"
          },
          {
            "name": "Hreflang Tags (Multilingual)",
            "value": "2 language(s): sk-SK, x-default",
            "status": "pass"
          },
          {
            "name": "Image Alt Attributes",
            "value": "Only 64% of 348 images have alt text · SPA detected — see note below",
            "status": "info",
            "howToFix": "JS-renderovaná stránka (Nuxt) — obsah sa načítava cez JavaScript a nie je viditeľný nášmu skeneru. Overte manuálne.\n\nJS-rendered site detected (Nuxt) — content is loaded client-side and not visible to our raw-HTML scanner. Verify manually or re-run with a headless browser.",
            "whyMatters": "Missing alt text means zero visibility in Google Image Search (which drives 20%+ of total search traffic for e-commerce)."
          },
          {
            "name": "Meta Robots Tag",
            "value": "index, follow",
            "status": "pass"
          },
          {
            "name": "Text-to-HTML Ratio",
            "value": "1% — very thin content (1456 words) · SPA detected — see note below",
            "status": "info",
            "howToFix": "JS-renderovaná stránka (Nuxt) — obsah sa načítava cez JavaScript a nie je viditeľný nášmu skeneru. Overte manuálne.\n\nJS-rendered site detected (Nuxt) — content is loaded client-side and not visible to our raw-HTML scanner. Verify manually or re-run with a headless browser.",
            "whyMatters": "Google's Helpful Content Update specifically targets thin content pages. This significantly hurts your rankings."
          },
          {
            "name": "Favicon",
            "value": "Favicon detected",
            "status": "pass"
          },
          {
            "name": "Image Format Optimization",
            "value": "53% next-gen formats (185 WebP, 0 AVIF)",
            "status": "pass"
          },
          {
            "name": "Semantic HTML Structure",
            "value": "Only 3/6 semantic elements — missing: <article>, <main>, <aside> · SPA detected — see note below",
            "status": "info",
            "howToFix": "JS-renderovaná stránka (Nuxt) — obsah sa načítava cez JavaScript a nie je viditeľný nášmu skeneru. Overte manuálne.\n\nJS-rendered site detected (Nuxt) — content is loaded client-side and not visible to our raw-HTML scanner. Verify manually or re-run with a headless browser.",
            "whyMatters": "Semantic HTML gives search engines clear signals about content structure. Pages with proper semantic markup earn more featured snippets and knowledge panel appearances."
          },
          {
            "name": "Canonical URL Consistency",
            "value": "Canonical points to different URL: https://zlatnictvohorvath.sk",
            "status": "warning",
            "howToFix": "Your canonical URL doesn't match the current page URL. Ensure the canonical points to the preferred version (with or without trailing slash, www vs non-www). Inconsistent canonicals confuse search engines.",
            "whyMatters": "A mismatched canonical tells Google this page is a duplicate of another URL. If unintentional, Google may ignore this page entirely in favor of the canonical target."
          },
          {
            "name": "Content Depth",
            "value": "1456 words — sufficient content",
            "status": "pass"
          },
          {
            "name": "Deep Heading Hierarchy",
            "value": "H2: 11, H3: 3 — well-structured content",
            "status": "pass"
          },
          {
            "name": "Internal Linking",
            "value": "86 internal links — strong site navigation",
            "status": "pass"
          },
          {
            "name": "Accessibility Fundamentals",
            "value": "3/4 a11y signals: 3 ARIA roles, 4 ARIA labels, lang=\"sk\"",
            "status": "pass"
          },
          {
            "name": "Color Contrast Signal",
            "value": "89 very light text colors found — potential contrast issues",
            "status": "warning",
            "howToFix": "Ensure text has minimum 4.5:1 contrast ratio against background (WCAG AA). Use tools like WebAIM Contrast Checker. Light gray text on white is the most common violation.",
            "whyMatters": "Low contrast text is the #1 accessibility issue found on 83.6% of home pages (WebAIM Million 2024). It affects 8% of men with color vision deficiency and everyone in bright sunlight."
          }
        ]
      },
      "gdpr": {
        "score": 52,
        "checks": [
          {
            "name": "Cookie Consent Banner (CMP)",
            "value": "SPA detected — see note below",
            "status": "info",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get GDPR Compliance →"
            },
            "howToFix": "JS-renderovaná stránka (Nuxt) — obsah sa načítava cez JavaScript a nie je viditeľný nášmu skeneru. Overte manuálne.\n\nJS-rendered site detected (Nuxt) — content is loaded client-side and not visible to our raw-HTML scanner. Verify manually or re-run with a headless browser.",
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7"
              ],
              "czLaw": [
                "§ 5"
              ],
              "skLaw": [
                "§ 14"
              ]
            },
            "whyMatters": "Since 2024, EU regulators actively enforce cookie consent. CNIL fined Google €150M and Amazon €35M for non-compliant cookie banners. Fines can reach 4% of global annual revenue."
          },
          {
            "name": "Tracking Scripts Without Consent",
            "value": "1 tracker(s) loading without consent: Google Analytics/GTM",
            "status": "fail",
            "howToFix": "These tracking scripts fire before user consent: Google Analytics/GTM. Configure your CMP to block them until explicit opt-in. Use Tag Manager's consent mode or CMP script blocking.",
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7"
              ],
              "skLaw": [
                "§ 14"
              ]
            },
            "whyMatters": "Loading ANY tracking before consent is a direct GDPR/ePrivacy violation. This is the most commonly fined offense — French CNIL issued €150M+ in fines for this in 2022 alone."
          },
          {
            "name": "Google Consent Mode v2",
            "status": "fail",
            "howToFix": "Implement Google Consent Mode v2 with gtag('consent', 'default', { ad_storage: 'denied', analytics_storage: 'denied', ad_user_data: 'denied', ad_personalization: 'denied' }). Required since March 2024 for EU audiences.",
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7"
              ],
              "skLaw": [
                "§ 14"
              ]
            },
            "whyMatters": "Google requires Consent Mode v2 for all EU traffic since March 2024. Without it, Google Ads remarketing and conversion data will not function, and you lose measurement data."
          },
          {
            "name": "Privacy Policy Page",
            "value": "SPA detected — see note below",
            "status": "info",
            "howToFix": "JS-renderovaná stránka (Nuxt) — obsah sa načítava cez JavaScript a nie je viditeľný nášmu skeneru. Overte manuálne.\n\nJS-rendered site detected (Nuxt) — content is loaded client-side and not visible to our raw-HTML scanner. Verify manually or re-run with a headless browser.",
            "legalRefs": {
              "gdpr": [
                "Art. 12",
                "Art. 13",
                "Art. 14"
              ],
              "czLaw": [
                "§ 8",
                "§ 9"
              ],
              "skLaw": [
                "§ 19",
                "§ 20"
              ]
            },
            "whyMatters": "A missing privacy policy is the #1 most cited GDPR violation. Every EU data protection authority considers this a basic requirement — and fines start at €5,000 for small businesses."
          },
          {
            "name": "Cookie Policy",
            "value": "SPA detected — see note below",
            "status": "info",
            "howToFix": "JS-renderovaná stránka (Nuxt) — obsah sa načítava cez JavaScript a nie je viditeľný nášmu skeneru. Overte manuálne.\n\nJS-rendered site detected (Nuxt) — content is loaded client-side and not visible to our raw-HTML scanner. Verify manually or re-run with a headless browser.",
            "legalRefs": {
              "gdpr": [
                "Art. 12",
                "Art. 13(1)(c)-(e)"
              ],
              "czLaw": [
                "§ 8"
              ],
              "skLaw": [
                "§ 19"
              ]
            },
            "whyMatters": "The ePrivacy Directive requires transparent cookie disclosure. Vague statements like 'we use cookies for functionality' don't meet the specificity requirement."
          },
          {
            "name": "Legal Contact / Imprint Page",
            "value": "/o-nas",
            "status": "pass"
          },
          {
            "name": "Terms & Conditions Page",
            "value": "/obchodne-podmienky",
            "status": "pass"
          },
          {
            "name": "Data Encryption (No Mixed Content)",
            "value": "All resources loaded over HTTPS",
            "status": "pass"
          },
          {
            "name": "Third-party Data Sharing",
            "value": "1 third-party domain(s)",
            "status": "pass"
          },
          {
            "name": "Personal Data Exposure in Source",
            "value": "1 email(s) found in page source: obchod@zlatnictvohorvath.sk",
            "status": "warning",
            "howToFix": "Remove plain-text email addresses from HTML source. Use contact forms instead, or obfuscate emails with JavaScript encoding.",
            "legalRefs": {
              "gdpr": [
                "Art. 5(1)(f)",
                "Art. 32",
                "Art. 33"
              ],
              "czLaw": [
                "§ 13",
                "§ 14"
              ],
              "skLaw": [
                "§ 39",
                "§ 40"
              ]
            },
            "whyMatters": "Exposing personal email addresses in HTML violates the data minimization principle (GDPR Art. 5). It also invites spam harvesting."
          },
          {
            "name": "International Data Transfers",
            "value": "1 US-based tracker(s) without consent: Google Analytics/GTM",
            "status": "warning",
            "howToFix": "US-based trackers transfer personal data outside the EU. Under GDPR, this requires: 1) User consent via CMP, 2) Standard Contractual Clauses (SCCs) with each provider, 3) Data Transfer Impact Assessment.",
            "whyMatters": "The EU-US Data Privacy Framework covers some transfers, but loading US trackers without consent remains a violation. Austrian and French DPAs have ruled Google Analytics non-compliant without proper safeguards."
          },
          {
            "name": "Forms Without Privacy Notice",
            "value": "1 form(s) on page with no privacy policy link",
            "status": "warning",
            "howToFix": "Add a link to your privacy policy next to or below every form that collects personal data (contact, registration, newsletter). Include a checkbox for consent where required.",
            "legalRefs": {
              "gdpr": [
                "Art. 13",
                "Art. 14"
              ],
              "czLaw": [
                "§ 8"
              ],
              "skLaw": [
                "§ 19",
                "§ 20"
              ]
            },
            "whyMatters": "GDPR Article 13 requires informing users about data processing at the point of collection. Forms without privacy notices violate the transparency principle."
          },
          {
            "name": "Right to Erasure (Data Deletion)",
            "status": "warning",
            "howToFix": "Provide a clear mechanism for users to request data deletion — either a dedicated page, a form, or explicit instructions in your privacy policy. Include a 'Delete my account' option in user settings.",
            "legalRefs": {
              "gdpr": [
                "Art. 17"
              ],
              "czLaw": [
                "§ 10"
              ],
              "skLaw": [
                "§ 23"
              ]
            },
            "whyMatters": "GDPR Article 17 gives users the 'right to be forgotten.' EU regulators expect a clear, accessible process. Italian DPA fined companies €20M+ for obstructing erasure requests."
          },
          {
            "name": "Newsletter Consent",
            "value": "Newsletter signup found without visible consent checkbox",
            "status": "warning",
            "howToFix": "Add an unchecked consent checkbox to your newsletter form: 'I agree to receive marketing emails and have read the Privacy Policy [link].' Pre-checked boxes are not valid consent under GDPR.",
            "legalRefs": {
              "gdpr": [
                "Art. 6(1)(a)",
                "Art. 7",
                "ePrivacy Art. 13"
              ],
              "skLaw": [
                "§ 14",
                "§ 116 zák. 452/2021"
              ]
            },
            "whyMatters": "GDPR requires 'freely given, specific, informed' consent for marketing emails. A newsletter form without explicit opt-in violates Article 7. Italian DPA fined companies for pre-checked newsletter boxes."
          },
          {
            "name": "Data Protection Officer Contact",
            "status": "warning",
            "howToFix": "Add DPO contact details (or privacy contact if DPO not required) to your privacy policy and footer. Include: name/title, email (e.g., dpo@yourdomain.com), and postal address.",
            "whyMatters": "GDPR Article 37 requires a DPO for organizations processing personal data at scale. Even if not mandatory, having a designated privacy contact builds trust and is expected by regulators."
          },
          {
            "name": "Withdrawal of Consent Mechanism",
            "status": "warning",
            "howToFix": "Provide a clear way to withdraw consent: an 'unsubscribe' link in emails, a 'cookie settings' button in the footer, and a 'revoke consent' section in your privacy policy.",
            "legalRefs": {
              "gdpr": [
                "Art. 7(3)"
              ],
              "skLaw": [
                "§ 14(4)"
              ]
            },
            "whyMatters": "GDPR Article 7(3): 'It shall be as easy to withdraw as to give consent.' If users can subscribe in one click, unsubscribing must be equally simple. Missing this is a common regulatory finding."
          }
        ]
      },
      "nis2": {
        "score": -1,
        "checks": [
          {
            "name": "NIS2 Compliance",
            "value": "Scope undetermined — IČO/company enrichment unavailable for this domain.",
            "status": "info",
            "howToFix": "",
            "whyMatters": ""
          }
        ]
      },
      "mobile": {
        "score": 46,
        "checks": [
          {
            "name": "Viewport Configuration",
            "value": "Present, but maximum-scale=1 disables pinch-to-zoom",
            "status": "warning",
            "howToFix": "Remove 'maximum-scale=1' and 'user-scalable=no' from your viewport meta tag. Use: <meta name='viewport' content='width=device-width, initial-scale=1'>",
            "whyMatters": "Preventing pinch-to-zoom is an accessibility violation (WCAG 1.4.4). Users with vision impairments need zoom. Google penalizes sites that disable zoom."
          },
          {
            "name": "Mobile Performance Score",
            "value": "36/100 — critically slow",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Mobile Optimization →"
            },
            "howToFix": "Your mobile experience is severely degraded. Priority fixes: 1) Reduce JavaScript by 50%+, 2) Convert all images to WebP with responsive sizing, 3) Enable aggressive caching, 4) Use a CDN.",
            "whyMatters": "A mobile score below 50 means your store takes 5+ seconds to become usable on a phone. 53% of mobile users abandon sites that take over 3 seconds. You're losing the majority of mobile visitors."
          },
          {
            "name": "Touch Target Size",
            "status": "warning",
            "howToFix": "Ensure ALL interactive elements (buttons, links, form fields) are at least 48×48px with 8px minimum spacing between them. Pay special attention to: navigation menus, filter buttons, product variant selectors, and footer links.",
            "whyMatters": "Small tap targets cause 37% more mis-taps on mobile (Google UX research). In e-commerce, a mis-tap on 'Remove from cart' instead of 'Checkout' directly loses revenue."
          },
          {
            "name": "Font Size Readability",
            "status": "warning",
            "howToFix": "Set minimum 16px font size for body text. Use relative units (rem/em) instead of px for scalability. Product titles: 18px+, prices: 20px+, CTAs: 16px+ with bold.",
            "whyMatters": "Text smaller than 16px forces mobile users to pinch-zoom. This breaks the responsive layout and creates a frustrating experience. Users over 40 are especially affected — and they have the highest purchasing power."
          },
          {
            "name": "Content Fits Viewport",
            "value": "No horizontal scrolling needed",
            "status": "pass"
          },
          {
            "name": "Responsive Design Techniques",
            "value": "Flexbox, CSS Grid, Media queries detected",
            "status": "pass"
          },
          {
            "name": "PWA Features",
            "status": "warning",
            "howToFix": "Consider adding Progressive Web App features: 1) Create manifest.json with app name, icons, and theme color, 2) Register a service worker for offline caching. This makes your store installable on mobile.",
            "whyMatters": "PWAs combine the best of web and native apps. Starbucks' PWA doubled daily active users. For e-commerce, PWAs enable push notifications, offline browsing, and home screen access."
          },
          {
            "name": "Theme Color",
            "status": "warning",
            "howToFix": "Add <meta name='theme-color' content='#your-brand-color'> to match your brand. Browsers use this to color the address bar, task switcher, and PWA chrome.",
            "whyMatters": "Theme-color creates a polished, branded mobile experience. It makes your site look native and professional — small detail, big perception impact."
          },
          {
            "name": "Mobile Navigation (Semantic)",
            "value": "<nav> element present — proper navigation landmark",
            "status": "pass"
          },
          {
            "name": "Inline CSS Size",
            "value": "441 KB of inline CSS",
            "status": "warning",
            "howToFix": "Extract inline styles to external CSS files. Inline CSS larger than 50 KB increases HTML payload and cannot be cached separately. Keep only critical above-the-fold CSS inline.",
            "whyMatters": "Large inline CSS blocks increase initial HTML download and parsing time — especially painful on mobile with limited CPU and slower connections."
          },
          {
            "name": "Responsive Images (srcset)",
            "value": "348 images without responsive sizing",
            "status": "warning",
            "howToFix": "Add srcset and sizes attributes to <img> tags to serve appropriately sized images for each screen. Mobile devices shouldn't download 1920px desktop images.",
            "whyMatters": "Without srcset, mobile users download full-size desktop images — wasting 50-80% of bandwidth. Responsive images are the single biggest mobile performance win for image-heavy sites."
          },
          {
            "name": "Form Input Types",
            "value": "phone fields use type='text' instead of type='tel'",
            "status": "warning",
            "howToFix": "Use semantic input types: type='email' for email (shows @ keyboard), type='tel' for phone (shows number pad), type='search' for search (shows search button). These trigger optimized mobile keyboards.",
            "whyMatters": "Correct input types show specialized mobile keyboards — email keyboard with @, phone with number pad. This reduces input errors by 30% and speeds up form completion (Baymard Institute)."
          },
          {
            "name": "Payment Methods Detected",
            "value": "2 method(s): Tatra Pay, QR platba / Pay by square",
            "status": "pass"
          },
          {
            "name": "Express Checkout (Apple Pay + Google Pay)",
            "status": "warning",
            "howToFix": "Pridaj Apple Pay + Google Pay cez Stripe/Adyen/Mollie. Biometric auth = -1 click checkout = vyšší conversion.",
            "whyMatters": "Mobile conversion pri express checkout je +15-25 % oproti klasickej karte. V SK/CZ trend roku 2025+."
          },
          {
            "name": "SK/CZ Local Payment Methods",
            "value": "Iba 2 SK/CZ metód (Tatra Pay, QR platba / Pay by square)",
            "status": "warning",
            "howToFix": "Pridaj ďalšie SK/CZ local methods: ComGate, GoPay, Barion, Besteron, PayU. SK zákazníci preferujú bankové tlačidlá a QR platbu pred kartou.",
            "whyMatters": "48 % SK online platieb ide cez lokálne banky alebo QR platbu (Tatrabanka study 2024). Iba karta = 50 % cart abandonment na SK trhu."
          },
          {
            "name": "Form Input Labels (WCAG 3.3.2)",
            "value": "Iba 0/3 inputs má label (0%)",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Accessibility audit — Inger"
            },
            "howToFix": "3 input elementov nemá label. Každý input musí mať priradený <label for=\"id\">Text</label> alebo aria-label. Placeholder NIE je label (WCAG 3.3.2). Ak je checkout/registrácia formulár — toto znižuje konverziu a porušuje EN 301 549 (EAA 2026).",
            "whyMatters": "EAA 2026 (European Accessibility Act) vstupuje do platnosti 28.6.2025. E-shopy nad 10 zamestnancov alebo €2M obrat musia byť WCAG 2.1 AA kompatibilné — chýbajúce labely sú jedna z najčastejších žalovateľných chýb."
          },
          {
            "name": "Heading Hierarchy (WCAG 1.3.1)",
            "value": "Preskočené úrovne: h2→h4, h2→h6",
            "status": "warning",
            "howToFix": "Dodržuj poradie nadpisov h1 → h2 → h3 → h4 bez preskočenia. Screen readers používajú hierarchiu nadpisov na navigáciu. Ak potrebuješ menšie písmo ale rovnakú úroveň, použi CSS triedu, nie nižší heading tag.",
            "whyMatters": "Preskočené heading levely (napr. h1 priamo na h3) zlomia navigáciu pre screen reader používateľov a signalizujú Googlu zlú štruktúru dokumentu. Aj SEO je negatívne ovplyvnené."
          },
          {
            "name": "Link Text Quality (WCAG 2.4.4)",
            "value": "Všetky odkazy majú popisný text",
            "status": "pass"
          }
        ]
      },
      "modules": [],
      "security": {
        "score": 55,
        "checks": [
          {
            "name": "SSL/TLS Certificate",
            "value": "Valid HTTPS connection established",
            "status": "pass"
          },
          {
            "name": "DNSSEC",
            "value": "Zone is DNSSEC-signed (DNSKEY published)",
            "status": "pass",
            "whyMatters": "DNSSEC protects against DNS cache poisoning and on-path attackers redirecting your domain. Required by some sector regulators for NIS2 essential/important entities."
          },
          {
            "name": "CAA DNS Record",
            "value": "No CAA records — any CA can issue certificates for this domain",
            "status": "warning",
            "howToFix": "Publish CAA TXT records pinning your CA. For Let's Encrypt: `0 issue \"letsencrypt.org\"`. For multiple CAs add additional `0 issue \"...\"` records. Add `0 iodef \"mailto:security@yourdomain.tld\"` for misissuance reports.",
            "whyMatters": "CAA records limit which Certificate Authorities can issue certificates for your domain. Without CAA, a compromised or rogue CA can issue valid certs that browsers will trust — a documented breach pattern (DigiNotar 2011, Symantec 2017)."
          },
          {
            "name": "HTTP → HTTPS Redirect",
            "value": "HTTP properly redirects to HTTPS",
            "status": "pass"
          },
          {
            "name": "HSTS (Strict-Transport-Security)",
            "status": "fail",
            "howToFix": "Add header: Strict-Transport-Security: max-age=31536000; includeSubDomains; preload — then submit to hstspreload.org.",
            "whyMatters": "Without HSTS, attackers can intercept the first HTTP request and downgrade the connection. This is the #1 way to steal session cookies on public WiFi."
          },
          {
            "name": "Content-Security-Policy (CSP)",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Security Hardening →"
            },
            "howToFix": "Implement a CSP header. Start with: Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: — then gradually tighten.",
            "whyMatters": "CSP is the most powerful defense against XSS attacks. Without it, any injected script runs with full privileges. CSP blocks inline script injection, the #1 web attack vector."
          },
          {
            "name": "Clickjacking Protection",
            "status": "fail",
            "howToFix": "Add X-Frame-Options: DENY (or SAMEORIGIN if iframes are needed). Better: use CSP frame-ancestors 'self'.",
            "whyMatters": "Clickjacking overlays your site in a hidden iframe. Attackers trick users into clicking buttons (like 'Confirm Purchase') without knowing it."
          },
          {
            "name": "X-Content-Type-Options",
            "status": "warning",
            "howToFix": "Add header: X-Content-Type-Options: nosniff",
            "whyMatters": "Without nosniff, browsers may execute uploaded files as scripts. An attacker could upload a .jpg that's actually JavaScript and trick the browser into running it."
          },
          {
            "name": "Referrer-Policy",
            "status": "warning",
            "howToFix": "Add header: Referrer-Policy: strict-origin-when-cross-origin — this is the best balance between functionality and privacy.",
            "whyMatters": "Without a referrer policy, browsers send the full URL to third parties. This can leak sensitive data like session tokens in URLs or internal page paths."
          },
          {
            "name": "Permissions-Policy",
            "status": "warning",
            "howToFix": "Add: Permissions-Policy: camera=(), microphone=(), geolocation=(), payment=() — disable APIs your site doesn't need.",
            "whyMatters": "Without Permissions-Policy, any third-party script (ads, analytics, chat widgets) can access camera, microphone, and geolocation without your knowledge."
          },
          {
            "name": "Cookie Security Flags",
            "value": "No cookies set on initial response",
            "status": "pass"
          },
          {
            "name": "Technology Disclosure",
            "value": "Server: nginx/1.29.4, X-Powered-By: Nuxt",
            "status": "warning",
            "howToFix": "Hide server version: set ServerTokens Prod (Apache) or server_tokens off (Nginx). Remove X-Powered-By header completely.",
            "whyMatters": "Exposing exact server/PHP versions lets attackers search CVE databases for specific exploits. This is the first step in most automated attacks."
          },
          {
            "name": "Subresource Integrity (SRI)",
            "value": "Only 0/2 external scripts have integrity hashes",
            "status": "warning",
            "howToFix": "Add integrity='sha384-...' and crossorigin='anonymous' attributes to all third-party <script> tags. Use srihash.org to generate hashes.",
            "whyMatters": "Without SRI, if a third-party CDN is compromised, attackers can inject malicious code into your site. The British Airways breach (£20M fine) was exactly this attack vector."
          },
          {
            "name": "security.txt (RFC 9116)",
            "status": "warning",
            "howToFix": "Create /.well-known/security.txt with Contact, Expires, and Preferred-Languages fields. See securitytxt.org for the generator.",
            "whyMatters": "security.txt lets ethical hackers report vulnerabilities responsibly. Without it, they may disclose publicly or not report at all. Required by ISO 27001 and SOC 2."
          },
          {
            "name": "Server Version Disclosure",
            "value": "Nginx 1.29.4 exposed in headers",
            "status": "warning",
            "howToFix": "Hide server version. Apache: add 'ServerTokens Prod' and 'ServerSignature Off' to httpd.conf. Nginx: add 'server_tokens off;' to nginx.conf.",
            "whyMatters": "Exposing \"Nginx 1.29.4\" lets attackers search for version-specific exploits. Hide it to add a layer of defense."
          },
          {
            "name": "CDN / WAF Protection",
            "status": "warning",
            "howToFix": "Add a CDN/WAF like Cloudflare (free tier), Sucuri, or Fastly. They provide DDoS protection, bot filtering, and SSL management.",
            "whyMatters": "Without a CDN/WAF, your origin server is directly exposed to DDoS attacks, bot traffic, and brute-force attempts. Cloudflare blocks 150+ billion daily threats."
          },
          {
            "name": "Password Field Security",
            "value": "1 password field(s) — allow password manager autofill",
            "status": "pass"
          }
        ]
      },
      "tech_stack": [
        {
          "eol": false,
          "name": "Magento",
          "category": "cms"
        },
        {
          "name": "Vue.js",
          "category": "framework"
        },
        {
          "name": "Nuxt.js",
          "category": "framework"
        },
        {
          "name": "Swiper",
          "category": "js-library"
        },
        {
          "name": "Toastr",
          "category": "js-library"
        },
        {
          "name": "Vite",
          "category": "js-library"
        },
        {
          "name": "Nginx",
          "version": "1.29.4",
          "category": "server"
        }
      ],
      "performance": {
        "score": 67,
        "checks": [
          {
            "name": "Server Response Time (TTFB)",
            "value": "108ms",
            "status": "pass"
          },
          {
            "name": "First Contentful Paint (FCP)",
            "value": "1.08s",
            "status": "pass"
          },
          {
            "name": "Largest Contentful Paint (LCP)",
            "value": "1.70s — Core Web Vital ✓",
            "status": "pass"
          },
          {
            "name": "Total Blocking Time (TBT)",
            "value": "947ms (good: <200ms)",
            "status": "fail",
            "howToFix": "Critical: audit all JavaScript. 1) Remove unused plugins/modules, 2) Defer analytics and chat widgets, 3) Code-split large bundles, 4) Move heavy computation to web workers.",
            "whyMatters": "TBT over 600ms means your page is unresponsive for over half a second. Users who can't interact within 100ms perceive the site as broken. This kills conversions."
          },
          {
            "name": "Cumulative Layout Shift (CLS)",
            "value": "0.000 — Core Web Vital ✓",
            "status": "pass"
          },
          {
            "name": "Speed Index",
            "value": "2.27s",
            "status": "pass"
          },
          {
            "name": "Total Page Weight",
            "value": "4.0 MB, 186 requests — too heavy!",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Performance Optimization →"
            },
            "howToFix": "Critical: your page is over 3 MB. 1) Convert all images to WebP/AVIF, 2) Lazy load everything below the fold, 3) Remove unused plugins, 4) Combine and minify CSS/JS, 5) Enable brotli compression.",
            "whyMatters": "Pages over 3 MB take 12+ seconds on 3G. The average e-commerce page is 2.2 MB — you're well above that. Amazon found every 100ms of latency costs 1% of sales."
          },
          {
            "name": "Render-blocking Resources",
            "value": "No render-blocking resources found",
            "status": "pass"
          },
          {
            "name": "Unused Code (CSS + JS)",
            "value": "592 KB wasted on unused code!",
            "status": "fail",
            "howToFix": "You're loading 592 KB of code that isn't used on this page. 1) Audit plugins and remove unused ones, 2) Use code-splitting for page-specific JS, 3) Run PurgeCSS on your stylesheets.",
            "whyMatters": "Over 200 KB of unused code significantly slows parsing and execution. This is one of the easiest performance wins — removing dead code requires no trade-offs."
          },
          {
            "name": "Text Compression (gzip/brotli)",
            "value": "All text resources properly compressed",
            "status": "pass"
          },
          {
            "name": "Resource Hints (Preload/Preconnect)",
            "value": "4 preload, 0 preconnect hint(s)",
            "status": "pass"
          },
          {
            "name": "Lazy Loading",
            "value": "32% of images use native lazy loading (112/348)",
            "status": "pass"
          },
          {
            "name": "Script Loading Strategy",
            "value": "100% of scripts use async/defer/module (1 async, 0 defer, 1 module)",
            "status": "pass"
          },
          {
            "name": "CSS File Count",
            "value": "8 CSS files loaded",
            "status": "warning",
            "howToFix": "Consolidate CSS files by bundling them into 1-3 files. Each CSS file is a separate HTTP request that blocks rendering until downloaded.",
            "whyMatters": "Each render-blocking CSS file adds network latency. Consolidating CSS from 8 to 2 files can save 200-400ms on first load."
          },
          {
            "name": "Font Preloading",
            "value": "Custom fonts detected without preload hints",
            "status": "warning",
            "howToFix": "Preload your primary font: <link rel='preload' href='/fonts/main.woff2' as='font' type='font/woff2' crossorigin>. For Google Fonts: preconnect to fonts.gstatic.com.",
            "whyMatters": "Fonts are discovered late in the render pipeline (after CSS is parsed). Preloading tells the browser to download them immediately, reducing Flash of Invisible Text (FOIT) by 200-500ms."
          },
          {
            "name": "Critical CSS Strategy",
            "value": "8 CSS files without critical CSS extraction",
            "status": "warning",
            "howToFix": "Extract critical above-the-fold CSS and inline it in <head>. Load remaining CSS asynchronously: <link rel='preload' href='styles.css' as='style' onload='this.rel=\"stylesheet\"'>.",
            "whyMatters": "Render-blocking CSS delays first paint. Inlining critical CSS eliminates the render-blocking round trip — the biggest FCP improvement for CSS-heavy sites."
          },
          {
            "name": "Inline JavaScript Size",
            "value": "468 KB of inline JavaScript",
            "status": "warning",
            "howToFix": "Move large inline scripts to external files. Inline JS over 100 KB inflates HTML, prevents caching, and blocks the parser. External files can be cached, compressed, and deferred.",
            "whyMatters": "Large inline scripts cannot be cached separately — they're re-downloaded with every page load. Moving them to external files with defer enables HTTP caching and parallel downloads."
          }
        ]
      },
      "ai_readiness": {
        "score": 53,
        "checks": [
          {
            "name": "AI Bot Access Policy",
            "value": "No AI bot restrictions (allowed by default)",
            "status": "pass"
          },
          {
            "name": "llms.txt (AI Site Descriptor)",
            "status": "fail",
            "fixLink": {
              "url": "https://llmstxt.org",
              "label": "Learn about llms.txt →"
            },
            "howToFix": "Create /llms.txt in Markdown format:\n# Your Store Name\n> One-line summary of your business and key offerings.\n\nDetailed description paragraph.\n\n## Products\n- [Product Category](URL): Description\n\n## About\n- [About Us](URL): Company history and values\n\nSee llmstxt.org for the full specification.",
            "whyMatters": "llms.txt is the emerging standard for AI-readable site descriptions — like robots.txt was for search engines. Early adopters (Yoast, Cloudflare, Stripe) are already using it. Without it, AI assistants have no guided overview of your store."
          },
          {
            "name": "llms-full.txt (Complete AI Content)",
            "status": "warning",
            "howToFix": "Create /llms-full.txt containing your complete site documentation in a single Markdown file — product catalog summaries, FAQs, policies, brand story. This gives AI models maximum context about your store.",
            "whyMatters": "llms-full.txt provides AI models with your entire site content in one parseable file. It's the difference between an AI having a brief overview vs. deep knowledge of your products and services."
          },
          {
            "name": "Content Accessibility for AI",
            "value": "Only 1456 words visible in HTML — content may be JS-dependent · SPA detected — see note below",
            "status": "info",
            "howToFix": "JS-renderovaná stránka (Nuxt) — obsah sa načítava cez JavaScript a nie je viditeľný nášmu skeneru. Overte manuálne.\n\nJS-rendered site detected (Nuxt) — content is loaded client-side and not visible to our raw-HTML scanner. Verify manually or re-run with a headless browser.",
            "whyMatters": "AI crawlers see only raw HTML. The LLMClicks audit tool found that JS-dependent pages score 70% lower in AI readiness. Server-rendered content is the #1 prerequisite for AI visibility."
          },
          {
            "name": "Structured Data Foundation",
            "value": "SPA detected — see note below",
            "status": "info",
            "fixLink": {
              "url": "https://zulien.sk",
              "label": "Add structured data →"
            },
            "howToFix": "JS-renderovaná stránka (Nuxt) — obsah sa načítava cez JavaScript a nie je viditeľný nášmu skeneru. Overte manuálne.\n\nJS-rendered site detected (Nuxt) — content is loaded client-side and not visible to our raw-HTML scanner. Verify manually or re-run with a headless browser.",
            "whyMatters": "Without structured data, your store is invisible to AI commerce. Google AI Overviews, ChatGPT Shopping, Perplexity, and Bing Copilot all rely on schema markup to understand and recommend products."
          },
          {
            "name": "Product Schema Completeness",
            "status": "fail",
            "fixLink": {
              "url": "https://zulien.sk",
              "label": "Add Product schema →"
            },
            "howToFix": "Add complete Product JSON-LD schema: name, description, image, sku, brand, offers (price, priceCurrency, availability, seller), aggregateRating, review. This is mandatory for AI-powered commerce.",
            "whyMatters": "No Product schema = invisible to AI shopping. 58% of consumers now use AI for product discovery (Adobe 2025). Without Product schema, your products don't exist in this channel."
          },
          {
            "name": "Organization Schema + Entity Linking",
            "value": "SPA detected — see note below",
            "status": "info",
            "howToFix": "JS-renderovaná stránka (Nuxt) — obsah sa načítava cez JavaScript a nie je viditeľný nášmu skeneru. Overte manuálne.\n\nJS-rendered site detected (Nuxt) — content is loaded client-side and not visible to our raw-HTML scanner. Verify manually or re-run with a headless browser.",
            "whyMatters": "Organization schema is the foundation of your AI identity. Without it, AI assistants can't confidently attribute information to your brand, verify your legitimacy, or show your Knowledge Panel."
          },
          {
            "name": "FAQ Schema (Direct AI Answers)",
            "value": "SPA detected — see note below",
            "status": "info",
            "howToFix": "JS-renderovaná stránka (Nuxt) — obsah sa načítava cez JavaScript a nie je viditeľný nášmu skeneru. Overte manuálne.\n\nJS-rendered site detected (Nuxt) — content is loaded client-side and not visible to our raw-HTML scanner. Verify manually or re-run with a headless browser.",
            "whyMatters": "FAQ schema provides 30% higher AI citation rates (LLMClicks research). ChatGPT, Perplexity, and Google AI Overviews pull FAQ answers verbatim. It's the fastest way to get your content cited by AI."
          },
          {
            "name": "Breadcrumb Schema",
            "status": "warning",
            "howToFix": "Add BreadcrumbList schema reflecting your category hierarchy: Home → Category → Subcategory → Product. Each item needs name and URL.",
            "whyMatters": "AI assistants use breadcrumbs to understand product categorization and site structure. Without it, AI can't contextualize where products fit in your catalog — e.g., 'Running Shoes' under 'Sports > Footwear > Running'."
          },
          {
            "name": "Site Search Schema (SearchAction)",
            "status": "warning",
            "howToFix": "Add WebSite schema with potentialAction: SearchAction. Define your search URL template so AI assistants and Google can search your store programmatically.",
            "whyMatters": "SearchAction enables Google's sitelinks search box and allows AI shopping assistants to search your catalog directly. It's how AI agents find specific products in your store."
          },
          {
            "name": "Content Depth for AI",
            "value": "1456 words — rich content for AI analysis and citation",
            "status": "pass"
          },
          {
            "name": "Answer-First Content Format",
            "value": "Content doesn't start with a strong summary paragraph · SPA detected — see note below",
            "status": "info",
            "howToFix": "JS-renderovaná stránka (Nuxt) — obsah sa načítava cez JavaScript a nie je viditeľný nášmu skeneru. Overte manuálne.\n\nJS-rendered site detected (Nuxt) — content is loaded client-side and not visible to our raw-HTML scanner. Verify manually or re-run with a headless browser.",
            "whyMatters": "AI assistants extract content from the first 100 words to generate summaries. The LLMClicks analyzer found pages with answer-first format get 40% more AI citations. Most AI systems read top-down."
          },
          {
            "name": "Heading Hierarchy for AI",
            "value": "Proper structure: 1 H1 → 11 H2s → 3 H3s — clear content outline",
            "status": "pass"
          },
          {
            "name": "Semantic HTML Structure",
            "value": "3/6 elements — missing: <article>, <main>, <aside> · SPA detected — see note below",
            "status": "info",
            "howToFix": "JS-renderovaná stránka (Nuxt) — obsah sa načítava cez JavaScript a nie je viditeľný nášmu skeneru. Overte manuálne.\n\nJS-rendered site detected (Nuxt) — content is loaded client-side and not visible to our raw-HTML scanner. Verify manually or re-run with a headless browser.",
            "whyMatters": "AI crawlers don't see your CSS. They rely on semantic HTML to distinguish main content from navigation, ads, and boilerplate. The WordLift AI Audit weights semantic HTML as a primary machine-readability signal."
          },
          {
            "name": "Structured Content (Lists & Tables)",
            "value": "27 lists found — consider adding comparison tables · SPA detected — see note below",
            "status": "info",
            "howToFix": "JS-renderovaná stránka (Nuxt) — obsah sa načítava cez JavaScript a nie je viditeľný nášmu skeneru. Overte manuálne.\n\nJS-rendered site detected (Nuxt) — content is loaded client-side and not visible to our raw-HTML scanner. Verify manually or re-run with a headless browser.",
            "whyMatters": "AI models are biased toward extracting data from HTML lists and tables. Perplexity and ChatGPT pull bullet points and table data with much higher accuracy than paragraph text. Structured content = more AI citations."
          },
          {
            "name": "Content Freshness Signals",
            "value": "SPA detected — see note below",
            "status": "info",
            "howToFix": "JS-renderovaná stránka (Nuxt) — obsah sa načítava cez JavaScript a nie je viditeľný nášmu skeneru. Overte manuálne.\n\nJS-rendered site detected (Nuxt) — content is loaded client-side and not visible to our raw-HTML scanner. Verify manually or re-run with a headless browser.",
            "whyMatters": "No freshness signals = AI assumes your content is stale. ChatGPT and Perplexity both weight recency in their citation algorithms. Competitors who show recent updates will be cited instead of your static pages."
          },
          {
            "name": "Entity Clarity & Brand Signals",
            "value": "OG tags complete but no sameAs entity links · SPA detected — see note below",
            "status": "info",
            "howToFix": "JS-renderovaná stránka (Nuxt) — obsah sa načítava cez JavaScript a nie je viditeľný nášmu skeneru. Overte manuálne.\n\nJS-rendered site detected (Nuxt) — content is loaded client-side and not visible to our raw-HTML scanner. Verify manually or re-run with a headless browser.",
            "whyMatters": "AI needs to confidently identify your brand entity. Open Graph + sameAs create a cross-platform identity that AI models recognize. The HubSpot AEO Grader found entity clarity is a top-3 factor for AI brand recognition."
          },
          {
            "name": "Author Expertise Signals (E-E-A-T)",
            "status": "warning",
            "howToFix": "For content pages (blog, guides, about): add Article/BlogPosting schema with author property linking to Person schema. Include the author's jobTitle, credentials, and social profiles.",
            "whyMatters": "AI models weight author expertise heavily. Pages from identified experts get cited 3x more than anonymous content. This is especially important for product guides, reviews, and advice content."
          },
          {
            "name": "Reviews & Ratings Schema",
            "status": "warning",
            "howToFix": "Add AggregateRating schema (ratingValue, reviewCount, bestRating) and individual Review schemas. AI shopping assistants prioritize products with verified reviews and ratings.",
            "whyMatters": "Products with star ratings appear in Google's rich results and get 35% more clicks. AI shopping assistants (ChatGPT, Bing Copilot) rank products with reviews significantly higher in recommendations."
          },
          {
            "name": "AI Plugin Manifest",
            "status": "warning",
            "howToFix": "Create /.well-known/ai-plugin.json if you have an API. This enables direct AI agent integration (ChatGPT Actions, custom GPTs). Include: name_for_model, description_for_model, auth config, and link to OpenAPI spec.",
            "whyMatters": "ai-plugin.json enables AI agents to interact with your store programmatically — search products, check prices, process orders. This is the bridge between AI assistants and your e-commerce functionality."
          },
          {
            "name": "Product Feed (AI Commerce)",
            "status": "warning",
            "howToFix": "Create a Google Merchant Center / product feed (XML or CSV). Expose it at a consistent URL and reference it in your sitemap. AI shopping assistants and comparison engines use product feeds for catalog discovery.",
            "whyMatters": "Product feeds power Google Shopping, Bing Shopping, and increasingly AI commerce. Without a structured product feed, AI agents can't efficiently index your full catalog for product recommendations."
          },
          {
            "name": "Heureka XML Feed",
            "status": "warning",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Setup Heureka Feed — Inger"
            },
            "howToFix": "Vygeneruj Heureka XML feed na /feed/heureka.xml (alebo /export/heureka.xml). PrestaShop má modul Heureka.cz, WooCommerce má pluginy. Štruktúra: <SHOP><SHOPITEM>...</SHOPITEM></SHOP> s ITEM_ID/PRODUCTNAME/URL/PRICE_VAT/CATEGORYTEXT (povinné) + EAN/PARAM/DELIVERY_DATE (highly recommended pre ranking).",
            "whyMatters": "Heureka.sk a Heureka.cz sú dominantné cenové porovnávače na SK/CZ trhu (40%+ all e-com discovery traffic). Bez XML feedu nie ste viditeľní na hlavnom trhovisku — strata 20-30 % potenciálneho traffic. Žiaden generický audit tool toto nekontroluje."
          },
          {
            "name": "Speakable Content (Voice AI)",
            "status": "warning",
            "howToFix": "Add SpeakableSpecification schema to identify content sections suitable for voice assistants (Google Assistant, Alexa, Siri). Mark your product summaries and FAQs as speakable.",
            "whyMatters": "Voice AI commerce is growing rapidly. SpeakableSpecification tells voice assistants which content to read aloud. Early adoption positions your store for the voice shopping wave."
          },
          {
            "name": "Extractable Answer Blocks",
            "value": "44 paragraphs, avg 10 words — too short for citation · SPA detected — see note below",
            "status": "info",
            "howToFix": "JS-renderovaná stránka (Nuxt) — obsah sa načítava cez JavaScript a nie je viditeľný nášmu skeneru. Overte manuálne.\n\nJS-rendered site detected (Nuxt) — content is loaded client-side and not visible to our raw-HTML scanner. Verify manually or re-run with a headless browser.",
            "whyMatters": "Pages with 40-80 word paragraphs earn 70% more AI citations (Otterly 2026 data). AI extracts individual paragraphs as answer snippets — dense walls of text get skipped."
          },
          {
            "name": "Statistics & Data Presence",
            "value": "Only 1 data point(s) — add more",
            "status": "warning",
            "howToFix": "Add specific statistics, percentages, dollar amounts, and quantified claims. E.g., '93% of customers report...', 'saves an average of €200/year', '3x faster than...' Data makes content citable.",
            "whyMatters": "Princeton/Georgia Tech study found that adding statistics to content improves AI visibility by 41% — the single most effective GEO optimization. AI assistants prefer content with verifiable data points."
          },
          {
            "name": "Section Length Optimization",
            "value": "Avg section: 77 words — only 17% in 80-200 word optimal range",
            "status": "warning",
            "howToFix": "Restructure content into sections of 120-180 words between H2/H3 headings. Each section should cover one topic completely. Split sections over 300 words, expand sections under 80 words.",
            "whyMatters": "Pages with 120-180 word sections earn 70% more AI citations (Otterly Citation Economy 2026). For Google AI Overviews specifically, 100-150 words per section is the sweet spot."
          },
          {
            "name": "Q&A Format Headings",
            "value": "3 question-format headings — excellent for AI Q&A extraction",
            "status": "pass"
          },
          {
            "name": "Internal Link Density",
            "value": "59 contextual internal links per 1,000 words — strong knowledge graph signal",
            "status": "pass"
          },
          {
            "name": "Canonical Tag for AI Deduplication",
            "value": "Canonical points to different URL: https://zlatnictvohorvath.sk · SPA detected — see note below",
            "status": "info",
            "howToFix": "JS-renderovaná stránka (Nuxt) — obsah sa načítava cez JavaScript a nie je viditeľný nášmu skeneru. Overte manuálne.\n\nJS-rendered site detected (Nuxt) — content is loaded client-side and not visible to our raw-HTML scanner. Verify manually or re-run with a headless browser.",
            "whyMatters": "AI search engines (ChatGPT, Perplexity, Bing Copilot) use canonicals to deduplicate content. A wrong canonical means AI may cite the wrong page version or ignore this page entirely."
          },
          {
            "name": "Return Policy Schema",
            "status": "warning",
            "howToFix": "Add MerchantReturnPolicy schema with: returnPolicyCategory (e.g., MerchantReturnFiniteReturnWindow), merchantReturnDays, returnMethod, returnFees. Link it from Product/Offer via hasMerchantReturnPolicy.",
            "whyMatters": "AI shopping agents (Google Shopping, ChatGPT, Bing Copilot) filter by return flexibility. Products with return policy schema get priority placement in AI product comparisons."
          },
          {
            "name": "Shipping Details Schema",
            "status": "warning",
            "howToFix": "Add OfferShippingDetails schema with: shippingRate, shippingDestination, deliveryTime (handlingTime + transitTime). AI agents deprioritize products without shipping info.",
            "whyMatters": "Fulfillment speed now factors into AI product recommendations. Complete shipping schema means AI can show 'Free shipping, delivers in 2-3 days' — a massive conversion driver."
          },
          {
            "name": "Knowledge Graph Readiness",
            "value": "1/4 signals — missing: @id in JSON-LD, sameAs links (Wikipedia, LinkedIn), Organization schema",
            "status": "warning",
            "howToFix": "Add: @id in JSON-LD, sameAs links (Wikipedia, LinkedIn), Organization schema. Use @id in JSON-LD to create a unique node identifier. Ensure your brand name is identical in title, schema, and OG tags. Link to Wikipedia/Wikidata via sameAs.",
            "whyMatters": "Brands with verified Knowledge Graph presence receive 3.1x more AI citations. @id creates a persistent entity identifier that connects your schema across pages and platforms."
          },
          {
            "name": "Content Readability for AI",
            "value": "Grade 20 — too complex for broad AI citation (technical threshold: 14)",
            "status": "warning",
            "howToFix": "Simplify sentences (target 15-20 words average), use common words, break complex ideas into shorter paragraphs. AI extracts content for general audiences — if it's too academic, AI skips it.",
            "whyMatters": "Content above grade 12 readability is harder for AI to extract as clear, concise answers. Pages using clear headers and approachable language are 28% more likely to be cited by AI."
          },
          {
            "name": "Image Alt Text Quality for AI",
            "value": "Only 38% quality alt text — 126 missing, 90 poor",
            "status": "fail",
            "howToFix": "Audit all images: add descriptive alt text (3-15 words) to every <img>. Include product names, features, materials, colors. This is critical for visual AI search and accessibility compliance.",
            "whyMatters": "Poor alt text means your product images are invisible to AI visual search (Google Lens, Bing Visual Search). This is also an accessibility requirement (WCAG 2.1 AA) — many regions enforce this legally."
          },
          {
            "name": "Expert Quotations & Citations",
            "status": "warning",
            "howToFix": "Add 2-3 expert quotes or data citations per major page. Use <blockquote> for quotes and link to authoritative sources (.gov, .edu, Wikipedia, industry reports).",
            "whyMatters": "Content without citations or expert quotes appears unverified to AI. AI assistants prefer content backed by named sources, data references, and expert opinions."
          },
          {
            "name": "ai.txt (AI Permissions)",
            "status": "warning",
            "howToFix": "Create /ai.txt or /.well-known/ai.txt to declare granular AI permissions per content type: which AI actions (summarization, training, extraction) are allowed for which content sections.",
            "whyMatters": "ai.txt is an emerging standard (proposed May 2025) for fine-grained AI permissions beyond robots.txt. Early adoption signals AI-forward thinking and gives you control over how AI uses your content."
          },
          {
            "name": "WebMCP Agentic Readiness",
            "status": "warning",
            "howToFix": "WebMCP (W3C Community Group standard, Chrome 146+) lets pages declare structured tools for AI agents. Add toolname and tooldescription attributes to <form> elements, or include a <script type='application/webmcp+json'> manifest.",
            "whyMatters": "WebMCP is called 'the new Schema.org moment' — it's how AI agents will interact with your store (search products, add to cart, check availability). Google and Microsoft are co-developing this standard."
          },
          {
            "name": "Content-to-Boilerplate Ratio",
            "value": "No <main> or <article> elements — AI can't isolate content from boilerplate · SPA detected — see note below",
            "status": "info",
            "howToFix": "JS-renderovaná stránka (Nuxt) — obsah sa načítava cez JavaScript a nie je viditeľný nášmu skeneru. Overte manuálne.\n\nJS-rendered site detected (Nuxt) — content is loaded client-side and not visible to our raw-HTML scanner. Verify manually or re-run with a headless browser.",
            "whyMatters": "Without semantic containers, AI crawlers must guess where content starts and navigation ends. This leads to poor content extraction and fewer citations."
          },
          {
            "name": "Trust Widget",
            "value": "Žiaden trust widget (Heureka / Trustpilot / AggregateRating) nedetekovaný",
            "status": "warning",
            "howToFix": "Pre SK/CZ shopy: inštaluj Heureka Ověřeno zákazníky widget (zadarmo pre overených predajcov — https://sluzby.heureka.sk). Alternatívne: Trustpilot, Google Reviews s AggregateRating schema. Trust widget na product + kategória + footer.",
            "whyMatters": "SK/CZ kupujúci majú 2× vyššiu dôveru k Heureka Ověřeno ako k iným trust signálom (Heureka research 2024). LLM-y (ChatGPT, Perplexity) a Google SGE citujú shopy s AggregateRating schema prednostne."
          }
        ]
      },
      "vulnerability": {
        "score": 59,
        "checks": [
          {
            "name": "CMS Version Disclosure",
            "value": "No generator tag — CMS identity hidden",
            "status": "pass"
          },
          {
            "name": "Sensitive Files Exposed",
            "value": ".env, .git, composer.json — all properly blocked",
            "status": "pass"
          },
          {
            "name": "Install Script Exposed",
            "value": "No /install/ or /setup/ paths accessible",
            "status": "pass"
          },
          {
            "name": "Directory Listing",
            "value": "Disabled — file structure hidden",
            "status": "pass"
          },
          {
            "name": "Admin Panel at Default URL",
            "value": "Not found at common paths (/admin, /wp-admin, /administrator, /backoffice)",
            "status": "pass"
          },
          {
            "name": "Debug Mode / Error Exposure",
            "value": "No debug indicators found in page output",
            "status": "pass"
          },
          {
            "name": "Form CSRF Protection",
            "value": "1 form(s) without CSRF tokens",
            "status": "fail",
            "howToFix": "Add CSRF token validation to every form. Most CMS frameworks have built-in CSRF protection — make sure it's enabled on all forms, including search and newsletter signup.",
            "whyMatters": "CSRF is in the OWASP Top 10. Without tokens, attackers can craft pages that automatically submit forms on your site as the victim's browser session."
          },
          {
            "name": "X-Powered-By Header",
            "value": "Nuxt",
            "status": "warning",
            "howToFix": "Remove the X-Powered-By header. PHP: add 'expose_php = Off' to php.ini. Express.js: app.disable('x-powered-by').",
            "whyMatters": "\"Nuxt\" reveals your server technology and version. Attackers use this to find matching CVEs."
          },
          {
            "name": "Inline JavaScript Exposure",
            "value": "468 KB of inline JavaScript",
            "status": "warning",
            "howToFix": "Move inline scripts to external files. Inline JavaScript expands the attack surface for XSS and makes CSP harder to implement (requires unsafe-inline).",
            "whyMatters": "Large amounts of inline JavaScript prevent proper CSP implementation and increase the risk of XSS. External scripts can be protected with SRI hashes."
          },
          {
            "name": "Suspicious Inline Script Patterns",
            "value": "Detected: Payment data exfiltration pattern",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get Malware Scan →"
            },
            "howToFix": "Review all inline scripts for obfuscated code. Magecart attackers inject payment skimmers disguised as analytics or GTM scripts. Compare your current HTML with a known-good version. Consider using CSP with strict nonces.",
            "whyMatters": "These patterns (Base64 decode, eval with encoding, dynamic script injection) are hallmarks of Magecart payment skimmers. The 2024 Akamai report found skimmers disguised as Google Tag Manager on thousands of e-commerce sites."
          },
          {
            "name": "SPF Record (Email Security)",
            "value": "SPF configured: v=spf1 a mx include:_spf.nameserver.sk -all",
            "status": "pass"
          },
          {
            "name": "DMARC Policy (Email Auth)",
            "value": "DMARC set to p=none (monitoring only, no enforcement)",
            "status": "warning",
            "howToFix": "Upgrade DMARC policy from p=none to p=quarantine or p=reject. p=none only monitors — it doesn't block spoofed emails. Start with quarantine, then move to reject after verifying legitimate emails pass.",
            "whyMatters": "DMARC p=none provides zero protection against email spoofing. It only generates reports. Move to p=quarantine to actually block forged emails from reaching your customers' inboxes."
          },
          {
            "name": "DKIM Signing (Email Auth)",
            "value": "DKIM configured (selectors: default)",
            "status": "pass"
          },
          {
            "name": "Cross-Origin Isolation",
            "status": "warning",
            "howToFix": "Add Cross-Origin-Opener-Policy: same-origin and Cross-Origin-Resource-Policy: same-origin headers. These protect against Spectre-type side-channel attacks.",
            "whyMatters": "Without cross-origin isolation headers, your site is vulnerable to Spectre attacks that can leak sensitive data across browser tabs. These headers are required for SharedArrayBuffer and high-resolution timers."
          },
          {
            "name": "Payment Page Security",
            "value": "Payment page missing: No HSTS, No CSP, No X-Content-Type-Options, No clickjacking protection",
            "status": "fail",
            "fixLink": {
              "url": "https://www.inger.sk/#contact",
              "label": "Get PCI Compliance Audit →"
            },
            "howToFix": "CRITICAL: Your payment page is missing security headers: No HSTS, No CSP, No X-Content-Type-Options, No clickjacking protection. PCI DSS Requirement 6.5 mandates protection against common vulnerabilities on pages handling card data.",
            "whyMatters": "Payment pages without proper security headers violate PCI DSS. This can result in fines of $5,000-$100,000/month from payment processors, and makes card data theft significantly easier."
          },
          {
            "name": "Clickjacking on Sensitive Page",
            "value": "Login/payment page without X-Frame-Options or CSP frame-ancestors",
            "status": "fail",
            "howToFix": "URGENT: Add X-Frame-Options: DENY and CSP frame-ancestors 'none' to pages with login forms or payment fields. Attackers can overlay your page in a transparent iframe.",
            "whyMatters": "Clickjacking on payment/login pages is a high-severity vulnerability. Users unknowingly submit credentials or payments through invisible iframes. PCI DSS requires frame-busting on payment pages."
          }
        ]
      },
      "opendata_security": null
    },
    "created_at": "2026-06-13T21:57:38.100081+00:00",
    "status": "complete",
    "platform_detected": "Magento",
    "company_ico": null,
    "company_name": null,
    "company_country": null,
    "company_nace": null,
    "company_size": null,
    "nis2_scope": null,
    "nis2_sector": null,
    "company_risk_score": null,
    "company_risk_level": null
  }
}