https://northstar-components.example/ · Completed 22 Jun 2026
Your score and grade are calculated solely from deterministic checks. AI does not alter them.Read the methodology
Confidence: MediumNo AI advisory review added
Audit health
77/100
High-impact findings
4
Total findings
19
Δ vs last run
—
Executive summary
This wholly synthetic website fixture was assessed by the real deterministic website provider from committed public implementation evidence. Its findings describe only the bounded page, crawl, performance-coverage and technology inputs in that fixture. No traffic, ranking, backlink, revenue or conversion-performance claim is made.
Assessment boundaries
What this report measures
Wholly synthetic golden fixture. Wholly synthetic fixture. No customer or anonymised production data is used.
Configuration and implementation health
77/100, grade C, across 7 categories.
Observed business performance
Not measured. This report makes no revenue, conversion, traffic or commercial-performance judgement from configuration evidence.
Evidence coverage
5 of 6 sources succeeded; 7 of 7 categories were assessed.
Public evidence limits. SpotCheck cannot know traffic volume, organic or keyword positions, backlink authority, market share, conversion performance or all-assistant share of voice from this audit. No third-party analytics or search account connection is required. Policy spotcheck-public-claims-v2.
Public evidence sources
Direct public HTTP fetch (observed, observed public HTTP responses). complete: Submitted origin and validated crawl-scope pages. Captured 22/06/2026, 10:30:00; freshness current as at 22/06/2026, 10:30:00.
Chrome UX Report API (measured, p75 LCP, INP and CLS field metrics). unavailable: Bounded URL and origin field-metric requests. Captured not available; freshness unknown as at 22/06/2026, 10:30:00.
PageSpeed Insights API / Lighthouse (measured, controlled lab metrics and audit scores). unavailable: Bounded mobile and desktop lab requests. Captured not available; freshness unknown as at 22/06/2026, 10:30:00.
Site classification
brochure
high confidence · deterministic · website-site-classifier-v2
Fired signals (1)
Product information with a contact route and no transaction flow
Method and source proof
How this assessment was produced
Each deterministic rule records its outcome and the privacy-safe evidence source it used. Unavailable or error evidence is shown explicitly, never treated as a pass and never used to lower the deterministic score.
Maximum contextual conversion form fields: 0; Rating: Pass; Ignored long non conversion forms: no; Maximum observed fields: 0; Offending purpose: none; Purpose counts: none; Threshold: 0; Total forms: 0.
Decision boundary
Deduct when any observed conversion form has more than 7 visible fields.
Structured proof
1 of 1 sources available; 0 findings, 0 point impact
Compare bounded technical observations from isolated browser contexts before choice, after reject and after accept.
Rule ID
website.check.trust.cookie-consent.v1
Taxonomy
technical risk (website-rule-taxonomy-v1)
Applicability
all site types; homepage; registered predicate
Evidence predicate
website.check.trust.cookie-consent.v1, available evidence required
Score authority
Scored, capped at 12 points per finding and 12 points per audit
Method authority
ICO guidance on cookies and similar technologies, reviewed 12/07/2026
Observed result
Consent state observation: 0; Accept known tracking count: 1; Banner detected: yes; Baseline known tracking count: 0; Limited: no; Reject interaction: clicked_direct; Reject known tracking count: 0; Unknown item count: 0.
Decision boundary
Apply at most one deduction when known tracking signals are observed before choice or remain after a successful reject interaction. Unavailable and unknown evidence is neutral.
Structured proof
1 of 1 sources available; 0 findings, 0 point impact
Deduct once for grouped critical or serious axe violations that are not already owned by existing static checks; unavailable axe execution is coverage only.
Structured proof
1 of 1 sources available; 0 findings, 0 point impact
These records identify the bounded source used by each rule. They contain labels, coverage state and non-identifying page roles, not raw customer payloads.
website.evidence.sha256.b1ed4fcb654e2669e9456b9d35b0c647615f863b1409bc0a15308a5ea44cbb8dweb.performance.coverageNo usable field or lab performance measurement was available.
Showing all findings across every owner. Pick a tab above to retell the same audit through one role's lens.
19 findings match this audience.
Category radar
Where this site stands
Higher is better. The shaded shape is this site; the dashed line is the portfolio median for brochure websites SpotCheck has audited.
Strongest category: Accessibility at 96/100. Lowest category: Trust and security at 58/100. A reliable compatible benchmark is not available for this chart.
This site
View category radar data
Category radar values, 0 to 100 points
Category
This site
Performance and Core Web Vitals
88/100
SEO health
67/100
AI discovery readiness
92/100
Conversion readiness
70/100
Trust and security
58/100
Accessibility
96/100
Tracking and data
75/100
Benchmark values appear only for compatible cohorts with enough retained audits to be reliable.
Impact × Effort
Where to focus
Each dot is a finding. Top-left means quick wins and top-right means strategic projects. Use the chart or the finding controls below to jump to a finding.
12 plotted findings look like quick wins. Highest plotted impact: No analytics tracking detected, 9/10 impact and about 3 hours.
Findings in the chart
5/10 impact, about 4 hours, Web/CMS
5/10 impact, about 2 hours, Web/CMS
3/10 impact, about 1 hours, Web/CMS
3/10 impact, about 1 hours, Web/CMS
5/10 impact, about 4 hours, Web/CMS
5/10 impact, about 4 hours, Marketing Ops
7/10 impact, about 3 hours, Web/CMS
5/10 impact, about 2 hours, Web/CMS
7/10 impact, about 4 hours, Marketing Ops
7/10 impact, about 4 hours, Marketing Ops
5/10 impact, about 2 hours, IT/Security
5/10 impact, about 2 hours, IT/Security
3/10 impact, about 2 hours, IT/Security
3/10 impact, about 2 hours, IT/Security
3/10 impact, about 2 hours, IT/Security
5/10 impact, about 4 hours, IT/Security
3/10 impact, about 1 hours, Marketing Ops
3/10 impact, about 2 hours, Web/CMS
9/10 impact, about 3 hours, Data Team
View impact and effort data
Impact and effort values for plotted findings
Finding
Severity
Impact
Effort
Owner
Images are not served in modern formats
medium
5/10
4 hours
Web/CMS
Page measurably overflows a phone viewport
medium
5/10
2 hours
Web/CMS
Title tags are suboptimal length
low
3/10
1 hours
Web/CMS
Meta descriptions are suboptimal length
low
3/10
1 hours
Web/CMS
Pages are missing canonical tags
medium
5/10
4 hours
Web/CMS
Internal linking is sparse
medium
5/10
4 hours
Marketing Ops
Missing Organisation structured data
high
7/10
3 hours
Web/CMS
No content date metadata found anywhere on the site
medium
5/10
2 hours
Web/CMS
No high-intent call-to-action for this type of site
high
7/10
4 hours
Marketing Ops
No pricing information or honest expectation-setting found
high
7/10
4 hours
Marketing Ops
Missing Content-Security-Policy header
medium
5/10
2 hours
IT/Security
Missing X-Frame-Options protection
medium
5/10
2 hours
IT/Security
Missing X-Content-Type-Options header
low
3/10
2 hours
IT/Security
Missing Referrer-Policy header
low
3/10
2 hours
IT/Security
Missing Permissions-Policy header
low
3/10
2 hours
IT/Security
No terms of service or legal page found
medium
5/10
4 hours
IT/Security
No visible company identity information
low
3/10
1 hours
Marketing Ops
No skip-navigation link found
low
3/10
2 hours
Web/CMS
No analytics tracking detected
critical
9/10
3 hours
Data Team
Critical High Medium Low Info
Severity heatmap
Where the fire is
Categories down, severities across. Cell intensity scales with finding count.
Critical
High
Medium
Low
Info
Total
Performance and Core Web Vitals
0
0
2
0
0
2
SEO health
0
1
2
2
0
5
AI discovery readiness
0
0
1
0
0
1
Conversion readiness
0
2
0
0
0
2
Trust and security
0
0
3
4
0
7
Accessibility
0
0
0
1
0
1
Tracking and data
1
0
0
0
0
1
Public field and Lighthouse lab evidence
Performance measurements
CrUX field evidence records public, real-user p75 Core Web Vitals. Lighthouse lab evidence is a controlled diagnostic run. Lab Total Blocking Time is not a Core Web Vital and is not field INP. Deterministic scoring may use this evidence; this display does not apply any additional score or grade adjustment.
No Lighthouse lab request was recorded for this run.
Technical consent observation
Before choice, reject and accept
Three fresh browser contexts were measured independently. Only bounded technical categories and opaque evidence identifiers were retained. Cookie values, storage values and complete request URLs were discarded before persistence.
Page role
homepage
Locale
en-GB
Timezone
Europe/London
Egress geography
Unknown
Geolocation permission
Not granted
Screenshot state
Before choice
Method
website-consent-three-state-v1
Guidance reviewed
12 Jul 2026
Before choice
Observed
No choice made
Captured
22 Jun 2026, 10:30:00
Duration
1200 ms
Known signals
1
Unknown signals
0
Banner
Detected
CMP
OneTrust
Accept control
Found
Reject control
Found
Settings control
Found
Consent preference storageconsent management · 1
After reject
Observed
Direct control used
Captured
22 Jun 2026, 10:30:00
Duration
1350 ms
Known signals
1
Unknown signals
0
Banner
Detected
CMP
OneTrust
Accept control
Found
Reject control
Found
Settings control
Found
Consent preference storageconsent management · 1
After accept
Observed
Direct control used
Captured
22 Jun 2026, 10:30:00
Duration
1400 ms
Known signals
2
Unknown signals
0
Banner
Detected
CMP
OneTrust
Accept control
Found
Reject control
Found
Settings control
Found
Analytics storageanalytics · 1
Consent preference storageconsent management · 1
This is a bounded technical observation from one configured browser execution. It is not legal advice or a compliance certification. Requirements and exceptions depend on purpose, implementation and jurisdiction. Region-dependent behaviour may differ, and unknown signals are not classified.
Method limitations and primary sources
single browser visit
service workers blocked
region dependent behaviour may differ
technical categories are not legal classifications
request observation does not prove payload or receipt
Each category is scored out of 100 and contributes to the overall grade by its weight. The rationale explains what moved each score.
Category
Grade
Score
Weight
Confidence
Why
Performance and Core Web Vitals
B
88
16%
Medium
Public field Core Web Vitals were unavailable; no points were lost for missing CrUX coverage. Lighthouse lab diagnostics were unavailable; no lab deduction was applied. Images are not served in modern formats. Page measurably overflows a phone viewport.
SEO health
C
67
18%
Medium
Title tags are suboptimal length. Meta descriptions are suboptimal length. Pages are missing canonical tags. Internal linking is sparse. Missing Organisation structured data.
AI discovery readiness
A
92
14%
Medium
No crawler-specific policy from crawler-purpose-matrix-v1-2026-07-12 was declared. This is informational and does not affect the score. No llms.txt proposal file was detected. The file is optional and experimental, and Google documents no Search visibility or ranking effect; no score or recommendation is affected. The answer-first paragraph check was skipped: fewer than 10 paragraphs were available to sample. No content date metadata found anywhere on the site. No citation-style source links (<cite> elements or citation-worded links) were observed in the sampled pages. This is a factual observation, not a quality score.
Conversion readiness
C
70
18%
High
No high-intent call-to-action for this type of site. No pricing information or honest expectation-setting found.
Trust and security
D
58
14%
Medium
Missing Content-Security-Policy header. Missing X-Frame-Options protection. Missing X-Content-Type-Options header. Missing Referrer-Policy header. Missing Permissions-Policy header. No terms of service or legal page found. No visible company identity information.
Accessibility
A
96
12%
Medium
No skip-navigation link found. Axe-core rendered accessibility evidence was unavailable; no points were lost for missing automation coverage. Rendered keyboard, reflow and target-size smoke evidence was unavailable; no points were lost for missing smoke-test coverage.
Tracking and data
C
75
8%
High
No analytics tracking detected.
Quick wins
Ship these in the next two hours each
High-leverage changes that don't need a project plan. Effort figures are indicative. Copy any card as ticket text with one click.
~2h
Page measurably overflows a phone viewport
https://northstar-components.example/ was rendered at a 390px phone viewport and its document measured 48px wider than the viewport, forcing horizontal scrolling on mobile.
Web/CMS
~2h
No content date metadata found anywhere on the site
No published/modified date metadata (article:published_time, article:modified_time, <time datetime>, or Last-Modified header) was found on any analysed page. Readers and automated parsers therefore have no explicit machine-readable freshness signal; this does not establish how any model will judge the content.
Web/CMS
~2h
Missing Content-Security-Policy header
No Content-Security-Policy header is set, so the browser has no allowlist restricting which scripts and resources may load, weakening XSS protection.
IT/Security
~2h
Missing X-Frame-Options protection
Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the site can be framed by other origins (a clickjacking risk).
IT/Security
~1h
Title tags are suboptimal length
1 page(s) have a title under 30 or over 60 characters, so they may be truncated or under-descriptive in search results. Affected: https://northstar-components.example/. The observed value is 20 characters; 30-60 is the soft guideline. These lengths are soft SEO guidelines, not hard rules: search engines index pages outside these ranges, so treat this as tuning guidance rather than a defect.
Web/CMS
~1h
Meta descriptions are suboptimal length
1 page(s) have a meta description under 120 or over 160 characters, so it may be truncated or too thin in search results. Affected: https://northstar-components.example/. The observed value is 69 characters; 120-160 is the soft guideline. These lengths are soft SEO guidelines, not hard rules: search engines index pages outside these ranges, so treat this as tuning guidance rather than a defect.
Web/CMS
Roadmap
30 / 60 / 90 day plan
Prioritised by severity, impact, effort, confidence and simple dependency order. Owner suggestions are heuristic; adjust to your team. Effort figures are indicative.
Next 30 days
6
Critical and high-impact items first
No verified analytics, tag-management or CRM-marketing measurement beacon was observed on the public site. Static tag signatures alone are treated as detected technology, not proof of healthy measurement.
Why now: critical severity with roughly 3h indicative effort; prioritised before lower-confidence or lower-impact work.
Outcome: Reduce or remove the critical risk described by "No analytics tracking detected", protecting an impact score of 9/10.
Verify: Re-run SpotCheck and confirm finding website.finding.sha256.3dcba88175fb7140360a5cc87c7ad0b028ae4fe8c7e5e4104b7aaf72e523275c is resolved or materially reduced.
Data Teammandatory defectspecialist~3himpact 9/10
No Organization JSON-LD was found anywhere on the analysed pages. This schema can provide search engines with explicit organisation details. It is an optional machine-readable enhancement; eligibility for any Google Search feature depends on that feature's current official requirements and is never guaranteed.
Why now: high severity with roughly 3h indicative effort; prioritised before lower-confidence or lower-impact work.
Outcome: Reduce or remove the high risk described by "Missing Organisation structured data", protecting an impact score of 7/10.
Verify: Re-run SpotCheck and confirm finding website.finding.sha256.8e5474a88212891d8c0f8a5cc2e1dcf70c10188a2e71edba85877e6590068396 is resolved or materially reduced.
Web/CMSmandatory defectinternal~3himpact 7/10
CTAs were found, but none match the high-intent actions expected for a brochure site (get in touch, contact us, enquire, email us). Visitors ready to act have no clear path.
Why now: high severity with roughly 4h indicative effort; prioritised before lower-confidence or lower-impact work.
Outcome: Reduce or remove the high risk described by "No high-intent call-to-action for this type of site", protecting an impact score of 7/10.
Verify: Re-run SpotCheck and confirm finding website.finding.sha256.0fb57eb975249c641f3f1043a74f1a4df02baa704bbc4f9e7a287a7f2a5ae531 is resolved or materially reduced.
For a brochure site, neither pricing numbers nor an honest expectation-setting path (a described quote process, a starting price, or a typical range) was found. A bare "Contact us" gives prospective buyers no useful expectation about cost or process.
Why now: high severity with roughly 4h indicative effort; prioritised before lower-confidence or lower-impact work.
Outcome: Reduce or remove the high risk described by "No pricing information or honest expectation-setting found", protecting an impact score of 7/10.
Verify: Re-run SpotCheck and confirm finding website.finding.sha256.0374494588a3881cbbed8016930b8843cd5d6aa0aff21574410a0b69e1e51094 is resolved or materially reduced.
https://northstar-components.example/ was rendered at a 390px phone viewport and its document measured 48px wider than the viewport, forcing horizontal scrolling on mobile.
Why now: medium severity with roughly 2h indicative effort; prioritised before lower-confidence or lower-impact work.
Outcome: Reduce or remove the medium risk described by "Page measurably overflows a phone viewport", protecting an impact score of 5/10.
Verify: Re-run SpotCheck and confirm finding website.finding.sha256.04744248d333bfe069eccd0941b61b809a25e28c65605afdb329789272034846 is resolved or materially reduced.
Web/CMSrisk reductioninternal~2himpact 5/10
No published/modified date metadata (article:published_time, article:modified_time, <time datetime>, or Last-Modified header) was found on any analysed page. Readers and automated parsers therefore have no explicit machine-readable freshness signal; this does not establish how any model will judge the content.
Why now: medium severity with roughly 2h indicative effort; prioritised before lower-confidence or lower-impact work.
Outcome: Reduce or remove the medium risk described by "No content date metadata found anywhere on the site", protecting an impact score of 5/10.
Verify: Re-run SpotCheck and confirm finding website.finding.sha256.8d3c0be2d2ee9fc20848214eba52eea0991c2dad301418a9cfe117396c7b6e1a is resolved or materially reduced.
Web/CMSrisk reductioninternal~2himpact 5/10
Days 31–60
3
Medium-impact follow-ups
No Content-Security-Policy header is set, so the browser has no allowlist restricting which scripts and resources may load, weakening XSS protection.
Why now: medium severity with roughly 2h indicative effort; prioritised before lower-confidence or lower-impact work.
Outcome: Reduce or remove the medium risk described by "Missing Content-Security-Policy header", protecting an impact score of 5/10.
Verify: Re-run SpotCheck and confirm finding website.finding.sha256.7c6199e140db48a0a68a6b64d8207b08f1553420c3c15ed2ebf398c3c96d3823 is resolved or materially reduced.
IT/Securityrisk reductionspecialist~2himpact 5/10
Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the site can be framed by other origins (a clickjacking risk).
Why now: medium severity with roughly 2h indicative effort; prioritised before lower-confidence or lower-impact work.
Outcome: Reduce or remove the medium risk described by "Missing X-Frame-Options protection", protecting an impact score of 5/10.
Verify: Re-run SpotCheck and confirm finding website.finding.sha256.047e6d6f873c5632bf1a68139462acdb52c5c0bdab658eb266c589c49e05ad4a is resolved or materially reduced.
IT/Securityrisk reductionspecialist~2himpact 5/10
On https://northstar-components.example/, over half of images (1 of 1) are JPEG/PNG with no WebP/AVIF alternative via srcset or <picture>.
Why now: medium severity with roughly 4h indicative effort; prioritised before lower-confidence or lower-impact work.
Outcome: Reduce or remove the medium risk described by "Images are not served in modern formats", protecting an impact score of 5/10.
Verify: Re-run SpotCheck and confirm finding website.finding.sha256.cd0ee6585daa22b6dd0bc52bb7dd2c0144bd8196e378581a8a1cee9c249511c1 is resolved or materially reduced.
Web/CMSrisk reductioninternal~4himpact 5/10
Days 61–90
6
Cleanup and longer-running work
1 page(s) have a title under 30 or over 60 characters, so they may be truncated or under-descriptive in search results. Affected: https://northstar-components.example/. The observed value is 20 characters; 30-60 is the soft guideline. These lengths are soft SEO guidelines, not hard rules: search engines index pages outside these ranges, so treat this as tuning guidance rather than a defect.
Why now: low severity with roughly 1h indicative effort; prioritised before lower-confidence or lower-impact work.
Outcome: Reduce or remove the low risk described by "Title tags are suboptimal length", protecting an impact score of 3/10.
Verify: Re-run SpotCheck and confirm finding website.finding.sha256.912fe67ee127cced8dd87df52133f1319825b2256b4978060e6ac3abe5707618 is resolved or materially reduced.
Web/CMSrisk reductioninternal~1himpact 3/10
1 page(s) have a meta description under 120 or over 160 characters, so it may be truncated or too thin in search results. Affected: https://northstar-components.example/. The observed value is 69 characters; 120-160 is the soft guideline. These lengths are soft SEO guidelines, not hard rules: search engines index pages outside these ranges, so treat this as tuning guidance rather than a defect.
Why now: low severity with roughly 1h indicative effort; prioritised before lower-confidence or lower-impact work.
Outcome: Reduce or remove the low risk described by "Meta descriptions are suboptimal length", protecting an impact score of 3/10.
Verify: Re-run SpotCheck and confirm finding website.finding.sha256.896d7d7a382f1422b10b8c9c4cfa74123c36b928a0d9347ffdb2cd96501f8a5f is resolved or materially reduced.
Web/CMSrisk reductioninternal~1himpact 3/10
No company registration number, VAT number, or physical address was found anywhere on the analysed pages. Visible company identity helps visitors understand who operates the site; this is usually a one-line omission rather than a decision.
Why now: low severity with roughly 1h indicative effort; prioritised before lower-confidence or lower-impact work.
Outcome: Reduce or remove the low risk described by "No visible company identity information", protecting an impact score of 3/10.
Verify: Re-run SpotCheck and confirm finding website.finding.sha256.500995e464505bd672fc9337a1aca0fa3af99652b802f01903d38f1a40e612f7 is resolved or materially reduced.
Marketing Opsrisk reductioninternal~1himpact 3/10
Fewer than half of the analysed pages (0 of 1) have a <link rel="canonical">, which risks duplicate-content ambiguity for search engines.
Why now: medium severity with roughly 4h indicative effort; prioritised before lower-confidence or lower-impact work.
Outcome: Reduce or remove the medium risk described by "Pages are missing canonical tags", protecting an impact score of 5/10.
Verify: Re-run SpotCheck and confirm finding website.finding.sha256.9c2258a978d9df08adc0dd2abb845243706a29733d470223f0704372ef016ac7 is resolved or materially reduced.
Web/CMSrisk reductioninternal~4himpact 5/10
Pages average 1 inbound internal links each (sparse is 1-2.9).
Why now: medium severity with roughly 4h indicative effort; prioritised before lower-confidence or lower-impact work.
Outcome: Reduce or remove the medium risk described by "Internal linking is sparse", protecting an impact score of 5/10.
Verify: Re-run SpotCheck and confirm finding website.finding.sha256.90ea7686a2bc3221e37b794069a5a37cf813dbffbc9b01a65230ced3d24c5d0b is resolved or materially reduced.
Marketing Opsrisk reductioninternal~4himpact 5/10
No terms of service or legal page was discoverable on the site, and no terms/legal link was found on the homepage. Most businesses need this to set the contractual basis for using the site or service.
Why now: medium severity with roughly 4h indicative effort; prioritised before lower-confidence or lower-impact work.
Outcome: Reduce or remove the medium risk described by "No terms of service or legal page found", protecting an impact score of 5/10.
Verify: Re-run SpotCheck and confirm finding website.finding.sha256.1e9813df90f30eb66b23086516f3ae52481b1f01732a7ba9d5e885349087328e is resolved or materially reduced.
IT/Securityrisk reductionspecialist~4himpact 5/10
plus 6 further items, prioritised in the findings table
Findings
19 of 19 findings shown
Search, filter, sort and expand findings. Results update without leaving this report.
19 findings shown after filtering and sorting.
Severity
Category
Owner
Fix type
Owner
Critical
No analytics tracking detected
Specialist
Tracking and data
Data Team
9/10
3h
High
Missing Organisation structured data
DIY
SEO health
Web/CMS
7/10
3h
High
No high-intent call-to-action for this type of site
Specialist
Conversion readiness
Marketing Ops
7/10
4h
High
No pricing information or honest expectation-setting found
Specialist
Conversion readiness
Marketing Ops
7/10
4h
Medium
Images are not served in modern formats
DIY
Performance and Core Web Vitals
Web/CMS
5/10
4h
Medium
Page measurably overflows a phone viewport
DIY
Performance and Core Web Vitals
Web/CMS
5/10
2h
Medium
Pages are missing canonical tags
DIY
SEO health
Web/CMS
5/10
4h
Medium
Internal linking is sparse
DIY
SEO health
Marketing Ops
5/10
4h
Medium
No content date metadata found anywhere on the site
DIY
AI discovery readiness
Web/CMS
5/10
2h
Medium
Missing Content-Security-Policy header
Specialist
Trust and security
IT/Security
5/10
2h
Medium
Missing X-Frame-Options protection
Specialist
Trust and security
IT/Security
5/10
2h
Medium
No terms of service or legal page found
Specialist
Trust and security
IT/Security
5/10
4h
Low
Title tags are suboptimal length
DIY
SEO health
Web/CMS
3/10
1h
Low
Meta descriptions are suboptimal length
DIY
SEO health
Web/CMS
3/10
1h
Low
Missing X-Content-Type-Options header
Specialist
Trust and security
IT/Security
3/10
2h
Low
Missing Referrer-Policy header
Specialist
Trust and security
IT/Security
3/10
2h
Low
Missing Permissions-Policy header
Specialist
Trust and security
IT/Security
3/10
2h
Low
No visible company identity information
DIY
Trust and security
Marketing Ops
3/10
1h
Low
No skip-navigation link found
DIY
Accessibility
Web/CMS
3/10
2h
No analytics tracking detected
Critical
Category
Tracking and data
Owner
Data Team
Impact
9/10
Effort
3h
Missing Organisation structured data
High
Category
SEO health
Owner
Web/CMS
Impact
7/10
Effort
3h
No high-intent call-to-action for this type of site
High
Category
Conversion readiness
Owner
Marketing Ops
Impact
7/10
Effort
4h
No pricing information or honest expectation-setting found
High
Category
Conversion readiness
Owner
Marketing Ops
Impact
7/10
Effort
4h
Images are not served in modern formats
Medium
Category
Performance and Core Web Vitals
Owner
Web/CMS
Impact
5/10
Effort
4h
Page measurably overflows a phone viewport
Medium
Category
Performance and Core Web Vitals
Owner
Web/CMS
Impact
5/10
Effort
2h
Pages are missing canonical tags
Medium
Category
SEO health
Owner
Web/CMS
Impact
5/10
Effort
4h
Internal linking is sparse
Medium
Category
SEO health
Owner
Marketing Ops
Impact
5/10
Effort
4h
No content date metadata found anywhere on the site
Medium
Category
AI discovery readiness
Owner
Web/CMS
Impact
5/10
Effort
2h
Missing Content-Security-Policy header
Medium
Category
Trust and security
Owner
IT/Security
Impact
5/10
Effort
2h
Missing X-Frame-Options protection
Medium
Category
Trust and security
Owner
IT/Security
Impact
5/10
Effort
2h
No terms of service or legal page found
Medium
Category
Trust and security
Owner
IT/Security
Impact
5/10
Effort
4h
Title tags are suboptimal length
Low
Category
SEO health
Owner
Web/CMS
Impact
3/10
Effort
1h
Meta descriptions are suboptimal length
Low
Category
SEO health
Owner
Web/CMS
Impact
3/10
Effort
1h
Missing X-Content-Type-Options header
Low
Category
Trust and security
Owner
IT/Security
Impact
3/10
Effort
2h
Missing Referrer-Policy header
Low
Category
Trust and security
Owner
IT/Security
Impact
3/10
Effort
2h
Missing Permissions-Policy header
Low
Category
Trust and security
Owner
IT/Security
Impact
3/10
Effort
2h
No visible company identity information
Low
Category
Trust and security
Owner
Marketing Ops
Impact
3/10
Effort
1h
No skip-navigation link found
Low
Category
Accessibility
Owner
Web/CMS
Impact
3/10
Effort
2h
Growth opportunities and manual checks
2 of 2 opportunities shown
These items are actionable but non-scored. They are not defects, do not enter the fix basket, and do not affect the roadmap or commercial estimate.
Search, filter, sort and expand opportunities. Results update without leaving this report.
2 opportunities shown after filtering and sorting.
Severity
Category
Owner
Owner
Info
Possible content-coverage gaps against homepage offerings (hypothesis only)
AI discovery readiness
Marketing Ops
Non-scored
Not estimated
Info
No lead capture mechanism found
Conversion readiness
Marketing Ops
Non-scored
Not estimated
Possible content-coverage gaps against homepage offerings (hypothesis only)
Info
Category
AI discovery readiness
Owner
Marketing Ops
Impact
Non-scored
Effort
Not estimated
No lead capture mechanism found
Info
Category
Conversion readiness
Owner
Marketing Ops
Impact
Non-scored
Effort
Not estimated
AI visual review
Visual review coverage
Synthetic fixture. No screenshot or model review is required.
Coverage
What was checked, what wasn't
An honest read on how complete this run was. A skipped or unavailable check reduces what could be assessed, not the score. Common causes include a page not loading, crawling being blocked, or public performance data being unavailable.
76 of 105 produced a result 10 not applicable 19 could not be run 0 errored
Performance and Core Web Vitals8/14 checked, 6 skipped (6 checked: no issue found, 2 checked: issue flagged, 6 not assessed: evidence unavailable)
SEO health30/36 checked, 4 skipped, 2 not applicable (25 checked: no issue found, 5 checked: issue flagged, 2 not applicable, 4 not assessed: evidence unavailable)
AI discovery readiness10/12 checked, 1 skipped, 1 not applicable (8 checked: no issue found, 2 checked: issue flagged, 1 not applicable, 1 not assessed: evidence unavailable)
Conversion readiness8/11 checked, 3 not applicable (5 checked: no issue found, 3 checked: issue flagged, 3 not applicable)
Trust and security13/17 checked, 3 skipped, 1 not applicable (6 checked: no issue found, 7 checked: issue flagged, 1 not applicable, 3 not assessed: evidence unavailable)
Accessibility5/11 checked, 5 skipped, 1 not applicable (4 checked: no issue found, 1 checked: issue flagged, 1 not applicable, 5 not assessed: evidence unavailable)
Tracking and data2/4 checked, 2 not applicable (1 checked: no issue found, 1 checked: issue flagged, 2 not applicable)
Free HubSpot audit
Now audit your HubSpot portal
SpotCheck® also runs a free HubSpot portal audit covering security, data quality, automation, and whether you're getting full value from your licence tier.
SpotDev help is optional. Nothing is selected unless you choose it. Recommended means critical or high-severity specialist findings, and AI review notes are advisory, not confirmed fixes.