Checkout HSTS missing
Security · 96% confidence
Website security headers scanResponse header snapshot shows Strict-Transport-Security is absent on the checkout route.
Demo Checkout Store · checkout.example
This synthetic report shows the customer-facing output structure before registration: risk score, prioritized findings, evidence status, scanned-page context, fix estimate, print/PDF views, and legal boundaries. It does not represent a real customer scan.
Highest-impact findings prioritized by severity and confidence.
3 shown
Security · 96% confidence
Website security headers scanResponse header snapshot shows Strict-Transport-Security is absent on the checkout route.
Consent and tracking · 88% confidence
GA4 consent mode auditViewport observation records the consent banner overlapping the pricing page primary action.
Checkout and forms · 84% confidence
Ecommerce checkout risk scanForm validation observation shows the error copy is visible but not connected to the failed field.
Release, change-control, monitoring, and CI guidance generated from report findings.
weekly cadence
Use this checklist before releasing changes that touch the scanned flows.
Run weekly regression monitoring until high-impact findings are fixed and retested.
Apply this guidance to affected components before release and retest.
Checkout and contact forms
Keep visible labels, programmatic names, focus order, error summaries, required-state cues, and touch targets stable across desktop and mobile breakpoints.
Treat tracking fixes as change-controlled configuration changes.
Document the CMP state, tag trigger, consent defaults, exception path, and rollback owner before publishing GTM, analytics, ad pixel, or CMP changes.
Use these checks where the project toolchain can support them without requiring manual delivery.
Accessibility CI check
Add axe, keyboard, focus, and form-validation checks for the affected flow before merging UI changes.
Tracking consent check
Add a smoke check that verifies analytics and ad tags wait for the expected consent state.
Scheduled monitoring check
Keep a scheduled live scan on the affected path after remediation so regressions are caught without manual review.
1 findings
96% confidence
Response header snapshot shows Strict-Transport-Security is absent on the checkout route.
1 findings
88% confidence
Viewport observation records the consent banner overlapping the pricing page primary action.
1 findings
84% confidence
Form validation observation shows the error copy is visible but not connected to the failed field.
1 findings
76% confidence
Keyboard navigation check did not detect a visible-on-focus skip link on the homepage template.
One high-impact checkout trust issue should be fixed first, followed by conversion and accessibility improvements that can be retested from public pages.
Total issues
4
High
1
Medium
2
Low
1
https://checkout.example/checkout
checkout · HTTP 200
Console 0 · Network 0 · Screenshot yes · HTML yes
https://checkout.example/pricing
pricing · HTTP 200
Console 1 · Network 0 · Screenshot yes · HTML no
https://checkout.example/contact
contact · HTTP 200
Console 0 · Network 0 · Screenshot no · HTML yes
https://checkout.example/
homepage · HTTP 200
Console 0 · Network 0 · Screenshot yes · HTML yes
Prioritize checkout security headers, consent banner placement, form error semantics, then retest the affected pages before enabling monitoring.
This report provides technical findings and remediation recommendations based on automated checks. It is not legal advice, a compliance certification, or a guarantee that every issue has been identified.