Evidence: security probe returned HTTP 403. Cloudflare header(s): cf-ray, server. URL: https://sadfinder.com/wp-config.php
Review Cloudflare WAF, bot protection, rate-limit, and challenge rules for public marketing/content routes. Allow safe public scans and legitimate search or AI user-fetch crawlers to reach public pages while keeping admin, authenticated, preview, and private paths protected.
Speed Insights
Grade C
77% performance
https://sadfinder.com
LCP
1.0s
Largest paint
TBT
693ms
Blocking time
CLS
0.000
Layout shift
77
out of 100
91
out of 100
101/111 rule points
76
out of 100
58/76 rule points
57
out of 100
54/94 rule points
83
out of 100
91/110 rule points
Category point breakdown
Biggest score-losing checks
Add common public security headers
-18 rule ptsWhat failed
Several basic browser protection headers were not visible.
Evidence
Detected 0 of 5 common public security controls. Present: none. Missing: strict-transport-security, content-security-policy, x-content-type-options, frame protection (x-frame-options or content-security-policy frame-ancestors), referrer-policy.
Priority
Priority 5: fix before sharing the page publicly.
Why it matters
These headers reduce avoidable browser-side risk and show a baseline of care before launch.
How to fix it
Add only the missing protections among Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, frame protection, and Referrer-Policy. An existing CSP frame-ancestors directive already provides frame protection and must remain unchanged.
Agent Prompt
Fix rendered axe accessibility violations
-18 rule ptsWhat failed
The rendered page has accessibility rule violations detected by axe-core.
Evidence
axe found 2 violation rule(s), including 2 serious or critical rule(s). Top rules: aria-prohibited-attr (3), color-contrast (18).
Affected elements
Elements must only use permitted ARIA attributes
Fix all of the following: aria-label attribute cannot be used on a div with no valid role attribute.
Elements must only use permitted ARIA attributes
Fix all of the following: aria-label attribute cannot be used on a div with no valid role attribute.
Elements must only use permitted ARIA attributes
Fix all of the following: aria-label attribute cannot be used on a div with no valid role attribute.
15 items
Priority
Priority 5: fix before sharing the page publicly.
Why it matters
axe checks the actual browser-rendered page, so these issues can affect people using keyboards, screen readers, or other assistive technology.
How to fix it
Fix the top axe rule IDs first, especially critical and serious violations around names, roles, labels, headings, contrast, landmarks, and keyboard-accessible controls.
Agent Prompt
Label public form fields
-14 rule ptsWhat failed
Some form controls do not have a detectable label or accessible name.
Evidence
Detected labels or accessible names for 3 of 5 form control(s).
Priority
Priority 7: fix during launch polish.
Why it matters
Unlabeled inputs make email capture, demo requests, and signups harder for assistive technology users.
How to fix it
Connect each input to a visible label or an accurate aria-label/aria-labelledby value.
Agent Prompt
Add a useful meta description
-10 rule ptsWhat failed
The page does not expose a strong short summary for search and answer engines.
Evidence
Meta description is 205 characters.
Priority
Priority 3: fix before sharing the page publicly.
Why it matters
A missing description makes previews weaker when early users share or find the page.
How to fix it
Add a meta description around 50 to 170 characters that says who the product helps and what outcome it creates.
Agent Prompt
Fix rendered layout ergonomics
-9 rule ptsWhat failed
The browser-rendered page has layout or tap-target issues.
Evidence
Horizontal overflow: 0px. Small tap targets: 57.
Affected elements
Skip to content
SADFinder
Pricing
Demo
Priority
Priority 13: fix during launch polish.
Why it matters
Horizontal overflow and tiny tap targets make the page feel broken on real devices, especially for mobile visitors.
How to fix it
Remove elements wider than the viewport, add responsive constraints, and make important links, buttons, inputs, and controls at least 40px tall and wide where possible.
Agent Prompt
SEO / AEO
Severity mix: 1 critical, 7 high, 3 medium, 1 low.
Meta description
-10 rule ptsMeta description is 205 characters.
Security
Severity mix: 2 critical, 3 high, 0 medium, 0 low.
Common security headers
-18 rule ptsDetected 0 of 5 common public security controls. Present: none. Missing: strict-transport-security, content-security-policy, x-content-type-options, frame protection (x-frame-options or content-security-policy frame-ancestors), referrer-policy.
Accessibility
Severity mix: 0 critical, 3 high, 5 medium, 0 low.
Rendered axe accessibility violations
-18 rule ptsaxe found 2 violation rule(s), including 2 serious or critical rule(s). Top rules: aria-prohibited-attr (3), color-contrast (18).
Affected elements
Elements must only use permitted ARIA attributes
Fix all of the following: aria-label attribute cannot be used on a div with no valid role attribute.
Elements must only use permitted ARIA attributes
Fix all of the following: aria-label attribute cannot be used on a div with no valid role attribute.
Elements must only use permitted ARIA attributes
Fix all of the following: aria-label attribute cannot be used on a div with no valid role attribute.
15 items
Form labels
-14 rule ptsDetected labels or accessible names for 3 of 5 form control(s).
Basic contrast
-8 rule pts27 of 100 rendered text color sample(s) missed WCAG contrast targets. Worst rendered ratio: 1.25.
Affected elements
English
SADFinder
File
Edit
Design
Severity mix: 0 critical, 3 high, 6 medium, 2 low.
Trust signals
-10 rule ptsDetected 0 trust-signal keyword occurrence(s).
Rendered layout ergonomics
-9 rule ptsHorizontal overflow: 0px. Small tap targets: 57.
Affected elements
Skip to content
SADFinder
Pricing
Demo
Failed checks
These checks need attention.
Meta description
0/10Meta description is 205 characters.
Failed: earned 0 of 10 points.
Priority: Priority 3: fix before sharing the page publicly.
Why it matters: A missing description makes previews weaker when early users share or find the page.
Fix: Add a meta description around 50 to 170 characters that says who the product helps and what outcome it creates.
Agent Prompt
Common security headers
0/18Detected 0 of 5 common public security controls. Present: none. Missing: strict-transport-security, content-security-policy, x-content-type-options, frame protection (x-frame-options or content-security-policy frame-ancestors), referrer-policy.
Failed: earned 0 of 18 points.
Priority: Priority 5: fix before sharing the page publicly.
Why it matters: These headers reduce avoidable browser-side risk and show a baseline of care before launch.
Fix: Add only the missing protections among Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, frame protection, and Referrer-Policy. An existing CSP frame-ancestors directive already provides frame protection and must remain unchanged.
Agent Prompt
Form labels
0/14Detected labels or accessible names for 3 of 5 form control(s).
Failed: earned 0 of 14 points.
Priority: Priority 7: fix during launch polish.
Why it matters: Unlabeled inputs make email capture, demo requests, and signups harder for assistive technology users.
Fix: Connect each input to a visible label or an accurate aria-label/aria-labelledby value.
Agent Prompt
Basic contrast
0/827 of 100 rendered text color sample(s) missed WCAG contrast targets. Worst rendered ratio: 1.25.
Affected elements
English
SADFinder
File
Edit
Failed: earned 0 of 8 points.
Priority: Priority 20: lower-risk cleanup after urgent launch blockers.
Why it matters: Low contrast makes a launch page feel less polished and can exclude users with low vision.
Fix: Review key text, buttons, and links against a 4.5:1 contrast target for normal text.
Agent Prompt
Rendered axe accessibility violations
0/18axe found 2 violation rule(s), including 2 serious or critical rule(s). Top rules: aria-prohibited-attr (3), color-contrast (18).
Affected elements
Elements must only use permitted ARIA attributes
Fix all of the following: aria-label attribute cannot be used on a div with no valid role attribute.
Elements must only use permitted ARIA attributes
Fix all of the following: aria-label attribute cannot be used on a div with no valid role attribute.
Elements must only use permitted ARIA attributes
Fix all of the following: aria-label attribute cannot be used on a div with no valid role attribute.
15 items
Failed: earned 0 of 18 points.
Priority: Priority 5: fix before sharing the page publicly.
Why it matters: axe checks the actual browser-rendered page, so these issues can affect people using keyboards, screen readers, or other assistive technology.
Fix: Fix the top axe rule IDs first, especially critical and serious violations around names, roles, labels, headings, contrast, landmarks, and keyboard-accessible controls.
Agent Prompt
Trust signals
0/10Detected 0 trust-signal keyword occurrence(s).
Failed: earned 0 of 10 points.
Priority: Priority 16: lower-risk cleanup after urgent launch blockers.
Why it matters: Trust signals reduce hesitation when strangers see the product for the first time.
Fix: Add honest proof such as customer quotes, usage stats, founder credibility, security notes, or relevant logos.
Agent Prompt
Rendered layout ergonomics
0/9Horizontal overflow: 0px. Small tap targets: 57.
Affected elements
Skip to content
SADFinder
Pricing
Demo
Failed: earned 0 of 9 points.
Priority: Priority 13: fix during launch polish.
Why it matters: Horizontal overflow and tiny tap targets make the page feel broken on real devices, especially for mobile visitors.
Fix: Remove elements wider than the viewport, add responsive constraints, and make important links, buttons, inputs, and controls at least 40px tall and wide where possible.
Agent Prompt
Page-level AEO readiness
Shared eligibility and content signals that affect every search and answer agent.
Index and citation eligibility
No general noindex directive was detected.
Snippet and answer controls
No general nosnippet or max-snippet:0 control was detected.
Canonical alignment
The canonical resolves to the scanned public URL.
Sitemap coverage and freshness
A sitemap index was found; this safe scan did not recursively fetch child sitemaps.
Structured data
Semantic schema score 80/100. Detected 2 JSON-LD block(s), 0 parse error(s), 10 graph node(s), and types ContactPoint, ImageObject, Offer, Organization, Person, Place, SoftwareApplication, WebSite. The schema type matches the detected page role.
Public or paywalled content
No isAccessibleForFree structured-data value was detected.
Entity clarity
Entity alignment scored 85/100 for “Work faster with a better Finder that snaps windows with one keystroke. with themes that fit your style. with a path bar you can type into. where Enter opens and Delete trashes. wh”. Title/H1 token overlap is 50%; description match detected; identity schema detected.
Answer-ready visible text
Answerability scored 70/100 from 790 main-content words, 7 concise answer block(s), 0 question heading(s), 6 definition(s), 0 list(s), and 0 table(s).
Authorship and accountability
Authorship is not a universal requirement for the detected home page role.
Published or updated date
Freshness metadata is contextual for the detected home page role.
Supporting-source links
Supporting sources are contextual for the detected home page role and do not affect readiness.
Rendered content availability
Rendered audit completed with 174 visible text element(s).
Synthetic search-agent reachability
8 of 8 completed search/discovery User-Agent probes returned reachable content.
Optional LLM-readable summary
https://sadfinder.com/llms.txt returned HTTP 200; this is supplemental and does not determine AI-search eligibility.
OAI-SearchBotAI search
Robots: allowed by oai-searchbot allow: / · line 23
Probe: reachable · HTTP 200 · 100% parity
GPTBotModel training
Robots: allowed by gptbot allow: / · line 21
Probe: not tested for this control
ChatGPT-UserUser-requested fetch
Robots: not applicable to user-requested fetches
Probe: not tested for this control
ClaudeBotModel training
Robots: allowed by claudebot allow: / · line 29
Probe: not tested for this control
Claude-SearchBotAI search
Robots: allowed by claude-searchbot allow: / · line 31
Probe: reachable · HTTP 200 · 100% parity
Claude-UserUser-requested fetch
Robots: allowed by claude-user allow: / · line 33
Probe: reachable · HTTP 200 · 100% parity
GooglebotSearch and discovery
Robots: allowed by * allow: / · line 4
Probe: reachable · HTTP 200 · 100% parity
Google-ExtendedData-use policy control
Robots: allowed by google-extended allow: / · line 45
Probe: not tested for this control
BingbotSearch and discovery
Robots: allowed by * allow: / · line 4
Probe: reachable · HTTP 200 · 100% parity
PerplexityBotAI search
Robots: allowed by perplexitybot allow: / · line 39
Probe: reachable · HTTP 200 · 100% parity
Perplexity-UserUser-requested fetch
Robots: not applicable to user-requested fetches
Probe: not tested for this control
ApplebotSearch and discovery
Robots: allowed by applebot allow: / · line 49
Probe: reachable · HTTP 200 · 100% parity
Applebot-ExtendedData-use policy control
Robots: allowed by applebot-extended allow: / · line 51
Probe: not tested for this control
MistralAI-IndexAI search
Robots: allowed by * allow: / · line 4
Probe: reachable · HTTP 200 · 100% parity
MistralAI-UserUser-requested fetch
Robots: allowed by * allow: / · line 4
Probe: reachable · HTTP 200 · 100% parity
meta-externalagentModel training
Robots: allowed by meta-externalagent allow: / · line 65
Probe: not tested for this control
meta-externalfetcherUser-requested fetch
Robots: allowed by * allow: / · line 4
Probe: reachable · HTTP 200 · 100% parity
AmazonbotModel training
Robots: allowed by amazonbot allow: / · line 63
Probe: not tested for this control
Amzn-SearchBotAI search
Robots: allowed by * allow: / · line 4
Probe: reachable · HTTP 200 · 100% parity
Amzn-UserUser-requested fetch
Robots: allowed by * allow: / · line 4
Probe: reachable · HTTP 200 · 100% parity
CCBotModel training
Robots: allowed by ccbot allow: / · line 55
Probe: not tested for this control
Ready combines robots policy, a bounded synthetic User-Agent fetch, indexability, and snippet eligibility. Synthetic probes do not prove vendor-origin traffic. Purple preference states are training or data-use choices and do not lower the AEO score.
The image refreshes from FreeScan after a completed rescan. Clicking it always opens the newest public report saved for this exact scanned URL.
Scan evidence is included as untrusted data. The implementation brief instructs agents to verify findings before editing and to avoid destructive or speculative changes.
