# kst.inger.sk — Zulien Score 70/100 (Grade B)

> Free e-commerce audit: 70/100 overall score. 100+ checkpoints in 7 categories (Performance, SEO, Security, Mobile, AI Readiness, GDPR, Vulnerability).

- **Audited:** https://kst.inger.sk
- **Scan date:** 2026-07-23
- **Full report:** https://score.zulien.sk/en/r/kst.inger.sk
- **JSON API:** https://euyszfecnvwsqpigioyx.supabase.co/functions/v1/api-v1/score/kst.inger.sk

## Score by category

| Category | Score |
|---|---|
| Security | 52/100 |
| Vulnerability | 96/100 |

## Detailed findings

### Performance

- **[INFO]** Performance — Website Unreachable (HTTP 401) — Client error (401). The URL may be invalid or access is restricted.

### SEO

- **[INFO]** SEO — Website Unreachable (HTTP 401) — Client error (401). The URL may be invalid or access is restricted.

### Security — 52/100

- **[FAIL]** HSTS (Strict-Transport-Security)
  - Fix: Add header: Strict-Transport-Security: max-age=31536000; includeSubDomains; preload — then submit to hstspreload.org.
  - Evidence: HTTP-header
- **[FAIL]** Content-Security-Policy (CSP)
  - Fix: Implement a CSP header. Start with: Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: — then gradually tighten.
  - Evidence: HTTP-header
- **[FAIL]** Clickjacking Protection
  - Fix: Add X-Frame-Options: DENY (or SAMEORIGIN if iframes are needed). Better: use CSP frame-ancestors 'self'.
  - Evidence: HTTP-header
- **[WARN]** DNSSEC — No DNSKEY records — zone is unsigned
  - Fix: Enable DNSSEC at your DNS host (most modern registrars offer 1-click activation: Cloudflare, Route 53, Google Cloud DNS, web.sk, websupport.sk). Verify via dnsviz.net afterwards.
  - Evidence: DNS
- **[WARN]** CAA DNS Record — No CAA records — any CA can issue certificates for this domain
  - Fix: Publish CAA TXT records pinning your CA. For Let's Encrypt: `0 issue "letsencrypt.org"`. For multiple CAs add additional `0 issue "..."` records. Add `0 iodef "mailto:security@yourdomain.tld"` for misissuance reports.
  - Evidence: DNS
- **[WARN]** X-Content-Type-Options
  - Fix: Add header: X-Content-Type-Options: nosniff
  - Evidence: HTTP-header
- **[WARN]** Referrer-Policy
  - Fix: Add header: Referrer-Policy: strict-origin-when-cross-origin — this is the best balance between functionality and privacy.
  - Evidence: HTTP-header
- **[WARN]** Permissions-Policy
  - Fix: Add: Permissions-Policy: camera=(), microphone=(), geolocation=(), payment=() — disable APIs your site doesn't need.
  - Evidence: HTTP-header
- **[WARN]** security.txt (RFC 9116)
  - Fix: Create /.well-known/security.txt with Contact, Expires, and Preferred-Languages fields. See securitytxt.org for the generator.
  - Evidence: file-probe
- **[WARN]** CDN / WAF Protection
  - Fix: Add a CDN/WAF like Cloudflare (free tier), Sucuri, or Fastly. They provide DDoS protection, bot filtering, and SSL management.
  - Evidence: HTTP-header
- **[PASS]** SSL/TLS Certificate — Valid HTTPS connection established
  - Evidence: SSL
- **[PASS]** HTTP → HTTPS Redirect — HTTP properly redirects to HTTPS
  - Evidence: HTTP-header
- **[PASS]** Cookie Security Flags — No cookies set on initial response
  - Evidence: HTTP-header
- **[PASS]** Technology Disclosure — Server: Caddy (no version)
  - Evidence: HTTP-header

### Mobile

- **[INFO]** Mobile — Website Unreachable (HTTP 401) — Client error (401). The URL may be invalid or access is restricted.

### AI Readiness

- **[INFO]** AI Readiness — Website Unreachable (HTTP 401) — Client error (401). The URL may be invalid or access is restricted.

### GDPR

- **[INFO]** GDPR — Website Unreachable (HTTP 401) — Client error (401). The URL may be invalid or access is restricted.

### Vulnerability — 96/100

- **[WARN]** Cross-Origin Isolation
  - Fix: Add Cross-Origin-Opener-Policy: same-origin and Cross-Origin-Resource-Policy: same-origin headers. These protect against Spectre-type side-channel attacks.
  - Evidence: HTTP-header
- **[INFO]** SPF Record (Email Security) — No SPF record, and no MX — this domain doesn't send/receive email, so deliverability isn't affected
  - Evidence: DNS · confidence: low
- **[INFO]** DMARC Policy (Email Auth) — No DMARC record, and no MX — this domain doesn't handle email, so deliverability isn't affected
  - Evidence: DNS · confidence: low
- **[INFO]** Email Infrastructure — No MX records — domain does not receive email
  - Evidence: DNS
- **[PASS]** CMS Version Disclosure — No generator tag — CMS identity hidden
  - Evidence: HTML-heuristic
- **[PASS]** Sensitive Files Exposed — .env, .git, composer.json — all properly blocked
  - Evidence: file-probe
- **[PASS]** Install Script Exposed — No /install/ or /setup/ paths accessible
  - Evidence: file-probe
- **[PASS]** Directory Listing — Disabled — file structure hidden
  - Evidence: file-probe
- **[PASS]** Admin Panel at Default URL — Not found at common paths (/admin, /wp-admin, /administrator, /backoffice)
  - Evidence: file-probe
- **[PASS]** Debug Mode / Error Exposure — No debug indicators found in page output
  - Evidence: HTML-heuristic

### NIS2

- **[INFO]** NIS2 Compliance — Website Unreachable (HTTP 401) — Client error (401). The URL may be invalid or access is restricted.

### Accessibility

- **[INFO]** Accessibility / EAA — Website Unreachable (HTTP 401) — Client error (401). The URL may be invalid or access is restricted.

---

Zulien Score is a free, automated heuristic audit covering performance (Core Web Vitals, TTFB, page weight), SEO (meta, structured data, sitemap), security (SSL/TLS, HSTS, CSP), mobile usability, AI readiness, GDPR / ePrivacy compliance and vulnerability surface. Results are cached for 6 hours and re-scanned on demand.

[View the full interactive report on Zulien Score →](https://score.zulien.sk/en/r/kst.inger.sk)
