# bonprix.sk — Zulien Score 83/100 (Grade A)

> Free e-commerce audit: 83/100 overall score. Platform: Magento. 100+ checkpoints in 7 categories (Performance, SEO, Security, Mobile, AI Readiness, GDPR, Vulnerability).

- **Audited:** https://bonprix.sk
- **Platform:** Magento
- **Scan date:** 2026-07-28
- **Full report:** https://score.zulien.sk/ro/r/bonprix.sk
- **JSON API:** https://euyszfecnvwsqpigioyx.supabase.co/functions/v1/api-v1/score/bonprix.sk

## Audit summary

Your store runs well, but has security and legal gaps. Add a cookie consent banner immediately for GDPR compliance. Your accessibility for users is excellent.

## Score by category

| Category | Score |
|---|---|
| Performance | 94/100 |
| SEO | 89/100 |
| Security | 83/100 |
| Mobile | 74/100 |
| AI Readiness | 72/100 |
| GDPR | 63/100 |
| Vulnerability | 75/100 |
| Accessibility | 96/100 |

## Detailed findings

### Performance — 94/100

- **[FAIL]** CSS File Count — 28 CSS files — too many!
  - Fix: Bundle your CSS files into 1-3 files maximum. Use a build tool (Webpack, Vite, Gulp) to concatenate and minify. Critical CSS should be inlined, the rest deferred.
  - Evidence: HTML-heuristic
- **[WARN]** Unused Code (CSS + JS) — 160 KB unused (CSS: 0 KB, JS: 160 KB)
  - Fix: Remove unused CSS with PurgeCSS or UnCSS. Code-split JavaScript so only needed code loads per page. Audit plugins — each adds CSS/JS.
  - Evidence: PSI-lab
- **[WARN]** Cache-Control Strategy — max-age=0, no-cache
  - Fix: Set appropriate cache headers: static assets should have max-age=31536000 with versioned filenames. HTML pages can use max-age=0 with ETag for revalidation.
  - Evidence: HTTP-header
- **[WARN]** Font Preloading — Custom fonts detected without preload hints
  - Fix: Preload your primary font: <link rel='preload' href='/fonts/main.woff2' as='font' type='font/woff2' crossorigin>. For Google Fonts: preconnect to fonts.gstatic.com.
  - Evidence: HTML-heuristic
- **[WARN]** Inline JavaScript Size — 105 KB of inline JavaScript
  - Fix: Move large inline scripts to external files. Inline JS over 100 KB inflates HTML, prevents caching, and blocks the parser. External files can be cached, compressed, and deferred.
  - Evidence: PSI-lab
- **[INFO]** Render-blocking Resources — Not measured — PageSpeed did not return the render-blocking audit for this URL
  - Evidence: PSI-lab
- **[PASS]** Server Response Time (TTFB) — 19ms
  - Evidence: PSI-lab
- **[PASS]** First Contentful Paint (FCP) — 0.81s
  - Evidence: PSI-lab
- **[PASS]** Largest Contentful Paint (LCP) — 0.89s — Core Web Vital ✓
  - Evidence: PSI-lab
- **[PASS]** Total Blocking Time (TBT) — 0ms
  - Evidence: PSI-lab
- **[PASS]** Cumulative Layout Shift (CLS) — 0.008 — Core Web Vital ✓
  - Evidence: PSI-lab
- **[PASS]** Speed Index — 1.45s
  - Evidence: PSI-lab
- **[PASS]** Total Page Weight — 1.4 MB (65 requests)
  - Evidence: PSI-lab
- **[PASS]** Text Compression (gzip/brotli) — All text resources properly compressed
  - Evidence: HTTP-header
- **[PASS]** Resource Hints (Preload/Preconnect) — 2 preload, 1 preconnect hint(s)
  - Evidence: HTML-heuristic
- **[PASS]** Lazy Loading — 95% of images use native lazy loading (35/37)
  - Evidence: HTML-heuristic
- **[PASS]** Font Loading Strategy — font-display: swap
  - Evidence: HTML-heuristic
- **[PASS]** HTTP/3 (QUIC) Support — HTTP/3 enabled via Alt-Svc header
  - Evidence: HTTP-header
- **[PASS]** Critical CSS Strategy — Critical CSS / async CSS loading detected
  - Evidence: PSI-lab

### SEO — 89/100

- **[FAIL]** Open Graph Image Format — og:image returned text/html
  - Fix: Make sure the og:image URL returns an image (Content-Type: image/png or image/jpeg). Common cause: returning HTML or JSON from a broken redirect.
  - Evidence: HTML-heuristic
- **[WARN]** Meta Description — 168 chars (optimal: 120-160)
  - Fix: Trim your meta description to 120-160 characters. Place the most important information and CTA in the first 120 chars.
  - Evidence: HTML-heuristic
- **[WARN]** Twitter/X Cards
  - Fix: Add <meta name='twitter:card' content='summary_large_image'>, twitter:title, and twitter:image tags.
  - Evidence: HTML-heuristic
- **[WARN]** Canonical URL Consistency — Canonical points to different URL: https://www.bonprix.sk
  - Fix: Your canonical URL doesn't match the current page URL. Ensure the canonical points to the preferred version (with or without trailing slash, www vs non-www). Inconsistent canonicals confuse search engines.
  - Evidence: HTML-heuristic
- **[WARN]** Sitemap in robots.txt — robots.txt exists but doesn't reference your sitemap
  - Fix: Add 'Sitemap: https://yourdomain.com/sitemap.xml' to your robots.txt file. This helps search engines discover your sitemap faster.
  - Evidence: HTML-heuristic
- **[INFO]** Text-to-HTML Ratio — 1% ratio but 690 words — content is substantial; the low ratio is markup/inline-JS bloat, not thin content
  - Evidence: HTML-heuristic
- **[PASS]** Meta Title — 60 chars — "bonprix • Internetový obchod • Odevy dámske, pánske a d…"
  - Evidence: HTML-heuristic
- **[PASS]** H1 Heading — "Odevy dámske, pánske a detské"
  - Evidence: HTML-heuristic
- **[PASS]** Content Structure (H2 Headings) — 2 H2 subheadings found
  - Evidence: HTML-heuristic
- **[PASS]** Open Graph Tags — og:title, og:description, og:image, og:type
  - Evidence: HTML-heuristic
- **[PASS]** Canonical URL — https://www.bonprix.sk
  - Evidence: HTML-heuristic
- **[PASS]** Structured Data (JSON-LD) — 2 block(s): WebSite, SearchAction, Organization
  - Evidence: schema
- **[PASS]** JSON-LD Validity — 2 block(s) parse cleanly
  - Evidence: HTML-heuristic
- **[PASS]** robots.txt — Present
  - Evidence: file-probe
- **[PASS]** XML Sitemap — Found with ~17+ URLs
  - Evidence: file-probe
- **[PASS]** HTML Language Attribute — lang="sk-SK"
  - Evidence: HTML-heuristic
- **[PASS]** Hreflang Tags (Multilingual) — 10 language(s): fr-BE, nl-BE, nl-NL, fr-FR, pl-PL
  - Evidence: HTML-heuristic
- **[PASS]** Image Alt Attributes — 100% of 37 images have alt text
  - Evidence: HTML-heuristic
- **[PASS]** Meta Robots Tag — index, follow
  - Evidence: HTML-heuristic
- **[PASS]** Favicon — Favicon detected
  - Evidence: file-probe
- **[PASS]** Image Format Optimization — 62% next-gen formats (23 WebP, 0 AVIF)
  - Evidence: HTML-heuristic
- **[PASS]** Semantic HTML Structure — 4/6 semantic elements: <nav>, <main>, <header>, <footer>
  - Evidence: HTML-heuristic
- **[PASS]** Content Depth — 690 words — sufficient content
  - Evidence: HTML-heuristic
- **[PASS]** Deep Heading Hierarchy — H2: 2, H3: 3 — well-structured content
  - Evidence: HTML-heuristic
- **[PASS]** Internal Linking — 43 internal links — strong site navigation
  - Evidence: HTML-heuristic
- **[PASS]** Empty/Dead Links — 1 minor dead link(s) — acceptable
  - Evidence: HTML-heuristic
- **[PASS]** Accessibility Fundamentals — 3/4 a11y signals: 5 ARIA roles, 86 ARIA labels, lang="sk-SK"
  - Evidence: HTML-heuristic

### Security — 83/100

- **[WARN]** DNSSEC — No DNSKEY records — zone is unsigned
  - Fix: Enable DNSSEC at your DNS host (most modern registrars offer 1-click activation: Cloudflare, Route 53, Google Cloud DNS, web.sk, websupport.sk). Verify via dnsviz.net afterwards.
  - Evidence: DNS
- **[WARN]** CAA DNS Record — No CAA records — any CA can issue certificates for this domain
  - Fix: Publish CAA TXT records pinning your CA. For Let's Encrypt: `0 issue "letsencrypt.org"`. For multiple CAs add additional `0 issue "..."` records. Add `0 iodef "mailto:security@yourdomain.tld"` for misissuance reports.
  - Evidence: DNS
- **[WARN]** Cookie Security Flags — 4 cookie(s): 1 missing HttpOnly
  - Fix: Set all cookies with: Secure (HTTPS only), HttpOnly (no JS access), SameSite=Lax or Strict (CSRF protection). Session cookies MUST have all three.
  - Evidence: HTTP-header
- **[WARN]** security.txt (RFC 9116)
  - Fix: Create /.well-known/security.txt with Contact, Expires, and Preferred-Languages fields. See securitytxt.org for the generator.
  - Evidence: file-probe
- **[WARN]** CDN / WAF Protection
  - Fix: Add a CDN/WAF like Cloudflare (free tier), Sucuri, or Fastly. They provide DDoS protection, bot filtering, and SSL management.
  - Evidence: HTTP-header
- **[PASS]** SSL/TLS Certificate — Valid HTTPS connection established
  - Evidence: SSL
- **[PASS]** HTTP → HTTPS Redirect — HTTP properly redirects to HTTPS
  - Evidence: HTTP-header
- **[PASS]** HSTS (Strict-Transport-Security) — max-age=31536000, preload, includeSubDomains
  - Evidence: HTTP-header
- **[PASS]** Content-Security-Policy (CSP) — Present and reasonably configured
  - Evidence: HTTP-header
- **[PASS]** Clickjacking Protection — X-Frame-Options: SAMEORIGIN
  - Evidence: HTTP-header
- **[PASS]** X-Content-Type-Options — nosniff
  - Evidence: HTTP-header
- **[PASS]** Referrer-Policy — no-referrer-when-downgrade
  - Evidence: HTTP-header
- **[PASS]** Permissions-Policy — geolocation=(self), camera=(self), microphone=(self)
  - Evidence: HTTP-header
- **[PASS]** Technology Disclosure — Server identity hidden
  - Evidence: HTTP-header

### Mobile — 74/100

- **[WARN]** Mobile Performance Score — 76/100 (target: 90+)
  - Fix: Optimize for mobile: compress images to WebP, defer non-critical JS, reduce CSS file size. Mobile CPUs are several times slower than desktop — what's fast on desktop is slow on mobile.
  - Evidence: PSI-lab
- **[WARN]** Touch Target Size — Some tappable targets are too small or too close together (Lighthouse tap-targets audit)
  - Fix: Ensure ALL interactive elements (buttons, links, form fields) are at least 48×48px with 8px minimum spacing between them. Pay special attention to: navigation menus, filter buttons, product variant selectors, and footer links.
  - Evidence: PSI-lab · Some tappable targets are too small or too close together (Lighthouse tap-targets audit)
- **[WARN]** Font Size Readability — Some text renders below the 12px legibility threshold (Lighthouse font-size audit)
  - Fix: Google's font-size audit flags text under 12px. Find the small text (often footer fine-print, captions, or cookie notices) and raise it; aim for a 16px+ body base with relative units (rem/em) so all text scales legibly on mobile.
  - Evidence: PSI-lab · Some text renders below the 12px legibility threshold (Lighthouse font-size audit)
- **[WARN]** Theme Color
  - Fix: Add <meta name='theme-color' content='#your-brand-color'> to match your brand. Browsers use this to color the address bar, task switcher, and PWA chrome.
  - Evidence: HTML-heuristic
- **[WARN]** Inline CSS Size — 157 KB of inline CSS
  - Fix: Extract inline styles to external CSS files. Inline CSS larger than 50 KB increases HTML payload and cannot be cached separately. Keep only critical above-the-fold CSS inline.
  - Evidence: HTML-heuristic
- **[WARN]** Responsive Images (srcset) — 37 images without responsive sizing
  - Fix: Add srcset and sizes attributes to <img> tags to serve appropriately sized images for each screen. Mobile devices shouldn't download 1920px desktop images.
  - Evidence: HTML-heuristic
- **[WARN]** Apple Mobile Web App — Missing: apple-mobile-web-app-capable, status-bar-style
  - Fix: Add: <meta name='apple-mobile-web-app-capable' content='yes'>, <meta name='apple-mobile-web-app-status-bar-style' content='default'>, <link rel='apple-touch-icon' href='/icon-180.png'>.
  - Evidence: HTML-heuristic
- **[WARN]** Notch/Safe Area Handling — viewport-fit=cover set but no safe-area-inset padding detected
  - Fix: Add CSS padding using env(safe-area-inset-*) for content near screen edges. Without it, content may be hidden behind the notch or Dynamic Island.
  - Evidence: HTML-heuristic
- **[WARN]** Fixed Width Elements — 14 large fixed-width value(s) may cause horizontal scroll: width:1200px, width:1320px, width:1500px…
  - Fix: Replace fixed pixel widths with max-width: 100% or use relative units (%, vw). Add 'overflow-x: hidden' to body as a safety net.
  - Evidence: HTML-heuristic · width:1200px, width:1320px, width:1500px
- **[WARN]** Link Text Quality (WCAG 2.4.4) — 1 odkazov má generický text ("click here", "more", "tu"...)
  - Fix: Nahraď 'Click here' / 'Read more' / 'Viac' popisným textom: 'Prečítaj si viac o GDPR', 'Pozri cenník modulov'. Screen readers čítajú odkazy mimo kontextu — samostatné 'viac' nemá význam.
  - Evidence: HTML-heuristic
- **[PASS]** Viewport Configuration — width=device-width, initial-scale=1
  - Evidence: HTML-heuristic
- **[PASS]** Content Fits Viewport — No horizontal scrolling needed
  - Evidence: HTML-heuristic
- **[PASS]** Responsive Design Techniques — Flexbox, CSS Grid, Media queries detected
  - Evidence: HTML-heuristic
- **[PASS]** Mobile Navigation (Semantic) — <nav> element present — proper navigation landmark
  - Evidence: HTML-heuristic
- **[PASS]** Form Input Types — Optimized: 1 email, 2 search
  - Evidence: HTML-heuristic
- **[PASS]** Form Input Labels (WCAG 3.3.2) — 3/3 inputs majú label
  - Evidence: HTML-heuristic
- **[PASS]** Heading Hierarchy (WCAG 1.3.1) — Žiadne preskočené úrovne
  - Evidence: HTML-heuristic

### AI Readiness — 72/100

- **[FAIL]** Content Freshness Signals
  - Fix: Add dateModified and datePublished to your JSON-LD schema, and display a visible 'Last updated' date on the page. Update content quarterly at minimum. AI heavily favors fresh, maintained content.
  - Evidence: HTML-heuristic
- **[WARN]** Structured Data Foundation — 2 distinct schema types (WebSite, BusinessEntity) — add more for comprehensive AI coverage
  - Fix: Expand your structured data with genuinely different types: Organization, Product, BreadcrumbList, WebSite with SearchAction, and FAQPage. Adding synonyms of the same entity (Store + LocalBusiness + Organization) does not help — variety of meaning does.
  - Evidence: schema
- **[WARN]** FAQ Schema (Direct AI Answers)
  - Fix: Add FAQPage schema to every product page and category page. Include 3-5 Q&As per page covering: product specifications, shipping, returns, usage instructions. Format: question (full sentence) + answer (75-150 words).
  - Evidence: schema
- **[WARN]** Structured Content (Lists & Tables) — 15 lists found — consider adding comparison tables
  - Fix: Add comparison tables to your content. Use <ul>/<ol> for feature lists, specifications, and benefits. Use <table> for product comparisons, pricing tiers, and specifications. AI extracts structured content much faster than paragraphs.
  - Evidence: HTML-heuristic
- **[WARN]** Author Expertise Signals (E-E-A-T)
  - Fix: For content pages (blog, guides, about): add Article/BlogPosting schema with author property linking to Person schema. Include the author's jobTitle, credentials, and social profiles.
  - Evidence: HTML-heuristic
- **[WARN]** Extractable Answer Blocks — 18 paragraphs, avg 19 words — too short for citation
  - Fix: Optimal paragraphs for AI citation are 40-80 words. Break long paragraphs into focused, self-contained answer blocks. Each should make one clear point that AI can extract and quote.
  - Evidence: HTML-heuristic
- **[WARN]** Section Length Optimization — Avg section: 91 words — only 20% in 80-200 word optimal range
  - Fix: Restructure content into sections of 120-180 words between H2/H3 headings. Each section should cover one topic completely. Split sections over 300 words, expand sections under 80 words.
  - Evidence: HTML-heuristic
- **[WARN]** Q&A Format Headings
  - Fix: Add H2/H3 headings phrased as questions your customers ask: 'How much does shipping cost?', 'What sizes are available?', 'How do I return an item?' Follow each with a direct, concise answer.
  - Evidence: HTML-heuristic
- **[WARN]** Common Question Coverage — Answers 3/5 — missing: price, availability
  - Fix: Add clear content answering the questions shoppers (and AI assistants) ask: pricing, shipping options & cost, returns/refund policy, stock availability, and accepted payment methods. A visible FAQ or info section covering these is ideal.
  - Evidence: HTML-heuristic
- **[WARN]** Canonical Tag for AI Deduplication — Canonical points to different URL: https://www.bonprix.sk
  - Fix: Verify this canonical is intentional. AI models cluster near-duplicate URLs and choose one representative page. If canonical points to a different URL, AI will only index that target URL, not this page.
  - Evidence: HTML-heuristic
- **[WARN]** Knowledge Graph Readiness — 2/4 signals — missing: @id in JSON-LD, consistent brand name (title/schema/OG)
  - Fix: Add: @id in JSON-LD, consistent brand name (title/schema/OG). Use @id in JSON-LD to create a unique node identifier. Ensure your brand name is identical in title, schema, and OG tags. Link to Wikipedia/Wikidata via sameAs.
  - Evidence: HTML-heuristic
- **[WARN]** Content Readability for AI — Grade 18 — too complex for broad AI citation (technical threshold: 14)
  - Fix: Simplify sentences (target 15-20 words average), use common words, break complex ideas into shorter paragraphs. AI extracts content for general audiences — if it's too academic, AI skips it.
  - Evidence: HTML-heuristic
- **[WARN]** Image Alt Text Quality for AI — 62% good, 14 poor, 0 missing
  - Fix: Improve alt text: use 3-15 descriptive words per image. Include product name, key feature, and context. Bad: 'image1' or 'photo'. Good: 'Red leather wallet with RFID protection — front view'.
  - Evidence: HTML-heuristic
- **[WARN]** Expert Quotations & Citations
  - Fix: Add 2-3 expert quotes or data citations per major page. Use <blockquote> for quotes and link to authoritative sources (.gov, .edu, Wikipedia, industry reports).
  - Evidence: HTML-heuristic
- **[WARN]** WebMCP Agentic Readiness
  - Fix: WebMCP (W3C Community Group standard, Chrome 146+) lets pages declare structured tools for AI agents. Add toolname and tooldescription attributes to <form> elements, or include a <script type='application/webmcp+json'> manifest.
  - Evidence: HTML-heuristic
- **[WARN]** Content-to-Boilerplate Ratio — 38% in main content area — too much boilerplate
  - Fix: Move more content into <main> or <article> elements. Reduce navigation text, footer content, and sidebar noise. AI crawlers extract content from semantic containers and discard the rest.
  - Evidence: HTML-heuristic
- **[INFO]** llms.txt (AI Site Descriptor) — Not present — not required for AI visibility
  - Evidence: file-probe
- **[INFO]** llms-full.txt (Complete AI Content) — Not present — not required for AI visibility
  - Evidence: file-probe
- **[INFO]** ai.txt (AI Permissions) — Not present — optional; AI-bot permissions are enforced via robots.txt, not ai.txt
  - Evidence: file-probe
- **[INFO]** Social Proof (Testimonials / Case Studies) — None detected. For a non-commercial/informational site, testimonials and case studies are optional
  - Evidence: HTML-heuristic · confidence: low
- **[INFO]** Agent-Commerce Readiness — 81/100 — pripravené pre AI agentov (Prístup 100 · Porozumenie 75 · Objaviteľnosť 100 · Transakcia 50)
- **[INFO]** Agent: Prístup — dostane sa agent dnu — 100/100 (2 signály/-ov)
- **[INFO]** Agent: Porozumenie — rozumie produktom — 75/100 (2 signály/-ov)
- **[INFO]** Agent: Objaviteľnosť — nájde celý katalóg — 100/100 (1 signál)
- **[INFO]** Agent: Transakcia — vie konať (kôš/podmienky) — 50/100 (1 signál)
- **[PASS]** AI Bot Access Policy — Explicitly allowed: Googlebot
  - Evidence: file-probe
- **[PASS]** Content Accessibility for AI — 690 words in raw HTML (1.3% text ratio) — readable by AI crawlers without executing JS
  - Evidence: HTML-heuristic
- **[PASS]** Organization Schema + Entity Linking — Organization found with 4 sameAs links — strong entity identity
  - Evidence: schema
- **[PASS]** Site Search Schema (SearchAction) — WebSite SearchAction configured — AI can search your store
  - Evidence: schema
- **[PASS]** Content Depth for AI — 690 words — rich content for AI analysis and citation
  - Evidence: HTML-heuristic
- **[PASS]** Answer-First Content Format — First paragraph: 20 words — good content density above the fold
  - Evidence: HTML-heuristic
- **[PASS]** Heading Hierarchy for AI — Proper structure: 1 H1 → 2 H2s → 3 H3s — clear content outline
  - Evidence: HTML-heuristic
- **[PASS]** Semantic HTML Structure — 4/6 semantic elements: <nav>, <main>, <header>, <footer>
  - Evidence: HTML-heuristic
- **[PASS]** Entity Clarity & Brand Signals — OG tags complete + 4 sameAs links: Facebook, Instagram, YouTube
  - Evidence: HTML-heuristic
- **[PASS]** Statistics & Data Presence — 6 data points found — strong citation magnet
  - Evidence: HTML-heuristic
- **[PASS]** Internal Link Density — 62 contextual internal links per 1,000 words — strong knowledge graph signal
  - Evidence: HTML-heuristic

### GDPR — 63/100

- **[FAIL]** Cookie Consent Banner (CMP)
  - Fix: Install a certified consent management platform: Cookiebot, OneTrust, Usercentrics, or CookieYes. The CMP must block ALL non-essential cookies and scripts until explicit consent is given (opt-in, not opt-out).
  - Evidence: HTML-heuristic
- **[FAIL]** Tracking Scripts Without Consent — 1 tracker(s) loading without consent: Pinterest Tag
  - Fix: These tracking scripts fire before user consent: Pinterest Tag. Configure your CMP to block them until explicit opt-in. Use Tag Manager's consent mode or CMP script blocking.
  - Evidence: HTML-heuristic
- **[WARN]** Cookie Policy
  - Fix: Create a separate cookie policy page listing every cookie by: name, provider, purpose, category (necessary/analytics/marketing), and expiration. Most CMPs auto-generate this.
  - Evidence: HTML-heuristic
- **[WARN]** International Data Transfers — 1 US-based tracker(s) without consent: Pinterest Tag
  - Fix: US-based trackers transfer personal data outside the EU. Under GDPR, this requires: 1) User consent via CMP, 2) Standard Contractual Clauses (SCCs) with each provider, 3) Data Transfer Impact Assessment.
  - Evidence: HTML-heuristic
- **[WARN]** Right to Erasure (Data Deletion)
  - Fix: Provide a clear mechanism for users to request data deletion — either a dedicated page, a form, or explicit instructions in your privacy policy. Include a 'Delete my account' option in user settings.
  - Evidence: HTML-heuristic
- **[INFO]** Terms & Conditions Page — No Terms & Conditions link found — for a non-commercial/informational site this is optional (no purchase or paid service to govern)
  - Evidence: HTML-heuristic · confidence: low
- **[PASS]** Privacy Policy Page — /pomoc/zasady-ochrany-osobnych-udajov/
  - Evidence: HTML-heuristic
- **[PASS]** Legal Contact / Imprint Page — /corporate/about-us/
  - Evidence: HTML-heuristic
- **[PASS]** Data Encryption (No Mixed Content) — All resources loaded over HTTPS
  - Evidence: HTML-heuristic
- **[PASS]** Newsletter Consent — Newsletter form with consent mechanism detected
  - Evidence: HTML-heuristic
- **[PASS]** Data Protection Officer Contact — DPO / data protection contact found
  - Evidence: HTML-heuristic
- **[PASS]** Withdrawal of Consent Mechanism — Consent withdrawal / opt-out mechanism found
  - Evidence: HTML-heuristic

### Vulnerability — 75/100

- **[FAIL]** Suspicious Inline Script Patterns — Detected: Payment data exfiltration pattern, Dynamic script injection
  - Fix: Review all inline scripts for obfuscated code. Magecart attackers inject payment skimmers disguised as analytics or GTM scripts. Compare your current HTML with a known-good version. Consider using CSP with strict nonces.
  - Evidence: file-probe
- **[FAIL]** DMARC Policy (Email Auth)
  - Fix: Add a DMARC TXT record at _dmarc.yourdomain.com: v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com — start with quarantine, then move to reject.
  - Evidence: DNS
- **[FAIL]** API Key Exposure in Source — 3 potential API key(s) in HTML: secretKey:"aiXA1G6zeoJUu40oYS3..., AIzaSyByJAknczAEXQ-w_RzW5e85ec...
  - Fix: URGENT: Rotate all exposed API keys immediately! Move secrets to server-side environment variables. Never include API keys in client-side HTML or JavaScript. Use server-side proxy endpoints for API calls.
  - Evidence: file-probe
- **[WARN]** Inline JavaScript Exposure — 105 KB of inline JavaScript
  - Fix: Move inline scripts to external files. Inline JavaScript expands the attack surface for XSS and makes CSP harder to implement (requires unsafe-inline).
  - Evidence: HTML-heuristic · confidence: low
- **[WARN]** DKIM Signing (Email Auth)
  - Fix: Configure DKIM signing through your email provider (Google Workspace, Microsoft 365, Mailchimp, SendGrid). Publish the DKIM public key as a TXT record at <selector>._domainkey.yourdomain.com.
  - Evidence: file-probe
- **[WARN]** Cross-Origin Isolation
  - Fix: Add Cross-Origin-Opener-Policy: same-origin and Cross-Origin-Resource-Policy: same-origin headers. These protect against Spectre-type side-channel attacks.
  - Evidence: HTTP-header
- **[PASS]** CMS Version Disclosure — No generator tag — CMS identity hidden
  - Evidence: HTML-heuristic
- **[PASS]** Sensitive Files Exposed — .env, .git, composer.json — all properly blocked
  - Evidence: file-probe
- **[PASS]** Install Script Exposed — No /install/ or /setup/ paths accessible
  - Evidence: file-probe
- **[PASS]** Directory Listing — Disabled — file structure hidden
  - Evidence: file-probe
- **[PASS]** Admin Panel at Default URL — Not found at common paths (/admin, /wp-admin, /administrator, /backoffice)
  - Evidence: file-probe
- **[PASS]** Debug Mode / Error Exposure — No debug indicators found in page output
  - Evidence: HTML-heuristic
- **[PASS]** Form CSRF Protection — 1 form(s) — all have CSRF tokens
  - Evidence: HTML-heuristic
- **[PASS]** SPF Record (Email Security) — SPF configured: v=spf1 a mx ip4:82.177.16.10/32 ip4:194.79.25.177/32 ip4:194.79.25.55/32 ip4:194
  - Evidence: DNS
- **[PASS]** Payment Page Security — All essential security headers present on payment page
  - Evidence: file-probe

### NIS2

- **[INFO]** NIS2 Compliance — Scope undetermined — IČO/company enrichment unavailable for this domain.

### Accessibility — 96/100

- **[WARN]** Skip Link — No skip-to-content link detected
  - Fix: Add a visually-hidden "Skip to content" link as the first focusable element, targeting <main id="main">.
  - Evidence: HTML-heuristic · confidence: low
- **[INFO]** EAA Legal Basis — In scope for the European Accessibility Act (in force 28.6.2025): SK zákon 351/2022 Z. z., CZ zákon 424/2023 Sb., Dir. (EU) 2019/882 — assessed against EN 301 549. Inger provides EAA remediation audits.
- **[PASS]** Page Language — <html lang="sk-SK"> is set
  - Evidence: HTML-heuristic
- **[PASS]** Image Alt Text — All 37 images have alt attributes
  - Evidence: HTML-heuristic
- **[PASS]** Form Labels — All 3 form inputs are labelled
  - Evidence: HTML-heuristic
- **[PASS]** Heading Structure — Single <h1> with a consistent heading outline
  - Evidence: HTML-heuristic
- **[PASS]** Link Text — Links use descriptive text
  - Evidence: HTML-heuristic · confidence: low
- **[PASS]** Landmark Regions — Semantic landmarks present (<main>, <nav>/<header>)
  - Evidence: HTML-heuristic
- **[PASS]** Zoom & Scaling — Pinch-zoom is not disabled
  - Evidence: HTML-heuristic

---

Zulien Score is a free, automated heuristic audit covering performance (Core Web Vitals, TTFB, page weight), SEO (meta, structured data, sitemap), security (SSL/TLS, HSTS, CSP), mobile usability, AI readiness, GDPR / ePrivacy compliance and vulnerability surface. Results are cached for 6 hours and re-scanned on demand.

[View the full interactive report on Zulien Score →](https://score.zulien.sk/ro/r/bonprix.sk)
