# kst.inger.sk — Zulien Score 70/100 (známka B)

> Bezplatný audit e-shopu: 70/100 celkové skóre. 100+ kontrol v 7 kategóriách (výkon, SEO, bezpečnosť, mobil, AI pripravenosť, GDPR, zraniteľnosti).

- **Auditovaný:** https://kst.inger.sk
- **Dátum auditu:** 2026-07-23
- **Plná správa:** https://score.zulien.sk/sk/r/kst.inger.sk
- **JSON API:** https://euyszfecnvwsqpigioyx.supabase.co/functions/v1/api-v1/score/kst.inger.sk

## Skóre podľa kategórií

| Kategória | Skóre |
|---|---|
| Bezpečnosť | 52/100 |
| Zraniteľnosti | 96/100 |

## Detailné nálezy

### Výkon

- **[INFO]** Performance — Website Unreachable (HTTP 401) — Client error (401). The URL may be invalid or access is restricted.

### SEO

- **[INFO]** SEO — Website Unreachable (HTTP 401) — Client error (401). The URL may be invalid or access is restricted.

### Bezpečnosť — 52/100

- **[CHYBA]** HSTS (Strict-Transport-Security)
  - Riešenie: Add header: Strict-Transport-Security: max-age=31536000; includeSubDomains; preload — then submit to hstspreload.org.
  - Dôkaz: HTTP-header
- **[CHYBA]** Content-Security-Policy (CSP)
  - Riešenie: Implement a CSP header. Start with: Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: — then gradually tighten.
  - Dôkaz: HTTP-header
- **[CHYBA]** Clickjacking Protection
  - Riešenie: Add X-Frame-Options: DENY (or SAMEORIGIN if iframes are needed). Better: use CSP frame-ancestors 'self'.
  - Dôkaz: HTTP-header
- **[UPOZORNENIE]** DNSSEC — No DNSKEY records — zone is unsigned
  - Riešenie: Enable DNSSEC at your DNS host (most modern registrars offer 1-click activation: Cloudflare, Route 53, Google Cloud DNS, web.sk, websupport.sk). Verify via dnsviz.net afterwards.
  - Dôkaz: DNS
- **[UPOZORNENIE]** CAA DNS Record — No CAA records — any CA can issue certificates for this domain
  - Riešenie: Publish CAA TXT records pinning your CA. For Let's Encrypt: `0 issue "letsencrypt.org"`. For multiple CAs add additional `0 issue "..."` records. Add `0 iodef "mailto:security@yourdomain.tld"` for misissuance reports.
  - Dôkaz: DNS
- **[UPOZORNENIE]** X-Content-Type-Options
  - Riešenie: Add header: X-Content-Type-Options: nosniff
  - Dôkaz: HTTP-header
- **[UPOZORNENIE]** Referrer-Policy
  - Riešenie: Add header: Referrer-Policy: strict-origin-when-cross-origin — this is the best balance between functionality and privacy.
  - Dôkaz: HTTP-header
- **[UPOZORNENIE]** Permissions-Policy
  - Riešenie: Add: Permissions-Policy: camera=(), microphone=(), geolocation=(), payment=() — disable APIs your site doesn't need.
  - Dôkaz: HTTP-header
- **[UPOZORNENIE]** security.txt (RFC 9116)
  - Riešenie: Create /.well-known/security.txt with Contact, Expires, and Preferred-Languages fields. See securitytxt.org for the generator.
  - Dôkaz: file-probe
- **[UPOZORNENIE]** CDN / WAF Protection
  - Riešenie: Add a CDN/WAF like Cloudflare (free tier), Sucuri, or Fastly. They provide DDoS protection, bot filtering, and SSL management.
  - Dôkaz: HTTP-header
- **[OK]** SSL/TLS Certificate — Valid HTTPS connection established
  - Dôkaz: SSL
- **[OK]** HTTP → HTTPS Redirect — HTTP properly redirects to HTTPS
  - Dôkaz: HTTP-header
- **[OK]** Cookie Security Flags — No cookies set on initial response
  - Dôkaz: HTTP-header
- **[OK]** Technology Disclosure — Server: Caddy (no version)
  - Dôkaz: HTTP-header

### Mobil

- **[INFO]** Mobile — Website Unreachable (HTTP 401) — Client error (401). The URL may be invalid or access is restricted.

### AI pripravenosť

- **[INFO]** AI Readiness — Website Unreachable (HTTP 401) — Client error (401). The URL may be invalid or access is restricted.

### GDPR

- **[INFO]** GDPR — Website Unreachable (HTTP 401) — Client error (401). The URL may be invalid or access is restricted.

### Zraniteľnosti — 96/100

- **[UPOZORNENIE]** Cross-Origin Isolation
  - Riešenie: Add Cross-Origin-Opener-Policy: same-origin and Cross-Origin-Resource-Policy: same-origin headers. These protect against Spectre-type side-channel attacks.
  - Dôkaz: HTTP-header
- **[INFO]** SPF Record (Email Security) — No SPF record, and no MX — this domain doesn't send/receive email, so deliverability isn't affected
  - Dôkaz: DNS · istota: low
- **[INFO]** DMARC Policy (Email Auth) — No DMARC record, and no MX — this domain doesn't handle email, so deliverability isn't affected
  - Dôkaz: DNS · istota: low
- **[INFO]** Email Infrastructure — No MX records — domain does not receive email
  - Dôkaz: DNS
- **[OK]** CMS Version Disclosure — No generator tag — CMS identity hidden
  - Dôkaz: HTML-heuristic
- **[OK]** Sensitive Files Exposed — .env, .git, composer.json — all properly blocked
  - Dôkaz: file-probe
- **[OK]** Install Script Exposed — No /install/ or /setup/ paths accessible
  - Dôkaz: file-probe
- **[OK]** Directory Listing — Disabled — file structure hidden
  - Dôkaz: file-probe
- **[OK]** Admin Panel at Default URL — Not found at common paths (/admin, /wp-admin, /administrator, /backoffice)
  - Dôkaz: file-probe
- **[OK]** Debug Mode / Error Exposure — No debug indicators found in page output
  - Dôkaz: HTML-heuristic

### NIS2

- **[INFO]** NIS2 Compliance — Website Unreachable (HTTP 401) — Client error (401). The URL may be invalid or access is restricted.

### Prístupnosť

- **[INFO]** Accessibility / EAA — Website Unreachable (HTTP 401) — Client error (401). The URL may be invalid or access is restricted.

---

Zulien Score je bezplatný automatizovaný heuristický audit pokrývajúci výkon (Core Web Vitals, TTFB, page weight), SEO (meta tagy, štruktúrované dáta, sitemap), bezpečnosť (SSL/TLS, HSTS, CSP), mobilnú použiteľnosť, AI pripravenosť, súlad s GDPR / ePrivacy a zraniteľnosti. Výsledky sú cache-ované na 6 hodín a re-skenovateľné na požiadanie.

[Zobraziť plnú interaktívnu správu na Zulien Score →](https://score.zulien.sk/sk/r/kst.inger.sk)
