acdc.co.ke
15-year-old e-commerce site based in United Kingdom, served through cloudflare, with email running through custom-or-self-hosted.
Privacy40Needs work
No privacy policy page found. Required by GDPR, CCPA, and most app store listings.
Terms of service page presence
No terms of service page found. Without one, you have no contractual basis for the relationship with your visitors.
Your homepage loads a moderate number of third-party trackers. Worth auditing what each one is for.
3 additional standards didn't apply to this category
SEO50Needs work
Schema.org structured data presence
Your homepage doesn't publish any Schema.org structured data. Search engines and AI tools fall back to guessing what your site is — and they guess wrong more often than not.
Schema.org type validity (parsed JSON-LD)
We didn't find any structured-data tags on your homepage.
No breadcrumb schema is published. Search engines can't show breadcrumb trails under your listings, and visitors lose the trail to important pages.
Title, meta description, OG, Twitter cards, canonical
Your homepage is missing one or more of the standard social-share and search-preview tags.
Internal link depth (clicks from homepage to deepest content)
Important pages take five or more clicks from your homepage — most visitors never reach them.
Your homepage has a clear H1 heading — search engines and screen readers know what the page is about.
4 additional standards didn't apply to this category
AI-readiness62Solid
JSON-LD richness score for LLMs
We couldn't find any organization details in your page's structured data.
1 additional standard didn't apply to this category
Accessibility65Excellent
Your heading levels skip — for example, an H1 followed by an H3 with no H2 in between. Screen reader users lose the outline of the page.
No skip-to-content link is published. Keyboard users have to tab through every nav item on every page before reaching the content.
Text on your homepage doesn't meet WCAG AA contrast minimums against its background. Visitors with low vision can't read parts of the page.
Every image on your homepage has alt text — screen readers can describe them.
ARIA labels presence and validity
Interactive elements have proper ARIA labels — screen reader users get a clear description of each control.
2 additional standards didn't apply to this category
Security67Excellent
Your site isn't sending any of the standard browser-protection headers.
There's no CAA record at your registrar saying which companies are allowed to issue certificates for you.
Your server doesn't staple OCSP. Visitors' browsers may have to contact the CA themselves, slowing first connects.
Neither OCSP stapling nor Must-Staple is in play. A revoked cert wouldn't be caught quickly.
Your TLS handshake takes over a second on a cold connection. Move behind a CDN with TLS session resumption and 0-RTT.
Certificate key strength and signature algorithm
Your certificate uses outdated key strength or a SHA-1 signature. Reissue with a modern ACME-class cert.
Embedded SCT count (Certificate Transparency)
Your certificate carries only one embedded SCT — modern browsers want at least two. Reissue from a CA that includes them.
Sensitive path exposure (.git, .env, /admin, xmlrpc.php, wp-login.php)
Some common admin or developer paths are reachable from the public internet.
SSL certificate validity & expiration window
Your SSL certificate is valid and not close to expiring.
WordPress REST API user enumeration exposure
Your WordPress REST API doesn't leak usernames — attackers can't list accounts without already being authenticated.
Only modern TLS (1.2 and above) is offered — TLS 1.0 and 1.1 are turned off.
Certificate chain completeness
Your server sends the full certificate chain — every device builds the path to a trusted root cleanly.
Certificate validity-period brevity
Your certificate uses a short validity window (≤ 90 days) — auto-renewal keeps revocation fast and frictionless.
Your certificate is issued by a tier-1 publicly trusted CA (Let's Encrypt, DigiCert, Google Trust, Sectigo, etc.).
5 additional standards didn't apply to this category
Performance68Excellent
Image optimization (WebP/AVIF)
Your images are served as JPEG or PNG when modern formats (WebP, AVIF) would cut their size by 30–60% with no visible loss.
Lazy loading on below-fold images
Images below the fold aren't lazy-loaded — visitors download them up front even if they never scroll that far.
Font loading strategy (FOUT/FOIT/swap)
Your fonts aren't using font-display: swap. Visitors see invisible text for a moment while the font downloads — Google penalises this.
Your server compresses pages with Brotli or gzip — visitors download a fraction of the raw size.
6 additional standards didn't apply to this category
Email health75Excellent
No MTA-STS or TLS-RPT policy is published — incoming mail could be downgraded to plaintext.
Lead magnet / signup incentive detected (free download, ebook, etc.)
We didn't find a lead magnet on your homepage — no free download, sample, or signup incentive. Visitors who aren't ready to buy have nothing to take with them.
Mailto: direct contact link present
We couldn't find a tap-to-email link anywhere on your site.
Email provider class (Workspace / 365 / Zoho / self-hosted / shared)
We couldn't confidently identify which service is hosting your email.
DMARC is enforcing — spoofed mail from your domain gets quarantined or rejected.
SPF is set and lists your sending services as approved senders.
Branded domain email address (vs free Gmail/Yahoo)
You send email from your own domain, not a free Gmail/Yahoo address.
DMARC aggregate reporting enabled (rua=)
You're set up to receive daily DMARC reports of spoofing attempts.
Free-email exposure on contact page (gmail/yahoo/outlook visible)
Your published contact address is on your own domain, not a free inbox.
SPF lookup count (10-limit deliverability check)
Your SPF record uses fewer than 10 DNS lookups — under the spec limit.
Email forwarding service detected (improvmx, forwardemail, etc.)
Mail to this domain is being forwarded — you have working email reachability.
4 additional standards didn't apply to this category
Brand presence78Excellent
We couldn't find a Trustpilot listing. Many consumers check Trustpilot before buying — a missing listing reads as a missing reputation.
Instagram presence (link from site → IG profile)
We couldn't find an Instagram profile linked from your site. For local / consumer-facing brands, Instagram is the lead channel.
Wayback Machine site age & last snapshot
We couldn't find your site in public web archives — it reads as brand new.
Your domain has been registered for years — long enough to clear fraud-detection signals.
9 additional standards didn't apply to this category
View formal standards verdicts → Composite-spec rollups for press, regulators, and compliance auditors.
17 additional standards planned, scorer not yet implemented.
Does it respect visitor privacy?40Needs work
You have a privacy policy page
No privacy policy page found. Required by GDPR, CCPA, and most app store listings.
You have a terms of service page
No terms of service page found. Without one, you have no contractual basis for the relationship with your visitors.
How many outside companies you let watch your visitors
Your homepage loads a moderate number of third-party trackers. Worth auditing what each one is for.
3 additional standards didn't apply to this site
Can people find this site?54Needs work
Hidden labels that explain your business to Google
Your homepage doesn't publish any Schema.org structured data. Search engines and AI tools fall back to guessing what your site is — and they guess wrong more often than not.
Whether your behind-the-scenes labels are valid
We didn't find any structured-data tags on your homepage.
A trail showing where visitors are on your site
No breadcrumb schema is published. Search engines can't show breadcrumb trails under your listings, and visitors lose the trail to important pages.
How well your site feeds AI the right facts
We couldn't find any organization details in your page's structured data.
How your site appears when shared or in search results
Your homepage is missing one or more of the standard social-share and search-preview tags.
How easy it is to reach your deepest pages
Important pages take five or more clicks from your homepage — most visitors never reach them.
Whether you're letting AI assistants read your site
You aren't blocking any AI crawlers in your robots.txt.
A clear headline on every page
Your homepage has a clear H1 heading — search engines and screen readers know what the page is about.
5 additional standards didn't apply to this site
Can everyone use it?65Excellent
Your headings are in a sensible order
Your heading levels skip — for example, an H1 followed by an H3 with no H2 in between. Screen reader users lose the outline of the page.
No skip-to-content link is published. Keyboard users have to tab through every nav item on every page before reaching the content.
Text on your homepage doesn't meet WCAG AA contrast minimums against its background. Visitors with low vision can't read parts of the page.
Your photos have written descriptions
Every image on your homepage has alt text — screen readers can describe them.
Your buttons and forms are labeled for screen readers
Interactive elements have proper ARIA labels — screen reader users get a clear description of each control.
2 additional standards didn't apply to this site
Is it safe to visit?67Excellent
Browser-level protections for visitors
Your site isn't sending any of the standard browser-protection headers.
Only your approved vendors can issue your padlock
There's no CAA record at your registrar saying which companies are allowed to issue certificates for you.
Visitors connect faster on the first click
Your server doesn't staple OCSP. Visitors' browsers may have to contact the CA themselves, slowing first connects.
Strict mode for your padlock check
Neither OCSP stapling nor Must-Staple is in play. A revoked cert wouldn't be caught quickly.
Your site finishes its handshake quickly
Your TLS handshake takes over a second on a cold connection. Move behind a CDN with TLS session resumption and 0-RTT.
Your padlock isn't using outdated keys
Your certificate uses outdated key strength or a SHA-1 signature. Reissue with a modern ACME-class cert.
Your certificate is publicly logged
Your certificate carries only one embedded SCT — modern browsers want at least two. Reissue from a CA that includes them.
Private files aren't open to the public
Some common admin or developer paths are reachable from the public internet.
Your padlock isn't about to expire
Your SSL certificate is valid and not close to expiring.
WordPress isn't leaking your usernames
Your WordPress REST API doesn't leak usernames — attackers can't list accounts without already being authenticated.
Old TLS versions are turned off
Only modern TLS (1.2 and above) is offered — TLS 1.0 and 1.1 are turned off.
Your padlock loads cleanly on every device
Your server sends the full certificate chain — every device builds the path to a trusted root cleanly.
Your padlock renews on a healthy schedule
Your certificate uses a short validity window (≤ 90 days) — auto-renewal keeps revocation fast and frictionless.
Your padlock comes from a reputable vendor
Your certificate is issued by a tier-1 publicly trusted CA (Let's Encrypt, DigiCert, Google Trust, Sectigo, etc.).
5 additional standards didn't apply to this site
Is it fast?68Excellent
Your photos are saved in modern formats
Your images are served as JPEG or PNG when modern formats (WebP, AVIF) would cut their size by 30–60% with no visible loss.
Photos lower on the page wait their turn
Images below the fold aren't lazy-loaded — visitors download them up front even if they never scroll that far.
Your text shows up while fonts load
Your fonts aren't using font-display: swap. Visitors see invisible text for a moment while the font downloads — Google penalises this.
Your site uses a modern web connection
Your server speaks HTTP/2 — page loads multiplex over a single connection.
Pages get squeezed before they're sent
Your server compresses pages with Brotli or gzip — visitors download a fraction of the raw size.
6 additional standards didn't apply to this site
Does this look like a real business?74Excellent
We couldn't find a Trustpilot listing. Many consumers check Trustpilot before buying — a missing listing reads as a missing reputation.
Whether anyone's written about you lately
No news mentions of this domain in the last 30 days.
How long your site has been online
We couldn't find your site in public web archives — it reads as brand new.
How long your domain has existed
Your domain has been registered for years — long enough to clear fraud-detection signals.
A contact form people can actually find
A visible contact form is reachable from your homepage.
6 additional standards didn't apply to this site
Is email from this domain trustworthy?77Excellent
Keeps your email private in transit
No MTA-STS or TLS-RPT policy is published — incoming mail could be downgraded to plaintext.
A clickable email link on your site
We couldn't find a tap-to-email link anywhere on your site.
What's actually running your email
We couldn't confidently identify which service is hosting your email.
Stops scammers from emailing customers as you
DMARC is enforcing — spoofed mail from your domain gets quarantined or rejected.
Lists who's allowed to email as your business
SPF is set and lists your sending services as approved senders.
You email from your own domain, not Gmail
You send email from your own domain, not a free Gmail/Yahoo address.
You get reports when someone fakes your email
You're set up to receive daily DMARC reports of spoofing attempts.
Your email setup is under a hidden limit
Your SPF record uses fewer than 10 DNS lookups — under the spec limit.
Your email is being forwarded, not hosted
Mail to this domain is being forwarded — you have working email reachability.
3 additional standards didn't apply to this site