camelliabrand.com
Corporate / B2B site based in United States, served through cloudflare, with email running through custom-or-self-hosted.
AI-readiness30Needs work
JSON-LD richness score for LLMs
We couldn't find any organization details in your page's structured data.
3 additional standards didn't apply to this category
Performance45Needs work
Mobile PageSpeed score + Core Web Vitals (LCP, FCP, CLS)
Your homepage is slow on mobile. The data Google uses to rank pages says real visitors wait too long for it to feel ready.
Your server still serves over the older HTTP/2 protocol — not the newer, faster HTTP/3.
Image optimization (WebP/AVIF)
Your images are served as JPEG or PNG when modern formats (WebP, AVIF) would cut their size by 30–60% with no visible loss.
Lazy loading on below-fold images
Images below the fold aren't lazy-loaded — visitors download them up front even if they never scroll that far.
Font loading strategy (FOUT/FOIT/swap)
Your fonts aren't using font-display: swap. Visitors see invisible text for a moment while the font downloads — Google penalises this.
Your server compresses pages with Brotli or gzip — visitors download a fraction of the raw size.
6 additional standards didn't apply to this category
Email health56Solid
You have DMARC set up, but in monitor-only mode — it's not actually rejecting spoofed mail.
No SPF record is published, so nothing tells mail providers who's allowed to send as you.
DMARC aggregate reporting enabled (rua=)
No DMARC aggregate-reporting address is published — you wouldn't see spoofing attempts.
Lead magnet / signup incentive detected (free download, ebook, etc.)
We didn't find a lead magnet on your homepage — no free download, sample, or signup incentive. Visitors who aren't ready to buy have nothing to take with them.
Email provider class (Workspace / 365 / Zoho / self-hosted / shared)
We couldn't confidently identify which service is hosting your email.
Branded domain email address (vs free Gmail/Yahoo)
You send email from your own domain, not a free Gmail/Yahoo address.
Free-email exposure on contact page (gmail/yahoo/outlook visible)
Your published contact address is on your own domain, not a free inbox.
Mailto: direct contact link present
Your site exposes a mailto: link visitors can tap to start a message.
Email forwarding service detected (improvmx, forwardemail, etc.)
Mail to this domain is being forwarded — you have working email reachability.
6 additional standards didn't apply to this category
Brand presence66Excellent
Google Business Profile presence + rating
We couldn't find a Google Business Profile linked to this domain.
Yelp presence + rating + review count
We couldn't find a Yelp listing for this business. Local-business searches and recommendation engines lean on Yelp as a signal.
We couldn't find a Trustpilot listing. Many consumers check Trustpilot before buying — a missing listing reads as a missing reputation.
LinkedIn Company Page (presence + employee count + follower count)
We couldn't find a LinkedIn Company Page for this business. B2B prospects look for it before reaching out.
Apple Maps presence (Apple Business Connect)
We couldn't find an Apple Business Connect listing. Apple Maps visitors and Siri queries can't find you cleanly.
Instagram presence (link from site → IG profile)
Your Instagram profile is linked from your site.
7 additional standards didn't apply to this category
Accessibility71Excellent
Your heading levels skip — for example, an H1 followed by an H3 with no H2 in between. Screen reader users lose the outline of the page.
No skip-to-content link is published. Keyboard users have to tab through every nav item on every page before reaching the content.
Text on your homepage doesn't meet WCAG AA contrast minimums against its background. Visitors with low vision can't read parts of the page.
Your accessibility statement page is published — visitors can find out what standards you commit to.
Every image on your homepage has alt text — screen readers can describe them.
ARIA labels presence and validity
Interactive elements have proper ARIA labels — screen reader users get a clear description of each control.
1 additional standard didn't apply to this category
Security74Excellent
Your server doesn't staple OCSP. Visitors' browsers may have to contact the CA themselves, slowing first connects.
Neither OCSP stapling nor Must-Staple is in play. A revoked cert wouldn't be caught quickly.
Your TLS handshake takes over a second on a cold connection. Move behind a CDN with TLS session resumption and 0-RTT.
Certificate key strength and signature algorithm
Your certificate uses outdated key strength or a SHA-1 signature. Reissue with a modern ACME-class cert.
Embedded SCT count (Certificate Transparency)
Your certificate carries only one embedded SCT — modern browsers want at least two. Reissue from a CA that includes them.
Certificate validity-period brevity
Your certificate lifetime is on the longer end (> 90 days). ACME-class certs renew every 60-90 days and rotate cleanly.
WordPress REST API user enumeration exposure
Your WordPress site exposes its user list through the REST API. Attackers can enumerate every account by username — the first half of any credential-stuffing attack is already done for them.
SSL certificate validity & expiration window
Your SSL certificate is valid and not close to expiring.
Sensitive path exposure (.git, .env, /admin, xmlrpc.php, wp-login.php)
None of the common admin or developer paths are publicly reachable.
Only modern TLS (1.2 and above) is offered — TLS 1.0 and 1.1 are turned off.
Forward secrecy is guaranteed by the negotiated handshake — past traffic stays unreadable even if your key leaks.
Certificate chain completeness
Your server sends the full certificate chain — every device builds the path to a trusted root cleanly.
Your certificate is issued by a tier-1 publicly trusted CA (Let's Encrypt, DigiCert, Google Trust, Sectigo, etc.).
7 additional standards didn't apply to this category
Privacy74Excellent
CCPA "Do Not Sell or Share My Personal Information" link
No CCPA "Do Not Sell or Share My Personal Information" link found. If you have California visitors and sell or share data, this is required.
Your homepage loads a moderate number of third-party trackers. Worth auditing what each one is for.
Cookie scan — actual cookies set on first load
Your homepage sets only essential cookies before consent. Non-essential cookies fire after opt-in.
1 additional standard didn't apply to this category
SEO77Excellent
Your homepage doesn't have a visible H1 heading. Without it, search engines and screen readers have no anchor for what the page is about.
Better Business Bureau accreditation
We couldn't find a BBB accreditation for this business. Older / risk-averse customers still look for the BBB seal.
Schema.org structured data presence
Your homepage publishes Schema.org structured data — search engines and AI tools can read what your site is directly.
Title, meta description, OG, Twitter cards, canonical
Your homepage has the title, description, OG, Twitter, and canonical tags.
Schema.org type validity (parsed JSON-LD)
Your structured-data tags parse cleanly against Schema.org.
Your pages publish breadcrumb schema — search results show the path back to important sections.
Internal link depth (clicks from homepage to deepest content)
Important pages are reachable in just a click or two from your homepage.
4 additional standards didn't apply to this category
View formal standards verdicts → Composite-spec rollups for press, regulators, and compliance auditors.
8 additional standards planned, scorer not yet implemented.
Is it fast?45Needs work
How fast your site loads on a phone
Your homepage is slow on mobile. The data Google uses to rank pages says real visitors wait too long for it to feel ready.
Your site uses the newest connection style
Your server still serves over the older HTTP/2 protocol — not the newer, faster HTTP/3.
Your photos are saved in modern formats
Your images are served as JPEG or PNG when modern formats (WebP, AVIF) would cut their size by 30–60% with no visible loss.
Photos lower on the page wait their turn
Images below the fold aren't lazy-loaded — visitors download them up front even if they never scroll that far.
Your text shows up while fonts load
Your fonts aren't using font-display: swap. Visitors see invisible text for a moment while the font downloads — Google penalises this.
Pages get squeezed before they're sent
Your server compresses pages with Brotli or gzip — visitors download a fraction of the raw size.
6 additional standards didn't apply to this site
Does this look like a real business?49Needs work
Your listing on Google Maps and search
We couldn't find a Google Business Profile linked to this domain.
We couldn't find a Yelp listing for this business. Local-business searches and recommendation engines lean on Yelp as a signal.
We couldn't find a Trustpilot listing. Many consumers check Trustpilot before buying — a missing listing reads as a missing reputation.
We couldn't find a LinkedIn Company Page for this business. B2B prospects look for it before reaching out.
We couldn't find an Apple Business Connect listing. Apple Maps visitors and Siri queries can't find you cleanly.
Whether anyone's written about you lately
No news mentions of this domain in the last 30 days.
A contact form people can actually find
A visible contact form is reachable from your homepage.
4 additional standards didn't apply to this site
Is email from this domain trustworthy?54Needs work
Stops scammers from emailing customers as you
You have DMARC set up, but in monitor-only mode — it's not actually rejecting spoofed mail.
Lists who's allowed to email as your business
No SPF record is published, so nothing tells mail providers who's allowed to send as you.
You get reports when someone fakes your email
No DMARC aggregate-reporting address is published — you wouldn't see spoofing attempts.
What's actually running your email
We couldn't confidently identify which service is hosting your email.
You email from your own domain, not Gmail
You send email from your own domain, not a free Gmail/Yahoo address.
A clickable email link on your site
Your site exposes a mailto: link visitors can tap to start a message.
Your email is being forwarded, not hosted
Mail to this domain is being forwarded — you have working email reachability.
5 additional standards didn't apply to this site
Can people find this site?71Excellent
A clear headline on every page
Your homepage doesn't have a visible H1 heading. Without it, search engines and screen readers have no anchor for what the page is about.
Whether you're listed with the Better Business Bureau
We couldn't find a BBB accreditation for this business. Older / risk-averse customers still look for the BBB seal.
How well your site feeds AI the right facts
We couldn't find any organization details in your page's structured data.
Hidden labels that explain your business to Google
Your homepage publishes Schema.org structured data — search engines and AI tools can read what your site is directly.
How your site appears when shared or in search results
Your homepage has the title, description, OG, Twitter, and canonical tags.
Whether your behind-the-scenes labels are valid
Your structured-data tags parse cleanly against Schema.org.
A trail showing where visitors are on your site
Your pages publish breadcrumb schema — search results show the path back to important sections.
How easy it is to reach your deepest pages
Important pages are reachable in just a click or two from your homepage.
7 additional standards didn't apply to this site
Can everyone use it?71Excellent
Your headings are in a sensible order
Your heading levels skip — for example, an H1 followed by an H3 with no H2 in between. Screen reader users lose the outline of the page.
No skip-to-content link is published. Keyboard users have to tab through every nav item on every page before reaching the content.
Text on your homepage doesn't meet WCAG AA contrast minimums against its background. Visitors with low vision can't read parts of the page.
You have an accessibility statement
Your accessibility statement page is published — visitors can find out what standards you commit to.
Your photos have written descriptions
Every image on your homepage has alt text — screen readers can describe them.
Your buttons and forms are labeled for screen readers
Interactive elements have proper ARIA labels — screen reader users get a clear description of each control.
1 additional standard didn't apply to this site
Is it safe to visit?74Excellent
Visitors connect faster on the first click
Your server doesn't staple OCSP. Visitors' browsers may have to contact the CA themselves, slowing first connects.
Strict mode for your padlock check
Neither OCSP stapling nor Must-Staple is in play. A revoked cert wouldn't be caught quickly.
Your site finishes its handshake quickly
Your TLS handshake takes over a second on a cold connection. Move behind a CDN with TLS session resumption and 0-RTT.
Your padlock isn't using outdated keys
Your certificate uses outdated key strength or a SHA-1 signature. Reissue with a modern ACME-class cert.
Your certificate is publicly logged
Your certificate carries only one embedded SCT — modern browsers want at least two. Reissue from a CA that includes them.
Your padlock renews on a healthy schedule
Your certificate lifetime is on the longer end (> 90 days). ACME-class certs renew every 60-90 days and rotate cleanly.
WordPress isn't leaking your usernames
Your WordPress site exposes its user list through the REST API. Attackers can enumerate every account by username — the first half of any credential-stuffing attack is already done for them.
Your padlock isn't about to expire
Your SSL certificate is valid and not close to expiring.
Private files aren't open to the public
None of the common admin or developer paths are publicly reachable.
Old TLS versions are turned off
Only modern TLS (1.2 and above) is offered — TLS 1.0 and 1.1 are turned off.
Old recordings stay locked even if a key leaks
Forward secrecy is guaranteed by the negotiated handshake — past traffic stays unreadable even if your key leaks.
Your padlock loads cleanly on every device
Your server sends the full certificate chain — every device builds the path to a trusted root cleanly.
Your padlock comes from a reputable vendor
Your certificate is issued by a tier-1 publicly trusted CA (Let's Encrypt, DigiCert, Google Trust, Sectigo, etc.).
7 additional standards didn't apply to this site
Does it respect visitor privacy?74Excellent
California privacy opt-out link
No CCPA "Do Not Sell or Share My Personal Information" link found. If you have California visitors and sell or share data, this is required.
How many outside companies you let watch your visitors
Your homepage loads a moderate number of third-party trackers. Worth auditing what each one is for.
What your site actually drops on visitors' phones
Your homepage sets only essential cookies before consent. Non-essential cookies fire after opt-in.
You have a terms of service page
Your terms of service page is reachable from the homepage.
1 additional standard didn't apply to this site