Web Quality Index
Scan complete · Scanned May 6, 2026 · 61 of 61 standards scored (39 didn’t apply)

Home/Reports/cmtlaw.com

cmtlaw.com

E-commerce site, served through Cloudflare, with email running through microsoft.

Site typeE-commerce
Built onwordpress
Hosted byUnified Layer
Sends email throughmicrosoft
Managed hostUnified Layer
CDN / WAFCloudflare / Cloudflare
DNS providerCloudflare
Spam protectionMicrosoft Defender for Office 365
DMARC policynone
Web Quality Score
68/100
Excellent
Well above baseline. A few refinements would push this site into best-in-class territory.
Check breakdown
58 scored
A further 13 standards didn’t apply to this site — most are accessibility and privacy tests that need page contents to evaluate.
Does it respect visitor privacy?
47
Needs work
6 standards behind this question
Pass1Fail2
Fail

You have a privacy policy page

No privacy policy page found. Required by GDPR, CCPA, and most app store listings.

WEBQ-47
Fail

You have a terms of service page

No terms of service page found. Without one, you have no contractual basis for the relationship with your visitors.

WEBQ-48
Pass

How many outside companies you let watch your visitors

Your homepage loads a reasonable number of third-party services — clean privacy footprint.

WEBQ-49

3 additional standards didn't apply to this site

Does this look like a real business?
68
Excellent
12 standards behind this question
Pass1Review2Fail1
Fail

Your reviews on Trustpilot

We couldn't find a Trustpilot listing. Many consumers check Trustpilot before buying — a missing listing reads as a missing reputation.

WEBQ-60
Review

Whether anyone's written about you lately

No news mentions of this domain in the last 30 days.

WEBQ-20
Review

Whether you have a Wikipedia entry

No Wikipedia entry was found for this business.

WEBQ-21
Pass

A contact form people can actually find

A visible contact form is reachable from your homepage.

WEBQ-83

8 additional standards didn't apply to this site

Can everyone use it?
68
Excellent
7 standards behind this question
Pass2Review1Fail2
Fail

A way to skip past the menu

No skip-to-content link is published. Keyboard users have to tab through every nav item on every page before reaching the content.

WEBQ-58
Fail

Text is dark enough to read

Text on your homepage doesn't meet WCAG AA contrast minimums against its background. Visitors with low vision can't read parts of the page.

WEBQ-56
Review

Your headings are in a sensible order

Your heading levels skip — for example, an H1 followed by an H3 with no H2 in between. Screen reader users lose the outline of the page.

WEBQ-55
Pass

Your photos have written descriptions

Every image on your homepage has alt text — screen readers can describe them.

WEBQ-54
Pass

Your buttons and forms are labeled for screen readers

Interactive elements have proper ARIA labels — screen reader users get a clear description of each control.

WEBQ-57

2 additional standards didn't apply to this site

Is it safe to visit?
73
Excellent
21 standards behind this question
Pass9Review3Fail5
Fail

Your domain can't be quietly hijacked

DNSSEC is not enabled on your domain.

WEBQ-22
Fail

Only your approved vendors can issue your padlock

There's no CAA record at your registrar saying which companies are allowed to issue certificates for you.

WEBQ-23
Fail

Your site is on the browser-baked-in safe list

Your domain isn't on Chrome's HSTS preload list. The first visit from a new browser still has a brief window where an attacker could intercept it.

WEBQ-26
Fail

Visitors connect faster on the first click

Your server doesn't staple OCSP. Visitors' browsers may have to contact the CA themselves, slowing first connects.

WEBQ-91
Fail

Strict mode for your padlock check

Neither OCSP stapling nor Must-Staple is in play. A revoked cert wouldn't be caught quickly.

WEBQ-96
Review

Your padlock isn't using outdated keys

Your certificate uses outdated key strength or a SHA-1 signature. Reissue with a modern ACME-class cert.

WEBQ-89
Review

Your certificate is publicly logged

Your certificate carries only one embedded SCT — modern browsers want at least two. Reissue from a CA that includes them.

WEBQ-92
Review

WordPress isn't leaking your usernames

Your WordPress site exposes its user list through the REST API. Attackers can enumerate every account by username — the first half of any credential-stuffing attack is already done for them.

WEBQ-06
Pass

Browser-level protections for visitors

Your site is sending the standard browser-protection headers.

WEBQ-04
Pass

Your padlock isn't about to expire

Your SSL certificate is valid and not close to expiring.

WEBQ-05
Pass

Private files aren't open to the public

None of the common admin or developer paths are publicly reachable.

WEBQ-07
Pass

Old TLS versions are turned off

Only modern TLS (1.2 and above) is offered — TLS 1.0 and 1.1 are turned off.

WEBQ-27
Pass

Forgotten subdomains aren't an open door

No forgotten or claimable subdomains were found.

WEBQ-28
Pass

Your padlock loads cleanly on every device

Your server sends the full certificate chain — every device builds the path to a trusted root cleanly.

WEBQ-90
Pass

Your padlock renews on a healthy schedule

Your certificate uses a short validity window (≤ 90 days) — auto-renewal keeps revocation fast and frictionless.

WEBQ-95
Pass

Your padlock comes from a reputable vendor

Your certificate is issued by a tier-1 publicly trusted CA (Let's Encrypt, DigiCert, Google Trust, Sectigo, etc.).

WEBQ-97
Pass

Your site finishes its handshake quickly

Your TLS handshake completes quickly — under 300ms on a cold connection.

WEBQ-98

4 additional standards didn't apply to this site

Is it fast?
74
Excellent
14 standards behind this question
Pass5Fail3
Fail

Your site uses the newest connection style

Your server still serves over the older HTTP/2 protocol — not the newer, faster HTTP/3.

WEBQ-30
Fail

Your photos are saved in modern formats

Your images are served as JPEG or PNG when modern formats (WebP, AVIF) would cut their size by 30–60% with no visible loss.

WEBQ-32
Fail

Photos lower on the page wait their turn

Images below the fold aren't lazy-loaded — visitors download them up front even if they never scroll that far.

WEBQ-35
Pass

Your site uses a modern web connection

Your server speaks HTTP/2 — page loads multiplex over a single connection.

WEBQ-09
Pass

Pages get squeezed before they're sent

Your server compresses pages with Brotli or gzip — visitors download a fraction of the raw size.

WEBQ-10
Pass

Reachable on the modern internet

Your domain is reachable on IPv6.

WEBQ-31
Pass

Your text shows up while fonts load

Your fonts swap in cleanly — text is readable in the system font while custom fonts download.

WEBQ-36
Pass

Your homepage isn't bloated

Your homepage downloads at a reasonable size.

WEBQ-37

6 additional standards didn't apply to this site

Is email from this domain trustworthy?
76
Excellent
13 standards behind this question
Pass6Review1Fail3
Fail

Keeps your email private in transit

No MTA-STS or TLS-RPT policy is published — incoming mail could be downgraded to plaintext.

WEBQ-24
Fail

Stops scammers from emailing customers as you

You have DMARC set up, but in monitor-only mode — it's not actually rejecting spoofed mail.

WEBQ-01
Review

A clickable email link on your site

We couldn't find a tap-to-email link anywhere on your site.

WEBQ-84
Pass

Lists who's allowed to email as your business

SPF is set and lists your sending services as approved senders.

WEBQ-03
Pass

You email from your own domain, not Gmail

You send email from your own domain, not a free Gmail/Yahoo address.

WEBQ-75
Pass

What's actually running your email

provider=microsoft_365, mx=cmtlaw-com.mail.protection.outlook.com, source=mx_classifier

WEBQ-76
Pass

You get reports when someone fakes your email

You're set up to receive daily DMARC reports of spoofing attempts.

WEBQ-77
Pass

Your email setup is under a hidden limit

Your SPF record uses fewer than 10 DNS lookups — under the spec limit.

WEBQ-82
Pass

Your email is being forwarded, not hosted

Mail to this domain is being forwarded — you have working email reachability.

WEBQ-85

3 additional standards didn't apply to this site

Can people find this site?
77
Excellent
15 standards behind this question
Pass6Review3Fail2
Fail

A clear headline on every page

Your homepage doesn't have a visible H1 heading. Without it, search engines and screen readers have no anchor for what the page is about.

WEBQ-13
Fail

How well your site feeds AI the right facts

We couldn't find any organization details in your page's structured data.

WEBQ-45
Review

A map of your site for search engines

No sitemap.xml or robots.txt is published.

WEBQ-14
Review

Hidden labels that explain your business to Google

Your homepage doesn't publish any Schema.org structured data. Search engines and AI tools fall back to guessing what your site is — and they guess wrong more often than not.

WEBQ-12
Review

A summary file for AI assistants

No /llms.txt file is published at your domain root.

WEBQ-15
Pass

How your site appears when shared or in search results

Your homepage has the title, description, OG, Twitter, and canonical tags.

WEBQ-11
Pass

Whether your behind-the-scenes labels are valid

Your structured-data tags parse cleanly against Schema.org.

WEBQ-39
Pass

A trail showing where visitors are on your site

Your pages publish breadcrumb schema — search results show the path back to important sections.

WEBQ-40
Pass

Telling Google which language a visitor should see

Your hreflang tags are published — visitors get routed to the right language version.

WEBQ-42
Pass

How easy it is to reach your deepest pages

Important pages are reachable in just a click or two from your homepage.

WEBQ-43
Pass

Whether you're letting AI assistants read your site

You aren't blocking any AI crawlers in your robots.txt.

WEBQ-16

4 additional standards didn't apply to this site