Web Quality Index
Scan complete · Scanned May 14, 2026 · 65 of 65 standards scored (35 didn’t apply)

Home/Reports/corsan.com.br

corsan.com.br

28-year-old corporate / B2B site, served through Cloudflare, with email running through microsoft.

Site typeCorporate / B2B
Built onwordpress
Hosted byCloudflare, Inc.
Domain age≈ 28 years
Online sinceJanuary 2000
Sends email throughmicrosoft
Managed hostCloudflare (host hidden)
CDN / WAFCloudflare / Cloudflare
DNS providerCloudflare
Spam protectionMicrosoft Defender for Office 365
DMARC policyquarantine
Web Quality Score
58/100
Solid
Meets the baseline standards we measure against — but with real room to improve.
Check breakdown
65 scored
A further 11 standards didn’t apply to this site — most are accessibility and privacy tests that need page contents to evaluate.
Is it fast?
53
Needs work
14 standards behind this question
Pass3Fail5
Fail

Your site uses the newest connection style

Your server still serves over the older HTTP/2 protocol — not the newer, faster HTTP/3.

WEBQ-30
Fail

Reachable on the modern internet

Your domain has no IPv6 address — only the older IPv4.

WEBQ-31
Fail

Your photos are saved in modern formats

Your images are served as JPEG or PNG when modern formats (WebP, AVIF) would cut their size by 30–60% with no visible loss.

WEBQ-32
Fail

Photos lower on the page wait their turn

Images below the fold aren't lazy-loaded — visitors download them up front even if they never scroll that far.

WEBQ-35
Fail

How fast your site loads on a phone

Your homepage is slow on mobile. The data Google uses to rank pages says real visitors wait too long for it to feel ready.

WEBQ-08
Pass

Pages get squeezed before they're sent

Your server compresses pages with Brotli or gzip — visitors download a fraction of the raw size.

WEBQ-10
Pass

Your homepage isn't bloated

Your homepage downloads at a reasonable size.

WEBQ-37
Pass

Your text shows up while fonts load

Your fonts swap in cleanly — text is readable in the system font while custom fonts download.

WEBQ-36

6 additional standards didn't apply to this site

Does it respect visitor privacy?
57
Solid
6 standards behind this question
Pass1Fail2
Fail

You have a privacy policy page

No privacy policy page found. Required by GDPR, CCPA, and most app store listings.

WEBQ-47
Fail

How many outside companies you let watch your visitors

Your homepage loads a high number of third-party trackers. Each one slows the page, leaks data, and increases your compliance surface.

WEBQ-49
Pass

You have a terms of service page

Your terms of service page is reachable from the homepage.

WEBQ-48

3 additional standards didn't apply to this site

Does this look like a real business?
58
Solid
12 standards behind this question
Pass3Review2Fail5
Fail

Your listing on Google Maps and search

We couldn't find a Google Business Profile linked to this domain.

WEBQ-19
Fail

Your reviews on Yelp

We couldn't find a Yelp listing for this business. Local-business searches and recommendation engines lean on Yelp as a signal.

WEBQ-59
Fail

Your reviews on Trustpilot

We couldn't find a Trustpilot listing. Many consumers check Trustpilot before buying — a missing listing reads as a missing reputation.

WEBQ-60
Fail

Your company page on LinkedIn

We couldn't find a LinkedIn Company Page for this business. B2B prospects look for it before reaching out.

WEBQ-62
Fail

Your listing on Apple Maps

We couldn't find an Apple Business Connect listing. Apple Maps visitors and Siri queries can't find you cleanly.

WEBQ-64
Review

Whether anyone's written about you lately

No news mentions of this domain in the last 30 days.

WEBQ-20
Review

Whether you have a Wikipedia entry

No Wikipedia entry was found for this business.

WEBQ-21
Pass

How long your site has been online

Your site has been online for years — public archives have a long history of it.

WEBQ-18
Pass

How long your domain has existed

Your domain has been registered for years — long enough to clear fraud-detection signals.

WEBQ-17
Pass

A contact form people can actually find

A visible contact form is reachable from your homepage.

WEBQ-83

2 additional standards didn't apply to this site

Can people find this site?
62
Solid
15 standards behind this question
Pass4Review1Fail5
Fail

Hidden labels that explain your business to Google

Your homepage doesn't publish any Schema.org structured data. Search engines and AI tools fall back to guessing what your site is — and they guess wrong more often than not.

WEBQ-12
Fail

Whether your behind-the-scenes labels are valid

We didn't find any structured-data tags on your homepage.

WEBQ-39
Fail

A trail showing where visitors are on your site

No breadcrumb schema is published. Search engines can't show breadcrumb trails under your listings, and visitors lose the trail to important pages.

WEBQ-40
Fail

How well your site feeds AI the right facts

We couldn't find any organization details in your page's structured data.

WEBQ-45
Fail

How your site appears when shared or in search results

Your homepage is missing one or more of the standard social-share and search-preview tags.

WEBQ-11
Review

A summary file for AI assistants

No /llms.txt file is published at your domain root.

WEBQ-15
Pass

Whether you're letting AI assistants read your site

You aren't blocking any AI crawlers in your robots.txt.

WEBQ-16
Pass

A clear headline on every page

Your homepage has a clear H1 heading — search engines and screen readers know what the page is about.

WEBQ-13
Pass

A map of your site for search engines

Your sitemap.xml and robots.txt are both published.

WEBQ-14
Pass

How easy it is to reach your deepest pages

Important pages are reachable in just a click or two from your homepage.

WEBQ-43

5 additional standards didn't apply to this site

Is it safe to visit?
70
Excellent
21 standards behind this question
Pass9Review5Fail5
Fail

WordPress isn't leaking your usernames

Your WordPress site exposes its user list through the REST API. Attackers can enumerate every account by username — the first half of any credential-stuffing attack is already done for them.

WEBQ-06
Fail

Your domain can't be quietly hijacked

DNSSEC is not enabled on your domain.

WEBQ-22
Fail

Only your approved vendors can issue your padlock

There's no CAA record at your registrar saying which companies are allowed to issue certificates for you.

WEBQ-23
Fail

Your site is on the browser-baked-in safe list

Your domain isn't on Chrome's HSTS preload list. The first visit from a new browser still has a brief window where an attacker could intercept it.

WEBQ-26
Fail

Strict mode for your padlock check

Neither OCSP stapling nor Must-Staple is in play. A revoked cert wouldn't be caught quickly.

WEBQ-96
Review

Your padlock isn't using outdated keys

Your certificate uses outdated key strength or a SHA-1 signature. Reissue with a modern ACME-class cert.

WEBQ-89
Review

Your certificate is publicly logged

Your certificate carries only one embedded SCT — modern browsers want at least two. Reissue from a CA that includes them.

WEBQ-92
Review

Your padlock renews on a healthy schedule

Your certificate lifetime is on the longer end (> 90 days). ACME-class certs renew every 60-90 days and rotate cleanly.

WEBQ-95
Review

Your padlock comes from a reputable vendor

Your certificate issuer isn't on the tier-1 trust list. Move to a mainstream public CA.

WEBQ-97
Review

Private files aren't open to the public

Some common admin or developer paths are reachable from the public internet.

WEBQ-07
Pass

Browser-level protections for visitors

Your site is sending the standard browser-protection headers.

WEBQ-04
Pass

Your padlock isn't about to expire

Your SSL certificate is valid and not close to expiring.

WEBQ-05
Pass

Old TLS versions are turned off

Only modern TLS (1.2 and above) is offered — TLS 1.0 and 1.1 are turned off.

WEBQ-27
Pass

Forgotten subdomains aren't an open door

No forgotten or claimable subdomains were found.

WEBQ-28
Pass

The padlock uses strong, modern math

The handshake negotiates a modern AEAD cipher (AES-GCM or ChaCha20-Poly1305).

WEBQ-87
Pass

Old recordings stay locked even if a key leaks

Forward secrecy is guaranteed by the negotiated handshake — past traffic stays unreadable even if your key leaks.

WEBQ-88
Pass

Your padlock loads cleanly on every device

Your server sends the full certificate chain — every device builds the path to a trusted root cleanly.

WEBQ-90
Pass

Visitors connect faster on the first click

Your server staples a fresh OCSP response — visitors don't have to round-trip to the CA on first connect.

WEBQ-91
Pass

Your site finishes its handshake quickly

Your TLS handshake completes quickly — under 300ms on a cold connection.

WEBQ-98

2 additional standards didn't apply to this site

Can everyone use it?
78
Excellent
7 standards behind this question
Pass3Review1Fail1
Fail

A way to skip past the menu

No skip-to-content link is published. Keyboard users have to tab through every nav item on every page before reaching the content.

WEBQ-58
Review

Your headings are in a sensible order

Your heading levels skip — for example, an H1 followed by an H3 with no H2 in between. Screen reader users lose the outline of the page.

WEBQ-55
Pass

Your photos have written descriptions

Every image on your homepage has alt text — screen readers can describe them.

WEBQ-54
Pass

Text is dark enough to read

Text on your homepage meets WCAG AA contrast minimums — readable by visitors with low vision.

WEBQ-56
Pass

Your buttons and forms are labeled for screen readers

Interactive elements have proper ARIA labels — screen reader users get a clear description of each control.

WEBQ-57

2 additional standards didn't apply to this site

Is email from this domain trustworthy?
87
Excellent
13 standards behind this question
Pass8Review1Fail1
Fail

Keeps your email private in transit

No MTA-STS or TLS-RPT policy is published — incoming mail could be downgraded to plaintext.

WEBQ-24
Review

A clickable email link on your site

We couldn't find a tap-to-email link anywhere on your site.

WEBQ-84
Pass

Stops scammers from emailing customers as you

DMARC is enforcing — spoofed mail from your domain gets quarantined or rejected.

WEBQ-01
Pass

Lists who's allowed to email as your business

SPF is set and lists your sending services as approved senders.

WEBQ-03
Pass

You email from your own domain, not Gmail

You send email from your own domain, not a free Gmail/Yahoo address.

WEBQ-75
Pass

What's actually running your email

provider=microsoft_365, mx=corsan-com-br.mail.protection.outlook.com, source=mx_classifier

WEBQ-76
Pass

You get reports when someone fakes your email

You're set up to receive daily DMARC reports of spoofing attempts.

WEBQ-77
Pass

Your email setup is under a hidden limit

Your SPF record uses fewer than 10 DNS lookups — under the spec limit.

WEBQ-82
Pass

Your email is being forwarded, not hosted

Mail to this domain is being forwarded — you have working email reachability.

WEBQ-85

3 additional standards didn't apply to this site