edatastyle.com
11-year-old e-commerce site, served through Cloudflare.
Email health31Needs work
You have DMARC set up, but in monitor-only mode — it's not actually rejecting spoofed mail.
No SPF record is published, so nothing tells mail providers who's allowed to send as you.
Branded domain email address (vs free Gmail/Yahoo)
Your published contact email is on a free service, not your own domain.
Mailto: direct contact link present
We couldn't find a tap-to-email link anywhere on your site.
Email forwarding service detected (improvmx, forwardemail, etc.)
We didn't detect any mail forwarding — your inbox provider is unclear.
Lead magnet / signup incentive detected (free download, ebook, etc.)
We didn't find a lead magnet on your homepage — no free download, sample, or signup incentive. Visitors who aren't ready to buy have nothing to take with them.
Free-email exposure on contact page (gmail/yahoo/outlook visible)
Your published contact address is on your own domain, not a free inbox.
9 additional standards didn't apply to this category
SEO58Solid
Title, meta description, OG, Twitter cards, canonical
Your homepage is missing one or more of the standard social-share and search-preview tags.
Schema.org type validity (parsed JSON-LD)
We didn't find any structured-data tags on your homepage.
No breadcrumb schema is published. Search engines can't show breadcrumb trails under your listings, and visitors lose the trail to important pages.
Internal link depth (clicks from homepage to deepest content)
Important pages are reachable in just a click or two from your homepage.
6 additional standards didn't apply to this category
Brand presence58Solid
We couldn't find a Trustpilot listing. Many consumers check Trustpilot before buying — a missing listing reads as a missing reputation.
We couldn't find a Facebook Page linked from your site. Many consumers still check Facebook before booking or buying.
Instagram presence (link from site → IG profile)
We couldn't find an Instagram profile linked from your site. For local / consumer-facing brands, Instagram is the lead channel.
Wayback Machine site age & last snapshot
Your site has been online for years — public archives have a long history of it.
Your domain has been registered for years — long enough to clear fraud-detection signals.
10 additional standards didn't apply to this category
AI-readiness68Excellent
JSON-LD richness score for LLMs
We couldn't find any organization details in your page's structured data.
1 additional standard didn't apply to this category
Security74Excellent
WordPress REST API user enumeration exposure
Your WordPress site exposes its user list through the REST API. Attackers can enumerate every account by username — the first half of any credential-stuffing attack is already done for them.
There's no CAA record at your registrar saying which companies are allowed to issue certificates for you.
Your domain isn't on Chrome's HSTS preload list. The first visit from a new browser still has a brief window where an attacker could intercept it.
Neither OCSP stapling nor Must-Staple is in play. A revoked cert wouldn't be caught quickly.
Embedded SCT count (Certificate Transparency)
Your certificate carries only one embedded SCT — modern browsers want at least two. Reissue from a CA that includes them.
Certificate validity-period brevity
Your certificate lifetime is on the longer end (> 90 days). ACME-class certs renew every 60-90 days and rotate cleanly.
Sensitive path exposure (.git, .env, /admin, xmlrpc.php, wp-login.php)
Some common admin or developer paths are reachable from the public internet.
Your site is sending the standard browser-protection headers.
SSL certificate validity & expiration window
Your SSL certificate is valid and not close to expiring.
Only modern TLS (1.2 and above) is offered — TLS 1.0 and 1.1 are turned off.
Modern cipher suite preference
The handshake negotiates a modern AEAD cipher (AES-GCM or ChaCha20-Poly1305).
Forward secrecy is guaranteed by the negotiated handshake — past traffic stays unreadable even if your key leaks.
Certificate key strength and signature algorithm
Your certificate uses strong modern math (ECDSA P-256+ or RSA-2048+ with SHA-256+).
Certificate chain completeness
Your server sends the full certificate chain — every device builds the path to a trusted root cleanly.
Your server staples a fresh OCSP response — visitors don't have to round-trip to the CA on first connect.
Your certificate is issued by a tier-1 publicly trusted CA (Let's Encrypt, DigiCert, Google Trust, Sectigo, etc.).
Your TLS handshake completes quickly — under 300ms on a cold connection.
2 additional standards didn't apply to this category
Accessibility83Excellent
Your heading levels skip — for example, an H1 followed by an H3 with no H2 in between. Screen reader users lose the outline of the page.
Every image on your homepage has alt text — screen readers can describe them.
ARIA labels presence and validity
Interactive elements have proper ARIA labels — screen reader users get a clear description of each control.
A skip-to-content link is published — keyboard users land directly on the main content.
3 additional standards didn't apply to this category
Performance86Excellent
Image optimization (WebP/AVIF)
Your images are served as JPEG or PNG when modern formats (WebP, AVIF) would cut their size by 30–60% with no visible loss.
Mobile PageSpeed score + Core Web Vitals (LCP, FCP, CLS)
Your homepage is mid-pack on mobile. Reasonable but Google's ranking signal rewards faster sites.
Your server compresses pages with Brotli or gzip — visitors download a fraction of the raw size.
7 additional standards didn't apply to this category
Privacy93Excellent
Your homepage loads a reasonable number of third-party services — clean privacy footprint.
3 additional standards didn't apply to this category
View formal standards verdicts → Composite-spec rollups for press, regulators, and compliance auditors.
19 additional standards planned, scorer not yet implemented.
Is email from this domain trustworthy?18Needs work
Stops scammers from emailing customers as you
You have DMARC set up, but in monitor-only mode — it's not actually rejecting spoofed mail.
Lists who's allowed to email as your business
No SPF record is published, so nothing tells mail providers who's allowed to send as you.
You email from your own domain, not Gmail
Your published contact email is on a free service, not your own domain.
A clickable email link on your site
We couldn't find a tap-to-email link anywhere on your site.
Your email is being forwarded, not hosted
We didn't detect any mail forwarding — your inbox provider is unclear.
8 additional standards didn't apply to this site
Can people find this site?62Solid
How your site appears when shared or in search results
Your homepage is missing one or more of the standard social-share and search-preview tags.
Whether your behind-the-scenes labels are valid
We didn't find any structured-data tags on your homepage.
A trail showing where visitors are on your site
No breadcrumb schema is published. Search engines can't show breadcrumb trails under your listings, and visitors lose the trail to important pages.
How well your site feeds AI the right facts
We couldn't find any organization details in your page's structured data.
How easy it is to reach your deepest pages
Important pages are reachable in just a click or two from your homepage.
Whether you're letting AI assistants read your site
You aren't blocking any AI crawlers in your robots.txt.
7 additional standards didn't apply to this site
Does this look like a real business?65Excellent
We couldn't find a Trustpilot listing. Many consumers check Trustpilot before buying — a missing listing reads as a missing reputation.
A contact form people can actually find
We couldn't find a visible contact form on your homepage.
Whether anyone's written about you lately
No news mentions of this domain in the last 30 days.
How long your site has been online
Your site has been online for years — public archives have a long history of it.
How long your domain has existed
Your domain has been registered for years — long enough to clear fraud-detection signals.
6 additional standards didn't apply to this site
Is it safe to visit?74Excellent
WordPress isn't leaking your usernames
Your WordPress site exposes its user list through the REST API. Attackers can enumerate every account by username — the first half of any credential-stuffing attack is already done for them.
Only your approved vendors can issue your padlock
There's no CAA record at your registrar saying which companies are allowed to issue certificates for you.
Your site is on the browser-baked-in safe list
Your domain isn't on Chrome's HSTS preload list. The first visit from a new browser still has a brief window where an attacker could intercept it.
Strict mode for your padlock check
Neither OCSP stapling nor Must-Staple is in play. A revoked cert wouldn't be caught quickly.
Your certificate is publicly logged
Your certificate carries only one embedded SCT — modern browsers want at least two. Reissue from a CA that includes them.
Your padlock renews on a healthy schedule
Your certificate lifetime is on the longer end (> 90 days). ACME-class certs renew every 60-90 days and rotate cleanly.
Private files aren't open to the public
Some common admin or developer paths are reachable from the public internet.
Browser-level protections for visitors
Your site is sending the standard browser-protection headers.
Your padlock isn't about to expire
Your SSL certificate is valid and not close to expiring.
Old TLS versions are turned off
Only modern TLS (1.2 and above) is offered — TLS 1.0 and 1.1 are turned off.
The padlock uses strong, modern math
The handshake negotiates a modern AEAD cipher (AES-GCM or ChaCha20-Poly1305).
Old recordings stay locked even if a key leaks
Forward secrecy is guaranteed by the negotiated handshake — past traffic stays unreadable even if your key leaks.
Your padlock isn't using outdated keys
Your certificate uses strong modern math (ECDSA P-256+ or RSA-2048+ with SHA-256+).
Your padlock loads cleanly on every device
Your server sends the full certificate chain — every device builds the path to a trusted root cleanly.
Visitors connect faster on the first click
Your server staples a fresh OCSP response — visitors don't have to round-trip to the CA on first connect.
Your padlock comes from a reputable vendor
Your certificate is issued by a tier-1 publicly trusted CA (Let's Encrypt, DigiCert, Google Trust, Sectigo, etc.).
Your site finishes its handshake quickly
Your TLS handshake completes quickly — under 300ms on a cold connection.
2 additional standards didn't apply to this site
Can everyone use it?83Excellent
Your headings are in a sensible order
Your heading levels skip — for example, an H1 followed by an H3 with no H2 in between. Screen reader users lose the outline of the page.
Your photos have written descriptions
Every image on your homepage has alt text — screen readers can describe them.
Your buttons and forms are labeled for screen readers
Interactive elements have proper ARIA labels — screen reader users get a clear description of each control.
A skip-to-content link is published — keyboard users land directly on the main content.
3 additional standards didn't apply to this site
Is it fast?86Excellent
Your photos are saved in modern formats
Your images are served as JPEG or PNG when modern formats (WebP, AVIF) would cut their size by 30–60% with no visible loss.
How fast your site loads on a phone
Your homepage is mid-pack on mobile. Reasonable but Google's ranking signal rewards faster sites.
Your site uses a modern web connection
Your server speaks HTTP/2 — page loads multiplex over a single connection.
Pages get squeezed before they're sent
Your server compresses pages with Brotli or gzip — visitors download a fraction of the raw size.
7 additional standards didn't apply to this site
Does it respect visitor privacy?93Excellent
How many outside companies you let watch your visitors
Your homepage loads a reasonable number of third-party services — clean privacy footprint.
You have a terms of service page
Your terms of service page is reachable from the homepage.
3 additional standards didn't apply to this site