mynorth.com
22-year-old news / Publisher site, served through Cloudflare, with email running through microsoft.
Privacy57Solid
Terms of service page presence
No terms of service page found. Without one, you have no contractual basis for the relationship with your visitors.
Your homepage loads a high number of third-party trackers. Each one slows the page, leaks data, and increases your compliance surface.
3 additional standards didn't apply to this category
AI-readiness75Excellent
JSON-LD richness score for LLMs
We couldn't find any organization details in your page's structured data.
3 additional standards didn't apply to this category
Accessibility76Excellent
Your heading levels skip — for example, an H1 followed by an H3 with no H2 in between. Screen reader users lose the outline of the page.
Text on your homepage doesn't meet WCAG AA contrast minimums against its background. Visitors with low vision can't read parts of the page.
Every image on your homepage has alt text — screen readers can describe them.
ARIA labels presence and validity
Interactive elements have proper ARIA labels — screen reader users get a clear description of each control.
A skip-to-content link is published — keyboard users land directly on the main content.
2 additional standards didn't apply to this category
Security82Excellent
WordPress REST API user enumeration exposure
Your WordPress site exposes its user list through the REST API. Attackers can enumerate every account by username — the first half of any credential-stuffing attack is already done for them.
Neither OCSP stapling nor Must-Staple is in play. A revoked cert wouldn't be caught quickly.
Embedded SCT count (Certificate Transparency)
Your certificate carries only one embedded SCT — modern browsers want at least two. Reissue from a CA that includes them.
Certificate validity-period brevity
Your certificate lifetime is on the longer end (> 90 days). ACME-class certs renew every 60-90 days and rotate cleanly.
Sensitive path exposure (.git, .env, /admin, xmlrpc.php, wp-login.php)
None of the common admin or developer paths are publicly reachable.
Only modern TLS (1.2 and above) is offered — TLS 1.0 and 1.1 are turned off.
Modern cipher suite preference
The handshake negotiates a modern AEAD cipher (AES-GCM or ChaCha20-Poly1305).
Forward secrecy is guaranteed by the negotiated handshake — past traffic stays unreadable even if your key leaks.
Certificate key strength and signature algorithm
Your certificate uses strong modern math (ECDSA P-256+ or RSA-2048+ with SHA-256+).
Certificate chain completeness
Your server sends the full certificate chain — every device builds the path to a trusted root cleanly.
Your server staples a fresh OCSP response — visitors don't have to round-trip to the CA on first connect.
Your certificate is issued by a tier-1 publicly trusted CA (Let's Encrypt, DigiCert, Google Trust, Sectigo, etc.).
Your TLS handshake completes quickly — under 300ms on a cold connection.
7 additional standards didn't apply to this category
Performance82Excellent
Your server still serves over the older HTTP/2 protocol — not the newer, faster HTTP/3.
Image optimization (WebP/AVIF)
Your images are served as JPEG or PNG when modern formats (WebP, AVIF) would cut their size by 30–60% with no visible loss.
Lazy loading on below-fold images
Below-fold images use loading="lazy" — they download only when the visitor scrolls toward them.
Mobile PageSpeed score + Core Web Vitals (LCP, FCP, CLS)
Your homepage loads fast on mobile — the metrics Google uses for ranking are in the green.
Your server compresses pages with Brotli or gzip — visitors download a fraction of the raw size.
Font loading strategy (FOUT/FOIT/swap)
Your fonts swap in cleanly — text is readable in the system font while custom fonts download.
6 additional standards didn't apply to this category
SEO85Excellent
Your homepage doesn't have a visible H1 heading. Without it, search engines and screen readers have no anchor for what the page is about.
Schema.org structured data presence
Your homepage publishes Schema.org structured data — search engines and AI tools can read what your site is directly.
Title, meta description, OG, Twitter cards, canonical
Your homepage has the title, description, OG, Twitter, and canonical tags.
Schema.org type validity (parsed JSON-LD)
Your structured-data tags parse cleanly against Schema.org.
Your pages publish breadcrumb schema — search results show the path back to important sections.
Internal link depth (clicks from homepage to deepest content)
Important pages are reachable in just a click or two from your homepage.
5 additional standards didn't apply to this category
Email health86Excellent
Lead magnet / signup incentive detected (free download, ebook, etc.)
We didn't find a lead magnet on your homepage — no free download, sample, or signup incentive. Visitors who aren't ready to buy have nothing to take with them.
No SPF record is published, so nothing tells mail providers who's allowed to send as you.
SPF lookup count (10-limit deliverability check)
Your SPF record exceeds the 10-lookup limit — receiving servers will reject it.
DMARC is enforcing — spoofed mail from your domain gets quarantined or rejected.
Branded domain email address (vs free Gmail/Yahoo)
You send email from your own domain, not a free Gmail/Yahoo address.
Email provider class (Workspace / 365 / Zoho / self-hosted / shared)
provider=microsoft_365, mx=mynorth-com.mail.protection.outlook.com, source=mx_classifier
DMARC aggregate reporting enabled (rua=)
You're set up to receive daily DMARC reports of spoofing attempts.
Free-email exposure on contact page (gmail/yahoo/outlook visible)
Your published contact address is on your own domain, not a free inbox.
Newsletter signup form detected
Your homepage exposes a newsletter or signup form — visitors can subscribe without leaving the page.
Email Service Provider (ESP) detected
Your Email Service Provider is detectable — newsletters and marketing email have a real sending platform behind them.
Mailto: direct contact link present
Your site exposes a mailto: link visitors can tap to start a message.
Email forwarding service detected (improvmx, forwardemail, etc.)
Mail to this domain is being forwarded — you have working email reachability.
3 additional standards didn't apply to this category
Brand presence99Excellent
Your domain has been registered for years — long enough to clear fraud-detection signals.
tools=Google Analytics, count=1, first_party_telemetry=navigator\.sendBeacon\s*\(
12 additional standards didn't apply to this category
View formal standards verdicts → Composite-spec rollups for press, regulators, and compliance auditors.
18 additional standards planned, scorer not yet implemented.
Does it respect visitor privacy?57Solid
You have a terms of service page
No terms of service page found. Without one, you have no contractual basis for the relationship with your visitors.
How many outside companies you let watch your visitors
Your homepage loads a high number of third-party trackers. Each one slows the page, leaks data, and increases your compliance surface.
3 additional standards didn't apply to this site
Can everyone use it?76Excellent
Your headings are in a sensible order
Your heading levels skip — for example, an H1 followed by an H3 with no H2 in between. Screen reader users lose the outline of the page.
Text on your homepage doesn't meet WCAG AA contrast minimums against its background. Visitors with low vision can't read parts of the page.
Your photos have written descriptions
Every image on your homepage has alt text — screen readers can describe them.
Your buttons and forms are labeled for screen readers
Interactive elements have proper ARIA labels — screen reader users get a clear description of each control.
A skip-to-content link is published — keyboard users land directly on the main content.
2 additional standards didn't apply to this site
Is it safe to visit?82Excellent
WordPress isn't leaking your usernames
Your WordPress site exposes its user list through the REST API. Attackers can enumerate every account by username — the first half of any credential-stuffing attack is already done for them.
Strict mode for your padlock check
Neither OCSP stapling nor Must-Staple is in play. A revoked cert wouldn't be caught quickly.
Your certificate is publicly logged
Your certificate carries only one embedded SCT — modern browsers want at least two. Reissue from a CA that includes them.
Your padlock renews on a healthy schedule
Your certificate lifetime is on the longer end (> 90 days). ACME-class certs renew every 60-90 days and rotate cleanly.
Private files aren't open to the public
None of the common admin or developer paths are publicly reachable.
Old TLS versions are turned off
Only modern TLS (1.2 and above) is offered — TLS 1.0 and 1.1 are turned off.
The padlock uses strong, modern math
The handshake negotiates a modern AEAD cipher (AES-GCM or ChaCha20-Poly1305).
Old recordings stay locked even if a key leaks
Forward secrecy is guaranteed by the negotiated handshake — past traffic stays unreadable even if your key leaks.
Your padlock isn't using outdated keys
Your certificate uses strong modern math (ECDSA P-256+ or RSA-2048+ with SHA-256+).
Your padlock loads cleanly on every device
Your server sends the full certificate chain — every device builds the path to a trusted root cleanly.
Visitors connect faster on the first click
Your server staples a fresh OCSP response — visitors don't have to round-trip to the CA on first connect.
Your padlock comes from a reputable vendor
Your certificate is issued by a tier-1 publicly trusted CA (Let's Encrypt, DigiCert, Google Trust, Sectigo, etc.).
Your site finishes its handshake quickly
Your TLS handshake completes quickly — under 300ms on a cold connection.
7 additional standards didn't apply to this site
Is it fast?82Excellent
Your site uses the newest connection style
Your server still serves over the older HTTP/2 protocol — not the newer, faster HTTP/3.
Your photos are saved in modern formats
Your images are served as JPEG or PNG when modern formats (WebP, AVIF) would cut their size by 30–60% with no visible loss.
Photos lower on the page wait their turn
Below-fold images use loading="lazy" — they download only when the visitor scrolls toward them.
How fast your site loads on a phone
Your homepage loads fast on mobile — the metrics Google uses for ranking are in the green.
Pages get squeezed before they're sent
Your server compresses pages with Brotli or gzip — visitors download a fraction of the raw size.
Your text shows up while fonts load
Your fonts swap in cleanly — text is readable in the system font while custom fonts download.
6 additional standards didn't apply to this site
Can people find this site?84Excellent
A clear headline on every page
Your homepage doesn't have a visible H1 heading. Without it, search engines and screen readers have no anchor for what the page is about.
How well your site feeds AI the right facts
We couldn't find any organization details in your page's structured data.
Hidden labels that explain your business to Google
Your homepage publishes Schema.org structured data — search engines and AI tools can read what your site is directly.
How your site appears when shared or in search results
Your homepage has the title, description, OG, Twitter, and canonical tags.
Whether your behind-the-scenes labels are valid
Your structured-data tags parse cleanly against Schema.org.
A trail showing where visitors are on your site
Your pages publish breadcrumb schema — search results show the path back to important sections.
How easy it is to reach your deepest pages
Important pages are reachable in just a click or two from your homepage.
8 additional standards didn't apply to this site
Is email from this domain trustworthy?89Excellent
Lists who's allowed to email as your business
No SPF record is published, so nothing tells mail providers who's allowed to send as you.
Your email setup is under a hidden limit
Your SPF record exceeds the 10-lookup limit — receiving servers will reject it.
Stops scammers from emailing customers as you
DMARC is enforcing — spoofed mail from your domain gets quarantined or rejected.
You email from your own domain, not Gmail
You send email from your own domain, not a free Gmail/Yahoo address.
What's actually running your email
provider=microsoft_365, mx=mynorth-com.mail.protection.outlook.com, source=mx_classifier
You get reports when someone fakes your email
You're set up to receive daily DMARC reports of spoofing attempts.
A real tool for sending newsletters
Your Email Service Provider is detectable — newsletters and marketing email have a real sending platform behind them.
A clickable email link on your site
Your site exposes a mailto: link visitors can tap to start a message.
Your email is being forwarded, not hosted
Mail to this domain is being forwarded — you have working email reachability.
3 additional standards didn't apply to this site
Does this look like a real business?98Excellent
How long your domain has existed
Your domain has been registered for years — long enough to clear fraud-detection signals.
Whether you have a Wikipedia entry
Your business has a Wikipedia entry — a strong reputation signal.
A contact form people can actually find
A visible contact form is reachable from your homepage.
8 additional standards didn't apply to this site