rivierapoolandspa.com
Corporate / B2B site.
Email health30Needs work
Mailto: direct contact link present
We couldn't find a tap-to-email link anywhere on your site.
9 additional standards didn't apply to this category
SEO62Fair
Schema.org type validity (parsed JSON-LD)
We didn't find any structured-data tags on your homepage.
Internal link depth (clicks from homepage to deepest content)
Important pages are reachable in just a click or two from your homepage.
8 additional standards didn't apply to this category
Performance65Fair
Your server still serves over the older HTTP/2 protocol — not the newer, faster HTTP/3.
11 additional standards didn't apply to this category
Accessibility70Strong
axe-core / WAVE accessibility scan
Automated accessibility scans flagged issues on your homepage — alt text, contrast, ARIA labels, or heading structure problems that block real users.
6 additional standards didn't apply to this category
Security83Strong
Your server doesn't staple OCSP. Visitors' browsers may have to contact the CA themselves, slowing first connects.
Neither OCSP stapling nor Must-Staple is in play. A revoked cert wouldn't be caught quickly.
Your TLS handshake takes over a second on a cold connection. Move behind a CDN with TLS session resumption and 0-RTT.
Certificate key strength and signature algorithm
Your certificate uses outdated key strength or a SHA-1 signature. Reissue with a modern ACME-class cert.
Embedded SCT count (Certificate Transparency)
Your certificate carries only one embedded SCT — modern browsers want at least two. Reissue from a CA that includes them.
Certificate validity-period brevity
Your certificate lifetime is on the longer end (> 90 days). ACME-class certs renew every 60-90 days and rotate cleanly.
Your certificate issuer isn't on the tier-1 trust list. Move to a mainstream public CA.
Sensitive path exposure (.git, .env, /admin, xmlrpc.php, wp-login.php)
None of the common admin or developer paths are publicly reachable.
Forward secrecy is guaranteed by the negotiated handshake — past traffic stays unreadable even if your key leaks.
Certificate chain completeness
Your server sends the full certificate chain — every device builds the path to a trusted root cleanly.
11 additional standards didn't apply to this category
View formal standards verdicts → Composite-spec rollups for press, regulators, and compliance auditors.
10 additional standards planned, scorer not yet implemented.
Is email from this domain trustworthy?30Needs work
A contact form people can actually find
We couldn't find a visible contact form on your homepage.
A clickable email link on your site
We couldn't find a tap-to-email link anywhere on your site.
9 additional standards didn't apply to this site
Is it fast?53Needs work
Your site uses the newest connection style
Your server still serves over the older HTTP/2 protocol — not the newer, faster HTTP/3.
11 additional standards didn't apply to this site
Is it safe to visit?63Fair
Visitors connect faster on the first click
Your server doesn't staple OCSP. Visitors' browsers may have to contact the CA themselves, slowing first connects.
Strict mode for your padlock check
Neither OCSP stapling nor Must-Staple is in play. A revoked cert wouldn't be caught quickly.
Your site finishes its handshake quickly
Your TLS handshake takes over a second on a cold connection. Move behind a CDN with TLS session resumption and 0-RTT.
Your padlock isn't using outdated keys
Your certificate uses outdated key strength or a SHA-1 signature. Reissue with a modern ACME-class cert.
Your certificate is publicly logged
Your certificate carries only one embedded SCT — modern browsers want at least two. Reissue from a CA that includes them.
Your padlock renews on a healthy schedule
Your certificate lifetime is on the longer end (> 90 days). ACME-class certs renew every 60-90 days and rotate cleanly.
Your padlock comes from a reputable vendor
Your certificate issuer isn't on the tier-1 trust list. Move to a mainstream public CA.
Private files aren't open to the public
None of the common admin or developer paths are publicly reachable.
Old recordings stay locked even if a key leaks
Forward secrecy is guaranteed by the negotiated handshake — past traffic stays unreadable even if your key leaks.
Your padlock loads cleanly on every device
Your server sends the full certificate chain — every device builds the path to a trusted root cleanly.
11 additional standards didn't apply to this site
Can people find this site?65Fair
Whether your behind-the-scenes labels are valid
We didn't find any structured-data tags on your homepage.
How easy it is to reach your deepest pages
Important pages are reachable in just a click or two from your homepage.
8 additional standards didn't apply to this site
Can everyone use it?70Strong
Your site works for visitors with disabilities
Automated accessibility scans flagged issues on your homepage — alt text, contrast, ARIA labels, or heading structure problems that block real users.
6 additional standards didn't apply to this site
Does this look like a real business?——
Does it respect visitor privacy?——
6 additional standards didn't apply to this site
Site signals
Context we detected about this site — presence, reputation, and the tools it runs. These are informational and don't affect the score, up or down.