Scan report for progasi-moto.by
5 pages crawled — 1802 words, 5 images and 68 links read straight off the pages and checked for accessibility, performance, SEO, security, forms, links and infrastructure. 20 issues found.
Report updated 2026-09-04
Category scores
- Overall
- 94/100
- SEO
- 99/100 · Issues: 1
- Accessibility
- 100/100 · No issues found
- Performance
- 100/100 · No issues found
- Security
- 73/100 · Issues: 5
- Privacy
- 88/100 · Issues: 2
- HTML validity
- 100/100 · No issues found
- Forms
- 100/100 · No issues found
- Links
- 100/100 · No issues found
- Console
- Not measured
- Infrastructure
- 88/100 · Issues: 12
Quick Wins
High-impact, low-effort fixes, ranked by what this scan actually found.
- Add an apple-touch-icon and a web app manifest — A site saved to a phone home screen gets its own icon.
- Publish an SPF record — Receiving servers can tell your mail from mail that only claims to be yours.
- Enable HTTP/2 — Assets download in parallel over one connection.
- Publish a DMARC record — Forged mail from the domain starts being reported and, later, rejected.
- Publish a CAA record — Only the certificate authority you name can issue certificates for the domain.
- Publish and link a privacy policy — Visitors and regulators find the policy the site is required to publish.
What the site checks found
- Low — The Content-Security-Policy allows 'unsafe-inline' or 'unsafe-eval', which is what a script injection needs.
- Low — The domain publishes no MX records, so it cannot receive email.
- Medium — No SPF record — anyone can send email that claims to come from this domain.
- Medium — No DMARC record at _dmarc — nothing tells receiving servers what to do with mail that fails the SPF check.
- Low — No CAA record — any certificate authority may issue a certificate for this domain.
- Low — The host has no AAAA record — visitors on IPv6-only networks reach it only through their carrier gateway.
- Low — The zone is not signed with DNSSEC, so a forged DNS answer cannot be detected.
- Low — The site loads Yandex Metrica with no consent layer anywhere in the markup — under the GDPR and the ePrivacy Directive those tags need consent before they run.
- Medium — None of the scanned pages links a privacy policy (missing: privacy, terms, imprint).
Other sites scanned recently
Scan your own site
Get the same diagnostic report for your website in under a minute.