Scan report for tmbk-moto.by
5 pages crawled — 1772 words, 5 images and 30 links read straight off the pages and checked for accessibility, performance, SEO, security, forms, links and infrastructure. 54 issues found.
Report updated 2026-09-04
Category scores
- Overall
- 91/100
- SEO
- 97/100 · Issues: 5
- Accessibility
- 100/100 · No issues found
- Performance
- 94/100 · Issues: 6
- Security
- 55/100 · Issues: 29
- Privacy
- 88/100 · Issues: 2
- HTML validity
- 97/100 · Issues: 5
- Forms
- 100/100 · No issues found
- Links
- 100/100 · No issues found
- Console
- Not measured
- Infrastructure
- 91/100 · Issues: 7
Quick Wins
High-impact, low-effort fixes, ranked by what this scan actually found.
- Send X-Content-Type-Options: nosniff — Browsers stop guessing content types and executing files as scripts.
- Send an X-Frame-Options header — The site cannot be framed for click-jacking.
- Send a Referrer-Policy header — Internal URLs stop leaking to third-party sites.
- Send a Permissions-Policy header — Camera, microphone and geolocation stay switched off for embedded content.
- Introduce a Content-Security-Policy — Injected scripts stop being able to run.
- Escape the bare ampersands as & — Ampersands render as written instead of being read as the start of an entity.
What the site checks found
- Low — The HTML is sent with no Cache-Control, Expires, ETag or Last-Modified — every visit re-downloads it in full.
- Low — The domain publishes no MX records, so it cannot receive email.
- Medium — No SPF record — anyone can send email that claims to come from this domain.
- Medium — No DMARC record at _dmarc — nothing tells receiving servers what to do with mail that fails the SPF check.
- Low — No CAA record — any certificate authority may issue a certificate for this domain.
- Low — The host has no AAAA record — visitors on IPv6-only networks reach it only through their carrier gateway.
- Low — The zone is not signed with DNSSEC, so a forged DNS answer cannot be detected.
- Low — The site loads Yandex Metrica with no consent layer anywhere in the markup — under the GDPR and the ePrivacy Directive those tags need consent before they run.
- Medium — None of the scanned pages links a privacy policy (missing: privacy, terms, imprint).
Other sites scanned recently
Scan your own site
Get the same diagnostic report for your website in under a minute.