Report loading
www.plooral.com.br
Preparing the full page inventory and screenshots.
Report loading
Preparing the full page inventory and screenshots.
49 / 100
Poor
0 critical fixes · 5 quick wins
Priority verdict
49/100 - poor. Start with the fixes below before reading the full report.
The biggest issue is missing strict-transport-security. Start with the priority fixes, then use the evidence and technical details when a developer needs proof.
Poor
3 priority fixes identified
Score
49 / 100 — Poor
No major launch blockers found.
Biggest risk
Missing Strict-Transport-Security
visitor safety and trust
Fastest win
Missing Strict-Transport-Security
A practical first fix for your builder or AI agent.
Estimated impact
Higher confidence and discoverability
Fix the priority items first, then re-scan to confirm the evidence.
Biggest area to improve: Security, which mostly means visitor safety and trust.
Priority verdict
This site is technically inspectable, but the priority is making the next fix obvious.
Fix the highest-impact issue first, then use structured evidence and developer prompts so search engines, AI answer engines, and real visitors can understand the site more reliably.
What's working
What needs attention
What to do first
The Plooral digital presence currently operates with significant security and accessibility gaps that undermine professional credibility and user experience. The website demonstrates strong foundational SEO and brand identity. It utilizes valid JSON-LD structured data for organization and website schema, maintains a clear value proposition in the hero section, and implements essential email authentication protocols (SPF, DMARC, and DKIM). The site is also well-prepared for AI-driven discovery, as robots.txt does not block major AI crawlers, ensuring the brand remains visible to emerging answer engines. However, the site faces high-priority technical risks. The absence of a Content-Security-Policy (CSP) and Strict-Transport-Security (HSTS) headers creates serious vulnerabilities to cross-site scripting (XSS) and protocol downgrade attacks. Furthermore, high-priority accessibility failures exist; insufficient color contrast ratios and undersized touch targets violate WCAG standards, which may alienate users and impact search rankings. Performance is also hindered by a heavy third-party script load and a Largest Contentful Paint (LCP) that exceeds recommended thresholds. The most significant opportunity lies in optimizing for "AI-readiness" and commercial intent. While the site is crawlable, it lacks specific content blocks—such as FAQs, pricing, or detailed product catalogs—that answer the specific buyer prompts used by commercial AI search engines. Developing these concise, machine-readable answer blocks will position Plooral as a primary citation source in AI-generated search results. To stabilize the platform, the following actions must be prioritized in the first 30 days: - Implement a robust Content-Security-Policy (CSP) and HSTS header to secure the domain.
Scan details
Checks performed: SEO, UX, accessibility, performance, security, AI search.
Fix workflow
Treat this report as a queue: send the ready fixes, accept any intentional risks, then re-scan the production URL after changes land.
32
Ready to send
71
Not started
0
Accepted risk
0
Re-scan queued
The full report has all the proof. This is the owner-friendly version of what to do first.
Plain-English reason
This affects visitor safety and trust. PageLens marked it as important so you know where it belongs in the queue.
What to ask your builder or AI agent to do
Add: Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
No HSTS header. Users are vulnerable to protocol downgrade attacks.
Plain-English reason
This affects visitor safety and trust. PageLens marked it as important so you know where it belongs in the queue.
What to ask your builder or AI agent to do
Add a Content-Security-Policy header. Start restrictive: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'
No CSP header found. The site is vulnerable to XSS and injection attacks.
Plain-English reason
This affects speed and loading experience. PageLens marked it as important so you know where it belongs in the queue.
What to ask your builder or AI agent to do
Audit every third-party tag: drop ones you're no longer measuring, switch from <script> to async/defer, route analytics through a single tag manager, and self-host fonts as woff2 (most font CDNs add 50-150 KB per family).
Third-party scripts (analytics, embeds, ad pixels, font CDNs, chat widgets) are hosted outside your control and often render-block, INP-block, or both. Each adds DNS resolution + TLS overhead and can fail independently of your own infrastructure.
A practical roadmap for turning the audit into progress.
Today
Add: Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
This week
Add a Content-Security-Policy header. Start restrictive: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'
This month
Audit every third-party tag: drop ones you're no longer measuring, switch from <script> to async/defer, route analytics through a single tag manager, and self-host fonts as woff2 (most font CDNs add 50-150 KB per family).
Same data as the full report, grouped by what a non-technical owner should do with it.
High-impact fixes that should usually be tackled before anything else.
Important fixes that may need more development time or a design decision.
Nothing in this bucket.
Polish and lower-priority work. Useful, but not where to start.
Need the detail?
The full report still has every finding, evidence, rule ID, filters, screenshots, and technical panels.