Sources: html · resources
- html
G-3TLPF2VC0M - resources
googletagmanager.com/gtag/js?id=G-
Final URL: https://aiagentskills.net/
Scanned at 7/12/2026, 3:40:34 AM UTC · HTTP status 200
Strong. A solid public-site baseline. Close the priority fixes to protect the score.
Coverage: This saved score reflects the public signals captured by this scan. Optional rendered-DOM, axe-core, and Lighthouse evidence is documented under “How this scan was produced.”
0/7 fixed
Add Strict-Transport-Security after confirming the full site works over HTTPS.
Security · high ·security.missing_hsts_header · View fix guide
Add a CSP header at the CDN or server layer and test third-party scripts.
Security · high ·security.missing_csp_header · View fix guide
Add X-Frame-Options: SAMEORIGIN or use frame-ancestors in CSP.
Security · medium ·security.missing_x_frame_options_header · View fix guide
Add X-Content-Type-Options: nosniff.
Security · medium ·security.missing_x_content_type_options_header
Associate every input with a visible label or accessible aria-label.
Accessibility · medium ·accessibility.form_labels_missing
Add Referrer-Policy: strict-origin-when-cross-origin.
Security · low ·security.missing_referrer_policy_header · View fix guide
Restrict browser features that the site does not use.
Security · low ·security.missing_permissions_policy_header
Sources: html · resources
G-3TLPF2VC0Mgoogletagmanager.com/gtag/js?id=G-Sources: html
class="overflow-x-hiddenSources: html · resources · headers
/_next/static/_next/staticnext-routerSources: headers · resources
cf-raycloudflareinsights.comOptional external enrichment — popularity, traffic, and DNS signals that complement the first-party scan. Fetched on demand from an external provider; it is not part of the live scan.
No strong WordPress signal was found in the public HTML/resources.
WordPress sites can hide public CMS traces behind caching, headless frontends, or bundled assets.
Final URL: https://aiagentskills.net/
That usually means the input URL resolved directly without HTTP hop cleanup.
This MVP uses fast static performance signals. Enable Lighthouse CLI to add lab performance, SEO, accessibility, and best-practices scores.
On-demand performance intelligence is disabled for this runtime. When enabled with a Google API key, it loads separately from the main scan.
This is a fast static accessibility scan. Enable Playwright + axe-core for automated rendered-page audits.
Missing headers usually mean CDN, reverse-proxy, or framework config still needs a hardening pass.
Showing all 7 issues
HSTS was not found in the response headers.
Fix: Add Strict-Transport-Security after confirming the full site works over HTTPS.
Content-Security-Policy was not found in the response headers.
Fix: Add a CSP header at the CDN or server layer and test third-party scripts.
X-Frame-Options was not found in the response headers.
Fix: Add X-Frame-Options: SAMEORIGIN or use frame-ancestors in CSP.
X-Content-Type-Options was not found in the response headers.
Fix: Add X-Content-Type-Options: nosniff.
Referrer-Policy was not found in the response headers.
Fix: Add Referrer-Policy: strict-origin-when-cross-origin.
Permissions-Policy was not found in the response headers.
Fix: Restrict browser features that the site does not use.
3 text-like inputs and 0 labels were found.
Fix: Associate every input with a visible label or accessible aria-label.
This was a fast static scan of the public HTML, headers, robots.txt, and sitemap. Deeper rendered-DOM, lab (Lighthouse), and axe-core checks are optional and off for this report — so any empty section below reflects that boundary, not a clean bill of health.
Themerella uses a self-owned static scanner that combines HTML, resources, headers, metadata, CSS-class hints, robots.txt, and sitemap.xml. Enable Playwright to add rendered DOM, runtime globals, dynamic network responses, axe, and Lighthouse.