Scanned sites / floridarevenue.com
SEO report for floridarevenue.com
The latest Site Spider scan of floridarevenue.com, with 1 scan on record. Each scan is at its own address, for example /domain/floridarevenue-com/2026-09-18-0700.
Latest scan
Scanned 9/18/2026, 7:00:02 AM, finished 9/18/2026, 9:36:45 AM. Found on page 2 of chatgpt for browser (api usage) results
Site: https://floridarevenue.com/faq/Pages/contactus.aspx
Download SQLite databaseEvery page and asset from this scan, with the crawl events, in one file.
On September 18, 2026 the Site Spider crawled 969 pages and 5057 assets of floridarevenue.com, starting from https://floridarevenue.com/faq/Pages/contactus.aspx. It scored 71 out of 100, a result that needs work. 13 of 14 checks found something to fix, led by image alt text (823), meta descriptions (500), sitemap coverage (500); 1 check passed. The list below shows each check's result, the fix plan, when present, explains what to do first, and the security review at the end of the page covers headers, transport, libraries and exposed files.
Security review: Medium3 medium, 2 low and 1 info findings. See the security findings ↓
- Pages crawled
- 969
- Assets fetched
- 5057
- Status
- Completed
- Checks with issues
- 13 of 14
- Title tags458 issues458 of 659 pages have title issues. 220 noindex or canonicalized pages excluded.
- Meta descriptions500 issues650 of 659 pages have meta description issues. 220 noindex or canonicalized pages excluded.
- Headings376 issues376 of 659 pages have heading issues. 220 noindex or canonicalized pages excluded.
- Broken links23 issues444 internal links point at 23 broken URLs.
- Redirects56 issues57 redirecting URLs, 5 of them chained.
- Non-200 responses35 issues93 URLs did not return a 2xx response.
- Rate limitedOKThe site did not rate limit the crawler.
- Indexability92 issues92 of 879 indexable pages have indexability warnings.
- Image alt text823 issues823 of 17681 image references have no alt attribute. 9 use an empty alt (decorative), which is fine.
- Heavy assets28 issues100 assets larger than 500 KB among the 100 heaviest.
- Orphan pages477 issues477 pages have no internal links pointing at them.
- Sitemap coverage500 issues1 sitemap listing 3556 URLs: 107 crawled pages missing, 503 listed URLs broken or redirecting, 2759 reachable only via the sitemap.
- Thin content299 issues299 of 659 pages have fewer than 200 words. 220 noindex or canonicalized pages excluded.
- Duplicate content2 issues1 group of pages with identical HTML.
Where this site sits among all scanned sites
1085 sites, median 82%, average 80%
floridarevenue.com scores 71%, higher than 15% of the 1085 scanned sites. See the full ranking.
Green 90% and up (Excellent), lime 75 to 89 (Good), amber 50 to 74 (Needs work), red below 50 (Poor).
Internal link map
Loading the link map...
Fix plan
Written by gpt-4o-mini from the scan findingsThe site has multiple technical SEO issues, such as broken links, redirects, and missing title tags that need urgent fixes to improve its health score. Prioritizing these changes can enhance user experience and search visibility.
- 1
Fix Broken Links
Why: Resolving broken links enhances user experience and maintains authority.
How: Identify each broken link and replace or remove it. Use a redirect if the page exists under a new URL.
Checks: broken-links
- 2
Resolve Redirect Issues
Why: Chained redirects slow down page loading, affecting SEO.
How: Streamline redirects by updating links to point directly to the final URL, thus removing unnecessary hops.
Checks: redirects
- 3
Address Non-200 Responses
Why: Non-200 responses can hinder page indexing and user access.
How: Investigate URLs returning errors and correct the underlying issues, either by fixing the server settings or updating links.
Checks: status-codes
- 4
Optimize Title Tags
Why: Proper title tags improve click-through rates and search rankings.
How: Shorten long titles and ensure unique titles for each page relevant to the content.
Checks: titles
- 5
Improve Meta Descriptions
Why: Unique meta descriptions can enhance visibility and click-through rates in search results.
How: Create unique and concise meta descriptions for each page, focusing on relevant keywords.
Checks: meta-descriptions
- 6
Add Image Alt Text
Why: Alt text improves accessibility and helps search engines understand image content.
How: Add descriptive alt attributes to images to convey their purpose or content.
Checks: images-alt
Generated automatically; verify each change against your own site before relying on it.
Security review
Written by gpt-4o-mini from 16 checks over the crawlThe website has several security vulnerabilities, primarily a lack of clickjacking protection and missing cookie security flags. It's essential to implement these changes to safeguard user data and enhance overall site integrity.
- 0 high
- 3 medium
- 2 low
- 1 info
- 1
Missing X-Frame-Options HeaderMedium
Why it matters: Without this header, pages may be embedded in frames on malicious sites, exposing users to clickjacking attacks.
Fix: Set the X-Frame-Options header to 'DENY' or use CSP 'frame-ancestors' directive.
Evidence: Clickjacking protection
- 2
Missing Secure Cookie FlagsMedium
Why it matters: Cookies lack security flags (Secure, HttpOnly, SameSite), making them vulnerable to theft and misuse.
Fix: Set Secure, HttpOnly, and SameSite flags on cookies.
Evidence: Cookie flags
- 3
Outdated JavaScript LibrariesMedium
Why it matters: Using libraries with known vulnerabilities can lead to security exploits.
Fix: Upgrade jQuery to at least version 3.5.0 and jQuery UI to 1.13.2.
Evidence: Vulnerable JavaScript libraries
- 4
Missing Referrer-Policy HeaderLow
Why it matters: Without this policy, sensitive URL data may be sent to other sites when users navigate away.
Fix: Add 'Referrer-Policy: no-referrer' or similar to your HTTP headers.
Evidence: Referrer policy
- 5
Mixed Content IssuesLow
Why it matters: Loading resources over HTTP on HTTPS pages can enable man-in-the-middle attacks.
Fix: Ensure all resources are loaded over HTTPS.
Evidence: Mixed content
- 6
No Permissions Policy HeaderInfo
Why it matters: Lack of this header means that unnecessary browser features remain enabled, which could be exploited.
Fix: Implement a Permissions-Policy header to disable unused features.
Evidence: Permissions policy
What the checks found
- FoundClickjacking protectionMedium
866 of 879 HTML pages send x-frame-options. Without X-Frame-Options (or a CSP frame-ancestors directive) the pages can be embedded in a frame on another site and overlaid with invisible controls.
- https://floridarevenue.com/u002f/u002ffloridarevenue.com/u002fchildsupport/u002f_vti_bin/u002fSpellCheck.asmx → no x-frame-options
- https://floridarevenue.com/faq/Pages/FAQSearch.aspx?Cat=4Subcat=60 → no x-frame-options
- https://floridarevenue.com/faq/Pages/FAQSearch.aspx?Cat=4Subcat=26 → no x-frame-options
- https://floridarevenue.com/faq/Pages/FAQSearch.aspx?Cat=4Subcat=46 → no x-frame-options
- https://floridarevenue.com/faq/Pages/FAQSearch.aspx?Cat=4Subcat=43 → no x-frame-options
- https://floridarevenue.com/u002f/u002ffloridarevenue.com/u002fproperty/u002f_vti_bin/u002fSpellCheck.asmx → no x-frame-options
- https://floridarevenue.com/faq/Pages/FAQSearch.aspx?Cat=4Subcat=40 → no x-frame-options
- https://floridarevenue.com/faq/Pages/FAQSearch.aspx?Cat=4Subcat=25 → no x-frame-options
- https://floridarevenue.com/faq/Pages/FAQSearch.aspx?Cat=4Subcat=36 → no x-frame-options
- https://floridarevenue.com/faq/Pages/faqsearch.aspx?Cat=4Subcat=37 → no x-frame-options
- https://floridarevenue.com/faq/Pages/FAQSearch.aspx?Cat=4Subcat=59 → no x-frame-options
- https://floridarevenue.com/faq/Pages/FAQSearch.aspx?Cat=4Subcat=35 → no x-frame-options
- FoundReferrer policyLow
No HTML page sends referrer-policy. Without a Referrer-Policy the full page address, including any query string, is sent to every site a visitor clicks through to.
- https://floridarevenue.com/faq/Pages/contactus.aspx → no referrer-policy
- https://floridarevenue.com/Pages/mobile.aspx → no referrer-policy
- https://floridarevenue.com/Pages/contact.aspx → no referrer-policy
- https://floridarevenue.com/faq/Pages/FAQSearch.aspx?Cat=1 → no referrer-policy
- https://floridarevenue.com/faq/Pages/FAQSearch.aspx?Cat=7 → no referrer-policy
- https://floridarevenue.com/faq/Pages/FAQSearch.aspx?Cat=4 → no referrer-policy
- https://floridarevenue.com/Pages/about_us.aspx → no referrer-policy
- https://floridarevenue.com/Pages/communication_assistance.aspx → no referrer-policy
- https://floridarevenue.com/Pages/forms_index.aspx → no referrer-policy
- https://floridarevenue.com/Pages/media.aspx → no referrer-policy
- https://floridarevenue.com/opengovt/Pages/meetings.aspx → no referrer-policy
- https://floridarevenue.com/Pages/survey.aspx → no referrer-policy
- FoundPermissions policyInfo
No HTML page sends permissions-policy. A Permissions-Policy header turns off browser features the site does not use (camera, microphone, geolocation), limiting what an injected script could do.
- https://floridarevenue.com/faq/Pages/contactus.aspx → no permissions-policy
- https://floridarevenue.com/Pages/mobile.aspx → no permissions-policy
- https://floridarevenue.com/Pages/contact.aspx → no permissions-policy
- https://floridarevenue.com/faq/Pages/FAQSearch.aspx?Cat=1 → no permissions-policy
- https://floridarevenue.com/faq/Pages/FAQSearch.aspx?Cat=7 → no permissions-policy
- https://floridarevenue.com/faq/Pages/FAQSearch.aspx?Cat=4 → no permissions-policy
- https://floridarevenue.com/Pages/about_us.aspx → no permissions-policy
- https://floridarevenue.com/Pages/communication_assistance.aspx → no permissions-policy
- https://floridarevenue.com/Pages/forms_index.aspx → no permissions-policy
- https://floridarevenue.com/Pages/media.aspx → no permissions-policy
- https://floridarevenue.com/opengovt/Pages/meetings.aspx → no permissions-policy
- https://floridarevenue.com/Pages/survey.aspx → no permissions-policy
- FoundCookie flagsMedium
6 of 6 cookies are missing protective flags. Without HttpOnly a script can read the cookie; without Secure it travels over plain HTTP; without SameSite it is sent on cross-site requests.
- dtCookie (set by https://floridarevenue.com/faq/Pages/contactus.aspx) lacks Secure, HttpOnly, SameSite
- TS019d1b6e (set by https://floridarevenue.com/faq/Pages/contactus.aspx) lacks Secure, HttpOnly, SameSite
- BIGipServerSP19_FLRevenue_PRD_EXT (set by https://floridarevenue.com/Pages/mobile.aspx) lacks SameSite
- SearchSession (set by https://floridarevenue.com/taxlaw/Pages/results.aspx) lacks HttpOnly, SameSite
- TS0139c107 (set by https://floridarevenue.com/taxlaw/Pages/results.aspx) lacks Secure, HttpOnly, SameSite
- TS01d72afa (set by https://www.floridarevenue.com/taxes/filepay) lacks Secure, HttpOnly, SameSite
- FoundMixed contentLow
2 resources on HTTPS pages are loaded over plain HTTP.
- https://floridarevenue.com/Pages/subscribe.aspx loads image http://img.constantcontact.com/ui/images1/safe_subscribe_logo.gif
- https://floridarevenue.com/Pages/subscribe.aspx loads image http://img.constantcontact.com/ui/images1/safe_subscribe_logo.gif
- FoundVulnerable JavaScript librariesMedium
5 libraries with published vulnerabilities: jQuery 1.10.2, jQuery 3.2.1, jQuery 3.4.1, jQuery 3.3.1, jQuery UI 1.11.2. Whether they are exploitable depends on how the site uses them, but each has a fixed release.
- jQuery 1.10.2 in https://floridarevenue.com/_catalogs/masterpage/FDOR-Internet/js/common/jquery-…: CVE-2015-9251 (XSS via cross-domain AJAX), CVE-2019-11358 (prototype pollution), CVE-2020-11022, CVE-2020-11023 (XSS via HTML passed to DOM methods); fixed in 3.5.0
- jQuery 3.2.1 in https://floridarevenue.com/childsupport/Site%20Assets/js/jquery-3.2.1.min.js: CVE-2019-11358 (prototype pollution), CVE-2020-11022, CVE-2020-11023 (XSS via HTML passed to DOM methods); fixed in 3.5.0
- jQuery 3.4.1 in https://code.jquery.com/jquery-3.4.1.js: CVE-2020-11022, CVE-2020-11023 (XSS via HTML passed to DOM methods); fixed in 3.5.0
- jQuery 3.3.1 in https://ajax.googleapis.com/ajax/libs/jquery/3.3.1/jquery.min.js: CVE-2019-11358 (prototype pollution), CVE-2020-11022, CVE-2020-11023 (XSS via HTML passed to DOM methods); fixed in 3.5.0
- jQuery UI 1.11.2 in https://floridarevenue.com/_catalogs/masterpage/FDOR-Internet/js/common/jquery-…: CVE-2016-7103, CVE-2021-41182, CVE-2021-41183, CVE-2021-41184, CVE-2022-31160 (XSS through widget options); fixed in 1.13.2
- NoteThird-party scripts
Scripts run from 8 other domains without Subresource Integrity, so a compromise of any of them changes what runs on this site. (Tag managers and analytics rarely support SRI; a Content-Security-Policy that names these hosts is the usual control.)
- www.googletagmanager.com (40 script tags)
- code.jquery.com (40 script tags)
- whoson.floridarevenue.com (2 script tags)
- cdnjs.cloudflare.com (21 script tags)
- cdn.jsdelivr.net (41 script tags)
- kit.fontawesome.com (1 script tag)
- cse.google.com (1 script tag)
- childsupportwebchat.floridarevenue.com (2 script tags)
- NoteSensitive paths in robots.txt
robots.txt lists 2 paths that look private. robots.txt is public and does not restrict access, so it doubles as a map for anyone probing the site; those paths need real access control.
- Disallow: /_private/
- Disallow: /_private/
8 checks passed
- OKHTTPS
All 879 crawled pages were served over HTTPS.
- OKHTTP Strict Transport Security
strict-transport-security is set on all 879 HTML pages.
- OKContent Security Policy
A Content-Security-Policy is set on 866 of 879 pages.
- OKMIME sniffing protection
x-content-type-options is set on all 879 HTML pages.
- OKSoftware version disclosure
The Server header names a product without a version, and there is no X-Powered-By header.
- OKForms over HTTPS
40 forms found, all on HTTPS pages posting to HTTPS addresses.
- OKKeys and secrets in page code
No API keys, tokens or private keys were found in the sampled HTML and scripts.
- OKExposed files and listings
None of the crawled URLs is a configuration file, backup, dump, repository folder or directory listing.
A passive review of what the crawl recorded: response headers, page and script contents and the URLs it found. It does not probe the site, test TLS settings or look for files that were not linked. Generated automatically; verify each finding against your own site before acting on it.
Earlier scans of floridarevenue.com
No other scans of this site yet.
This report was produced by the DIY SEO Hub Site Spider crawling floridarevenue.com from its public pages. Anyone can run a scan of any site they own or are authorised to check. Is this your site? Claim it to manage the listing, or ask for removal through the support form.