Scanned sites / hellogorgeousskinlab.com / 2026-09-18-1608
hellogorgeousskinlab.com scan from 9/18/2026, 4:08:52 PM
Scan 2026-09-18-1608
Scanned 9/18/2026, 4:08:52 PM, finished 9/18/2026, 4:10:50 PM. Found with openstreetmap overpass
Site: http://hellogorgeousskinlab.com/
Download SQLite databaseEvery page and asset from this scan, with the crawl events, in one file.
On September 18, 2026 the Site Spider crawled 10 pages and 63 assets of hellogorgeousskinlab.com, starting from http://hellogorgeousskinlab.com/. It scored 84 out of 100, a good result. 8 of 14 checks found something to fix, led by image alt text (207), meta descriptions (5), heavy assets (3); 6 checks passed. The list below shows each check's result, the fix plan, when present, explains what to do first, and the security review at the end of the page covers headers, transport, libraries and exposed files.
Security review: High2 high, 4 medium and 1 info findings. See the security findings ↓
- Pages crawled
- 10
- Assets fetched
- 63
- Status
- Completed
- Checks with issues
- 8 of 14
- Title tagsOK0 of 5 pages have title issues. 4 noindex or canonicalized pages excluded.
- Meta descriptions5 issues5 of 5 pages have meta description issues. 4 noindex or canonicalized pages excluded.
- Headings1 issue1 of 5 pages have heading issues. 4 noindex or canonicalized pages excluded.
- Broken linksOK0 internal links point at 0 broken URLs.
- Redirects1 issue1 redirecting URL, 0 of them chained.
- Non-200 responsesOK1 URL did not return a 2xx response.
- Rate limitedOKThe site did not rate limit the crawler.
- IndexabilityOK0 of 5 indexable pages have indexability warnings. 4 pages noindex by design.
- Image alt text207 issues207 of 232 image references have no alt attribute.
- Heavy assets3 issues3 assets larger than 500 KB among the 63 heaviest.
- Orphan pages2 issues2 pages have no internal links pointing at them.
- Sitemap coverage2 issues5 sitemaps listing 7 URLs: 0 crawled pages missing, 0 listed URLs broken or redirecting, 0 reachable only via the sitemap.
- Thin content1 issue1 of 5 pages have fewer than 200 words. 4 noindex or canonicalized pages excluded.
- Duplicate contentOK0 groups of pages with identical HTML.
Where this scan sits among all scanned sites
1089 sites, median 82%, average 80%
hellogorgeousskinlab.com scores 84%, higher than 57% of the 1089 scanned sites. See the full ranking.
Green 90% and up (Excellent), lime 75 to 89 (Good), amber 50 to 74 (Needs work), red below 50 (Poor).
Internal link map
Loading the link map...
Fix plan
Written by gpt-4o-mini from the scan findingsSeveral SEO optimizations are needed to improve your site's performance. Key areas include fixing the 301 redirect, adding missing meta descriptions, alt text for images, and internal links for orphaned pages. Addressing these will enhance visibility and user experience.
- 1
Fix Redirects
Why: A redirect affects user experience and may dilute link equity.
How: Change the redirect status from 301 to direct access for /contact.
Checks: redirects
- 2
Add Meta Descriptions
Why: Missing meta descriptions can hinder click-through rates from search results.
How: Create unique, compelling meta descriptions for about, aftercare, contact, and treatments pages.
Checks: meta-descriptions
- 3
Implement Image Alt Text
Why: Adding alt text improves accessibility and SEO for non-visible content.
How: Provide descriptive alt text for the 207 images missing alt attributes.
Checks: images-alt
- 4
Fix Heading Issues
Why: Missing headings affect content structure and SEO.
How: Add an H1 tag to the contact page.
Checks: headings
- 5
Link Orphan Pages
Why: Internal links improve navigation and indexability of the site.
How: Add links from other relevant pages to the orphaned author pages.
Checks: orphan-pages
- 6
Reduce Heavy Assets
Why: Large assets can slow down loading times, impacting user experience.
How: Optimize or replace the three assets over 500 KB to lower file sizes.
Checks: heavy-assets
Generated automatically; verify each change against your own site before relying on it.
Security review
Written by gpt-4o-mini from 16 checks over the crawlYour website has several security vulnerabilities, primarily due to not using HTTPS and missing important security headers. This can expose user data to interception. Immediate actions are needed to secure your site and your users' information.
- 2 high
- 4 medium
- 0 low
- 1 info
- 1
Insecure HTTP TrafficHigh
Why it matters: Your site serves pages over HTTP, making them vulnerable to interception and tampering.
Fix: Ensure all pages are served over HTTPS by obtaining an SSL certificate and redirecting HTTP requests.
Evidence: HTTPS
- 2
Forms Transmit Data Over HTTPHigh
Why it matters: Forms on your site send data over HTTP, exposing user input to potential interception.
Fix: Serve all forms over HTTPS. Redirect users from HTTP to HTTPS or enforce HTTPS directly.
Evidence: Forms over HTTPS
- 3
Missing Content Security PolicyMedium
Why it matters: Lack of a Content Security Policy allows potential scripts to load from any source, increasing XSS risks.
Fix: Add a Content-Security-Policy header to your HTML pages, e.g., 'Content-Security-Policy: default-src 'self';'.
Evidence: Content Security Policy
- 4
Cookie Flags MissingMedium
Why it matters: Cookies on the site do not have protective flags, making them vulnerable to XSS attacks.
Fix: Set the cookie flags: 'Set-Cookie: wordpress_test_cookie=...; HttpOnly; Secure; SameSite=Strict'.
Evidence: Cookie flags
- 5
Vulnerable JavaScript LibrariesMedium
Why it matters: Your site uses outdated jQuery versions with known vulnerabilities that could be exploited.
Fix: Update jQuery to at least version 3.5.0 for security improvements.
Evidence: Vulnerable JavaScript libraries
- 6
Leaked Google API KeyMedium
Why it matters: An API key exposed in your source code can be misused by attackers.
Fix: Restrict this API key in the Google Cloud Console to trusted referrer URLs.
Evidence: Keys and secrets in page code
- 7
Missing Permissions PolicyInfo
Why it matters: Not setting a Permissions Policy exposes features not needed by your site.
Fix: Add a Permissions-Policy header, e.g., 'Permissions-Policy: geolocation=(self)'.
Evidence: Permissions policy
What the checks found
- FoundHTTPSHigh
9 pages answered 200 over plain HTTP with no redirect to HTTPS. Anyone on the network path can read or alter these pages.
- http://hellogorgeousskinlab.com/ → 200 over http
- http://hellogorgeousskinlab.com/about/ → 200 over http
- http://hellogorgeousskinlab.com/treatments/ → 200 over http
- http://hellogorgeousskinlab.com/aftercare/ → 200 over http
- http://hellogorgeousskinlab.com/contact/ → 200 over http
- http://hellogorgeousskinlab.com/author/hellogorgeous/ → 200 over http
- http://hellogorgeousskinlab.com/author/info-wax/ → 200 over http
- http://hellogorgeousskinlab.com/wp-login.php → 200 over http
- http://hellogorgeousskinlab.com/wp-login.php?action=lostpassword → 200 over http
- FoundContent Security PolicyMedium
None of the 9 HTML pages send a Content-Security-Policy header or meta tag, so the browser has no restriction on where scripts, styles and frames may load from.
- http://hellogorgeousskinlab.com/ → no content-security-policy
- http://hellogorgeousskinlab.com/about/ → no content-security-policy
- http://hellogorgeousskinlab.com/treatments/ → no content-security-policy
- http://hellogorgeousskinlab.com/aftercare/ → no content-security-policy
- http://hellogorgeousskinlab.com/contact/ → no content-security-policy
- http://hellogorgeousskinlab.com/author/hellogorgeous/ → no content-security-policy
- http://hellogorgeousskinlab.com/author/info-wax/ → no content-security-policy
- http://hellogorgeousskinlab.com/wp-login.php → no content-security-policy
- http://hellogorgeousskinlab.com/wp-login.php?action=lostpassword → no content-security-policy
- FoundPermissions policyInfo
No HTML page sends permissions-policy. A Permissions-Policy header turns off browser features the site does not use (camera, microphone, geolocation), limiting what an injected script could do.
- http://hellogorgeousskinlab.com/ → no permissions-policy
- http://hellogorgeousskinlab.com/about/ → no permissions-policy
- http://hellogorgeousskinlab.com/treatments/ → no permissions-policy
- http://hellogorgeousskinlab.com/aftercare/ → no permissions-policy
- http://hellogorgeousskinlab.com/contact/ → no permissions-policy
- http://hellogorgeousskinlab.com/author/hellogorgeous/ → no permissions-policy
- http://hellogorgeousskinlab.com/author/info-wax/ → no permissions-policy
- http://hellogorgeousskinlab.com/wp-login.php → no permissions-policy
- http://hellogorgeousskinlab.com/wp-login.php?action=lostpassword → no permissions-policy
- FoundCookie flagsMedium
1 of 1 cookie are missing protective flags. Without HttpOnly a script can read the cookie; without Secure it travels over plain HTTP; without SameSite it is sent on cross-site requests.
- wordpress_test_cookie (set by http://hellogorgeousskinlab.com/wp-login.php) lacks HttpOnly, SameSite
- FoundForms over HTTPSHigh
4 forms would send what visitors type over plain HTTP, where it can be read or changed on the way.
- http://hellogorgeousskinlab.com/author/hellogorgeous/ has 2 forms on a page served over plain HTTP
- http://hellogorgeousskinlab.com/author/info-wax/ has 2 forms on a page served over plain HTTP
- http://hellogorgeousskinlab.com/wp-login.php has a password field on a page served over plain HTTP
- http://hellogorgeousskinlab.com/wp-login.php?action=lostpassword has 1 form on a page served over plain HTTP
- FoundVulnerable JavaScript librariesMedium
3 libraries with published vulnerabilities: jQuery 1.12.4, jQuery 3.2.1, jQuery 1.9.1. Whether they are exploitable depends on how the site uses them, but each has a fixed release.
- jQuery 1.12.4 in http://hellogorgeousskinlab.com/wp-includes/js/jquery/jquery.js: CVE-2015-9251 (XSS via cross-domain AJAX), CVE-2019-11358 (prototype pollution), CVE-2020-11022, CVE-2020-11023 (XSS via HTML passed to DOM methods); fixed in 3.5.0
- jQuery 3.2.1 in https://ajax.googleapis.com/ajax/libs/jquery/3.2.1/jquery.min.js: CVE-2019-11358 (prototype pollution), CVE-2020-11022, CVE-2020-11023 (XSS via HTML passed to DOM methods); fixed in 3.5.0
- jQuery 1.9.1 in http://ajax.googleapis.com/ajax/libs/jquery/1.9.1/jquery.min.js: CVE-2015-9251 (XSS via cross-domain AJAX), CVE-2019-11358 (prototype pollution), CVE-2020-11022, CVE-2020-11023 (XSS via HTML passed to DOM methods); fixed in 3.5.0
- FoundKeys and secrets in page codeMedium
1 credential-like value found in code served to every visitor: Google API key.
- Google API key AIzaSy…E0 (39 chars) in http://hellogorgeousskinlab.com/: browser keys are expected in pages, but must be restricted by HTTP referrer and API in the Google Cloud console
- NoteThird-party scripts
Scripts run from 3 other domains without Subresource Integrity, so a compromise of any of them changes what runs on this site. (Tag managers and analytics rarely support SRI; a Content-Security-Policy that names these hosts is the usual control.)
- ajax.googleapis.com (9 script tags)
- cdnjs.cloudflare.com (7 script tags)
- maps.googleapis.com (2 script tags)
- NoteSensitive paths in robots.txt
robots.txt lists 1 path that look private. robots.txt is public and does not restrict access, so it doubles as a map for anyone probing the site; those paths need real access control.
- Disallow: /wp-admin/
5 checks passed, 2 not applicable
- OKClickjacking protection
x-frame-options is set on all 9 HTML pages.
- OKMIME sniffing protection
x-content-type-options is set on all 9 HTML pages.
- OKReferrer policy
A referrer policy is set through a <meta name="referrer"> tag.
- OKSoftware version disclosure
The Server header names a product without a version, and there is no X-Powered-By header.
- OKExposed files and listings
None of the crawled URLs is a configuration file, backup, dump, repository folder or directory listing.
- Not applicableHTTP Strict Transport Security
No page was served over HTTPS, so this header does not apply yet.
- Not applicableMixed content
No page was served over HTTPS, so mixed content does not apply yet.
A passive review of what the crawl recorded: response headers, page and script contents and the URLs it found. It does not probe the site, test TLS settings or look for files that were not linked. Generated automatically; verify each finding against your own site before acting on it.
This report was produced by the DIY SEO Hub Site Spider crawling hellogorgeousskinlab.com from its public pages. Anyone can run a scan of any site they own or are authorised to check. Is this your site? Claim it to manage the listing, or ask for removal through the support form.