Scanned sites / www.alltimefitness.ca / 2026-09-19-0318

www.alltimefitness.ca scan from 9/19/2026, 3:18:16 AM

Scan 2026-09-19-0318

Scanned 9/19/2026, 3:18:16 AM, finished 9/19/2026, 3:48:31 AM. Found with openstreetmap overpass

Site: https://www.alltimefitness.ca/

Download SQLite databaseEvery page and asset from this scan, with the crawl events, in one file.

69/ 100Needs work

On September 19, 2026 the Site Spider crawled 159 pages and 1003 assets of www.alltimefitness.ca, starting from https://www.alltimefitness.ca/. It scored 69 out of 100, a result that needs work. 10 of 14 checks found something to fix, led by meta descriptions (84), redirects (66), sitemap coverage (36); 4 checks passed. The list below shows each check's result, the fix plan, when present, explains what to do first, and the security review at the end of the page covers headers, transport, libraries and exposed files.

Security review: Medium3 medium, 2 low and 1 info findings. See the security findings ↓

Pages crawled
159
Assets fetched
1003
Status
Completed
Checks with issues
10 of 14
  • Title tags30 issues
    30 of 84 pages have title issues. 4 noindex or canonicalized pages excluded.
  • Meta descriptions84 issues
    84 of 84 pages have meta description issues. 4 noindex or canonicalized pages excluded.
  • HeadingsOK
    0 of 84 pages have heading issues. 4 noindex or canonicalized pages excluded.
  • Broken links4 issues
    8 internal links point at 4 broken URLs.
  • Redirects66 issues
    68 redirecting URLs, 5 of them chained.
  • Non-200 responses4 issues
    72 URLs did not return a 2xx response.
  • Rate limitedOK
    The site did not rate limit the crawler.
  • Indexability30 issues
    30 of 84 indexable pages have indexability warnings. 4 pages noindex by design.
  • Image alt textOK
    0 of 872 image references have no alt attribute. 36 use an empty alt (decorative), which is fine.
  • Heavy assets19 issues
    19 assets larger than 500 KB among the 100 heaviest.
  • Orphan pages31 issues
    31 pages have no internal links pointing at them.
  • Sitemap coverage36 issues
    10 sitemaps listing 84 URLs: 4 crawled pages missing, 1 listed URL broken or redirecting, 28 reachable only via the sitemap.
  • Thin content22 issues
    22 of 84 pages have fewer than 200 words. 4 noindex or canonicalized pages excluded.
  • Duplicate contentOK
    0 groups of pages with identical HTML.

Where this scan sits among all scanned sites

1099 sites, median 82%, average 80%

www.alltimefitness.ca scores 69%, higher than 12% of the 1099 scanned sites. See the full ranking.

028560%: 0 sites1%: 0 sites2%: 0 sites3%: 0 sites4%: 0 sites5%: 0 sites6%: 0 sites7%: 0 sites8%: 0 sites9%: 0 sites10%: 0 sites11%: 0 sites12%: 0 sites13%: 0 sites14%: 0 sites15%: 0 sites16%: 0 sites17%: 0 sites18%: 0 sites19%: 0 sites20%: 0 sites21%: 1 site22%: 0 sites23%: 0 sites24%: 0 sites25%: 0 sites26%: 0 sites27%: 0 sites28%: 1 site29%: 0 sites30%: 0 sites31%: 0 sites32%: 0 sites33%: 0 sites34%: 0 sites35%: 1 site36%: 1 site37%: 0 sites38%: 0 sites39%: 0 sites40%: 0 sites41%: 0 sites42%: 0 sites43%: 0 sites44%: 0 sites45%: 2 sites46%: 1 site47%: 1 site48%: 0 sites49%: 0 sites50%: 3 sites51%: 4 sites52%: 1 site53%: 1 site54%: 2 sites55%: 1 site56%: 2 sites57%: 3 sites58%: 6 sites59%: 3 sites60%: 5 sites61%: 8 sites62%: 12 sites63%: 5 sites64%: 9 sites65%: 9 sites66%: 7 sites67%: 15 sites68%: 27 sites69%: 12 sites70%: 23 sites71%: 22 sites72%: 24 sites73%: 24 sites74%: 30 sites75%: 26 sites76%: 37 sites77%: 37 sites78%: 34 sites79%: 33 sites80%: 44 sites81%: 54 sites82%: 49 sites83%: 45 sites84%: 55 sites85%: 47 sites86%: 47 sites87%: 47 sites88%: 56 sites89%: 38 sites90%: 51 sites91%: 38 sites92%: 25 sites93%: 17 sites94%: 16 sites95%: 8 sites96%: 10 sites97%: 4 sites98%: 2 sites99%: 1 site100%: 12 sites69% here100%90%80%70%60%50%40%30%20%10%0%

Green 90% and up (Excellent), lime 75 to 89 (Good), amber 50 to 74 (Needs work), red below 50 (Poor).

Internal link map

Loading the link map...

Start page (centre)OKRedirectErrorOrphanLinked from most pagesOne inbound link or noneRings = clicks from the start page. Size = inbound links. Drag to pan, scroll to zoom, click a page to see only its links.

Fix plan

Written by gpt-4o-mini from the scan findings

Your website has several issues that need fixing to improve its SEO performance. Focus on correcting broken links, reducing redirects, and addressing title and meta description problems. These changes will significantly enhance your site's health score and user experience.

  1. 1

    Fix Broken Links

    Why: Broken links hurt user experience and SEO.

    How: Identify and remove or update the 8 broken internal links.

    Checks: broken-links

  2. 2

    Reduce Redirects

    Why: Too many redirects can slow down the site and confuse crawlers.

    How: Eliminate or streamline the 68 redirects, especially the 5 chained ones.

    Checks: redirects

  3. 3

    Resolve Non-200 Responses

    Why: Non-200 responses signify broken or unreachable pages.

    How: Fix the 72 URLs that return non-200 responses by updating or removing them.

    Checks: status-codes

  4. 4

    Update Title Tags

    Why: Missing or duplicate title tags can lead to poor search engine visibility.

    How: Correct the title issues for 30 pages, ensuring each has a unique, relevant title.

    Checks: titles

  5. 5

    Add Meta Descriptions

    Why: Missing meta descriptions can reduce click-through rates in search results.

    How: Create and add unique meta descriptions for all 84 pages.

    Checks: meta-descriptions

  6. 6

    Enhance Thin Content

    Why: Thin content ranks poorly in search engines.

    How: Add valuable content to the 22 pages with fewer than 200 words.

    Checks: thin-content

Generated automatically; verify each change against your own site before relying on it.

Security review

Written by gpt-4o-mini from 16 checks over the crawl

Your website has several security weaknesses related to response headers and cookie settings. This leaves user data at risk during transmission and could allow unauthorized actions through clickjacking or script injection. Implementing the recommended headers and configuring cookies correctly will strengthen your site’s security significantly.

  • 0 high
  • 3 medium
  • 2 low
  • 1 info
  1. 1

    Missing HTTP Strict Transport Security (HSTS)Medium

    Why it matters: Without HSTS, visitors can be intercepted when accessing the site via HTTP.

    Fix: Add the header: Strict-Transport-Security: max-age=31536000; includeSubDomains

    Evidence: HTTP Strict Transport Security

  2. 2

    Missing X-Frame-Options HeaderMedium

    Why it matters: Lack of this header allows clickjacking attacks by embedding your pages in frames on malicious sites.

    Fix: Add the header: X-Frame-Options: DENY or use a CSP with frame-ancestors.

    Evidence: Clickjacking protection

  3. 3

    Cookies Missing Protective FlagsMedium

    Why it matters: Cookies without Secure, HttpOnly, and SameSite flags are vulnerable to theft and cross-site request forgery.

    Fix: Set the following flags on cookies: HttpOnly, Secure; for SameSite use SameSite=Strict or SameSite=Lax.

    Evidence: Cookie flags

  4. 4

    Missing X-Content-Type-Options HeaderLow

    Why it matters: Without this header, browsers may misinterpret file types, leading to severe security vulnerabilities.

    Fix: Add the header: X-Content-Type-Options: nosniff

    Evidence: MIME sniffing protection

  5. 5

    Missing Referrer-Policy HeaderLow

    Why it matters: Without a defined referrer policy, sensitive information may be leaked to third-party sites.

    Fix: Add the header: Referrer-Policy: no-referrer or appropriate policy.

    Evidence: Referrer policy

  6. 6

    Missing Permissions-Policy HeaderInfo

    Why it matters: The absence of this header leaves browser features open to potentially malicious scripts.

    Fix: Add the header: Permissions-Policy: (feature) 'none'; limit access to unnecessary features.

    Evidence: Permissions policy

What the checks found

  • FoundHTTP Strict Transport SecurityMedium

    No HTML page sends strict-transport-security. Without it a visitor who types the address without https:// can be intercepted on the first request.

    • https://www.alltimefitness.ca/ → no strict-transport-security
    • https://www.alltimefitness.ca/personal-trainer-calgary/ → no strict-transport-security
    • https://www.alltimefitness.ca/our-workouts/ → no strict-transport-security
    • https://www.alltimefitness.ca/weight-loss-transformation/ → no strict-transport-security
    • https://www.alltimefitness.ca/cardio-training/ → no strict-transport-security
    • https://www.alltimefitness.ca/bodybuilding-training/ → no strict-transport-security
    • https://www.alltimefitness.ca/our-memberships/ → no strict-transport-security
    • https://www.alltimefitness.ca/blog/ → no strict-transport-security
    • https://www.alltimefitness.ca/about-us/ → no strict-transport-security
    • https://www.alltimefitness.ca/our-facilities/ → no strict-transport-security
    • https://www.alltimefitness.ca/contact/ → no strict-transport-security
    • https://www.alltimefitness.ca/beginner-gym-workouts/ → no strict-transport-security
  • FoundClickjacking protectionMedium

    2 of 88 HTML pages send x-frame-options. Without X-Frame-Options (or a CSP frame-ancestors directive) the pages can be embedded in a frame on another site and overlaid with invisible controls.

    • https://www.alltimefitness.ca/ → no x-frame-options
    • https://www.alltimefitness.ca/personal-trainer-calgary/ → no x-frame-options
    • https://www.alltimefitness.ca/our-workouts/ → no x-frame-options
    • https://www.alltimefitness.ca/weight-loss-transformation/ → no x-frame-options
    • https://www.alltimefitness.ca/cardio-training/ → no x-frame-options
    • https://www.alltimefitness.ca/bodybuilding-training/ → no x-frame-options
    • https://www.alltimefitness.ca/our-memberships/ → no x-frame-options
    • https://www.alltimefitness.ca/blog/ → no x-frame-options
    • https://www.alltimefitness.ca/about-us/ → no x-frame-options
    • https://www.alltimefitness.ca/our-facilities/ → no x-frame-options
    • https://www.alltimefitness.ca/contact/ → no x-frame-options
    • https://www.alltimefitness.ca/beginner-gym-workouts/ → no x-frame-options
  • FoundMIME sniffing protectionLow

    No HTML page sends x-content-type-options. Without X-Content-Type-Options: nosniff a browser may run a file as a script because of its contents rather than its declared type.

    • https://www.alltimefitness.ca/ → no x-content-type-options
    • https://www.alltimefitness.ca/personal-trainer-calgary/ → no x-content-type-options
    • https://www.alltimefitness.ca/our-workouts/ → no x-content-type-options
    • https://www.alltimefitness.ca/weight-loss-transformation/ → no x-content-type-options
    • https://www.alltimefitness.ca/cardio-training/ → no x-content-type-options
    • https://www.alltimefitness.ca/bodybuilding-training/ → no x-content-type-options
    • https://www.alltimefitness.ca/our-memberships/ → no x-content-type-options
    • https://www.alltimefitness.ca/blog/ → no x-content-type-options
    • https://www.alltimefitness.ca/about-us/ → no x-content-type-options
    • https://www.alltimefitness.ca/our-facilities/ → no x-content-type-options
    • https://www.alltimefitness.ca/contact/ → no x-content-type-options
    • https://www.alltimefitness.ca/beginner-gym-workouts/ → no x-content-type-options
  • FoundReferrer policyLow

    No HTML page sends referrer-policy. Without a Referrer-Policy the full page address, including any query string, is sent to every site a visitor clicks through to.

    • https://www.alltimefitness.ca/ → no referrer-policy
    • https://www.alltimefitness.ca/personal-trainer-calgary/ → no referrer-policy
    • https://www.alltimefitness.ca/our-workouts/ → no referrer-policy
    • https://www.alltimefitness.ca/weight-loss-transformation/ → no referrer-policy
    • https://www.alltimefitness.ca/cardio-training/ → no referrer-policy
    • https://www.alltimefitness.ca/bodybuilding-training/ → no referrer-policy
    • https://www.alltimefitness.ca/our-memberships/ → no referrer-policy
    • https://www.alltimefitness.ca/blog/ → no referrer-policy
    • https://www.alltimefitness.ca/about-us/ → no referrer-policy
    • https://www.alltimefitness.ca/our-facilities/ → no referrer-policy
    • https://www.alltimefitness.ca/contact/ → no referrer-policy
    • https://www.alltimefitness.ca/beginner-gym-workouts/ → no referrer-policy
  • FoundPermissions policyInfo

    No HTML page sends permissions-policy. A Permissions-Policy header turns off browser features the site does not use (camera, microphone, geolocation), limiting what an injected script could do.

    • https://www.alltimefitness.ca/ → no permissions-policy
    • https://www.alltimefitness.ca/personal-trainer-calgary/ → no permissions-policy
    • https://www.alltimefitness.ca/our-workouts/ → no permissions-policy
    • https://www.alltimefitness.ca/weight-loss-transformation/ → no permissions-policy
    • https://www.alltimefitness.ca/cardio-training/ → no permissions-policy
    • https://www.alltimefitness.ca/bodybuilding-training/ → no permissions-policy
    • https://www.alltimefitness.ca/our-memberships/ → no permissions-policy
    • https://www.alltimefitness.ca/blog/ → no permissions-policy
    • https://www.alltimefitness.ca/about-us/ → no permissions-policy
    • https://www.alltimefitness.ca/our-facilities/ → no permissions-policy
    • https://www.alltimefitness.ca/contact/ → no permissions-policy
    • https://www.alltimefitness.ca/beginner-gym-workouts/ → no permissions-policy
  • FoundCookie flagsMedium

    5 of 5 cookies are missing protective flags. Without HttpOnly a script can read the cookie; without Secure it travels over plain HTTP; without SameSite it is sent on cross-site requests.

    • _fbp (set by https://www.alltimefitness.ca/sitemap.xml) lacks HttpOnly
    • PHPSESSID (set by https://www.alltimefitness.ca/sitemap.xml) lacks Secure, HttpOnly, SameSite
    • woocommerce_items_in_cart (set by https://www.alltimefitness.ca/product-category/regular_membership/?add-to-cart=…) lacks Secure, HttpOnly, SameSite
    • woocommerce_cart_hash (set by https://www.alltimefitness.ca/product-category/regular_membership/?add-to-cart=…) lacks Secure, HttpOnly, SameSite
    • wp_woocommerce_session_57d7f35d7272d2125c01ee1269fafe59 (set by https://www.alltimefitness.ca/product-category/regular_membership/?add-to-cart=…) lacks SameSite
  • NoteThird-party scripts

    Scripts run from 3 other domains without Subresource Integrity, so a compromise of any of them changes what runs on this site. (Tag managers and analytics rarely support SRI; a Content-Security-Policy that names these hosts is the usual control.)

    • widgets.leadconnectorhq.com (40 script tags)
    • www.googletagmanager.com (80 script tags)
    • libs.na.bambora.com (4 script tags)
  • NoteSensitive paths in robots.txt

    robots.txt lists 6 paths that look private. robots.txt is public and does not restrict access, so it doubles as a map for anyone probing the site; those paths need real access control.

    • Disallow: /admin/
    • Disallow: /includes/
    • Disallow: /config/
    • Disallow: /backup/
    • Disallow: /wp-admin/
    • Disallow: /wp-includes/
8 checks passed
  • OKHTTPS

    All 88 crawled pages were served over HTTPS.

  • OKContent Security Policy

    A Content-Security-Policy is set on 2 of 88 pages.

  • OKSoftware version disclosure

    The Server header names a product without a version, and there is no X-Powered-By header.

  • OKMixed content

    No HTTPS page loads a script, stylesheet, font or image over plain HTTP.

  • OKForms over HTTPS

    22 forms found, all on HTTPS pages posting to HTTPS addresses.

  • OKVulnerable JavaScript libraries

    1 library version recognised, none with known vulnerabilities.

  • OKKeys and secrets in page code

    No API keys, tokens or private keys were found in the sampled HTML and scripts.

  • OKExposed files and listings

    None of the crawled URLs is a configuration file, backup, dump, repository folder or directory listing.

A passive review of what the crawl recorded: response headers, page and script contents and the URLs it found. It does not probe the site, test TLS settings or look for files that were not linked. Generated automatically; verify each finding against your own site before acting on it.

This report was produced by the DIY SEO Hub Site Spider crawling www.alltimefitness.ca from its public pages. Anyone can run a scan of any site they own or are authorised to check. Is this your site? Claim it to manage the listing, or ask for removal through the support form.

www.alltimefitness.ca scan 2026-09-19-0318 | DIY SEO Hub