Scanned sites / www.bowbottomvet.com / 2026-09-19-0947
www.bowbottomvet.com scan from 9/19/2026, 9:47:41 AM
Scan 2026-09-19-0947
Scanned 9/19/2026, 9:47:41 AM, finished 9/19/2026, 11:13:18 AM. Found with openstreetmap overpass
Site: https://www.bowbottomvet.com/
Download SQLite databaseEvery page and asset from this scan, with the crawl events, in one file.
On September 19, 2026 the Site Spider crawled 437 pages and 598 assets of www.bowbottomvet.com, starting from https://www.bowbottomvet.com/. It scored 68 out of 100, a result that needs work. 12 of 14 checks found something to fix, led by meta descriptions (367), title tags (338), sitemap coverage (268); 2 checks passed. The list below shows each check's result, the fix plan, when present, explains what to do first, and the security review at the end of the page covers headers, transport, libraries and exposed files.
Security review: Medium5 medium, 3 low and 1 info findings. See the security findings ↓
- Pages crawled
- 437
- Assets fetched
- 598
- Status
- Completed
- Checks with issues
- 12 of 14
- Title tags338 issues338 of 368 pages have title issues. 31 noindex or canonicalized pages excluded.
- Meta descriptions367 issues367 of 368 pages have meta description issues. 31 noindex or canonicalized pages excluded.
- Headings44 issues44 of 368 pages have heading issues. 31 noindex or canonicalized pages excluded.
- Broken links25 issues430 internal links point at 25 broken URLs.
- Redirects24 issues24 redirecting URLs, 0 of them chained.
- Non-200 responses18 issues132 URLs did not return a 2xx response.
- Rate limitedOKThe site did not rate limit the crawler.
- Indexability127 issues127 of 391 indexable pages have indexability warnings. 8 pages noindex by design.
- Image alt textOK0 of 1782 image references have no alt attribute. 1024 use an empty alt (decorative), which is fine.
- Heavy assets35 issues35 assets larger than 500 KB among the 100 heaviest.
- Orphan pages6 issues6 pages have no internal links pointing at them.
- Sitemap coverage268 issues4 sitemaps listing 113 URLs: 261 crawled pages missing, 5 listed URLs broken or redirecting, 1 reachable only via the sitemap.
- Thin content2 issues2 of 368 pages have fewer than 200 words. 31 noindex or canonicalized pages excluded.
- Duplicate content12 issues2 groups of pages with identical HTML.
Where this scan sits among all scanned sites
1105 sites, median 82%, average 80%
www.bowbottomvet.com scores 68%, higher than 10% of the 1105 scanned sites. See the full ranking.
Green 90% and up (Excellent), lime 75 to 89 (Good), amber 50 to 74 (Needs work), red below 50 (Poor).
Internal link map
Loading the link map...
Fix plan
Written by gpt-4o-mini from the scan findingsYour website has several SEO issues that need fixing. The most critical problems involve broken links, redirects, non-200 responses, and missing title tags and meta descriptions. Addressing these will improve user experience and search engine visibility.
- 1
Fix Broken Links
Why: Internal links pointing to broken URLs hurt user experience and SEO.
How: Update or remove the 430 links leading to 25 broken URLs.
Checks: broken-links
- 2
Resolve Non-200 Responses
Why: 132 URLs not returning a 2xx status limit access to your content.
How: Investigate and resolve 132 non-200 response issues.
Checks: status-codes
- 3
Optimize Title Tags
Why: 338 pages have title issues, making it hard for search engines to index effectively.
How: Revise titles to be unique and under 60 characters for 338 pages.
Checks: titles
- 4
Enhance Meta Descriptions
Why: 367 pages lack meta descriptions, which decreases click-through rates.
How: Create compelling meta descriptions under 155 characters for these pages.
Checks: meta-descriptions
- 5
Fix Redirects
Why: 24 URLs redirecting can complicate site structure.
How: Review and fix unnecessary redirects to streamline access.
Checks: redirects
- 6
Improve Sitemap Coverage
Why: 261 crawled pages are missing from the sitemap, which can impede indexing.
How: Update the sitemap to include all pages and ensure it functions correctly.
Checks: sitemap-coverage
Generated automatically; verify each change against your own site before relying on it.
Security review
Written by gpt-4o-mini from 16 checks over the crawlThis security review identifies critical issues on your website that, if addressed, will enhance protection against various attacks. Key findings include missing security headers and vulnerable JavaScript libraries. Promptly implementing the suggested fixes will significantly improve your site's security posture.
- 0 high
- 5 medium
- 3 low
- 1 info
- 1
Missing HTTP Strict Transport Security (HSTS)Medium
Why it matters: Without HSTS, visitors using HTTP may be vulnerable to interception.
Fix: Add the header: Strict-Transport-Security: max-age=31536000; includeSubDomains
Evidence: HTTP Strict Transport Security
- 2
Missing X-Frame-Options HeaderMedium
Why it matters: Lack of X-Frame-Options allows for potential clickjacking attacks.
Fix: Add the header: X-Frame-Options: DENY
Evidence: Clickjacking protection
- 3
Cookies Missing Security FlagsMedium
Why it matters: Missing flags allow potential access to cookies in insecure ways.
Fix: Set cookies with: Secure; HttpOnly; SameSite=Strict
Evidence: Cookie flags
- 4
Vulnerable JavaScript LibraryMedium
Why it matters: Using jQuery 1.7.0 exposes the site to known vulnerabilities.
Fix: Upgrade jQuery to at least version 3.5.0.
Evidence: Vulnerable JavaScript libraries
- 5
Leaked Google API KeyMedium
Why it matters: Exposing sensitive API keys can lead to unauthorized usage.
Fix: Restrict API key usage with HTTP referrer settings in Google Cloud console.
Evidence: Keys and secrets in page code
- 6
Missing X-Content-Type-Options HeaderLow
Why it matters: Without this header, browsers can mistakenly execute files as scripts.
Fix: Add the header: X-Content-Type-Options: nosniff
Evidence: MIME sniffing protection
- 7
Missing Referrer PolicyLow
Why it matters: Lack of a referrer policy can expose sensitive information during navigations.
Fix: Add the header: Referrer-Policy: no-referrer-when-downgrade
Evidence: Referrer policy
- 8
Exposed Server and Framework VersionsLow
Why it matters: Version disclosures can allow attackers to exploit known vulnerabilities.
Fix: Configure the server to hide version numbers in headers.
Evidence: Software version disclosure
- 9
Missing Permissions-Policy HeaderInfo
Why it matters: A permissions policy can reduce the risk of unwanted features usage.
Fix: Add the header: Permissions-Policy: geolocation=(self), autoplay=(self)
Evidence: Permissions policy
What the checks found
- FoundHTTP Strict Transport SecurityMedium
No HTML page sends strict-transport-security. Without it a visitor who types the address without https:// can be intercepted on the first request.
- https://www.bowbottomvet.com/ → no strict-transport-security
- https://www.bowbottomvet.com/location-hours/ → no strict-transport-security
- https://www.bowbottomvet.com/forms/ → no strict-transport-security
- https://www.bowbottomvet.com/blog/ → no strict-transport-security
- https://www.bowbottomvet.com/testimonials/ → no strict-transport-security
- https://www.bowbottomvet.com/new-clients/ → no strict-transport-security
- https://www.bowbottomvet.com/new-clients/what-to-expect/ → no strict-transport-security
- https://www.bowbottomvet.com/new-clients/take-a-tour/ → no strict-transport-security
- https://www.bowbottomvet.com/about-us/ → no strict-transport-security
- https://www.bowbottomvet.com/about-us/welcome-to-our-clinic/ → no strict-transport-security
- https://www.bowbottomvet.com/about-us/team/ → no strict-transport-security
- https://www.bowbottomvet.com/all-services/services/ → no strict-transport-security
- FoundClickjacking protectionMedium
397 of 399 HTML pages send x-frame-options. Without X-Frame-Options (or a CSP frame-ancestors directive) the pages can be embedded in a frame on another site and overlaid with invisible controls.
- https://www.bowbottomvet.com/services/boarding/admin-ajax-2/ → no x-frame-options
- https://www.bowbottomvet.com/author/bowbottomadmin/ → no x-frame-options
- FoundMIME sniffing protectionLow
No HTML page sends x-content-type-options. Without X-Content-Type-Options: nosniff a browser may run a file as a script because of its contents rather than its declared type.
- https://www.bowbottomvet.com/ → no x-content-type-options
- https://www.bowbottomvet.com/location-hours/ → no x-content-type-options
- https://www.bowbottomvet.com/forms/ → no x-content-type-options
- https://www.bowbottomvet.com/blog/ → no x-content-type-options
- https://www.bowbottomvet.com/testimonials/ → no x-content-type-options
- https://www.bowbottomvet.com/new-clients/ → no x-content-type-options
- https://www.bowbottomvet.com/new-clients/what-to-expect/ → no x-content-type-options
- https://www.bowbottomvet.com/new-clients/take-a-tour/ → no x-content-type-options
- https://www.bowbottomvet.com/about-us/ → no x-content-type-options
- https://www.bowbottomvet.com/about-us/welcome-to-our-clinic/ → no x-content-type-options
- https://www.bowbottomvet.com/about-us/team/ → no x-content-type-options
- https://www.bowbottomvet.com/all-services/services/ → no x-content-type-options
- FoundReferrer policyLow
No HTML page sends referrer-policy. Without a Referrer-Policy the full page address, including any query string, is sent to every site a visitor clicks through to.
- https://www.bowbottomvet.com/ → no referrer-policy
- https://www.bowbottomvet.com/location-hours/ → no referrer-policy
- https://www.bowbottomvet.com/forms/ → no referrer-policy
- https://www.bowbottomvet.com/blog/ → no referrer-policy
- https://www.bowbottomvet.com/testimonials/ → no referrer-policy
- https://www.bowbottomvet.com/new-clients/ → no referrer-policy
- https://www.bowbottomvet.com/new-clients/what-to-expect/ → no referrer-policy
- https://www.bowbottomvet.com/new-clients/take-a-tour/ → no referrer-policy
- https://www.bowbottomvet.com/about-us/ → no referrer-policy
- https://www.bowbottomvet.com/about-us/welcome-to-our-clinic/ → no referrer-policy
- https://www.bowbottomvet.com/about-us/team/ → no referrer-policy
- https://www.bowbottomvet.com/all-services/services/ → no referrer-policy
- FoundPermissions policyInfo
No HTML page sends permissions-policy. A Permissions-Policy header turns off browser features the site does not use (camera, microphone, geolocation), limiting what an injected script could do.
- https://www.bowbottomvet.com/ → no permissions-policy
- https://www.bowbottomvet.com/location-hours/ → no permissions-policy
- https://www.bowbottomvet.com/forms/ → no permissions-policy
- https://www.bowbottomvet.com/blog/ → no permissions-policy
- https://www.bowbottomvet.com/testimonials/ → no permissions-policy
- https://www.bowbottomvet.com/new-clients/ → no permissions-policy
- https://www.bowbottomvet.com/new-clients/what-to-expect/ → no permissions-policy
- https://www.bowbottomvet.com/new-clients/take-a-tour/ → no permissions-policy
- https://www.bowbottomvet.com/about-us/ → no permissions-policy
- https://www.bowbottomvet.com/about-us/welcome-to-our-clinic/ → no permissions-policy
- https://www.bowbottomvet.com/about-us/team/ → no permissions-policy
- https://www.bowbottomvet.com/all-services/services/ → no permissions-policy
- FoundSoftware version disclosureLow
Responses reveal the exact server or framework version, which lets an attacker look up known vulnerabilities for it without guessing.
- server: Apache/2.4.53 (Ubuntu) (936 responses)
- x-powered-by: W3 Total Cache/2.7.0 (426 responses)
- x-powered-by: PHP/7.4.28 (317 responses)
- server: awselb/2.0 (98 responses)
- server: Caddy (1 response)
- FoundCookie flagsMedium
5 of 5 cookies are missing protective flags. Without HttpOnly a script can read the cookie; without Secure it travels over plain HTTP; without SameSite it is sent on cross-site requests.
- webdvm (set by https://www.bowbottomvet.com/) lacks Secure, HttpOnly, SameSite
- AWSALBAPP-0 (set by https://www.bowbottomvet.com/) lacks Secure, HttpOnly, SameSite
- AWSALBAPP-1 (set by https://www.bowbottomvet.com/) lacks Secure, HttpOnly, SameSite
- AWSALBAPP-2 (set by https://www.bowbottomvet.com/) lacks Secure, HttpOnly, SameSite
- AWSALBAPP-3 (set by https://www.bowbottomvet.com/) lacks Secure, HttpOnly, SameSite
- FoundVulnerable JavaScript librariesMedium
1 library with published vulnerabilities: jQuery 1.7.0. Whether they are exploitable depends on how the site uses them, but each has a fixed release.
- jQuery 1.7.0 in https://www.bowbottomvet.com/wp-content/themes/salient/js/build/third-party/hov…: CVE-2012-6708 (selector XSS), CVE-2015-9251, CVE-2019-11358, CVE-2020-11022, CVE-2020-11023; fixed in 3.5.0
- FoundKeys and secrets in page codeMedium
1 credential-like value found in code served to every visitor: Google API key.
- Google API key AIzaSy…hk (39 chars) in https://www.bowbottomvet.com/: browser keys are expected in pages, but must be restricted by HTTP referrer and API in the Google Cloud console
- NoteThird-party scripts
Scripts run from 2 other domains without Subresource Integrity, so a compromise of any of them changes what runs on this site. (Tag managers and analytics rarely support SRI; a Content-Security-Policy that names these hosts is the usual control.)
- www.googletagmanager.com (80 script tags)
- www.google.com (6 script tags)
5 checks passed, 1 not applicable
- OKHTTPS
All 399 crawled pages were served over HTTPS.
- OKContent Security Policy
A Content-Security-Policy is set on 397 of 399 pages.
- OKMixed content
No HTTPS page loads a script, stylesheet, font or image over plain HTTP.
- OKForms over HTTPS
52 forms found, all on HTTPS pages posting to HTTPS addresses.
- OKExposed files and listings
None of the crawled URLs is a configuration file, backup, dump, repository folder or directory listing.
- Not applicableSensitive paths in robots.txt
No robots.txt was fetched.
A passive review of what the crawl recorded: response headers, page and script contents and the URLs it found. It does not probe the site, test TLS settings or look for files that were not linked. Generated automatically; verify each finding against your own site before acting on it.
This report was produced by the DIY SEO Hub Site Spider crawling www.bowbottomvet.com from its public pages. Anyone can run a scan of any site they own or are authorised to check. Is this your site? Claim it to manage the listing, or ask for removal through the support form.