Scanned sites / www.highpointplumbing.ca / 2026-09-25-1704

www.highpointplumbing.ca scan from 9/25/2026, 5:04:41 PM

Scan 2026-09-25-1704

Scanned 9/25/2026, 5:04:41 PM, finished 9/25/2026, 5:26:33 PM. Found with openstreetmap overpass

Site: https://www.highpointplumbing.ca/

Download SQLite databaseEvery page and asset from this scan, with the crawl events, in one file.

84/ 100Good

On September 25, 2026 the Site Spider crawled 190 pages and 1002 assets of www.highpointplumbing.ca, starting from https://www.highpointplumbing.ca/. It scored 84 out of 100, a good result. 8 of 14 checks found something to fix, led by sitemap coverage (177), title tags (126), meta descriptions (55); 6 checks passed. The list below shows each check's result, the fix plan, when present, explains what to do first, and the security review at the end of the page covers headers, transport, libraries and exposed files.

Security review: Medium5 medium, 3 low and 1 info findings. See the security findings ↓

Pages crawled
190
Assets fetched
1002
Status
Completed
Checks with issues
8 of 14
  • Title tags126 issues
    126 of 177 pages have title issues. 7 noindex or canonicalized pages excluded.
  • Meta descriptions55 issues
    55 of 177 pages have meta description issues. 7 noindex or canonicalized pages excluded.
  • HeadingsOK
    0 of 177 pages have heading issues. 7 noindex or canonicalized pages excluded.
  • Broken links4 issues
    7 internal links point at 4 broken URLs.
  • Redirects2 issues
    3 redirecting URLs, 0 of them chained.
  • Non-200 responses4 issues
    7 URLs did not return a 2xx response.
  • Rate limitedOK
    The site did not rate limit the crawler.
  • Indexability2 issues
    2 of 179 indexable pages have indexability warnings. 5 pages noindex by design.
  • Image alt textOK
    0 of 1538 image references have no alt attribute. 256 use an empty alt (decorative), which is fine.
  • Heavy assetsOK
    0 assets larger than 500 KB among the 100 heaviest.
  • Orphan pagesOK
    0 pages have no internal links pointing at them.
  • Sitemap coverage177 issues
    1 sitemap listing 0 URLs: 177 crawled pages missing, 0 listed URLs broken or redirecting, 0 reachable only via the sitemap.
  • Thin content1 issue
    1 of 177 pages have fewer than 200 words. 7 noindex or canonicalized pages excluded.
  • Duplicate contentOK
    0 groups of pages with identical HTML.

Where this scan sits among all scanned sites

1265 sites, median 82%, average 80%

www.highpointplumbing.ca scores 84%, higher than 57% of the 1265 scanned sites. See the full ranking.

033660%: 0 sites1%: 0 sites2%: 0 sites3%: 0 sites4%: 0 sites5%: 0 sites6%: 0 sites7%: 0 sites8%: 0 sites9%: 0 sites10%: 0 sites11%: 0 sites12%: 0 sites13%: 0 sites14%: 0 sites15%: 0 sites16%: 0 sites17%: 0 sites18%: 0 sites19%: 0 sites20%: 0 sites21%: 1 site22%: 0 sites23%: 0 sites24%: 0 sites25%: 0 sites26%: 0 sites27%: 0 sites28%: 1 site29%: 0 sites30%: 0 sites31%: 0 sites32%: 0 sites33%: 0 sites34%: 0 sites35%: 1 site36%: 1 site37%: 0 sites38%: 0 sites39%: 0 sites40%: 0 sites41%: 0 sites42%: 0 sites43%: 0 sites44%: 0 sites45%: 2 sites46%: 2 sites47%: 1 site48%: 1 site49%: 0 sites50%: 3 sites51%: 4 sites52%: 4 sites53%: 4 sites54%: 4 sites55%: 2 sites56%: 2 sites57%: 3 sites58%: 8 sites59%: 4 sites60%: 7 sites61%: 9 sites62%: 12 sites63%: 4 sites64%: 9 sites65%: 10 sites66%: 11 sites67%: 16 sites68%: 29 sites69%: 14 sites70%: 26 sites71%: 25 sites72%: 29 sites73%: 28 sites74%: 33 sites75%: 29 sites76%: 41 sites77%: 42 sites78%: 39 sites79%: 38 sites80%: 51 sites81%: 57 sites82%: 56 sites83%: 53 sites84%: 60 sites85%: 53 sites86%: 51 sites87%: 57 sites88%: 61 sites89%: 44 sites90%: 66 sites91%: 40 sites92%: 25 sites93%: 21 sites94%: 18 sites95%: 10 sites96%: 11 sites97%: 4 sites98%: 3 sites99%: 2 sites100%: 23 sites84% here100%90%80%70%60%50%40%30%20%10%0%

Green 90% and up (Excellent), lime 75 to 89 (Good), amber 50 to 74 (Needs work), red below 50 (Poor).

Internal link map

Loading the link map...

Start page (centre)OKRedirectErrorOrphanLinked from most pagesOne inbound link or noneRings = clicks from the start page. Size = inbound links. Drag to pan, scroll to zoom, click a page to see only its links.

Fix plan

Written by gpt-4o-mini from the scan findings

Your site has a good health score, but several issues need fixing for improved SEO. Prioritize resolving broken links and optimizing title tags and meta descriptions for better visibility.

  1. 1

    Fix Broken Links

    Why: Correcting these improves user experience and SEO.

    How: Update or remove broken links identified in the crawl.

    Checks: broken-links

  2. 2

    Update Title Tags

    Why: Optimizing titles improves search engine rankings.

    How: Shorten titles over 60 characters to under 60.

    Checks: titles

  3. 3

    Revise Meta Descriptions

    Why: Refined meta descriptions enhance click-through rates.

    How: Condense descriptions longer than 160 characters.

    Checks: meta-descriptions

  4. 4

    Address Non-200 Responses

    Why: Ensuring all pages respond correctly is crucial for SEO.

    How: Redirect 404 errors to relevant pages and keep 301s in check.

    Checks: status-codes

  5. 5

    Enhance Sitemap Coverage

    Why: Adding missing pages ensures they are indexed.

    How: Re-generate the sitemap to include all relevant URLs.

    Checks: sitemap-coverage

  6. 6

    Improve Thin Content

    Why: More content can increase engagement and rankings.

    How: Add additional relevant content to the thin page.

    Checks: thin-content

Generated automatically; verify each change against your own site before relying on it.

Security review

Written by gpt-4o-mini from 16 checks over the crawl

Your website has several security vulnerabilities that could expose visitors to attacks or data leaks. Key issues include missing HTTP headers that protect against various threats and outdated libraries. Prioritize adding these protections to safeguard your site and users.

  • 0 high
  • 5 medium
  • 3 low
  • 1 info
  1. 1

    Missing HTTP Strict Transport Security (HSTS)Medium

    Why it matters: Without HSTS, visitors can be intercepted on the first request if they enter the address without HTTPS.

    Fix: Add the header: `Strict-Transport-Security: max-age=31536000; includeSubDomains`.

    Evidence: HTTP Strict Transport Security

  2. 2

    Missing Content Security Policy (CSP)Medium

    Why it matters: Lack of CSP allows unrestricted loading of scripts and frames, increasing the risk of cross-site scripting and other attacks.

    Fix: Implement a CSP header like: `Content-Security-Policy: default-src 'self';`.

    Evidence: Content Security Policy

  3. 3

    Missing X-Frame-Options HeaderMedium

    Why it matters: Without this header, your pages can be embedded into iframes by other sites, leading to clickjacking vulnerabilities.

    Fix: Add the header: `X-Frame-Options: DENY`.

    Evidence: Clickjacking protection

  4. 4

    Cookie Flags MissingMedium

    Why it matters: Missing flags (HttpOnly, Secure, SameSite) can expose cookies to theft or misuse.

    Fix: Set flags for cookies as follows: `Set-Cookie: _fbp; HttpOnly; Secure; SameSite=Lax`.

    Evidence: Cookie flags

  5. 5

    Outdated jQuery LibraryMedium

    Why it matters: The use of jQuery 1.8.7 presents known vulnerabilities that could be exploited by attackers.

    Fix: Upgrade jQuery to at least version 3.5.0 to resolve vulnerabilities.

    Evidence: Vulnerable JavaScript libraries

  6. 6

    Missing X-Content-Type-Options HeaderLow

    Why it matters: This absence increases the risk of MIME type confusion, potentially leading to security exploitation.

    Fix: Add the header: `X-Content-Type-Options: nosniff`.

    Evidence: MIME sniffing protection

  7. 7

    Missing Referrer PolicyLow

    Why it matters: Not implementing a referrer policy can expose the full page URL to third parties when users navigate away.

    Fix: Add the header: `Referrer-Policy: no-referrer`.

    Evidence: Referrer policy

  8. 8

    Server Version DisclosureLow

    Why it matters: Revealing your server version can assist attackers in targeting vulnerabilities specific to that version.

    Fix: Remove or modify headers like `Server` and `X-Powered-By` to disguise version information.

    Evidence: Software version disclosure

  9. 9

    No Permissions-Policy HeaderInfo

    Why it matters: The absence of this header means browser features (e.g., camera, microphone) remain accessible, increasing risk from injected scripts.

    Fix: Consider adding: `Permissions-Policy: geolocation=(self), microphone=()`. Adjust according to your site's needs.

    Evidence: Permissions policy

What the checks found

  • FoundHTTP Strict Transport SecurityMedium

    No HTML page sends strict-transport-security. Without it a visitor who types the address without https:// can be intercepted on the first request.

    • https://www.highpointplumbing.ca/ → no strict-transport-security
    • https://www.highpointplumbing.ca/east-kootenay-bc-boiler-installation-and-replacement/ → no strict-transport-security
    • https://www.highpointplumbing.ca/east-kootenay-bc-boiler-maintenance/ → no strict-transport-security
    • https://www.highpointplumbing.ca/east-kootenay-bc-boiler-repair/ → no strict-transport-security
    • https://www.highpointplumbing.ca/furnace-installation-replacement-cranbrook-bc/ → no strict-transport-security
    • https://www.highpointplumbing.ca/east-kootenay-bc-furnace-maintenance/ → no strict-transport-security
    • https://www.highpointplumbing.ca/east-kootenay-bc-furnace-repair/ → no strict-transport-security
    • https://www.highpointplumbing.ca/east-kootenay-bc-geothermal-heating-air-conditioning-installation-repair/ → no strict-transport-security
    • https://www.highpointplumbing.ca/east-kootenay-bc-heat-pump-installation-replacement/ → no strict-transport-security
    • https://www.highpointplumbing.ca/east-kootenay-bc-heat-pump-maintenance/ → no strict-transport-security
    • https://www.highpointplumbing.ca/east-kootenay-bc-heat-pump-repair/ → no strict-transport-security
    • https://www.highpointplumbing.ca/west-kootenay-bc-boiler-installation-and-replacement/ → no strict-transport-security
  • FoundContent Security PolicyMedium

    None of the 184 HTML pages send a Content-Security-Policy header or meta tag, so the browser has no restriction on where scripts, styles and frames may load from.

    • https://www.highpointplumbing.ca/ → no content-security-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-boiler-installation-and-replacement/ → no content-security-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-boiler-maintenance/ → no content-security-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-boiler-repair/ → no content-security-policy
    • https://www.highpointplumbing.ca/furnace-installation-replacement-cranbrook-bc/ → no content-security-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-furnace-maintenance/ → no content-security-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-furnace-repair/ → no content-security-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-geothermal-heating-air-conditioning-installation-repair/ → no content-security-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-heat-pump-installation-replacement/ → no content-security-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-heat-pump-maintenance/ → no content-security-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-heat-pump-repair/ → no content-security-policy
    • https://www.highpointplumbing.ca/west-kootenay-bc-boiler-installation-and-replacement/ → no content-security-policy
  • FoundClickjacking protectionMedium

    No HTML page sends x-frame-options. Without X-Frame-Options (or a CSP frame-ancestors directive) the pages can be embedded in a frame on another site and overlaid with invisible controls.

    • https://www.highpointplumbing.ca/ → no x-frame-options
    • https://www.highpointplumbing.ca/east-kootenay-bc-boiler-installation-and-replacement/ → no x-frame-options
    • https://www.highpointplumbing.ca/east-kootenay-bc-boiler-maintenance/ → no x-frame-options
    • https://www.highpointplumbing.ca/east-kootenay-bc-boiler-repair/ → no x-frame-options
    • https://www.highpointplumbing.ca/furnace-installation-replacement-cranbrook-bc/ → no x-frame-options
    • https://www.highpointplumbing.ca/east-kootenay-bc-furnace-maintenance/ → no x-frame-options
    • https://www.highpointplumbing.ca/east-kootenay-bc-furnace-repair/ → no x-frame-options
    • https://www.highpointplumbing.ca/east-kootenay-bc-geothermal-heating-air-conditioning-installation-repair/ → no x-frame-options
    • https://www.highpointplumbing.ca/east-kootenay-bc-heat-pump-installation-replacement/ → no x-frame-options
    • https://www.highpointplumbing.ca/east-kootenay-bc-heat-pump-maintenance/ → no x-frame-options
    • https://www.highpointplumbing.ca/east-kootenay-bc-heat-pump-repair/ → no x-frame-options
    • https://www.highpointplumbing.ca/west-kootenay-bc-boiler-installation-and-replacement/ → no x-frame-options
  • FoundMIME sniffing protectionLow

    No HTML page sends x-content-type-options. Without X-Content-Type-Options: nosniff a browser may run a file as a script because of its contents rather than its declared type.

    • https://www.highpointplumbing.ca/ → no x-content-type-options
    • https://www.highpointplumbing.ca/east-kootenay-bc-boiler-installation-and-replacement/ → no x-content-type-options
    • https://www.highpointplumbing.ca/east-kootenay-bc-boiler-maintenance/ → no x-content-type-options
    • https://www.highpointplumbing.ca/east-kootenay-bc-boiler-repair/ → no x-content-type-options
    • https://www.highpointplumbing.ca/furnace-installation-replacement-cranbrook-bc/ → no x-content-type-options
    • https://www.highpointplumbing.ca/east-kootenay-bc-furnace-maintenance/ → no x-content-type-options
    • https://www.highpointplumbing.ca/east-kootenay-bc-furnace-repair/ → no x-content-type-options
    • https://www.highpointplumbing.ca/east-kootenay-bc-geothermal-heating-air-conditioning-installation-repair/ → no x-content-type-options
    • https://www.highpointplumbing.ca/east-kootenay-bc-heat-pump-installation-replacement/ → no x-content-type-options
    • https://www.highpointplumbing.ca/east-kootenay-bc-heat-pump-maintenance/ → no x-content-type-options
    • https://www.highpointplumbing.ca/east-kootenay-bc-heat-pump-repair/ → no x-content-type-options
    • https://www.highpointplumbing.ca/west-kootenay-bc-boiler-installation-and-replacement/ → no x-content-type-options
  • FoundReferrer policyLow

    No HTML page sends referrer-policy. Without a Referrer-Policy the full page address, including any query string, is sent to every site a visitor clicks through to.

    • https://www.highpointplumbing.ca/ → no referrer-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-boiler-installation-and-replacement/ → no referrer-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-boiler-maintenance/ → no referrer-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-boiler-repair/ → no referrer-policy
    • https://www.highpointplumbing.ca/furnace-installation-replacement-cranbrook-bc/ → no referrer-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-furnace-maintenance/ → no referrer-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-furnace-repair/ → no referrer-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-geothermal-heating-air-conditioning-installation-repair/ → no referrer-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-heat-pump-installation-replacement/ → no referrer-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-heat-pump-maintenance/ → no referrer-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-heat-pump-repair/ → no referrer-policy
    • https://www.highpointplumbing.ca/west-kootenay-bc-boiler-installation-and-replacement/ → no referrer-policy
  • FoundPermissions policyInfo

    No HTML page sends permissions-policy. A Permissions-Policy header turns off browser features the site does not use (camera, microphone, geolocation), limiting what an injected script could do.

    • https://www.highpointplumbing.ca/ → no permissions-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-boiler-installation-and-replacement/ → no permissions-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-boiler-maintenance/ → no permissions-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-boiler-repair/ → no permissions-policy
    • https://www.highpointplumbing.ca/furnace-installation-replacement-cranbrook-bc/ → no permissions-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-furnace-maintenance/ → no permissions-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-furnace-repair/ → no permissions-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-geothermal-heating-air-conditioning-installation-repair/ → no permissions-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-heat-pump-installation-replacement/ → no permissions-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-heat-pump-maintenance/ → no permissions-policy
    • https://www.highpointplumbing.ca/east-kootenay-bc-heat-pump-repair/ → no permissions-policy
    • https://www.highpointplumbing.ca/west-kootenay-bc-boiler-installation-and-replacement/ → no permissions-policy
  • FoundSoftware version disclosureLow

    Responses reveal the exact server or framework version, which lets an attacker look up known vulnerabilities for it without guessing.

    • server: Apache (1192 responses)
    • x-powered-by: PHP/8.1.34 (193 responses)
  • FoundCookie flagsMedium

    1 of 1 cookie are missing protective flags. Without HttpOnly a script can read the cookie; without Secure it travels over plain HTTP; without SameSite it is sent on cross-site requests.

    • _fbp (set by https://www.highpointplumbing.ca/robots.txt) lacks HttpOnly
  • FoundVulnerable JavaScript librariesMedium

    1 library with published vulnerabilities: jQuery 1.8.7. Whether they are exploitable depends on how the site uses them, but each has a fixed release.

    • jQuery 1.8.7 in https://www.highpointplumbing.ca/wp-content/plugins/jet-search/assets/lib/chose…: CVE-2012-6708 (selector XSS), CVE-2015-9251, CVE-2019-11358, CVE-2020-11022, CVE-2020-11023; fixed in 3.5.0
  • NoteThird-party scripts

    Scripts run from 1 other domain without Subresource Integrity, so a compromise of any of them changes what runs on this site. (Tag managers and analytics rarely support SRI; a Content-Security-Policy that names these hosts is the usual control.)

    • link.msgsndr.com (80 script tags)
  • NoteSensitive paths in robots.txt

    robots.txt lists 1 path that look private. robots.txt is public and does not restrict access, so it doubles as a map for anyone probing the site; those paths need real access control.

    • Disallow: /wp-admin/
4 checks passed, 1 not applicable
  • OKHTTPS

    All 184 crawled pages were served over HTTPS.

  • OKMixed content

    No HTTPS page loads a script, stylesheet, font or image over plain HTTP.

  • OKKeys and secrets in page code

    No API keys, tokens or private keys were found in the sampled HTML and scripts.

  • OKExposed files and listings

    None of the crawled URLs is a configuration file, backup, dump, repository folder or directory listing.

  • Not applicableForms over HTTPS

    No forms were found on the sampled pages.

A passive review of what the crawl recorded: response headers, page and script contents and the URLs it found. It does not probe the site, test TLS settings or look for files that were not linked. Generated automatically; verify each finding against your own site before acting on it.

Sites scoring near www.highpointplumbing.ca

Their neighbours in the SEO rank table, which orders every scanned site by health score.

This report was produced by the DIY SEO Hub Site Spider crawling www.highpointplumbing.ca from its pages as published, the way a search engine does. It shows summary figures only.

Own www.highpointplumbing.ca?

  • Claim this site to manage the listing, hide it from the public lists, or keep it.
  • Want it gone instead? Ask through the support form or e-mail support@diyseohub.com, naming www.highpointplumbing.ca. Removal needs no account and no proof of purchase.
www.highpointplumbing.ca scan 2026-09-25-1704 | DIY SEO Hub