Scanned sites / www.kcphysiotherapy.com / 2026-09-17-1348

www.kcphysiotherapy.com scan from 9/17/2026, 1:48:11 PM

A newer scan exists. See the latest report for www.kcphysiotherapy.com.

Scan 2026-09-17-1348

Scanned 9/17/2026, 1:48:11 PM, finished 9/17/2026, 1:55:21 PM. Found with openstreetmap overpass

Site: https://www.kcphysiotherapy.com/

Download SQLite databaseEvery page and asset from this scan, with the crawl events, in one file.

71/ 100Needs work

On September 17, 2026 the Site Spider crawled 87 pages and 597 assets of www.kcphysiotherapy.com, starting from https://www.kcphysiotherapy.com/. It scored 71 out of 100, a result that needs work. 8 of 14 checks found something to fix, led by meta descriptions (87), headings (53), indexability (40); 6 checks passed. The list below shows each check's result, the fix plan, when present, explains what to do first, and the security review at the end of the page covers headers, transport, libraries and exposed files.

Security review: Medium3 medium, 3 low and 2 info findings. See the security findings ↓

Pages crawled
87
Assets fetched
597
Status
Completed
Checks with issues
8 of 14
  • Title tags21 issues
    21 of 87 pages have title issues.
  • Meta descriptions87 issues
    87 of 87 pages have meta description issues.
  • Headings53 issues
    53 of 87 pages have heading issues.
  • Broken linksOK
    0 internal links point at 0 broken URLs.
  • RedirectsOK
    1 redirecting URL, 0 of them chained.
  • Non-200 responsesOK
    1 URL did not return a 2xx response.
  • Rate limitedOK
    The site did not rate limit the crawler.
  • Indexability40 issues
    40 of 87 indexable pages have indexability warnings.
  • Image alt textOK
    0 of 619 image references have no alt attribute. 421 use an empty alt (decorative), which is fine.
  • Heavy assets30 issues
    31 assets larger than 500 KB among the 100 heaviest.
  • Orphan pages12 issues
    12 pages have no internal links pointing at them.
  • Sitemap coverage22 issues
    5 sitemaps listing 77 URLs: 10 crawled pages missing, 0 listed URLs broken or redirecting, 12 reachable only via the sitemap.
  • Thin content20 issues
    20 of 87 pages have fewer than 200 words.
  • Duplicate contentOK
    0 groups of pages with identical HTML.

Where this scan sits among all scanned sites

1086 sites, median 82%, average 80%

www.kcphysiotherapy.com scores 71%, higher than 15% of the 1086 scanned sites. See the full ranking.

028550%: 0 sites1%: 0 sites2%: 0 sites3%: 0 sites4%: 0 sites5%: 0 sites6%: 0 sites7%: 0 sites8%: 0 sites9%: 0 sites10%: 0 sites11%: 0 sites12%: 0 sites13%: 0 sites14%: 0 sites15%: 0 sites16%: 0 sites17%: 0 sites18%: 0 sites19%: 0 sites20%: 0 sites21%: 1 site22%: 0 sites23%: 0 sites24%: 0 sites25%: 0 sites26%: 0 sites27%: 0 sites28%: 1 site29%: 0 sites30%: 0 sites31%: 0 sites32%: 0 sites33%: 0 sites34%: 0 sites35%: 1 site36%: 1 site37%: 0 sites38%: 0 sites39%: 0 sites40%: 0 sites41%: 0 sites42%: 0 sites43%: 0 sites44%: 0 sites45%: 2 sites46%: 1 site47%: 0 sites48%: 0 sites49%: 0 sites50%: 3 sites51%: 4 sites52%: 1 site53%: 1 site54%: 2 sites55%: 1 site56%: 2 sites57%: 3 sites58%: 6 sites59%: 3 sites60%: 5 sites61%: 8 sites62%: 12 sites63%: 4 sites64%: 9 sites65%: 9 sites66%: 7 sites67%: 15 sites68%: 27 sites69%: 12 sites70%: 22 sites71%: 22 sites72%: 24 sites73%: 24 sites74%: 30 sites75%: 26 sites76%: 39 sites77%: 37 sites78%: 34 sites79%: 30 sites80%: 42 sites81%: 53 sites82%: 49 sites83%: 45 sites84%: 53 sites85%: 47 sites86%: 46 sites87%: 46 sites88%: 55 sites89%: 39 sites90%: 51 sites91%: 36 sites92%: 25 sites93%: 17 sites94%: 16 sites95%: 8 sites96%: 10 sites97%: 4 sites98%: 2 sites99%: 1 site100%: 12 sites71% here100%90%80%70%60%50%40%30%20%10%0%

Green 90% and up (Excellent), lime 75 to 89 (Good), amber 50 to 74 (Needs work), red below 50 (Poor).

Internal link map

Loading the link map...

Start page (centre)OKRedirectErrorOrphanLinked from most pagesOne inbound link or noneRings = clicks from the start page. Size = inbound links. Drag to pan, scroll to zoom, click a page to see only its links.

Fix plan

Written by gpt-4o-mini from the scan findings

Your website requires improvements, primarily in titles, meta descriptions, headings, indexability, and handling of redirects. Implementing these fixes can enhance your SEO performance significantly.

  1. 1

    Fix Title Tag Issues

    Why: 21 pages have long or duplicate titles, negatively impacting SEO.

    How: Shorten titles to under 60 characters and ensure uniqueness for each page.

    Checks: titles

  2. 2

    Add Meta Descriptions

    Why: All pages lack meta descriptions; this can improve click-through rates.

    How: Create unique descriptions under 160 characters summarizing each page's content.

    Checks: meta-descriptions

  3. 3

    Implement H1 Headings

    Why: 53 pages are missing H1 headings, which can weaken content relevance.

    How: Add a single, relevant H1 heading to each of the affected pages.

    Checks: headings

  4. 4

    Resolve Indexability Warnings

    Why: 40 pages have indexability warnings affecting their search visibility.

    How: Add canonical tags to pages missing them, guiding search engines on content relevance.

    Checks: indexability

  5. 5

    Fix Redirects

    Why: 1 redirecting URL can lead to user confusion and SEO issues.

    How: Update or remove the redirect on https://www.kcphysiotherapy.com/sitemap.xml.

    Checks: redirects

  6. 6

    Address Orphan Pages

    Why: 12 pages lack internal links, which hinders their discoverability.

    How: Create internal links to these pages, integrating them into the site structure.

    Checks: orphan-pages

Generated automatically; verify each change against your own site before relying on it.

Security review

Written by gpt-4o-mini from 16 checks over the crawl

Your website has several security headers missing, exposing it to various risks like man-in-the-middle attacks and clickjacking. Key protections like Content Security Policy (CSP) and HTTP Strict Transport Security (HSTS) are notably absent, which are essential for safeguarding user data and enhancing privacy.

  • 0 high
  • 3 medium
  • 3 low
  • 2 info
  1. 1

    Missing HTTP Strict Transport Security (HSTS)Medium

    Why it matters: Without HSTS, users can be intercepted on their first connection if they type the URL without 'https://'.

    Fix: Add the header 'Strict-Transport-Security' with a value of 'max-age=31536000; includeSubDomains; preload'.

    Evidence: HTTP Strict Transport Security

  2. 2

    Missing Content Security Policy (CSP)Medium

    Why it matters: Without CSP, malicious scripts can be executed or loaded from unauthorized sources.

    Fix: Implement a CSP header by adding 'Content-Security-Policy: default-src 'self';' or more restrictive directives appropriate for your site.

    Evidence: Content Security Policy

  3. 3

    Missing X-Frame-OptionsMedium

    Why it matters: Without this protection, your site could be framed by malicious sites, leading to clickjacking attacks.

    Fix: Add the header 'X-Frame-Options: DENY' or 'X-Frame-Options: SAMEORIGIN'.

    Evidence: Clickjacking protection

  4. 4

    Missing X-Content-Type-OptionsLow

    Why it matters: Absence of this header allows browsers to incorrectly interpret files, potentially executing malicious scripts.

    Fix: Add the header 'X-Content-Type-Options: nosniff'.

    Evidence: MIME sniffing protection

  5. 5

    Missing Referrer PolicyLow

    Why it matters: Not specifying a referrer policy risks leaking sensitive URLs to third-party sites.

    Fix: Add the header 'Referrer-Policy: no-referrer' or a similar privacy-focused setting.

    Evidence: Referrer policy

  6. 6

    Server Banner DisclosureLow

    Why it matters: Revealing server version details can make it easier for attackers to exploit known vulnerabilities.

    Fix: Configure your server to remove or mask the 'Server' header in responses.

    Evidence: Software version disclosure

  7. 7

    Missing Permissions PolicyInfo

    Why it matters: Without this policy, browser features like camera and microhpone could be exposed to unauthorized scripts.

    Fix: Implement the header 'Permissions-Policy: geolocation=(self), camera=(), microphone=()' to restrict access as necessary.

    Evidence: Permissions policy

  8. 8

    Sensitive Paths in robots.txtInfo

    Why it matters: Publicly listing paths like '/wp-admin/' can provide attackers with a map of sensitive areas.

    Fix: Consider removing sensitive paths from the robots.txt or implement proper access control.

    Evidence: Sensitive paths in robots.txt

What the checks found

  • FoundHTTP Strict Transport SecurityMedium

    No HTML page sends strict-transport-security. Without it a visitor who types the address without https:// can be intercepted on the first request.

    • https://www.kcphysiotherapy.com/ → no strict-transport-security
    • https://www.kcphysiotherapy.com/our-services/ → no strict-transport-security
    • https://www.kcphysiotherapy.com/free-webinars/ → no strict-transport-security
    • https://www.kcphysiotherapy.com/therapist-list/ → no strict-transport-security
    • https://www.kcphysiotherapy.com/category/physiotherapy/ → no strict-transport-security
    • https://www.kcphysiotherapy.com/category/massage-therapy/ → no strict-transport-security
    • https://www.kcphysiotherapy.com/category/athletictherapy/ → no strict-transport-security
    • https://www.kcphysiotherapy.com/join-our-team/ → no strict-transport-security
    • https://www.kcphysiotherapy.com/faq/ → no strict-transport-security
    • https://www.kcphysiotherapy.com/photo-gallery/ → no strict-transport-security
    • https://www.kcphysiotherapy.com/category/physiotherapy-blog/ → no strict-transport-security
    • https://www.kcphysiotherapy.com/auto-draft/ → no strict-transport-security
  • FoundContent Security PolicyMedium

    None of the 87 HTML pages send a Content-Security-Policy header or meta tag, so the browser has no restriction on where scripts, styles and frames may load from.

    • https://www.kcphysiotherapy.com/ → no content-security-policy
    • https://www.kcphysiotherapy.com/our-services/ → no content-security-policy
    • https://www.kcphysiotherapy.com/free-webinars/ → no content-security-policy
    • https://www.kcphysiotherapy.com/therapist-list/ → no content-security-policy
    • https://www.kcphysiotherapy.com/category/physiotherapy/ → no content-security-policy
    • https://www.kcphysiotherapy.com/category/massage-therapy/ → no content-security-policy
    • https://www.kcphysiotherapy.com/category/athletictherapy/ → no content-security-policy
    • https://www.kcphysiotherapy.com/join-our-team/ → no content-security-policy
    • https://www.kcphysiotherapy.com/faq/ → no content-security-policy
    • https://www.kcphysiotherapy.com/photo-gallery/ → no content-security-policy
    • https://www.kcphysiotherapy.com/category/physiotherapy-blog/ → no content-security-policy
    • https://www.kcphysiotherapy.com/auto-draft/ → no content-security-policy
  • FoundClickjacking protectionMedium

    No HTML page sends x-frame-options. Without X-Frame-Options (or a CSP frame-ancestors directive) the pages can be embedded in a frame on another site and overlaid with invisible controls.

    • https://www.kcphysiotherapy.com/ → no x-frame-options
    • https://www.kcphysiotherapy.com/our-services/ → no x-frame-options
    • https://www.kcphysiotherapy.com/free-webinars/ → no x-frame-options
    • https://www.kcphysiotherapy.com/therapist-list/ → no x-frame-options
    • https://www.kcphysiotherapy.com/category/physiotherapy/ → no x-frame-options
    • https://www.kcphysiotherapy.com/category/massage-therapy/ → no x-frame-options
    • https://www.kcphysiotherapy.com/category/athletictherapy/ → no x-frame-options
    • https://www.kcphysiotherapy.com/join-our-team/ → no x-frame-options
    • https://www.kcphysiotherapy.com/faq/ → no x-frame-options
    • https://www.kcphysiotherapy.com/photo-gallery/ → no x-frame-options
    • https://www.kcphysiotherapy.com/category/physiotherapy-blog/ → no x-frame-options
    • https://www.kcphysiotherapy.com/auto-draft/ → no x-frame-options
  • FoundMIME sniffing protectionLow

    No HTML page sends x-content-type-options. Without X-Content-Type-Options: nosniff a browser may run a file as a script because of its contents rather than its declared type.

    • https://www.kcphysiotherapy.com/ → no x-content-type-options
    • https://www.kcphysiotherapy.com/our-services/ → no x-content-type-options
    • https://www.kcphysiotherapy.com/free-webinars/ → no x-content-type-options
    • https://www.kcphysiotherapy.com/therapist-list/ → no x-content-type-options
    • https://www.kcphysiotherapy.com/category/physiotherapy/ → no x-content-type-options
    • https://www.kcphysiotherapy.com/category/massage-therapy/ → no x-content-type-options
    • https://www.kcphysiotherapy.com/category/athletictherapy/ → no x-content-type-options
    • https://www.kcphysiotherapy.com/join-our-team/ → no x-content-type-options
    • https://www.kcphysiotherapy.com/faq/ → no x-content-type-options
    • https://www.kcphysiotherapy.com/photo-gallery/ → no x-content-type-options
    • https://www.kcphysiotherapy.com/category/physiotherapy-blog/ → no x-content-type-options
    • https://www.kcphysiotherapy.com/auto-draft/ → no x-content-type-options
  • FoundReferrer policyLow

    No HTML page sends referrer-policy. Without a Referrer-Policy the full page address, including any query string, is sent to every site a visitor clicks through to.

    • https://www.kcphysiotherapy.com/ → no referrer-policy
    • https://www.kcphysiotherapy.com/our-services/ → no referrer-policy
    • https://www.kcphysiotherapy.com/free-webinars/ → no referrer-policy
    • https://www.kcphysiotherapy.com/therapist-list/ → no referrer-policy
    • https://www.kcphysiotherapy.com/category/physiotherapy/ → no referrer-policy
    • https://www.kcphysiotherapy.com/category/massage-therapy/ → no referrer-policy
    • https://www.kcphysiotherapy.com/category/athletictherapy/ → no referrer-policy
    • https://www.kcphysiotherapy.com/join-our-team/ → no referrer-policy
    • https://www.kcphysiotherapy.com/faq/ → no referrer-policy
    • https://www.kcphysiotherapy.com/photo-gallery/ → no referrer-policy
    • https://www.kcphysiotherapy.com/category/physiotherapy-blog/ → no referrer-policy
    • https://www.kcphysiotherapy.com/auto-draft/ → no referrer-policy
  • FoundPermissions policyInfo

    No HTML page sends permissions-policy. A Permissions-Policy header turns off browser features the site does not use (camera, microphone, geolocation), limiting what an injected script could do.

    • https://www.kcphysiotherapy.com/ → no permissions-policy
    • https://www.kcphysiotherapy.com/our-services/ → no permissions-policy
    • https://www.kcphysiotherapy.com/free-webinars/ → no permissions-policy
    • https://www.kcphysiotherapy.com/therapist-list/ → no permissions-policy
    • https://www.kcphysiotherapy.com/category/physiotherapy/ → no permissions-policy
    • https://www.kcphysiotherapy.com/category/massage-therapy/ → no permissions-policy
    • https://www.kcphysiotherapy.com/category/athletictherapy/ → no permissions-policy
    • https://www.kcphysiotherapy.com/join-our-team/ → no permissions-policy
    • https://www.kcphysiotherapy.com/faq/ → no permissions-policy
    • https://www.kcphysiotherapy.com/photo-gallery/ → no permissions-policy
    • https://www.kcphysiotherapy.com/category/physiotherapy-blog/ → no permissions-policy
    • https://www.kcphysiotherapy.com/auto-draft/ → no permissions-policy
  • FoundSoftware version disclosureLow

    Responses reveal the exact server or framework version, which lets an attacker look up known vulnerabilities for it without guessing.

    • server: Apache (583 responses)
    • server: nginx/1.29.8 (101 responses)
  • NoteSensitive paths in robots.txt

    robots.txt lists 1 path that look private. robots.txt is public and does not restrict access, so it doubles as a map for anyone probing the site; those paths need real access control.

    • Disallow: /wp-admin/
7 checks passed, 1 not applicable
  • OKHTTPS

    All 87 crawled pages were served over HTTPS.

  • OKMixed content

    No HTTPS page loads a script, stylesheet, font or image over plain HTTP.

  • OKForms over HTTPS

    61 forms found, all on HTTPS pages posting to HTTPS addresses.

  • OKVulnerable JavaScript libraries

    2 library versions recognised, none with known vulnerabilities.

  • OKKeys and secrets in page code

    No API keys, tokens or private keys were found in the sampled HTML and scripts.

  • OKExposed files and listings

    None of the crawled URLs is a configuration file, backup, dump, repository folder or directory listing.

  • OKThird-party scripts

    The sampled pages load no scripts from other domains.

  • Not applicableCookie flags

    The crawl set no cookies, so there are no cookie flags to check.

A passive review of what the crawl recorded: response headers, page and script contents and the URLs it found. It does not probe the site, test TLS settings or look for files that were not linked. Generated automatically; verify each finding against your own site before acting on it.

This report was produced by the DIY SEO Hub Site Spider crawling www.kcphysiotherapy.com from its public pages. Anyone can run a scan of any site they own or are authorised to check. Is this your site? Claim it to manage the listing, or ask for removal through the support form.

www.kcphysiotherapy.com scan 2026-09-17-1348 | DIY SEO Hub