Scanned sites / www.sistani.org
SEO report for www.sistani.org
The latest Site Spider scan of www.sistani.org, with 1 scan on record. Each scan is at its own address, for example /domain/www-sistani-org/2026-10-02-2256.
Latest scan
Scanned 10/2/2026, 10:56:24 PM, finished 10/3/2026, 8:18:29 AM
Site: https://www.sistani.org/arabic/
Download SQLite databaseEvery page and asset from this scan, with the crawl events, in one file.
On October 2, 2026 the Site Spider crawled 4997 pages and 928 assets of www.sistani.org, starting from https://www.sistani.org/arabic/. It scored 57 out of 100, a result that needs work. 13 of 16 checks found something to fix, led by title tags (3,690), indexability (3,690), heavy assets (22); 2 checks passed. Most of the points went to title tags (−10), indexability (−10), heavy assets (−6). 1 check found something the score does not count, listed as noted. The list below shows each check's result, the fix plan, when present, explains what to do first, and the security review at the end of the page covers headers, transport, libraries and exposed files.
Security review: High1 high, 3 medium, 4 low and 1 info findings. See the security findings ↓
- Pages crawled
- 4997
- Assets fetched
- 928
- Status
- Completed
- Checks with issues
- 13 of 16
5,925 of 5,930 discovered URLs were fetched, 4 failed, 16,216 left out by the 5,000-page and 1,000-asset budget. The job finished, but the crawl did not reach everything it found. HTML only: nothing here ran JavaScript. 41 link destinations on other sites were checked.
- Title tags3,690 issues3690 of 3690 pages have title issues.−10 points
- Meta descriptions2,567 issues2567 of 3690 pages have meta description issues.−5.6 points
- Headings3,638 issues3638 of 3690 pages have heading issues.−5.9 points
- Broken links7 issues2256 internal links point at 7 broken URLs.
- Links to other sites2 issues2 destinations answered with an error, 6 could not be determined (timeouts, rate limits or refusals), of 41 destinations checked.
- Redirects1,304 issues1309 redirecting URLs, 4 of them chained.−1.4 points
- Non-200 responses6 issues1345 URLs did not return a 2xx response. 1310 of them are pages, 6 with an error status; the rest are assets or redirects.
- Rate limitedOKThe site did not rate limit the crawler.
- Indexability3,690 issues3690 of 3690 indexable pages have indexability warnings.−10 points
- Image alt textOK0 of 816 image references have no alt attribute. 207 use an empty alt (decorative), which is fine.
- Heavy assets22 issues22 assets larger than 500 KB among 928 fetched assets. 46 documents over that size are listed but not counted: downloads are not page weight.−6 points
- Orphan pages3 issues3 pages have no internal links pointing at them.
- Sitemap coverage1,845 issuesNo sitemap found. Tried: https://www.sistani.org/sitemap.xml (404). Add one at /sitemap.xml or list it in robots.txt.−3 points
- Internal link countsOKInternal link counts for 500 pages.
- Thin content452 issues452 of 3690 pages have fewer than 200 words.−1 points
- Duplicate content6 issues3 groups of pages with identical HTML.
Where this site sits among all scanned sites
1953 sites, median 80%, average 79%
www.sistani.org scores 57%, higher than 4% of the 1953 scanned sites. See the full ranking.
Green 90% and up (Excellent), lime 75 to 89 (Good), amber 50 to 74 (Needs work), red below 50 (Poor).
Internal link map
Loading the link map...
Fix plan
Written by gpt-4o-mini from the scan findingsThe site needs several critical fixes to improve its SEO health. Focus on resolving broken links and optimizing titles and meta descriptions for better indexability.
- 1
Fix Broken Links
Why: 2256 internal links point to 7 broken URLs, which negatively affect user experience and SEO ranking.
How: Identify broken links using your CMS or a tool, updating or removing links as needed.
Checks: broken-links
- 2
Optimize Title Tags
Why: 3690 pages have title issues, affecting search visibility and user engagement.
How: Craft unique, descriptive titles under 60 characters for each page, using relevant keywords.
Checks: titles
- 3
Write Meta Descriptions
Why: 2567 pages lack effective meta descriptions, hindering click-through rates from search results.
How: Create concise, relevant meta descriptions under 160 characters for affected pages.
Checks: meta-descriptions
- 4
Resolve Non-200 Responses
Why: 1345 URLs did not return a 2xx response, leading to poor user experience and crawl issues.
How: Check and fix URLs returning errors by redirecting or updating links.
Checks: status-codes
- 5
Implement Sitemap
Why: No sitemap found, affecting crawl efficiency and indexability of your site.
How: Create a sitemap.xml file and upload it to the root of your domain, referencing it in robots.txt.
Checks: sitemap-coverage
- 6
Fix Headings Structure
Why: 3638 pages have heading issues, which complicates content understanding for search engines.
How: Ensure each page has one H1; remove excess or add missing H1s where applicable.
Checks: headings
Generated automatically; verify each change against your own site before relying on it.
Security review
Written by gpt-4o-mini from 16 checks over the crawlThe website has several security vulnerabilities, primarily related to missing security headers and a mix of HTTP and HTTPS content. Immediate improvements include enforcing HTTPS, implementing security headers, and updating vulnerable libraries to protect against potential attacks.
- 1 high
- 3 medium
- 4 low
- 1 info
- 1
HTTP Response without HTTPSHigh
Why it matters: One page is served over plain HTTP, exposing it to potential eavesdropping or tampering.
Fix: Configure the server to redirect all HTTP requests to HTTPS.
Evidence: HTTPS
- 2
Missing Content Security PolicyMedium
Why it matters: Lack of CSP allows external scripts and resources, increasing XSS vulnerability.
Fix: Add a Content-Security-Policy header, e.g., "Content-Security-Policy: default-src 'self';"
Evidence: Content Security Policy
- 3
Missing X-Frame-Options HeaderMedium
Why it matters: Without this header, the site can be embedded in frames, leading to clickjacking.
Fix: Add an X-Frame-Options header with value "DENY" or "SAMEORIGIN".
Evidence: Clickjacking protection
- 4
Vulnerable JavaScript LibraryMedium
Why it matters: Using jQuery 1.9.1 exposes the site to known security vulnerabilities.
Fix: Upgrade jQuery to version 3.5.0 or later.
Evidence: Vulnerable JavaScript libraries
- 5
Missing X-Content-Type-Options HeaderLow
Why it matters: No MIME sniffing protection increases risk of executing non-script files as scripts.
Fix: Add an X-Content-Type-Options header with value "nosniff".
Evidence: MIME sniffing protection
- 6
Missing Referrer-Policy HeaderLow
Why it matters: Absence of a referrer policy may leak sensitive referrer information.
Fix: Add a Referrer-Policy header with value "no-referrer".
Evidence: Referrer policy
- 7
Server Version DisclosureLow
Why it matters: Revealing server and framework versions could assist attackers in exploiting known vulnerabilities.
Fix: Remove or modify the Server and X-Powered-By headers via server configuration.
Evidence: Software version disclosure
- 8
Mixed ContentLow
Why it matters: Loading resources over HTTP on HTTPS pages can undermine HTTPS security.
Fix: Update resource URLs to HTTPS or host them securely.
Evidence: Mixed content
- 9
Missing Permissions-Policy HeaderInfo
Why it matters: Not restricting browser features may allow unwanted capabilities for malicious scripts.
Fix: Add a Permissions-Policy header to specify allowed features, e.g., "Permissions-Policy: geolocation=(), microphone=()".
Evidence: Permissions policy
What the checks found
- FoundHTTPSHigh
1 page answered 200 over plain HTTP with no redirect to HTTPS, while 3689 were served over HTTPS. Anyone on the network path can read or alter these pages.
- http://www.sistani.org/ → 200 over http
- FoundContent Security PolicyMedium
None of the 3690 HTML pages send a Content-Security-Policy header or meta tag, so the browser has no restriction on where scripts, styles and frames may load from.
- https://www.sistani.org/arabic/ → no content-security-policy
- https://www.sistani.org/arabic/rss/ → no content-security-policy
- https://www.sistani.org/persian/ → no content-security-policy
- https://www.sistani.org/urdu/ → no content-security-policy
- https://www.sistani.org/english/ → no content-security-policy
- https://www.sistani.org/azari/ → no content-security-policy
- https://www.sistani.org/turkish/ → no content-security-policy
- https://www.sistani.org/french/ → no content-security-policy
- https://www.sistani.org/arabic/data/1/ → no content-security-policy
- https://www.sistani.org/arabic/book/ → no content-security-policy
- https://www.sistani.org/arabic/book/fatwa/ → no content-security-policy
- https://www.sistani.org/arabic/qa/ → no content-security-policy
- FoundClickjacking protectionMedium
No HTML page sends x-frame-options. Without X-Frame-Options (or a CSP frame-ancestors directive) the pages can be embedded in a frame on another site and overlaid with invisible controls.
- https://www.sistani.org/arabic/ → no x-frame-options
- https://www.sistani.org/arabic/rss/ → no x-frame-options
- https://www.sistani.org/persian/ → no x-frame-options
- https://www.sistani.org/urdu/ → no x-frame-options
- https://www.sistani.org/english/ → no x-frame-options
- https://www.sistani.org/azari/ → no x-frame-options
- https://www.sistani.org/turkish/ → no x-frame-options
- https://www.sistani.org/french/ → no x-frame-options
- https://www.sistani.org/arabic/data/1/ → no x-frame-options
- https://www.sistani.org/arabic/book/ → no x-frame-options
- https://www.sistani.org/arabic/book/fatwa/ → no x-frame-options
- https://www.sistani.org/arabic/qa/ → no x-frame-options
- FoundMIME sniffing protectionLow
No HTML page sends x-content-type-options. Without X-Content-Type-Options: nosniff a browser may run a file as a script because of its contents rather than its declared type.
- https://www.sistani.org/arabic/ → no x-content-type-options
- https://www.sistani.org/arabic/rss/ → no x-content-type-options
- https://www.sistani.org/persian/ → no x-content-type-options
- https://www.sistani.org/urdu/ → no x-content-type-options
- https://www.sistani.org/english/ → no x-content-type-options
- https://www.sistani.org/azari/ → no x-content-type-options
- https://www.sistani.org/turkish/ → no x-content-type-options
- https://www.sistani.org/french/ → no x-content-type-options
- https://www.sistani.org/arabic/data/1/ → no x-content-type-options
- https://www.sistani.org/arabic/book/ → no x-content-type-options
- https://www.sistani.org/arabic/book/fatwa/ → no x-content-type-options
- https://www.sistani.org/arabic/qa/ → no x-content-type-options
- FoundReferrer policyLow
No HTML page sends referrer-policy. Without a Referrer-Policy the full page address, including any query string, is sent to every site a visitor clicks through to.
- https://www.sistani.org/arabic/ → no referrer-policy
- https://www.sistani.org/arabic/rss/ → no referrer-policy
- https://www.sistani.org/persian/ → no referrer-policy
- https://www.sistani.org/urdu/ → no referrer-policy
- https://www.sistani.org/english/ → no referrer-policy
- https://www.sistani.org/azari/ → no referrer-policy
- https://www.sistani.org/turkish/ → no referrer-policy
- https://www.sistani.org/french/ → no referrer-policy
- https://www.sistani.org/arabic/data/1/ → no referrer-policy
- https://www.sistani.org/arabic/book/ → no referrer-policy
- https://www.sistani.org/arabic/book/fatwa/ → no referrer-policy
- https://www.sistani.org/arabic/qa/ → no referrer-policy
- FoundPermissions policyInfo
No HTML page sends permissions-policy. A Permissions-Policy header turns off browser features the site does not use (camera, microphone, geolocation), limiting what an injected script could do.
- https://www.sistani.org/arabic/ → no permissions-policy
- https://www.sistani.org/arabic/rss/ → no permissions-policy
- https://www.sistani.org/persian/ → no permissions-policy
- https://www.sistani.org/urdu/ → no permissions-policy
- https://www.sistani.org/english/ → no permissions-policy
- https://www.sistani.org/azari/ → no permissions-policy
- https://www.sistani.org/turkish/ → no permissions-policy
- https://www.sistani.org/french/ → no permissions-policy
- https://www.sistani.org/arabic/data/1/ → no permissions-policy
- https://www.sistani.org/arabic/book/ → no permissions-policy
- https://www.sistani.org/arabic/book/fatwa/ → no permissions-policy
- https://www.sistani.org/arabic/qa/ → no permissions-policy
- FoundSoftware version disclosureLow
Responses reveal the exact server or framework version, which lets an attacker look up known vulnerabilities for it without guessing.
- server: nginx (5925 responses)
- x-powered-by: PHP/7.4.33 (4952 responses)
- FoundMixed contentLow
1996 resources on HTTPS pages are loaded over plain HTTP.
- https://www.sistani.org/arabic/data/1/ loads image http://www.sistani.com/images/display/archives/ejaze-3.jpg
- https://www.sistani.org/arabic/data/1/ loads image http://www.sistani.com/images/display/archives/ejaze-2.jpg
- https://www.sistani.org/arabic/data/1/ loads image http://www.sistani.com/images/display/archives/ejaze-1.jpg
- https://www.sistani.org/arabic/data/1/ loads image http://www.sistani.com/images/display/archives/ejaze-4.jpg
- https://www.sistani.org/arabic/archive/26930/ loads image http://www.sistani.com/images/ahelleh1447/31.png
- https://www.sistani.org/arabic/archive/26930/ loads image http://www.sistani.com/images/ahelleh1447/30.png
- https://www.sistani.org/arabic/archive/26930/ loads image http://www.sistani.com/images/ahelleh1447/29.png
- https://www.sistani.org/arabic/archive/26930/ loads image http://www.sistani.com/images/ahelleh1447/28_.png
- https://www.sistani.org/arabic/archive/26930/ loads image http://www.sistani.com/images/ahelleh1447/27.png
- https://www.sistani.org/arabic/archive/26930/ loads image http://www.sistani.com/images/ahelleh1447/26.png
- https://www.sistani.org/arabic/archive/26930/ loads image http://www.sistani.com/images/ahelleh1447/25.png
- https://www.sistani.org/arabic/archive/26930/ loads image http://www.sistani.com/images/ahelleh1447/24.png
- FoundVulnerable JavaScript librariesMedium
1 library with published vulnerabilities: jQuery 1.9.1. Whether they are exploitable depends on how the site uses them, but each has a fixed release.
- jQuery 1.9.1 in https://cdnjs.cloudflare.com/ajax/libs/jquery/1.9.1/jquery.min.js: CVE-2015-9251 (XSS via cross-domain AJAX), CVE-2019-11358 (prototype pollution), CVE-2020-11022, CVE-2020-11023 (XSS via HTML passed to DOM methods); fixed in 3.5.0
- NoteThird-party scripts
Scripts run from 1 other domain without Subresource Integrity, so a compromise of any of them changes what runs on this site. (Tag managers and analytics rarely support SRI; a Content-Security-Policy that names these hosts is the usual control.)
- cdnjs.cloudflare.com (39 script tags)
5 checks passed, 1 not applicable
- OKHTTP Strict Transport Security
strict-transport-security is set on all 3689 HTML pages.
- OKForms over HTTPS
39 forms found, all on HTTPS pages posting to HTTPS addresses.
- OKKeys and secrets in page code
No API keys, tokens or private keys were found in the sampled HTML and scripts.
- OKExposed files and listings
None of the crawled URLs is a configuration file, backup, dump, repository folder or directory listing.
- OKSensitive paths in robots.txt
robots.txt does not point at admin, backup or private paths.
- Not applicableCookie flags
The crawl set no cookies, so there are no cookie flags to check.
A passive review of what the crawl recorded: response headers, page and script contents and the URLs it found. It does not probe the site, test TLS settings or look for files that were not linked. Generated automatically; verify each finding against your own site before acting on it.
Earlier scans of www.sistani.org
No other scans of this site yet.
Sites scoring near www.sistani.org
Their neighbours in the SEO rank table, which orders every scanned site by health score.
- example.com58/100 · rank 1857 · 1 page
- example.org58/100 · rank 1857 · 1 page
- www.studio1rpdance.com57/100 · rank 1872 · 329 pages
- www.echodance.com57/100 · rank 1872 · 47 pages
- www.northwestanimal.com57/100 · rank 1872 · 61 pages
- www.hardyautomotive.com57/100 · rank 1872 · 2,227 pages
This report was produced by the DIY SEO Hub Site Spider crawling www.sistani.org from its pages as published, the way a search engine does. It shows summary figures only.
Own www.sistani.org?
- Claim this site to manage the listing, hide it from the public lists, or keep it.
- Want it gone instead? Ask through the support form or e-mail support@diyseohub.com, naming www.sistani.org. Removal needs no account and no proof of purchase.