Scanned sites / www.square1coffee.ca / 2026-09-26-0513

www.square1coffee.ca scan from 9/26/2026, 5:13:09 AM

Scan 2026-09-26-0513

Scanned 9/26/2026, 5:13:09 AM, finished 9/26/2026, 5:29:04 AM. Found with openstreetmap overpass

Site: https://www.square1coffee.ca/

Download SQLite databaseEvery page and asset from this scan, with the crawl events, in one file.

45/ 100Poor

On September 26, 2026 the Site Spider crawled 22 pages and 255 assets of www.square1coffee.ca, starting from https://www.square1coffee.ca/. It scored 45 out of 100, a poor result. 10 of 14 checks found something to fix, led by sitemap coverage (17), non-200 responses (12), meta descriptions (10); 4 checks passed. The list below shows each check's result, the fix plan, when present, explains what to do first, and the security review at the end of the page covers headers, transport, libraries and exposed files.

Security review: Medium3 medium, 4 low and 2 info findings. See the security findings ↓

Pages crawled
22
Assets fetched
255
Status
Completed
Checks with issues
10 of 14
  • Title tags7 issues
    7 of 10 pages have title issues.
  • Meta descriptions10 issues
    10 of 10 pages have meta description issues.
  • Headings6 issues
    6 of 10 pages have heading issues.
  • Broken links2 issues
    4 internal links point at 2 broken URLs.
  • RedirectsOK
    1 redirecting URL, 0 of them chained.
  • Non-200 responses12 issues
    15 URLs did not return a 2xx response.
  • Rate limitedOK
    The site did not rate limit the crawler.
  • Indexability3 issues
    3 of 10 indexable pages have indexability warnings.
  • Image alt textOK
    0 of 38 image references have no alt attribute. 28 use an empty alt (decorative), which is fine.
  • Heavy assets7 issues
    7 assets larger than 500 KB among the 100 heaviest.
  • Orphan pages5 issues
    5 pages have no internal links pointing at them.
  • Sitemap coverage17 issues
    6 sitemaps listing 22 URLs: 0 crawled pages missing, 12 listed URLs broken or redirecting, 5 reachable only via the sitemap.
  • Thin content9 issues
    9 of 10 pages have fewer than 200 words.
  • Duplicate contentOK
    0 groups of pages with identical HTML.

Where this scan sits among all scanned sites

1270 sites, median 82%, average 80%

www.square1coffee.ca scores 45%, higher than 0% of the 1270 scanned sites. See the full ranking.

034670%: 0 sites1%: 0 sites2%: 0 sites3%: 0 sites4%: 0 sites5%: 0 sites6%: 0 sites7%: 0 sites8%: 0 sites9%: 0 sites10%: 0 sites11%: 0 sites12%: 0 sites13%: 0 sites14%: 0 sites15%: 0 sites16%: 0 sites17%: 0 sites18%: 0 sites19%: 0 sites20%: 0 sites21%: 1 site22%: 0 sites23%: 0 sites24%: 0 sites25%: 0 sites26%: 0 sites27%: 0 sites28%: 1 site29%: 0 sites30%: 0 sites31%: 0 sites32%: 0 sites33%: 0 sites34%: 0 sites35%: 1 site36%: 1 site37%: 0 sites38%: 0 sites39%: 0 sites40%: 0 sites41%: 0 sites42%: 0 sites43%: 0 sites44%: 0 sites45%: 3 sites46%: 2 sites47%: 1 site48%: 1 site49%: 0 sites50%: 3 sites51%: 4 sites52%: 4 sites53%: 4 sites54%: 4 sites55%: 2 sites56%: 2 sites57%: 3 sites58%: 8 sites59%: 4 sites60%: 7 sites61%: 9 sites62%: 12 sites63%: 4 sites64%: 9 sites65%: 10 sites66%: 10 sites67%: 16 sites68%: 29 sites69%: 14 sites70%: 26 sites71%: 25 sites72%: 29 sites73%: 28 sites74%: 33 sites75%: 30 sites76%: 41 sites77%: 42 sites78%: 39 sites79%: 37 sites80%: 51 sites81%: 57 sites82%: 58 sites83%: 53 sites84%: 60 sites85%: 54 sites86%: 50 sites87%: 54 sites88%: 60 sites89%: 47 sites90%: 67 sites91%: 42 sites92%: 26 sites93%: 20 sites94%: 18 sites95%: 11 sites96%: 11 sites97%: 4 sites98%: 3 sites99%: 2 sites100%: 23 sites45% here100%90%80%70%60%50%40%30%20%10%0%

Green 90% and up (Excellent), lime 75 to 89 (Good), amber 50 to 74 (Needs work), red below 50 (Poor).

Internal link map

Loading the link map...

Start page (centre)OKRedirectErrorOrphanLinked from most pagesOne inbound link or noneRings = clicks from the start page. Size = inbound links. Drag to pan, scroll to zoom, click a page to see only its links.

Fix plan

Written by gpt-4o-mini from the scan findings

Your website has significant SEO issues, particularly with broken links, title tags, and meta descriptions. Prioritizing these fixes can improve your site's performance.

  1. 1

    Fix Broken Links

    Why: To prevent user frustration and improve page ranking.

    How: Update or remove 4 internal links that lead to broken URLs.

    Checks: broken-links

  2. 2

    Update Title Tags

    Why: To enhance click-through rates and SEO visibility.

    How: Revise 7 title tags to be more descriptive and above 30 characters.

    Checks: titles

  3. 3

    Add Meta Descriptions

    Why: To improve user engagement and search engine optimization.

    How: Create and apply unique meta descriptions for all 10 pages.

    Checks: meta-descriptions

  4. 4

    Resolve Non-200 Responses

    Why: To ensure all pages load correctly, enhancing user experience.

    How: Investigate and rectify all 15 URLs that do not return a 2xx response.

    Checks: status-codes

  5. 5

    Fix Missing Headings

    Why: To improve accessibility and on-page SEO.

    How: Add H1 tags to the 6 pages that lack them.

    Checks: headings

  6. 6

    Link Orphan Pages

    Why: To improve internal site navigation and indexing.

    How: Create internal links to the 5 orphan pages from relevant pages.

    Checks: orphan-pages

Generated automatically; verify each change against your own site before relying on it.

Security review

Written by gpt-4o-mini from 16 checks over the crawl

The website has several security shortcomings, notably the absence of HTTP Strict Transport Security and Content Security Policy headers, which expose users to risks like interception and script injection. Implementing recommended headers will mitigate these risks effectively.

  • 0 high
  • 3 medium
  • 4 low
  • 2 info
  1. 1

    Missing HSTS HeaderMedium

    Why it matters: Without an HSTS header, visitors are vulnerable to interception on first requests without HTTPS.

    Fix: Add the header 'Strict-Transport-Security: max-age=31536000; includeSubDomains'.

    Evidence: HTTP Strict Transport Security

  2. 2

    Missing Content Security PolicyMedium

    Why it matters: Lack of a CSP allows unrestricted loading of resources, increasing the risk of XSS attacks.

    Fix: Implement a Content Security Policy header, e.g., 'Content-Security-Policy: default-src 'self';'.

    Evidence: Content Security Policy

  3. 3

    Missing X-Frame-Options HeaderMedium

    Why it matters: This increases vulnerability to clickjacking attacks, as pages can be embedded by malicious sites.

    Fix: Add 'X-Frame-Options: DENY' to the server response.

    Evidence: Clickjacking protection

  4. 4

    Missing X-Content-Type-Options HeaderLow

    Why it matters: Without this protection, browsers may incorrectly interpret files and execute them as scripts.

    Fix: Add 'X-Content-Type-Options: nosniff'.

    Evidence: MIME sniffing protection

  5. 5

    Missing Referrer-PolicyLow

    Why it matters: This could expose sensitive referrer information when users navigate away from the site.

    Fix: Include 'Referrer-Policy: no-referrer' in your headers.

    Evidence: Referrer policy

  6. 6

    Disclosed Server FrameworkLow

    Why it matters: The presence of the X-Powered-By header reveals the use of WP Engine, which may expose the site to targeted attacks.

    Fix: Consider removing or not exposing the 'X-Powered-By' header.

    Evidence: Software version disclosure

  7. 7

    Use of Third-Party Scripts without SRILow

    Why it matters: Running scripts from unverified sources could compromise the site if those resources are altered.

    Fix: Use Subresource Integrity when feasible or enforce a Content Security Policy.

    Evidence: Third-party scripts

  8. 8

    Missing Permissions-Policy HeaderInfo

    Why it matters: Lacking this header leaves browser features enabled that may not be necessary for your site.

    Fix: Add 'Permissions-Policy: geolocation=(self), microphone=()' to restrict access.

    Evidence: Permissions policy

  9. 9

    Sensitive Path in robots.txtInfo

    Why it matters: The presence of /wp-admin/ in robots.txt could unintentionally invite probing for vulnerabilities.

    Fix: Consider revising access controls for sensitive paths instead of relying on robots.txt.

    Evidence: Sensitive paths in robots.txt

What the checks found

  • FoundHTTP Strict Transport SecurityMedium

    No HTML page sends strict-transport-security. Without it a visitor who types the address without https:// can be intercepted on the first request.

    • https://www.square1coffee.ca/ → no strict-transport-security
    • https://www.square1coffee.ca/about/ → no strict-transport-security
    • https://www.square1coffee.ca/locations/ → no strict-transport-security
    • https://www.square1coffee.ca/related-businesses/ → no strict-transport-security
    • https://www.square1coffee.ca/contact/ → no strict-transport-security
    • https://www.square1coffee.ca/gallery/ → no strict-transport-security
    • https://www.square1coffee.ca/shop/ → no strict-transport-security
    • https://www.square1coffee.ca/product/muffin/ → no strict-transport-security
    • https://www.square1coffee.ca/quantity/6/ → no strict-transport-security
    • https://www.square1coffee.ca/quantity/12/ → no strict-transport-security
  • FoundContent Security PolicyMedium

    None of the 10 HTML pages send a Content-Security-Policy header or meta tag, so the browser has no restriction on where scripts, styles and frames may load from.

    • https://www.square1coffee.ca/ → no content-security-policy
    • https://www.square1coffee.ca/about/ → no content-security-policy
    • https://www.square1coffee.ca/locations/ → no content-security-policy
    • https://www.square1coffee.ca/related-businesses/ → no content-security-policy
    • https://www.square1coffee.ca/contact/ → no content-security-policy
    • https://www.square1coffee.ca/gallery/ → no content-security-policy
    • https://www.square1coffee.ca/shop/ → no content-security-policy
    • https://www.square1coffee.ca/product/muffin/ → no content-security-policy
    • https://www.square1coffee.ca/quantity/6/ → no content-security-policy
    • https://www.square1coffee.ca/quantity/12/ → no content-security-policy
  • FoundClickjacking protectionMedium

    No HTML page sends x-frame-options. Without X-Frame-Options (or a CSP frame-ancestors directive) the pages can be embedded in a frame on another site and overlaid with invisible controls.

    • https://www.square1coffee.ca/ → no x-frame-options
    • https://www.square1coffee.ca/about/ → no x-frame-options
    • https://www.square1coffee.ca/locations/ → no x-frame-options
    • https://www.square1coffee.ca/related-businesses/ → no x-frame-options
    • https://www.square1coffee.ca/contact/ → no x-frame-options
    • https://www.square1coffee.ca/gallery/ → no x-frame-options
    • https://www.square1coffee.ca/shop/ → no x-frame-options
    • https://www.square1coffee.ca/product/muffin/ → no x-frame-options
    • https://www.square1coffee.ca/quantity/6/ → no x-frame-options
    • https://www.square1coffee.ca/quantity/12/ → no x-frame-options
  • FoundMIME sniffing protectionLow

    No HTML page sends x-content-type-options. Without X-Content-Type-Options: nosniff a browser may run a file as a script because of its contents rather than its declared type.

    • https://www.square1coffee.ca/ → no x-content-type-options
    • https://www.square1coffee.ca/about/ → no x-content-type-options
    • https://www.square1coffee.ca/locations/ → no x-content-type-options
    • https://www.square1coffee.ca/related-businesses/ → no x-content-type-options
    • https://www.square1coffee.ca/contact/ → no x-content-type-options
    • https://www.square1coffee.ca/gallery/ → no x-content-type-options
    • https://www.square1coffee.ca/shop/ → no x-content-type-options
    • https://www.square1coffee.ca/product/muffin/ → no x-content-type-options
    • https://www.square1coffee.ca/quantity/6/ → no x-content-type-options
    • https://www.square1coffee.ca/quantity/12/ → no x-content-type-options
  • FoundReferrer policyLow

    No HTML page sends referrer-policy. Without a Referrer-Policy the full page address, including any query string, is sent to every site a visitor clicks through to.

    • https://www.square1coffee.ca/ → no referrer-policy
    • https://www.square1coffee.ca/about/ → no referrer-policy
    • https://www.square1coffee.ca/locations/ → no referrer-policy
    • https://www.square1coffee.ca/related-businesses/ → no referrer-policy
    • https://www.square1coffee.ca/contact/ → no referrer-policy
    • https://www.square1coffee.ca/gallery/ → no referrer-policy
    • https://www.square1coffee.ca/shop/ → no referrer-policy
    • https://www.square1coffee.ca/product/muffin/ → no referrer-policy
    • https://www.square1coffee.ca/quantity/6/ → no referrer-policy
    • https://www.square1coffee.ca/quantity/12/ → no referrer-policy
  • FoundPermissions policyInfo

    No HTML page sends permissions-policy. A Permissions-Policy header turns off browser features the site does not use (camera, microphone, geolocation), limiting what an injected script could do.

    • https://www.square1coffee.ca/ → no permissions-policy
    • https://www.square1coffee.ca/about/ → no permissions-policy
    • https://www.square1coffee.ca/locations/ → no permissions-policy
    • https://www.square1coffee.ca/related-businesses/ → no permissions-policy
    • https://www.square1coffee.ca/contact/ → no permissions-policy
    • https://www.square1coffee.ca/gallery/ → no permissions-policy
    • https://www.square1coffee.ca/shop/ → no permissions-policy
    • https://www.square1coffee.ca/product/muffin/ → no permissions-policy
    • https://www.square1coffee.ca/quantity/6/ → no permissions-policy
    • https://www.square1coffee.ca/quantity/12/ → no permissions-policy
  • NoteSoftware version disclosure

    Responses name the framework in an X-Powered-By header but hide the version.

    • server: cloudflare (277 responses)
    • x-powered-by: WP Engine (18 responses)
  • NoteThird-party scripts

    Scripts run from 1 other domain without Subresource Integrity, so a compromise of any of them changes what runs on this site. (Tag managers and analytics rarely support SRI; a Content-Security-Policy that names these hosts is the usual control.)

    • static.klaviyo.com (10 script tags)
  • NoteSensitive paths in robots.txt

    robots.txt lists 1 path that look private. robots.txt is public and does not restrict access, so it doubles as a map for anyone probing the site; those paths need real access control.

    • Disallow: /wp-admin/
7 checks passed
  • OKHTTPS

    All 10 crawled pages were served over HTTPS.

  • OKCookie flags

    All 1 cookie carry Secure, HttpOnly and SameSite flags.

  • OKMixed content

    No HTTPS page loads a script, stylesheet, font or image over plain HTTP.

  • OKForms over HTTPS

    5 forms found, all on HTTPS pages posting to HTTPS addresses.

  • OKVulnerable JavaScript libraries

    2 library versions recognised, none with known vulnerabilities.

  • OKKeys and secrets in page code

    No API keys, tokens or private keys were found in the sampled HTML and scripts.

  • OKExposed files and listings

    None of the crawled URLs is a configuration file, backup, dump, repository folder or directory listing.

A passive review of what the crawl recorded: response headers, page and script contents and the URLs it found. It does not probe the site, test TLS settings or look for files that were not linked. Generated automatically; verify each finding against your own site before acting on it.

Sites scoring near www.square1coffee.ca

Their neighbours in the SEO rank table, which orders every scanned site by health score.

This report was produced by the DIY SEO Hub Site Spider crawling www.square1coffee.ca from its pages as published, the way a search engine does. It shows summary figures only.

Own www.square1coffee.ca?

  • Claim this site to manage the listing, hide it from the public lists, or keep it.
  • Want it gone instead? Ask through the support form or e-mail support@diyseohub.com, naming www.square1coffee.ca. Removal needs no account and no proof of purchase.
www.square1coffee.ca scan 2026-09-26-0513 | DIY SEO Hub