Audit Result

UUID: 01a06d28-e611-7341-98ed-98d77cc4fac0

fortunacysec.com

https://fortunacysec.com/

Scanned 2 days ago

69
Fair Score
39 total checks
Passed
19
Warnings
16
Errors
4

Meta Information

  • Title Tag Warning

    Found 66 characters. Keep title between 30 and 60 characters.

    Fix: Add a unique <title> tag describing the main page intent in 30-60 characters.

  • Found 94 characters. Good snippet length.

  • Canonical URL Warning

    Canonical link not found.

    Fix: Add <link rel="canonical" href="https://example.com/page"> to avoid duplicate URL ambiguity.

  • Favicon Pass

    Favicon found and reachable: https://cdn.prod.website-files.com/650940518bc322ab5b65f32f/650944a874a05b0a0d7dba13_cysec_favicon.png (HTTP 200).

    Favicon
  • Viewport configured: width=device-width, initial-scale=1

  • HTML Lang Pass

    Language declared as "en".

Content Structure

  • H1 Tag Pass

    Exactly one H1 found: "Make cybersecurity a part of your enterprise's DNA".

  • Valid heading flow across 58 headings.

  • 53 of 55 images are missing alt text.

    Fix: Add meaningful alt attributes to all informative images for accessibility and image SEO.

Technical Optimization

  • HTTPS Pass

    Page is served over HTTPS.

  • 2 HTTPS hardening issues detected.

    • • HSTS is missing includeSubDomains.
    • • Could not probe the HTTP version of this page.
    • • Strict-Transport-Security: max-age=31536000

    Fix: Set Strict-Transport-Security with a long max-age, add includeSubDomains, and redirect all HTTP requests to HTTPS.

  • Missing: x-content-type-options, referrer-policy.

    Full HTTP headers (18)
    • • age: 170648
    • • alt-svc: h3=":443"; ma=86400
    • • cf-cache-status: HIT
    • • cf-ray: a35e38f85c0bd6e9-IAD
    • • content-encoding: gzip
    • • content-security-policy: frame-ancestors 'self'
    • • content-type: text/html; charset=utf-8
    • • date: Fri, 04 Sep 2026 16:03:08 GMT
    • • last-modified: Wed, 02 Sep 2026 16:39:00 GMT
    • • link: <https://cdn.prod.website-files.com>; rel=preconnect; crossorigin, <https://cdn.prod.website-files.com/650940518bc322ab5b65f32f/css/cysec-ed.webflow.shared.01e09964d.min.css>; rel=preload; as=style; crossorigin; integrity="sha384-AeCZZNP3vnTK5ZSgqs8/nzGbdghRopf/RkgeXyrYHRZapaMZ3HINWpaQFDL75TAr"
    • • server: cloudflare
    • • strict-transport-security: max-age=31536000
    • • surrogate-control: max-age=432000
    • • surrogate-key: fortunacysec.com 650940518bc322ab5b65f32f pageId:650940518bc322ab5b65f36c 6597cc9654beab5b4f064553
    • • vary: accept-encoding
    • • x-frame-options: SAMEORIGIN
    • • x-lambda-id: 9b1c6f05-38ce-4ca3-81a7-8bc15dd783d8
    • • x-wf-region: us-east-1

    Fix: Add the missing security headers at your reverse proxy or application layer.

  • CSP Quality Warning

    2 CSP hardening issues detected.

    • • CSP is missing object-src 'none'.
    • • CSP is missing a base-uri restriction.
    • • Content-Security-Policy: frame-ancestors 'self'

    Fix: Tighten Content-Security-Policy by removing unsafe directives and adding object-src, base-uri, and frame-ancestors restrictions.

  • No first-party cookies were set during the initial page load.

  • Server response headers do not expose version tokens.

  • Domain appears to be behind Cloudflare.

    • • server: cloudflare
    • • cf-cache-status: HIT
    • • cf-ray: a35e38f85c0bd6e9-IAD
  • Loaded in 0.22s (perceived).

  • 4 scripts and 1 styles may block rendering.

    • • script: https://js.hscollectedforms.net/collectedforms.js
    • • script: https://js.hs-banner.com/v2/50222064/banner.js
    • • script: https://js.hs-analytics.net/analytics/1788533400000/50222064.js
    • • script: https://www.google.com/recaptcha/api.js
    • • style: https://cdn.prod.website-files.com/650940518bc322ab5b65f32f/css/cysec-ed.webflow.shared.01e09964d.min.css

    Fix: Defer non-critical scripts and inline critical CSS to improve first paint speed.

  • Compression Warning

    4 text resources look uncompressed.

    • • https://fortunacysec.com/avljl2rk9q5pNjUwOTQwNTE4YmMzMjJhYjViNjVmMzJm/ga/g/c?v=2&tid=G-TYFF7RSDJP&gtm=45g92e6921v9194485921za204zd9194485921&_p=1788537788267&gcd=13l3l3l3l1l1&npa=0&dma=0&gdid=dZGVlNj.dYWYxNW.dNzQzZD&_uip=%3A%3A&are=1&cid=1004453761.1788537789&fp=1&frm=0&ngs=1&pscdl=noapi&rcb=17&sr=1280x800&uaa=x86&uab=64&uafvl=Not%253AA-Brand%3B99.0.0.0%7CHeadlessChrome%3B145.0.7632.6%7CChromium%3B145.0.7632.6&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&ur=US-VA&_gsid=3NCZY0vPUSB2WOLbUwYUynyToSvzCdN42g&_s=1&tag_exp=115938466~115938469~118897920~118897930~120213116~120385423~120469145~120469153&sid=1788537788&sct=1&seg=0&dl=https%3A%2F%2Ffortunacysec.com%2F&dt=Fortuna%20Cysec%20-%20Make%20cybersecurity%20a%20part%20of%20your%20enterprise%27s%20DNA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.gtb=1&tfd=448 (text/plain)
    • • https://aplo-evnt.com/api/v1/intent_pixel/can_track_visitor?x_app_id=68e90eb58e852e0011d23ce0 (application/json; charset=utf-8)
    • • https://api.factors.ai/sdk/get_info (application/json; charset=utf-8)
    • • https://api.factors.ai/sdk/user/add_properties (application/json; charset=utf-8)

    Fix: Enable Brotli or Gzip compression for HTML, CSS, JS, and JSON responses.

  • Robots.txt Pass

    Found robots.txt (200).

  • Sitemap File Warning

    Sitemap missing or inaccessible at https://fortunacysec.com/sitemap.xml (404).

    Fix: Publish a sitemap.xml and reference it in robots.txt with: Sitemap: https://fortunacysec.com/sitemap.xml

  • No robots meta tag defined.

    Fix: Add <meta name="robots" content="index,follow"> (or the intended directive) in <head>.

Accessibility Basics

  • Form Labels Error

    7 of 7 controls are missing labels.

    • • input[type="text"].text_field-style.w-input (First-Name)
    • • input[type="text"]#Last-Name-2.text_field-style.w-input (Last-Name-2)
    • • input[type="text"]#email-2.text_field-style.w-input (Company)
    • • input[type="text"]#Job-Title-2.text_field-style.w-input (Job-Title-2)
    • • input[type="email"]#Email-4.text_field-style.w-input (Email-4)
    • • textarea#Message-2.pop_up-text_area-field-style.w-input (Message-2)
    • • input[type="email"]#email.text-field.w-input (email)

    Fix: Associate each form control with a visible label, aria-label, or aria-labelledby.

  • Landmarks Warning

    Missing landmarks: footer.

    Fix: Use semantic regions (<header>, <nav>, <main>, <footer>) for navigation and assistive tech.

  • Tap Target Size Warning

    25 interactive elements appear smaller than 48px.

    • • button.cc-nb-okagree (I agree) - 78x40px
    • • button.cc-nb-reject (I decline) - 84x40px
    • • button.cc-nb-changep (Change my preferences) - 172x40px
    • • a.brand.w-nav-brand (home) - 157x36px
    • • a.navbar-link_text.w--current (Home) - 40x29px
    • • a.navbar-dropdown1_dropdown-current.w-inline-block (Platform) - 74x16px
    • • a.navbar-link_text (Services) - 56x29px
    • • a.navbar-dropdown1_dropdown-current.w-inline-block (Resources) - 86x16px
    • • a.navbar-link_text (Customer Portal) - 102x29px
    • • a.footer-cta.w-inline-block (Contact Us @media only screen and (width >= 992px) {.footer-cta{ clip-path) - 149x31px
    • • a.w-inline-block (how we do it) - 211x38px
    • • a.w-inline-block (Talk to an expert) - 196x27px
    • • a#w-tabs-0-data-w-tab-0.threats-tab-link.is-blog (Predict) - 186x39px
    • • a#w-tabs-0-data-w-tab-1.threats-tab-link.is-case (Prevent) - 186x39px
    • • a#w-tabs-0-data-w-tab-2.threats-tab-link.is-event (Protect) - 186x39px
    • • a#w-tabs-2-data-w-tab-0.platform-tab-link.w-inline-block (Network Telemetry) - 384x10px
    • • a#w-tabs-2-data-w-tab-1.platform-tab-link.w-inline-block (EDR ( MITRE)) - 384x10px
    • • a#w-tabs-2-data-w-tab-2.platform-tab-link.w-inline-block (Cloud & Server Monitoring) - 384x10px
    • • a#w-tabs-3-data-w-tab-0.siloes-tab_link.w-inline-block (Without Fortunox) - 206x29px
    • • a#w-tabs-3-data-w-tab-1.siloes-tab_link.w-inline-block (With Fortunox) - 168x27px
    • • a#w-tabs-5-data-w-tab-0.data-tab-link._1 (Healthcare) - 119x34px
    • • a#w-tabs-5-data-w-tab-1.data-tab-link._2 (Finance) - 119x34px
    • • a#w-tabs-5-data-w-tab-2.data-tab-link._3 (Insurance) - 119x34px
    • • a.w-inline-block (Read USe case) - 218x38px
    • • a.w-inline-block (Read blog) - 183x38px

    Fix: Increase target size to at least 48x48 CSS pixels for touch interactions.

Social & Rich Results

  • Core Open Graph tags are present.

  • og:image is present and absolute.

    Open Graph Image
  • twitter:card set to summary_large_image.

  • Structured Data Warning

    No JSON-LD schema scripts found.

    Fix: Add JSON-LD structured data matching your page type (Organization, Article, Product, etc.).

  • PWA Metadata Warning

    Manifest or Apple touch icon is missing.

    Fix: Link your web app manifest and apple-touch-icon for improved install/share experiences.

  • 2 social preview quality issues detected.

    • • ISSUE: og:url should be an absolute URL.
    • • ISSUE: Failed to fetch preview image: network error.
    • • GUIDELINE: Optimal og:title length: 40-60 characters (acceptable: 10-70).
    • • GUIDELINE: Optimal og:description length: 110-160 characters (acceptable: 50-200).
    • • GUIDELINE: Optimal preview image size: 1200x630 pixels.
    • • GUIDELINE: Optimal preview image aspect ratio: 1.91:1.
    • • GUIDELINE: Optimal preview image file size: under 5 MB.
    • • GUIDELINE: Recommended twitter:card: summary_large_image.

    Fix: Use absolute OG/Twitter URLs, keep metadata lengths in recommended ranges, and provide a preview image near 1200x630 under 5MB.

Links Analysis

  • 1 internal links returned errors.

    • • https://fortunacysec.com/terms-of-service (HTTP 404)

    Fix: Fix or remove the listed internal URLs, and ensure routes/pages return 200 responses.

  • No broken external links found in checked URLs.

  • Link Format Warning

    9 links are empty, invalid, or placeholder-only.

    • • href="#"
    • • href="#"
    • • href="#"
    • • href="#" text="Careers"
    • • href="#" text="Leadership"
    • • href="#"
    • • href="#"
    • • href="#"
    • • href="#"

    Fix: Replace empty/#/javascript href values with real destinations or use buttons for non-navigation actions.

Performance & Runtime

  • Largest Contentful Paint: 0.22s.

  • Cumulative Layout Shift: 0.024.

  • Total Blocking Time estimate: 79ms.

  • 2 asset requests failed.

    • • https://assets.positional-bucket.com/positional.min.js (net::ERR_BLOCKED_BY_ORB)
    • • https://www.termsfeed.com/public-ping/cookie-consent/4.2.0/cookie-consent.js/fortunacysec.com (net::ERR_BLOCKED_BY_RESPONSE.NotSameOrigin)

    Fix: Fix missing files, update asset URLs, and ensure static assets return HTTP 200.

  • 8 JavaScript runtime issues detected.

    • • Request failed: https://aplo-evnt.com/api/v1/intent_pixel/track_request?app_id=68e90eb58e852e0011d23ce0 (HTTP 400, type: fetch)
    • • Request failed: https://assets.positional-bucket.com/positional.min.js (net::ERR_BLOCKED_BY_ORB, type: script)
    • • Request failed: https://www.termsfeed.com/public-ping/cookie-consent/4.2.0/cookie-consent.js/fortunacysec.com (net::ERR_BLOCKED_BY_RESPONSE.NotSameOrigin, type: script)
    • • Request failed: https://fortunacysec.com/avljl2rk9q5pNjUwOTQwNTE4YmMzMjJhYjViNjVmMzJm/ga/g/c?v=2&tid=G-TYFF7RSDJP&gtm=45g92e6921v9194485921za204zd9194485921&_p=1788537788267&gcd=13l3l3l3l1l1&npa=0&dma=0&gdid=dZGVlNj.dYWYxNW.dNzQzZD&_uip=%3A%3A&are=1&cid=1004453761.1788537789&fp=1&frm=0&ngs=1&pscdl=noapi&rcb=17&sr=1280x800&uaa=x86&uab=64&uafvl=Not%253AA-Brand%3B99.0.0.0%7CHeadlessChrome%3B145.0.7632.6%7CChromium%3B145.0.7632.6&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&ur=US-VA&_gsid=3NCZY0vPUSB2WOLbUwYUynyToSvzCdN42g&_s=1&tag_exp=115938466~115938469~118897920~118897930~120213116~120385423~120469145~120469153&sid=1788537788&sct=1&seg=0&dl=https%3A%2F%2Ffortunacysec.com%2F&dt=Fortuna%20Cysec%20-%20Make%20cybersecurity%20a%20part%20of%20your%20enterprise%27s%20DNA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.gtb=1&tfd=448 (net::ERR_ABORTED, type: fetch)
    • • Request failed: https://px.ads.linkedin.com/wa/?medium=fetch&fmt=g (net::ERR_ABORTED, type: fetch)
    • • Failed to load resource: net::ERR_BLOCKED_BY_RESPONSE.NotSameOrigin [https://www.termsfeed.com/public-ping/cookie-consent/4.2.0/cookie-consent.js/fortunacysec.com:1]
    • • Failed to load resource: the server responded with a status of 400 () [https://aplo-evnt.com/api/v1/intent_pixel/track_request?app_id=68e90eb58e852e0011d23ce0:1]
    • • Cannot read properties of null (reading 'value')

    Fix: Fix JS files returning 404/failed requests and resolve the listed runtime exceptions.