Example report | harbourlanebakery.example
Your findings, and how to fix them
Each finding shows what we saw on your site, why it matters and, in broad terms, what putting it right involves. This is a guide to the size of the job, not a step-by-step manual.
Checked on 1 October 2026. Read as a local service site. 98 of 101 automated checks could be evaluated, and 71 passed. Report reference EXAMPLE.
This example uses a made-up bakery and a made-up website address (.example addresses can never belong to a real site). The findings, scores and evidence are invented, but the layout, wording and guidance are exactly what a real full report contains.
Download the example as a PDF Run the free check on your site
Summary of findings
27 open findings: 2 critical, 12 important and 13 minor, plus one tip.
Every finding in this report, grouped by area with the most serious first. Select a finding to go straight to the detail.
- Critical: a likely legal breach, security failure or blocker that is live now. Deal with these straight away.
- Important: clear gaps that cost enquiries, visibility or trust, or engage a legal duty. Aim for the next 30 days.
- Minor: refinements worth doing when convenient.
- Needs checking: a signal rather than a conclusion. A person should confirm it on the live site.
2 checks couldn't be completed this time. See what we couldn't check.
Compliance: 8 findings
Critical
Compliance · Cookies and consentP1-08
Advertising or visitor-identification trackers run before any consent is given
What we saw
Before any choice was made on the cookie banner, the homepage loaded Meta Pixel and Google Ads remarketing.
Why it matters
Advertising, retargeting and visitor-identification technologies need prior consent. Loading them on arrival is the most common cookie breach and a current ICO enforcement focus.
Reference: PECR Regulation 6, ICO storage and access guidance (April 2026).
How to fix
- Hold all advertising and visitor-identification tags back until a visitor chooses "Accept".
- Make sure "Reject" is as easy as "Accept" and really switches them off.
- Re-test in a fresh browser to confirm nothing loads early.
- Effort
- Medium
- Who usually does this
- Your web developer, about half a day including testing.
Back to summary
Important
Compliance · Privacy noticeP1-03
Privacy policy does not mention the right to complain to the ICO
What we saw
The privacy policy at /privacy does not mention the Information Commissioner's Office (ICO) or the right to complain to it.
Why it matters
People must be told they can complain to the Information Commissioner.
Reference: UK GDPR Article 13(2)(d).
How to fix
- Add a line saying people can complain to the Information Commissioner's Office, with a link to ico.org.uk.
- Effort
- Low
- Who usually does this
- You or whoever looks after your policies, a few minutes.
Back to summary
Important
Compliance · Cookies and consentNeeds checkingP1-10
Cookie banner has no equally easy way to reject
What we saw
The cookie banner has an "Accept all" button, but refusing takes two more clicks through "Settings".
This is a signal rather than a conclusion: a person should confirm it on the live site.
Why it matters
Consent is not valid if refusing takes more effort than accepting.
Reference: PECR Regulation 6, ICO guidance on consent (reject as easy as accept).
How to fix
- Add a "Reject all" button to the first screen of the cookie banner, as easy to see and use as "Accept all".
- Effort
- Low
- Who usually does this
- Your web developer, usually a setting in your cookie tool. Under an hour.
Back to summary
Important
Compliance · Pricing and consumer lawP1-16
No returns, refunds or cancellation information found
What we saw
Celebration cakes can be ordered online, but no refund or cancellation information was found on the pages read.
Why it matters
Online shops must explain the cancellation right before purchase.
Reference: Consumer Contracts Regulations 2013 (14-day cancellation right).
How to fix
- Publish a returns, refunds and cancellation page.
- Link it from product pages, the basket and checkout.
- Effort
- Medium
- Who usually does this
- You, with a template or adviser; your web developer adds the page and links.
Back to summary
Important
Compliance · Business detailsP1-17
Company registration number is not shown
What we saw
The footer names "Harbour Lane Bakery Ltd", but no company number appears on the pages read.
Why it matters
Limited companies and LLPs must show their registered number on their website.
Reference: Company, LLP and Business Names (Miscellaneous Provisions) Regulations 2015 reg. 25.
How to fix
- Add your company name, company number, where you're registered and your registered office to the footer or a legal information page.
- Effort
- Low
- Who usually does this
- Your web developer, a few minutes.
Back to summary
Important
Compliance · Accessibility rulesP1-22
Images are missing text alternatives
What we saw
9 of 24 images on the homepage have no text alternative, including the photos of the cake range.
Why it matters
Screen-reader users get no description of images without alt text.
Reference: WCAG 2.2 AA 1.1.1; Equality Act 2010.
How to fix
- Add a short description to each image that carries meaning.
- Mark purely decorative images so screen readers skip them.
- Effort
- Low to medium
- Who usually does this
- Your web developer or whoever edits your content, an hour or two.
Back to summary
Minor
Compliance · Privacy noticeP1-06
Privacy policy does not say how long data is kept
What we saw
The privacy policy does not say how long order and enquiry details are kept.
Why it matters
People must be told the retention period or the criteria used to set it.
Reference: UK GDPR Article 13(2)(a).
How to fix
- Say how long you keep each kind of data, for example enquiries, customer records and analytics.
- Effort
- Low
- Who usually does this
- You or whoever looks after your policies, under an hour.
Back to summary
Minor
Compliance · Marketing claimsNeeds checkingP1-26
Superlative or performance claims that need evidence on file
What we saw
The homepage says "the best sourdough on the coast". Keep evidence on file for claims like this.
This is a signal rather than a conclusion: a person should confirm it on the live site.
Why it matters
Objective claims such as "best", "number one" or "guaranteed" results must be backed by evidence held before the claim is made.
Reference: CAP Code rules 3.7 and 3.33 (substantiation), DMCCA 2024.
How to fix
- For each "best", "number one" or performance claim, keep evidence on file, or soften the wording.
- Effort
- Low
- Who usually does this
- You, an hour or so.
Back to summary
Findability: 5 findings
Important
Findability · Page titles and structureP2-11
Page titles are missing, duplicated or poorly sized
What we saw
4 of the 7 pages read share the title "Home | Harbour Lane Bakery".
Why it matters
The title is the main line shown in search results.
Reference: Google Search Central: title links.
How to fix
- Give every page its own clear title, roughly 30 to 60 characters, that says what the page is about.
- Effort
- Low to medium
- Who usually does this
- You or whoever edits your content, an hour or two.
Back to summary
Important
Findability · Local searchP2-16
No hidden business summary for search engines (structured data with your name, address and phone)
What we saw
No LocalBusiness or Bakery structured data with the name, address and phone number was found.
Why it matters
Schema confirms the business name, location and contact details to search engines and AI assistants.
Reference: Google Search Central: Organization and LocalBusiness structured data.
How to fix
- Add a hidden business summary with your name, address, phone, logo and profile links.
- Check it with Google's free Rich Results Test.
- Effort
- Low
- Who usually does this
- Your web developer, under an hour. Often a plugin or setting.
Back to summary
Minor
Findability · Search engine basicsP2-04
The sitemap isn't mentioned in the site's crawler rules (robots.txt)
What we saw
robots.txt does not include a Sitemap line.
Why it matters
Listing the sitemap in robots.txt lets every crawler find it.
Reference: Sitemaps protocol.
How to fix
- Add a line pointing to your sitemap in the crawler rules file.
- Effort
- Low
- Who usually does this
- Your web developer, a few minutes.
Back to summary
Minor
Findability · Page titles and structureP2-12
Pages are missing meta descriptions
What we saw
5 of the 7 pages read have no meta description.
Why it matters
Without one, search engines pick text from the page, often badly.
Reference: Google Search Central: snippets.
How to fix
- Write a short, unique summary for each key page, roughly 120 to 160 characters.
- Effort
- Low to medium
- Who usually does this
- You or whoever edits your content, an hour or two.
Back to summary
Minor
Findability · AI assistantsP2-20
The business summary doesn't link to your official profiles
What we saw
The business summary has no sameAs links to the bakery's Instagram or Facebook pages.
Why it matters
sameAs links tie the website to the business's LinkedIn, Companies House and review profiles, which helps AI answers and knowledge panels.
Reference: Google Search Central: Organization structured data.
How to fix
- Add links to your official profiles (such as LinkedIn) to the hidden business summary.
- Effort
- Low
- Who usually does this
- Your web developer, a few minutes.
Back to summary
Experience: 3 findings
Important
Experience · SpeedP3-04
Google's mobile speed test gives a low score
What we saw
Google's mobile speed score is 41 out of 100. The largest image on the homepage is a 3.8 MB photo.
Why it matters
Slow mobile pages lose visitors before they see the offer.
Reference: Lighthouse performance guidance.
How to fix
- Compress and resize images, remove scripts you don't need, and stop content jumping as it loads.
- Effort
- Medium
- Who usually does this
- Your web developer, half a day to a day.
Back to summary
Minor
Experience · Easy to use for everyoneP3-07
No skip-to-content link
What we saw
No skip-to-content link was found on the homepage.
Why it matters
Keyboard users must tab through the whole menu on every page.
Reference: WCAG 2.2 AA 2.4.1 (bypass blocks).
How to fix
- Add a "Skip to content" link at the very top of each page for keyboard users.
- Effort
- Low
- Who usually does this
- Your web developer, under an hour.
Back to summary
Minor
Experience · Enquiries and contactP3-13
Enquiry form asks for a lot of information
What we saw
The cake order form asks for 14 details, including date of birth.
Why it matters
Every extra required field reduces enquiries and may collect more than needed.
Reference: UK GDPR Article 5(1)(c) (data minimisation); conversion good practice.
How to fix
- Cut the form down to what you need for a first reply, usually name, email and a message.
- Effort
- Low
- Who usually does this
- You decide; your web developer makes the change. Under an hour.
Back to summary
Trust and security: 11 findings
Critical
Trust and security · Platform and softwareP4-28
Some add-ons (plugins or themes) have known security problems
What we saw
bakeshop-orders 2.3.1 (a made-up add-on for this example): 2 known problems, for example "Order details can be downloaded without logging in". Example data only, so no vulnerability record links are shown.
Why it matters
Add-ons are the most common way WordPress sites are broken into. These versions have published security problems.
Reference: UK GDPR Article 32; NCSC guidance on keeping software up to date.
How to fix
- Take a backup, then update each add-on listed.
- If no fixed version exists, replace or remove the add-on.
- Remove add-ons you don't use.
- Effort
- Low to medium
- Who usually does this
- Your web developer, an hour or two. Urgent if any are marked critical.
Back to summary
Important
Trust and security · Website securityP4-02
Browsers aren't told to always use the secure version of the site
What we saw
No Strict-Transport-Security header was sent.
Why it matters
HSTS stops downgrade attacks on public wifi.
Reference: NCSC and OWASP secure headers guidance.
How to fix
- Turn on the setting that tells browsers to always use the secure version of your site (HSTS).
- Effort
- Low
- Who usually does this
- Your web developer or hosting support, a few minutes. Often a Cloudflare or hosting setting.
Back to summary
Important
Trust and security · Trackers and third partiesP4-12
Trackers on the site are not named in the privacy or cookie policy
What we saw
Meta Pixel and Hotjar load on the site, but neither is named in the privacy or cookie policy.
Why it matters
Visitors must be told which third parties receive their data.
Reference: UK GDPR Article 13(1)(e) (recipients); PECR Regulation 6.
How to fix
- List each third-party tool, what it's for and who provides it in your cookie or privacy policy.
- Effort
- Low to medium
- Who usually does this
- You or whoever looks after your policies, an hour or two.
Back to summary
Important
Trust and security · Email securityP4-21
Email providers aren't told to reject fake emails from your domain (DMARC missing or monitoring only)
What we saw
The DMARC record is set to p=none, so fake emails from the domain are only monitored, not rejected.
Why it matters
DMARC tells mail servers to reject email that pretends to be from you.
Reference: NCSC email security guidance.
How to fix
- Add a DMARC record with reporting, then, once your real email passes, tell providers to quarantine or reject fakes.
- Effort
- Low to medium
- Who usually does this
- Whoever manages your domain or email, an hour now and a check-in a few weeks later.
Back to summary
Important
Trust and security · Platform and softwareP4-31
Anyone can see a list of the files in a folder
What we saw
/wp-content/uploads/ shows a list of its files.
Why it matters
A file list can reveal documents, backups or uploads that were never meant to be found.
Reference: UK GDPR Article 32; OWASP information exposure guidance.
How to fix
- Turn off folder listings on the server.
- Look through the folder for old files, backups or documents that should not be public, and remove them.
- Effort
- Low
- Who usually does this
- Your web developer or hosting support, under an hour.
Back to summary
Minor
Trust and security · Website securityP4-03
No browser rules limiting which scripts can run (Content Security Policy)
What we saw
No Content-Security-Policy header was sent.
Why it matters
A CSP limits the damage of injected scripts.
Reference: OWASP secure headers guidance.
How to fix
- Add browser rules listing where scripts and styles may load from, starting in a "report only" mode so nothing breaks.
- Effort
- Medium
- Who usually does this
- Your web developer, a few hours including testing.
Back to summary
Minor
Trust and security · Trust signalsP4-15
Copyright year in the footer is out of date
What we saw
The footer says "© 2023".
Why it matters
An old year makes the site look abandoned.
Reference: Trust good practice.
How to fix
- Update the copyright year in the footer, or set it to update itself.
- Effort
- Low
- Who usually does this
- Your web developer, a few minutes.
Back to summary
Minor
Trust and security · Email securityP4-24
No security contact file for people reporting problems (security.txt)
What we saw
No /.well-known/security.txt with a Contact line.
Why it matters
Tells researchers how to report a security problem to you.
Reference: RFC 9116; NCSC vulnerability disclosure toolkit.
How to fix
- Publish a small security contact file so people can report problems to you.
- Effort
- Low
- Who usually does this
- Your web developer, a few minutes.
Back to summary
Minor
Trust and security · Platform and softwareP4-27
The website software is not the latest version
What we saw
The site runs WordPress 6.5.2. The latest version is 7.1.2.
Why it matters
Older versions miss improvements and, sooner or later, security fixes.
Reference: NCSC guidance on keeping software up to date.
How to fix
- Take a backup, then update WordPress from the dashboard and check the site still works.
- Effort
- Low
- Who usually does this
- Your web developer, or whoever looks after the site, under an hour.
Back to summary
Minor
Trust and security · Platform and softwareP4-29
Some add-ons (plugins or themes) are out of date
What we saw
3 add-ons are behind the latest version: bakeshop-orders 2.3.1 (latest 2.6.0), harbour-gallery 1.0.4 (latest 1.2.1) and simple-opening-hours 3.1 (latest 3.4).
Why it matters
Out-of-date add-ons are a common way in for attackers, and can break when WordPress updates.
Reference: NCSC guidance on keeping software up to date.
How to fix
- Take a backup, then update the add-ons listed and check the site still works.
- Turn on automatic updates for add-ons from trusted makers.
- Effort
- Low
- Who usually does this
- Your web developer, or whoever looks after the site, under an hour.
Back to summary
Minor
Trust and security · Platform and softwareP4-32
The website software version is shown publicly
What we saw
The page code says WordPress 6.5.2.
Why it matters
Showing the exact version makes it easy for automated attacks to target known weaknesses.
Reference: OWASP information exposure guidance.
How to fix
- Hide the software version from the page code (a setting or small add-on).
- Delete the default readme file.
- Effort
- Low
- Who usually does this
- Your web developer, a few minutes.
Back to summary
Tips
Good practice worth knowing about. Tips aren't problems and don't count towards your score.
TipTrust and security · Platform and softwareP4-33
The login page is at the standard address
What we saw
The WordPress login page is open at /wp-login.php, as it is on most WordPress sites. We did not try to log in. It is worth checking every account has a strong password and two-step login.
Why it's worth a look
Automated tools try passwords on standard login pages all day. Strong passwords and a second login step keep them out.
What to do
- Make sure every login uses a strong, unique password and two-step verification.
- Limit repeated login attempts with a security add-on or your host's settings.
- Remove old or unused accounts.
- Effort
- Low
- Who usually does this
- Your web developer, under an hour.
Back to summary
What we couldn't check this time
These checks couldn't be completed automatically, usually because a page is built with scripts or a service didn't respond. They are not counted against you.
- P3-03: Real visitors find the site slow by Google's measures (Core Web Vitals)
- P4-09: Low security grade from Mozilla's free website security test
Scores by topic
Some areas need a human eye, so the automated check caps them at 80. The expert audit can score them fully.
| Area | Topic | Score | Note |
|---|
| Compliance | Privacy notice | 74 | |
| Compliance | Cookies and consent | 45 | |
| Compliance | Pricing and consumer law | 80 | Partly automated |
| Compliance | Business details | 80 | |
| Compliance | Accessibility rules | 80 | |
| Compliance | Marketing claims | 80 | Capped at 80 |
| Findability | Search engine basics | 94 | |
| Findability | Page titles and structure | 74 | Partly automated |
| Findability | Local search | 80 | Partly automated |
| Findability | AI assistants | 94 | |
| Findability | Content and credibility | 80 | Capped at 80 |
| Experience | Speed | 80 | |
| Experience | Clear next steps | 80 | Capped at 80 |
| Experience | Mobile | 80 | Capped at 80 |
| Experience | Easy to use for everyone | 94 | |
| Experience | Enquiries and contact | 80 | Capped at 80 |
| Trust and security | Website security | 74 | |
| Trust and security | Trackers and third parties | 80 | |
| Trust and security | Trust signals | 80 | Capped at 80 |
| Trust and security | Measuring results | 100 | |
| Trust and security | Email security | 74 | |
| Trust and security | Platform and software | 17 | |
What happens next
You've seen what needs doing. Here are your options.
Fix it yourself
If you or someone on your team is comfortable working on the site, the guidance above shows what's involved. Run the free check again afterwards to see what's cleared.
Pass this report to your current provider
Send them this report. It's worth asking them why these weren't raised, and how they'll stop them coming back.
Let serva.digital fix it
You shouldn't have to chase these. I'll fix them for an agreed price and keep an eye on your site so they don't creep back.
You'll get a fixed quote for the items you choose, with the £29 you paid for this report credited against the work if you go ahead within 90 days. When it's done, your site is checked again so you can see each item is fixed.
If you'd like, ongoing care is available from £10 a month, matched to what your site needs, so issues like these are caught early.
Ask for a fixed quote
No obligation. Prices are fixed and agreed in writing before any work starts. No VAT is charged.
Would you rather a person went through the whole site first? The expert audit covers the things an automated check can't judge, with a walkthrough call and a written summary. It costs £149 to £199, depending on the size of the site, and the £29 you paid for this report is credited against it if you book within 90 days. About the expert audit
David Allison, serva.digital
How this check works
- We read your public pages (home, about, contact, privacy, cookies, terms, order). We never log in, submit forms or try to break in.
- We also make a few ordinary requests that any browser could make, to see whether files that should be private (such as /.env or /.git/) can be opened, whether a folder lists its files, and which software versions the site shows. We don't keep the contents of any private file.
- Software versions are compared with WordPress.org, Wordfence Intelligence and retire.js. Certificate dates come from public certificate logs (Cert Spotter, by SSLMate) and domain renewal dates from the domain registry.
- Your homepage was loaded in a real browser located in the UK to see what runs before anyone agrees to cookies.
- Speed and accessibility scores come from Google PageSpeed Insights. The security grade comes from Mozilla's free website security test (not available this time).
- Rules version 2026-10-04.6.
This report is an automated check of publicly visible pages on the date shown. It is indicative and is not legal advice. Items marked "needs checking" are signals, not conclusions. Material compliance points should be confirmed with a qualified adviser.