Example report. Harbour Lane Bakery is a made-up business, and every finding here is made up, to show what a full report looks like.

Example report | harbourlanebakery.example

Your findings, and how to fix them

Each finding shows what we saw on your site, why it matters and, in broad terms, what putting it right involves. This is a guide to the size of the job, not a step-by-step manual.

Checked on 1 October 2026. Read as a local service site. 98 of 101 automated checks could be evaluated, and 71 passed. Report reference EXAMPLE.

This example uses a made-up bakery and a made-up website address (.example addresses can never belong to a real site). The findings, scores and evidence are invented, but the layout, wording and guidance are exactly what a real full report contains.

Download the example as a PDF Run the free check on your site

79/ 100

Quick check score: Established

An automated score from your public pages. Areas that need a human eye are capped at 80, so only the expert audit can score them higher.

  • UK legal and compliance73
  • Findability84
  • Experience and performance83
  • Trust, security and data70

Summary of findings

27 open findings: 2 critical, 12 important and 13 minor, plus one tip.

Every finding in this report, grouped by area with the most serious first. Select a finding to go straight to the detail.

RefAreaTopicSeverityFinding
P1-08ComplianceCookies and consentCriticalAdvertising or visitor-identification trackers run before any consent is given
P1-03CompliancePrivacy noticeImportantPrivacy policy does not mention the right to complain to the ICO
P1-10ComplianceCookies and consentImportantCookie banner has no equally easy way to reject Needs checking
P1-16CompliancePricing and consumer lawImportantNo returns, refunds or cancellation information found
P1-17ComplianceBusiness detailsImportantCompany registration number is not shown
P1-22ComplianceAccessibility rulesImportantImages are missing text alternatives
P1-06CompliancePrivacy noticeMinorPrivacy policy does not say how long data is kept
P1-26ComplianceMarketing claimsMinorSuperlative or performance claims that need evidence on file Needs checking
P2-11FindabilityPage titles and structureImportantPage titles are missing, duplicated or poorly sized
P2-16FindabilityLocal searchImportantNo hidden business summary for search engines (structured data with your name, address and phone)
P2-04FindabilitySearch engine basicsMinorThe sitemap isn't mentioned in the site's crawler rules (robots.txt)
P2-12FindabilityPage titles and structureMinorPages are missing meta descriptions
P2-20FindabilityAI assistantsMinorThe business summary doesn't link to your official profiles
P3-04ExperienceSpeedImportantGoogle's mobile speed test gives a low score
P3-07ExperienceEasy to use for everyoneMinorNo skip-to-content link
P3-13ExperienceEnquiries and contactMinorEnquiry form asks for a lot of information
P4-28Trust and securityPlatform and softwareCriticalSome add-ons (plugins or themes) have known security problems
P4-02Trust and securityWebsite securityImportantBrowsers aren't told to always use the secure version of the site
P4-12Trust and securityTrackers and third partiesImportantTrackers on the site are not named in the privacy or cookie policy
P4-21Trust and securityEmail securityImportantEmail providers aren't told to reject fake emails from your domain (DMARC missing or monitoring only)
P4-31Trust and securityPlatform and softwareImportantAnyone can see a list of the files in a folder
P4-03Trust and securityWebsite securityMinorNo browser rules limiting which scripts can run (Content Security Policy)
P4-15Trust and securityTrust signalsMinorCopyright year in the footer is out of date
P4-24Trust and securityEmail securityMinorNo security contact file for people reporting problems (security.txt)
P4-27Trust and securityPlatform and softwareMinorThe website software is not the latest version
P4-29Trust and securityPlatform and softwareMinorSome add-ons (plugins or themes) are out of date
P4-32Trust and securityPlatform and softwareMinorThe website software version is shown publicly
P4-33Trust and securityPlatform and softwareTipThe login page is at the standard address Not scored
  • Critical: a likely legal breach, security failure or blocker that is live now. Deal with these straight away.
  • Important: clear gaps that cost enquiries, visibility or trust, or engage a legal duty. Aim for the next 30 days.
  • Minor: refinements worth doing when convenient.
  • Needs checking: a signal rather than a conclusion. A person should confirm it on the live site.

2 checks couldn't be completed this time. See what we couldn't check.

Compliance: 8 findings

Critical Compliance · Cookies and consentP1-08

Advertising or visitor-identification trackers run before any consent is given

What we saw

Before any choice was made on the cookie banner, the homepage loaded Meta Pixel and Google Ads remarketing.

Why it matters

Advertising, retargeting and visitor-identification technologies need prior consent. Loading them on arrival is the most common cookie breach and a current ICO enforcement focus.

Reference: PECR Regulation 6, ICO storage and access guidance (April 2026).

How to fix

  • Hold all advertising and visitor-identification tags back until a visitor chooses "Accept".
  • Make sure "Reject" is as easy as "Accept" and really switches them off.
  • Re-test in a fresh browser to confirm nothing loads early.
Effort
Medium
Who usually does this
Your web developer, about half a day including testing.

Back to summary

Important Compliance · Privacy noticeP1-03

Privacy policy does not mention the right to complain to the ICO

What we saw

The privacy policy at /privacy does not mention the Information Commissioner's Office (ICO) or the right to complain to it.

Why it matters

People must be told they can complain to the Information Commissioner.

Reference: UK GDPR Article 13(2)(d).

How to fix

  • Add a line saying people can complain to the Information Commissioner's Office, with a link to ico.org.uk.
Effort
Low
Who usually does this
You or whoever looks after your policies, a few minutes.

Back to summary

Important Compliance · Cookies and consentNeeds checkingP1-10

Cookie banner has no equally easy way to reject

What we saw

The cookie banner has an "Accept all" button, but refusing takes two more clicks through "Settings".

This is a signal rather than a conclusion: a person should confirm it on the live site.

Why it matters

Consent is not valid if refusing takes more effort than accepting.

Reference: PECR Regulation 6, ICO guidance on consent (reject as easy as accept).

How to fix

  • Add a "Reject all" button to the first screen of the cookie banner, as easy to see and use as "Accept all".
Effort
Low
Who usually does this
Your web developer, usually a setting in your cookie tool. Under an hour.

Back to summary

Important Compliance · Pricing and consumer lawP1-16

No returns, refunds or cancellation information found

What we saw

Celebration cakes can be ordered online, but no refund or cancellation information was found on the pages read.

Why it matters

Online shops must explain the cancellation right before purchase.

Reference: Consumer Contracts Regulations 2013 (14-day cancellation right).

How to fix

  • Publish a returns, refunds and cancellation page.
  • Link it from product pages, the basket and checkout.
Effort
Medium
Who usually does this
You, with a template or adviser; your web developer adds the page and links.

Back to summary

Important Compliance · Business detailsP1-17

Company registration number is not shown

What we saw

The footer names "Harbour Lane Bakery Ltd", but no company number appears on the pages read.

Why it matters

Limited companies and LLPs must show their registered number on their website.

Reference: Company, LLP and Business Names (Miscellaneous Provisions) Regulations 2015 reg. 25.

How to fix

  • Add your company name, company number, where you're registered and your registered office to the footer or a legal information page.
Effort
Low
Who usually does this
Your web developer, a few minutes.

Back to summary

Important Compliance · Accessibility rulesP1-22

Images are missing text alternatives

What we saw

9 of 24 images on the homepage have no text alternative, including the photos of the cake range.

Why it matters

Screen-reader users get no description of images without alt text.

Reference: WCAG 2.2 AA 1.1.1; Equality Act 2010.

How to fix

  • Add a short description to each image that carries meaning.
  • Mark purely decorative images so screen readers skip them.
Effort
Low to medium
Who usually does this
Your web developer or whoever edits your content, an hour or two.

Back to summary

Minor Compliance · Privacy noticeP1-06

Privacy policy does not say how long data is kept

What we saw

The privacy policy does not say how long order and enquiry details are kept.

Why it matters

People must be told the retention period or the criteria used to set it.

Reference: UK GDPR Article 13(2)(a).

How to fix

  • Say how long you keep each kind of data, for example enquiries, customer records and analytics.
Effort
Low
Who usually does this
You or whoever looks after your policies, under an hour.

Back to summary

Minor Compliance · Marketing claimsNeeds checkingP1-26

Superlative or performance claims that need evidence on file

What we saw

The homepage says "the best sourdough on the coast". Keep evidence on file for claims like this.

This is a signal rather than a conclusion: a person should confirm it on the live site.

Why it matters

Objective claims such as "best", "number one" or "guaranteed" results must be backed by evidence held before the claim is made.

Reference: CAP Code rules 3.7 and 3.33 (substantiation), DMCCA 2024.

How to fix

  • For each "best", "number one" or performance claim, keep evidence on file, or soften the wording.
Effort
Low
Who usually does this
You, an hour or so.

Back to summary

Findability: 5 findings

Important Findability · Page titles and structureP2-11

Page titles are missing, duplicated or poorly sized

What we saw

4 of the 7 pages read share the title "Home | Harbour Lane Bakery".

Why it matters

The title is the main line shown in search results.

Reference: Google Search Central: title links.

How to fix

  • Give every page its own clear title, roughly 30 to 60 characters, that says what the page is about.
Effort
Low to medium
Who usually does this
You or whoever edits your content, an hour or two.

Back to summary

Important Findability · Local searchP2-16

No hidden business summary for search engines (structured data with your name, address and phone)

What we saw

No LocalBusiness or Bakery structured data with the name, address and phone number was found.

Why it matters

Schema confirms the business name, location and contact details to search engines and AI assistants.

Reference: Google Search Central: Organization and LocalBusiness structured data.

How to fix

  • Add a hidden business summary with your name, address, phone, logo and profile links.
  • Check it with Google's free Rich Results Test.
Effort
Low
Who usually does this
Your web developer, under an hour. Often a plugin or setting.

Back to summary

Minor Findability · Search engine basicsP2-04

The sitemap isn't mentioned in the site's crawler rules (robots.txt)

What we saw

robots.txt does not include a Sitemap line.

Why it matters

Listing the sitemap in robots.txt lets every crawler find it.

Reference: Sitemaps protocol.

How to fix

  • Add a line pointing to your sitemap in the crawler rules file.
Effort
Low
Who usually does this
Your web developer, a few minutes.

Back to summary

Minor Findability · Page titles and structureP2-12

Pages are missing meta descriptions

What we saw

5 of the 7 pages read have no meta description.

Why it matters

Without one, search engines pick text from the page, often badly.

Reference: Google Search Central: snippets.

How to fix

  • Write a short, unique summary for each key page, roughly 120 to 160 characters.
Effort
Low to medium
Who usually does this
You or whoever edits your content, an hour or two.

Back to summary

Minor Findability · AI assistantsP2-20

The business summary doesn't link to your official profiles

What we saw

The business summary has no sameAs links to the bakery's Instagram or Facebook pages.

Why it matters

sameAs links tie the website to the business's LinkedIn, Companies House and review profiles, which helps AI answers and knowledge panels.

Reference: Google Search Central: Organization structured data.

How to fix

  • Add links to your official profiles (such as LinkedIn) to the hidden business summary.
Effort
Low
Who usually does this
Your web developer, a few minutes.

Back to summary

Experience: 3 findings

Important Experience · SpeedP3-04

Google's mobile speed test gives a low score

What we saw

Google's mobile speed score is 41 out of 100. The largest image on the homepage is a 3.8 MB photo.

Why it matters

Slow mobile pages lose visitors before they see the offer.

Reference: Lighthouse performance guidance.

How to fix

  • Compress and resize images, remove scripts you don't need, and stop content jumping as it loads.
Effort
Medium
Who usually does this
Your web developer, half a day to a day.

Back to summary

Minor Experience · Easy to use for everyoneP3-07

No skip-to-content link

What we saw

No skip-to-content link was found on the homepage.

Why it matters

Keyboard users must tab through the whole menu on every page.

Reference: WCAG 2.2 AA 2.4.1 (bypass blocks).

How to fix

  • Add a "Skip to content" link at the very top of each page for keyboard users.
Effort
Low
Who usually does this
Your web developer, under an hour.

Back to summary

Minor Experience · Enquiries and contactP3-13

Enquiry form asks for a lot of information

What we saw

The cake order form asks for 14 details, including date of birth.

Why it matters

Every extra required field reduces enquiries and may collect more than needed.

Reference: UK GDPR Article 5(1)(c) (data minimisation); conversion good practice.

How to fix

  • Cut the form down to what you need for a first reply, usually name, email and a message.
Effort
Low
Who usually does this
You decide; your web developer makes the change. Under an hour.

Back to summary

Trust and security: 11 findings

Critical Trust and security · Platform and softwareP4-28

Some add-ons (plugins or themes) have known security problems

What we saw

bakeshop-orders 2.3.1 (a made-up add-on for this example): 2 known problems, for example "Order details can be downloaded without logging in". Example data only, so no vulnerability record links are shown.

Why it matters

Add-ons are the most common way WordPress sites are broken into. These versions have published security problems.

Reference: UK GDPR Article 32; NCSC guidance on keeping software up to date.

How to fix

  • Take a backup, then update each add-on listed.
  • If no fixed version exists, replace or remove the add-on.
  • Remove add-ons you don't use.
Effort
Low to medium
Who usually does this
Your web developer, an hour or two. Urgent if any are marked critical.

Back to summary

Important Trust and security · Website securityP4-02

Browsers aren't told to always use the secure version of the site

What we saw

No Strict-Transport-Security header was sent.

Why it matters

HSTS stops downgrade attacks on public wifi.

Reference: NCSC and OWASP secure headers guidance.

How to fix

  • Turn on the setting that tells browsers to always use the secure version of your site (HSTS).
Effort
Low
Who usually does this
Your web developer or hosting support, a few minutes. Often a Cloudflare or hosting setting.

Back to summary

Important Trust and security · Trackers and third partiesP4-12

Trackers on the site are not named in the privacy or cookie policy

What we saw

Meta Pixel and Hotjar load on the site, but neither is named in the privacy or cookie policy.

Why it matters

Visitors must be told which third parties receive their data.

Reference: UK GDPR Article 13(1)(e) (recipients); PECR Regulation 6.

How to fix

  • List each third-party tool, what it's for and who provides it in your cookie or privacy policy.
Effort
Low to medium
Who usually does this
You or whoever looks after your policies, an hour or two.

Back to summary

Important Trust and security · Email securityP4-21

Email providers aren't told to reject fake emails from your domain (DMARC missing or monitoring only)

What we saw

The DMARC record is set to p=none, so fake emails from the domain are only monitored, not rejected.

Why it matters

DMARC tells mail servers to reject email that pretends to be from you.

Reference: NCSC email security guidance.

How to fix

  • Add a DMARC record with reporting, then, once your real email passes, tell providers to quarantine or reject fakes.
Effort
Low to medium
Who usually does this
Whoever manages your domain or email, an hour now and a check-in a few weeks later.

Back to summary

Important Trust and security · Platform and softwareP4-31

Anyone can see a list of the files in a folder

What we saw

/wp-content/uploads/ shows a list of its files.

Why it matters

A file list can reveal documents, backups or uploads that were never meant to be found.

Reference: UK GDPR Article 32; OWASP information exposure guidance.

How to fix

  • Turn off folder listings on the server.
  • Look through the folder for old files, backups or documents that should not be public, and remove them.
Effort
Low
Who usually does this
Your web developer or hosting support, under an hour.

Back to summary

Minor Trust and security · Website securityP4-03

No browser rules limiting which scripts can run (Content Security Policy)

What we saw

No Content-Security-Policy header was sent.

Why it matters

A CSP limits the damage of injected scripts.

Reference: OWASP secure headers guidance.

How to fix

  • Add browser rules listing where scripts and styles may load from, starting in a "report only" mode so nothing breaks.
Effort
Medium
Who usually does this
Your web developer, a few hours including testing.

Back to summary

Minor Trust and security · Trust signalsP4-15

Copyright year in the footer is out of date

What we saw

The footer says "© 2023".

Why it matters

An old year makes the site look abandoned.

Reference: Trust good practice.

How to fix

  • Update the copyright year in the footer, or set it to update itself.
Effort
Low
Who usually does this
Your web developer, a few minutes.

Back to summary

Minor Trust and security · Email securityP4-24

No security contact file for people reporting problems (security.txt)

What we saw

No /.well-known/security.txt with a Contact line.

Why it matters

Tells researchers how to report a security problem to you.

Reference: RFC 9116; NCSC vulnerability disclosure toolkit.

How to fix

  • Publish a small security contact file so people can report problems to you.
Effort
Low
Who usually does this
Your web developer, a few minutes.

Back to summary

Minor Trust and security · Platform and softwareP4-27

The website software is not the latest version

What we saw

The site runs WordPress 6.5.2. The latest version is 7.1.2.

Why it matters

Older versions miss improvements and, sooner or later, security fixes.

Reference: NCSC guidance on keeping software up to date.

How to fix

  • Take a backup, then update WordPress from the dashboard and check the site still works.
Effort
Low
Who usually does this
Your web developer, or whoever looks after the site, under an hour.

Back to summary

Minor Trust and security · Platform and softwareP4-29

Some add-ons (plugins or themes) are out of date

What we saw

3 add-ons are behind the latest version: bakeshop-orders 2.3.1 (latest 2.6.0), harbour-gallery 1.0.4 (latest 1.2.1) and simple-opening-hours 3.1 (latest 3.4).

Why it matters

Out-of-date add-ons are a common way in for attackers, and can break when WordPress updates.

Reference: NCSC guidance on keeping software up to date.

How to fix

  • Take a backup, then update the add-ons listed and check the site still works.
  • Turn on automatic updates for add-ons from trusted makers.
Effort
Low
Who usually does this
Your web developer, or whoever looks after the site, under an hour.

Back to summary

Minor Trust and security · Platform and softwareP4-32

The website software version is shown publicly

What we saw

The page code says WordPress 6.5.2.

Why it matters

Showing the exact version makes it easy for automated attacks to target known weaknesses.

Reference: OWASP information exposure guidance.

How to fix

  • Hide the software version from the page code (a setting or small add-on).
  • Delete the default readme file.
Effort
Low
Who usually does this
Your web developer, a few minutes.

Back to summary

Tips

Good practice worth knowing about. Tips aren't problems and don't count towards your score.

TipTrust and security · Platform and softwareP4-33

The login page is at the standard address

What we saw

The WordPress login page is open at /wp-login.php, as it is on most WordPress sites. We did not try to log in. It is worth checking every account has a strong password and two-step login.

Why it's worth a look

Automated tools try passwords on standard login pages all day. Strong passwords and a second login step keep them out.

What to do

  • Make sure every login uses a strong, unique password and two-step verification.
  • Limit repeated login attempts with a security add-on or your host's settings.
  • Remove old or unused accounts.
Effort
Low
Who usually does this
Your web developer, under an hour.

Back to summary

What we couldn't check this time

These checks couldn't be completed automatically, usually because a page is built with scripts or a service didn't respond. They are not counted against you.

  • P3-03: Real visitors find the site slow by Google's measures (Core Web Vitals)
  • P4-09: Low security grade from Mozilla's free website security test

Scores by topic

Some areas need a human eye, so the automated check caps them at 80. The expert audit can score them fully.

AreaTopicScoreNote
CompliancePrivacy notice74
ComplianceCookies and consent45
CompliancePricing and consumer law80Partly automated
ComplianceBusiness details80
ComplianceAccessibility rules80
ComplianceMarketing claims80Capped at 80
FindabilitySearch engine basics94
FindabilityPage titles and structure74Partly automated
FindabilityLocal search80Partly automated
FindabilityAI assistants94
FindabilityContent and credibility80Capped at 80
ExperienceSpeed80
ExperienceClear next steps80Capped at 80
ExperienceMobile80Capped at 80
ExperienceEasy to use for everyone94
ExperienceEnquiries and contact80Capped at 80
Trust and securityWebsite security74
Trust and securityTrackers and third parties80
Trust and securityTrust signals80Capped at 80
Trust and securityMeasuring results100
Trust and securityEmail security74
Trust and securityPlatform and software17

What happens next

You've seen what needs doing. Here are your options.

Fix it yourself

If you or someone on your team is comfortable working on the site, the guidance above shows what's involved. Run the free check again afterwards to see what's cleared.

Pass this report to your current provider

Send them this report. It's worth asking them why these weren't raised, and how they'll stop them coming back.

Let serva.digital fix it

You shouldn't have to chase these. I'll fix them for an agreed price and keep an eye on your site so they don't creep back.

You'll get a fixed quote for the items you choose, with the £29 you paid for this report credited against the work if you go ahead within 90 days. When it's done, your site is checked again so you can see each item is fixed.

If you'd like, ongoing care is available from £10 a month, matched to what your site needs, so issues like these are caught early.

Ask for a fixed quote

No obligation. Prices are fixed and agreed in writing before any work starts. No VAT is charged.

Would you rather a person went through the whole site first? The expert audit covers the things an automated check can't judge, with a walkthrough call and a written summary. It costs £149 to £199, depending on the size of the site, and the £29 you paid for this report is credited against it if you book within 90 days. About the expert audit

David Allison, serva.digital

How this check works

  • We read your public pages (home, about, contact, privacy, cookies, terms, order). We never log in, submit forms or try to break in.
  • We also make a few ordinary requests that any browser could make, to see whether files that should be private (such as /.env or /.git/) can be opened, whether a folder lists its files, and which software versions the site shows. We don't keep the contents of any private file.
  • Software versions are compared with WordPress.org, Wordfence Intelligence and retire.js. Certificate dates come from public certificate logs (Cert Spotter, by SSLMate) and domain renewal dates from the domain registry.
  • Your homepage was loaded in a real browser located in the UK to see what runs before anyone agrees to cookies.
  • Speed and accessibility scores come from Google PageSpeed Insights. The security grade comes from Mozilla's free website security test (not available this time).
  • Rules version 2026-10-04.6.

This report is an automated check of publicly visible pages on the date shown. It is indicative and is not legal advice. Items marked "needs checking" are signals, not conclusions. Material compliance points should be confirmed with a qualified adviser.