{
  "exported_at": "2026-09-30T10:05:01.613286Z",
  "kind": "page",
  "target": "https://capcrop.com",
  "run_id": "2e3ad2ac703145488f8c6b32ad690800",
  "status": "done",
  "stats": {
    "pages": 10,
    "templates": 9,
    "cache_hits": 8,
    "findings_by_severity": {
      "serious": 28,
      "moderate": 11,
      "minor": 27,
      "info": 35
    },
    "duration_secs": 42.29,
    "tokens": {
      "input": 13093,
      "output": 1124,
      "cache_read": 0,
      "cache_write": 0
    }
  },
  "findings": [
    {
      "type": "finding",
      "id": 323,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 324,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 325,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 326,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 327,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 328,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 329,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 330,
      "url": "https://capcrop.com",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": ".signup-card > .signup > form > button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          },
          {
            "selector": ".refer",
            "snippet": "<span class=\"promo-tag refer\">Refer &amp; earn</span>"
          },
          {
            "selector": ".cta-band > .signup > form > button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          },
          {
            "selector": ".val",
            "snippet": "<span class=\"ochip val\">a $6 value</span>"
          }
        ],
        "node_count": 5,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 331,
      "url": "https://capcrop.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.8",
      "detail": "Lighthouse category 'Performance' scored 0.8 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.8
      }
    },
    {
      "type": "finding",
      "id": 332,
      "url": "https://capcrop.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.95",
      "detail": "Lighthouse category 'Accessibility' scored 0.95 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.95
      }
    },
    {
      "type": "finding",
      "id": 333,
      "url": "https://capcrop.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 334,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 335,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 336,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 337,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 338,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 339,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 340,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 341,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 342,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 343,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.94",
      "detail": "Lighthouse category 'Accessibility' scored 0.94 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.94
      }
    },
    {
      "type": "finding",
      "id": 344,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 345,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 346,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 347,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 348,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 349,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 350,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 351,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 352,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 353,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 354,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.94",
      "detail": "Lighthouse category 'Accessibility' scored 0.94 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.94
      }
    },
    {
      "type": "finding",
      "id": 355,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 356,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 357,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 358,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 359,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 360,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 361,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 362,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 363,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 364,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 365,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.95",
      "detail": "Lighthouse category 'Accessibility' scored 0.95 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.95
      }
    },
    {
      "type": "finding",
      "id": 366,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 367,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 368,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 369,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 370,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 371,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 372,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 373,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 374,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 375,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 376,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.95",
      "detail": "Lighthouse category 'Accessibility' scored 0.95 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.95
      }
    },
    {
      "type": "finding",
      "id": 377,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 378,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 379,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 380,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 381,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 382,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 383,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 384,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 385,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 386,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 387,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.95",
      "detail": "Lighthouse category 'Accessibility' scored 0.95 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.95
      }
    },
    {
      "type": "finding",
      "id": 388,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 389,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 390,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 391,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 392,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 393,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 394,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 395,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 396,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 397,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 398,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.94",
      "detail": "Lighthouse category 'Accessibility' scored 0.94 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.94
      }
    },
    {
      "type": "finding",
      "id": 399,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 400,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 401,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 402,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 403,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 404,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 405,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 406,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 407,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 408,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 409,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.94",
      "detail": "Lighthouse category 'Accessibility' scored 0.94 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.94
      }
    },
    {
      "type": "finding",
      "id": 410,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 411,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 412,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 413,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 414,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 415,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 416,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 417,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 418,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 419,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 0.99",
      "detail": "Lighthouse category 'Performance' scored 0.99 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.99
      }
    },
    {
      "type": "finding",
      "id": 420,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.95",
      "detail": "Lighthouse category 'Accessibility' scored 0.95 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.95
      }
    },
    {
      "type": "finding",
      "id": 421,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 422,
      "url": "https://capcrop.com",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.4.3",
      "severity": "serious",
      "title": "Insufficient color contrast on page text/UI elements",
      "detail": "Low-vision users may be unable to read body copy, badges, or button labels (e.g., 'Private beta \u00b7 opening soon', hashtag pills, radio labels in the 'What you get' section) if text/background contrast falls below the required 4.5:1 (or 3:1 for large text/UI components per 1.4.11). Axe-core flagged this as serious; a manual check of computed colors for hero subtext, form placeholder text, and the aria-hidden decorative badges rendered as visible content should be performed. Fix: verify all text and interactive control colors against their backgrounds meet 4.5:1 (normal text) or 3:1 (large text/graphical objects), especially subtle gray-on-white or light pastel button/pill styling common in marketing pages.",
      "evidence": {
        "selector": "body text, .badge/hashtag pills, form inputs/buttons",
        "note": "axe-core serious flag; needs manual contrast verification per component/state"
      }
    },
    {
      "type": "finding",
      "id": 423,
      "url": "https://capcrop.com",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/3.3.1",
      "severity": "moderate",
      "title": "No visible or programmatic error feedback on email signup forms",
      "detail": "Screen-reader and low-vision users submitting an invalid or empty email get no confirmation that validation failed beyond native browser tooltips, which are not reliably announced by assistive tech and may not appear at all if custom JS intercepts submission. Both the header/hero form and the bottom 'Be first through the door' form use only `required` and `type=email` with no visible error text, no `aria-invalid`, and no `aria-describedby` pointing to an error message. Fix: on failed validation, render a visible error message adjacent to the field, set `aria-invalid=\"true\"` on the input, and associate the message via `aria-describedby` so both sighted and screen-reader users are informed of the specific problem and how to fix it.",
      "evidence": {
        "selector": "form input[type=email]",
        "note": "Applies to both signup forms on the page"
      }
    }
  ],
  "errors": []
}