{
  "exported_at": "2026-09-30T10:05:42.960957Z",
  "kind": "page",
  "target": "https://capcrop.com",
  "run_id": "52b9b36d9e6140b983c1bdb3e15c9b94",
  "status": "done",
  "stats": {
    "pages": 10,
    "templates": 9,
    "cache_hits": 8,
    "findings_by_severity": {
      "serious": 28,
      "moderate": 12,
      "minor": 27,
      "info": 35
    },
    "duration_secs": 40.81,
    "tokens": {
      "input": 10415,
      "output": 1187,
      "cache_read": 0,
      "cache_write": 0
    },
    "tokens_by_model": {
      "claude-haiku-4-5": {
        "input": 2464,
        "output": 330,
        "cache_read": 0,
        "cache_write": 0
      },
      "claude-sonnet-5": {
        "input": 7951,
        "output": 857,
        "cache_read": 0,
        "cache_write": 0
      }
    },
    "estimated_cost_usd": 0.0408
  },
  "findings": [
    {
      "type": "finding",
      "id": 626,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 627,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 628,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 629,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 630,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 631,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 632,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 633,
      "url": "https://capcrop.com",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": ".signup-card > .signup > form > button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          },
          {
            "selector": ".refer",
            "snippet": "<span class=\"promo-tag refer\">Refer &amp; earn</span>"
          },
          {
            "selector": ".cta-band > .signup > form > button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          },
          {
            "selector": ".val",
            "snippet": "<span class=\"ochip val\">a $6 value</span>"
          }
        ],
        "node_count": 5,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 634,
      "url": "https://capcrop.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.83",
      "detail": "Lighthouse category 'Performance' scored 0.83 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.83
      }
    },
    {
      "type": "finding",
      "id": 635,
      "url": "https://capcrop.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.95",
      "detail": "Lighthouse category 'Accessibility' scored 0.95 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.95
      }
    },
    {
      "type": "finding",
      "id": 636,
      "url": "https://capcrop.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 637,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 638,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 639,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 640,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 641,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 642,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 643,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 644,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 645,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 646,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.95",
      "detail": "Lighthouse category 'Accessibility' scored 0.95 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.95
      }
    },
    {
      "type": "finding",
      "id": 647,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 648,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 649,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 650,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 651,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 652,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 653,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 654,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 655,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 656,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 657,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.94",
      "detail": "Lighthouse category 'Accessibility' scored 0.94 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.94
      }
    },
    {
      "type": "finding",
      "id": 658,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 659,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 660,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 661,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 662,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 663,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 664,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 665,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 666,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 667,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 668,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.95",
      "detail": "Lighthouse category 'Accessibility' scored 0.95 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.95
      }
    },
    {
      "type": "finding",
      "id": 669,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 670,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 671,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 672,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 673,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 674,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 675,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 676,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 677,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 678,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 679,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.94",
      "detail": "Lighthouse category 'Accessibility' scored 0.94 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.94
      }
    },
    {
      "type": "finding",
      "id": 680,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 681,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 682,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 683,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 684,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 685,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 686,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 687,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 688,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 689,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 690,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.94",
      "detail": "Lighthouse category 'Accessibility' scored 0.94 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.94
      }
    },
    {
      "type": "finding",
      "id": 691,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 692,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 693,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 694,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 695,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 696,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 697,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 698,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 699,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 700,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 0.99",
      "detail": "Lighthouse category 'Performance' scored 0.99 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.99
      }
    },
    {
      "type": "finding",
      "id": 701,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.95",
      "detail": "Lighthouse category 'Accessibility' scored 0.95 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.95
      }
    },
    {
      "type": "finding",
      "id": 702,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 703,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 704,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 705,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 706,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 707,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 708,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 709,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 710,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 711,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 712,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.95",
      "detail": "Lighthouse category 'Accessibility' scored 0.95 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.95
      }
    },
    {
      "type": "finding",
      "id": 713,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 714,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 715,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 716,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 717,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 718,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 719,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 720,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 721,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 722,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 723,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.94",
      "detail": "Lighthouse category 'Accessibility' scored 0.94 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.94
      }
    },
    {
      "type": "finding",
      "id": 724,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 725,
      "url": "https://capcrop.com",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.4.3",
      "severity": "serious",
      "title": "Low-contrast text on marketing landing page",
      "detail": "Low-vision users may be unable to read body copy, labels, or CTA text if text/background contrast falls below the 4.5:1 (normal text) or 3:1 (large text) thresholds. This is common on marketing pages using light-gray text on white backgrounds for subheads, disclaimers ('No spam...'), and secondary CTAs. Since this cannot be fully confirmed from the DOM skeleton alone, a visual/computed-style check is needed on: hero subtext, form helper text, checkbox label text, and badge/credit copy. Fix: ensure all text meets WCAG AA contrast ratios, particularly for muted/secondary text styles, using a contrast checker against actual rendered colors.",
      "evidence": {
        "selector": "body copy, form labels, section descriptions",
        "note": "Requires rendered-color inspection to confirm exact failing elements; flagged as likely given typical marketing site styling of muted secondary text."
      }
    },
    {
      "type": "finding",
      "id": 726,
      "url": "https://capcrop.com",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/3.3.1",
      "severity": "moderate",
      "title": "No visible error identification for email signup forms",
      "detail": "Screen-reader and low-vision users submitting an invalid or empty email have no indication in the skeleton of an error message region (e.g., aria-live announcement or inline error text) tied to the input. WCAG 3.3.1 requires errors be identified in text and programmatically associated with the field. Without this, a keyboard/screen-reader user who mistypes an email may not know submission failed. Fix: add an aria-live polite error container next to each email input that displays specific error text and is referenced via aria-describedby.",
      "evidence": {
        "selector": "form input[type=email]",
        "note": "no error message elements or aria-describedby present in skeleton"
      }
    },
    {
      "type": "finding",
      "id": 727,
      "url": "https://capcrop.com",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/4.1.3",
      "severity": "moderate",
      "title": "No status message for successful submission",
      "detail": "Users relying on assistive technology have no way to perceive confirmation that their email was successfully submitted, since no aria-live region or role=status is present for success feedback. This violates 4.1.3 Status Messages, which requires success/error states to be announced without requiring focus to move. Fix: add a role='status' or aria-live='polite' region that announces 'Thanks, you're on the list' after successful submission.",
      "evidence": {
        "selector": "form",
        "note": "duplicate forms both lack a visible/programmatic success indicator"
      }
    }
  ],
  "errors": []
}