{
  "exported_at": "2026-09-30T10:03:52.477920Z",
  "kind": "page",
  "target": "https://artificialatheist.com",
  "run_id": "617fca5feaac4b0c93080644057760d8",
  "status": "done",
  "stats": {
    "pages": 20,
    "templates": 19,
    "cache_hits": 5,
    "findings_by_severity": {
      "moderate": 50,
      "info": 38,
      "serious": 3,
      "minor": 17
    },
    "duration_secs": 445.95,
    "tokens": {
      "input": 82375,
      "output": 10567,
      "cache_read": 0,
      "cache_write": 0
    },
    "tokens_by_model": {
      "claude-haiku-4-5": {
        "input": 24943,
        "output": 4366,
        "cache_read": 0,
        "cache_write": 0
      },
      "claude-sonnet-5": {
        "input": 57432,
        "output": 6201,
        "cache_read": 0,
        "cache_write": 0
      }
    },
    "estimated_cost_usd": 0.3121
  },
  "findings": [
    {
      "type": "finding",
      "id": 2309,
      "url": "https://artificialatheist.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2310,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.61",
      "detail": "Lighthouse category 'Performance' scored 0.61 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.61
      }
    },
    {
      "type": "finding",
      "id": 2311,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2312,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2313,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2314,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.57",
      "detail": "Lighthouse category 'Performance' scored 0.57 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.57
      }
    },
    {
      "type": "finding",
      "id": 2315,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2316,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2317,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2318,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.62",
      "detail": "Lighthouse category 'Performance' scored 0.62 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.62
      }
    },
    {
      "type": "finding",
      "id": 2319,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2320,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2321,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2322,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.58",
      "detail": "Lighthouse category 'Performance' scored 0.58 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.58
      }
    },
    {
      "type": "finding",
      "id": 2323,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2324,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2325,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2326,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.63",
      "detail": "Lighthouse category 'Performance' scored 0.63 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.63
      }
    },
    {
      "type": "finding",
      "id": 2327,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2328,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2329,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2330,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.68",
      "detail": "Lighthouse category 'Performance' scored 0.68 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.68
      }
    },
    {
      "type": "finding",
      "id": 2331,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2332,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2333,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2334,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.8",
      "detail": "Lighthouse category 'Performance' scored 0.8 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.8
      }
    },
    {
      "type": "finding",
      "id": 2335,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2336,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2337,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2338,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.86",
      "detail": "Lighthouse category 'Performance' scored 0.86 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.86
      }
    },
    {
      "type": "finding",
      "id": 2339,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2340,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2341,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2342,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.63",
      "detail": "Lighthouse category 'Performance' scored 0.63 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.63
      }
    },
    {
      "type": "finding",
      "id": 2343,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2344,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2345,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 2346,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 2347,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 2348,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "document-title",
      "severity": "serious",
      "title": "Documents must have <title> element to aid in navigation",
      "detail": "Ensure each HTML document contains a non-empty <title> element https://dequeuniversity.com/rules/axe/4.10/document-title?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.text-alternatives",
          "wcag2a",
          "wcag242",
          "TTv5",
          "TT12.a",
          "EN-301-549",
          "EN-9.2.4.2",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2349,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "html-has-lang",
      "severity": "serious",
      "title": "<html> element must have a lang attribute",
      "detail": "Ensure every HTML document has a lang attribute https://dequeuniversity.com/rules/axe/4.10/html-has-lang?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.language",
          "wcag2a",
          "wcag311",
          "TTv5",
          "TT11.a",
          "EN-301-549",
          "EN-9.3.1.1",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2350,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "landmark-one-main",
      "severity": "moderate",
      "title": "Document should have one main landmark",
      "detail": "Ensure the document has a main landmark https://dequeuniversity.com/rules/axe/4.10/landmark-one-main?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.semantics",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2351,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "page-has-heading-one",
      "severity": "moderate",
      "title": "Page should contain a level-one heading",
      "detail": "Ensure that the page, or at least one of its frames contains a level-one heading https://dequeuniversity.com/rules/axe/4.10/page-has-heading-one?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.semantics",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2352,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "region",
      "severity": "moderate",
      "title": "All page content should be contained by landmarks",
      "detail": "Ensure all page content is contained by landmarks https://dequeuniversity.com/rules/axe/4.10/region?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "pre",
            "snippet": "<pre style=\"word-wrap: break-word; white-space: pre-wrap;\">"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.keyboard",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2353,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse-unavailable",
      "severity": "info",
      "title": "Lighthouse unavailable",
      "detail": "could not parse lighthouse output (rc=1): Unterminated string starting at: line 806 column 21 (char 130799). stderr: Runtime error encountered: The page provided is not HTML (served as MIME type text/plain).\n",
      "evidence": {}
    },
    {
      "type": "finding",
      "id": 2354,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2355,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.87",
      "detail": "Lighthouse category 'Performance' scored 0.87 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.87
      }
    },
    {
      "type": "finding",
      "id": 2356,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2357,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2358,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2359,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.84",
      "detail": "Lighthouse category 'Performance' scored 0.84 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.84
      }
    },
    {
      "type": "finding",
      "id": 2360,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2361,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2362,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site includes interactive quiz functionality with client-side scoring logic, increasing the attack surface for DOM-based XSS if any user-controlled input is reflected into the page. A weak CSP (e.g., missing directives like script-src/object-src, or use of 'unsafe-inline'/'unsafe-eval') provides little defense-in-depth against injected scripts, meaning any XSS vulnerability discovered elsewhere (stored, reflected, or DOM-based) could be exploited without CSP mitigation. Remediation: implement a strict CSP with a nonce- or hash-based script-src, restrict object-src to 'none', and set base-uri and frame-ancestors explicitly rather than relying on default-src alone.",
      "evidence": {
        "note": "CSP header present but insufficiently restrictive per triage; no inline-script nonce/hash scheme apparent from skeleton (inline event-handling likely used for quiz buttons)."
      }
    },
    {
      "type": "finding",
      "id": 2363,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/4.1.3",
      "severity": "moderate",
      "title": "Quiz feedback and results may not be announced to screen reader users",
      "detail": "The quiz's scoring, validation, and result states appear to be dynamically rendered without visible ARIA live regions in the skeleton. If answer feedback, error states, or final scores are injected into the DOM without aria-live='polite' or role='status'/'alert', screen reader users won't know their answer was recorded, if they made an error, or what their final score is. This blocks blind/low-vision users from completing the quiz meaningfully. Fix: wrap dynamic feedback/result containers in an aria-live region (polite for score updates, assertive only for critical errors), and ensure focus is moved to the results summary when the quiz completes.",
      "evidence": {
        "selector": "main section (quiz container)",
        "note": "escalate:false"
      }
    },
    {
      "type": "finding",
      "id": 2364,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/3.3.1",
      "severity": "moderate",
      "title": "No visible error identification for unanswered/skipped questions",
      "detail": "If the quiz allows submission without answering, users need clear text-based error identification (not just color) describing which question needs a response. Skeleton shows no visible error text pattern; this should be verified in the live interactive quiz. Sighted keyboard users and screen reader users both need programmatically associated error text (e.g., via aria-describedby) rather than relying solely on visual cues like red borders.",
      "evidence": {
        "selector": "main section (quiz container)",
        "note": "criterion 3.3.1"
      }
    },
    {
      "type": "finding",
      "id": 2365,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/4.1.2",
      "severity": "moderate",
      "title": "Toggle buttons for quiz mode selection rely on aria-pressed but selection outcome may not be communicated",
      "detail": "The 'Random mix' and 'By topic' buttons use aria-pressed correctly for toggle state, but if selecting a mode changes subsequent question content/format without an announcement, screen reader users may not perceive the change in context (SC 3.2.2 On Input / 4.1.2). Verify that any dynamically appearing topic-selection sub-options are announced or at minimum keyboard-focusable in logical order after toggling.",
      "evidence": {
        "selector": "button[aria-pressed]",
        "note": "criterion 4.1.2, 3.2.2"
      }
    },
    {
      "type": "finding",
      "id": 2366,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2367,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.68",
      "detail": "Lighthouse category 'Performance' scored 0.68 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.68
      }
    },
    {
      "type": "finding",
      "id": 2368,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2369,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2370,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2371,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.84",
      "detail": "Lighthouse category 'Performance' scored 0.84 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.84
      }
    },
    {
      "type": "finding",
      "id": 2372,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2373,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2374,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2375,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.64",
      "detail": "Lighthouse category 'Performance' scored 0.64 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.64
      }
    },
    {
      "type": "finding",
      "id": 2376,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2377,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2378,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/4.1.2",
      "severity": "minor",
      "title": "Icon-only buttons have adequate aria-labels but state changes may not be announced",
      "detail": "The 'Smaller text', 'Larger text', and dark mode toggle buttons use aria-pressed to convey state, which is good, but verify that aria-pressed actually updates on activation via JS. If it does not update, screen reader users will not know the current state (font size level, light/dark mode), violating 4.1.2 Name, Role, Value. Fix: ensure aria-pressed is toggled programmatically on click and consider adding a visible/announced confirmation (e.g., via aria-live region) when text size or theme changes, since these actions have no visible label text to confirm the change occurred.",
      "evidence": {
        "selector": "button[aria-label='Toggle light or dark mode']",
        "note": "aria-pressed=false present in skeleton; must verify it updates dynamically"
      }
    },
    {
      "type": "finding",
      "id": 2379,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.4.1",
      "severity": "minor",
      "title": "Icon buttons rely solely on icon shape with no visible text label",
      "detail": "Low-vision users who don't use screen readers but rely on zoom/magnification may struggle to distinguish 'A' smaller vs 'A' larger buttons and the mode-toggle icon if visual size/contrast differences are subtle. While aria-label covers screen reader users, ensure sufficient visual distinction (size, color) between the two 'A' buttons for sighted users with low vision, per 1.4.1 Use of Color and general perceivability. Fix: use distinctly sized 'A' icons (small A vs large A) rather than identical size text, and ensure icons have programmatic tooltips/visible text on hover/focus for clarity.",
      "evidence": {
        "selector": "button[aria-label='Smaller text'], button[aria-label='Larger text']"
      }
    },
    {
      "type": "finding",
      "id": 2380,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2381,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.57",
      "detail": "Lighthouse category 'Performance' scored 0.57 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.57
      }
    },
    {
      "type": "finding",
      "id": 2382,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2383,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2384,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2385,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.74",
      "detail": "Lighthouse category 'Performance' scored 0.74 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.74
      }
    },
    {
      "type": "finding",
      "id": 2386,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2387,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2388,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2389,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.81",
      "detail": "Lighthouse category 'Performance' scored 0.81 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.81
      }
    },
    {
      "type": "finding",
      "id": 2390,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2391,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2392,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/3.3.2",
      "severity": "minor",
      "title": "Search input relies on placeholder + aria-label instead of visible label",
      "detail": "The search input has an aria-label ('Search articles') which satisfies 4.1.2 Name/Role/Value and gives screen-reader users an accessible name, but there is no visible <label>. Low-vision users, users with cognitive disabilities, and users who zoom text can lose the placeholder text once they focus/type in the field, leaving no persistent visible cue of the field's purpose. Fix: add a visible <label> (can be styled as a heading or use a visually-associated text near the input) rather than relying solely on placeholder/aria-label so the field's purpose remains visible during and after interaction.",
      "evidence": {
        "selector": "input[type=search]",
        "note": "aria-label present but no visible label text; placeholder disappears on input"
      }
    },
    {
      "type": "finding",
      "id": 2393,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2394,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.73",
      "detail": "Lighthouse category 'Performance' scored 0.73 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.73
      }
    },
    {
      "type": "finding",
      "id": 2395,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2396,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2397,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.3.1",
      "severity": "minor",
      "title": "FAQ heading structure lacks grouping semantics for answers",
      "detail": "Screen-reader users navigating by heading get h2 questions but answers appear as untagged text with no explicit programmatic association (e.g., via aria-expanded/disclosure pattern or adjacent landmark). If these are meant to be an accordion/FAQ list, add proper disclosure widget markup (button + aria-expanded + aria-controls) or ensure answer text immediately follows each h2 in reading order so the relationship is clear to AT users.",
      "evidence": {
        "selector": "main h2",
        "note": "h2 questions with no visible answer/button relationship in skeleton"
      }
    },
    {
      "type": "finding",
      "id": 2398,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/4.1.2",
      "severity": "minor",
      "title": "Text-resize buttons rely only on visual 'A' glyph plus aria-label",
      "detail": "The 'Smaller text'/'Larger text' buttons are properly labeled via aria-label, which is fine for screen readers, but low-vision users who zoom may not perceive the size difference between the two 'A' glyphs if custom font rendering doesn't scale them distinctly. Ensure visual size difference is sufficient (WCAG 1.4.1) - this is a minor usability note, not a name/role violation.",
      "evidence": {
        "selector": "button[aria-label='Smaller text'], button[aria-label='Larger text']"
      }
    },
    {
      "type": "finding",
      "id": 2399,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative icons correctly hidden but no redundant text confirmation for toggle state",
      "detail": "Dark/light mode toggle button and text-size buttons use aria-pressed to convey state, which is good, but the icon itself (aria-hidden) conveys no fallback text if aria-pressed isn't announced by a given AT/browser combination. Consider adding visually-hidden text reflecting current state (e.g., 'Dark mode: off') for robustness across assistive tech.",
      "evidence": {
        "selector": "button[aria-label='Toggle light or dark mode']"
      }
    },
    {
      "type": "finding",
      "id": 2400,
      "url": "https://artificialatheist.com",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative-style empty alt on article thumbnail images is acceptable given adjacent text link",
      "detail": "Screen-reader users encountering the article thumbnails (religion-by-inheritance, c-elegans, afterlife-assumption images) will not hear redundant descriptions, but each image is immediately followed by a heading link with the full article title (e.g. 'What the Nervous System of C. elegans Actually Taught Us'), so the empty alt='' is a valid pattern for images that are purely illustrative/duplicative of adjacent text rather than a barrier. No fix required if images truly add no unique content; if the images convey information not in the title (e.g., a diagram or photo relevant to understanding the topic), alt text should be added.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Empty alt is correct WCAG practice when image is redundant with adjacent link text, not a violation by itself."
      }
    },
    {
      "type": "finding",
      "id": 2401,
      "url": "https://artificialatheist.com",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/2.4.4",
      "severity": "moderate",
      "title": "Featured article image link has generic redundant accessible name",
      "detail": "The hero image link (aria-label='Religion by Inheritance: How Birth Predicts Belief') duplicates the immediately following h1 link of the same text, which is fine, but combined with an image that has alt='' inside it, a screen reader user tabbing through gets three consecutive identical-purpose links (image link, h1 link, 'Read' link) all pointing to the same URL with overlapping/duplicate names. This is not a hard failure but creates redundant navigation stops; keyboard/screen-reader users must tab through duplicate links to reach content. Consider combining the image and heading into a single link or marking the image link as decorative/skip.",
      "evidence": {
        "selector": "section a[aria-label]",
        "note": "Three separate anchors to the same destination in one card."
      }
    },
    {
      "type": "finding",
      "id": 2402,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or overly permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., allowing 'unsafe-inline'/'unsafe-eval' or broad source lists), which reduces its effectiveness as a mitigation against XSS and data injection. On a content-driven blog with no visible user-input forms in the skeleton, the immediate exploitation surface is limited, but any future injection point (comments, search, third-party embeds like Ko-fi widgets) would be under-protected. Remediation: tighten CSP to avoid 'unsafe-inline'/'unsafe-eval', use nonces or hashes for any inline scripts, and explicitly set default-src, script-src, and frame-ancestors directives rather than relying on defaults.",
      "evidence": {
        "note": "CSP directive values not fully enumerated in provided headers; flagged as weak per triage pipeline. No compensating strict directives observed to offset the weakness."
      }
    },
    {
      "type": "finding",
      "id": 2403,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Empty alt text on article preview images is likely appropriate",
      "detail": "Article preview images use alt=\"\" while the adjacent heading link (e.g. 'Secularism and the Court Witness: Truth Without God') provides the accessible name for the article card. This is the recommended pattern per WCAG 1.1.1 since the image is decorative/duplicative of text already present. No screen-reader user is blocked from differentiating articles because each card exposes a unique heading link; the icons (aria-hidden) are correctly hidden decorative glyphs. Downgrading the triage flag: this is not a barrier as implemented. If any card lacks a corresponding text heading/link, that specific image would need descriptive alt text instead.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Verify each article card has an accompanying non-empty heading/link text; if some cards omit a visible title, add descriptive alt text to those images."
      }
    },
    {
      "type": "finding",
      "id": 2404,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Hero image alt text likely acceptable but unverifiable as decorative",
      "detail": "The article hero image has alt=\"\" which is appropriate if the image is purely decorative/illustrative and does not convey information not already present in the heading/text. Since the filename suggests a generic thematic illustration (not a chart, photo of a specific event, or data visualization) and the article title/heading already conveys the topic, empty alt is likely correct per 1.1.1. However, this should be confirmed by a sighted reviewer viewing the actual rendered image: if it contains any text, data, or unique content (e.g., an infographic), screen-reader users would be blocked from that content and a descriptive alt is required. Fix: verify image content; if decorative, keep alt=\"\" (current state is fine); if informative, add a concise alt describing the depicted content.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "filename: religion-by-inheritance-how-birth-predicts-belief.png; used as hero for article of same title"
      }
    },
    {
      "type": "finding",
      "id": 2405,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or overly permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., allowing 'unsafe-inline'/'unsafe-eval' or broad wildcard sources), which reduces its effectiveness as a defense-in-depth control against XSS. Given this is a content-heavy site with search functionality and dynamically rendered article content, a weak CSP increases the blast radius if any injection vector (e.g., stored XSS via post content, search reflection) is found. Remediate by tightening script-src/style-src to specific hashes/nonces, removing 'unsafe-inline' and 'unsafe-eval', and adding frame-ancestors and object-src 'none' directives.",
      "evidence": {
        "note": "CSP header flagged as weak by triage; no specific directive values provided for confirmation"
      }
    },
    {
      "type": "finding",
      "id": 2406,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Hero image uses empty alt text without clear decorative justification",
      "detail": "The article hero image (secularism-and-the-political-party-when-movements-organise.png) has alt=\"\", treating it as purely decorative. If the image only illustrates the topic generically (e.g., a stock photo) and conveys no unique information, empty alt is actually the correct WCAG 1.1.1 treatment and not a barrier for screen-reader users, who will simply have it skipped. However, if the image contains any text, diagram, or specific visual meaning relevant to the article's content, screen-reader users would miss that information. Recommend confirming the image is purely decorative; if so, no fix needed, otherwise add a concise descriptive alt text summarizing its relevance to the secularism/political-party topic.",
      "evidence": {
        "selector": "article > img[alt='']",
        "note": "Same pattern repeats on the related-post thumbnail image, suggesting a site-wide convention of decorative hero images rather than a per-page authoring error."
      }
    },
    {
      "type": "finding",
      "id": 2407,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Hero image alt text likely acceptable but unverifiable decorative status",
      "detail": "The article hero image (what-the-nervous-system-of-c-elegans-actually-taught-us.png) has alt=\"\", marking it decorative. For a science blog post illustrating a worm's nervous system, this image is plausibly a generic/stock illustration rather than conveying unique content (e.g., a diagram with data), so empty alt is likely appropriate per 1.1.1 since the article text conveys the same information. However, if the image contains a diagram, chart, or specific visual information about the connectome not described in surrounding text, screen reader users would miss that content. Fix: confirm image is purely decorative/stock; if it contains explanatory diagrams or labels, add descriptive alt text summarizing the depicted content.",
      "evidence": {
        "selector": "article img[alt='']",
        "snippet": "<img alt=\"\" src=\"what-the-nervous-system-of-c-elegans-actually-taught-us.png\">",
        "note": "Same pattern repeated on related-post thumbnail image."
      }
    },
    {
      "type": "finding",
      "id": 2408,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or missing Content-Security-Policy",
      "detail": "No response headers were provided showing a strict CSP (e.g., no restrictive script-src/frame-ancestors directives observed). Without a CSP that restricts script sources, any injected markup (e.g., via a compromised comment, ad script, or third-party embed like ko-fi widget) could execute arbitrary JavaScript, enabling XSS, session theft, or defacement. This is a static content site with limited user input surface, which lowers exploitability, but the lack of a strong CSP removes a key defense-in-depth layer against supply-chain or third-party script compromise (e.g., the ko-fi.com embed). Remediation: implement a CSP with script-src restricted to self and explicitly trusted origins, avoid 'unsafe-inline'/'unsafe-eval', and set frame-ancestors to prevent clickjacking as a compensating control.",
      "evidence": {
        "selector": "header",
        "note": "CSP header not present or not strict in provided response headers metadata"
      }
    },
    {
      "type": "finding",
      "id": 2409,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Empty alt text on article hero image likely acceptable but unverified",
      "detail": "The hero image in the article (what-the-multiverse-hypothesis-actually-predicts.png) has alt=\"\", which is appropriate if the image is purely decorative/illustrative and conveys no information beyond the article title already in the H1. Screen-reader users are not blocked since the image is correctly hidden from the accessibility tree as decorative. However, if the image contains a diagram, chart, or specific illustrative content relevant to understanding the multiverse concept (e.g., a diagram of branching universes), the empty alt would deprive blind/low-vision screen-reader users of that content. Fix: confirm image intent; if purely decorative/stock-photo, empty alt is correct and no change needed; if it conveys unique content, add a concise descriptive alt text.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Applies to both the main article hero image and the related-post thumbnail image, both using empty alt.','criterion':'1.1.1'"
      }
    },
    {
      "type": "finding",
      "id": 2410,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., overly broad source lists or missing restrictive directives such as script-src/object-src/base-uri), which reduces its effectiveness as a defense-in-depth control against XSS and data injection. Static content sites like this have limited dynamic input surfaces, but any third-party embeds (Ko-fi widget, analytics, fonts) or future comment/search functionality would be exposed to injected script execution if an XSS vector is found elsewhere. Remediation: define a strict CSP with 'script-src 'self'' plus explicit trusted hosts, 'object-src none', 'base-uri self', and 'frame-ancestors' to also cover clickjacking, avoiding 'unsafe-inline'/'unsafe-eval' wherever possible.",
      "evidence": {
        "note": "CSP header present but permissive per triage; no nonce/hash-based script restriction observed"
      }
    },
    {
      "type": "finding",
      "id": 2411,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Article hero image has empty alt text",
      "detail": "The featured image at the top of the article (secularism-and-the-court-witness-truth-without-god.png) has alt=\"\", treating it as decorative. Given it's a generic stock/illustrative header image accompanying a text article and not referenced in body content, empty alt is likely appropriate per 1.1.1 (decorative images should be marked so, and this appears purely illustrative rather than conveying unique information). This is a low-risk pattern already used consistently across article cards, but should be verified that the image contains no text or diagram content essential to understanding the article; if it's purely a stylistic/thematic photo, current markup is acceptable. Flagging as minor only to confirm intent rather than a confirmed violation.",
      "evidence": {
        "selector": "article > img[alt='']",
        "note": "Consistent with related-post thumbnail also using alt=''\"; suggests deliberate decorative pattern, not a functional oversight."
      }
    },
    {
      "type": "finding",
      "id": 2412,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., allowing 'unsafe-inline'/broad script-src or missing object-src/base-uri restrictions), which reduces protection against injected script if any XSS vector is found (e.g., via search feature or comment rendering). A static blog with minimal dynamic input has lower exploitation likelihood, but the search page and templated content increase surface. Remediation: define a strict CSP with script-src limited to 'self' and specific hashes/nonces, avoid 'unsafe-inline', set object-src 'none', base-uri 'self', and frame-ancestors 'self' to also cover clickjacking. Verify no compensating strict-dynamic or nonce-based policy is already in place before treating as high risk.",
      "evidence": {
        "selector": "header:CSP",
        "note": "CSP directives observed as weak/permissive per triage; no nonce or strict-dynamic evidence found in skeleton or headers provided"
      }
    },
    {
      "type": "finding",
      "id": 2413,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Article thumbnail images have empty alt text",
      "detail": "Featured article images use alt=\"\" (e.g. what-the-nervous-system-of-c-elegans-actually-taught-us.png). Since each image sits beside a text link/heading with the same article title, treating them as decorative is defensible and not a barrier for screen-reader users \u2014 the link text already conveys the article's purpose (2.4.4). However, if these thumbnails are meant to visually differentiate topics or convey unique editorial content (e.g. an illustrative diagram), the empty alt would omit useful information for blind users. Recommend confirming they are purely decorative; if so, current markup is compliant, otherwise add concise descriptive alt text.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Image is adjacent to a duplicate-text heading link, mitigating harm; low confidence of real barrier."
      }
    },
    {
      "type": "finding",
      "id": 2414,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative hero image with empty alt is likely acceptable",
      "detail": "The hero image accompanying the article appears to be a generic decorative illustration rather than content conveying unique information (topic/title are already provided in adjacent text/heading). Empty alt is the correct pattern per WCAG 1.1.1 for decorative images, so this is not a barrier for screen-reader users provided the image truly adds no additional information beyond the headline. If the image contains meaningful text or data not present elsewhere, alt text should be added; otherwise no fix is needed.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Image alt is empty; same pattern repeated across article teaser thumbnails."
      }
    },
    {
      "type": "finding",
      "id": 2415,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., broad 'unsafe-inline'/'unsafe-eval' or missing script-src restrictions), which reduces defense-in-depth against XSS if any injection point is found (e.g., search feature, comment/AI content pipeline). While this is a static content site with no obvious user-input reflection in the skeleton, the presence of a search page and AI-generated content pipeline increases the value of a strict CSP as a compensating control. Remediation: define explicit script-src/style-src allowlists, avoid 'unsafe-inline', add object-src 'none', base-uri 'self', and frame-ancestors 'self' to also cover clickjacking protection.",
      "evidence": {
        "note": "Cak reported weak/absent strict CSP directives (script-src/style-src) \u2014 no nonce or hash-based script allowlisting observed"
      }
    },
    {
      "type": "finding",
      "id": 2416,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Article thumbnail images use empty alt text without clear justification",
      "detail": "Each article card includes a thumbnail image (e.g., 'the-concept-of-supervenience-when-one-level-rests-on-another.png') marked alt=\"\", which tells screen reader users to skip it entirely. If these images are purely decorative/stock illustrations that don't add information beyond the adjacent heading and summary, empty alt is correct and this is a non-issue. However, if the images are meant to visually reinforce or uniquely represent the article topic (as their file names suggest specific conceptual illustrations), screen reader users lose that supplementary context. Recommend confirming editorial intent: if decorative, current markup is fine; if meaningful, add concise descriptive alt text. Low confidence this blocks any critical task since title/summary text is already available as the link text.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "file names suggest topic-specific illustrations, not generic stock decoration"
      }
    }
  ],
  "errors": []
}