{
  "exported_at": "2026-09-30T10:03:06.141223Z",
  "kind": "page",
  "target": "https://artificialatheist.com",
  "run_id": "72ee321fc4284e42950d9d03f84447ad",
  "status": "done",
  "stats": {
    "pages": 20,
    "templates": 19,
    "cache_hits": 19,
    "findings_by_severity": {
      "moderate": 56,
      "minor": 34,
      "serious": 10,
      "info": 38
    },
    "duration_secs": 8.27,
    "tokens": {
      "input": 0,
      "output": 0,
      "cache_read": 0,
      "cache_write": 0
    },
    "tokens_by_model": {},
    "estimated_cost_usd": 0.0
  },
  "findings": [
    {
      "type": "finding",
      "id": 1415,
      "url": "https://artificialatheist.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1416,
      "url": "https://artificialatheist.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 1417,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "serious",
      "title": "Lighthouse Performance score: 0.4",
      "detail": "Lighthouse category 'Performance' scored 0.4 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.4
      }
    },
    {
      "type": "finding",
      "id": 1418,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1419,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1420,
      "url": "https://artificialatheist.com",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., broad allowances such as 'unsafe-inline'/'unsafe-eval' or missing directives like script-src/object-src/base-uri), which reduces its effectiveness as a mitigation against XSS. On a content-heavy site with third-party embeds and no visible auth surface, the practical impact is moderate rather than critical, but a weak CSP fails to compensate for any future injection bugs (e.g., in comment/search features). Remediation: adopt a strict CSP with nonce- or hash-based script-src, restrict object-src 'none', default-src 'self', and explicit frame-ancestors to also cover clickjacking, avoiding 'unsafe-inline'/'unsafe-eval'.",
      "evidence": {
        "selector": "header:Content-Security-Policy",
        "snippet": "CSP present but permissive",
        "note": "Exact header value not provided; assessed from triage flag description"
      }
    },
    {
      "type": "finding",
      "id": 1421,
      "url": "https://artificialatheist.com",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "moderate",
      "title": "Article thumbnail images lack meaningful alt text",
      "detail": "Article card images (e.g. what-the-nervous-system-of-c-elegans...png, secularism-and-the-court-witness...png) have empty alt=\"\" while being wrapped in links to the articles. Since adjacent text (headline) already conveys the link purpose in most cards, the empty alt is acceptable per 1.1.1 as long as the image is purely decorative. However, in cases where the image is the ONLY content inside a link (e.g. the top featured article's image link with aria-label present, that one is fine), any card image-link that lacks an accessible name/adjacent text label leaves screen reader users with an unlabeled link announced only as the URL or nothing, violating 2.4.4 Link Purpose and 4.1.2 Name/Role/Value. Fix: keep alt=\"\" only when the image is inside a link that also contains descriptive text; otherwise add descriptive alt text or aria-label identifying the article the image links to.",
      "evidence": {
        "selector": "section img[alt='']",
        "note": "Some image links (e.g. secularism-and-the-court-witness) appear to combine image+title text in a single <a>, which is acceptable; but if any purely image-only links exist without text/aria-label, they fail 2.4.4/4.1.2."
      }
    },
    {
      "type": "finding",
      "id": 1422,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1423,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 1424,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.65",
      "detail": "Lighthouse category 'Performance' scored 0.65 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.65
      }
    },
    {
      "type": "finding",
      "id": 1425,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1426,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1427,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak Content-Security-Policy allows injection/clickjacking exposure",
      "detail": "The site's CSP does not sufficiently restrict script-src/frame-ancestors/object-src, leaving it more exposed to XSS payload execution if any injection point exists (e.g., search input reflected without proper encoding) and to framing/clickjacking if frame-ancestors is absent. On a content site with a client-side search feature and third-party ad/analytics scripts, a permissive or missing CSP increases the blast radius of any single injection bug from contained to fully exploitable (arbitrary script execution, credential/session theft, malicious redirects). Remediation: adopt a strict CSP with explicit script-src allowlist (nonce/hash-based), object-src 'none', base-uri 'self', and frame-ancestors 'self' (or 'none'), then iteratively tighten while auditing third-party script needs.",
      "evidence": {
        "note": "reported as weak CSP by triage; header value not fully specified"
      }
    },
    {
      "type": "finding",
      "id": 1428,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/3.3.2",
      "severity": "minor",
      "title": "Search input relies on placeholder/aria-label only, no visible label",
      "detail": "Low-vision users and users with cognitive disabilities benefit from a persistent visible label rather than a placeholder that disappears on input; the aria-label 'Search articles' does satisfy 4.1.2 Name, Role, Value and provides an accessible name for screen readers, so this is a minor usability concern rather than a hard barrier. Fix: add a visible <label> (can be visually styled minimally) associated with the input in addition to the aria-label to aid all users, especially those who zoom or have memory/cognitive impairments.",
      "evidence": {
        "selector": "input[type=search]",
        "note": "placeholder='Search articles', aria-label='Search articles'"
      }
    },
    {
      "type": "finding",
      "id": 1429,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 1430,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 1431,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 1432,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "document-title",
      "severity": "serious",
      "title": "Documents must have <title> element to aid in navigation",
      "detail": "Ensure each HTML document contains a non-empty <title> element https://dequeuniversity.com/rules/axe/4.10/document-title?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.text-alternatives",
          "wcag2a",
          "wcag242",
          "TTv5",
          "TT12.a",
          "EN-301-549",
          "EN-9.2.4.2",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1433,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "html-has-lang",
      "severity": "serious",
      "title": "<html> element must have a lang attribute",
      "detail": "Ensure every HTML document has a lang attribute https://dequeuniversity.com/rules/axe/4.10/html-has-lang?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.language",
          "wcag2a",
          "wcag311",
          "TTv5",
          "TT11.a",
          "EN-301-549",
          "EN-9.3.1.1",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1434,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "landmark-one-main",
      "severity": "moderate",
      "title": "Document should have one main landmark",
      "detail": "Ensure the document has a main landmark https://dequeuniversity.com/rules/axe/4.10/landmark-one-main?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.semantics",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1435,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "page-has-heading-one",
      "severity": "moderate",
      "title": "Page should contain a level-one heading",
      "detail": "Ensure that the page, or at least one of its frames contains a level-one heading https://dequeuniversity.com/rules/axe/4.10/page-has-heading-one?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.semantics",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1436,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "region",
      "severity": "moderate",
      "title": "All page content should be contained by landmarks",
      "detail": "Ensure all page content is contained by landmarks https://dequeuniversity.com/rules/axe/4.10/region?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "pre",
            "snippet": "<pre style=\"word-wrap: break-word; white-space: pre-wrap;\">"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.keyboard",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1437,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse-unavailable",
      "severity": "info",
      "title": "Lighthouse unavailable",
      "detail": "could not parse lighthouse output (rc=1): Unterminated string starting at: line 806 column 21 (char 130799). stderr: Runtime error encountered: The page provided is not HTML (served as MIME type text/plain).\n",
      "evidence": {}
    },
    {
      "type": "finding",
      "id": 1438,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1439,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 1440,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "serious",
      "title": "Lighthouse Performance score: 0.38",
      "detail": "Lighthouse category 'Performance' scored 0.38 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.38
      }
    },
    {
      "type": "finding",
      "id": 1441,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1442,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1443,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative-style empty alt on article card thumbnails is acceptable but redundant link text should be checked",
      "detail": "The article card images use alt=\"\" which is appropriate since each card already has an adjacent text link containing the full article title, making the image purely decorative/redundant. This is not a barrier for screen-reader users since the link text conveys the same information via the wrapping <a> element. No fix needed if images are purely illustrative thumbnails with no unique informational content (e.g., author photos, diagrams). If any thumbnail conveys unique meaning not present in the title/text (e.g., an infographic teaser), it should have descriptive alt text instead of empty alt.",
      "evidence": {
        "selector": "main a img[alt='']",
        "note": "criterion 1.1.1"
      }
    },
    {
      "type": "finding",
      "id": 1444,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1445,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 1446,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.58",
      "detail": "Lighthouse category 'Performance' scored 0.58 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.58
      }
    },
    {
      "type": "finding",
      "id": 1447,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1448,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1449,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or overly permissive Content-Security-Policy",
      "detail": "The flagged CSP appears weak, likely including broad source allowances (e.g. 'unsafe-inline', 'unsafe-eval', or wildcard host sources) that undermine its ability to mitigate XSS and data-injection attacks. For a static content site this may be low practical risk if no user input is rendered, but any third-party embeds (analytics, Ko-fi widget, images) increase the attack surface if injected via a compromised dependency. Recommend tightening script-src/style-src to specific hosts or nonces/hashes, avoiding 'unsafe-inline'/'unsafe-eval', and ensuring frame-ancestors is set to mitigate clickjacking (compensating for any missing X-Frame-Options). Without the exact policy text, this is flagged for confirmation of scope rather than definitive exploitability.",
      "evidence": {
        "note": "Actual CSP header value not provided in evidence; assessment based on triage flag reasoning."
      }
    },
    {
      "type": "finding",
      "id": 1450,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Hero image alt text likely acceptable as decorative",
      "detail": "The hero image accompanying the article title appears to be a generic/stock illustration rather than content-bearing (common pattern for blog hero images). Empty alt='' is appropriate if the image conveys no information beyond what the headline and body text already provide, so screen-reader users are not blocked from any unique content. However, if the image contains a diagram or visual representation specific to the multiverse concept (e.g., branching universes, illustrative model) that aids comprehension, the empty alt would fail 1.1.1 for low-vision/screen-reader users who cannot perceive that visual context. Fix: confirm image content; if purely decorative/stock, empty alt is correct, otherwise add a concise descriptive alt (e.g., 'Illustration of branching parallel universes').",
      "evidence": {
        "selector": "img[src='what-the-multiverse-hypothesis-actually-predicts.png']",
        "note": "escalate:false"
      }
    },
    {
      "type": "finding",
      "id": 1451,
      "url": "https://artificialatheist.com/posts/the-argument-from-morality-does-ethics-need-a-divine-anchor/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1452,
      "url": "https://artificialatheist.com/posts/the-argument-from-morality-does-ethics-need-a-divine-anchor/",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 1453,
      "url": "https://artificialatheist.com/posts/the-argument-from-morality-does-ethics-need-a-divine-anchor/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.62",
      "detail": "Lighthouse category 'Performance' scored 0.62 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.62
      }
    },
    {
      "type": "finding",
      "id": 1454,
      "url": "https://artificialatheist.com/posts/the-argument-from-morality-does-ethics-need-a-divine-anchor/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1455,
      "url": "https://artificialatheist.com/posts/the-argument-from-morality-does-ethics-need-a-divine-anchor/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1456,
      "url": "https://artificialatheist.com/posts/the-argument-from-morality-does-ethics-need-a-divine-anchor/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears to permit broad script sources or lacks strict directives (e.g., missing 'script-src' nonce/hash restriction, allowing 'unsafe-inline' or wildcard hosts), which reduces its effectiveness as a defense-in-depth control against XSS. On a content site with no visible user-generated input fields in this page's skeleton, direct injection risk is lower, but a weak CSP still fails to mitigate risk from third-party scripts, compromised CDN dependencies, or future injection points (e.g., search functionality noted in the header). Remediation: adopt a strict CSP using nonces or hashes for scripts, avoid 'unsafe-inline'/'unsafe-eval', restrict 'default-src' to 'self' plus explicitly trusted origins, and set 'frame-ancestors' to prevent clickjacking (which also mitigates any missing X-Frame-Options).",
      "evidence": {
        "snippet": "N/A"
      }
    },
    {
      "type": "finding",
      "id": 1457,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1458,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 1459,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.54",
      "detail": "Lighthouse category 'Performance' scored 0.54 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.54
      }
    },
    {
      "type": "finding",
      "id": 1460,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1461,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1462,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "minor",
      "title": "Weak or missing Content-Security-Policy",
      "detail": "The site appears to lack a strong Content-Security-Policy (e.g., no restrictive script-src/frame-ancestors directives), which reduces defense-in-depth against XSS if any injection point is later introduced. This is a static, content-only site (blog posts, topic listings) with no visible forms, search input reflection, or user-generated content in the skeleton, which lowers real exploitability. Recommend adding a CSP with script-src 'self' and object-src 'none', plus frame-ancestors 'self' to mitigate clickjacking and reduce blast radius of any future injection bug.",
      "evidence": {
        "selector": "response headers",
        "note": "CSP header absent or weak per triage flag"
      }
    },
    {
      "type": "finding",
      "id": 1463,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative bullet character not hidden from assistive tech",
      "detail": "Each of the 19 post-card links begins with a '\u25cf' character that appears to be a decorative separator/marker rather than meaningful content. If this glyph is not wrapped in an element with aria-hidden='true', screen reader users will hear 'circle' or 'bullet' announced before every single link name across the whole list, adding noise but not blocking comprehension since the following title text is unique and descriptive. Fix: wrap the bullet in a <span aria-hidden='true'> or remove it from the accessible name so only the article title is announced.",
      "evidence": {
        "selector": "main a",
        "note": "Link text begins with '\u25cf Title...' repeated pattern"
      }
    },
    {
      "type": "finding",
      "id": 1464,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/2.4.4",
      "severity": "minor",
      "title": "Redundant topic name repeated inside link text",
      "detail": "Link accessible names appear to concatenate the topic label ('Secularism') plus the full post title (e.g. 'Secularism Secularism and the Court Witness: Truth Without God...'), duplicating the word 'Secularism'. This does not block understanding for screen reader users since the title itself is unique and descriptive per link, but it adds redundant verbosity when navigating by link list, mildly slowing comprehension for screen reader users skimming links. Fix: move the topic label out of the anchor's accessible name (e.g. as a separate visually-hidden or aria-hidden label) so each link's name is just the post title.",
      "evidence": {
        "selector": "main a[href*='/posts/']",
        "note": "Link text: 'Secularism Secularism and the Court Witness...'"
      }
    },
    {
      "type": "finding",
      "id": 1465,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1466,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 1467,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.53",
      "detail": "Lighthouse category 'Performance' scored 0.53 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.53
      }
    },
    {
      "type": "finding",
      "id": 1468,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1469,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1470,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or overly permissive Content-Security-Policy",
      "detail": "A weak CSP (e.g. broad use of 'unsafe-inline'/'unsafe-eval', wildcard sources, or missing directives like script-src/object-src/frame-ancestors) reduces the effectiveness of CSP as a mitigation against XSS and clickjacking. On a content site with third-party embeds (e.g. ko-fi widget), some permissiveness may be needed, but directives should be scoped to specific trusted hosts rather than wildcards or 'unsafe-inline'. Recommend tightening script-src/style-src to nonce/hash-based allowances, explicitly listing required third-party origins, and adding frame-ancestors/object-src 'none' to reduce injection and framing risk.",
      "evidence": {
        "note": "Policy observed as weak/permissive per triage; exact header value not shown in provided evidence."
      }
    },
    {
      "type": "finding",
      "id": 1471,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative hero image alt text likely appropriate",
      "detail": "The hero image appears to be a generic illustrative/stock graphic accompanying an opinion article title, not conveying unique information not already present in the H1 and surrounding text. Empty alt='' is an acceptable pattern here for screen-reader users, who will simply skip it, as long as the image truly is decorative and doesn't contain embedded text or data. If the image contains any text, charts, or symbolic content specific to the article's argument, it should instead have descriptive alt text. Recommend content author confirm the image has no informational content; otherwise add a concise alt description.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "secularism-and-the-political-party-when-movements-organise.png"
      }
    },
    {
      "type": "finding",
      "id": 1472,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1473,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 1474,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.59",
      "detail": "Lighthouse category 'Performance' scored 0.59 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.59
      }
    },
    {
      "type": "finding",
      "id": 1475,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1476,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1477,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The CSP header appears to lack strong restrictions (e.g., allows 'unsafe-inline'/'unsafe-eval' or overly broad source lists), reducing its effectiveness as a mitigation against XSS and data injection. Since this is a mostly static content site without visible dynamic user input, the practical exploit surface is limited, but a weak CSP still fails to provide defense-in-depth against any future injection point (e.g., compromised third-party script such as analytics or ad tags). Remediation: tighten CSP to avoid 'unsafe-inline'/'unsafe-eval', use nonces or hashes for inline scripts, and restrict script-src/object-src/base-uri to self and explicitly trusted origins.",
      "evidence": {
        "note": "CSP directive weakness inferred from triage flag; exact header value not provided in evidence"
      }
    },
    {
      "type": "finding",
      "id": 1478,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1479,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 1480,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.6",
      "detail": "Lighthouse category 'Performance' scored 0.6 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.6
      }
    },
    {
      "type": "finding",
      "id": 1481,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1482,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1483,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak Content-Security-Policy permits inline script execution",
      "detail": "The CSP appears to lack strict script-src restrictions (e.g., allows 'unsafe-inline' or is otherwise permissive), which undermines its effectiveness as a mitigation against reflected/stored XSS. On a content site with no visible user-input forms in the skeleton, the immediate injection surface is low, but any future comment/search functionality or third-party script (analytics, Ko-fi embed) could be leveraged if an injection point is found. Remediation: adopt a strict CSP using nonces or hashes for legitimate inline scripts, avoid 'unsafe-inline' and 'unsafe-eval', and restrict script-src to self and explicitly trusted origins.",
      "evidence": {
        "note": "CSP directive weakness flagged in triage; no frame-ancestors or nonce-based script-src confirmed to compensate"
      }
    },
    {
      "type": "finding",
      "id": 1484,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative-looking hero image correctly given empty alt, but verify content relevance",
      "detail": "The article header image (the-afterlife-assumption...png) has alt=\"\" which is appropriate if the image is purely decorative/illustrative and adds no information beyond the headline. Since the image appears to be an abstract/thematic illustration accompanying the post title rather than conveying unique content (e.g., a chart, diagram, or photo of a specific referenced subject), empty alt is likely correct per 1.1.1 guidance for decorative images. However, if the image contains any text or meaningfully illustrates a concept discussed in the article, screen reader users would miss that context. Recommend confirming image content is purely decorative; if so, current empty alt is fine, otherwise add a concise descriptive alt text.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Same pattern repeated on related-post thumbnail image, also empty alt - consistent decorative treatment suggests intentional design choice."
      }
    },
    {
      "type": "finding",
      "id": 1485,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1486,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 1487,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.65",
      "detail": "Lighthouse category 'Performance' scored 0.65 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.65
      }
    },
    {
      "type": "finding",
      "id": 1488,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1489,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1490,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "A weak CSP (e.g. allowing 'unsafe-inline' or broad script-src wildcards) reduces the effectiveness of CSP as a defense-in-depth control against XSS. On a content site with search functionality and article rendering, any injection point (e.g. search query reflection, comment/markdown rendering) could be leveraged for stored/reflected XSS without a strict policy to block inline script execution. Remediate by adopting a nonce- or hash-based script-src, disallowing 'unsafe-inline'/'unsafe-eval', and restricting object-src/base-uri/frame-ancestors to 'none' or 'self' where feasible.",
      "evidence": {
        "note": "CSP header present but permissive per triage flag; exact directive values not provided in skeleton"
      }
    },
    {
      "type": "finding",
      "id": 1491,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Hero image alt text is empty but likely appropriate as decorative",
      "detail": "The article hero image (the-concept-of-supervenience...png) has alt=\"\". If this image is purely a decorative illustration accompanying the title and adds no information beyond the heading/text, empty alt is the correct WCAG 1.1.1 treatment and is not a barrier for screen-reader users, who will simply skip it. However, if the image conveys unique content (e.g., a diagram illustrating the philosophical concept), it should have descriptive alt text; currently a screen-reader user gets no indication of any visual content tied to the article. Recommend author confirm whether the image is purely decorative stock art (keep alt='') or conceptually informative (add descriptive alt text). Same issue exists on the related-post thumbnail image.",
      "evidence": {
        "selector": "img[alt='']",
        "note": "the-concept-of-supervenience-when-one-level-rests-on-another.png and the-gambler-s-fallacy...png both have alt=''"
      }
    },
    {
      "type": "finding",
      "id": 1492,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1493,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 1494,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "serious",
      "title": "Lighthouse Performance score: 0.49",
      "detail": "Lighthouse category 'Performance' scored 0.49 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.49
      }
    },
    {
      "type": "finding",
      "id": 1495,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1496,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1497,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or missing Content-Security-Policy",
      "detail": "The page appears to lack a strict CSP (or uses a permissive one), which reduces defense-in-depth against XSS if any injection point exists (e.g., search, quiz scoring logic, or DOM-based rendering of quiz content). Without directives like default-src 'self', script-src with nonces/hashes, and object-src 'none', any injected script would execute unrestricted. Recommend deploying a strict CSP (script-src 'self' plus nonces, frame-ancestors 'self', object-src 'none') and testing in report-only mode first. No other compensating controls (e.g., Trusted Types, SRI enforcement) were observed in the provided headers.",
      "evidence": {
        "note": "absent or weak Content-Security-Policy header value not shown as strict"
      }
    },
    {
      "type": "finding",
      "id": 1498,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/2.4.7",
      "severity": "moderate",
      "title": "Quiz option buttons may lack visible focus indicator",
      "detail": "Keyboard-only users need a clear visual indicator of which control has focus when tabbing through the 'Random mix', 'By topic', and 'Start random quiz' buttons. If these custom <button> elements rely on default browser outline that has been suppressed by CSS (common with custom-styled buttons), keyboard users cannot tell which option is selected before activating it. Fix: ensure a visible, high-contrast focus outline (min 3:1 contrast, 2px offset) is present on :focus-visible for all buttons, and verify it is not removed via outline:none without a replacement.",
      "evidence": {
        "selector": "main section button[type='button']",
        "note": "Three sibling buttons with no visible state distinction described in skeleton"
      }
    },
    {
      "type": "finding",
      "id": 1499,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/4.1.2",
      "severity": "moderate",
      "title": "Toggle-style quiz option buttons lack ARIA state for selection",
      "detail": "The 'Random mix' and 'By topic' buttons appear to represent mutually exclusive choices (like a radio/tab selection) but are plain <button> elements without aria-pressed, aria-selected, or role='radio' to convey the chosen state to screen reader users. A screen reader user tabbing through cannot determine which mode is currently selected. Fix: add aria-pressed (if toggle buttons) or implement as a radiogroup/tablist with proper roles and aria-checked/aria-selected states that update as selection changes.",
      "evidence": {
        "selector": "button:contains('Random mix'), button:contains('By topic')",
        "note": "No aria-pressed or role attributes shown in skeleton, unlike header buttons which correctly use aria-pressed"
      }
    },
    {
      "type": "finding",
      "id": 1500,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1501,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 1502,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "serious",
      "title": "Lighthouse Performance score: 0.42",
      "detail": "Lighthouse category 'Performance' scored 0.42 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.42
      }
    },
    {
      "type": "finding",
      "id": 1503,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1504,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1505,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or missing Content-Security-Policy",
      "detail": "No robust CSP with restrictive script-src/object-src/frame-ancestors was observed. Without a strong CSP, any injected markup (e.g., via a compromised comment field, third-party script, or CMS vulnerability) could execute arbitrary JavaScript (XSS) or be framed for clickjacking. Even a static-content blog benefits from a CSP scoping allowed script/style/img sources and setting frame-ancestors/base-uri/object-src 'none', since it mitigates impact of any future injection point (e.g., search, comments) and third-party embeds (Ko-fi, analytics). Recommend defining an explicit allowlist CSP rather than relying on default-src '*' or an absent header, and pairing with X-Content-Type-Options: nosniff.",
      "evidence": {
        "selector": "header/CSP",
        "note": "CSP header absent or overly permissive; no frame-ancestors/script-src restriction confirmed in provided headers"
      }
    },
    {
      "type": "finding",
      "id": 1506,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Empty alt text on decorative-looking hero and article thumbnail images likely acceptable, but should be verified",
      "detail": "The hero image and related-post thumbnail images use alt=\"\", which is appropriate if these images are purely decorative (e.g., generic stock/illustration accompanying the article title, which is already conveyed by the adjacent heading text). Screen reader users would not be blocked from content since the alt='' causes these images to be skipped rather than announced as unlabeled. However, if any of these images convey information not present in surrounding text (e.g., a diagram, chart, or a picture that supports understanding of the article's argument), empty alt violates 1.1.1 Non-text Content and would leave screen-reader users without equivalent information. Recommend confirming with content authors that all such images are decorative; if any carry semantic meaning, add descriptive alt text.",
      "evidence": {
        "selector": "img[alt='']",
        "note": "Applies to secularism-and-the-court-witness... hero image and secularism-and-the-political-party... thumbnail"
      }
    },
    {
      "type": "finding",
      "id": 1507,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1508,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 1509,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.58",
      "detail": "Lighthouse category 'Performance' scored 0.58 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.58
      }
    },
    {
      "type": "finding",
      "id": 1510,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1511,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1512,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., overly broad source lists or missing directives such as script-src/object-src/frame-ancestors), which reduces its effectiveness as a defense-in-depth control against XSS and clickjacking. Given this is a content site rendering AI-generated posts and images, a weak CSP increases the blast radius if any injection vector (e.g., stored content, third-party widget, or ad script) is compromised. No compensating controls (e.g., strict frame-ancestors or X-Frame-Options) were observed in the provided headers to offset this. Remediation: define a strict CSP with explicit script-src/style-src allowlists or nonces, restrict object-src to 'none', and set frame-ancestors to 'self' or 'none' to prevent framing attacks.",
      "evidence": {
        "note": "CSP flagged as weak by triage; specific directive values not provided in headers snapshot"
      }
    },
    {
      "type": "finding",
      "id": 1513,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/2.4.4",
      "severity": "moderate",
      "title": "Truncated article preview link text may reduce clarity",
      "detail": "Screen reader users navigating by links or link lists will hear the full concatenated text (title plus truncated excerpt ending mid-sentence, e.g. 'it's worth asking what a p') since the entire preview block is wrapped in a single anchor. While the article title itself is present and likely sufficient to satisfy 2.4.4 at a minimum level, the abrupt truncation of the excerpt is confusing and adds noise, making the link's purpose harder to parse quickly. Fix: truncate excerpt text at a natural word/sentence boundary with an ellipsis, or move the excerpt outside the anchor (or mark it aria-hidden) so only the article title is announced as the link text, with the full excerpt available as visible supplementary text.",
      "evidence": {
        "selector": "main a[href*='/posts/machine-authored-inquiry/']",
        "snippet": "'News What Machine-Authored Inquiry Can Be Now that AI can write clearly about hard questions, it's worth asking what a p'"
      }
    },
    {
      "type": "finding",
      "id": 1514,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.3.1",
      "severity": "minor",
      "title": "Redundant topic label prefixed inside link text",
      "detail": "Each preview link begins with the topic name ('News') duplicating the page context already conveyed by the h1 and nav, which adds redundant verbosity to link announcements for screen reader users and could be better marked up as a separate, non-linked category label distinct from the link name.",
      "evidence": {
        "selector": "main a"
      }
    },
    {
      "type": "finding",
      "id": 1515,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1516,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 1517,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "serious",
      "title": "Lighthouse Performance score: 0.46",
      "detail": "Lighthouse category 'Performance' scored 0.46 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.46
      }
    },
    {
      "type": "finding",
      "id": 1518,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1519,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1520,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or absent Content-Security-Policy",
      "detail": "The site appears to lack a strong CSP (no restrictive script-src/frame-ancestors observed). For a static content/blog site this limits defense-in-depth against XSS from third-party scripts, ad/analytics tags, or compromised dependencies, and does not mitigate clickjacking unless frame-ancestors or X-Frame-Options is separately set. Since content is AI-generated and published without apparent user-input surfaces, injection risk is lower than on interactive apps, but any future comment/search functionality or third-party widget could be leveraged for stored/reflected XSS with no CSP backstop. Remediation: implement a CSP with script-src limited to self and specific trusted hosts, object-src 'none', frame-ancestors 'self', and base-uri 'self'.",
      "evidence": {
        "note": "No strong CSP directives observed in response headers; page has a client-side search feature (/search/) increasing reflected-input surface"
      }
    },
    {
      "type": "finding",
      "id": 1521,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/2.1.1",
      "severity": "serious",
      "title": "Text-resize controls not keyboard operable",
      "detail": "The 'Smaller text' and 'Larger text' controls are implemented as <div role=\"button\"> elements. Native semantics of a div do not include keyboard focus or Enter/Space activation, so unless custom tabindex and keydown handlers were added, keyboard-only users cannot tab to or activate these controls. Fix: use native <button> elements, or add tabindex=\"0\" plus keydown handlers for Enter/Space, ensuring visible focus indication (2.4.7).",
      "evidence": {
        "selector": "div[role=button][aria-label='Smaller text'], div[role=button][aria-label='Larger text']",
        "note": "Confirmed via triage that no keyboard handlers were detected"
      }
    },
    {
      "type": "finding",
      "id": 1522,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/4.1.2",
      "severity": "moderate",
      "title": "aria-pressed state may not update correctly on custom buttons",
      "detail": "Screen reader users rely on aria-pressed to know whether toggle buttons are in an active state. If the div-based buttons only respond to mouse click events, aria-pressed will never update for keyboard users, and if JS doesn't toggle the attribute programmatically, SR users get inaccurate state information. Verify that activating via keyboard also toggles aria-pressed, or switch to native <button aria-pressed> which handles focus/activation robustly.",
      "evidence": {
        "selector": "div[role=button][aria-pressed='false']",
        "note": "State management should be verified via testing"
      }
    },
    {
      "type": "finding",
      "id": 1523,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.4.4",
      "severity": "minor",
      "title": "Toggle mode button lacks aria-pressed state",
      "detail": "The 'Toggle light or dark mode' div-button has no aria-pressed or aria-checked attribute to communicate current mode state to assistive technology users, unlike the text-resize buttons. This is a minor Name/Role/Value gap (4.1.2) that should be reviewed alongside the resize controls fix for consistency.",
      "evidence": {
        "selector": "div[role=button][aria-label='Toggle light or dark mode']"
      }
    },
    {
      "type": "finding",
      "id": 1524,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1525,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 1526,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.63",
      "detail": "Lighthouse category 'Performance' scored 0.63 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.63
      }
    },
    {
      "type": "finding",
      "id": 1527,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1528,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1529,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or missing Content-Security-Policy",
      "detail": "No response headers were provided showing a robust CSP (e.g., script-src restrictions, frame-ancestors). Without a strict CSP, the site has reduced defense-in-depth against XSS and clickjacking; a compromised third-party script or reflected injection point could execute arbitrary JS in the browser context. Given the static, template-driven nature of this blog (no visible user input forms besides search), risk is somewhat mitigated but not eliminated \u2014 the search feature and any future comment/embed functionality would be exposed. Remediate by adding a CSP with at minimum default-src 'self', restrictive script-src (avoiding 'unsafe-inline'/'unsafe-eval'), and frame-ancestors 'none' or 'self' to also cover clickjacking protection.",
      "evidence": {
        "selector": "response headers",
        "note": "No CSP header value was supplied in the evidence; treated as absent/weak based on triage flag."
      }
    },
    {
      "type": "finding",
      "id": 1530,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Article hero image uses empty alt text",
      "detail": "The image at the top of the article (what-the-nervous-system-of-c-elegans-actually-taught-us.png) has alt=\"\". If this image is purely decorative/stock illustration and conveys no information beyond the adjacent heading, empty alt is actually the correct WCAG 1.1.1 treatment and no fix is needed. However, if the image contains diagram content relevant to understanding the connectome discussion (e.g., an actual neuron map), screen reader users get no equivalent information and this becomes a real barrier. Recommend confirming image content: if decorative, leave empty alt (current state is fine); if it conveys substantive information, add a concise descriptive alt text summarizing the diagram/photo content. Same pattern repeats on the related-post thumbnail image.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Downgraded from 'serious' since empty alt on hero/thumbnail images is a common valid decorative pattern; severity depends on actual image content which cannot be confirmed from skeleton alone."
      }
    },
    {
      "type": "finding",
      "id": 1531,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1532,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 1533,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.59",
      "detail": "Lighthouse category 'Performance' scored 0.59 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.59
      }
    },
    {
      "type": "finding",
      "id": 1534,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1535,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1536,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "minor",
      "title": "Weak or overly permissive Content-Security-Policy",
      "detail": "The site's CSP appears relaxed (e.g. broad script-src/style-src allowances or missing frame-ancestors/object-src restrictions), reducing its effectiveness as a defense-in-depth control against XSS and clickjacking. On a content site with no visible user input surfaces or auth flows, the practical exploitation risk is low, but tightening script-src/style-src to specific hosts, adding object-src 'none', base-uri 'self', and frame-ancestors 'self' would meaningfully reduce residual injection/clickjacking risk with minimal disruption to functionality. Recommend auditing actual directive values and removing 'unsafe-inline'/'unsafe-eval' if present, replacing with nonces/hashes.",
      "evidence": {
        "note": "CSP header value not fully provided; flagged as weak per triage \u2014 recommend confirming directive-by-directive."
      }
    },
    {
      "type": "finding",
      "id": 1537,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/2.1.1",
      "severity": "serious",
      "title": "Custom div-based buttons may not be keyboard operable",
      "detail": "Keyboard-only users may be unable to activate the 'Smaller text', 'Larger text', and 'Toggle light or dark mode' controls because they are implemented as <div role=\"button\"> elements rather than native <button> elements. Divs are not natively focusable or triggerable via Enter/Space unless tabindex and keydown handlers are explicitly added. Without inspecting the JS, this is a high-risk pattern that frequently fails 2.1.1 Keyboard. Fix: use native <button> elements, or ensure tabindex=\"0\" plus keydown handlers for Enter/Space are implemented.",
      "evidence": {
        "selector": "div[role=button]",
        "note": "header controls"
      }
    },
    {
      "type": "finding",
      "id": 1538,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/2.4.7",
      "severity": "moderate",
      "title": "Missing visible focus indicator on custom buttons",
      "detail": "Low-vision and keyboard-only users rely on a visible focus outline to track their position on the page. Custom div-based buttons often have default browser focus styles suppressed by CSS resets without a replacement, meaning users tabbing through the header cannot see which control is focused. Fix: ensure a clearly visible focus outline (e.g. via :focus-visible) is present on all three custom controls, meeting 2.4.7 Focus Visible.",
      "evidence": {
        "selector": "div[role=button]",
        "note": "text size and theme toggle buttons"
      }
    },
    {
      "type": "finding",
      "id": 1539,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/4.1.2",
      "severity": "moderate",
      "title": "Toggle mode button lacks accessible name and state text",
      "detail": "The 'Toggle light or dark mode' button has an aria-label but no visible text content, and unlike the text-size buttons it lacks aria-pressed, so screen reader users cannot determine whether dark mode is currently on or off. Fix: add aria-pressed reflecting current state, consistent with the other two buttons.",
      "evidence": {
        "selector": "div[role=button][aria-label='Toggle light or dark mode']",
        "note": "criterion 4.1.2"
      }
    },
    {
      "type": "finding",
      "id": 1540,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1541,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 1542,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.57",
      "detail": "Lighthouse category 'Performance' scored 0.57 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.57
      }
    },
    {
      "type": "finding",
      "id": 1543,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1544,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1545,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The CSP appears to lack sufficiently restrictive script-src/style-src directives (or relies on 'unsafe-inline'/broad wildcards), reducing its effectiveness as a mitigation against XSS. Since this is a content publishing site with no visible user-input forms in the skeleton, the practical injection surface is limited, but any future comment/search functionality or third-party script inclusion would be at higher risk. Recommend tightening CSP to use nonces/hashes for scripts, avoid 'unsafe-inline' and wildcard sources, and add frame-ancestors and base-uri directives.",
      "evidence": {
        "note": "specific header value not provided in evidence; assessed as weak based on triage flag"
      }
    },
    {
      "type": "finding",
      "id": 1546,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1547,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 1548,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.58",
      "detail": "Lighthouse category 'Performance' scored 0.58 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.58
      }
    },
    {
      "type": "finding",
      "id": 1549,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1550,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1551,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or ineffective Content-Security-Policy",
      "detail": "The CSP present on this page appears weak (e.g., overly permissive source lists, missing script-src restriction, or reliance on 'unsafe-inline'/'unsafe-eval'), which reduces its effectiveness as a mitigation against XSS and data injection. Given the site renders user-agnostic static content but also loads images and scripts from third parties, a weak CSP does not provide meaningful compensating control against injection if any input reflection or third-party script compromise occurs. Remediation: adopt a strict CSP using nonces or hashes for scripts, restrict object-src/base-uri/frame-ancestors, and avoid unsafe-inline/unsafe-eval directives.",
      "evidence": {
        "note": "policy directives observed as overly permissive or incomplete based on triage flag; no strong script-src/object-src restrictions confirmed"
      }
    },
    {
      "type": "finding",
      "id": 1552,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative empty alt on post-card thumbnails is likely acceptable but should be verified for content-bearing images",
      "detail": "Post-card images (e.g. what-the-nervous-system-of-c-elegans-actually-taught-us.png) use alt=\"\" while the adjacent link text already contains the full article title and teaser text. For screen-reader users this is fine if the images are purely illustrative/stock-style graphics, since the redundant text is already exposed via the link. However, if any of these images convey unique information (e.g. diagrams, charts, or photos with meaning not stated in the surrounding text), empty alt would hide that content from screen-reader and low-vision (image-off) users. Fix: confirm each image is purely decorative; for any that carry unique meaning, supply a concise descriptive alt text instead of empty alt.",
      "evidence": {
        "selector": "main a img[alt='']",
        "note": "18+ similar cards on page, all with empty alt"
      }
    }
  ],
  "errors": []
}