{
  "exported_at": "2026-09-30T10:04:43.930187Z",
  "kind": "page",
  "target": "https://artificialatheist.com",
  "run_id": "7e0d4308f9bf4595ad43a14bec85a3b3",
  "status": "done",
  "stats": {
    "pages": 20,
    "templates": 19,
    "findings_by_severity": {
      "moderate": 49,
      "info": 37,
      "serious": 3,
      "minor": 17
    },
    "duration_secs": 630.48,
    "tokens": {
      "input": 115934,
      "output": 15310,
      "cache_read": 0,
      "cache_write": 0
    },
    "tokens_by_model": {
      "claude-haiku-4-5": {
        "input": 31961,
        "output": 5921,
        "cache_read": 0,
        "cache_write": 0
      },
      "claude-sonnet-5": {
        "input": 83973,
        "output": 9389,
        "cache_read": 0,
        "cache_write": 0
      }
    },
    "estimated_cost_usd": 0.4543
  },
  "findings": [
    {
      "type": "finding",
      "id": 2601,
      "url": "https://artificialatheist.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2602,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.79",
      "detail": "Lighthouse category 'Performance' scored 0.79 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.79
      }
    },
    {
      "type": "finding",
      "id": 2603,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2604,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2605,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2606,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.59",
      "detail": "Lighthouse category 'Performance' scored 0.59 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.59
      }
    },
    {
      "type": "finding",
      "id": 2607,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2608,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2609,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2610,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.59",
      "detail": "Lighthouse category 'Performance' scored 0.59 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.59
      }
    },
    {
      "type": "finding",
      "id": 2611,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2612,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2613,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2614,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.79",
      "detail": "Lighthouse category 'Performance' scored 0.79 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.79
      }
    },
    {
      "type": "finding",
      "id": 2615,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2616,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2617,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2618,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.84",
      "detail": "Lighthouse category 'Performance' scored 0.84 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.84
      }
    },
    {
      "type": "finding",
      "id": 2619,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2620,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2621,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2622,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.74",
      "detail": "Lighthouse category 'Performance' scored 0.74 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.74
      }
    },
    {
      "type": "finding",
      "id": 2623,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2624,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2625,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2626,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.66",
      "detail": "Lighthouse category 'Performance' scored 0.66 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.66
      }
    },
    {
      "type": "finding",
      "id": 2627,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2628,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2629,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2630,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.74",
      "detail": "Lighthouse category 'Performance' scored 0.74 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.74
      }
    },
    {
      "type": "finding",
      "id": 2631,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2632,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2633,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2634,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.85",
      "detail": "Lighthouse category 'Performance' scored 0.85 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.85
      }
    },
    {
      "type": "finding",
      "id": 2635,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2636,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2637,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2638,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "serious",
      "title": "Lighthouse Performance score: 0.39",
      "detail": "Lighthouse category 'Performance' scored 0.39 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.39
      }
    },
    {
      "type": "finding",
      "id": 2639,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2640,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2641,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2642,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.83",
      "detail": "Lighthouse category 'Performance' scored 0.83 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.83
      }
    },
    {
      "type": "finding",
      "id": 2643,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2644,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2645,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2646,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "document-title",
      "severity": "serious",
      "title": "Documents must have <title> element to aid in navigation",
      "detail": "Ensure each HTML document contains a non-empty <title> element https://dequeuniversity.com/rules/axe/4.10/document-title?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.text-alternatives",
          "wcag2a",
          "wcag242",
          "TTv5",
          "TT12.a",
          "EN-301-549",
          "EN-9.2.4.2",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2647,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "html-has-lang",
      "severity": "serious",
      "title": "<html> element must have a lang attribute",
      "detail": "Ensure every HTML document has a lang attribute https://dequeuniversity.com/rules/axe/4.10/html-has-lang?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.language",
          "wcag2a",
          "wcag311",
          "TTv5",
          "TT11.a",
          "EN-301-549",
          "EN-9.3.1.1",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2648,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "landmark-one-main",
      "severity": "moderate",
      "title": "Document should have one main landmark",
      "detail": "Ensure the document has a main landmark https://dequeuniversity.com/rules/axe/4.10/landmark-one-main?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.semantics",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2649,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "page-has-heading-one",
      "severity": "moderate",
      "title": "Page should contain a level-one heading",
      "detail": "Ensure that the page, or at least one of its frames contains a level-one heading https://dequeuniversity.com/rules/axe/4.10/page-has-heading-one?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.semantics",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2650,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "region",
      "severity": "moderate",
      "title": "All page content should be contained by landmarks",
      "detail": "Ensure all page content is contained by landmarks https://dequeuniversity.com/rules/axe/4.10/region?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "pre",
            "snippet": "<pre style=\"word-wrap: break-word; white-space: pre-wrap;\">"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.keyboard",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2651,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse-unavailable",
      "severity": "info",
      "title": "Lighthouse unavailable",
      "detail": "could not parse lighthouse output (rc=1): Unterminated string starting at: line 424 column 21 (char 65377). stderr: Runtime error encountered: The page provided is not HTML (served as MIME type text/plain).\n",
      "evidence": {}
    },
    {
      "type": "finding",
      "id": 2652,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2653,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.83",
      "detail": "Lighthouse category 'Performance' scored 0.83 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.83
      }
    },
    {
      "type": "finding",
      "id": 2654,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2655,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2656,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2657,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.65",
      "detail": "Lighthouse category 'Performance' scored 0.65 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.65
      }
    },
    {
      "type": "finding",
      "id": 2658,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2659,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2660,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.75",
      "detail": "Lighthouse category 'Performance' scored 0.75 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.75
      }
    },
    {
      "type": "finding",
      "id": 2661,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2662,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2663,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2664,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.62",
      "detail": "Lighthouse category 'Performance' scored 0.62 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.62
      }
    },
    {
      "type": "finding",
      "id": 2665,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2666,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2667,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2668,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.66",
      "detail": "Lighthouse category 'Performance' scored 0.66 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.66
      }
    },
    {
      "type": "finding",
      "id": 2669,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2670,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2671,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2672,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.68",
      "detail": "Lighthouse category 'Performance' scored 0.68 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.68
      }
    },
    {
      "type": "finding",
      "id": 2673,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2674,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2675,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2676,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.5",
      "detail": "Lighthouse category 'Performance' scored 0.5 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.5
      }
    },
    {
      "type": "finding",
      "id": 2677,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2678,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2679,
      "url": "https://artificialatheist.com",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "moderate",
      "title": "Article thumbnail images lack descriptive alt text",
      "detail": "Screen reader users browsing the recent articles list and featured post hear nothing for the article thumbnails (alt=\"\"). While the images are paired with adjacent headline links (which do have accessible text via the h1/h2 link), the images themselves are being treated as purely decorative. If the thumbnails are generic stock/AI-generated illustrations that add no unique information beyond the headline, empty alt is acceptable per 1.1.1 (decorative). However, if they are meant to convey topical context (e.g., a diagram of C. elegans anatomy) that sighted users glean visually, screen reader users are missing that context. Recommend confirming intent: if decorative, keep alt=\"\" (current implementation is then correct); if informative, add concise alt text describing the image's relevance.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Featured card img and article card imgs all have alt=''; each is already adjacent to a text link with the same info, so likely compliant as decorative"
      }
    },
    {
      "type": "finding",
      "id": 2680,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/3.3.2",
      "severity": "minor",
      "title": "Search input relies solely on placeholder/aria-label, no persistent visible label",
      "detail": "Low-vision users and users with cognitive disabilities may lose the input's purpose once text is entered or if placeholder rendering is suppressed by browser zoom/high-contrast settings, since the aria-label 'Search articles' is not visually present as a label. While this satisfies 4.1.2 Name/Role/Value programmatically, it is a weak pattern for 3.3.2 Labels or Instructions. Fix: add a visible <label> (can be visually styled but not hidden) tied to the input via for/id.",
      "evidence": {
        "selector": "input[type=search]",
        "note": "aria-label='Search articles', placeholder='Search articles'"
      }
    },
    {
      "type": "finding",
      "id": 2681,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/3.3.1",
      "severity": "minor",
      "title": "No indication of error/empty-query feedback for search submission",
      "detail": "Keyboard and screen-reader users submitting an empty or invalid search query have no described mechanism for status messages or error identification (no aria-live region or role='status' evident in skeleton). If no results are found, screen reader users may not be informed. Fix: ensure search results/error states are announced via an ARIA live region so users relying on assistive tech receive feedback equivalent to sighted users.",
      "evidence": {
        "selector": "main input[type=search]",
        "note": "No visible form/button or live-region markup present in skeleton"
      }
    },
    {
      "type": "finding",
      "id": 2682,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative-style empty alt on article preview thumbnails likely acceptable",
      "detail": "Article preview images use alt=\"\" alongside adjacent link text (the h2 headline linking to the same article) that conveys the article's subject. Since the image is paired with a redundant text link and heading, empty alt is an appropriate way to avoid duplicate announcements for screen-reader users, and is not a barrier. However, if these thumbnails are meant to visually represent distinct article content (e.g., a diagram of C. elegans anatomy) rather than purely decorative branding, low-vision or blind users lose potentially useful context. Recommend confirming intent: if purely decorative/stock imagery, empty alt is correct per 1.1.1; if the image conveys unique information not in the text, add a concise descriptive alt.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "escalate false"
      }
    },
    {
      "type": "finding",
      "id": 2683,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "minor",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., allowing broad script/style sources or missing directives such as script-src/object-src/frame-ancestors). For a static content site like this FAQ page with no visible forms or user input surfaces, the immediate injection risk is low, but a weak CSP still reduces defense-in-depth against stored/reflected XSS should a comment system, search feature, or third-party ad/analytics script be compromised. The search page (/search/) in particular should be checked for reflected query parameters. Remediation: adopt a strict CSP with explicit script-src/style-src allowlists (avoiding 'unsafe-inline'/'unsafe-eval'), and set object-src 'none' and frame-ancestors 'self' to also cover clickjacking protections.",
      "evidence": {
        "note": "No CSP value provided in evidence beyond triage flag; assessed based on absence of strong directives implied by triage reason."
      }
    },
    {
      "type": "finding",
      "id": 2684,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/4.1.2",
      "severity": "moderate",
      "title": "Text resize buttons don't communicate state changes to assistive technology",
      "detail": "The 'Smaller text' and 'Larger text' buttons have aria-pressed='false' hardcoded and never appear to update after activation. Screen-reader users pressing these toggle-like buttons receive no confirmation that a state change occurred, violating Name/Role/Value requirements since aria-pressed should reflect actual state. Additionally, low-vision users relying on visual cues alone may not notice the page text has resized if the change is subtle, and there's no live region announcement (e.g., via aria-live) confirming the new size. Fix: update aria-pressed dynamically based on actual toggle state (if these are meant to be toggle buttons), or if they are simple actions (not toggles), remove aria-pressed entirely and instead announce the change via an aria-live region (e.g., 'Text size increased to 120%').",
      "evidence": {
        "selector": "button[aria-label='Smaller text'], button[aria-label='Larger text']",
        "note": "aria-pressed='false' static in skeleton for both buttons"
      }
    },
    {
      "type": "finding",
      "id": 2685,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.4.4",
      "severity": "minor",
      "title": "No visible confirmation of resize toggle causing ambiguity for low-vision users",
      "detail": "Low-vision users who rely on the A+/A- controls to resize text may not perceive small increments in font size, especially if repeated clicks show no obvious visual feedback (e.g., a size indicator or highlighted active state). This creates uncertainty whether the control is functioning, potentially causing repeated unnecessary clicks. Fix: add a small text-size indicator (e.g., 'Text size: Medium') near the buttons that updates on click.",
      "evidence": {
        "selector": "button[aria-label='Smaller text'], button[aria-label='Larger text']"
      }
    },
    {
      "type": "finding",
      "id": 2686,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or missing Content-Security-Policy",
      "detail": "The site appears to lack a strict Content-Security-Policy (or has one with overly permissive directives such as 'unsafe-inline'/'unsafe-eval' or missing script-src restrictions). On a content-heavy blog rendering user-adjacent or third-party embedded content (images, Ko-fi widget, fonts), a weak CSP reduces defense-in-depth against XSS if any injection point (e.g., search feature, comment rendering, or a compromised third-party script) is exploited. Without CSP script-src/object-src restrictions, an injected script would execute unrestricted, enabling session/cookie theft or defacement. Remediation: implement a CSP with at minimum default-src 'self', explicit script-src allow-list (avoiding 'unsafe-inline'/'unsafe-eval'), frame-ancestors directive, and object-src 'none'. Since no other compensating headers (e.g., X-Frame-Options combined with frame-ancestors) were observed in the provided evidence, this should be treated as a real gap rather than moot.",
      "evidence": {
        "selector": "",
        "snippet": "",
        "note": "No CSP header value provided in evidence beyond flag classification 'weak-csp'; assuming directive is either absent or overly permissive."
      }
    },
    {
      "type": "finding",
      "id": 2687,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Hero image alt likely appropriately empty (decorative)",
      "detail": "The article hero image appears to be a decorative illustrative graphic accompanying the title rather than conveying unique informational content; empty alt=\"\" is a valid pattern under 1.1.1 for decorative images so screen-reader users aren't burdened with redundant description. This is not a confirmed barrier unless the image conveys data or content not present in text (e.g., a chart or diagram). If the image is purely stylistic/generic (as is typical for this site's AI-generated header art), no fix is needed. If it instead illustrates a specific concept referenced in the text, a concise descriptive alt should be added so screen-reader users get equivalent information to sighted users.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Same empty-alt pattern is used across other article thumbnails on the page, suggesting a consistent, intentional decorative-image convention rather than an oversight."
      }
    },
    {
      "type": "finding",
      "id": 2688,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/2.4.4",
      "severity": "minor",
      "title": "Decorative bullet separators are properly hidden but article previews rely on truncated text",
      "detail": "The '\u25cf' separators are aria-hidden, so they do not create confusing announcements for screen reader users\u2014this part is fine. However, article preview links each go to distinctly titled headings (h2 with descriptive link text), which do satisfy Link Purpose in Context. No real barrier confirmed here; the truncated body text is supplementary, not the accessible name of the link, so screen reader users can still distinguish articles via the h2 link text. Downgraded to informational: verify that truncated excerpt text does not end mid-word/mid-sentence in a way that implies missing content via ARIA live regions or is announced as part of the link.",
      "evidence": {
        "selector": "article h2 a",
        "note": "Each article's link name is the full descriptive headline, not the truncated excerpt, so no confirmed barrier."
      }
    },
    {
      "type": "finding",
      "id": 2689,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or absent Content-Security-Policy",
      "detail": "No strong CSP directives were confirmed for this page; without a restrictive CSP (script-src, object-src, base-uri, frame-ancestors), the site has reduced defense-in-depth against XSS and clickjacking if any injection point is later found. This is a static content site with no visible forms or user input sinks, which lowers immediate risk, but the lack of CSP removes a compensating control that would otherwise mitigate future injection or third-party script compromise (e.g., analytics, ko-fi embed). Remediation: implement a CSP with script-src 'self' plus explicit trusted hosts, object-src 'none', base-uri 'self', and frame-ancestors 'self' to reduce clickjacking and injection blast radius.",
      "evidence": {
        "note": "Header content not provided in full; flagged as weak/absent per triage \u2014 no frame-ancestors or script-src restriction confirmed"
      }
    },
    {
      "type": "finding",
      "id": 2690,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Hero image uses empty alt text (likely acceptable)",
      "detail": "The article hero image is presentational/illustrative of an abstract concept ('Religion by Inheritance...') rather than conveying unique content or data. Empty alt (alt='') is appropriate under 1.1.1 if the image is purely decorative and the adjacent heading/text already conveys the same information. Screen reader users are not blocked since the h1 and article text carry the meaning. However, if the image contains any text, chart, or specific illustrative meaning not captured elsewhere, it should have a descriptive alt instead. Recommend confirming the image is purely decorative; if so, current markup is correct and this should be downgraded/closed. If it conveys unique meaning, add a concise descriptive alt attribute.",
      "evidence": {
        "selector": "article img[src='religion-by-inheritance-how-birth-predicts-belief.png']",
        "note": "needs visual confirmation of image content"
      }
    },
    {
      "type": "finding",
      "id": 2691,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/other",
      "severity": "minor",
      "title": "No security-relevant issue identified in flagged item",
      "detail": "The flagged item concerns accessibility (aria-hidden icons nested in interactive elements), which is a UX/a11y concern, not a security vulnerability. No headers, TLS metadata, or credential exposure were provided for this flagged item, so no security finding applies. No action needed from a security review perspective.",
      "evidence": {
        "note": "Flagged item is UX/accessibility in nature, out of scope for security rubric"
      }
    },
    {
      "type": "finding",
      "id": 2692,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or overly permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g. allowing 'unsafe-inline' or broad wildcard sources), which reduces its effectiveness as a mitigation against XSS/injection attacks. Given the page renders user-agnostic static content with no visible form inputs or user-generated content sinks, exploitability is limited, but any future injection point (search feature, comments) would be exposed. Recommend tightening CSP to remove 'unsafe-inline'/'unsafe-eval', use nonces or hashes for scripts, and restrict default-src/script-src to self and known trusted origins.",
      "evidence": {
        "note": "CSP present but weakened directives observed; no compensating frame-ancestors or strict script-src confirmed"
      }
    },
    {
      "type": "finding",
      "id": 2693,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Hero image alt text likely acceptable but unverified",
      "detail": "The article hero image has alt=\"\" (decorative treatment). If the image is purely illustrative/stock and does not convey information not already present in the surrounding text (title, heading), empty alt is correct per 1.1.1 and no barrier exists for screen-reader users. However, if the image contains meaningful visual content (e.g., a chart, quote, or scene relevant to the article's argument) that isn't conveyed elsewhere, screen-reader users would miss that information. Recommend the content team confirm the image is decorative; if so, current markup is fine, otherwise add a concise descriptive alt attribute.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Same empty-alt pattern repeated on all article thumbnails site-wide, suggesting an intentional decorative convention rather than an oversight."
      }
    },
    {
      "type": "finding",
      "id": 2694,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or missing Content-Security-Policy",
      "detail": "The site's CSP appears weak or overly permissive, providing insufficient mitigation against XSS/injection attacks. While this is a content/blog site with limited user input surfaces (search page could still reflect input), a weak CSP removes an important defense-in-depth layer against stored/reflected XSS and third-party script compromise (e.g., analytics, ad scripts). Remediation: implement a strict CSP with nonce/hash-based script-src, restrict default-src to 'self', and set frame-ancestors to prevent clickjacking, replacing any use of 'unsafe-inline' or wildcard sources.",
      "evidence": {
        "note": "CSP header flagged as weak by triage; no evidence of nonce/hash-based script-src or restrictive default-src"
      }
    },
    {
      "type": "finding",
      "id": 2695,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The CSP appears to allow inline scripts/styles or overly broad source lists (e.g. 'unsafe-inline' or wildcard hosts), which significantly weakens its ability to mitigate XSS. If any injection point exists (search functionality, comments, or third-party embeds), an attacker's injected script would execute unhindered. Remediation: remove 'unsafe-inline'/'unsafe-eval', use nonces or hashes for required inline scripts/styles, and restrict script-src/style-src to specific trusted hosts.",
      "evidence": {
        "selector": "CSP header",
        "note": "Inline styles/scripts observed in rendered skeleton suggest permissive style-src/script-src directives"
      }
    },
    {
      "type": "finding",
      "id": 2696,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Hero image alt text likely appropriate as decorative",
      "detail": "The hero image accompanying the article appears purely illustrative/thematic (a generic multiverse-themed graphic) rather than conveying unique content not already present in the heading and text. Empty alt='' is the correct pattern per WCAG 1.1.1 for decorative images, preventing screen reader users from hearing redundant announcements. No fix needed unless the image contains diagrams, charts, or data relevant to the article content, in which case a descriptive alt should be added. Recommend author confirm the image conveys no unique information before closing this out.",
      "evidence": {
        "selector": "article img[src='what-the-multiverse-hypothesis-actually-predicts.png']",
        "note": "appears decorative based on skeleton context"
      }
    },
    {
      "type": "finding",
      "id": 2697,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative hero image uses empty alt appropriately",
      "detail": "The hero image is a generic/illustrative accompaniment to the article and conveys no additional information beyond the headline and body text; empty alt (alt=\"\") is actually the correct treatment per 1.1.1 for purely decorative images so screen-reader users aren't burdened with redundant announcements. No barrier confirmed here \u2014 flagged item is a false positive unless the image contains information (e.g., a diagram of the C. elegans connectome) not available in text, in which case a descriptive alt would be required. Recommend author confirm whether image is purely decorative or contains meaningful content; if decorative, no fix needed.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Image appears to be a generic stock/illustrative header, not a data visualization"
      }
    },
    {
      "type": "finding",
      "id": 2698,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., broad 'unsafe-inline'/'unsafe-eval' allowances or missing restrictive directives), which reduces its effectiveness as a mitigation against XSS/injection attacks. On a content site with search functionality and dynamic rendering, a weak CSP means that if any injection vector (e.g., reflected search input, third-party embeds, comment fields) is exploited, the browser will not meaningfully block inline script execution or exfiltration to arbitrary origins. Remediation: define a strict CSP with a nonce- or hash-based script-src, disallow 'unsafe-inline' and 'unsafe-eval', restrict object-src to 'none', and set a base-uri and form-action to limit injection impact. Also confirm frame-ancestors is set to mitigate clickjacking if X-Frame-Options is absent.",
      "evidence": {
        "note": "CSP header content not fully shown in provided metadata; assessed as weak based on triage flag."
      }
    },
    {
      "type": "finding",
      "id": 2699,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Hero image alt text likely appropriate but unverifiable decorative status",
      "detail": "The hero image for the article is marked alt=\"\" (decorative). If it is purely stylistic/generic stock imagery, this is correct and helpful for screen-reader users who would otherwise hear a meaningless filename-derived description. However, since the filename suggests topical illustration (courtroom/secularism themed), a low-vision or blind user could be missing contextual meaning if the image conveys content not present in surrounding text. Fix: confirm the image is purely decorative; if it conveys any unique information not in the text, add a concise descriptive alt.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "same pattern repeats for related-post thumbnail images"
      }
    },
    {
      "type": "finding",
      "id": 2700,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak Content-Security-Policy allows inline scripts/unsafe resources",
      "detail": "The CSP appears to permit 'unsafe-inline' and/or broad source lists, which undermines its primary purpose of mitigating XSS. If any injection point exists (e.g., search functionality, comment forms, or user-influenced content), an attacker could execute arbitrary script since inline script execution is not blocked. No compensating controls (e.g., nonce/hash-based script-src, strict frame-ancestors) were observed in the provided headers to offset this weakness. Remediation: adopt a strict CSP using nonces or hashes for scripts, remove 'unsafe-inline'/'unsafe-eval', and restrict script-src/object-src/base-uri to trusted origins only.",
      "evidence": {
        "note": "Header value not fully provided, but flagged as weak/permissive during triage; no nonce/hash strategy or frame-ancestors directive confirmed to compensate."
      }
    },
    {
      "type": "finding",
      "id": 2701,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative-style empty alt on article preview image is acceptable but context-dependent",
      "detail": "The article preview image (machine-authored-inquiry.png) uses alt=\"\", which is appropriate under 1.1.1 if the image is purely decorative and the adjacent heading link ('What Machine-Authored Inquiry Can Be') already conveys the article's identity to screen-reader users. Since each article card has a heading link with the same destination and text, the empty alt does not create a real barrier \u2014 screen reader users still get the article title/purpose from the linked heading. This is not a confirmed WCAG failure; treat as informational rather than a blocking issue unless the images convey unique information (e.g., diagrams, screenshots) not available in text elsewhere.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "criterion 1.1.1"
      }
    },
    {
      "type": "finding",
      "id": 2702,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., allowing 'unsafe-inline' or wildcard sources), which reduces its effectiveness as a mitigation against XSS and data injection. Given this is a static-content publishing site with no visible user input forms in the flagged skeleton, the practical exploitation surface is limited, but any third-party scripts, ad tags, or comment widgets could be leveraged for injection if the policy doesn't restrict script-src tightly. Remediation: adopt a strict CSP using nonces or hashes for scripts, avoid 'unsafe-inline'/'unsafe-eval', and restrict object-src/base-uri/frame-ancestors to 'none' or 'self'.",
      "evidence": {
        "selector": "header:Content-Security-Policy",
        "note": "Redacted; policy allows overly broad sources per triage flag"
      }
    },
    {
      "type": "finding",
      "id": 2703,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Text-resize/theme buttons rely on ambiguous glyph 'A' with no visible text label",
      "detail": "The 'Smaller text' and 'Larger text' buttons both display the same visible glyph 'A' distinguished only by size difference and an aria-label. Low-vision sighted users (who do not use a screen reader) may not perceive the size difference or understand the buttons' purpose from the visual label alone, violating the intent of 3.3.2/2.4.6 (visible label should match/convey function). Fix: add discernible visual differentiation (e.g., 'A-' and 'A+' or icons with size cues) so sighted users without assistive tech can determine function without relying on the hidden aria-label.",
      "evidence": {
        "selector": "button[aria-label='Smaller text'], button[aria-label='Larger text']",
        "note": "Both buttons render identical visible character 'A'"
      }
    },
    {
      "type": "finding",
      "id": 2704,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/4.1.2",
      "severity": "minor",
      "title": "Toggle buttons use aria-pressed but state change on activation should be verified",
      "detail": "Buttons for text size and dark/light toggle include aria-pressed='false' which is good for conveying state to screen reader users (4.1.2 Name, Role, Value), but confirm the pressed state updates dynamically on activation; if it does not update, screen reader users won't know current mode. Verify via testing and ensure state toggles correctly.",
      "evidence": {
        "selector": "button[aria-pressed='false']",
        "note": "Static skeleton doesn't confirm dynamic update"
      }
    },
    {
      "type": "finding",
      "id": 2705,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., allowing 'unsafe-inline'/'unsafe-eval' or overly broad source lists, or missing entirely), which reduces its effectiveness as a mitigation against XSS if any injection point is later found (e.g., search functionality, comments, or templating errors). While this static content site has limited visible user input surfaces, a search page exists (/search/) which could reflect user input. Without a strict CSP (script-src 'self' plus nonces/hashes, object-src 'none', base-uri 'self'), any future or overlooked injection vector becomes directly exploitable for script execution, session theft, or defacement. Remediate by defining a strict CSP with nonce- or hash-based script-src, disallowing inline scripts/styles, restricting frame-ancestors, and setting default-src 'self'.",
      "evidence": {
        "note": "CSP header flagged as weak in triage; specific directive values not provided in skeleton/headers excerpt"
      }
    },
    {
      "type": "finding",
      "id": 2706,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative-style empty alt on featured article image likely acceptable",
      "detail": "The featured image alt=\"\" is treated as decorative. For an abstract philosophy article, the image is almost certainly a generic illustrative graphic rather than content-bearing, so empty alt is often appropriate per 1.1.1 and doesn't block screen-reader users from article meaning since the text content fully conveys the topic. However, if the image conveys any unique information (e.g., a diagram illustrating supervenience levels) it must have descriptive alt text; as a stock/generic hero image, this is a low-impact issue rather than a clear violation. Recommend confirming image content and adding brief descriptive alt only if it conveys meaning not present in text.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "the-concept-of-supervenience...png alt=''; same pattern repeated on related-post thumbnail"
      }
    }
  ],
  "errors": []
}