{
  "exported_at": "2026-09-30T10:05:22.053885Z",
  "kind": "page",
  "target": "https://artificialatheist.com",
  "run_id": "b8fcc211be36464c9052c4b8f8457c94",
  "status": "done",
  "stats": {
    "pages": 20,
    "templates": 19,
    "cache_hits": 19,
    "findings_by_severity": {
      "moderate": 56,
      "info": 38,
      "minor": 18,
      "serious": 3
    },
    "duration_secs": 9.98,
    "tokens": {
      "input": 0,
      "output": 0,
      "cache_read": 0,
      "cache_write": 0
    },
    "tokens_by_model": {},
    "estimated_cost_usd": 0.0
  },
  "findings": [
    {
      "type": "finding",
      "id": 2194,
      "url": "https://artificialatheist.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2195,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.6",
      "detail": "Lighthouse category 'Performance' scored 0.6 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.6
      }
    },
    {
      "type": "finding",
      "id": 2196,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2197,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2198,
      "url": "https://artificialatheist.com",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears to allow broad script sources (or lacks strict directives like script-src 'self' and object-src 'none'), which weakens protection against XSS if an injection point is ever found. No compensating control (e.g., strict frame-ancestors, nonce-based script-src, or Subresource Integrity) is evident from the provided headers. Recommend tightening CSP to a strict allowlist of trusted script origins, adding 'nonce-' or 'strict-dynamic', disallowing 'unsafe-inline'/'unsafe-eval', and setting object-src 'none' and base-uri 'self'.",
      "evidence": {
        "selector": "header:Content-Security-Policy",
        "note": "Policy present but permissive; exact directive values not fully shown in provided data"
      }
    },
    {
      "type": "finding",
      "id": 2199,
      "url": "https://artificialatheist.com",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "moderate",
      "title": "Article thumbnail images have empty alt text",
      "detail": "Screen reader users browsing the recent articles list rely on link/image text to distinguish articles. Since the article thumbnails are wrapped alongside a redundant text headline link, empty alt (alt=\"\") is actually acceptable here as decorative, provided each article's title link is present and descriptive. However, in the featured section the image is inside its own separate <a aria-label> link duplicating the headline link, making the image link redundant but not harmful. Confirm each thumbnail truly is decorative (i.e., doesn't convey unique info like a chart, quote, or photo subject relevant to the article) \u2014 if any image conveys unique content (e.g., a diagram referenced in the article), it needs descriptive alt text. Fix: audit each image; keep alt=\"\" only for purely decorative/duplicate thumbnails, add meaningful alt for any image conveying unique information not in the adjacent text.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "e.g. what-the-nervous-system-of-c-elegans-actually-taught-us.png, the-afterlife-assumption...png"
      }
    },
    {
      "type": "finding",
      "id": 2200,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2201,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.73",
      "detail": "Lighthouse category 'Performance' scored 0.73 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.73
      }
    },
    {
      "type": "finding",
      "id": 2202,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2203,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2204,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.3.1",
      "severity": "minor",
      "title": "FAQ heading structure lacks grouping semantics for answers",
      "detail": "Screen-reader users navigating by heading get h2 questions but answers appear as untagged text with no explicit programmatic association (e.g., via aria-expanded/disclosure pattern or adjacent landmark). If these are meant to be an accordion/FAQ list, add proper disclosure widget markup (button + aria-expanded + aria-controls) or ensure answer text immediately follows each h2 in reading order so the relationship is clear to AT users.",
      "evidence": {
        "selector": "main h2",
        "note": "h2 questions with no visible answer/button relationship in skeleton"
      }
    },
    {
      "type": "finding",
      "id": 2205,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/4.1.2",
      "severity": "minor",
      "title": "Text-resize buttons rely only on visual 'A' glyph plus aria-label",
      "detail": "The 'Smaller text'/'Larger text' buttons are properly labeled via aria-label, which is fine for screen readers, but low-vision users who zoom may not perceive the size difference between the two 'A' glyphs if custom font rendering doesn't scale them distinctly. Ensure visual size difference is sufficient (WCAG 1.4.1) - this is a minor usability note, not a name/role violation.",
      "evidence": {
        "selector": "button[aria-label='Smaller text'], button[aria-label='Larger text']"
      }
    },
    {
      "type": "finding",
      "id": 2206,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative icons correctly hidden but no redundant text confirmation for toggle state",
      "detail": "Dark/light mode toggle button and text-size buttons use aria-pressed to convey state, which is good, but the icon itself (aria-hidden) conveys no fallback text if aria-pressed isn't announced by a given AT/browser combination. Consider adding visually-hidden text reflecting current state (e.g., 'Dark mode: off') for robustness across assistive tech.",
      "evidence": {
        "selector": "button[aria-label='Toggle light or dark mode']"
      }
    },
    {
      "type": "finding",
      "id": 2207,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2208,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.58",
      "detail": "Lighthouse category 'Performance' scored 0.58 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.58
      }
    },
    {
      "type": "finding",
      "id": 2209,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2210,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2211,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP does not sufficiently restrict script/style sources, leaving a viable XSS injection vector if any user-supplied or third-party content is rendered without proper sanitization. A weak CSP (e.g. allowing 'unsafe-inline' or broad wildcard source lists) undermines defense-in-depth against injection, even though this is a static/content site with limited apparent input surfaces (search form is the main dynamic vector). Remediation: adopt a strict CSP with nonce- or hash-based script-src, disallow 'unsafe-inline'/'unsafe-eval', restrict object-src to 'none', and set base-uri/self and frame-ancestors directives explicitly rather than relying on defaults.",
      "evidence": {
        "note": "CSP header flagged as weak by triage; exact directive values not provided in evidence set, so severity kept moderate pending confirmation of directive specifics."
      }
    },
    {
      "type": "finding",
      "id": 2212,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative alt text on article thumbnails likely acceptable but verify images are truly decorative",
      "detail": "Article card images use alt=\"\" which is appropriate if the image is purely decorative and the adjacent link text (article title) conveys full context. Screen-reader users rely solely on the link text ('Secularism and the Court Witness: Truth Without God') which does appear descriptive, so this is likely not a barrier. However, if any thumbnail conveys unique information not present in the title text, empty alt would hide that content. Fix: confirm all card images are purely decorative; if any carry meaning, add descriptive alt text.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Applies to all ~19 article cards"
      }
    },
    {
      "type": "finding",
      "id": 2213,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/2.4.4",
      "severity": "moderate",
      "title": "Ambiguous repeated link text pattern within article cards",
      "detail": "Each article card contains a topic label span, an icon, and a separate link with the article title, plus a bullet '\u25cf' span in the header list items. Keyboard and screen-reader users navigating by links may encounter multiple non-link elements interspersed, but the actual link purpose is determinable from the title text alone, so this is a minor risk rather than a confirmed failure. Fix: ensure the entire card (including image) is wrapped in the single link so screen-reader and touch users get one predictable target instead of separate icon/image and text link elements.",
      "evidence": {
        "selector": "article a",
        "note": "Icon (i) and title link are separate interactive-looking elements"
      }
    },
    {
      "type": "finding",
      "id": 2214,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2215,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.54",
      "detail": "Lighthouse category 'Performance' scored 0.54 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.54
      }
    },
    {
      "type": "finding",
      "id": 2216,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2217,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2218,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., overly broad source lists or missing restrictive directives such as script-src/object-src/base-uri), reducing its effectiveness as a defense-in-depth control against XSS and data injection. While this static content site has limited visible user input surfaces (a search page exists), any future reflected content, third-party scripts, or stored content becomes higher risk without a strict CSP. Remediation: adopt a strict CSP with script-src 'self' (plus nonces/hashes for any inline scripts), object-src 'none', base-uri 'self', and frame-ancestors 'none' or 'self' to also cover clickjacking protection.",
      "evidence": {
        "selector": "header:Content-Security-Policy",
        "note": "CSP present but permissive; specific directive values not fully enumerated in provided metadata"
      }
    },
    {
      "type": "finding",
      "id": 2219,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2220,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.79",
      "detail": "Lighthouse category 'Performance' scored 0.79 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.79
      }
    },
    {
      "type": "finding",
      "id": 2221,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2222,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2223,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., allowing 'unsafe-inline' or broad wildcard sources), reducing its effectiveness as a mitigation against XSS and data injection. On a content site with no visible user-input forms in this article, exploitability is limited, but a weak CSP still removes a key defense-in-depth layer against injected scripts (e.g., via compromised third-party assets, ad scripts, or a future stored-XSS bug). Remediation: tighten CSP to avoid 'unsafe-inline'/'unsafe-eval', use nonces or hashes for any inline scripts, restrict script-src/style-src to specific trusted origins, and include frame-ancestors to also cover clickjacking protection.",
      "evidence": {
        "note": "Exact CSP header content not provided in triage payload; assessed as weak based on flag reason. Recommend reviewing actual directive values (script-src, style-src, frame-ancestors, object-src) before increasing severity."
      }
    },
    {
      "type": "finding",
      "id": 2224,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative-looking hero image marked empty alt is likely acceptable",
      "detail": "The article's hero image (religion-by-inheritance-how-birth-predicts-belief.png) has alt=\"\" . Given the heading and body text already convey the article's topic and the image appears to be a generic decorative/stock illustration rather than content-bearing (e.g., a chart or diagram), empty alt is likely appropriate per 1.1.1 since it avoids redundant announcements for screen-reader users. However, if the image contains any unique informational content (e.g., an infographic or data visualization relevant to 'birth predicts belief'), it must have a descriptive alt attribute; currently a screen-reader user cannot verify this and may miss information if it exists. Fix: confirm image is purely decorative; if it conveys information, add concise descriptive alt text.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "src=religion-by-inheritance-how-birth-predicts-belief.png"
      }
    },
    {
      "type": "finding",
      "id": 2225,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2226,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.85",
      "detail": "Lighthouse category 'Performance' scored 0.85 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.85
      }
    },
    {
      "type": "finding",
      "id": 2227,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2228,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2229,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Empty alt text on main article hero image likely appropriate but should be verified",
      "detail": "The article's lead image (secularism-and-the-political-party-when-movements-organise.png) has alt=\"\" which is correct if the image is purely decorative/illustrative stock-style artwork accompanying the article title. Screen-reader users would simply skip it, which is fine for decorative imagery and avoids redundant announcements. However, if the image conveys unique information not present in the text (e.g., a diagram, chart, or specific scene relevant to the article's argument), empty alt would hide that content from blind/low-vision screen-reader users, violating 1.1.1 Non-text Content. Fix: confirm the image is purely decorative; if so, empty alt is correct. If it conveys meaning, add a concise descriptive alt attribute summarizing its relevant content.",
      "evidence": {
        "selector": "article > img[alt='']",
        "note": "same pattern repeated on related-post thumbnail image; likely a site-wide decorative convention"
      }
    },
    {
      "type": "finding",
      "id": 2230,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2231,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.8",
      "detail": "Lighthouse category 'Performance' scored 0.8 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.8
      }
    },
    {
      "type": "finding",
      "id": 2232,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2233,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2234,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., broad allowlists, unsafe-inline/unsafe-eval, or missing key directives such as object-src/base-uri/script-src restrictions). On a content-heavy static-ish blog this reduces defense-in-depth against XSS if any injection point (comment forms, search, CMS admin) is compromised. A weak CSP does not itself create the vulnerability but removes a mitigating control that would otherwise contain script injection. Recommend defining a strict CSP with script-src 'self' plus specific hashes/nonces, object-src 'none', base-uri 'self', and frame-ancestors 'self' to also cover clickjacking protection.",
      "evidence": {
        "selector": "http-header:Content-Security-Policy",
        "note": "Header present but overly permissive per triage flag; exact directive values not fully enumerated in provided data"
      }
    },
    {
      "type": "finding",
      "id": 2235,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative-style empty alt on article thumbnail images is acceptable but redundant link text nearby should be checked",
      "detail": "The article card images use alt=\"\" which is appropriate since each card already contains an adjacent text link with the article title (e.g. 'Religion by Inheritance: How Birth Predicts Belief'). Screen reader users are not blocked because the accessible name of the linked content is available via the title text link. This is not a barrier under 1.1.1 as long as the image is purely decorative/duplicative of the adjacent link text. No fix required unless images convey unique information (e.g., a chart or diagram) not represented in text, in which case descriptive alt text should be added.",
      "evidence": {
        "selector": "article img[alt='']",
        "snippet": "<img alt=\"\" src=\"religion-by-inheritance-how-birth-predicts-belief.png\">",
        "note": "1.1.1 Non-text Content"
      }
    },
    {
      "type": "finding",
      "id": 2236,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2237,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.72",
      "detail": "Lighthouse category 'Performance' scored 0.72 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.72
      }
    },
    {
      "type": "finding",
      "id": 2238,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2239,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2240,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Hero image alt text may omit meaningful content",
      "detail": "The article hero image is marked alt=\"\" (decorative). If the image is purely a generic/stock illustration accompanying the article, this is acceptable per 1.1.1. However, if it depicts an actual C. elegans connectome diagram or worm anatomy relevant to understanding the article, screen-reader users are denied that informational content. Recommend confirming image content: if illustrative/stock, empty alt is correct; if it conveys a diagram or specific visual information referenced in the text, add descriptive alt text (e.g., 'Diagram of C. elegans neural connectome showing 302 neurons and synaptic connections').",
      "evidence": {
        "selector": "article > img[alt='']",
        "note": "criterion 1.1.1"
      }
    },
    {
      "type": "finding",
      "id": 2241,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2242,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.78",
      "detail": "Lighthouse category 'Performance' scored 0.78 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.78
      }
    },
    {
      "type": "finding",
      "id": 2243,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2244,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2245,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or missing Content-Security-Policy",
      "detail": "The site's CSP does not appear to restrict script-src/object-src or frame-ancestors adequately, leaving it more exposed to XSS injection if any unsanitized user input or third-party script is later introduced. Even a content-focused static site benefits from a strict CSP as defense-in-depth against injected scripts (e.g. from compromised ad/analytics tags or a CMS vulnerability). Impact is moderate since no dynamic user input surface was observed in the skeleton (search page may accept input), but absence of CSP removes an important mitigation layer for stored/reflected XSS. Remediation: implement a strict CSP with script-src 'self' plus explicit trusted hosts, default-src 'none' fallback, and frame-ancestors 'none' or 'self' to also cover clickjacking, avoiding 'unsafe-inline'/'unsafe-eval'.",
      "evidence": {
        "selector": "header:Content-Security-Policy",
        "note": "CSP flagged as weak; no nonce/hash-based script-src or frame-ancestors directive confirmed"
      }
    },
    {
      "type": "finding",
      "id": 2246,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2247,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.82",
      "detail": "Lighthouse category 'Performance' scored 0.82 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.82
      }
    },
    {
      "type": "finding",
      "id": 2248,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2249,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2250,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative alt on hero image likely acceptable but unverified",
      "detail": "The article's hero image (what-the-multiverse-hypothesis-actually-predicts.png) has alt=\"\", which is appropriate if it is purely decorative/illustrative and adds no information beyond the article title already in the H1. Screen reader users would not lose content in that case. However, if the image contains any text, diagram, or specific illustrative content relevant to understanding the multiverse concept (e.g., a diagram of branching universes), the empty alt would hide meaningful information from blind/low-vision screen reader users, violating 1.1.1 Non-text Content. Recommend content authors confirm image intent; if purely decorative/stock, empty alt is correct, otherwise add a concise descriptive alt text.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "same pattern repeated on related-post thumbnail images"
      }
    },
    {
      "type": "finding",
      "id": 2251,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 2252,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 2253,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 2254,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "document-title",
      "severity": "serious",
      "title": "Documents must have <title> element to aid in navigation",
      "detail": "Ensure each HTML document contains a non-empty <title> element https://dequeuniversity.com/rules/axe/4.10/document-title?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.text-alternatives",
          "wcag2a",
          "wcag242",
          "TTv5",
          "TT12.a",
          "EN-301-549",
          "EN-9.2.4.2",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2255,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "html-has-lang",
      "severity": "serious",
      "title": "<html> element must have a lang attribute",
      "detail": "Ensure every HTML document has a lang attribute https://dequeuniversity.com/rules/axe/4.10/html-has-lang?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.language",
          "wcag2a",
          "wcag311",
          "TTv5",
          "TT11.a",
          "EN-301-549",
          "EN-9.3.1.1",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2256,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "landmark-one-main",
      "severity": "moderate",
      "title": "Document should have one main landmark",
      "detail": "Ensure the document has a main landmark https://dequeuniversity.com/rules/axe/4.10/landmark-one-main?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.semantics",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2257,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "page-has-heading-one",
      "severity": "moderate",
      "title": "Page should contain a level-one heading",
      "detail": "Ensure that the page, or at least one of its frames contains a level-one heading https://dequeuniversity.com/rules/axe/4.10/page-has-heading-one?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.semantics",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2258,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "region",
      "severity": "moderate",
      "title": "All page content should be contained by landmarks",
      "detail": "Ensure all page content is contained by landmarks https://dequeuniversity.com/rules/axe/4.10/region?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "pre",
            "snippet": "<pre style=\"word-wrap: break-word; white-space: pre-wrap;\">"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.keyboard",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2259,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse-unavailable",
      "severity": "info",
      "title": "Lighthouse unavailable",
      "detail": "could not parse lighthouse output (rc=1): Unterminated string starting at: line 806 column 21 (char 130799). stderr: Runtime error encountered: The page provided is not HTML (served as MIME type text/plain).\n",
      "evidence": {}
    },
    {
      "type": "finding",
      "id": 2260,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2261,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.81",
      "detail": "Lighthouse category 'Performance' scored 0.81 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.81
      }
    },
    {
      "type": "finding",
      "id": 2262,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2263,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2264,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/3.3.2",
      "severity": "minor",
      "title": "Search input relies on placeholder + aria-label instead of visible label",
      "detail": "The search input has an aria-label ('Search articles') which satisfies 4.1.2 Name/Role/Value and gives screen-reader users an accessible name, but there is no visible <label>. Low-vision users, users with cognitive disabilities, and users who zoom text can lose the placeholder text once they focus/type in the field, leaving no persistent visible cue of the field's purpose. Fix: add a visible <label> (can be styled as a heading or use a visually-associated text near the input) rather than relying solely on placeholder/aria-label so the field's purpose remains visible during and after interaction.",
      "evidence": {
        "selector": "input[type=search]",
        "note": "aria-label present but no visible label text; placeholder disappears on input"
      }
    },
    {
      "type": "finding",
      "id": 2265,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2266,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.83",
      "detail": "Lighthouse category 'Performance' scored 0.83 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.83
      }
    },
    {
      "type": "finding",
      "id": 2267,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2268,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2269,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "minor",
      "title": "Weak or missing Content-Security-Policy",
      "detail": "The site appears to lack a strict CSP (or uses a permissive one), which reduces defense-in-depth against XSS/injection even though no direct injection vector was observed in the skeleton. Given this is a static, content-heavy blog with no visible forms or user input fields, the practical exploitation surface is low, but a missing 'frame-ancestors' or 'script-src' directive would leave the site more exposed if any third-party script or ad injection is later added. Remediation: implement a CSP with at least 'default-src self', explicit 'script-src' allowlist, and 'frame-ancestors self' to mitigate clickjacking and reduce impact of any future stored content injection (e.g., via CMS/AI-generation pipeline).",
      "evidence": {
        "selector": "http-header",
        "note": "CSP header not confirmed present/strict; no compensating frame-ancestors or X-Frame-Options observed in skeleton"
      }
    },
    {
      "type": "finding",
      "id": 2270,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2271,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.84",
      "detail": "Lighthouse category 'Performance' scored 0.84 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.84
      }
    },
    {
      "type": "finding",
      "id": 2272,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2273,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2274,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site includes interactive quiz functionality with client-side scoring logic, increasing the attack surface for DOM-based XSS if any user-controlled input is reflected into the page. A weak CSP (e.g., missing directives like script-src/object-src, or use of 'unsafe-inline'/'unsafe-eval') provides little defense-in-depth against injected scripts, meaning any XSS vulnerability discovered elsewhere (stored, reflected, or DOM-based) could be exploited without CSP mitigation. Remediation: implement a strict CSP with a nonce- or hash-based script-src, restrict object-src to 'none', and set base-uri and frame-ancestors explicitly rather than relying on default-src alone.",
      "evidence": {
        "note": "CSP header present but insufficiently restrictive per triage; no inline-script nonce/hash scheme apparent from skeleton (inline event-handling likely used for quiz buttons)."
      }
    },
    {
      "type": "finding",
      "id": 2275,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/4.1.3",
      "severity": "moderate",
      "title": "Quiz feedback and results may not be announced to screen reader users",
      "detail": "The quiz's scoring, validation, and result states appear to be dynamically rendered without visible ARIA live regions in the skeleton. If answer feedback, error states, or final scores are injected into the DOM without aria-live='polite' or role='status'/'alert', screen reader users won't know their answer was recorded, if they made an error, or what their final score is. This blocks blind/low-vision users from completing the quiz meaningfully. Fix: wrap dynamic feedback/result containers in an aria-live region (polite for score updates, assertive only for critical errors), and ensure focus is moved to the results summary when the quiz completes.",
      "evidence": {
        "selector": "main section (quiz container)",
        "note": "escalate:false"
      }
    },
    {
      "type": "finding",
      "id": 2276,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/3.3.1",
      "severity": "moderate",
      "title": "No visible error identification for unanswered/skipped questions",
      "detail": "If the quiz allows submission without answering, users need clear text-based error identification (not just color) describing which question needs a response. Skeleton shows no visible error text pattern; this should be verified in the live interactive quiz. Sighted keyboard users and screen reader users both need programmatically associated error text (e.g., via aria-describedby) rather than relying solely on visual cues like red borders.",
      "evidence": {
        "selector": "main section (quiz container)",
        "note": "criterion 3.3.1"
      }
    },
    {
      "type": "finding",
      "id": 2277,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/4.1.2",
      "severity": "moderate",
      "title": "Toggle buttons for quiz mode selection rely on aria-pressed but selection outcome may not be communicated",
      "detail": "The 'Random mix' and 'By topic' buttons use aria-pressed correctly for toggle state, but if selecting a mode changes subsequent question content/format without an announcement, screen reader users may not perceive the change in context (SC 3.2.2 On Input / 4.1.2). Verify that any dynamically appearing topic-selection sub-options are announced or at minimum keyboard-focusable in logical order after toggling.",
      "evidence": {
        "selector": "button[aria-pressed]",
        "note": "criterion 4.1.2, 3.2.2"
      }
    },
    {
      "type": "finding",
      "id": 2278,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2279,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.72",
      "detail": "Lighthouse category 'Performance' scored 0.72 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.72
      }
    },
    {
      "type": "finding",
      "id": 2280,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2281,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2282,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP does not sufficiently restrict script/style sources, leaving a static content site with reduced defense-in-depth against XSS if any injection point (comments, search, CMS admin) is later compromised. No compensating controls (e.g., strict frame-ancestors, script-src 'self'/nonce) were observed. Recommend adopting a strict CSP: default-src 'self'; script-src 'self' with nonces/hashes; object-src 'none'; frame-ancestors 'self'; and avoiding 'unsafe-inline'/'unsafe-eval'.",
      "evidence": {
        "note": "CSP header present but weak per triage; no nonce/strict-dynamic or restrictive directives evident"
      }
    },
    {
      "type": "finding",
      "id": 2283,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Hero image alt text may be inappropriately empty",
      "detail": "The article's hero image (the-concept-of-supervenience-when-one-level-rests-on-another.png) is marked alt=\"\", treating it as purely decorative. If the image is a generic stock/illustrative graphic that adds no unique information beyond the headline, empty alt is correct and this is a non-issue. However, if the image is meant to visually reinforce or represent the article's concept (common for blog hero images), screen reader users lose that context entirely since it's skipped. Recommend content authors confirm decorative intent; if decorative, current markup is compliant. If informative, add concise descriptive alt text conveying the image's relevance to the topic.",
      "evidence": {
        "selector": "article > img[alt='']",
        "snippet": "<img alt=\"\" src=\"the-concept-of-supervenience-when-one-level-rests-on-another.png\">",
        "note": "Low confidence barrier; likely decorative per site pattern (same pattern on related article thumbnail)."
      }
    },
    {
      "type": "finding",
      "id": 2284,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2285,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.64",
      "detail": "Lighthouse category 'Performance' scored 0.64 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.64
      }
    },
    {
      "type": "finding",
      "id": 2286,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2287,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2288,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/4.1.2",
      "severity": "minor",
      "title": "Icon-only buttons have adequate aria-labels but state changes may not be announced",
      "detail": "The 'Smaller text', 'Larger text', and dark mode toggle buttons use aria-pressed to convey state, which is good, but verify that aria-pressed actually updates on activation via JS. If it does not update, screen reader users will not know the current state (font size level, light/dark mode), violating 4.1.2 Name, Role, Value. Fix: ensure aria-pressed is toggled programmatically on click and consider adding a visible/announced confirmation (e.g., via aria-live region) when text size or theme changes, since these actions have no visible label text to confirm the change occurred.",
      "evidence": {
        "selector": "button[aria-label='Toggle light or dark mode']",
        "note": "aria-pressed=false present in skeleton; must verify it updates dynamically"
      }
    },
    {
      "type": "finding",
      "id": 2289,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.4.1",
      "severity": "minor",
      "title": "Icon buttons rely solely on icon shape with no visible text label",
      "detail": "Low-vision users who don't use screen readers but rely on zoom/magnification may struggle to distinguish 'A' smaller vs 'A' larger buttons and the mode-toggle icon if visual size/contrast differences are subtle. While aria-label covers screen reader users, ensure sufficient visual distinction (size, color) between the two 'A' buttons for sighted users with low vision, per 1.4.1 Use of Color and general perceivability. Fix: use distinctly sized 'A' icons (small A vs large A) rather than identical size text, and ensure icons have programmatic tooltips/visible text on hover/focus for clarity.",
      "evidence": {
        "selector": "button[aria-label='Smaller text'], button[aria-label='Larger text']"
      }
    },
    {
      "type": "finding",
      "id": 2290,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2291,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.6",
      "detail": "Lighthouse category 'Performance' scored 0.6 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.6
      }
    },
    {
      "type": "finding",
      "id": 2292,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2293,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2294,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative alt text on article preview images likely acceptable, but confirm intent",
      "detail": "The article preview images (e.g. the C. elegans connectome illustration) use alt=\"\", which is appropriate if the adjacent link text ('What the Nervous System of C. elegans Actually Taught Us') already conveys the same information, making the image purely decorative/redundant. This is a common and valid pattern for card thumbnails paired with a text headline link. However, if these images carry unique informational content (e.g. an actual diagram of the connectome that isn't described elsewhere), screen reader users would miss that information. Fix: verify editorial intent \u2014 if the image is purely illustrative/decorative alongside descriptive link text, alt=\"\" is correct and no change is needed; if the image conveys unique meaning, add a concise alt describing it (e.g. alt=\"Diagram of C. elegans neural connectome\").",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "criterion 1.1.1"
      }
    },
    {
      "type": "finding",
      "id": 2295,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2296,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.65",
      "detail": "Lighthouse category 'Performance' scored 0.65 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.65
      }
    },
    {
      "type": "finding",
      "id": 2297,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2298,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2299,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears to allow inline script execution (e.g. via 'unsafe-inline' or an overly broad default-src), which undermines CSP's primary purpose of mitigating XSS. If any injection point exists (e.g. search functionality, comment rendering, or third-party embeds), an attacker could execute arbitrary script in visitors' browsers. Even a static/blog-style site benefits from a strict CSP as defense-in-depth against supply-chain compromise of third-party scripts (analytics, embeds like ko-fi). Remediation: adopt a nonce- or hash-based CSP for scripts, remove 'unsafe-inline', restrict default-src/script-src to 'self' and explicitly trusted origins, and add frame-ancestors/object-src 'none' as further hardening.",
      "evidence": {
        "note": "Not directly observed in provided headers, but flagged by triage as weak; no compensating strict CSP directives (script-src, frame-ancestors) were confirmed present"
      }
    },
    {
      "type": "finding",
      "id": 2300,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Hero image alt text may be inappropriately empty",
      "detail": "Screen reader users get no information about the article hero image (the-afterlife-assumption...png), which is announced as decorative and skipped. If the image is purely stylistic/generic, empty alt is correct; but if it conveys topic-relevant imagery (e.g., symbolic afterlife visual), a concise descriptive alt should be provided. Given the article title is already conveyed via the adjacent h1, low risk, but content authors should confirm intent and add descriptive alt if the image carries meaning beyond decoration.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "same pattern repeated on related-post thumbnail images"
      }
    },
    {
      "type": "finding",
      "id": 2301,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2302,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.66",
      "detail": "Lighthouse category 'Performance' scored 0.66 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.66
      }
    },
    {
      "type": "finding",
      "id": 2303,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2304,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2305,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or overly permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak/non-restrictive (e.g., broad allowlists or missing script-src/object-src restrictions), which reduces its effectiveness as a defense-in-depth control against XSS. Although this is a static/AI-generated content site with limited user input surfaces (search page being the main dynamic entry point), a weak CSP still leaves the site more exposed if any injection vector (stored content, third-party script compromise, or reflected search parameter) is found. Remediation: adopt a strict CSP with explicit script-src (nonce or hash-based), object-src 'none', base-uri 'self', and frame-ancestors 'self' to mitigate injection and clickjacking risks.",
      "evidence": {
        "note": "CSP header present but insufficiently restrictive per triage flag; specific directive values not provided in evidence"
      }
    },
    {
      "type": "finding",
      "id": 2306,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative-style empty alt text on article thumbnail images",
      "detail": "Screen-reader users hear nothing for the article images, which is acceptable since the images appear purely decorative/illustrative and each article card has an adjacent text link naming the article. No barrier here as long as images convey no unique content not present in text; recommend confirming images are truly decorative and keep alt=\"\" as-is.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "e.g. the-concept-of-supervenience-when-one-level-rests-on-another.png"
      }
    },
    {
      "type": "finding",
      "id": 2307,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/2.4.4",
      "severity": "moderate",
      "title": "Article card links rely on visually adjacent text but structure may confuse link purpose in isolation",
      "detail": "Each article card's link text (e.g. 'The Concept of Supervenience: When One Level Rests on Another') is descriptive on its own, satisfying 2.4.4 Link Purpose (In Context). However, the category label (e.g. 'Philosophy') and trailing icon are marked aria-hidden and not part of the accessible link name, so screen-reader users navigating by link list only hear the title text without category context that sighted users get. This is a minor clarity gap, not a blocking barrier, since the title alone is descriptive enough to identify the article.",
      "evidence": {
        "selector": "article a[href*='/posts/']",
        "note": "category span and icon are aria-hidden, not included in link name"
      }
    },
    {
      "type": "finding",
      "id": 2308,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.3.1",
      "severity": "moderate",
      "title": "Repeated card structure lacks semantic heading markup for article titles",
      "detail": "Article card titles appear to be rendered as plain links rather than headings (e.g., h2/h3) within each 'article' element in the skeleton provided. This prevents screen-reader users from using heading navigation to skim the list of 19+ articles efficiently, forcing them to tab through each link individually. Fix: wrap each article title link in an appropriate heading level (e.g., <h2><a>Title</a></h2>) inside each <article> to support programmatic structure and navigation.",
      "evidence": {}
    }
  ],
  "errors": []
}