{
  "exported_at": "2026-09-30T10:02:37.951451Z",
  "kind": "page",
  "target": "https://artificialatheist.com",
  "run_id": "de036b2b5071432fb652d023ecb9abc8",
  "status": "done",
  "stats": {
    "pages": 20,
    "templates": 19,
    "findings_by_severity": {
      "moderate": 51,
      "info": 37,
      "serious": 2,
      "minor": 16
    },
    "duration_secs": 540.0,
    "tokens": {
      "input": 106600,
      "output": 15238,
      "cache_read": 0,
      "cache_write": 0
    },
    "tokens_by_model": {
      "claude-haiku-4-5": {
        "input": 32152,
        "output": 6263,
        "cache_read": 0,
        "cache_write": 0
      },
      "claude-sonnet-5": {
        "input": 74448,
        "output": 8975,
        "cache_read": 0,
        "cache_write": 0
      }
    },
    "estimated_cost_usd": 0.4214
  },
  "findings": [
    {
      "type": "finding",
      "id": 2417,
      "url": "https://artificialatheist.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2418,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.59",
      "detail": "Lighthouse category 'Performance' scored 0.59 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.59
      }
    },
    {
      "type": "finding",
      "id": 2419,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2420,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2421,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2422,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.56",
      "detail": "Lighthouse category 'Performance' scored 0.56 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.56
      }
    },
    {
      "type": "finding",
      "id": 2423,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2424,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2425,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2426,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.63",
      "detail": "Lighthouse category 'Performance' scored 0.63 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.63
      }
    },
    {
      "type": "finding",
      "id": 2427,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2428,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2429,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2430,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.87",
      "detail": "Lighthouse category 'Performance' scored 0.87 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.87
      }
    },
    {
      "type": "finding",
      "id": 2431,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2432,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2433,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2434,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.69",
      "detail": "Lighthouse category 'Performance' scored 0.69 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.69
      }
    },
    {
      "type": "finding",
      "id": 2435,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2436,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2437,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2438,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.72",
      "detail": "Lighthouse category 'Performance' scored 0.72 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.72
      }
    },
    {
      "type": "finding",
      "id": 2439,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2440,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2441,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2442,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.85",
      "detail": "Lighthouse category 'Performance' scored 0.85 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.85
      }
    },
    {
      "type": "finding",
      "id": 2443,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2444,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2445,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2446,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.84",
      "detail": "Lighthouse category 'Performance' scored 0.84 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.84
      }
    },
    {
      "type": "finding",
      "id": 2447,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2448,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2449,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2450,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.73",
      "detail": "Lighthouse category 'Performance' scored 0.73 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.73
      }
    },
    {
      "type": "finding",
      "id": 2451,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2452,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2453,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2454,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.63",
      "detail": "Lighthouse category 'Performance' scored 0.63 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.63
      }
    },
    {
      "type": "finding",
      "id": 2455,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2456,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2457,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2458,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.89",
      "detail": "Lighthouse category 'Performance' scored 0.89 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.89
      }
    },
    {
      "type": "finding",
      "id": 2459,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2460,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2461,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2462,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.7",
      "detail": "Lighthouse category 'Performance' scored 0.7 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.7
      }
    },
    {
      "type": "finding",
      "id": 2463,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2464,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2465,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2466,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.7",
      "detail": "Lighthouse category 'Performance' scored 0.7 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.7
      }
    },
    {
      "type": "finding",
      "id": 2467,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2468,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2469,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2470,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.74",
      "detail": "Lighthouse category 'Performance' scored 0.74 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.74
      }
    },
    {
      "type": "finding",
      "id": 2471,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2472,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2473,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2474,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.81",
      "detail": "Lighthouse category 'Performance' scored 0.81 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.81
      }
    },
    {
      "type": "finding",
      "id": 2475,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2476,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2477,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2478,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.73",
      "detail": "Lighthouse category 'Performance' scored 0.73 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.73
      }
    },
    {
      "type": "finding",
      "id": 2479,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2480,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2481,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2482,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "document-title",
      "severity": "serious",
      "title": "Documents must have <title> element to aid in navigation",
      "detail": "Ensure each HTML document contains a non-empty <title> element https://dequeuniversity.com/rules/axe/4.10/document-title?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.text-alternatives",
          "wcag2a",
          "wcag242",
          "TTv5",
          "TT12.a",
          "EN-301-549",
          "EN-9.2.4.2",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2483,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "html-has-lang",
      "severity": "serious",
      "title": "<html> element must have a lang attribute",
      "detail": "Ensure every HTML document has a lang attribute https://dequeuniversity.com/rules/axe/4.10/html-has-lang?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.language",
          "wcag2a",
          "wcag311",
          "TTv5",
          "TT11.a",
          "EN-301-549",
          "EN-9.3.1.1",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2484,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "landmark-one-main",
      "severity": "moderate",
      "title": "Document should have one main landmark",
      "detail": "Ensure the document has a main landmark https://dequeuniversity.com/rules/axe/4.10/landmark-one-main?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.semantics",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2485,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "page-has-heading-one",
      "severity": "moderate",
      "title": "Page should contain a level-one heading",
      "detail": "Ensure that the page, or at least one of its frames contains a level-one heading https://dequeuniversity.com/rules/axe/4.10/page-has-heading-one?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.semantics",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2486,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "region",
      "severity": "moderate",
      "title": "All page content should be contained by landmarks",
      "detail": "Ensure all page content is contained by landmarks https://dequeuniversity.com/rules/axe/4.10/region?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "pre",
            "snippet": "<pre style=\"word-wrap: break-word; white-space: pre-wrap;\">"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.keyboard",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2487,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse-unavailable",
      "severity": "info",
      "title": "Lighthouse unavailable",
      "detail": "could not parse lighthouse output (rc=1): Unterminated string starting at: line 424 column 21 (char 65377). stderr: Runtime error encountered: The page provided is not HTML (served as MIME type text/plain).\n",
      "evidence": {}
    },
    {
      "type": "finding",
      "id": 2488,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2489,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.85",
      "detail": "Lighthouse category 'Performance' scored 0.85 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.85
      }
    },
    {
      "type": "finding",
      "id": 2490,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2491,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2492,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2493,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.85",
      "detail": "Lighthouse category 'Performance' scored 0.85 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.85
      }
    },
    {
      "type": "finding",
      "id": 2494,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2495,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2496,
      "url": "https://artificialatheist.com",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "moderate",
      "title": "Article thumbnail images have empty alt text",
      "detail": "Screen reader users encounter article thumbnail images (e.g. what-the-nervous-system-of-c-elegans-actually-taught-us.png, the-afterlife-assumption...png, religion-by-inheritance...png) with alt=\"\", causing them to be skipped as decorative. Since these images are wrapped alongside article titles and appear to be editorial/topical illustrations accompanying distinct articles, they convey contextual meaning (visually distinguishing articles) that is lost for non-sighted users. If these images are purely decorative duplicates of the adjacent headline text, empty alt is correct and acceptable per 1.1.1; but if they carry unique topical content (e.g., a diagram, photo of a specific subject) not otherwise conveyed in text, they need descriptive alt text. Fix: audit each image\u2014use empty alt only for true decoration, otherwise provide concise descriptive alt text (e.g. alt=\"Illustration of C. elegans neural connectome\").",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "multiple article card thumbnails with alt=''"
      }
    },
    {
      "type": "finding",
      "id": 2497,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/3.3.2",
      "severity": "minor",
      "title": "Search input lacks a visible label",
      "detail": "The search input relies on aria-label='Search articles' and a placeholder for its label, so screen reader users get an accessible name, but low-vision users, users with cognitive disabilities, or those who zoom/enlarge text lose the placeholder text once they begin typing or when it's truncated, leaving no persistent visible label. Fix by adding a visible <label> (can be visually styled but not display:none) associated with the input via for/id, in addition to or instead of aria-label.",
      "evidence": {
        "selector": "input[type=search]",
        "note": "placeholder + aria-label only, no visible <label>"
      }
    },
    {
      "type": "finding",
      "id": 2498,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative-seeming article images have empty alt text but may convey topical content",
      "detail": "Article thumbnail images (e.g. what-the-nervous-system-of-c-elegans-actually-taught-us.png) use alt=\"\", treating them as purely decorative. Since each image is paired with a descriptive heading link right below it, this is likely acceptable, but if any images convey unique information not in the heading text, screen reader users would miss it. Verify intent; if truly decorative, current markup is fine per 1.1.1.",
      "evidence": {
        "selector": "article img",
        "snippet": "alt=\"\"",
        "note": "Low-severity, verify author intent"
      }
    },
    {
      "type": "finding",
      "id": 2499,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/2.4.4",
      "severity": "minor",
      "title": "Article link text is descriptive but duplicated across two elements",
      "detail": "Each article's title is wrapped in an <a> inside an <h2>, and the link text itself (e.g. 'What the Nervous System of C. elegans Actually Taught Us') is fully descriptive and meets 2.4.4 Link Purpose (In Context). No 'read more' ambiguous pattern was found in the skeleton. No barrier confirmed for screen-reader or low-vision users; closing out as non-issue after review.",
      "evidence": {
        "selector": "h2 > a",
        "note": "Reviewed and found compliant"
      }
    },
    {
      "type": "finding",
      "id": 2500,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or overly permissive Content-Security-Policy",
      "detail": "The site's CSP appears to lack strict directives such as script-src nonces/hashes, object-src 'none', and frame-ancestors, likely relying on broad allowances (e.g. 'unsafe-inline' or wildcard sources). This weakens defense-in-depth against XSS: if any injection point exists (e.g. via search or comment functionality), a weak CSP would not meaningfully block malicious script execution. Remediation: implement a strict CSP with per-response nonces or hashes for scripts/styles, explicit script-src/style-src allowlists, object-src 'none', base-uri 'self', and frame-ancestors 'self' to also cover clickjacking. Verify no 'unsafe-inline'/'unsafe-eval' are present.",
      "evidence": {
        "note": "CSP header content not fully shown but flagged as weak in triage; no nonce/hash strategy evident"
      }
    },
    {
      "type": "finding",
      "id": 2501,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative-style empty alt on featured article image likely acceptable",
      "detail": "The featured image accompanies a heading and full article text that already conveys the topic; screen-reader users lose little since the image appears purely illustrative/stock-style and is adjacent to the article title. If the image conveys unique information (e.g., a diagram of levels/relations specific to supervenience) not present in text, it should have descriptive alt text; otherwise empty alt is correct per 1.1.1 for decorative images. Recommend content review to confirm image is decorative before treating as a violation.",
      "evidence": {
        "selector": "article > img",
        "note": "Multiple article thumbnail images across the page all use alt=''; consistent pattern suggests decorative treatment rather than an isolated oversight."
      }
    },
    {
      "type": "finding",
      "id": 2502,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Empty alt text on article preview images is appropriate but redundant markup could be simplified",
      "detail": "The article preview images use alt=\"\" while the adjacent heading link already provides the article title text (e.g., 'The Concept of Supervenience...'). Since each image is purely illustrative and its meaning is fully conveyed by the adjacent linked heading, empty alt is actually the correct choice per 1.1.1 \u2014 screen reader users are not blocked because the redundant image is properly hidden from the accessibility tree and the article title is available via the heading link. No barrier exists for screen-reader users. This is not a real issue; downgrading concern, but flagging as minor documentation gap: authors should confirm each image truly has an equivalent text nearby before relying on alt=\"\", since if any image conveyed unique information (e.g., a diagram) this pattern would fail 1.1.1.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Verified adjacent h2 > a provides equivalent text content, so empty alt is compliant, not a violation."
      }
    },
    {
      "type": "finding",
      "id": 2503,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak Content-Security-Policy allows injection vectors",
      "detail": "The site's CSP appears weak or permissive (e.g., allowing 'unsafe-inline' or broad script-src wildcards), which reduces its effectiveness as a mitigation against XSS. Although this is a static content/blog site with no visible user input forms in the skeleton, third-party embeds (e.g., Ko-fi widget) and any future comment/search functionality could become injection vectors if CSP does not restrict script sources tightly. Remediation: adopt a strict CSP with nonce- or hash-based script-src, avoid 'unsafe-inline'/'unsafe-eval', and explicitly set object-src 'none' and base-uri 'self'. Verify frame-ancestors is set to mitigate clickjacking as a compensating control.",
      "evidence": {
        "note": "CSP header not shown in full; flagged as weak by triage. No inline event handlers observed in skeleton, and no user-input forms visible, which lowers immediate exploitability."
      }
    },
    {
      "type": "finding",
      "id": 2504,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative-looking article header image lacks alt text but may be purely decorative",
      "detail": "The hero image accompanying the article has alt=\"\" which is only appropriate if the image is purely decorative and conveys no information beyond what's in the surrounding text. Given this appears to be a generic illustrative/stock image alongside the article title and headings, empty alt is likely acceptable since the article text fully conveys the content. Screen reader users are not blocked from any unique information as long as the image doesn't contain data, diagrams, or text not present elsewhere. No fix needed unless the image contains meaningful visual information (e.g., a diagram of the argument); if so, add a concise descriptive alt attribute.",
      "evidence": {
        "selector": "article img[src='the-afterlife-assumption-what-immortality-costs-moral-reason.png']",
        "note": "Applies also to the related-post thumbnail img with alt=''.\", \"criterion\": \"1.1.1"
      }
    },
    {
      "type": "finding",
      "id": 2505,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g. overly broad source lists, allowance of 'unsafe-inline'/'unsafe-eval', or missing object-src/base-uri/frame-ancestors restrictions), which reduces its effectiveness as a defense-in-depth control against XSS and clickjacking. Given this is a static/blog-style content site with no visible user input forms in the skeleton, the practical exploitation surface is limited, but any future injection point (comments, search, third-party embeds) would not be well contained. Remediation: tighten CSP to a strict allowlist (avoid 'unsafe-inline'/'unsafe-eval'), add explicit object-src 'none', base-uri 'self', and frame-ancestors 'none' or 'self' to also cover clickjacking, and consider a nonce/hash-based approach for any inline scripts.",
      "evidence": {
        "note": "CSP directive strength inferred from triage flag; no strong compensating directives (frame-ancestors, strict script-src) confirmed present."
      }
    },
    {
      "type": "finding",
      "id": 2506,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Featured article images use empty alt text",
      "detail": "The article's hero image and related-post thumbnail images have alt=\"\" and are not marked with role=presentation or otherwise semantically hidden beyond alt. If these images are purely decorative/stock illustrations accompanying the article title, empty alt is acceptable and correct per 1.1.1. However, since the image filename suggests it is a topic-specific illustration for the post, screen reader users get no indication of any illustrative content; if the image conveys any meaning beyond decoration (e.g., a diagram or thematically relevant photo the sighted reader would appreciate), it should have a short descriptive alt. As currently implemented (empty alt, no other indication) this is a low-severity issue since the title and surrounding text already establish context, so screen-reader users lose little, but authors should confirm the images are truly decorative.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "the-gambler-s-fallacy...png and related post thumbnail img both use alt=''"
      }
    },
    {
      "type": "finding",
      "id": 2507,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Empty alt on featured article image likely acceptable but should be verified",
      "detail": "The featured image at the top of the article has alt=\"\" (decorative treatment). Since the image sits directly beside the article title and appears to be a generic/stock illustration rather than conveying unique information not present in the surrounding text (headline, article text), empty alt is likely appropriate under 1.1.1 and reduces noise for screen-reader users. However, if the image contains a chart, statistic, or infographic-like content relevant to the article's data claims (e.g., 'the data are not subtle'), the empty alt would hide meaningful information from screen-reader users and should instead have a descriptive alt text. A sighted reviewer should confirm the image is purely decorative/stock; if it conveys information, add a concise alt describing that content.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Same empty-alt pattern also used on related-post thumbnail image, suggesting a site-wide decorative-image convention rather than an oversight, which supports treating it as low severity."
      }
    },
    {
      "type": "finding",
      "id": 2508,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/security-misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., allowing 'unsafe-inline' and/or broad script-src wildcards, or missing entirely), reducing its effectiveness as a mitigation against XSS/injection. A blog with search functionality and dynamic content rendering is a plausible injection surface. Recommend adopting a strict CSP: avoid 'unsafe-inline'/'unsafe-eval', use nonces or hashes for any required inline scripts, restrict script-src/object-src to 'self' and trusted CDNs only, and add frame-ancestors to also cover clickjacking protection.",
      "evidence": {
        "selector": "CSP header",
        "snippet": "header not fully provided, inferred weak/absent policy",
        "note": "No CSP directive text was supplied in the observed headers, or the policy did not restrict script-src/style-src tightly enough \u2014 flagged for weak policy per triage; exact directive values unavailable for confirmation."
      }
    },
    {
      "type": "finding",
      "id": 2509,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Empty alt text on article hero/thumbnail images",
      "detail": "The hero image in the article and the thumbnail images in the related-post cards use alt=\"\" despite having filenames that suggest they are topical illustrations (e.g. 'secularism-and-the-political-party-when-movements-organise.png'). If these images convey any topical/editorial meaning beyond decoration (e.g. an illustrative graphic tied to the article's theme), screen-reader users get no equivalent information, while sighted users receive a visual cue. However, since adjacent text (headline, topic label) already conveys the same information redundantly, marking them decorative is likely correct and not a barrier. Recommend confirming with content editors that these images are purely decorative/stock-like illustrations with no unique information; if they are, alt=\"\" is correct per 1.1.1's guidance on decorative images and no fix is needed. If any image contains text or diagrammatic content, add descriptive alt text.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Filenames mirror article/heading titles, suggesting possible informative content; low confidence issue given redundant text context nearby."
      }
    },
    {
      "type": "finding",
      "id": 2510,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The observed CSP does not sufficiently restrict script-src/object-src or lacks nonce/hash-based restrictions, leaving the page more exposed to injected script execution if any XSS sink is found elsewhere on the site (e.g., search page, comment/contact forms). Even a static blog benefits from a strict CSP as defense-in-depth against third-party script compromise (e.g., analytics, ad tags). Remediation: define a strict CSP with script-src 'self' plus explicit trusted hosts, avoid 'unsafe-inline'/'unsafe-eval', and add frame-ancestors and base-uri directives to cover the layered risk (clickjacking, base tag injection).",
      "evidence": {
        "selector": "header:Content-Security-Policy",
        "note": "CSP present but weak; no directive limiting inline scripts or object-src observed"
      }
    },
    {
      "type": "finding",
      "id": 2511,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative empty alt on article preview images likely acceptable, but verify redundancy",
      "detail": "Each article card's preview image has alt=\"\" while the adjacent heading link (e.g., 'Religion by Inheritance: How Birth Predicts Belief') provides the same information textually. For screen-reader users, this is compliant under 1.1.1 since the image is decorative/redundant to the linked heading text. No barrier exists as long as every preview image is purely illustrative and does not convey unique information not present in the heading or excerpt. If any preview image conveys unique meaning (e.g., a chart, diagram, or infographic specific to that article) alt=\"\" would fail 1.1.1 and needs a real description. Recommend confirming all article images are purely decorative/stock; otherwise add meaningful alt text.",
      "evidence": {
        "selector": "article img[alt='']",
        "snippet": "<img alt=\"\" src=\"religion-by-inheritance-how-birth-predicts-belief.png\">",
        "note": "No barrier confirmed for generic case; flag only if images ever carry unique content."
      }
    },
    {
      "type": "finding",
      "id": 2512,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative-treated featured image lacks alt text",
      "detail": "Screen-reader users get no description of the featured article image (alt=\"\"). Since the image appears to be a generic/illustrative stock or AI-generated graphic accompanying the article rather than conveying unique data or content not present in the text, empty alt is acceptable per WCAG if truly decorative, but if it depicts something informative (e.g., a diagram of the C. elegans nervous system) that isn't described elsewhere, this is a Success Criterion 1.1.1 violation. Fix: verify image content; if purely decorative/illustrative, empty alt is correct and no fix needed, otherwise add a concise descriptive alt text summarizing what the image shows.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Same pattern repeats on card images in article list, suggesting a site-wide template decision to treat all post images as decorative."
      }
    },
    {
      "type": "finding",
      "id": 2513,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "moderate",
      "title": "Decorative-only alt text on article preview images",
      "detail": "Screen-reader users get no information from article thumbnail images (alt=\"\"), which may be acceptable if purely decorative, but since these images accompany distinct article previews they could convey topical context. If the images are purely decorative this is fine, but if they illustrate article content, empty alt text deprives blind users of that context. Verify intent and add concise alt text if images are meaningful.",
      "evidence": {
        "selector": "article img[alt='']",
        "snippet": "<img alt=\"\" src=\"machine-authored-inquiry.png\">",
        "note": "1.1.1 Non-text Content"
      }
    },
    {
      "type": "finding",
      "id": 2514,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/2.4.6",
      "severity": "minor",
      "title": "Article preview link text relies on adjacent heading only",
      "detail": "Each article card's link text (the h2 link) is descriptive, but the surrounding preview text block itself is not part of the link, meaning screen-reader users navigating by links or headings still get meaningful names via the h2 link text; this is not a barrier. No fix needed\u2014confirmed non-issue upon deep review.",
      "evidence": {
        "selector": "article h2 a",
        "note": "2.4.4/2.4.6 satisfied"
      }
    },
    {
      "type": "finding",
      "id": 2515,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.3.1",
      "severity": "moderate",
      "title": "Article preview structure lacks semantic grouping for category label",
      "detail": "The 'News' category label rendered as a <span aria-hidden=\"true\"> inside each article is hidden from assistive tech entirely, so screen-reader users cannot perceive the topic/category associated with each preview article, reducing their ability to distinguish article purpose in a list of results. Fix: remove aria-hidden from the category label or provide an accessible equivalent (e.g., visually-hidden text) so AT users can perceive the category alongside sighted users.",
      "evidence": {
        "selector": "article span[aria-hidden='true']",
        "snippet": "<span aria-hidden=\"true\"> News",
        "note": "1.3.1 Info and Relationships"
      }
    },
    {
      "type": "finding",
      "id": 2516,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or missing Content-Security-Policy",
      "detail": "The site's CSP appears weak or overly permissive, which reduces defense-in-depth against XSS/injection if any script injection vector is later found (e.g., via search or comment features). For a static content blog with no visible user-input forms besides search, the practical exploitation risk is lower, but a weak CSP still removes an important mitigation layer. Recommend adopting a strict CSP with nonce/hash-based script-src, restricting object-src 'none', and setting frame-ancestors to prevent clickjacking, especially since the search feature could become an injection surface.",
      "evidence": {
        "selector": "header",
        "note": "CSP header present but permissive/weak per triage; no compensating frame-ancestors or strict script-src confirmed"
      }
    },
    {
      "type": "finding",
      "id": 2517,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Hero image alt text likely appropriate but should be verified",
      "detail": "The hero image (what-the-multiverse-hypothesis-actually-predicts.png) uses alt=\"\" which is correct if the image is purely decorative/illustrative and does not convey information beyond the article title/topic already in the heading. Since the image is a generic topical illustration accompanying an article that already has a descriptive h1 and topic label, empty alt is an acceptable pattern for 1.1.1 and does not block screen reader users from accessing content. No fix required unless the image contains diagram-like content (e.g., illustrating a specific concept from the article) that isn't conveyed elsewhere in text, in which case a concise descriptive alt should be added.",
      "evidence": {
        "selector": "article > img[alt='']",
        "note": "Confirmed as low-risk; decorative treatment is reasonable for a stock/illustrative hero image."
      }
    },
    {
      "type": "finding",
      "id": 2518,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site references external embeds (Ko-fi) and no CSP directives were confirmed as strict. A weak or missing CSP (e.g., allowing 'unsafe-inline' scripts or wildcard sources) increases the impact of any injected script (XSS) since there is no defense-in-depth layer to block exfiltration or inline script execution. For a static content site this is lower urgency, but if user input is ever rendered (comments, search) this becomes a serious injection vector. Remediation: define a CSP with explicit script-src/style-src allowlists (avoiding 'unsafe-inline'/'unsafe-eval'), and add frame-ancestors to mitigate clickjacking, rather than relying on X-Frame-Options alone.",
      "evidence": {
        "note": "CSP directives not confirmed as restrictive; external third-party embed (ko-fi.com) present in markup"
      }
    },
    {
      "type": "finding",
      "id": 2519,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative-style empty alt on hero/preview images likely acceptable but should be verified against content role",
      "detail": "The hero image and article preview thumbnails use alt=\"\" (treated as decorative). If these images are purely stylistic/illustrative accompaniment to the article title, empty alt is correct per 1.1.1 and no barrier exists for screen-reader users. However, if the images convey topical context not otherwise available in text (e.g., a photo illustrating a specific courtroom scene), the empty alt would deny that information to blind users. Fix: confirm editorial intent; if decorative, keep alt=\"\"; if meaningful, add concise descriptive alt text.",
      "evidence": {
        "selector": "img[src*='secularism-and-the-court-witness']",
        "note": "alt=\"\" on hero image; similarly empty/generic alt on related-article thumbnail"
      }
    },
    {
      "type": "finding",
      "id": 2520,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or missing Content-Security-Policy",
      "detail": "No robust CSP (e.g. script-src restrictions, frame-ancestors) was observed in the provided headers. This page includes interactive JS-driven quiz functionality, increasing the impact of any future XSS: without a strict CSP, injected scripts could execute freely and exfiltrate data or hijack the interactive quiz flow. Remediate by adding a CSP with script-src 'self' (plus specific trusted hosts), object-src 'none', and frame-ancestors 'self', avoiding 'unsafe-inline'/'unsafe-eval'.",
      "evidence": {
        "selector": "response headers",
        "note": "Content-Security-Policy header absent or permissive; not enumerated in provided header set"
      }
    },
    {
      "type": "finding",
      "id": 2521,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "minor",
      "title": "Clickjacking protection not confirmed",
      "detail": "No X-Frame-Options header or CSP frame-ancestors directive was observed. While impact is limited on a quiz page, an attacker could frame the page for clickjacking against the interactive buttons (e.g. 'Start random quiz'). Add frame-ancestors 'self' via CSP or set X-Frame-Options: SAMEORIGIN.",
      "evidence": {
        "selector": "response headers",
        "note": "X-Frame-Options absent; CSP frame-ancestors not confirmed present"
      }
    },
    {
      "type": "finding",
      "id": 2522,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative icons properly hidden but topic links rely solely on visible text",
      "detail": "Icons (<i aria-hidden=\"true\">) inside nav topic links and header buttons are correctly hidden from assistive tech, and adjacent visible text ('Science', 'News') or aria-label attributes (e.g., 'Smaller text', 'Toggle light or dark mode') provide accessible names. This pattern is compliant for screen-reader users under 4.1.2 Name, Role, Value and 1.1.1 Non-text Content \u2014 no barrier found for these instances. No fix required.",
      "evidence": {
        "selector": "nav[aria-label='Topics'] a i[aria-hidden='true']",
        "note": "Verified icons have accessible sibling text or parent aria-label"
      }
    }
  ],
  "errors": []
}