{
  "exported_at": "2026-09-30T10:04:57.338515Z",
  "kind": "page",
  "target": "https://capcrop.com",
  "run_id": "e3162c8faa6f40f485681eaf9b895edb",
  "status": "done",
  "stats": {
    "pages": 10,
    "templates": 9,
    "cache_hits": 8,
    "findings_by_severity": {
      "serious": 28,
      "moderate": 11,
      "minor": 28,
      "info": 35
    },
    "duration_secs": 53.37,
    "tokens": {
      "input": 10409,
      "output": 1741,
      "cache_read": 0,
      "cache_write": 0
    }
  },
  "findings": [
    {
      "type": "finding",
      "id": 524,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 525,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 526,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 527,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 528,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 529,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 530,
      "url": "https://capcrop.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 531,
      "url": "https://capcrop.com",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": ".signup-card > .signup > form > button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          },
          {
            "selector": ".refer",
            "snippet": "<span class=\"promo-tag refer\">Refer &amp; earn</span>"
          },
          {
            "selector": ".cta-band > .signup > form > button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          },
          {
            "selector": ".val",
            "snippet": "<span class=\"ochip val\">a $6 value</span>"
          }
        ],
        "node_count": 5,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 532,
      "url": "https://capcrop.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.89",
      "detail": "Lighthouse category 'Performance' scored 0.89 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.89
      }
    },
    {
      "type": "finding",
      "id": 533,
      "url": "https://capcrop.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.95",
      "detail": "Lighthouse category 'Accessibility' scored 0.95 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.95
      }
    },
    {
      "type": "finding",
      "id": 534,
      "url": "https://capcrop.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 535,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 536,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 537,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 538,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 539,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 540,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 541,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 542,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 543,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 544,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.94",
      "detail": "Lighthouse category 'Accessibility' scored 0.94 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.94
      }
    },
    {
      "type": "finding",
      "id": 545,
      "url": "https://capcrop.com/guides/digitize-old-family-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 546,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 547,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 548,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 549,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 550,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 551,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 552,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 553,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 554,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 555,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.95",
      "detail": "Lighthouse category 'Accessibility' scored 0.95 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.95
      }
    },
    {
      "type": "finding",
      "id": 556,
      "url": "https://capcrop.com/batch-crop",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 557,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 558,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 559,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 560,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 561,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 562,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 563,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 564,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 565,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 566,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.94",
      "detail": "Lighthouse category 'Accessibility' scored 0.94 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.94
      }
    },
    {
      "type": "finding",
      "id": 567,
      "url": "https://capcrop.com/guides/why-we-dont-train-ai-on-your-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 568,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 569,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 570,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 571,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 572,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 573,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 574,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 575,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 576,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 577,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.95",
      "detail": "Lighthouse category 'Accessibility' scored 0.95 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.95
      }
    },
    {
      "type": "finding",
      "id": 578,
      "url": "https://capcrop.com/guides/scan-multiple-photos-flatbed",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 579,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 580,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 581,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 582,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 583,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 584,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 585,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 586,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 587,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 588,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.94",
      "detail": "Lighthouse category 'Accessibility' scored 0.94 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.94
      }
    },
    {
      "type": "finding",
      "id": 589,
      "url": "https://capcrop.com/guides/scan-color-negatives-flatbed",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 590,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 591,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 592,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 593,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 594,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 595,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 596,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 597,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 598,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 599,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.94",
      "detail": "Lighthouse category 'Accessibility' scored 0.94 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.94
      }
    },
    {
      "type": "finding",
      "id": 600,
      "url": "https://capcrop.com/guides/straighten-scanned-photos",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 601,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 602,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 603,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 604,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 605,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 606,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 607,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 608,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 609,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 0.99",
      "detail": "Lighthouse category 'Performance' scored 0.99 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.99
      }
    },
    {
      "type": "finding",
      "id": 610,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.95",
      "detail": "Lighthouse category 'Accessibility' scored 0.95 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.95
      }
    },
    {
      "type": "finding",
      "id": 611,
      "url": "https://capcrop.com/compare/capcrop-vs-photomyne",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 612,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 613,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-hsts",
      "severity": "serious",
      "title": "Missing Strict-Transport-Security header",
      "detail": "This HTTPS page does not send Strict-Transport-Security, so browsers won't enforce HTTPS on subsequent visits.",
      "evidence": {
        "header": "strict-transport-security",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 614,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-frame-protection",
      "severity": "moderate",
      "title": "Missing clickjacking protection",
      "detail": "Neither X-Frame-Options nor a CSP frame-ancestors directive is present, so the page can be framed by another site.",
      "evidence": {
        "x-frame-options": null,
        "csp_frame_ancestors": false
      }
    },
    {
      "type": "finding",
      "id": 615,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-xcto",
      "severity": "minor",
      "title": "Missing X-Content-Type-Options: nosniff",
      "detail": "Without 'nosniff', browsers may MIME-sniff responses in ways that enable content-type confusion attacks.",
      "evidence": {
        "header": "x-content-type-options",
        "value": null
      }
    },
    {
      "type": "finding",
      "id": 616,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-referrer-policy",
      "severity": "minor",
      "title": "Missing Referrer-Policy header",
      "detail": "No Referrer-Policy header was present, so the browser's default (often permissive) referrer behavior applies.",
      "evidence": {
        "header": "referrer-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 617,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 618,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 619,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "color-contrast",
      "severity": "serious",
      "title": "Elements must meet minimum color contrast ratio thresholds",
      "detail": "Ensure the contrast between foreground and background colors meets WCAG 2 AA minimum contrast ratio thresholds https://dequeuniversity.com/rules/axe/4.10/color-contrast?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": ".cta-mini",
            "snippet": "<a class=\"cta-mini\" href=\"#join\">Get early access</a>"
          },
          {
            "selector": "button",
            "snippet": "<button class=\"cap-btn\" type=\"submit\">Get early access</button>"
          }
        ],
        "node_count": 2,
        "tags": [
          "cat.color",
          "wcag2aa",
          "wcag143",
          "TTv5",
          "TT13.c",
          "EN-301-549",
          "EN-9.1.4.3",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 620,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 1",
      "detail": "Lighthouse category 'Performance' scored 1 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 621,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 0.95",
      "detail": "Lighthouse category 'Accessibility' scored 0.95 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 0.95
      }
    },
    {
      "type": "finding",
      "id": 622,
      "url": "https://capcrop.com/compare/capcrop-vs-autocropper",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 623,
      "url": "https://capcrop.com",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.4.3",
      "severity": "serious",
      "title": "Potential low-contrast text on marketing sections",
      "detail": "Low-vision users may not be able to read text if color contrast is insufficient. Flagged elements likely include the muted/secondary copy (e.g., 'launching 2026', 'Private beta \u00b7 opening soon', aria-hidden decorative labels rendered near visible content, and hashtag/caption text like '#roadtrip #1970 #yellowstone') which often use light-gray-on-white or pastel color schemes typical of modern SaaS landing pages. Without direct rendering access this cannot be confirmed pixel-by-pixel, but given the design pattern (small uppercase eyebrow text, muted captions), contrast ratio is likely below the 4.5:1 (normal text) or 3:1 (large text) threshold. Fix: verify actual computed colors with a contrast checker (e.g., axe, Lighthouse) and adjust foreground/background pairs to meet AA minimums, particularly for small gray text used in badges, eyebrow labels, and photo captions.",
      "evidence": {
        "selector": "nav > *, section > div[aria-hidden] captions, .eyebrow/badge text",
        "note": "visual/computed style inspection required to confirm exact ratio"
      }
    },
    {
      "type": "finding",
      "id": 624,
      "url": "https://capcrop.com",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/3.3.1",
      "severity": "moderate",
      "title": "No accessible error/success feedback for email signup forms",
      "detail": "Screen-reader users and low-vision users submitting the email capture forms (both in the hero and bottom 'Be first through the door' sections) have no way to perceive validation errors (e.g., invalid email) or confirmation of success beyond native browser tooltips, which are not reliably announced by assistive tech and may not appear at all if custom JS intercepts submission. Fix: add an aria-live region (polite) near each form that reports 'Please enter a valid email' or 'Thanks, you're on the list' when the form is submitted, and ensure error text is programmatically associated with the input via aria-describedby.",
      "evidence": {
        "selector": "form input[type=email]",
        "note": "only 'required' attribute present, no error/success messaging observed"
      }
    },
    {
      "type": "finding",
      "id": 625,
      "url": "https://capcrop.com",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/4.1.3",
      "severity": "minor",
      "title": "Status messages not exposed via live regions",
      "detail": "If submission succeeds or fails asynchronously (e.g., single-page behavior), the resulting status message is not wrapped in a role='status' or aria-live container, so screen reader users won't be notified of the outcome without moving focus manually. Add role='status' or aria-live='polite' to the confirmation/error message container.",
      "evidence": {
        "selector": "form",
        "note": "no aria-live region present near forms"
      }
    }
  ],
  "errors": []
}