{
  "exported_at": "2026-09-30T10:03:05.641029Z",
  "kind": "page",
  "target": "https://artificialatheist.com",
  "run_id": "f3f833d64df94e90ace1a17203e6aa91",
  "status": "done",
  "stats": {
    "pages": 20,
    "templates": 19,
    "cache_hits": 1,
    "findings_by_severity": {
      "moderate": 46,
      "serious": 13,
      "info": 38,
      "minor": 15
    },
    "duration_secs": 512.96,
    "tokens": {
      "input": 127279,
      "output": 16983,
      "cache_read": 0,
      "cache_write": 0
    },
    "tokens_by_model": {
      "claude-haiku-4-5": {
        "input": 30699,
        "output": 5649,
        "cache_read": 0,
        "cache_write": 0
      },
      "claude-sonnet-5": {
        "input": 96580,
        "output": 11334,
        "cache_read": 0,
        "cache_write": 0
      }
    },
    "estimated_cost_usd": 0.5187
  },
  "findings": [
    {
      "type": "finding",
      "id": 1967,
      "url": "https://artificialatheist.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1968,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "serious",
      "title": "Lighthouse Performance score: 0.45",
      "detail": "Lighthouse category 'Performance' scored 0.45 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.45
      }
    },
    {
      "type": "finding",
      "id": 1969,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1970,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1971,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1972,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "serious",
      "title": "Lighthouse Performance score: 0.4",
      "detail": "Lighthouse category 'Performance' scored 0.4 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.4
      }
    },
    {
      "type": "finding",
      "id": 1973,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1974,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1975,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1976,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "serious",
      "title": "Lighthouse Performance score: 0.48",
      "detail": "Lighthouse category 'Performance' scored 0.48 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.48
      }
    },
    {
      "type": "finding",
      "id": 1977,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1978,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1979,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-csp",
      "severity": "serious",
      "title": "Missing Content-Security-Policy header",
      "detail": "No Content-Security-Policy header was present, leaving the page without a script-injection safety net.",
      "evidence": {
        "header": "content-security-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 1980,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "security",
      "tier": 0,
      "rule": "missing-permissions-policy",
      "severity": "info",
      "title": "Missing Permissions-Policy header",
      "detail": "No Permissions-Policy header was present to restrict access to powerful browser features.",
      "evidence": {
        "header": "permissions-policy",
        "present": false
      }
    },
    {
      "type": "finding",
      "id": 1981,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "security",
      "tier": 0,
      "rule": "server-version-disclosure",
      "severity": "minor",
      "title": "Server header discloses version information",
      "detail": "The server header ('nginx/1.24.0 (Ubuntu)') discloses software/version details useful for targeting known vulnerabilities.",
      "evidence": {
        "header": "server",
        "value": "nginx/1.24.0 (Ubuntu)"
      }
    },
    {
      "type": "finding",
      "id": 1982,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "document-title",
      "severity": "serious",
      "title": "Documents must have <title> element to aid in navigation",
      "detail": "Ensure each HTML document contains a non-empty <title> element https://dequeuniversity.com/rules/axe/4.10/document-title?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.text-alternatives",
          "wcag2a",
          "wcag242",
          "TTv5",
          "TT12.a",
          "EN-301-549",
          "EN-9.2.4.2",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1983,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "html-has-lang",
      "severity": "serious",
      "title": "<html> element must have a lang attribute",
      "detail": "Ensure every HTML document has a lang attribute https://dequeuniversity.com/rules/axe/4.10/html-has-lang?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.language",
          "wcag2a",
          "wcag311",
          "TTv5",
          "TT11.a",
          "EN-301-549",
          "EN-9.3.1.1",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1984,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "landmark-one-main",
      "severity": "moderate",
      "title": "Document should have one main landmark",
      "detail": "Ensure the document has a main landmark https://dequeuniversity.com/rules/axe/4.10/landmark-one-main?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.semantics",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1985,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "page-has-heading-one",
      "severity": "moderate",
      "title": "Page should contain a level-one heading",
      "detail": "Ensure that the page, or at least one of its frames contains a level-one heading https://dequeuniversity.com/rules/axe/4.10/page-has-heading-one?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.semantics",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1986,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "region",
      "severity": "moderate",
      "title": "All page content should be contained by landmarks",
      "detail": "Ensure all page content is contained by landmarks https://dequeuniversity.com/rules/axe/4.10/region?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "pre",
            "snippet": "<pre style=\"word-wrap: break-word; white-space: pre-wrap;\">"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.keyboard",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1987,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse-unavailable",
      "severity": "info",
      "title": "Lighthouse unavailable",
      "detail": "could not parse lighthouse output (rc=1): Unterminated string starting at: line 806 column 21 (char 130799). stderr: Runtime error encountered: The page provided is not HTML (served as MIME type text/plain).\n",
      "evidence": {}
    },
    {
      "type": "finding",
      "id": 1988,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1989,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.5",
      "detail": "Lighthouse category 'Performance' scored 0.5 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.5
      }
    },
    {
      "type": "finding",
      "id": 1990,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1991,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1992,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1993,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "serious",
      "title": "Lighthouse Performance score: 0.43",
      "detail": "Lighthouse category 'Performance' scored 0.43 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.43
      }
    },
    {
      "type": "finding",
      "id": 1994,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1995,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1996,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 1997,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.52",
      "detail": "Lighthouse category 'Performance' scored 0.52 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.52
      }
    },
    {
      "type": "finding",
      "id": 1998,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 1999,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2000,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2001,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.66",
      "detail": "Lighthouse category 'Performance' scored 0.66 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.66
      }
    },
    {
      "type": "finding",
      "id": 2002,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2003,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2004,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2005,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "serious",
      "title": "Lighthouse Performance score: 0.48",
      "detail": "Lighthouse category 'Performance' scored 0.48 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.48
      }
    },
    {
      "type": "finding",
      "id": 2006,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2007,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2008,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2009,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "serious",
      "title": "Lighthouse Performance score: 0.43",
      "detail": "Lighthouse category 'Performance' scored 0.43 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.43
      }
    },
    {
      "type": "finding",
      "id": 2010,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2011,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2012,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2013,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "serious",
      "title": "Lighthouse Performance score: 0.4",
      "detail": "Lighthouse category 'Performance' scored 0.4 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.4
      }
    },
    {
      "type": "finding",
      "id": 2014,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2015,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2016,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2017,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "serious",
      "title": "Lighthouse Performance score: 0.44",
      "detail": "Lighthouse category 'Performance' scored 0.44 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.44
      }
    },
    {
      "type": "finding",
      "id": 2018,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2019,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2020,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2021,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.54",
      "detail": "Lighthouse category 'Performance' scored 0.54 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.54
      }
    },
    {
      "type": "finding",
      "id": 2022,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2023,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2024,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2025,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.59",
      "detail": "Lighthouse category 'Performance' scored 0.59 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.59
      }
    },
    {
      "type": "finding",
      "id": 2026,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2027,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2028,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2029,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "serious",
      "title": "Lighthouse Performance score: 0.43",
      "detail": "Lighthouse category 'Performance' scored 0.43 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.43
      }
    },
    {
      "type": "finding",
      "id": 2030,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2031,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2032,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2033,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.58",
      "detail": "Lighthouse category 'Performance' scored 0.58 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.58
      }
    },
    {
      "type": "finding",
      "id": 2034,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2035,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2036,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2037,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.54",
      "detail": "Lighthouse category 'Performance' scored 0.54 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.54
      }
    },
    {
      "type": "finding",
      "id": 2038,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2039,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2040,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2041,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.66",
      "detail": "Lighthouse category 'Performance' scored 0.66 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.66
      }
    },
    {
      "type": "finding",
      "id": 2042,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2043,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2044,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 2045,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "serious",
      "title": "Lighthouse Performance score: 0.4",
      "detail": "Lighthouse category 'Performance' scored 0.4 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.4
      }
    },
    {
      "type": "finding",
      "id": 2046,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2047,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 2048,
      "url": "https://artificialatheist.com",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or insufficient Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., missing script-src/object-src restrictions or reliance on unsafe-inline/broad wildcards), which reduces defense-in-depth against XSS if any injection vector exists (e.g., search feature, comment rendering, or content-authoring pipeline for AI-generated posts). Impact: if an XSS bug is introduced, a permissive CSP fails to mitigate script execution, cookie theft, or content defacement. Remediation: define a strict CSP with explicit script-src (nonce or hash-based, no 'unsafe-inline'/'unsafe-eval'), default-src 'none' with allowlisted resource types, and frame-ancestors 'none' or 'self' to also cover clickjacking. Given the site has a search endpoint and dynamic content injection points (article rendering), tightening CSP is a reasonable compensating control.",
      "evidence": {
        "selector": "/search/ and dynamic article templates",
        "note": "No strong script-src/object-src restrictions evident; CSP directive strength not confirmed as strict"
      }
    },
    {
      "type": "finding",
      "id": 2049,
      "url": "https://artificialatheist.com",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Article preview thumbnails use empty alt text",
      "detail": "Screen-reader users browsing the article list get no penalty here because each thumbnail is paired with an adjacent text link/headline containing the same article title (e.g. 'Religion by Inheritance...'), so the image is decorative/redundant relative to nearby text. This satisfies 1.1.1 since redundant images may have empty alt. However, confirm every preview image is truly decorative (no unique visual information like charts/diagrams) \u2014 if any thumbnail conveys unique content not in the adjacent text, it needs descriptive alt text instead of empty alt.",
      "evidence": {
        "selector": "main section img[alt='']",
        "note": "e.g. what-the-nervous-system-of-c-elegans-actually-taught-us.png, the-afterlife-assumption-what-immortality-costs-moral-reason.png"
      }
    },
    {
      "type": "finding",
      "id": 2050,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or missing Content-Security-Policy",
      "detail": "No strong CSP was observed enforcing script-src/object-src restrictions. Without a CSP that restricts script sources and disallows inline scripts, any injected markup (e.g., via a stored XSS in comments, search, or third-party embeds like ko-fi widgets) could execute arbitrary JavaScript in visitors' browsers. This is a defense-in-depth control; if the app has no other output-encoding issues the risk is lower, but the site includes third-party links (ko-fi.com) and dynamic content areas (search) that increase attack surface. Remediation: implement a CSP with script-src 'self' plus explicit allow-listed hosts, avoid 'unsafe-inline'/'unsafe-eval', and set object-src 'none' and base-uri 'self'.",
      "evidence": {
        "note": "No CSP header value provided in observed response headers; skeleton shows externally linked third-party (ko-fi.com) and a search feature that could reflect user input."
      }
    },
    {
      "type": "finding",
      "id": 2051,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative-style hero image with empty alt is acceptable",
      "detail": "The hero/cover image is purely illustrative of an abstract concept (multiverse) and does not convey information not already present in the heading/text. Empty alt=\"\" correctly hides it from screen reader users, which is appropriate per WCAG guidance for decorative images. This is not a real barrier since no unique content is lost; however, if the image contains a specific illustrative diagram or unique visual metaphor that adds context beyond the title, a short descriptive alt should be added. Recommend editorial review to confirm image is purely decorative; if so, no fix needed.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Cover image directly after H1 area; alt is empty, likely decorative stock/generated art"
      }
    },
    {
      "type": "finding",
      "id": 2052,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The observed CSP does not sufficiently restrict script sources, allowing 'unsafe-inline' or wildcard directives (or lacking one entirely), which reduces defense-in-depth against XSS if any injection point exists (e.g., search feature). No compensating controls such as strict script-src, nonce/hash usage, or frame-ancestors restrictions were observed. Remediation: adopt a strict CSP with script-src limited to self/nonce-based sources, avoid 'unsafe-inline'/'unsafe-eval', and add frame-ancestors and object-src 'none' directives.",
      "evidence": {
        "selector": "header:Content-Security-Policy",
        "snippet": "weak/absent script-src restrictions",
        "note": "Static content site reduces exploitability, but the search endpoint increases injection surface."
      }
    },
    {
      "type": "finding",
      "id": 2053,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/2.4.4",
      "severity": "minor",
      "title": "Link name conflates title and truncated excerpt text",
      "detail": "Screen-reader users navigating by links or headings will hear the article title run directly into an abruptly truncated excerpt ('...What Machine-Authored Inquiry Can Be Now that AI can write clearly about hard questions, it's worth asking what a public') as one single link name with no separation or indication that it's cut off. This makes the link purpose unclear and the content sound broken/incomplete. Fix: end excerpts with an ellipsis or 'Read more' cue, and/or separate the title from the excerpt using distinct elements (e.g., heading + aria-hidden excerpt, or a visually hidden ' - read more' segment) so the accessible name is unambiguous and the truncation is perceivable to all users, not just sighted ones who see visual cropping.",
      "evidence": {
        "selector": "main a[href*='machine-authored-inquiry']",
        "note": "Link text ends mid-sentence: \"...it's worth asking what a public\""
      }
    },
    {
      "type": "finding",
      "id": 2054,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Empty alt text on article preview images is likely appropriate but unverified",
      "detail": "Screen reader users hear the adjacent link text (article title) already, so empty alt on preview thumbnails is acceptable if images are purely decorative/redundant. However, if the thumbnail conveys unique content-relevant information (e.g., a diagram or photo specific to the article, not a generic stock image), empty alt would deprive screen-reader users of that context. Confirm each preview image is purely decorative/illustrative; if any carry meaning, add a concise descriptive alt. Low severity since link text provides the title either way.",
      "evidence": {
        "selector": "main a img[alt='']",
        "note": "img alt=\"\" inside article preview links; title text present in surrounding link"
      }
    },
    {
      "type": "finding",
      "id": 2055,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g. allows 'unsafe-inline'/'unsafe-eval' or broad wildcard sources, or is otherwise insufficiently restrictive), which reduces its effectiveness as a mitigation against XSS and data-injection attacks. Given the site renders content pages without visible strict output-encoding indicators, a weak CSP removes a key defense-in-depth layer. Remediation: adopt a strict CSP using nonces/hashes for scripts, restrict default-src/script-src to 'self' and required third-party origins only, and set frame-ancestors and object-src 'none'.",
      "evidence": {
        "note": "CSP header present but assessed as weak per triage; exact directive values not enumerated in provided evidence"
      }
    },
    {
      "type": "finding",
      "id": 2056,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Hero image alt text likely appropriate but should be verified for decorative status",
      "detail": "The article hero image (secularism-and-the-court-witness-truth-without-god.png) has alt=\"\", which is correct WCAG 1.1.1 practice if the image is purely decorative/illustrative and adjacent text (h1, article body) already conveys the topic. Screen-reader users are not blocked since the heading and surrounding text fully describe the article's subject, and the image appears to be a generic stock/thematic illustration rather than content-bearing. However, if the image contains any text, diagrams, or unique visual information (e.g. courtroom iconography specific to the argument) not represented elsewhere, an empty alt would deprive screen-reader users of that content. Recommend content team confirm the image conveys no unique information; if it does, add a concise descriptive alt.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Same empty-alt pattern is also used on related-post thumbnail images, suggesting a site-wide deliberate decorative convention."
      }
    },
    {
      "type": "finding",
      "id": 2057,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., overly broad script-src such as 'unsafe-inline'/'unsafe-eval' or wildcard sources), which reduces its effectiveness as a mitigation against XSS/injection. Static content pages reduce immediate risk, but any future reflected input, third-party widget, or ad script could be leveraged for script injection without a strong policy in place. Remediate by defining strict script-src/style-src allowlists (nonce or hash-based), avoiding 'unsafe-inline', and adding frame-ancestors/object-src 'none' directives.",
      "evidence": {
        "selector": "header:content-security-policy",
        "snippet": "CSP present but permissive",
        "note": "No visible compensating control such as strict script-src or nonce usage observed in provided headers"
      }
    },
    {
      "type": "finding",
      "id": 2058,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative-style empty alt on featured article image",
      "detail": "The article's featured image and the related-post thumbnail both use alt=\"\", treating them as decorative. Since these are generic stock/illustrative header images that don't convey unique content beyond the article title already present as text, empty alt is an acceptable pattern under 1.1.1 and doesn't block screen-reader users from understanding the article. However, if the image contains any diagram or visual metaphor specific to 'supervenience' that isn't described elsewhere, a short descriptive alt should be added. Low confidence real barrier since heading text already conveys equivalent info; recommend content review to confirm image is purely decorative.",
      "evidence": {
        "selector": "article img",
        "note": "alt=\"\" on featured and related-post images"
      }
    },
    {
      "type": "finding",
      "id": 2059,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy on interactive quiz page",
      "detail": "The quiz page is interactive (buttons, likely inline JS/state handling) and the flagged CSP appears weak, potentially allowing 'unsafe-inline' script-src or broad data:/https: wildcards. If the CSP permits inline scripts or unrestricted script sources, it significantly weakens XSS mitigation for this page's dynamic scoring/quiz logic, which processes user-driven interactions. Even without direct evidence of injection points, a weak CSP removes a key defense-in-depth layer against any future injection vulnerability (e.g., reflected XSS via quiz state, query params). Remediation: tighten CSP to avoid 'unsafe-inline'/'unsafe-eval', use nonces or hashes for required inline scripts, restrict script-src/object-src/base-uri to 'self' and required CDNs only, and add frame-ancestors to cover clickjacking (compensating for missing X-Frame-Options if applicable).",
      "evidence": {
        "note": "CSP header content not fully provided in input; assessed based on triage flag indicating weak policy allowing inline scripts or data URIs on an interactive page."
      }
    },
    {
      "type": "finding",
      "id": 2060,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or missing Content-Security-Policy",
      "detail": "No strong CSP (with restrictive default-src/script-src and frame-ancestors) was observed protecting this page. For a content site rendering AI-generated article text, absence of a robust CSP increases the blast radius of any injected script (e.g., via a compromised generation pipeline, third-party ad/analytics tag, or stored XSS in article content) since the browser has no defense-in-depth against inline/script-src violations. Impact is moderate rather than critical since no direct injection point was confirmed in the skeleton, but the risk is real given machine-generated content is a plausible injection vector. Remediation: implement a CSP with default-src 'self', explicit script-src allowlist (avoiding 'unsafe-inline'/'unsafe-eval'), and frame-ancestors 'self' to also cover clickjacking, plus consider nonce/hash-based script loading.",
      "evidence": {
        "note": "CSP header reported as weak by triage; no evidence of frame-ancestors or strict script-src compensating control in provided headers"
      }
    },
    {
      "type": "finding",
      "id": 2061,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.3.1",
      "severity": "minor",
      "title": "Heading hierarchy appears correct; no real defect found",
      "detail": "The skeleton actually shows an <h1> 'Frequently asked questions' followed by <h2> question headings, which is a valid hierarchy. Screen reader users navigating by heading level would encounter a logical structure: one h1 then sibling h2s for each FAQ question. No skipped levels are evident. This flagged concern does not represent an actual barrier; no fix required unless the live page differs from the skeleton (e.g., missing landmark labeling for FAQ groups, or lack of visible focus indication when expanding answers if collapsible). Recommend verifying that FAQ answers, if implemented as accordions, use proper aria-expanded and are keyboard operable (4.1.2), but that is outside the scope of the flagged heading issue.",
      "evidence": {
        "selector": "main h1, main h2",
        "note": "h1 present with 4 h2 children per skeleton"
      }
    },
    {
      "type": "finding",
      "id": 2062,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP does not sufficiently restrict script/style sources, reducing its effectiveness as a defense-in-depth control against XSS and data injection. While no direct injection vector is visible in this static content page (no forms, no user-controlled output rendered), a weak CSP means that if any injection flaw (e.g. in search, comments, or CMS admin) is later introduced or already exists elsewhere on the site, it could be exploited without CSP mitigation. Recommend adopting a strict CSP with nonce- or hash-based script-src, disallowing 'unsafe-inline' and 'unsafe-eval', and setting object-src 'none' and frame-ancestors as compensating clickjacking control.",
      "evidence": {
        "note": "CSP header present but permissive per triage flag; no inline mitigations such as nonces observed"
      }
    },
    {
      "type": "finding",
      "id": 2063,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or missing Content-Security-Policy",
      "detail": "The site appears to lack a strong CSP (or ships a permissive one), which reduces defense-in-depth against XSS/injection if any user-controllable content or third-party script is ever rendered unescaped. For a content site with no visible authentication or user input forms in the skeleton, the exploitable surface is currently limited, but a missing frame-ancestors/script-src directive still leaves the site reliant solely on output-encoding correctness. Remediation: add a CSP with at minimum default-src 'self', script-src restricted to known origins, and frame-ancestors 'none' or 'self', plus object-src 'none'.",
      "evidence": {
        "selector": "header:Content-Security-Policy",
        "note": "absent or weak per triage flag; not independently verifiable from skeleton alone"
      }
    },
    {
      "type": "finding",
      "id": 2064,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative image alt text is acceptable given descriptive link text",
      "detail": "Article preview card images use alt=\"\" (decorative), but the enclosing links contain full article titles and topic labels (e.g., 'The Concept of Supervenience: When One Level Rests on Another Supervenience explains how mental states, moral properties'). Screen-reader users get sufficient context from the link name alone via 4.1.2/2.4.4, so empty alt on purely illustrative thumbnail images is appropriate and not a barrier. No fix required.",
      "evidence": {
        "selector": "main a img[alt='']",
        "note": "criterion: 1.1.1"
      }
    },
    {
      "type": "finding",
      "id": 2065,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/2.4.4",
      "severity": "moderate",
      "title": "Link text embeds unrelated excerpt text creating overly long, redundant link names",
      "detail": "Preview links concatenate the title with the start of the article body text with no separation for assistive tech (e.g., title runs directly into 'Supervenience explains how mental states...'), and also include the topic label span and icon inside the same link. Screen-reader users navigating by link list will hear an unstructured run-on that is hard to parse, and it isn't clear where the title ends and excerpt begins. Fix: separate title and excerpt with distinct elements (e.g., a heading for the title, aria-hidden or visually-hidden separation) or use aria-label to give the link a clean accessible name (title only), and move excerpt outside the anchor or mark it non-link text.",
      "evidence": {
        "selector": "main a"
      }
    },
    {
      "type": "finding",
      "id": 2066,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/2.4.4",
      "severity": "minor",
      "title": "Article card link names likely acceptable but verify duplicate/ambiguous text",
      "detail": "Article cards appear to wrap the whole title and excerpt text into a single anchor, which is good for link purpose, but the skeleton shows truncated excerpt text bleeding into the accessible name (e.g., 'What the Nervous System of C. elegans Actually Taught Us The complete wiring diagram...'). Screen reader users navigating by links (e.g., NVDA 'links list') will hear the title concatenated with excerpt text and a decorative category label ('Science') and icon glyphs, making the announced name longer and potentially confusing though not ambiguous. Fix: ensure the excerpt text is either visually hidden from the link name (aria-hidden or moved outside the anchor) or explicitly separated so the accessible name is just the article title, with excerpt marked up as a sibling <p> outside the <a>, and ensure the aria-hidden bullet/category spans do not get included in the computed name.",
      "evidence": {
        "selector": "main a[href*='/posts/']",
        "snippet": "What the Nervous System of C. elegans Actually Taught Us The complete wiring diagram of a 302-neuron worm reshaped how s...",
        "note": "Accessible name may include excerpt and category text, creating overly verbose but not ambiguous link text"
      }
    },
    {
      "type": "finding",
      "id": 2067,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or absent Content-Security-Policy",
      "detail": "The site's CSP appears weak or insufficiently restrictive, which reduces defense-in-depth against XSS and data injection if any injection vector is later found (e.g., search feature, comment/embed content). A static, mostly content-driven blog has lower inherent risk, but no compensating controls (e.g., strict script-src, frame-ancestors, object-src 'none') were observed in the skeleton or headers provided. Remediation: implement a CSP with script-src limited to self and required third-party origins (e.g., analytics), frame-ancestors 'none' or 'self', and object-src 'none', and validate it doesn't allow 'unsafe-inline'/'unsafe-eval' unless required.",
      "evidence": {
        "selector": "header:Content-Security-Policy",
        "note": "No strong CSP directives observed; treat as security misconfiguration pending confirmation of header value."
      }
    },
    {
      "type": "finding",
      "id": 2068,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative-treated hero image lacks context alt text",
      "detail": "Screen reader users get no information from the article's featured image (alt=\"\"), which is treated as decorative. If the image is purely illustrative/stock-style and adds no unique information beyond the headline, empty alt is actually acceptable per WCAG 1.1.1. However, if the image conveys a concept (e.g., a diagram or illustration relevant to the gambler's fallacy) it should have a concise descriptive alt. Fix: verify image intent; if purely decorative, empty alt is correct and no change needed; if illustrative of content, add alt text describing the concept depicted.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit.png"
      }
    },
    {
      "type": "finding",
      "id": 2069,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or absent Content-Security-Policy",
      "detail": "No response headers were provided showing a strong CSP (e.g., no evidence of script-src restrictions or frame-ancestors directive). On a content site with no visible user input surfaces, exploitation risk is lower than on an app with forms, but a weak/missing CSP still leaves the site exposed to XSS-based content injection, clickjacking, and third-party script abuse if any injection vector (e.g., compromised ad/analytics script, stored XSS in AI-generated content pipeline) is found. Remediation: implement a strict CSP with script-src limited to self/trusted hosts, object-src 'none', base-uri 'self', and frame-ancestors 'none' or 'self' to also cover clickjacking protection without relying solely on X-Frame-Options.",
      "evidence": {
        "note": "No CSP header value was supplied in the observed headers set; assessed as weak/absent based on flag context."
      }
    },
    {
      "type": "finding",
      "id": 2070,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Article thumbnail images use empty alt text",
      "detail": "Article card thumbnails are marked alt=\"\" (decorative), which is acceptable since each card already has an adjacent text link with the full article title, so screen-reader users don't lose information. However, if these images are meant to convey topic-specific imagery (distinct from the title text) that sighted users rely on to scan/differentiate cards, empty alt suppresses that context for blind users. Recommend confirming images are purely decorative; if they carry meaning, add concise descriptive alt text distinct from the title.",
      "evidence": {
        "selector": "img[alt='']",
        "note": "repeated across ~19 article cards"
      }
    },
    {
      "type": "finding",
      "id": 2071,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or incomplete Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., permissive script-src including 'unsafe-inline'/'unsafe-eval' or missing entirely), which reduces mitigation of XSS if any injection point (comments, search, CMS admin) is compromised. On a content-heavy blog with third-party embeds (images, Ko-fi links), a weak CSP means an attacker who finds any injection vector could execute arbitrary script in visitors' browsers. Remediate by defining a strict CSP with nonce/hash-based script-src, restricting object-src/base-uri, and adding frame-ancestors to also cover clickjacking protection.",
      "evidence": {
        "selector": "response header: Content-Security-Policy",
        "note": "policy details not fully provided in triage; assessed as weak/incomplete based on flag reason"
      }
    },
    {
      "type": "finding",
      "id": 2072,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative-style empty alt on article/thumbnail images may omit meaningful content",
      "detail": "The hero image on the article and the thumbnail image on the related-post card both have alt=\"\", which is appropriate only if the images are purely decorative. If these images convey information (e.g., a stylized illustration relevant to the topic) beyond what's in the adjacent heading/text, screen-reader users get no equivalent description and lose that content. Since the images appear to be generic/stock illustrations accompanying article titles that are already announced via heading text, empty alt is likely acceptable here, but should be verified: if any image conveys unique meaning not present in surrounding text, add a concise descriptive alt attribute. Fix: confirm decorative intent; if decorative, keep alt=\"\" (current behavior is compliant); if meaningful, add descriptive alt text.",
      "evidence": {
        "selector": "article img, a img",
        "note": "alt=\"\" on hero and related-post thumbnail images"
      }
    },
    {
      "type": "finding",
      "id": 2073,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "minor",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., broad allowlists or unsafe-inline/unsafe-eval directives), which reduces protection against reflected/stored XSS. For a mostly static content site with no visible user-generated content or complex forms, the injection surface is limited, so real-world risk is lower than on an interactive app. Recommend tightening CSP by removing 'unsafe-inline'/'unsafe-eval', restricting script-src to self and specific trusted CDNs (analytics, Ko-fi widget if used), and adding frame-ancestors 'none' or 'self' to also cover clickjacking protection. Test in report-only mode before enforcing.",
      "evidence": {
        "note": "No script-src/object-src restrictions confirmed as strict; content is static/blog-like reducing exploitation surface"
      }
    },
    {
      "type": "finding",
      "id": 2074,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "moderate",
      "title": "Hero image missing descriptive alt text",
      "detail": "The article's hero image has alt=\"\" (treated as decorative), but it visually represents the article's topic and may carry conceptual/illustrative meaning for sighted users. Screen-reader users lose any contextual or thematic content the image conveys. If the image is purely stylistic/generic (e.g., a generic stock illustration not conveying unique information), empty alt is acceptable; however if it depicts something specific relevant to the topic (e.g., political party imagery, secularism symbolism), it should have a concise descriptive alt attribute conveying that context. Fix: audit the image's purpose \u2014 if decorative, keep alt=\"\"; if content-bearing, add meaningful alt text describing what it depicts in relation to the article.",
      "evidence": {
        "selector": "article img[src='secularism-and-the-political-party-when-movements-organise.png']",
        "note": "Same pattern repeated on related-post thumbnail images site-wide.[criterion 1.1.1]"
      }
    },
    {
      "type": "finding",
      "id": 2075,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/none-applicable",
      "severity": "minor",
      "title": "No security-relevant issue identified",
      "detail": "The flagged item concerns content transparency/UX (AI-generated disclosure placement), not a security control. No headers, TLS metadata, or injection surface were provided to review in relation to this flag. No security finding applies here; this should be handled by content/editorial review rather than a security assessment.",
      "evidence": {
        "note": "Flagged item is a UX/content disclosure concern, out of scope for security rubric."
      }
    },
    {
      "type": "finding",
      "id": 2076,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or overly permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., allowing 'unsafe-inline' or broad script-src wildcards), which reduces its effectiveness as a mitigation against XSS. The search page contains a client-side search input that likely reflects or filters content dynamically, increasing the impact if injection occurs elsewhere on the site. Without a strict CSP (nonce/hash-based script-src, no unsafe-inline/unsafe-eval, restrictive default-src), any injection vulnerability elsewhere becomes exploitable for script execution. Remediation: tighten CSP to disallow inline scripts/styles unless nonce/hash-based, restrict script-src to self and trusted CDNs, and add frame-ancestors/object-src 'none' as defense in depth.",
      "evidence": {
        "selector": "header: content-security-policy",
        "note": "Policy contents not fully provided; assessed as weak per triage flag\u2014recommend verifying directives such as script-src, unsafe-inline usage, and frame-ancestors."
      }
    },
    {
      "type": "finding",
      "id": 2077,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak/permissive (e.g., allowing broad script-src or missing restrictions), which reduces its effectiveness as a mitigation against XSS and other injection attacks. Even though no direct injection point was observed in the semantic skeleton (search form, static content), a weak CSP removes a key defense-in-depth layer should any injection vulnerability (e.g., in search, comments, or third-party ad/analytics scripts) be discovered later. Recommend tightening CSP directives (script-src limited to self and specific trusted hosts, avoiding 'unsafe-inline'/'unsafe-eval', adding object-src 'none' and base-uri 'self') and adding frame-ancestors to also cover clickjacking protection.",
      "evidence": {
        "note": "CSP header flagged as weak by triage; specific directive values not provided in evidence but indicates overly permissive script-src/style-src allowances."
      }
    },
    {
      "type": "finding",
      "id": 2078,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/2.4.4",
      "severity": "moderate",
      "title": "Overly verbose, truncated link names on article cards",
      "detail": "Each article preview card is wrapped in a single <a> whose accessible name includes the title plus a truncated snippet ending mid-sentence (e.g. '...yet treat it as a'). Screen reader users navigating by link list or using 'read link text' will hear an incomplete, run-on sentence, making it hard to judge the link's purpose or scan content efficiently. Keyboard users tabbing through the page also land on a single large focusable region with no way to distinguish title from body. Fix: truncate the snippet at a natural boundary (or omit it from the link name) and consider separating the image/link from the descriptive text, using aria-label or visually-hidden text to give the link a concise, complete name (e.g. just the title).",
      "evidence": {
        "selector": "main a[href*='/posts/']",
        "snippet": "Religion by Inheritance: How Birth Predicts Belief Most people hold the religion they were born into, yet treat it as a",
        "note": ""
      }
    }
  ],
  "errors": []
}