{
  "exported_at": "2026-09-30T10:03:24.648362Z",
  "kind": "page",
  "target": "https://artificialatheist.com",
  "run_id": "fb04d0b2bc334812a27a62cdfdb12235",
  "status": "done",
  "stats": {
    "pages": 20,
    "templates": 19,
    "findings_by_severity": {
      "moderate": 51,
      "info": 38,
      "serious": 3,
      "minor": 16
    },
    "duration_secs": 589.55,
    "tokens": {
      "input": 109723,
      "output": 16076,
      "cache_read": 0,
      "cache_write": 0
    },
    "tokens_by_model": {
      "claude-haiku-4-5": {
        "input": 32061,
        "output": 5892,
        "cache_read": 0,
        "cache_write": 0
      },
      "claude-sonnet-5": {
        "input": 77662,
        "output": 10184,
        "cache_read": 0,
        "cache_write": 0
      }
    },
    "estimated_cost_usd": 0.4473
  },
  "findings": [
    {
      "type": "finding",
      "id": 3419,
      "url": "https://artificialatheist.com",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3420,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.7",
      "detail": "Lighthouse category 'Performance' scored 0.7 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.7
      }
    },
    {
      "type": "finding",
      "id": 3421,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3422,
      "url": "https://artificialatheist.com",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3423,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3424,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "document-title",
      "severity": "serious",
      "title": "Documents must have <title> element to aid in navigation",
      "detail": "Ensure each HTML document contains a non-empty <title> element https://dequeuniversity.com/rules/axe/4.10/document-title?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.text-alternatives",
          "wcag2a",
          "wcag242",
          "TTv5",
          "TT12.a",
          "EN-301-549",
          "EN-9.2.4.2",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3425,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "html-has-lang",
      "severity": "serious",
      "title": "<html> element must have a lang attribute",
      "detail": "Ensure every HTML document has a lang attribute https://dequeuniversity.com/rules/axe/4.10/html-has-lang?application=axeAPI",
      "evidence": {
        "impact": "serious",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.language",
          "wcag2a",
          "wcag311",
          "TTv5",
          "TT11.a",
          "EN-301-549",
          "EN-9.3.1.1",
          "ACT"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3426,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "landmark-one-main",
      "severity": "moderate",
      "title": "Document should have one main landmark",
      "detail": "Ensure the document has a main landmark https://dequeuniversity.com/rules/axe/4.10/landmark-one-main?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.semantics",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3427,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "page-has-heading-one",
      "severity": "moderate",
      "title": "Page should contain a level-one heading",
      "detail": "Ensure that the page, or at least one of its frames contains a level-one heading https://dequeuniversity.com/rules/axe/4.10/page-has-heading-one?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "html",
            "snippet": "<html>"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.semantics",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3428,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "wcag",
      "tier": 0,
      "rule": "region",
      "severity": "moderate",
      "title": "All page content should be contained by landmarks",
      "detail": "Ensure all page content is contained by landmarks https://dequeuniversity.com/rules/axe/4.10/region?application=axeAPI",
      "evidence": {
        "impact": "moderate",
        "nodes": [
          {
            "selector": "pre",
            "snippet": "<pre style=\"word-wrap: break-word; white-space: pre-wrap;\">"
          }
        ],
        "node_count": 1,
        "tags": [
          "cat.keyboard",
          "best-practice"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3429,
      "url": "https://artificialatheist.com/feed.xml",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse-unavailable",
      "severity": "info",
      "title": "Lighthouse unavailable",
      "detail": "could not parse lighthouse output (rc=1): Unterminated string starting at: line 424 column 21 (char 65361). stderr: Runtime error encountered: The page provided is not HTML (served as MIME type text/plain).\n",
      "evidence": {}
    },
    {
      "type": "finding",
      "id": 3430,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3431,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "info",
      "title": "Lighthouse Performance score: 0.9",
      "detail": "Lighthouse category 'Performance' scored 0.9 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.9
      }
    },
    {
      "type": "finding",
      "id": 3432,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3433,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3434,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3435,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.86",
      "detail": "Lighthouse category 'Performance' scored 0.86 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.86
      }
    },
    {
      "type": "finding",
      "id": 3436,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3437,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3438,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.72",
      "detail": "Lighthouse category 'Performance' scored 0.72 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.72
      }
    },
    {
      "type": "finding",
      "id": 3439,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3440,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3441,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3442,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.63",
      "detail": "Lighthouse category 'Performance' scored 0.63 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.63
      }
    },
    {
      "type": "finding",
      "id": 3443,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3444,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3445,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3446,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.86",
      "detail": "Lighthouse category 'Performance' scored 0.86 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.86
      }
    },
    {
      "type": "finding",
      "id": 3447,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3448,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3449,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3450,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.89",
      "detail": "Lighthouse category 'Performance' scored 0.89 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.89
      }
    },
    {
      "type": "finding",
      "id": 3451,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3452,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3453,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3454,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.64",
      "detail": "Lighthouse category 'Performance' scored 0.64 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.64
      }
    },
    {
      "type": "finding",
      "id": 3455,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3456,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3457,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3458,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.58",
      "detail": "Lighthouse category 'Performance' scored 0.58 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.58
      }
    },
    {
      "type": "finding",
      "id": 3459,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3460,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3461,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3462,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.6",
      "detail": "Lighthouse category 'Performance' scored 0.6 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.6
      }
    },
    {
      "type": "finding",
      "id": 3463,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3464,
      "url": "https://artificialatheist.com/faq/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3465,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3466,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.75",
      "detail": "Lighthouse category 'Performance' scored 0.75 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.75
      }
    },
    {
      "type": "finding",
      "id": 3467,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3468,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3469,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3470,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.65",
      "detail": "Lighthouse category 'Performance' scored 0.65 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.65
      }
    },
    {
      "type": "finding",
      "id": 3471,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3472,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3473,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3474,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.68",
      "detail": "Lighthouse category 'Performance' scored 0.68 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.68
      }
    },
    {
      "type": "finding",
      "id": 3475,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3476,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3477,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3478,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.63",
      "detail": "Lighthouse category 'Performance' scored 0.63 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.63
      }
    },
    {
      "type": "finding",
      "id": 3479,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3480,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3481,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3482,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "serious",
      "title": "Lighthouse Performance score: 0.46",
      "detail": "Lighthouse category 'Performance' scored 0.46 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.46
      }
    },
    {
      "type": "finding",
      "id": 3483,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3484,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3485,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3486,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.56",
      "detail": "Lighthouse category 'Performance' scored 0.56 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.56
      }
    },
    {
      "type": "finding",
      "id": 3487,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3488,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3489,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3490,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.51",
      "detail": "Lighthouse category 'Performance' scored 0.51 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.51
      }
    },
    {
      "type": "finding",
      "id": 3491,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3492,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3493,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "security",
      "tier": 0,
      "rule": "weak-csp",
      "severity": "moderate",
      "title": "Content-Security-Policy allows unsafe inline/eval",
      "detail": "The CSP's script-src directive permits 'unsafe-inline' or 'unsafe-eval', which significantly weakens its XSS protection.",
      "evidence": {
        "header": "content-security-policy",
        "value": "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; font-src 'self'; img-src 'self' data: https://www.googletagmanager.com https://*.google-analytics.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'",
        "weak_directives": [
          "script-src"
        ]
      }
    },
    {
      "type": "finding",
      "id": 3494,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/performance",
      "severity": "moderate",
      "title": "Lighthouse Performance score: 0.56",
      "detail": "Lighthouse category 'Performance' scored 0.56 (0-1 scale).",
      "evidence": {
        "category": "performance",
        "score": 0.56
      }
    },
    {
      "type": "finding",
      "id": 3495,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/accessibility",
      "severity": "info",
      "title": "Lighthouse Accessibility score: 1",
      "detail": "Lighthouse category 'Accessibility' scored 1 (0-1 scale).",
      "evidence": {
        "category": "accessibility",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3496,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "ux",
      "tier": 0,
      "rule": "ux/lighthouse/best-practices",
      "severity": "info",
      "title": "Lighthouse Best Practices score: 1",
      "detail": "Lighthouse category 'Best Practices' scored 1 (0-1 scale).",
      "evidence": {
        "category": "best-practices",
        "score": 1
      }
    },
    {
      "type": "finding",
      "id": 3497,
      "url": "https://artificialatheist.com",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., broad allowlists or missing restrictive directives like script-src/object-src/frame-ancestors), which reduces mitigation against XSS and clickjacking. Even a static content site benefits from a strict CSP (script-src 'self', object-src 'none', frame-ancestors 'none', base-uri 'self') to limit damage if any injection point (search, comments, third-party scripts) is compromised. Recommend tightening CSP directives and validating no unsafe-inline/unsafe-eval or wildcard sources are used.",
      "evidence": {
        "note": "No explicit CSP directive values were provided in headers; flagged as weak based on triage signal."
      }
    },
    {
      "type": "finding",
      "id": 3498,
      "url": "https://artificialatheist.com",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "moderate",
      "title": "Article thumbnail images have empty alt text despite conveying article-related imagery",
      "detail": "Screen-reader users encounter repeated blog-post thumbnails (e.g. religion-by-inheritance, c-elegans, afterlife-assumption images) with alt=\"\", so the images are skipped entirely. Because each image is wrapped in or adjacent to the article title link, the images are likely decorative/duplicative rather than informative, which is acceptable under 1.1.1 if truly decorative \u2014 however, several are also wrapped in their own separate <a> link (e.g. the featured post's linked image with aria-label duplicating the title), creating a redundant link with no distinguishing content for screen-reader users navigating by link/image list. If any image conveys unique visual context (e.g. an illustrative diagram), empty alt denies that content to blind users. Fix: confirm images are purely decorative accompaniments to headline links; if so, empty alt is correct, but redundant wrapping anchors around decorative images should be removed or merged with the heading link to avoid duplicate tab stops (2.4.4/4.1.2 concern). If images carry unique meaning, provide concise descriptive alt text.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Multiple <img alt=''> inside article/section blocks, some independently wrapped in <a>"
      }
    },
    {
      "type": "finding",
      "id": 3499,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The CSP observed for this page appears weak (e.g., allowing 'unsafe-inline'/'unsafe-eval' or overly broad source lists), which reduces its effectiveness as a defense-in-depth control against XSS. On a content site with a search input rendering user-influenced text, a weak CSP means that if any injection point is missed elsewhere, the attacker's script could still execute since the policy does not meaningfully restrict inline scripts or third-party origins. Remediation: adopt a strict CSP using nonces or hashes for scripts, avoid 'unsafe-inline' and 'unsafe-eval', and restrict object-src/base-uri/frame-ancestors to 'none' or self as appropriate.",
      "evidence": {
        "selector": "input[type=search]",
        "note": "CSP header content not fully shown in provided metadata but flagged as weak by triage; no compensating control such as strict script-src or frame-ancestors confirmed."
      }
    },
    {
      "type": "finding",
      "id": 3500,
      "url": "https://artificialatheist.com/search/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/3.3.2",
      "severity": "minor",
      "title": "Search input relies solely on placeholder/aria-label, no visible label",
      "detail": "The search input on the /search/ page has an aria-label 'Search articles' and a placeholder, but no persistent visible <label>. Low-vision users, users with cognitive disabilities, and users who zoom text may lose the placeholder text once they begin typing or if the field is small, leaving no visible indication of the input's purpose. Screen reader users are not blocked since aria-label provides an accessible name (satisfying 4.1.2), but this is a usability gap under 3.3.2. Fix: add a visible <label> or heading text near the input (e.g. 'Search') that remains visible regardless of input state, rather than relying only on placeholder/aria-label.",
      "evidence": {
        "selector": "input[type=search]",
        "note": "placeholder='Search articles', aria-label='Search articles', no visible <label> element"
      }
    },
    {
      "type": "finding",
      "id": 3501,
      "url": "https://artificialatheist.com/posts/secularism-and-the-court-witness-truth-without-god/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (broad source allowances or missing restrictive directives such as script-src/object-src/frame-ancestors), reducing its effectiveness as a mitigation against XSS and clickjacking. Given this is a static/blog-style content site with no visible interactive forms or user input surfaces in the skeleton, the immediate injection risk is low, but any future addition of comments, search result rendering, or third-party embeds (e.g. Ko-fi widget) could be exploited if the policy doesn't restrict script-src to trusted origins. Remediation: tighten CSP to explicit allowlists (script-src 'self' plus specific trusted CDNs), add object-src 'none', base-uri 'self', and frame-ancestors 'self' to also cover clickjacking protection without relying solely on X-Frame-Options.",
      "evidence": {
        "note": "CSP present but with broad/weak directives per triage flag; no explicit header value provided for exact directive review"
      }
    },
    {
      "type": "finding",
      "id": 3502,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/4.1.2",
      "severity": "moderate",
      "title": "Toggle buttons rely on aria-pressed without clear indication of grouping/relationship",
      "detail": "Screen-reader users navigating the 'Random mix' and 'By topic' buttons will hear 'button, pressed/not pressed' but the group is not exposed as a radio-group or tablist, so the relationship between the two mutually-exclusive options isn't conveyed via role. This can confuse users into thinking these are independent toggles rather than a single choice. Fix: wrap the options in a role='radiogroup' with role='radio' children, or use native radio inputs styled as buttons, and ensure aria-pressed is replaced with aria-checked as appropriate.",
      "evidence": {
        "selector": "button[aria-pressed]",
        "note": "'Random mix' and 'By topic' buttons"
      }
    },
    {
      "type": "finding",
      "id": 3503,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.3.1",
      "severity": "moderate",
      "title": "Quiz result/score updates not confirmed accessible to screen readers",
      "detail": "The flagged concern that quiz scoring and result content may update dynamically without being announced to assistive technology is valid: if results replace content in the DOM without an aria-live region or focus management, screen-reader users won't know a quiz was scored or see the facts presented. Fix: use aria-live='polite' (or role='status') on the results container, or programmatically move focus to the results heading after submission.",
      "evidence": {
        "selector": "main section",
        "note": "No live region visible in skeleton for quiz results"
      }
    },
    {
      "type": "finding",
      "id": 3504,
      "url": "https://artificialatheist.com/quiz/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/2.4.6",
      "severity": "minor",
      "title": "Ambiguous button label 'Start random quiz \u2192' includes decorative arrow as text",
      "detail": "Low-vision or screen-reader users hear the arrow glyph read literally in some synthesizers, and the label alone doesn't clarify how many questions or what happens next (e.g., navigation vs in-place update). Fix: mark the arrow as aria-hidden or use a proper icon element, and consider clarifying the button's purpose (e.g., 'Start random quiz (10 questions)').",
      "evidence": {
        "selector": "button:contains('Start random quiz')"
      }
    },
    {
      "type": "finding",
      "id": 3505,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "minor",
      "title": "Weak or missing Content-Security-Policy",
      "detail": "No response headers were provided showing a CSP with strong directives (e.g., script-src restricted to self/nonce, frame-ancestors, object-src 'none'). For a static blog with no visible user input fields, forms, or inline script surface, the practical risk is low, but a weak/absent CSP removes an important defense-in-depth layer against XSS if any injection vector (comments, search, third-party embeds like Ko-fi widgets) is later added or already present client-side. Recommend adding a CSP with default-src 'self', restrictive script-src, and frame-ancestors 'self' to mitigate clickjacking and reduce blast radius of any future script injection.",
      "evidence": {
        "note": "No CSP header value was supplied in the observed headers; the site links out to ko-fi.com which would need to be allow-listed if any embed script is added."
      }
    },
    {
      "type": "finding",
      "id": 3506,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "minor",
      "title": "Clickjacking protection dependent on CSP frame-ancestors or X-Frame-Options",
      "detail": "No evidence of X-Frame-Options or CSP frame-ancestors was provided. Since the flagged CSP is described as weak, this site may lack framing protection, allowing the page to be embedded in a malicious iframe for UI-redress attacks. Low severity given the site is read-only content, but recommend adding frame-ancestors 'self' or X-Frame-Options: SAMEORIGIN.",
      "evidence": {
        "note": "No headers demonstrating frame-ancestors or X-Frame-Options were shown in the provided metadata."
      }
    },
    {
      "type": "finding",
      "id": 3507,
      "url": "https://artificialatheist.com/posts/the-concept-of-supervenience-when-one-level-rests-on-another/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative image correctly marked with empty alt, not a barrier",
      "detail": "The image accompanying the related article 'The Gambler's Fallacy' uses alt=\"\" while the article title itself is provided in an adjacent link/heading text. Since the image is purely decorative/illustrative and the link text already conveys the article's purpose, empty alt is the correct treatment per WCAG 1.1.1 and does not block screen-reader users \u2014 they still hear the link/heading text naming the article. This flag is a false positive; no fix needed unless the image conveys unique information not in the text, in which case a short descriptive alt should be added.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Adjacent h2 > a provides the article title, satisfying non-text content requirements."
      }
    },
    {
      "type": "finding",
      "id": 3508,
      "url": "https://artificialatheist.com/topics/science/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Icon-only buttons rely solely on aria-label with no visible text",
      "detail": "Sighted users (especially those with cognitive disabilities or low vision) may not understand the purpose of the 'A' text-resize buttons or the dark-mode toggle icon since there is no visible text label, only an aria-label exposed to assistive tech. While this passes 4.1.2 Name/Role/Value (accessible name is programmatically exposed), it creates a usability gap under 3.3.2/2.4.6 best practice guidance for clear labeling for all users. Fix: add visible text labels or persistent tooltips, or ensure icon glyphs are unambiguous (e.g., sun/moon icon plus visible 'Dark mode' text on larger viewports).",
      "evidence": {
        "selector": "button[aria-label='Smaller text'], button[aria-label='Larger text'], button[aria-label='Toggle light or dark mode']",
        "note": "Not a WCAG failure since accessible name exists; flagged as a moderate usability concern, not a conformance blocker."
      }
    },
    {
      "type": "finding",
      "id": 3509,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., broad allowances for scripts/styles or missing directives such as script-src/object-src/frame-ancestors), which reduces defense-in-depth against XSS and clickjacking. While this is a static content site with limited user input surface, any injected script (via compromised third-party asset, ad, or comment/search feature) could execute without restriction. Remediation: define a strict CSP with script-src 'self' (plus explicit hashes/nonces for any inline scripts), object-src 'none', base-uri 'self', and frame-ancestors 'none' or 'self' to also cover clickjacking protection.",
      "evidence": {
        "note": "CSP header observed as weak/permissive per triage; specific directive values not fully enumerated in provided metadata"
      }
    },
    {
      "type": "finding",
      "id": 3510,
      "url": "https://artificialatheist.com/posts/the-afterlife-assumption-what-immortality-costs-moral-reason/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Empty alt text on related-article thumbnail is likely acceptable",
      "detail": "The image accompanying the 'Religion by Inheritance' related-post card has alt=\"\" while the adjacent heading link already conveys the article title as text. Since the image is purely decorative/illustrative and the link's accessible name comes from the visible heading text, screen-reader users are not blocked from understanding the link's purpose. This is a correct use of empty alt for a non-informative image and does not need descriptive alt text. No fix required, but confirm consistency: the main article's own image uses a descriptive alt ('Abstract geometric illustration...'), so there is an inconsistency in treatment of visually similar decorative images across the site that could confuse content authors, though it is not itself a WCAG failure.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Adjacent link text (h2 > a) already provides the accessible name for the linked card."
      }
    },
    {
      "type": "finding",
      "id": 3511,
      "url": "https://artificialatheist.com/about/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., missing directives or allowing 'unsafe-inline'/broad sources), which reduces mitigation against XSS and data injection if any injection point is later found. No compensating controls (such as a strict frame-ancestors, nonce-based script-src, or Subresource Integrity) were observed. Recommend defining a strict CSP with explicit script-src/style-src allowlists or nonces, disallowing 'unsafe-inline' and 'unsafe-eval', and adding frame-ancestors 'none' or 'self' to reduce clickjacking/injection risk.",
      "evidence": {
        "selector": "header: content-security-policy",
        "note": "Policy present but weak; no CSP directive strength verified in provided headers list"
      }
    },
    {
      "type": "finding",
      "id": 3512,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or ineffective Content-Security-Policy",
      "detail": "A weak CSP (e.g. permissive script-src such as 'unsafe-inline'/'unsafe-eval' or wildcard sources, or missing object-src/base-uri/frame-ancestors restrictions) reduces the effectiveness of CSP as a defense-in-depth control against XSS. On a content site that aggregates AI-generated posts and third-party assets, this increases the impact of any injection vulnerability (e.g. via a compromised CMS, ad script, or comment field) since injected scripts would not be blocked. Remediate by tightening script-src to specific hashes/nonces or trusted origins, removing 'unsafe-inline'/'unsafe-eval', and adding object-src 'none', base-uri 'self', and frame-ancestors directives.",
      "evidence": {
        "note": "CSP header present but permissive; no other injection vector observed in the page skeleton (static article listing, no visible user input forms other than search)."
      }
    },
    {
      "type": "finding",
      "id": 3513,
      "url": "https://artificialatheist.com/topics/philosophy/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Article thumbnail images have empty alt text despite being adjacent to article-specific content",
      "detail": "Screen reader users browsing the article list hear only the linked heading text, missing the thumbnail images entirely. Since each thumbnail appears to be a unique illustrative image generated per article topic (e.g., 'the-concept-of-supervenience...png') rather than a purely decorative/stock graphic, they arguably convey supplementary context about the article's theme. If purely decorative, empty alt is correct and this is a non-issue; if they carry meaning (e.g., custom illustration summarizing the article), alt text describing the image's relevance should be added. Recommend content owner confirm intent \u2014 if decorative, no fix needed (informational only), otherwise add concise descriptive alt text per image.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "filename pattern suggests topic-specific illustrations, not generic stock decoration"
      }
    },
    {
      "type": "finding",
      "id": 3514,
      "url": "https://artificialatheist.com/posts/the-gambler-s-fallacy-and-the-limits-of-intuitive-probabilit/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., allowing 'unsafe-inline' scripts/styles or wide-open source lists), which reduces its effectiveness as a mitigation against XSS/injection on a content site rendering user- or CMS-generated article content. Without strict script-src/object-src/base-uri directives, a successful injection (e.g., via a compromised CMS or third-party embed) could execute arbitrary script in visitors' browsers. Impact is moderate given this is a static-content blog with no visible login or form-based input surface reducing direct injection vectors, but any third-party widgets (Ko-fi embed, analytics) increase exposure. Remediation: tighten CSP to avoid 'unsafe-inline'/'unsafe-eval', use nonces or hashes for inline scripts, restrict script-src/object-src to 'self' and required trusted hosts, and set base-uri 'self' and frame-ancestors explicitly.",
      "evidence": {
        "note": "Flagged as weak-csp during triage; no explicit strict directives observed for script-src/object-src/base-uri"
      }
    },
    {
      "type": "finding",
      "id": 3515,
      "url": "https://artificialatheist.com/topics/secularism/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative alt on article thumbnail is likely acceptable, but verify intent",
      "detail": "Article preview images use alt=\"\" alongside adjacent linked headings that already convey the article title via text link. Since the image is adjacent to a redundant text link to the same article and doesn't convey unique information, empty alt is actually the correct WCAG-compliant choice per 1.1.1 (decorative/redundant images should have null alt). No barrier exists for screen-reader users since the article title link provides equivalent information. This is not a real defect; downgrading from the triage flag. If these thumbnails are meant to convey unique visual information not in the title (e.g., a chart or photo of a specific person), an alt describing that content should be added instead.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Image alt is empty but adjacent h2 link provides text equivalent"
      }
    },
    {
      "type": "finding",
      "id": 3516,
      "url": "https://artificialatheist.com/posts/religion-by-inheritance-how-birth-predicts-belief/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "minor",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., allows unsafe-inline scripts/styles or overly broad source lists), which reduces its effectiveness as a defense-in-depth control against XSS. For a mostly static content site (blog posts, no visible form inputs or dynamic user content in the skeleton), the injection surface is low, limiting realistic impact \u2014 no forms or user-supplied content sinks are present in the page skeleton. Recommend tightening CSP to remove 'unsafe-inline'/'unsafe-eval', use nonces or hashes for any required inline scripts, and restrict script-src/style-src/img-src to specific trusted origins. Also ensure frame-ancestors and object-src 'none' are set to cover clickjacking/plugin risks that might otherwise require X-Frame-Options.",
      "evidence": {
        "note": "CSP header content not fully provided; assessed as weak per triage flag. No injectable form fields or dynamic content sinks observed in DOM skeleton, lowering practical exploitability."
      }
    },
    {
      "type": "finding",
      "id": 3517,
      "url": "https://artificialatheist.com/posts/secularism-and-the-political-party-when-movements-organise/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Empty alt text on secondary article card image is acceptable but unconfirmed as decorative",
      "detail": "The nested article card image (secularism-and-the-court-witness-truth-without-god.png) has alt=\"\" while the primary article's image has descriptive alt text. Since the card already has an adjacent linked heading text conveying the article title, treating the image as decorative and giving it empty alt is correct practice under 1.1.1, and no screen-reader user is blocked\u2014the link text alone conveys purpose (2.4.4 also satisfied). This is not a barrier; classify as informational/no real issue rather than a defect. If the image is meant to be purely decorative, current markup is correct; no fix required.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "context suggests decorative intent, consistent with WCAG guidance"
      }
    },
    {
      "type": "finding",
      "id": 3518,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., allowing broad script-src/unsafe-inline or missing frame-ancestors/object-src restrictions), reducing mitigation of XSS and clickjacking on a content site with no visible user-input surfaces other than search. Impact is limited since no forms process sensitive data, but a weak CSP still increases exposure if any injected script (via compromised ad/analytics script or a stored XSS elsewhere) executes. Remediation: tighten CSP to restrict script-src to specific trusted origins, avoid 'unsafe-inline'/'unsafe-eval', and set frame-ancestors 'none' or 'self' to also cover clickjacking protection without relying solely on X-Frame-Options.",
      "evidence": {
        "selector": "n/a",
        "note": "CSP header value not fully shown; flagged as weak by triage heuristic"
      }
    },
    {
      "type": "finding",
      "id": 3519,
      "url": "https://artificialatheist.com/topics/religion/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative-style empty alt on article thumbnail is likely acceptable",
      "detail": "The image accompanies a heading and link with the same text ('Religion by Inheritance: How Birth Predicts Belief'), so it functions as a decorative/duplicative thumbnail rather than conveying unique content. Empty alt='' is an acceptable pattern per WCAG 1.1.1 when an adjacent text link already conveys the same information, preventing redundant announcements for screen-reader users. This is true across all 20 article cards in the skeleton. No barrier is created since the link text supplies equivalent information; downgrading from 'moderate' as originally flagged. If any of these images convey information not present in the adjacent heading/link (e.g., a chart or diagram illustrating stats), alt text should be added for that specific image.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "Image is adjacent to a heading link with matching text, satisfying redundant-content exception."
      }
    },
    {
      "type": "finding",
      "id": 3520,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The CSP directives observed appear overly permissive (e.g., broad script-src allowances or missing 'object-src'/'base-uri' restrictions), which reduces the mitigation value of CSP against XSS/injection if any user-controllable or third-party content is rendered (e.g., comment widgets, search page, ko-fi embed). Without strict script-src (nonce/hash based) and frame-ancestors/base-uri restrictions, an injected script or clickjacking vector could execute in the page context. Remediation: adopt a strict CSP using nonces or hashes for scripts, explicit script-src/style-src allowlists limited to required origins (e.g., ko-fi, analytics), and set base-uri 'self', object-src 'none', and frame-ancestors 'self' to harden against injection and framing.",
      "evidence": {
        "selector": "weak-csp",
        "note": "CSP directive content not fully provided; assessed as permissive based on triage flag"
      }
    },
    {
      "type": "finding",
      "id": 3521,
      "url": "https://artificialatheist.com/posts/what-the-multiverse-hypothesis-actually-predicts/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Empty alt on related-article thumbnail is likely acceptable but unverified",
      "detail": "The C. elegans article card image has alt=\"\" while the main article's hero image has a descriptive alt. If the thumbnail is purely decorative/redundant with the adjacent link text 'What the Nervous System of C. elegans Actually Taught Us', empty alt is correct per 1.1.1 and avoids duplicate announcements for screen-reader users. However, if similar thumbnails elsewhere in the site carry descriptive alt text, this is an inconsistency that could indicate the alt was omitted by mistake rather than intentionally decorative, which would deprive screen-reader users of contextual info when scanning teaser cards. Fix: confirm intent \u2014 keep alt='' if decorative/redundant, otherwise add a short descriptive alt.",
      "evidence": {
        "selector": "article img[alt='']",
        "note": "compare with hero image alt on same page which is descriptive"
      }
    },
    {
      "type": "finding",
      "id": 3522,
      "url": "https://artificialatheist.com/posts/what-the-nervous-system-of-c-elegans-actually-taught-us/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Empty alt on related-article thumbnail is likely acceptable but link text relies on adjacent heading",
      "detail": "The related-article image (what-the-multiverse-hypothesis-actually-predicts.png) has alt=\"\", making it decorative for screen-reader users, which is appropriate since the article title is already conveyed via the adjacent <h2><a> link text. No blind user is blocked because the link's accessible name comes from the heading text. This is a correct pattern, not a defect, so severity is minor/informational rather than a real barrier. If the image were meant to convey unique content (e.g., a diagram relevant to the article), empty alt would hide that information; confirm editorial intent and keep empty alt only for purely decorative images.",
      "evidence": {
        "selector": "article img[alt='']",
        "snippet": "<img alt=\"\" src=\"what-the-multiverse-hypothesis-actually-predicts.png\">",
        "note": "Adjacent h2>a provides descriptive link text, satisfying 2.4.4 and 1.1.1 despite empty alt."
      }
    },
    {
      "type": "finding",
      "id": 3523,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "security",
      "tier": 2,
      "rule": "security/misconfiguration",
      "severity": "moderate",
      "title": "Weak or permissive Content-Security-Policy",
      "detail": "The site's CSP appears weak (e.g., broad allowances like 'unsafe-inline'/'unsafe-eval' or wildcard sources), which reduces defense-in-depth against XSS if any injection point (comments, search, dynamic content rendering) is later found. For a static/blog-style site with no visible user-input forms in the skeleton, actual exploitation risk is currently low, but the policy should still be tightened: remove 'unsafe-inline'/'unsafe-eval', use nonces/hashes for any needed inline scripts, and restrict script-src/style-src/img-src to specific trusted origins. Also verify frame-ancestors is set to mitigate clickjacking, which would reduce reliance on X-Frame-Options.",
      "evidence": {
        "note": "CSP header contents not fully provided in input; flagged based on triage classification as weak."
      }
    },
    {
      "type": "finding",
      "id": 3524,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/2.4.4",
      "severity": "minor",
      "title": "Article link text lacks context of surrounding preview",
      "detail": "The article heading link ('What Machine-Authored Inquiry Can Be') is itself descriptive, so link purpose is met from link text alone; however the large block of preview text and image are not part of the link, so screen reader users navigating by link will not get the teaser context. This is not a failure but a minor UX gap\u2014consider wrapping the whole card in the link or adding aria-describedby to associate the teaser text for richer context.",
      "evidence": {
        "selector": "article h2 a",
        "note": "Teaser paragraph is a sibling, not part of the link"
      }
    },
    {
      "type": "finding",
      "id": 3525,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/1.1.1",
      "severity": "minor",
      "title": "Decorative empty alt on article images is appropriate but should be verified",
      "detail": "img alt=\"\" is correct only if the image is purely decorative and the adjacent heading link fully conveys the article topic. Since the heading text already describes the article, empty alt is acceptable here and not a barrier for screen-reader users; no fix needed unless images convey unique info not in text.",
      "evidence": {
        "selector": "article img",
        "note": "alt=\"\" confirmed appropriate given adjacent descriptive heading"
      }
    },
    {
      "type": "finding",
      "id": 3526,
      "url": "https://artificialatheist.com/topics/news/",
      "pipeline": "wcag",
      "tier": 2,
      "rule": "wcag/4.1.2",
      "severity": "moderate",
      "title": "Icon-only decorative icons on links lack redundant text but are aria-hidden, fine; navigation icons need check",
      "detail": "The <i aria-hidden=\"true\"> icons inside nav links (Science, News, etc.) are correctly hidden from assistive tech, and the link text itself (e.g. 'Science') provides an accessible name, satisfying 4.1.2 and 2.4.4. No barrier found for screen-reader users. Downgrading original flag: navigation aria labeling is sufficient.",
      "evidence": {
        "selector": "nav[aria-label='Topics'] a",
        "note": "Visible text plus aria-hidden icon = accessible name present"
      }
    }
  ],
  "errors": []
}