◆ Northlight Studio
Bayside Auto Group
baysideauto.com
Overall
C+
72 / 100
B
Security84C
SEO68D
Speed55C
Email70
How to read this report.
This is an automated scan — a reliable guide to where the site stands against common benchmarks, not a
guarantee or a manual penetration test. Every finding below is grounded in a real, reproducible check
performed on Jul 2, 2026. Anything we could not verify from the outside is marked
Not checked rather than guessed. Fixing these items raises the
grade; it does not by itself certify the site as secure.
B
Security
5 checks · header hardening & transport
HSTS enforced
Strict-Transport-Security · max-age=31536000 · present on all responses
Content-Security-Policy missing
No CSP header returned — page has no defence-in-depth against injected scripts
X-Frame-Options missing
No anti-clickjacking header — site can be embedded in a hostile iframe
TLS 1.3 negotiated
Modern protocol · strong cipher suite · valid certificate chain
No mixed content
All subresources loaded over HTTPS — no insecure asset requests detected
C
SEO
6 checks · crawl & discoverability
3 pages missing meta descriptions
/inventory · /financing · /about — no <meta name="description"> found
2 broken internal links
/financing → /apply-now (404) · /inventory → /specials-2024 (404)
No structured data
No JSON-LD / schema.org markup — dealership, vehicles and reviews aren't machine-readable
Titles & primary meta present
Homepage & key landing pages have unique, length-appropriate titles
Sitemap valid
/sitemap.xml reachable · 48 URLs · well-formed
robots.txt healthy
Present · does not block crawlable content · references sitemap
D
Speed
Web Vitals · mobile emulation · 4G
LCP 4.6s on mobile
Largest Contentful Paint · "poor" (> 4.0s) — hero image is the LCP element
Render-blocking JavaScript
4 scripts in <head> block first paint — no defer/async on main bundle
Uncompressed images
Est. ~1.8 MB savings from modern formats (WebP/AVIF) + right-sizing on 11 images
No CDN detected
Assets served from a single origin — no edge caching header signature found
Field data (CrUX)
Not checked — insufficient real-user traffic in the public dataset for this origin
C
Email deliverability
3 checks · DNS records
SPF present
v=spf1 record found · single ~all — authorised senders declared
DKIM present
Selector default._domainkey resolves · public key published
DMARC missing
No _dmarc TXT record — spoofed mail from this domain won't be rejected or reported
Inbox placement / reputation
Not checked — requires live send testing outside the scope of a passive DNS scan
Prepared by Northlight Studio · northlight.studio
Report ID BAY-2026-0702 · valid as of scan date · questions? hello@northlight.studio
Report ID BAY-2026-0702 · valid as of scan date · questions? hello@northlight.studio
One free follow-up scan
Single-use · verify your fixes
FLWP-7K2Q
Single-use · verify your fixes