SquirrelScan
============================================================
Auditing: https://nikcub.me
Crawled 51 pages
Health Score: 76/100 (C)
Category Breakdown:
--------------------------------------------------
Content ████████░░ 82%
Passed: 342 | Warnings: 33 | Failed: 6
Accessibility █████████░ 92%
Passed: 1473 | Warnings: 68 | Failed: 4
Performance █████████░ 92%
Passed: 667 | Warnings: 115 | Failed: 1
Core SEO ████████░░ 88%
Passed: 482 | Warnings: 58 | Failed: 1
Images █████████░ 94%
Passed: 307 | Warnings: 51 | Failed: 0
Security ████████░░ 88%
Passed: 248 | Warnings: 50 | Failed: 0
Links ███████░░░ 78%
Passed: 374 | Warnings: 22 | Failed: 0
Crawlability █████████░ 96%
Passed: 166 | Warnings: 4 | Failed: 0
E-E-A-T ████████░░ 83%
Passed: 6 | Warnings: 2 | Failed: 0
URL Structure ██████████ 100%
Passed: 318 | Warnings: 1 | Failed: 0
Internationalization ██████████ 100%
Passed: 49 | Warnings: 0 | Failed: 0
Legal Compliance ██████████ 100%
Passed: 2 | Warnings: 0 | Failed: 0
Mobile ██████████ 100%
Passed: 193 | Warnings: 0 | Failed: 0
Structured Data ██████████ 100%
Passed: 48 | Warnings: 0 | Failed: 0
Social Media ██████████ 100%
Passed: 211 | Warnings: 0 | Failed: 0
Total: 4886 passed, 404 warnings, 12 errors
SUMMARY
----------------------------------------
Passed: 4886
Warnings: 404
Failed: 12
ISSUES
----------------------------------------
=== SEO ===
[CORE SEO]
[error] core/meta-description - Meta Description
Description: Validates meta description presence and length
Solution: Meta descriptions should be 120-160 characters and provide a
compelling summary of the page. While not a direct ranking factor,
good descriptions improve click-through rates from search results.
Write unique descriptions for each page that accurately preview the
content. Include a call-to-action when appropriate. If missing, search
engines will auto-generate snippets which may not represent your page
optimally.
[X] meta-description: Missing meta description
-> /fb-table.html
[!] meta-description: Description too long (7 pages)
-> /posts/blockplus-a-browser-extension-to-block-google-notifications
-> /posts/craig-wright-is-not-satoshi-nakamoto
-> /posts/fbi-seizes-fake-tor-hosted-jihad-funding-website-as-part-of-operation-onymous-leaves-up-real-site
-> /posts/frictionless-browser-plugin
-> /posts/logging-out-of-facebook-is-not-enough
-> /posts/notes-on-the-celebrity-data-theft
-> /posts/the-download-dot-con
-> Releasing BlockPlus, a Chrome extension that remov (163 chars)
-> A detailed investigation into Craig Wright's claim (172 chars)
-> During Operation Onymous the FBI seized a fake clo (168 chars)
-> Launching Frictionless, a Chrome extension that by (163 chars)
-> When it comes to losing track of Facebook online a (182 chars)
-> An in-depth look at the underground networks behin (170 chars)
-> How CNet's Download.com bundles adware and toolbar (170 chars)
[!] meta-description: Description too short (14 pages)
-> /about
-> /asides
-> /contact
-> /posts
-> /posts/how-megaupload-was-investigated-and-indicted
-> /posts/multiple-vulnerabilities-in-disqus-wordpress-plugin
-> /posts/persistant-and-unblockable-cookies-using-http-headers
-> /posts?page=1
-> /posts?page=2
-> /posts?page=3
-> /posts?page=4
-> /privacy
-> /subscribe
-> /tracking-cookie
-> Australian engineer working on data systems and AI (117 chars)
-> Short observations on security, technology, and cu (62 chars)
-> Get in touch with Nik Cubrilovic for collaboration (70 chars)
-> Long-form writing on security, privacy, and techno (54 chars)
-> Security research and technology analysis (41 chars)
-> Disclosure and fixes for a number of bugs in the W (106 chars)
-> Using HTTP headers as unblockable super-cookies (47 chars)
-> Long-form writing on security, privacy, and techno (54 chars)
-> Long-form writing on security, privacy, and techno (63 chars)
-> Long-form writing on security, privacy, and techno (63 chars)
-> Long-form writing on security, privacy, and techno (63 chars)
-> Privacy policy for nikcub.me - how we handle your (79 chars)
-> Get notified when I publish new articles. Subscrib (115 chars)
-> Demonstration of how tracking cookies work and per (79 chars)
[recommendation] core/twitter-cards - Twitter Cards
Description: Validates Twitter Card meta tags
Solution: Twitter Cards enhance how links appear in tweets. The twitter:card
meta tag specifies the card type (summary, summary_large_image,
player, or app). Add twitter:card, twitter:title, twitter:description,
and twitter:image tags. For large images, use summary_large_image with
images at least 800x418 pixels. Validate using Twitter's Card
Validator tool.
[!] twitter-card: No Twitter card or Open Graph tags for Twitter sharing
-> /fb-table.html
[warning] core/meta-title - Meta Title
Description: Validates page title presence and length
Solution: Every page needs a unique, descriptive title tag between 30-60
characters. Titles appear in browser tabs, search results, and social
shares. Write titles that accurately describe the page content while
including your primary keyword near the beginning. If your title is
too short, add more descriptive context. If too long, prioritize the
most important information first and trim secondary details. Avoid
keyword stuffing or duplicate titles across pages.
[!] meta-title: Title too long (24 pages)
-> /
-> /posts/60-minutes-australia-on-silk-road-and-bitcoin
-> /posts/analyzing-fbi-explanation-silk-road
-> /posts/blockplus-a-browser-extension-to-block-google-notifications
-> /posts/blockplus-v4-released-block-google-widgets-and-links-from-other-google-sites
-> /posts/crunchpad-proof-obviousness-in-ipad-design
-> /posts/cs-cart-v4-2-0-session-hijacking-and-other-vulnerabilities
-> /posts/facebook-also-doesnt-honor-p3p
-> /posts/facebook-fixes-logout-issue-explains-cookies
-> /posts/facebook-re-enables-controversial-tracking-cookie
-> /posts/fbi-seizes-fake-tor-hosted-jihad-funding-website-as-part-of-operation-onymous-leaves-up-real-site
-> /posts/fidelio-a-browser-plugin-for-secure-web-browsing
-> /posts/frictionless-browser-plugin
-> /posts/google-firefox-chrome-lady-gaga
-> /posts/guide-to-finding-a-good-and-safe-company-or-product-name
-> /posts/how-megaupload-was-investigated-and-indicted
-> /posts/howto-setup-secure-and-private-facebook-browsing
-> /posts/multiple-vulnerabilities-in-disqus-wordpress-plugin
-> /posts/multiple-vulnerabilities-in-mygov-australian-government
-> /posts/onymous-part1
-> /posts/persistant-and-unblockable-cookies-using-http-headers
-> /posts/securing-blockchain-users-with-tor-and-ssl
-> /posts/unicode-uf8ff-aka-the-apple-logo-character-on-macs
-> /posts/yahoo-axis-chrome-extension-leaks-private-certificate-file
-> Nik Cubrilovic | Engineer writing about AI, data, (69 chars)
-> 60 Minutes Australia on Silk Road and Bitcoin | Ni (62 chars)
-> Analyzing the FBI’s Explanation of How They Locate (78 chars)
-> BlockPlus - A browser extension to block Google+ n (79 chars)
-> BlockPlus v4 - Block Google+ widgets and links fro (87 chars)
-> The Crunchpad is proof of obviousness in the iPad (73 chars)
-> CS-Cart v4.2.0 Session Hijacking and Other Vulnera (75 chars)
-> Facebook and many other sites also bypass Internet (93 chars)
-> Facebook Fixes Logout Issue, Explains Cookies | Ni (62 chars)
-> Facebook Re-Enables Controversial Tracking Cookie (66 chars)
-> FBI seizes fake Tor hosted Jihad funding website a (115 chars)
-> Fidelio - A browser plugin for secure web browsing (67 chars)
-> Introducing Frictionless - Taking the friction out (107 chars)
-> The Google Firefox search deal, Chrome and Lady Ga (69 chars)
-> Guide to Finding a Good and Safe Company or Produc (73 chars)
-> How Megaupload Was Investigated and Indicted | Nik (61 chars)
-> How To Setup secure and private Facebook browsing (66 chars)
-> Multiple Vulnerabilities in Disqus WordPress Plugi (68 chars)
-> Multiple Vulnerabilities in MyGov, the Australian (123 chars)
-> Large Number of Tor Hidden Sites Seized by the FBI (113 chars)
-> Persistent and Unblockable Cookies Using HTTP Head (70 chars)
-> Securing Blockchain.info Users with Tor and SSL | (64 chars)
-> Unicode U+F8FF - aka. The Apple Logo Character, on (72 chars)
-> Yahoo Axis Chrome Extension Leaks Private Certific (75 chars)
[!] meta-title: Title too short (6 pages)
-> /contact
-> /fb-table.html
-> /posts
-> /posts/numeronym
-> /posts?page=1
-> /subscribe
-> Contact | Nik Cubrilovic (24 chars)
-> Facebook Cookie Analysis (24 chars)
-> Articles | Nik Cubrilovic (25 chars)
-> Numeronym | Nik Cubrilovic (26 chars)
-> Articles | Nik Cubrilovic (25 chars)
-> Subscribe | Nik Cubrilovic (26 chars)
[warning] core/canonical - Canonical URL
Description: Validates canonical URL presence and format
Solution: Canonical URLs tell search engines which version of a page is the
"master" copy, preventing duplicate content issues. Every page should
specify a canonical URL, typically pointing to itself. Add a tag in the head section. Use absolute URLs
and ensure consistency (with or without trailing slash, www vs
non-www). For paginated content, point to the main page or use
rel="prev/next".
[!] canonical: Missing canonical URL
-> /fb-table.html
[warning] core/og-tags - Open Graph Tags
Description: Validates Open Graph meta tags for social sharing
Solution: Open Graph tags control how your content appears when shared on
Facebook, LinkedIn, and other platforms. Required tags: og:title,
og:description, og:image, og:url, and og:type. Add OG tags in your
page head. Use images at least 1200x630 pixels for best display. Keep
og:title under 60 characters and og:description under 200. Test shares
using Facebook's Sharing Debugger tool.
[!] og-description: Missing og:description
-> /fb-table.html
[!] og-image: Missing og:image - social shares will lack imagery
-> /fb-table.html
[!] og-title: Missing og:title
-> /fb-table.html
[warning] core/title-unique - Title Uniqueness
Description: Checks that page titles are unique across the site
Solution: Each page should have a unique title that accurately describes its
content. Duplicate titles confuse search engines and users about which
page to display. Use a pattern like 'Page Topic | Brand Name' to
ensure uniqueness. CMS often generate duplicate titles - audit and
customize them.
[!] title-unique: 1 duplicate title(s) affecting 2 pages
-> "articles | nik cubrilovic..." (2 pages)
from: /posts
from: /posts?page=1
[warning] core/favicon - Favicon
Description: Checks for favicon presence
Solution: Favicons help with brand recognition and UX. Include multiple formats:
for legacy, for modern browsers, and
for iOS.
32x32px for .ico, 180x180px for Apple touch icon.
[!] favicon: No favicon found
-> /fb-table.html
[CONTENT]
[error] content/meta-in-body - Meta Tags in Body
Description: Detects meta tags incorrectly placed in document body
Solution: Move all meta tags from
to . Meta tags in the body are
ignored by browsers and search engines. Common offenders: meta
description, viewport, robots, and Open Graph tags. This is often
caused by incorrect HTML structure or dynamic rendering issues.
[X] meta-in-body: Found 16 meta tags in (6 pages)
-> /asides
-> /posts
-> /posts?page=1
-> /posts?page=2
-> /posts?page=3
-> /posts?page=4
-> description="Long-form writing on security, privacy, and techno..."
-> og:description="Long-form writing on security, privacy, and techno..."
-> og:image="https://nikcub.me/og-default.png"
-> og:image:alt="Articles"
-> og:image:height="630"
-> og:image:width="1200"
-> og:locale="en_US"
-> og:site_name="Nik Cubrilovic"
-> og:title="Articles"
-> og:type="website"
-> og:url="https://nikcub.me/posts"
-> twitter:card="summary_large_image"
-> twitter:creator="@nikcub"
-> twitter:description="Long-form writing on security, privacy, and techno..."
-> twitter:image="https://nikcub.me/og-default.png"
-> twitter:title="Articles"
[warning] content/duplicate-title - Duplicate Title
Description: Checks for duplicate title tags across the site
Solution: Each page should have a unique title tag that accurately describes its
content. Duplicate titles confuse search engines about which page to
rank and make your pages less distinguishable in search results. Use
unique, descriptive titles that include relevant keywords. For similar
pages (e.g., pagination), add differentiating elements like page
numbers or category names.
[!] duplicate-title: 1 duplicate title(s) found across 2 pages
-> "articles | nik cubrilovic..." (2 pages)
from: /posts
from: /posts?page=1
[warning] content/duplicate-description - Duplicate Description
Description: Checks for duplicate meta descriptions across the site
Solution: Each page should have a unique meta description that summarizes its
specific content. Duplicate descriptions reduce click-through rates
and provide poor user experience in search results. Write unique,
compelling descriptions for each page. For pages without unique
content (like paginated results), consider using no description rather
than a duplicate.
[!] duplicate-description: 1 duplicate description(s) found across 2 pages
-> "long-form writing on security, privacy, ..." (2 pages)
from: /posts
from: /posts?page=1
[warning] content/keyword-stuffing - Keyword Stuffing
Description: Detects excessive keyword repetition in content
Solution: Keyword stuffing is repeating words unnaturally to manipulate
rankings. Search engines penalize this practice. Write naturally for
users first. Use keywords where they fit naturally. Aim for 1-2%
keyword density at most. Use synonyms and related terms instead of
repeating the exact same phrase. Focus on providing value, not gaming
algorithms.
[!] keyword-stuffing: N word(s) may be overused (20 pages)
-> /fb-table.html
-> /posts
-> /posts/blockplus-a-browser-extension-to-block-google-notifications
-> /posts/blockplus-v4-released-block-google-widgets-and-links-from-other-google-sites
-> /posts/craig-wright-is-not-satoshi-nakamoto
-> /posts/cs-cart-v4-2-0-session-hijacking-and-other-vulnerabilities
-> /posts/facebook-is-losing-e-commerce
-> /posts/facebook-re-enables-controversial-tracking-cookie
-> /posts/guide-to-finding-a-good-and-safe-company-or-product-name
-> /posts/logging-out-of-facebook-is-not-enough
-> /posts/pain-and-gain
-> /posts/the-download-dot-con
-> /posts/the-google-ipo-skeptics
-> /posts/unicode-uf8ff-aka-the-apple-logo-character-on-macs
-> /posts/yahoo-axis-chrome-extension-leaks-private-certificate-file
-> /posts?page=1
-> /posts?page=2
-> /posts?page=3
-> /posts?page=4
-> /tracking-cookie
-> "blockplus" (3.3%)
-> "character" (3.6%)
-> "cookie" (3.1%)
-> "cookies" (6.5%)
-> "deleted" (9.2%)
-> "domain" (3.5%)
-> "download" (4.1%)
-> "extension" (3.7%)
-> "facebook" (3.5%)
-> "google" (4.4%)
-> "logo" (3.2%)
-> "lzfw" (3.9%)
-> "min" (3.1%)
-> "request" (4.6%)
-> "session" (3.6%)
-> "story" (3.6%)
-> "wright" (3.2%)
[warning] content/word-count - Word Count
Description: Checks content length for thin content issues
Solution: Pages with thin content (under 300 words) often struggle to rank well
and are actively deindexed by Google since the June 2025 core update.
Add more valuable, relevant content to thin pages—aim for at least 500
words for standard pages and 1000+ for in-depth articles. If a page
can't be fleshed out, voluntarily noindex it or consolidate it into a
more comprehensive resource. Trimming thin pages from your index is
better than leaving low-value content for Google to penalize.
[!] word-count: Thin content: N words (min N) (11 pages)
-> /
-> /asides
-> /contact
-> /fb-table.html
-> /posts/blockplus-a-browser-extension-to-block-google-notifications
-> /posts/fbi-seizes-fake-tor-hosted-jihad-funding-website-as-part-of-operation-onymous-leaves-up-real-site
-> /posts/numeronym
-> /posts?page=4
-> /privacy
-> /subscribe
-> /tracking-cookie
-> Thin content: 252 words (min 300)
-> Thin content: 42 words (min 300)
-> Thin content: 82 words (min 300)
-> Thin content: 189 words (min 300)
-> Thin content: 292 words (min 300)
-> Thin content: 269 words (min 300)
-> Thin content: 223 words (min 300)
-> Thin content: 224 words (min 300)
-> Thin content: 184 words (min 300)
-> Thin content: 82 words (min 300)
-> Thin content: 188 words (min 300)
[ACCESSIBILITY]
[error] a11y/duplicate-id-aria - Duplicate ID ARIA
Description: Checks that IDs used in ARIA attributes are unique
Solution: IDs referenced by ARIA attributes (aria-labelledby, aria-describedby,
aria-controls, etc.) must be unique on the page. Duplicate IDs cause
assistive technology to potentially reference the wrong element.
Rename duplicate IDs to be unique.
[X] duplicate-id-aria: 1 problematic ID(s) in ARIA attributes (2 pages)
-> /posts/relevance-time-for-twitter
-> /posts/securing-blockchain-users-with-tor-and-ssl
-> "footnote-label" (not found)
[error] a11y/label-content-name-mismatch - Label Content Name Mismatch
Description: Checks that visible label text is part of accessible name
Solution: For controls with visible labels, the accessible name should contain
the visible text. Voice control users say what they see - if the
accessible name doesn't include the visible label, voice commands
won't work. Example: A button showing 'Search' should not have
aria-label='Find products'.
[X] label-content-name-mismatch: 1 element(s) where visible text doesn't match accessible name (2 pages)
-> /posts/relevance-time-for-twitter
-> /posts/securing-blockchain-users-with-tor-and-ssl
-> a: visible="↩" vs aria-label="back to reference 1"
[recommendation] a11y/landmark-regions - Landmark Regions
Description: Checks for proper landmark regions (main, nav, footer)
Solution: Landmark regions help screen reader users navigate page structure. Use
semantic HTML5 elements: for primary content,