01

Method

We parsed script src attributes and form elements in seven server-rendered responses. Inline framework code was not classified as a third-party origin. Client-side network requests after interaction were outside this collection.

The result is used as a before-state for future analytics or advertising changes. It is not described as a complete privacy audit.

Measurement recordHostinger VPS in Europe; one cold request per URLCollector version 1.0.0Raw JSON ↗
02

Observed evidence

SignalObservedWhy it matters
External script origins0 across 7 sampled responsesNo third-party script src host was observed.
Server-rendered forms0 across 7 sampled responsesNo HTML form element was present in the initial responses.
Readiness tool0 forms · 0 external script originsThe interactive checklist remained browser-local in the sampled HTML.
03

Findings

  • The pre-advertising sample had no external script origin.
  • The readiness tool did not submit an HTML form.
  • Future ad or analytics code would materially change this baseline and needs a new disclosure and CSP review.
04

Decision and resulting changes

Keep advertising disabled during remediation. When approval occurs, enable ads only on substantive reports, update the privacy inventory, and exclude tools, policy pages, errors, APIs, and indexes from ad placement.

  • Added an explicit ad-eligibility policy to editorial pages.
  • Kept the readiness tool noindex and ad-free.
  • Published the raw pre-ad baseline for later comparison.
05

Limits and reproduction

Re-run automation/evidence_collector.py against the public origin and compare the resulting JSON fields. A difference is evidence of a changed response, not automatically an improvement.

  • The collector does not execute JavaScript.
  • Browser extensions, service workers, and post-interaction requests are not included.

Primary references

Release record

— Baseline captured from the public site, limitations documented, and remediation decision published.

Prepared by SiteSignal Hub Field Lab. Evidence collection and structural checks are automated; no personal use, customer result, or human test is claimed.