In the past fortnight we have published four audits of other people’s websites. We asked 100 Irish domains for their robots.txt and found 27 refusing a documented crawler. We checked the same cohort for CAA records and found not one with the account binding Google had asked for six days earlier. We checked whether any of them could prove consent was enforced and found two. We checked 86 sites on a hosted platform and found 80 sending no security headers at all.
On 8 October 2026 we pointed every one of those scripts at ourselves: the seven hosts REPTILEHAUS owns and operates. We expected to come out ahead of the cohort. We did not.
TL;DR
- Our own privacy policy page has been published with zero bytes of content since 5 February 2019, while the same site loads Google Tag Manager, GA4, a Meta Pixel and Google Ads conversion tracking.
- Consent defaults to denied on all seven storage types, then flips
ad_storageto granted when a visitor submits the contact form, and uploads their email address with it. There is no consent platform on the page. - Across the estate we serve 3,758 bytes of robots.txt containing not one directive. Three hosts serve a byte-identical 1,248-byte file that is 100% comments.
- HSTS: 0 of 7 hosts. CSP: 0 of 7. CAA: 0 of 7. DMARC enforcement: 0 of 4 domains. One host sends any security headers, and one of the five it sends was deprecated years ago.
- The only control we pass on every host is TLS, and nobody here configured it. Our CDN did.
What we measured, and how
Seven hosts: reptile.haus, praguers.com, micadora.eu, satosh.ie, dev.satosh.ie, blog.satosh.ie and crionnahealth.reptile.haus. Four of those are apex domains, so the DNS checks run against four rather than seven.
Every check is the one we published, re-run unmodified: dig at the apex for CAA, DS, MX, SPF and DMARC with all negatives re-tested on three independent resolvers; curl for response headers, redirect behaviour and robots.txt; openssl s_client for protocol support and the live certificate issuer; and a markup scan of each homepage for tag managers, trackers and consent gating. The whole sweep takes about four minutes. That number matters, and we will come back to it.
Finding one: the privacy policy is an empty page
Requesting /privacy-policy/ on our own site returns HTTP 200. The page has a title, a navigation bar, a footer and a call to action. Strip the site chrome and the body contains no policy text whatsoever.
This is not a rendering artefact. Reading the page straight out of the WordPress REST API, post ID 1864, slug privacy-policy, status publish, the content field is zero bytes and the last modified date is 5 February 2019. Of the 17 published pages on the site, exactly one has fewer than 15 words of body content, and it is that one.
In the seven years and eight months since that page was last touched, the site has gained Google Tag Manager, a GA4 property, a Meta Pixel and Google Ads conversion tracking with enhanced conversions enabled. Every one of those arrived after the document that was supposed to describe them stopped being written.
Finding two: our contact form is our consent banner
The homepage sets a consent default that looks exemplary. All seven Google consent types are initialised to denied: ad storage, ad user data, ad personalisation, analytics storage, functionality storage, personalisation storage and security storage.
Further down the same document, inside a listener bound to the Contact Form 7 wpcf7mailsent event, the page grants ad_storage and ad_user_data, passes the submitter’s email address to Google Ads as enhanced-conversion user data, and fires a conversion.
Read that as a visitor would experience it. You arrive, nothing is stored, everything is denied. You fill in the contact form because you want to talk to us about a project. Submitting it is treated as your consent to advertising storage, and your email address is handed to Google Ads with it.
We scanned both tracked sites for fifteen consent management platforms by name. Zero hits. We counted scripts gated with type="text/plain", which our own consent audit identified as the only form of enforcement that can be proved from outside. Zero, on every host. By the standard we set for 100 Irish sites a fortnight ago, we are in the 98 that cannot prove anything.
The sister site blog.satosh.ie is worse in one respect: it runs a tag manager, GA4 and a session-recording tool, and has no privacy policy at any of the seven paths we probed.
Finding three: 3,758 bytes of robots.txt, zero rules
Three of our hosts serve a robots.txt of exactly 1,248 bytes. The files are byte-identical across all three, sharing an MD5 of 3f95773253df085be0d6fd831ae2195f. Every line in that file begins with #. It is a 1,248-byte explanation of what content signals are, followed by this, in capitals:
ANY RESTRICTIONS EXPRESSED VIA CONTENT SIGNALS ARE EXPRESS RESERVATIONS OF RIGHTS UNDER ARTICLE 4 OF THE EUROPEAN UNION DIRECTIVE 2019/790 ON COPYRIGHT AND RELATED RIGHTS IN THE DIGITAL SINGLE MARKET.
No content signals are expressed. The legal reservation covers an empty set. This is a CDN default that ships whether or not you configure anything: it looks like policy and it is packaging.
The other four hosts are no better. blog.satosh.ie serves 14 bytes, a bare User-agent: * stanza with no rule under it. praguers.com and micadora.eu return an nginx 404 page, which also announces the server version. And satosh.ie redirects the robots.txt request to another host’s homepage, which answers 200 with HTML.
Our own words on this, from twelve days ago: a 4xx on robots.txt is not protection, it is permission. RFC 9309 section 2.3.1.3 says a crawler may then access any resource on the server. We published that, and two of our own domains do exactly it.
Finding four: the headers
| Header | Hosts sending it |
|---|---|
| Strict-Transport-Security | 0 of 7 |
| Content-Security-Policy | 0 of 7 |
| Cross-Origin-Opener-Policy | 0 of 7 |
| X-Frame-Options | 2 of 7 |
| X-Content-Type-Options | 2 of 7 |
| Referrer-Policy | 2 of 7 |
| Permissions-Policy | 2 of 7 |
Five of our seven hosts, including the agency’s own site, send none of the eleven headers we checked. The two that send anything are the same application on two hostnames, and it sends five. One of the five is X-XSS-Protection, a header browsers removed support for years ago, while the two that would actually do something, HSTS and CSP, are absent.
For comparison, the hosted platform we criticised five days ago had one site in 86 sending HSTS. We have none in seven.
Finding five: the DNS, and a plaintext homepage
Not one host publishes a CAA record. We re-tested every negative on three independent resolvers and all of them held, so this is our configuration rather than a resolver artefact. Six of our seven hosts present a certificate from Google Trust Services, which means a single line, 0 issue "pki.goog", would restrict issuance on almost the whole estate at zero operational cost.
One of four apex domains is DNSSEC-signed. Two of four publish SPF, one with a soft fail. Two publish DMARC and both sit at p=none, which we described in July as instructing receiving servers to do precisely nothing. Two of our four domains have no SPF and no DMARC at all, which makes them free to spoof. None publishes MTA-STS or TLS reporting.
The worst single result is on satosh.ie. Over HTTPS the apex returns a 301 to dev.satosh.ie for every path, discarding the path as it goes, so /.env and /.git/config both resolve to a 200. Over plain HTTP the apex does not redirect at all: it serves the full production homepage in cleartext, with no HSTS anywhere on the domain to prevent a downgrade. The canonical property answers on a hostname called dev, and the one route that should be closed is the one that is open.
The pattern, which is the actual finding
There is one control we pass on all seven hosts. Every host negotiates TLS 1.3 and refuses TLS 1.0 and 1.1. It is the cleanest result in the audit, and nobody at REPTILEHAUS configured it. Cloudflare did, as a platform default, for every customer.
Sort the results by that distinction and they stop being a list of mistakes. Everything we pass is a vendor default. Everything we fail required a person to make a decision, write a line of configuration and own it afterwards. CAA, HSTS, a CSP, a DMARC policy above p=none, a robots.txt with a rule in it, a privacy policy with a sentence in it: each one needs an owner, and on our own estate none of them had one.
This is the failure mode we see most often in client audits, and the reason is structural rather than technical. Client work is scheduled, invoiced and reviewed. Internal work is none of those things, so it loses every scheduling conflict it ever has. Our own estate lost seven years and eight months of them.
What we are doing, and what you should do
The fixes here are not hard, which is the uncomfortable part. Publishing an actual privacy policy and moving consent behind a real consent platform are the two that matter most and the two that need a decision rather than a deploy, so they are first. A 0 issue CAA record, an HSTS header, a robots.txt with directives in it, forcing HTTPS on the satosh.ie apex and retiring the dev hostname from production are all configuration changes measured in minutes. Moving DMARC off p=none needs a reporting period first, so it gets a date rather than a ticket.
If you want the same picture of your own estate, you do not need us. The checks are dig, curl and openssl, all of them free, all of them externally observable, and the full sweep took four minutes for seven hosts. The reason most organisations have never seen this report about themselves is not cost. It is that nobody has been asked to run it.
Three things worth doing this week. Request your own privacy policy URL and read what actually comes back, because an HTTP 200 is not evidence that a document exists. Grep your homepage source for consent and follow every call that changes state, because a denied default means nothing if something downstream grants it. And run the sweep on a schedule rather than once, because every finding above was true yesterday too and the only thing that changed today was that somebody looked.
REPTILEHAUS builds and operates web platforms, and this is the standard we hold client estates to, which is precisely why publishing our own results was the only honest option. If you want this audit run against your domains, or the findings fixed rather than just listed, get in touch.
📷 Photo by Thilina Alagiyawanna on Unsplash — an ornate four-way signpost whose plates face you blank. The ironwork is the expensive part; the direction is the part that was supposed to be written on it.
