The same document a verified owner receives, produced by the shipped rules from a storefront we wrote ourselves.
Synthetic storefront
www.deep-synthetic.example is not a real shop. It is a storefront we authored for our own tests — every product, category, extension and defect in it was written by hand, and the hostname is under a reserved domain that resolves nowhere. We do not publish an audit of somebody else’s site as marketing, which is the same commitment the crawler page and the partner clauses make to merchants who are not our customers.
The findings, the scores and the skipped checks below are not written copy: they are what the rules in the product produce from that storefront, at a standard audit depth, rendered at the Enterprise plan so nothing is hidden behind a lock. The executive summary a language model writes is absent, because no model was called to produce this document and we do not fabricate one.
SuiteCommerce health report — www.deep-synthetic.example
Generated 2026-09-15T00:00:00.000Z
Scores
81 / 100Overall health
Host
www.deep-synthetic.example
Platform
sca
Release
2024.1.30 (certain, modern family)
Theme
none detected
Extensions
2
Audit depth
standard
Pages fetched
60
Pages rendered
20
Generated
2026-09-15T00:00:00.000Z
SEO58 / 100
coverage 72%
Exposure80 / 100
coverage 74%
Content90 / 100
coverage 84%
Performance98 / 100
coverage 86%
Accessibility94 / 100
coverage 100%
Platform95 / 100
coverage 86%
Exposure80 / 100 · coverage 74%
Exposure findings
Severity
Confidence
Status
Finding
Affected
Source
Evidence
Error
Certain
?Unknown
Plain HTTP does not redirect permanently to HTTPS1 plain-HTTP address(es) for this storefront answer without redirecting to HTTPS, so the site — and a shopper session on it — is reachable over an unencrypted connection.
site-wide—
rule
Warning
Certain
?Unknown
The storefront can be framed by another siteThe storefront sends neither X-Frame-Options nor a CSP frame-ancestors directive, so any site can load it in a frame and overlay it.
site-wide—
rule
Info
Certain
?Unknown
No Content-Security-Policy is sentThe storefront sends no Content-Security-Policy. A useful one is hard here: the SSP application emits inline scripts and the templates bundle is evaluated at runtime, so a policy without unsafe-inline would break the site. This is recorded as context rather than as a defect.
site-wide—
rule
Info
Certain
?Unknown
Platform: The NetSuite account id is reachable from the storefrontThe account id is reachable from the storefront: the CMS domain API names the NetSuite system domain, which carries it. This is NetSuite behaviour and there is no setting that suppresses it.
site-wide—
rule
Info
Likely
?Unknown
The public items API returns internal item fieldsThe public items API returns 2 operational field(s) for every item: isinactive, isonline. No commercial or cost field is exposed; confirm each of these is one you mean to publish.
2 configuration keys—
rule
Info
Certain
?Unknown
No Referrer-Policy is declaredThe storefront declares no Referrer-Policy, so the browser default decides what is sent with every cross-origin request. Storefront URLs carry search terms, facet paths and session tokens.
site-wide—
rule
Info
Certain
?Unknown
Platform: No Strict-Transport-Security header is sentThe storefront sends no Strict-Transport-Security header, so a shopper who types the domain makes one interceptable plain-HTTP request before being redirected. NetSuite does not emit this header and no Web Site setting adds it.
site-wide—
rule
Want this for your own storefront? See the plans, or verify a domain and take the free audit.