Across 9 audit categories. Two critical issues require immediate management decision — a 12-year-old CMS and absent cookie consent.
The site is running a CMS from approximately 2014. This version has multiple publicly-known and exploitable vulnerabilities including SQL injection, XSS, and remote code execution. Upgrading to Concrete CMS 9.x is the single most important action on the entire site.
The site sets a session cookie and runs tracking without any consent banner or mechanism. This is a direct legal liability under GDPR for EU visitors and the UAE Personal Data Protection Law.
The bilingual EN/AR site has no hreflang alternate tags, no canonical tags, and no structured data. These three items can be added in 1–2 sprints and would materially improve organic search performance.
Baseline indicators from automated checks only. Not a substitute for full testing.