Executive Overview

MAG Lifestyle Development
Website Audit V1

www.mag.global — Property Developers in Dubai

Audit Date28 August 2026
Auditorvl-web-audit v2.1
VersionV1
PlatformConcrete5 5.6 · nginx · Plesk
MarketUAE · GCC · International
MAG
22 Issues Identified

Across 9 audit categories. Two critical issues require immediate management decision — a 12-year-old CMS and absent cookie consent.

2Critical
9High
7Medium
4Low
🚨
Concrete5 CMS Version 5.6.3.5b1 — End-of-Life Platform

The site is running a CMS from approximately 2014. This version has multiple publicly-known and exploitable vulnerabilities including SQL injection, XSS, and remote code execution. Upgrading to Concrete CMS 9.x is the single most important action on the entire site.

⚠️
No Cookie Consent — GDPR & UAE PDPL Risk

The site sets a session cookie and runs tracking without any consent banner or mechanism. This is a direct legal liability under GDPR for EU visitors and the UAE Personal Data Protection Law.

🔍
SEO Foundations Missing — Hreflang, Canonical, Schema All Absent

The bilingual EN/AR site has no hreflang alternate tags, no canonical tags, and no structured data. These three items can be added in 1–2 sprints and would materially improve organic search performance.

Performance by Category

Baseline indicators from automated checks only. Not a substitute for full testing.

Business & Content
60
Good portfolio; no schema; Twitter meta bug
UI / UX
45
Functional; no consent banner; switcher hidden
Accessibility
30
user-scalable=no fails WCAG; no hreflang
Performance
35
HSTS strong; no CDN; 1981 Expires date
SEO
40
Sitemap present; no hreflang, canonical, schema
Security
50
HSTS preload excellent; Concrete5 CVEs critical
Privacy / Legal
20
No cookie consent; no GDPR mechanism
Code Quality
25
Ancient CMS; IE conditionals; HTML bugs
CI / CD / Deployment
20
nginx/Plesk; no CDN; no CI/CD visible
Critical Issues — Fix This Week
SEC-001
Concrete5 CMS 5.6.3.5b1 — 12-year-old platform with active CVEs
Generator meta: `concrete5 - 5.6.3.5b1`. This version reached end-of-life circa 2015. Multiple publicly-known vulnerabilities exist including SQL injection, XSS, and remote code execution exploits.
→ Plan migration to Concrete CMS 9.x (current) on staging. Deploy post-testing. This is a multi-week project but must begin immediately.
CriticalP0Large
PRIV-001
No cookie consent — CONCRETE5 session cookie set before consent
No cookie banner detected. `CONCRETE5` session cookie set on first page load with no consent prompt. Site likely runs analytics and tracking without user consent.
→ Implement CookieYes or OneTrust with Google Consent Mode v2. Gate all tracking behind consent. Privacy policy page exists — banner is the missing piece.
CriticalP0Medium
High Priority Issues
SEO-001
No hreflang tags — bilingual site with no language signals
EN/AR versions exist at /ar/ prefix. Zero `` tags in source. Google treats both versions as duplicate content.
→ Add hreflang="en", hreflang="ar-ae", and hreflang="x-default" to all pages via Concrete5 page attributes.
HighP1Small
SEO-002 / SEO-003
No canonical tags · No structured data
No `` on any page. No JSON-LD schema detected — Organisation and RealEstateListing schemas are both missing despite a 15+ project portfolio.
→ Add canonical tags to every page template. Add Organization + RealEstateListing JSON-LD to homepage and project pages.
HighP1Medium
ACC-001
user-scalable=no in viewport — WCAG 1.4.4 Level AA failure
`` — prevents pinch-to-zoom, which is required for users with low vision.
→ Remove `user-scalable=no` from viewport meta. One-line fix in the CMS header template.
HighP1Quick Win
SEC-002
No Content-Security-Policy header
Header absent from all responses — XSS injection unmitigated at header level, especially significant given the outdated CMS.
→ Add CSP via nginx config in report-only mode first. Progressively harden.
HighP1Small
SEC-003
Session cookie missing Secure and SameSite flags
CONCRETE5 cookie set with `HttpOnly` but no `Secure` or `SameSite` — transmittable over HTTP; CSRF attack surface open.
→ Add `Secure; SameSite=Lax` to session cookie in Concrete5 configuration.
HighP1Small
PERF-001
No CDN · 1981 Expires date · Pragma no-cache
No CDN headers detected. `expires: Thu, 19 Nov 1981 08:52:00 GMT` — a 45-year-old expiry date. `pragma: no-cache` — all requests hit origin with zero caching.
→ Add Cloudflare CDN in front of nginx. Configure modern Cache-Control headers.
HighP1Medium
SEO-004
Twitter description has malformed unclosed HTML quote
Source: `content="...this is why at MAG we build more than luxury homes, we develop communities that can uplift you. At the heart of everything we do is the art of living well>"` — trailing `>` inside attribute.
→ Fix the closing quote in the CMS Twitter card meta configuration.
HighP1Quick Win
SEC-004
x-powered-by: PleskLin discloses hosting platform
Response header `x-powered-by: PleskLin` identifies the server management platform to every visitor and scanner.
→ Suppress via nginx config: `more_clear_headers 'X-Powered-By';`
HighP1Quick Win
Existing Strengths
HSTS with preload
max-age=581,536,000; includeSubDomains; preload — one of the strongest HSTS configurations possible
HTTPS enforced
HTTP 301 redirect to HTTPS working correctly
X-Frame-Options: SAMEORIGIN
Clickjacking protection header present
X-Content-Type-Options: nosniff
MIME sniffing protection present
robots.txt blocks CMS internals
All /concrete/, /config/, /models/, /libraries/ paths correctly disallowed
164-URL sitemap
Comprehensive coverage of all projects, news, and Arabic pages
reCAPTCHA on forms
Google reCAPTCHA deployed on contact and inquiry forms
Bilingual EN / AR
Full Arabic version at /ar/ prefix — appropriate for UAE market
Privacy Policy & Terms
Both pages exist and are linked from the footer
Strong project portfolio
Keturah Resort, Ritz-Carlton Residences, Emirates Financial Towers + 15 projects