Skip to main content
Verified Passive AuditScanned: Sep 11, 2026100% Non-Intrusive

silverwoodmedicalcentre.com

Full technical assessment across email security, infrastructure encryption, search & AI discovery, and conversion pathways. Written with exact steps for non-technical leadership and developers.

Overall Score
84/100
Rating
Grade B
Book 48-Hour Diagnostic Sprint
Critical Issues
2

Requires immediate remediation

Quick Wins
17

Under 1 hour to resolve

AI & AEO Ready
76%

Perplexity & ChatGPT visibility

Opportunities
13

Revenue & security upsides

DataForSEO TelemetryLive SERP Verification

Google Search Footprint & Competitor Value

Est. Google Ads Replacement Value$0/mo
Total Indexed Keywords
4

Ranking in Top 100 on Google

Est. Monthly Organic Visits
~3

High-intent non-paid traffic

Google Knowledge Panel
Verified

Official brand entity card

Top Sample Ranking Keywords & SERP Features
riverdale medical centreVol: 210/mo
#23
murugu clinicVol: 210/mo
#48
medwin hospitalVol: 50/mo
#55
oakwood hospitalVol: 880/mo
#59

System Category Breakdown

Email Security & Deliverability98/100 (A)
0 issues2 opportunity
SSL/TLS & Encryption98/100 (A)
0 issues1 opportunity
Website & Cloud Security56/100 (D)
6 issues2 opportunity
Privacy & Kenya DPA 201980/100 (B)
1 issue0 opportunity
Speed, Assets & Carbon Footprint66/100 (C)
3 issues3 opportunity
Search Engine Visibility76/100 (B)
2 issues2 opportunity
AI Engine Optimization (AEO)76/100 (B)
1 issue2 opportunity
accessibility90/100 (A)
1 issue0 opportunity
AI Workflow & Agent Readiness100/100 (A)
0 issues1 opportunity

Detailed Findings & Recommendations (27)

highSpeed, Assets & Carbon Footprint

Your server takes 10.1 seconds to start responding

OBSERVED EVIDENCE:We measured 10142ms to first byte from our connection. Google treats anything over 800ms as needing improvement.
Commercial Impact

This delay happens before a visitor sees anything at all — no text, no logo, a blank screen. On mobile data it is worse. Google has published that the probability of a visitor leaving rises sharply with every additional second, and slow server response also directly suppresses your search ranking.

Recommended Fix

Usually caching, an oversized page query, or hosting located far from your customers. The fix is typically a CDN in front of the site plus caching at the server, which is a day of work rather than a rebuild.

HarLyn Service Line:High-Speed Web Systems
highPrivacy & Kenya DPA 2019

You collect personal information but publish no privacy policy

OBSERVED EVIDENCE:Your homepage has a form that collects visitor details, but we found no link to a privacy policy.
Commercial Impact

Kenya's Data Protection Act 2019 requires that you tell people what data you collect, why, how long you keep it and who you share it with — before you collect it. The same applies under GDPR for any European visitors. Beyond the legal exposure, the absence of a policy is a visible trust problem for anyone deciding whether to hand over their details.

Recommended Fix

Publish a privacy policy covering the personal data you actually collect, your lawful basis, retention periods, third parties you share with, and how someone exercises their rights. Link it from the footer and from every form.

HarLyn Service Line:Cyber Defense & Compliance
Technical Reference
mediumWebsite & Cloud SecurityQuick Win (< 1hr)

Missing HSTS header — the first visit each day is downgradeable

OBSERVED EVIDENCE:Your site sends no Strict-Transport-Security header.
Commercial Impact

HSTS tells browsers to only ever contact your site over an encrypted connection. Without it, a visitor on public Wi-Fi can be silently redirected to an unencrypted copy of your site before the redirect to HTTPS happens, and anything they type there is readable.

Recommended Fix

Add a Strict-Transport-Security header with a max-age of at least one year, after confirming every subdomain you use supports HTTPS.

HarLyn Service Line:Cyber Defense & Compliance
mediumWebsite & Cloud SecurityQuick Win (< 1hr)

Your pages can be embedded inside another site

OBSERVED EVIDENCE:No X-Frame-Options header and no frame-ancestors directive in a Content Security Policy.
Commercial Impact

An attacker can load your site invisibly inside their own page and trick your visitors into clicking your buttons — submitting a form or authorising an action they cannot see. It is also used to host convincing copies of login pages.

Recommended Fix

Add X-Frame-Options: SAMEORIGIN, or a frame-ancestors directive in your Content Security Policy.

HarLyn Service Line:Cyber Defense & Compliance
mediumSearch Engine VisibilityQuick Win (< 1hr)

No meta description — Google is writing your search listing for you

OBSERVED EVIDENCE:We found no meta description tag on the homepage.
Commercial Impact

The meta description is the two-line summary under your link in search results. Without one, Google scrapes whatever text it finds first, which is often a menu or a cookie notice. That is your sales pitch, written by an algorithm.

Recommended Fix

Write a 150-160 character description for each important page that states the offer and gives a reason to click.

HarLyn Service Line:High-Speed Web Systems
mediumSearch Engine VisibilityQuick Win (< 1hr)

No XML sitemap — search engines have to guess which pages exist

OBSERVED EVIDENCE:We found no sitemap at https://silverwoodmedicalcentre.com/sitemap.xml.
Commercial Impact

A sitemap is the list of pages you want indexed. Without one, search engines only find pages they can reach by following links, so anything buried deep in the site — often exactly the product or service pages you want ranking — may never be crawled.

Recommended Fix

Generate an XML sitemap, reference it from robots.txt, and submit it in Google Search Console. Most platforms can generate it automatically.

HarLyn Service Line:High-Speed Web Systems
mediumaccessibilityQuick Win (< 1hr)

1 form field has no proper label

OBSERVED EVIDENCE:We found 1 input field without an associated label element or accessible name.
Commercial Impact

A screen reader announces an unlabelled field as just "edit text", so a blind user cannot complete the form at all. For sighted users, placeholder-only labels vanish as soon as they start typing, which causes errors and abandonment.

Recommended Fix

Associate a visible <label> with every field. Placeholders are not a substitute for labels.

HarLyn Service Line:High-Speed Web Systems
mediumWebsite & Cloud Security

No Content Security Policy — the browser will run any script injected into your pages

OBSERVED EVIDENCE:Your site sends no Content-Security-Policy header.
Commercial Impact

A Content Security Policy tells the browser which scripts it is allowed to run. Without one, if an attacker manages to inject code into a page — through a comment field, a compromised plugin, or a third-party script that gets hijacked — the browser executes it without question. This is the mechanism behind most card-skimming attacks on small e-commerce sites.

Recommended Fix

Add a Content-Security-Policy header listing the domains permitted to serve scripts, styles and frames. Roll it out in report-only mode first so you can see what would break before enforcing it.

HarLyn Service Line:Cyber Defense & Compliance
Technical Reference
mediumAI Engine Optimization (AEO)

Your homepage has very little text for a search engine or AI to work with

OBSERVED EVIDENCE:We counted roughly 178 words of body content once navigation, headers and footers were excluded.
Commercial Impact

Search engines and AI assistants can only cite what they can read. A page built mostly from images, sliders or text baked into graphics gives them almost nothing to index, so it will not rank for the terms your customers search and will not be quoted in an AI answer.

Recommended Fix

Add real, specific text covering what you sell, who you serve, where you operate and what makes you the right choice. Text inside images should be moved into actual page copy.

HarLyn Service Line:High-Speed Web Systems
lowWebsite & Cloud SecurityQuick Win (< 1hr)

Missing X-Content-Type-Options header

OBSERVED EVIDENCE:Your site does not send X-Content-Type-Options: nosniff.
Commercial Impact

Without this header, browsers may guess the type of a file rather than trusting what the server declares. An uploaded image that actually contains script can then be executed as script.

Recommended Fix

Add the header X-Content-Type-Options: nosniff. It is a one-line server configuration change.

HarLyn Service Line:Cyber Defense & Compliance
lowWebsite & Cloud SecurityQuick Win (< 1hr)

Links that open in a new tab give the destination control over yours

OBSERVED EVIDENCE:4 links open in a new tab without rel="noopener".
Commercial Impact

The page you link to can quietly replace the tab your visitor came from with a copy of your site — a convincing way to harvest logins. It also slows down the browser.

Recommended Fix

Add rel="noopener noreferrer" to every link using target="_blank".

HarLyn Service Line:High-Speed Web Systems
lowWebsite & Cloud SecurityQuick Win (< 1hr)

Your site publicly announces which platform and version it runs

OBSERVED EVIDENCE:The page includes a generator tag reading: "WordPress 7.1"
Commercial Impact

This tells anyone — including automated scanners — exactly which software and version you run, so they can look up published vulnerabilities for it without any effort. It offers no benefit to you or to visitors.

Recommended Fix

Remove the generator meta tag. On WordPress this is a one-line change in the theme; most platforms have a setting for it.

HarLyn Service Line:Cyber Defense & Compliance
lowSpeed, Assets & Carbon FootprintQuick Win (< 1hr)

2 scripts block your page from rendering

OBSERVED EVIDENCE:We found 2 script tags in the page head without async or defer.
Commercial Impact

The browser stops building the page and waits for each of these to download and run before showing anything. Each one adds directly to how long a visitor stares at a blank screen.

Recommended Fix

Add defer (or async, where order does not matter) to these tags, or move them to the end of the document.

HarLyn Service Line:High-Speed Web Systems
lowSpeed, Assets & Carbon Footprint

Your homepage HTML is unusually heavy

OBSERVED EVIDENCE:The HTML document alone is 157KB before any images, scripts or fonts are loaded.
Commercial Impact

Every kilobyte here is downloaded before the page can start rendering. On a Kenyan mobile connection this is the difference between a page that appears instantly and one that visibly assembles itself.

Recommended Fix

Usually inlined styles, a page builder that ships unused markup, or content that should be loaded on demand. Compression (Brotli or gzip) alone often cuts this by 70%.

HarLyn Service Line:High-Speed Web Systems
highAI Engine Optimization (AEO)

No structured data — AI assistants cannot reliably describe your business

OBSERVED EVIDENCE:We found no JSON-LD structured data on your homepage.
Commercial Impact

Structured data is the machine-readable summary of who you are, what you sell, where you are and when you are open. Google uses it for rich results, and ChatGPT, Perplexity and Google AI Overviews lean on it heavily when deciding which business to name in an answer. Without it, an AI assistant asked to recommend a supplier in your category has to guess from your prose — and it will more often name a competitor whose details it can read cleanly.

Recommended Fix

Add Organization and LocalBusiness schema with your name, address, phone, hours and service area, plus Product or Service schema on the relevant pages and FAQPage schema on any question-and-answer content.

HarLyn Service Line:High-Speed Web Systems
Technical Reference
mediumAI Engine Optimization (AEO)Quick Win (< 1hr)

No llms.txt — you have no summary written for AI assistants

OBSERVED EVIDENCE:We found no /llms.txt file on your site.
Commercial Impact

llms.txt is an emerging convention: a plain-text file giving AI assistants a clean, authoritative summary of what your business does and which pages matter, instead of leaving them to infer it from navigation menus and marketing copy. Adoption is early, which is exactly why publishing one now is cheap and puts you ahead of competitors who will get to it in a year.

Recommended Fix

Publish a short /llms.txt describing the business, the services, the service area and links to the pages you most want cited.

HarLyn Service Line:AI Search & AEO Integration
Technical Reference
lowEmail Security & DeliverabilityQuick Win (< 1hr)

No MTA-STS policy — inbound email can be intercepted via TLS downgrade

OBSERVED EVIDENCE:We looked up _mta-sts.silverwoodmedicalcentre.com and found no MTA-STS record.
Commercial Impact

Standard SMTP encryption (STARTTLS) is opportunistic, meaning an active attacker on the network can strip the encryption handshake and read incoming emails in plaintext. MTA-STS (RFC 8461) forces sending mail servers to use TLS 1.2+ encryption, closing the man-in-the-middle downgrade loophole.

Recommended Fix

Publish an MTA-STS DNS record at _mta-sts and host the standard policy text at https://mta-sts.<domain>/.well-known/mta-sts.txt.

HarLyn Service Line:Cyber Defense & Compliance
Technical Reference
lowSSL/TLS & EncryptionQuick Win (< 1hr)

No CAA record — any Certificate Authority is permitted to issue certificates for you

OBSERVED EVIDENCE:We looked up DNS CAA records for silverwoodmedicalcentre.com and found none.
Commercial Impact

A CAA (Certificate Authority Authorization) DNS record explicitly specifies which Certificate Authorities (like Let's Encrypt, DigiCert, or Google Trust Services) are allowed to issue certificates for your domain. Without it, if any CA anywhere in the world is compromised or misconfigured, it could issue an unauthorized certificate for your domain without your knowledge.

Recommended Fix

Publish a CAA DNS record for silverwoodmedicalcentre.com naming your approved certificate provider(s) (e.g. '0 issue "letsencrypt.org"').

HarLyn Service Line:Cyber Defense & Compliance
Technical Reference
lowWebsite & Cloud SecurityQuick Win (< 1hr)

Missing Referrer-Policy header

OBSERVED EVIDENCE:Your site sends no Referrer-Policy header.
Commercial Impact

Without a referrer policy, the full address of the page a visitor came from — which may contain private identifiers or search terms — is passed to every external site they click through to.

Recommended Fix

Add Referrer-Policy: strict-origin-when-cross-origin.

HarLyn Service Line:Cyber Defense & Compliance
lowSpeed, Assets & Carbon FootprintQuick Win (< 1hr)

Every image loads immediately, including the ones nobody scrolls to

OBSERVED EVIDENCE:6 of 6 images load eagerly rather than on demand.
Commercial Impact

Visitors download images far below the fold that most of them will never see. On mobile data this is bandwidth they pay for, spent slowing down the part of the page they actually wanted.

Recommended Fix

Add loading="lazy" to images below the fold — keeping it off the main hero image, which should load immediately.

HarLyn Service Line:High-Speed Web Systems
lowSearch Engine VisibilityQuick Win (< 1hr)

Your links look broken when shared on WhatsApp or LinkedIn

OBSERVED EVIDENCE:Open Graph tags are incomplete: og:title missing, og:image missing.
Commercial Impact

When someone shares your link on WhatsApp, LinkedIn or Facebook, these tags decide whether it appears as a rich preview with an image and headline, or as a bare grey URL. In a market where WhatsApp is the main sharing channel, this directly affects how many people click a link a customer forwards.

Recommended Fix

Add og:title, og:description and og:image (1200x630px) to every page, plus the Twitter card equivalents.

HarLyn Service Line:High-Speed Web Systems
lowSpeed, Assets & Carbon Footprint

Your pages are not cached, so every visit is rebuilt from scratch

OBSERVED EVIDENCE:No Cache-Control header is present.
Commercial Impact

Caching lets repeat visitors and the CDN reuse work already done. Without it your server does the full job for every single request, which costs you both speed and hosting capacity on your busiest days.

Recommended Fix

Set appropriate Cache-Control headers — long-lived for assets with versioned filenames, short with revalidation for HTML.

HarLyn Service Line:High-Speed Web Systems
lowSpeed, Assets & Carbon Footprint

Your images use older, heavier formats

OBSERVED EVIDENCE:4 images are served as JPEG or PNG rather than a modern format such as WebP or AVIF.
Commercial Impact

Modern image formats are typically 25-50% smaller at the same visual quality. On an image-heavy page this is often the single largest saving available.

Recommended Fix

Convert images to WebP or AVIF with a fallback, or move to an image CDN that does the conversion automatically per visitor.

HarLyn Service Line:High-Speed Web Systems
lowSearch Engine Visibility

Google ranks your domain for 4 search queries in Kenya

OBSERVED EVIDENCE:DataForSEO live telemetry measures ~3 monthly organic visitors from Google (Kenya), with an estimated Google Ads replacement value of $0/mo.
Commercial Impact

Organic search traffic is high-intent compounding revenue. Knowing which keywords drive inbound interest allows you to protect your highest-converting search positions against aggressive competitors.

Recommended Fix

Strengthen internal linking to your top-ranking pages and publish dedicated landing pages for second-page keywords (positions 11-20) to push them into the top 3.

HarLyn Service Line:High-Speed Web Systems
infoEmail Security & DeliverabilityQuick Win (< 1hr)

No TLS-RPT reporting configured for mail transport security

OBSERVED EVIDENCE:We looked up _smtp._tls.silverwoodmedicalcentre.com and found no TLS-RPT record.
Commercial Impact

TLS-RPT (RFC 8460) works alongside MTA-STS to send you daily diagnostic reports on inbound email delivery failures and TLS decryption attempts.

Recommended Fix

Publish a TXT record at _smtp._tls.silverwoodmedicalcentre.com with "v=TLSRPTv1; rua=mailto:tls-reports@silverwoodmedicalcentre.com".

HarLyn Service Line:Cyber Defense & Compliance
Technical Reference
infoWebsite & Cloud SecurityQuick Win (< 1hr)

No security.txt — researchers have no way to report a problem to you

OBSERVED EVIDENCE:We found no file at /.well-known/security.txt.
Commercial Impact

When someone discovers a vulnerability in your site, security.txt tells them where to report it. Without one, findings tend to go unreported or get posted publicly instead of coming to you first.

Recommended Fix

Publish a short /.well-known/security.txt listing a contact address and a preferred language.

HarLyn Service Line:Cyber Defense & Compliance
Technical Reference
infoAI Workflow & Agent Readiness

Your booking process still needs a person in the middle

OBSERVED EVIDENCE:Your site invites visitors to book a consultation, appointment or demo.
Commercial Impact

Every booking arranged by exchanging messages costs staff time and loses the people who did not want to wait for a reply. Automated scheduling with confirmation and reminders removes both the delay and the no-shows.

Recommended Fix

Connect a scheduling system directly to your team calendars with automated confirmations and reminders by email and WhatsApp.

HarLyn Service Line:Workflow Automation
HarLyn Engagement Roadmap

How HarLyn Resolves These Findings

Every issue and opportunity above maps directly to one of our four core offerings. Our 48-hour diagnostic sprint delivers the exact technical remediation blueprint, zero-trust implementation, and AI discovery foundation.

1. Cyber Defense & Compliance

Email Authentication & Zero-Trust Hardening

Full DMARC p=reject rollout, SPF & DKIM alignment, MTA-STS mail encryption, and compliance auditing under Kenya Data Protection Act 2019.

2. High-Speed Web Systems

SSR Architecture & Edge Performance

Eliminating client-rendering bottlenecks, instant page transitions, CDN caching, security header enforcement, and carbon footprint reduction.

3. AI Search & AEO Integration

Entity Schema & LLM Discovery

Structured JSON-LD schema (Organization, LocalBusiness, FAQ), /llms.txt deployment, and unlocking crawl access for ChatGPT, Claude, and Perplexity.

4. AI Automation & Workflows

Self-Healing Lead & Inbound Pipelines

Instant quote automation, Telegram/WhatsApp alert routing, and autonomous client acquisition pipelines built with n8n and TypeScript.

Ready to resolve these items?
Fixed fee · 48-hour turnaround · Handled directly by Harrison & Nazline
Claim 48-Hour Assessment (KES 35,000 / $280)