White Label
https://whitelabel.org · 50/92 checks passed · not_for_profit
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 25/37 (11 failed) |
| Level 2 — Enhanced | 10/27 (11 failed) |
| Level 3 — Advanced | 1/10 (8 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 8/13 |
| Accountability | 1/5 |
| AI & Automation | 3/8 |
| Interoperability | 2/3 |
| Privacy | 10/16 |
| Provenance | 2/2 |
| Security | 5/11 |
| Transparency | 5/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- 2 WCAG 2.1 Level A violations reported by axe-core: link-name, scrollable-region-focusable.
- 2 WCAG 2.1 Level A violations reported by axe-core: link-name, scrollable-region-focusable.
- Heading hierarchy issues: h2 -> h4 (skipped h3).
AI & Automation
-
policy_exists: The page only mentions AI as a personal interest (Claude Code) but contains no AI use policy or statement.
Fix: Add a brief AI policy section stating whether and how AI is used in creating site content.
-
scope_clear: There is no explanation of what AI is used for on the site, only a passing mention of the author's interest in AI.
Fix: Clearly describe the scope of AI usage, such as whether AI assists in writing posts, coding, or is not used at all in site content.
- Not found at any of: /ai-policy, /ai.
Privacy
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://whitelabel.org
- x-frame-options: SAMEORIGIN
- referrer-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
- Not found at any of: /contact, /contact-us.
FAIL
Contact form present
- Not found at any of: /contact, /contact-us.
SKIPPED
Contact information present
Skipped: Target page not found in captured content
Level 2 — Enhanced
Accessibility
Accountability
-
response_timeframe: The About page only provides contact methods (LinkedIn, email) with no mention of when a response can be expected.
Fix: Add a statement near the Contact section indicating a target response window (e.g. 'I aim to reply within 5 business days').
-
specific: Since no timeframe is published at all, there is no specific day-based commitment to evaluate.
Fix: Publish a concrete numeric timeframe in days (e.g. 'within 7 days') rather than vague language.
-
process_exists: The page offers only generic contact options and does not describe any complaints or feedback process.
Fix: Add a short 'Complaints & Feedback' section outlining how readers can raise concerns and what will happen next.
-
steps_clear: Because no complaints process is documented, there are no steps for users to follow.
Fix: Provide numbered steps (how to submit, what information to include, how it will be acknowledged and resolved) for raising a complaint.
SKIPPED
Clear appeals process
Skipped: Target page not found in captured content
AI & Automation
-
detailed_scope: No detailed scope of AI use is provided beyond the author noting Claude Code is 'winning me over'.
Fix: Publish a dedicated AI policy page detailing specific use cases, tools, and contexts where AI is applied.
-
limitations: The page does not acknowledge any limitations of AI systems.
Fix: Include a statement acknowledging known AI limitations such as hallucinations, bias, or factual errors.
-
safeguards: No safeguards or quality-control measures for AI-generated content are described.
Fix: Describe safeguards such as human review, fact-checking, or disclosure labels applied to AI-assisted content.
-
marking_policy: The About page mentions AI interest (Claude Code) but provides no policy for marking AI-assisted content.
Fix: Add a clear statement describing how and when AI-assisted content is labeled on the site.
-
consistent: Without a stated policy, there is no evidence of consistent AI content marking on the page.
Fix: Apply a consistent label or disclosure (e.g., an 'AI-assisted' tag) to any post drafted or edited with AI tools.
-
oversight_exists: The page does not document any human oversight process for AI outputs.
Fix: Add a short note explaining that a human reviews and approves any AI-generated content before publication.
-
review_process: No review or approval workflow for AI content is described on the About page.
Fix: Describe the specific review steps (e.g., fact-checking, editing, final sign-off) applied to AI-assisted posts.
Interoperability
Privacy
-
banner_present: The page content shows no cookie or consent banner anywhere on the visible page.
Fix: Add a visible cookie/consent banner on first visit that allows users to accept or reject non-essential cookies.
-
partner_sharing_mentioned: No banner or on-page consent copy is present, so third-party partner data sharing is not disclosed.
Fix: Include clear language in the consent banner and privacy policy disclosing any sharing of data with third-party partners.
-
partner_count_specific: No partner sharing is disclosed and therefore no specific numeric partner count is stated on the page.
Fix: If partners are used, state the exact number of third-party partners (e.g., 'We share data with 12 partners') in the consent banner.
SKIPPED
Human-readable privacy policy
Skipped: Target page not found in captured content
SKIPPED
Plain language data practices
Skipped: Target page not found in captured content
Skipped: Target page not found in captured content
SKIPPED
Published data retention periods
Skipped: Target page not found in captured content
Skipped: Target page not found in captured content
Provenance
Security
- security.txt not published.
Transparency
-
role_clear: While described as the author/blogger, there is no explicit statement of his role or authority regarding enquiries (e.g., owner, editor, responsible party).
Fix: Add a short line clarifying his role, e.g., 'Stefan Magdalinski, owner and sole author of whitelabel.org, handles all enquiries.'
-
detail: The disclosure 'No tracking. No ads. Just words.' lacks meaningful detail such as hosting costs, self-funding categories, or percentages.
Fix: Add a brief note specifying how the site is supported (e.g., 'Self-funded by the author; hosting paid personally') to provide categorical detail.
-
complete: The disclosure only rules out ads and tracking but does not address other potential streams like affiliate links, donations, or sponsorships of linked projects.
Fix: Expand the disclosure to explicitly address all potential funding streams (affiliates, donations, sponsored content, employer relationships) to confirm none exist.
-
governance_exists: The About page describes the author's interests and past projects but does not outline any governance or editorial structure for the site.
Fix: Add a short section describing how content is reviewed, edited, and published, even if it is a personal blog run solely by the author.
-
roles_clear: Only Stefan Magdalinski is named as the author, with no identification of editorial, moderation, or other responsibilities.
Fix: List the key roles (author, editor, maintainer, contact) and clarify who is responsible for each, even if one person fills them all.
-
annual_statement: The page mentions 'No tracking. No ads.' but provides no evidence of a periodic or annual review of data practices.
Fix: Add a brief privacy/data practices statement that notes when it was last reviewed and commit to reviewing it annually.
-
dated: The 'No tracking. No ads.' statement is not dated or versioned, so readers cannot tell when it was last affirmed.
Fix: Include a 'last updated' date or version number alongside the data practices statement.
Level 3 — Advanced
Accessibility
-
statement_exists: The About page contains a personal bio and links but no dedicated accessibility statement.
Fix: Add a dedicated accessibility statement page describing the site's conformance to standards such as WCAG 2.1 AA.
-
known_issues: There is no accessibility statement and therefore no acknowledgment of known accessibility issues or limitations.
Fix: In the accessibility statement, list any known accessibility barriers such as unlabeled links or archived content not meeting standards.
-
remediation_timeline: No accessibility statement or timeline for fixing accessibility issues is present on the page.
Fix: Include a target date or ongoing commitment for remediating identified accessibility issues in the statement.
-
feedback_channel: While contact options via LinkedIn and email exist, there is no accessibility-specific feedback mechanism or response commitment.
Fix: Provide a dedicated accessibility feedback channel and state a response time commitment, e.g., replying within five business days.
Accountability
-
policy_exists: The About page contains no published moderation policy for comments or user contributions.
Fix: Add a dedicated moderation policy page (or section) outlining rules for any user-submitted content.
-
criteria_clear: No moderation criteria are stated anywhere on the page.
Fix: Publish clear criteria describing what content is permitted or removed, such as prohibitions on spam, harassment, or illegal content.
-
enforcement: The page does not explain any enforcement process for moderation decisions.
Fix: Document how moderation is enforced, including who reviews content, response timelines, and any appeal or contact path.
Interoperability
- Not found at: /status
Security
-
plan_exists: The About page is a personal blog bio with no published incident response plan or policy anywhere on the page.
Fix: Publish a dedicated incident response policy page describing how security incidents are detected, handled, and remediated.
-
notification_commitment: The page contains no commitment to publicly notify users of significant security incidents.
Fix: Add an explicit statement committing to public notification of any significant security or data incidents.
-
timeframe: No disclosure timeframe for notifying affected users is stated anywhere on the page.
Fix: Specify a concrete disclosure timeframe (e.g., notifying affected users within 72 hours of discovering an incident).
Skipped: Target page not found in captured content
Transparency
-
open_source: While a GitHub profile is linked generally under 'Elsewhere', there is no indication that this site's source code is publicly available.
Fix: Publish the site's source code in a public repository and link to it directly from the about page.
-
tech_docs: No technical documentation about the site's stack, build, or architecture is published on or linked from the about page.
Fix: Add a brief colophon or /tech page describing the site's stack and link to any associated documentation.
Responsibility to the Future
-
disclosure_exists: The About page contains no published environmental impact or sustainability disclosure, only a note about no tracking and no ads.
Fix: Add a dedicated sustainability or environmental impact statement describing the site's ecological footprint and any mitigation measures.
-
specific_metrics: The page provides no specific figures for carbon emissions, energy use, or other environmental metrics.
Fix: Include quantified metrics such as grams of CO2 per page view or annual energy consumption in a published disclosure.
-
hosting_disclosure: There is no information about the carbon or energy profile of the hosting infrastructure anywhere on the page.
Fix: Disclose the hosting provider and whether it uses renewable or low-carbon energy, ideally with supporting figures.
-
plan_exists: The About page describes the author's interests and history but contains no published plan for what happens if the site or its owner fails or exits.
Fix: Add a short succession or continuity statement describing what will happen to the site if the owner can no longer maintain it.
-
data_and_content_fate: The page mentions content was revived from the Internet Archive in 2025 but does not state what will happen to user data or published content in the future.
Fix: Document the intended fate of content and any user data, for example committing to keep archives available or releasing them under an open license.
-
custodians_or_mirrors: The page references the Internet Archive as a past revival source but does not identify any designated custodian, mirror, or archive partner responsible for the site going forward.
Fix: Name a custodian or archive partner (e.g., an ongoing Internet Archive mirror or a trusted individual) who would preserve the content if the site ends.
-
policy_exists: The page is a personal blog's 'About' section with no published policy on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy page if the site represents an organization with workers.
-
specific_commitments: There are no specific commitments regarding pay, hours, mental health, or benefits anywhere on the page.
Fix: Add concrete, measurable commitments covering pay, working hours, mental health support, and benefits to a worker wellbeing policy.
-
accountability: The page identifies no person, role, or body accountable for overseeing worker conditions.
Fix: Name a responsible role or oversight body and describe how worker conditions are monitored and reviewed.