This is a real SDG audit, published as a case-study sample — the Horizon site as first built, before fixes. Read the full story →
Website audit — Avalon Beach NSW 2107

Audit findings for Horizon Football Festival 2026.

horizonfootballfestival.com.au

Horizon Football Festival 2026 is a four-day youth football tournament hosted by Manly United FC at Cromer Park, Sydney, for players aged U9 to U13.

Homepage of horizonfootballfestival.com.au as captured during this audit.
2High13Medium1Low-med21Low

Before we get into the findings — here's who we think you are

Everything below is drawn from your homepage and about page as we found them today. If we've got something wrong, tell us and we'll correct it.

What you do Horizon Football Festival 2026 is a four-day youth football tournament hosted by Manly United FC at Cromer Park on Sydney's Northern Beaches, running 2–5 October 2026. It is open to clubs, academies, and individual teams, with six age groups across mixed and girls divisions from U9 to U13.

Who you are The festival positions itself around player development and competitive experience, describing its aim as giving players aged U9–U13 the opportunity to "test themselves, embrace new challenges, and create lasting memories" in a structured tournament environment.

Where we think you sit In our experience, event and festival sites like this one carry a particular digital burden: they need to convert a visiting coach or team manager in a single session, often months before the event date, and then hold that registration intent across a long lead time. Technical or trust issues that might be tolerable on a general brochure site tend to have a more direct cost here, because the registration window is finite.

With that in mind, here's what we found. Each finding is laid out the same way — what's happening, who gets hurt if it isn't addressed, why it's commonly missed, what it costs you if it goes wrong, and how we'd fix it. Technical detail is tucked behind a toggle for anyone who wants to see the working.

Findings at a glance

  1. Security

  2. 01
    Browsers don't remember to keep your site on HTTPS

    What's happening Your site has a setting that tells browsers to always use the encrypted version — but it expires so quickly that browsers forget the instruction within weeks.

    Why it matters During the gap, a visitor on a compromised network like a café's Wi-Fi could be quietly downgraded to an unencrypted connection, where login details or form data travel in plain text and can be intercepted.

    The fix We'd extend the setting to a one-year window, add the right supporting directives, and submit your domain to the browser preload list so the protection applies before a visitor even arrives. About 30 minutes of work.

    Read full finding →
    High
  3. 02
    Your DMARC is in monitor-only mode — it watches but doesn't block

    What's happening Your DMARC record is published but set to monitor-only mode — it collects reports about mail claiming to be from your domain, but tells receivers to do nothing about suspicious messages.

    Why it matters Forged emails carrying your domain name still reach your customers' inboxes, and because a policy technically exists, neither you nor your provider is likely to treat it as an open gap.

    The fix We review the reports already accumulated, confirm legitimate senders pass correctly, then advance the policy to quarantine and eventually reject in a staged transition — two to four weeks of review, then a single DNS edit.

    Read full finding →
    Medium
  4. 03
    Your contact email is on a different domain than your website

    What's happening Every contact address on the site uses a different domain from the one visitors just landed on, so the email and the website don't visibly belong together. Sites with this pattern tend to see a small but real drop in first-contact enquiries from cautious registrants. Adding a matching email address and forwarding it to the existing inbox is about a 30-minute DNS and mailbox change.

    Read full finding →
    Medium
  5. 04
    Your site can't stop malicious code from running if any injection slips through

    What's happening Without a Content-Security-Policy, your visitors' browsers will load and run anything your page references — from any source, without restriction.

    Why it matters If an attacker injects content through a plugin vulnerability or a hijacked third-party script, there's nothing telling your customers' browsers to refuse it — credentials, payment details, and form data can be taken silently.

    The fix We configure a policy listing every legitimate source your site loads from and instructing browsers to block everything else — a few hours to build, a week or two in report-only mode to confirm nothing legitimate is caught, then enforcement.

    Read full finding →
    Medium
  6. 05
    External scripts on your site can be tampered with mid-flight

    What's happening A script loaded from an external CDN has no tamper-check attached. If that CDN were compromised, the altered script would run unchallenged. Sites in this configuration typically face indirect risk — low probability but high consequence. Adding a single integrity attribute to the script tag closes the gap in under 30 minutes.

    Read full finding →
    Medium
  7. 06
    Your pages can be embedded inside another site without permission

    What's happening Without a frame-blocking header, your website can be embedded invisibly inside another site, with a transparent overlay sitting on top capturing your visitors' clicks and redirecting their actions.

    Why it matters A logged-in visitor thinks they're clicking a button on your site; they're actually triggering something else entirely on their authenticated session — payment confirmations, account changes, and bookings are the common targets.

    The fix We add a two-line configuration change telling browsers to refuse to render your site inside another site's iframe — under 30 minutes, and your own site embedding its own pages still works fine.

    Read full finding →
    Medium
  8. 07
    Browsers might guess your file types wrong and run them as scripts

    What's happening Browsers are designed to guess a file's type if the server's labelling seems off — without a header turning off that guessing, a browser could treat an uploaded image or document as something executable.

    Why it matters Visitors on any site with user uploads are most exposed: if an attacker can upload a file that the browser misreads as a script, it runs in the visitor's browser without warning.

    The fix We add a single header line telling every browser to trust only what your server declares — no guessing, no effect on legitimate traffic, done as part of the security-headers pass we run on all managed clients.

    Read full finding →
    Medium
  9. 08
    Your DMARC reports are being sent to a broken address — you'll never see them

    What's happening Your DMARC record includes a reporting address, but it's formatted incorrectly — mail receivers that follow the standard are required to discard addresses they can't parse, so none of the spoofing reports are arriving anywhere.

    Why it matters You're flying blind: there's no data showing whether your domain is being used in fraud attempts or whether your current senders are passing authentication correctly.

    The fix We correct the reporting address to a valid format — a one-line DNS change, under five minutes, with reports starting to arrive from major receivers within 24 hours.

    Read full finding →
    Medium
  10. 09
    Visitor URLs leak in full to every external site you link to

    What's happening Every time a visitor clicks an external link from your site, their browser sends the full URL of your page — including any query strings, session tokens, or password-reset links — to whoever owns the destination site.

    Why it matters Your visitors' sensitive URL parameters end up in third-party analytics and advertising logs you don't control; if a password-reset link appears in an external server's logs, that's a privacy disclosure under the Australian Privacy Act regardless of whether anyone misuses it.

    The fix We set a single Referrer-Policy header that passes your domain name to external sites — enough for their analytics — without including page paths, tokens, or query strings. Minutes to configure.

    Read full finding →
    Medium
  11. 10
    Third-party scripts can silently access camera, microphone, or location

    What's happening Without a Permissions-Policy header, every third-party script your site loads — analytics tools, chat widgets, advertising pixels — inherits the ability to request browser features like camera, microphone, and geolocation, with no site-level instruction limiting them.

    Why it matters If any one of those scripts is ever compromised or changes behaviour, your visitor sees an unexpected browser permission prompt and has no way to know it isn't coming from you — and many will simply close the tab and not return.

    The fix We set a Permissions-Policy header explicitly denying every browser feature your site doesn't use — a one-time configuration as part of the security-headers pass, with specific features enabled only if you genuinely add them later.

    Read full finding →
    Medium
  12. 11

    3 smaller items worth knowing about in Security

    Each of these is true and worth fixing eventually, but none is urgent on its own. We've grouped them so they don't drown out the findings that are. Click any one to read the full detail.

    Show the 3 items
    3 × low
  13. Compliance & Privacy

  14. 14
    No privacy policy published anywhere on the site

    What's happening The site invites team registrations and contact enquiries — both of which collect personal information — but publishes no privacy policy anywhere on the page or in the footer. Under the Privacy Act 1988 and the Australian Privacy Principles, organisations collecting personal data are required to make a privacy policy readily accessible. Sites in this position tend to face regulatory exposure if a complaint is filed or a data incident occurs, with no documented policy to demonstrate compliance. Publishing a clear privacy policy page and linking it from the footer is a straightforward fix — typically a few hours of drafting and one small footer code change.

    Read full finding →
    High
  15. 15
    Your cookie banner sets tracking cookies before the visitor agrees

    What's happening The site accepts team registrations but publishes no Terms & Conditions. Without agreed terms, cancellation and refund rules tend to be unenforceable if a dispute reaches a tribunal. A single linked T&C page covering entry fees and liability closes the gap — typically a 1–2 hour task.

    Read full finding →
    Medium
  16. 16
    ABN not visible anywhere on the site

    What's happening Your Australian Business Number isn't visible on the website. An ABN displayed in the footer is a trust signal, a B2B expectation, and in some industries a legal requirement.

    Why it matters Visitors verifying your business legitimacy can look up an ABN on the ABR; its absence is one less verification path.

    The fix We add 'ABN 12 345 678 901' to the footer of every page. Five minutes.

    Read full finding →
    Low
  17. 17
    No mention of public liability insurance

    What's happening No mention of public liability insurance on the site. For trades, cleaners, personal trainers, mobile services — any business that visits customer premises — public liability insurance is something customers actively check for.

    Why it matters Particularly costly for commercial / B2B work where contracts often require insurance confirmation upfront.

    The fix If you carry it, we add 'Public liability insured to $Nm' to the footer. If you don't and your business should, that's a separate conversation.

    Read full finding →
    Low
  18. Performance

  19. 18
    Your pages jump around as they load

    What's happening A script loads synchronously in the page header, forcing the browser to pause before displaying anything to the visitor. Sites with this pattern typically score lower on Core Web Vitals, affecting search ranking. Adding a single `defer` attribute to the script tag fixes it in under five minutes.

    ▶ Watch as the page loads — elements jump when images and fonts settle. Captured at throttled 1.5 Mbps to show the shift at human speed. Read full finding →
    Medium
  20. 19
    Your pages jump around as images load

    What's happening Your images don't tell the browser how much space to hold for them while they download, so as each image loads the page content below it jumps downward.

    Why it matters Visitors who go to tap a button or read a line at the wrong moment end up tapping the wrong thing or losing their place — and Google measures this shifting behaviour directly as a ranking signal.

    The fix We add the correct width and height values to every image element so the browser reserves the right space before the image arrives — a systematic pass across the site, typically a few hours.

    ▶ The image jump is visible mid-load — the browser had no width or height to reserve space, so layout shifts when the image arrives. Read full finding →
    Low–Med
  21. 20

    4 smaller items worth knowing about in Performance

    Each of these is true and worth fixing eventually, but none is urgent on its own. We've grouped them so they don't drown out the findings that are. Click any one to read the full detail.

    Show the 4 items
    4 × low
  22. Accessibility

  23. 24
    Decorative images have `alt=""`

    What's happening Screen readers use landmark elements like <main> to let users skip straight to the content — none is present here, so assistive technology users must navigate past every menu item manually. This tends to create real friction for visitors with disabilities and can attract DDA-related complaints for event sites collecting registrations. Adding a <main> wrapper around the primary content resolves it in about 10 minutes.

    Read full finding →
    Medium
  24. 25
    Image `alt` text descriptive (not "image", "IMG_4100")

    What's happening Some images on your site have the description field filled in, but what's there isn't useful — things like 'image', 'photo', or a camera filename — and a screen reader reads that text aloud word for word.

    Why it matters Visitors using assistive technology hear filler that wastes their time and tells them nothing; Google's systems also recognise generic or keyword-stuffed alt text and get no useful signal from it.

    The fix We'd review every image's alt text and rewrite anything generic or unhelpful into a plain, honest description of what the image actually shows — editorial work rather than technical, and a few hours across a typical site.

    Read full finding →
    Low
  25. 26
    Moderate accessibility violations detected by axe

    What's happening The scan found moderate accessibility issues — duplicate link text pointing to different destinations, slightly uncomfortable contrast, and heading structure that's grown inconsistent over time.

    Why it matters Visitors using assistive technology feel the cumulative friction, and the site reads in any formal audit as one where accessibility was added as an afterthought rather than built in.

    The fix We'd fold these into the same pass as the critical and serious fixes — the same CSS and copy-level work, just extended slightly. Usually no meaningful extra time once the bigger items are done.

    Read full finding →
    Low
  26. SEO & content

  27. 27
    Google has indexed fewer of your pages than your sitemap declares

    What's happening Google currently shows fewer of your pages in search than your sitemap says exist — pages that aren't in Google's index can't bring in customers, no matter how good they are.

    Why it matters The most common causes are accidental noindex tags, mis-configured robots.txt rules, or duplicate-content collapse — all invisible to you unless someone checks specifically.

    The fix We diagnose the cause via Google Search Console, fix the underlying block, then request re-crawl. About 1-2 hours of diagnostic plus per-page fixes.

    Read full finding →
    Low
  28. Trust, brand & UX

  29. 28
    No phone number visible on the homepage

    What's happening The site lists only an email address for all enquiries — there is no phone number anywhere on the page. Coaches or administrators who prefer a quick call before committing a team have no direct option, which typically adds friction to the sign-up decision. Adding a single phone number to the footer and contact section takes under 30 minutes.

    Read full finding →
    Medium
  30. 29

    6 smaller items worth knowing about in Trust, brand & UX

    Each of these is true and worth fixing eventually, but none is urgent on its own. We've grouped them so they don't drown out the findings that are. Click any one to read the full detail.

    Show the 6 items
    6 × low
  31. Mobile & platforms

  32. 35
    Your site doesn't work well on phones

    What's happening Your site has several mobile usability problems — touch targets too small to tap reliably, content spilling off the edge of the screen, or text requiring pinching to read.

    Why it matters The visitor trying to tap your contact button on their phone gives up and goes back to search results; Google also uses mobile usability as a ranking signal, so the problem reduces how many visitors arrive in the first place.

    The fix We'd fix the specific issues identified — button sizes, viewport configuration, body text size — as a packaged half-day of targeted mobile-foundations work.

    Read full finding →
    Low
  33. 36
    Horizontal scroll at tablet viewport (rendered)

    What's happening On a tablet or a phone held sideways, your site spills past the edge of the screen and forces visitors to scroll sideways to read it.

    Why it matters Tablet visitors — often the ones spending the most time considering a purchase — hit a broken layout and quietly lose confidence in the business behind it.

    The fix We'd track down the element causing the overflow — usually one oversized image or a fixed-width component — and correct the CSS so every screen size fits cleanly. One to two hours of work.

    Read full finding →
    Low
  34. History & continuity

  35. 37
    Cloudflare or CDN presence (DDoS resilience)

    What's happening Your website is served directly from your hosting server with no buffer layer in front of it — so every request, legitimate or otherwise, hits the server directly.

    Why it matters If traffic spikes during a promotion, a press mention, or a deliberate flood of fake requests, your server can tip over and your site goes offline precisely when the most people are trying to reach it.

    The fix We'd route your domain through Cloudflare, which sits between the internet and your hosting server and filters traffic before it arrives; a one-off setup of a few hours, with the change live within a day.

    Read full finding →
    Low

You've seen what's wrong. Here's what happens next.

SDG fixes everything you just saw, then keeps watch so it doesn't come back. This audit is the starting line — most of our clients stay with us for the ongoing build, content, SEO, and the maintenance that stops audits like this from being needed again.

What you get with every engagement

  • Every finding addressed within scope, with verification screenshots and a written change log
  • A PDF version of this audit, formatted for your records and any insurer / compliance request
  • A 30-minute planning call to walk through the work, gather access, and agree the order
  • A written project plan with delivery dates against each finding category
  • Any unfixed findings get a free re-audit at 12 months — we don't move on until they're closed

Tailored to your site, not a stock package. The prices below are calculated from the specific issues we found on your site — not a generic menu. A cleaner site pays less; a site with more to address pays more. You’re paying for the actual work, not a tier ceiling.

We don’t proceed without a conversation. Whichever tier you pick, the engagement starts with a phone call — fifteen minutes, no pitch. The audit puts the findings in front of you; the call puts a face to the name. We’d genuinely rather meet over a coffee in Avalon if you’re local — either way, no work begins until we’ve talked.

Pick the tier that suits your appetite

Your audit found 2 high-severity issues across compliance, security, plus performance and polish items that materially affect how your site performs. Surf addresses the lot end-to-end.

Beach

The must-fixes — compliance, security, and anything legal or financial.

$990
+ GST, fixed quote
Findings
2 of the issues above
Covers
compliance, security
Get started →

Ocean

Everything in Surf plus every low-severity polish item — 26 hygiene fixes thrown in for free.

$2,690
+ GST, fixed quote
Findings
16 priced findings + 26 hygiene fixes thrown in
Covers
SEO + schema, accessibility, brand + social, compliance, continuity, email, other, performance, security, trust signals, vulnerabilities
Get started →

Prices are calculated from the actual findings on horizonfootballfestival.com.au at a fixed rate of $250 + GST per remediation unit. A unit reflects the full engagement effort — work, verification, customer handoff — not just delivery time. Quoted prices are fixed once accepted; no scope creep.

What this audit does not cover

A complete review of a business needs more than a public-surface audit can deliver. The lines below set out — explicitly — the questions this report cannot answer, so you know where its boundaries are.

How this audit was run

Run on
2026-06-17
How we looked
From outside, as a normal visitor would. We didn't log in, didn't submit any forms, didn't try to break anything.
What kind of site
Treated as a brochure site — we focused on the things that matter for this kind of business (and skipped 5 checks that don't apply).
What we checked
52 things across your site. 37 came up as worth your attention. 0 were fine. 0 couldn't be checked from the outside.
Our promise
Everything above is something we observed, double-checked, and can show you exactly how to verify yourself.