Skip to content
https://autonews.com

Compliance

· 13 checks — WCAG, consent & privacy, language, viewport, cookie inventory, and legal pages rolled into one auditable list.
SCORE
82
GRADE
B
FIX
1
REVIEW
2
PASS
7
INFO
3
Checks
13
7 PASS 2 REVIEW 1 FIX
F
Third-Party Trackers
Action
21 trackers detected
FIX
21 trackers detected
Info::
21 third-party trackers detected
Found 12 analytics, 6 advertising, 1 marketing, 2 tag manager trackers.
Got: 21 trackers
Warning::
6 advertising/retargeting trackers detected
Advertising trackers collect user data for ad targeting. Under GDPR, these typically require explicit consent.
Warning::
Trackers detected but no cookie policy found
This page loads 21 trackers but no cookie policy was detected. GDPR requires disclosure when using tracking cookies.
Warning::
Trackers detected but no privacy policy found
Most data protection regulations require a privacy policy when collecting user data via trackers.
Warning::
Session replay tool detected: Hotjar
Session replay tools record user interactions. These require clear disclosure and often explicit consent under GDPR.
Warning::
Session replay tool detected: Microsoft Clarity
Session replay tools record user interactions. These require clear disclosure and often explicit consent under GDPR.
B
Compliance Badges
1 compliance badge(s) detected
REVIEW
1 compliance badge(s) detected
Info::
TRUSTe / TrustArc badge detected
Found via link URL: 'https://preferences-mgr.truste.com/?pid=crain01&aid=crain01&type=crain&site=crain.com&action=notice&country=us&locale=en&behavior=implied&privacypolicylink=http%253a%252f%252fwww.autonews.com%252fsection%252fprivacy-policy&from=http%3a//consent.trustarc.com/'. Note: the presence of a badge does not verify the certification is current or valid.
Got: Detected by: link URL
SOC 2
ISO 27001
PCI DSS
GDPR Certified
HIPAA Compliant
Better Business Bureau
TRUSTe / TrustArc detected

Detected by: link URL

Evidence: https://preferences-mgr.truste.com/?pid=crain01&aid=crain01&type=crain&site=crain.com&action=notice&country=us&locale=en&behavior=implied&privacypolicylink=http%253a%252f%252fwww.autonews.com%252fsection%252fprivacy-policy&from=http%3a//consent.trustarc.com/

Privacy Shield
McAfee SECURE / TrustedSite
Norton Secured
Badge detection is based on image alt text, link URLs, and page content. Detection does not verify that certifications are current or valid.
A+
WCAG Compliance
No testable criteria
PASS
No testable criteria
Level A
Level AA

0

Passed

0

Failed

0

Partial

0

Manual review

0

Not tested

Key accessibility barriers

Images without alt text

Screen reader users cannot understand 2 image(s)

~8M screen reader users in the US

Form controls without labels

Assistive technology cannot identify 1 input(s)

Screen reader and voice-control users

Automated testing covers ~30–40% of WCAG criteria. Manual review is recommended for full conformance.

Full WCAG 2.1 AA compliance checklist — paste into a client deliverable or ticket

A
Language & i18n
Lang attribute present
PASS
Lang attribute present
Info::
<html lang> attribute is present
Info::
<html lang> value is valid
Info::
No Content-Language HTTP header
Info::
Language signals are inconsistent
The <html lang> attribute and Content-Language header should agree.
Page Language DetectedContent-Language Header Consistent No

The <html lang> attribute and Content-Language header should agree.

Why this matters

<html lang>, Content-Language, or og:locale disagree — pick one source of truth and align the others.

Learn more

Browsers and assistive tech use different sources for language. When they disagree, behavior is undefined: some pronounce by <html lang>, some by Content-Language. Decide on the canonical language for the page and set all signals to match.

Source: WCAG 2.1 SC 3.1.1

A+
Readability & Typography
Font sizes and tap targets checked
PASS
Font sizes and tap targets checked
A+
Viewport Configuration
Viewport properly configured
PASS
Viewport properly configured
Info::
Viewport meta tag is present
Info::
width=device-width is set
Info::
User zooming is allowed
Viewport Configuration Good
Content
width=device-width, initial-scale=1
width=device-width

Responsive layout enabled

initial-scale=1

Correct initial zoom level

User zooming allowed

Accessibility-friendly — users can zoom

Regulatory Indicators
2 regulatory indicator(s) detected
INFO
2 regulatory indicator(s) detected
Info::
This is a technical scan, not a legal assessment
BeaverCheck detects technical indicators that may suggest regulatory relevance. This is not a compliance audit and should not be relied upon for legal decisions. Consult qualified legal counsel for compliance assessments.
Info::
GDPR indicators detected (strong confidence)
Indicators suggesting GDPR may be relevant: Consent management platform detected: trustarc.com; Privacy policy page found. EU General Data Protection Regulation — governs collection and processing of personal data of EU residents.
Got: 2 indicators: Consent management platform detected: trustarc.com, Privacy policy page found
Info::
PCI-DSS indicators detected (moderate confidence)
Indicators suggesting PCI-DSS may be relevant: Payment processor detected: js.stripe.com. Payment Card Industry Data Security Standard — applies to organizations handling credit card data.
Got: 1 indicators: Payment processor detected: js.stripe.com

This is a technical scan, not a legal assessment.

BeaverCheck detects technical indicators that may suggest regulatory relevance. This should not be relied upon for legal decisions. Consult qualified legal counsel.

GDPR Strong

EU General Data Protection Regulation — governs collection and processing of personal data of EU residents.

Indicators detected

  • Consent management platform detected: trustarc.com
  • Privacy policy page found
PCI-DSS Moderate

Payment Card Industry Data Security Standard — applies to organizations handling credit card data.

Indicators detected

  • Payment processor detected: js.stripe.com
Third-Party Data Sharing
7 third-party service(s) detected
INFO
7 third-party service(s) detected
Info::
Data inventory for transparency purposes
This inventory identifies third-party services that receive data from your site visitors. Under regulations like GDPR (Article 30), maintaining records of data processing activities is commonly considered a best practice. This automated scan provides a starting point — it may not capture all data flows.
Info::
7 third-party services across 6 categories
7 third-party services detected across 6 categories: Analytics (1), Advertising (2), Session Recording (1), Payment (1), Error Tracking (1), Security (1). Each of these services receives some user data from your site visitors.
Info::
Google Analytics (Analytics)
Detected via script URL. Typically collects: Page views, User behavior, Demographics, Device info, IP address. Privacy policy: https://policies.google.com/privacy. Data Processing Agreement available.
Got: Category: Analytics | Data types: Page views, User behavior, Demographics, Device info, IP address
Info::
Facebook Pixel (Advertising)
Detected via script URL. Typically collects: Page views, Conversions, User behavior, Ad targeting. Privacy policy: https://www.facebook.com/privacy/policy. Data Processing Agreement available.
Got: Category: Advertising | Data types: Page views, Conversions, User behavior, Ad targeting
Info::
Hotjar (Session Recording)
Detected via script URL. Typically collects: Session recordings, Heatmaps, Click patterns, Form interactions. Privacy policy: https://www.hotjar.com/privacy/. Data Processing Agreement available.
Got: Category: Session Recording | Data types: Session recordings, Heatmaps, Click patterns, Form interactions
Info::
Stripe (Payment)
Detected via script URL. Typically collects: Payment card data (PCI-scoped), Transaction details. Privacy policy: https://stripe.com/privacy. Data Processing Agreement available.
Got: Category: Payment | Data types: Payment card data (PCI-scoped), Transaction details
Info::
Sentry (Error Tracking)
Detected via script URL. Typically collects: Error reports, Stack traces, User context, Device info. Privacy policy: https://sentry.io/privacy/. Data Processing Agreement available.
Got: Category: Error Tracking | Data types: Error reports, Stack traces, User context, Device info
Info::
LinkedIn Insight (Advertising)
Detected via script URL. Typically collects: Page views, Conversions, Ad targeting, Professional demographics. Privacy policy: https://www.linkedin.com/legal/privacy-policy. Data Processing Agreement available.
Got: Category: Advertising | Data types: Page views, Conversions, Ad targeting, Professional demographics
Info::
reCAPTCHA (Security)
Detected via script URL. Typically collects: Browser behavior, Device info, IP address. Privacy policy: https://policies.google.com/privacy. Data Processing Agreement available.
Got: Category: Security | Data types: Browser behavior, Device info, IP address
Analytics (1)
Advertising (2)
Session Recording (1)
Payment (1)
Error Tracking (1)
Security (1)
Google Analytics Analytics
Detected by: script URL
Data typically collected:
Page viewsUser behaviorDemographicsDevice infoIP address
Privacy policy → DPA available ✓
Facebook Pixel Advertising
Detected by: script URL
Data typically collected:
Page viewsConversionsUser behaviorAd targeting
Privacy policy → DPA available ✓
Hotjar Session Recording
Detected by: script URL
Data typically collected:
Session recordingsHeatmapsClick patternsForm interactions
Privacy policy → DPA available ✓
Stripe Payment
Detected by: script URL
Data typically collected:
Payment card data (PCI-scoped)Transaction details
Privacy policy → DPA available ✓
Sentry Error Tracking
Detected by: script URL
Data typically collected:
Error reportsStack tracesUser contextDevice info
Privacy policy → DPA available ✓
LinkedIn Insight Advertising
Detected by: script URL
Data typically collected:
Page viewsConversionsAd targetingProfessional demographics
Privacy policy → DPA available ✓
reCAPTCHA Security
Detected by: script URL
Data typically collected:
Browser behaviorDevice infoIP address
Privacy policy → DPA available ✓

This inventory identifies services receiving visitor data.

Under regulations like GDPR Article 30, maintaining records of data processing is commonly considered a best practice. This scan provides a starting point.

Readability Scores
1805 words, Flesch-Kincaid grade 20.9
INFO

Readability Analysis (Flesch-Kincaid)

Grade Level

20.9

Grade 21 (college+)

Reading Ease

17

Very Difficult

Words

1805

Sentences

45

All checks on this page are automated. Results are estimates - run targeted manual reviews when the score affects a release decision.

Send Feedback