← back to Instant Audit
instant-audit: snapshot (parallel-session build + package.json dotenv fix)
fdb2782a4d47881113a059f93f45baa8138174d9 · 2026-07-13 00:13:33 -0700 · Steve
Files touched
A .gitignoreA package-lock.jsonA package.jsonA public/index.htmlA reports/.gitkeepA server.jsA src/fulfill.js
Diff
commit fdb2782a4d47881113a059f93f45baa8138174d9
Author: Steve <steve@designerwallcoverings.com>
Date: Mon Jul 13 00:13:33 2026 -0700
instant-audit: snapshot (parallel-session build + package.json dotenv fix)
---
.gitignore | 8 +
package-lock.json | 893 ++++++++++++++++++++++++++++++++++++++++++++++++++++++
package.json | 15 +
public/index.html | 248 +++++++++++++++
reports/.gitkeep | 0
server.js | 198 ++++++++++++
src/fulfill.js | 261 ++++++++++++++++
7 files changed, 1623 insertions(+)
diff --git a/.gitignore b/.gitignore
new file mode 100644
index 0000000..3e835eb
--- /dev/null
+++ b/.gitignore
@@ -0,0 +1,8 @@
+node_modules/
+.env
+.env.*
+reports/*.html
+!reports/.gitkeep
+*.log
+.DS_Store
+tmp/
diff --git a/package-lock.json b/package-lock.json
new file mode 100644
index 0000000..35158b5
--- /dev/null
+++ b/package-lock.json
@@ -0,0 +1,893 @@
+{
+ "name": "instant-audit",
+ "version": "1.0.0",
+ "lockfileVersion": 3,
+ "requires": true,
+ "packages": {
+ "": {
+ "name": "instant-audit",
+ "version": "1.0.0",
+ "license": "ISC",
+ "dependencies": {
+ "dotenv": "^17.4.2",
+ "express": "^5.2.1",
+ "stripe": "^22.3.1"
+ }
+ },
+ "node_modules/accepts": {
+ "version": "2.0.0",
+ "resolved": "https://registry.npmjs.org/accepts/-/accepts-2.0.0.tgz",
+ "integrity": "sha512-5cvg6CtKwfgdmVqY1WIiXKc3Q1bkRqGLi+2W/6ao+6Y7gu/RCwRuAhGEzh5B4KlszSuTLgZYuqFqo5bImjNKng==",
+ "license": "MIT",
+ "dependencies": {
+ "mime-types": "^3.0.0",
+ "negotiator": "^1.0.0"
+ },
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/body-parser": {
+ "version": "2.3.0",
+ "resolved": "https://registry.npmjs.org/body-parser/-/body-parser-2.3.0.tgz",
+ "integrity": "sha512-2cGmJupaNgg+QUwVLAucDuWuoMZ6EX9iHDRswZ5lsNYEmwPaRknMPCLZz07yTzVq/83p4o/wzbDZbBrTvGGTIw==",
+ "license": "MIT",
+ "dependencies": {
+ "bytes": "^3.1.2",
+ "content-type": "^2.0.0",
+ "debug": "^4.4.3",
+ "http-errors": "^2.0.1",
+ "iconv-lite": "^0.7.2",
+ "on-finished": "^2.4.1",
+ "qs": "^6.15.2",
+ "raw-body": "^3.0.2",
+ "type-is": "^2.1.0"
+ },
+ "engines": {
+ "node": ">=18"
+ },
+ "funding": {
+ "type": "opencollective",
+ "url": "https://opencollective.com/express"
+ }
+ },
+ "node_modules/body-parser/node_modules/content-type": {
+ "version": "2.0.0",
+ "resolved": "https://registry.npmjs.org/content-type/-/content-type-2.0.0.tgz",
+ "integrity": "sha512-j/O/d7GcZCyNl7/hwZAb606rzqkyvaDctLmckbxLzHvFBzTJHuGEdodATcP3yIRoDrLHkIATJuvzbFlp/ki2cQ==",
+ "license": "MIT",
+ "engines": {
+ "node": ">=18"
+ },
+ "funding": {
+ "type": "opencollective",
+ "url": "https://opencollective.com/express"
+ }
+ },
+ "node_modules/bytes": {
+ "version": "3.1.2",
+ "resolved": "https://registry.npmjs.org/bytes/-/bytes-3.1.2.tgz",
+ "integrity": "sha512-/Nf7TyzTx6S3yRJObOAV7956r8cr2+Oj8AC5dt8wSP3BQAoeX58NoHyCU8P8zGkNXStjTSi6fzO6F0pBdcYbEg==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.8"
+ }
+ },
+ "node_modules/call-bind-apply-helpers": {
+ "version": "1.0.2",
+ "resolved": "https://registry.npmjs.org/call-bind-apply-helpers/-/call-bind-apply-helpers-1.0.2.tgz",
+ "integrity": "sha512-Sp1ablJ0ivDkSzjcaJdxEunN5/XvksFJ2sMBFfq6x0ryhQV/2b/KwFe21cMpmHtPOSij8K99/wSfoEuTObmuMQ==",
+ "license": "MIT",
+ "dependencies": {
+ "es-errors": "^1.3.0",
+ "function-bind": "^1.1.2"
+ },
+ "engines": {
+ "node": ">= 0.4"
+ }
+ },
+ "node_modules/call-bound": {
+ "version": "1.0.4",
+ "resolved": "https://registry.npmjs.org/call-bound/-/call-bound-1.0.4.tgz",
+ "integrity": "sha512-+ys997U96po4Kx/ABpBCqhA9EuxJaQWDQg7295H4hBphv3IZg0boBKuwYpt4YXp6MZ5AmZQnU/tyMTlRpaSejg==",
+ "license": "MIT",
+ "dependencies": {
+ "call-bind-apply-helpers": "^1.0.2",
+ "get-intrinsic": "^1.3.0"
+ },
+ "engines": {
+ "node": ">= 0.4"
+ },
+ "funding": {
+ "url": "https://github.com/sponsors/ljharb"
+ }
+ },
+ "node_modules/content-disposition": {
+ "version": "1.1.0",
+ "resolved": "https://registry.npmjs.org/content-disposition/-/content-disposition-1.1.0.tgz",
+ "integrity": "sha512-5jRCH9Z/+DRP7rkvY83B+yGIGX96OYdJmzngqnw2SBSxqCFPd0w2km3s5iawpGX8krnwSGmF0FW5Nhr0Hfai3g==",
+ "license": "MIT",
+ "engines": {
+ "node": ">=18"
+ },
+ "funding": {
+ "type": "opencollective",
+ "url": "https://opencollective.com/express"
+ }
+ },
+ "node_modules/content-type": {
+ "version": "1.0.5",
+ "resolved": "https://registry.npmjs.org/content-type/-/content-type-1.0.5.tgz",
+ "integrity": "sha512-nTjqfcBFEipKdXCv4YDQWCfmcLZKm81ldF0pAopTvyrFGVbcR6P/VAAd5G7N+0tTr8QqiU0tFadD6FK4NtJwOA==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/cookie": {
+ "version": "0.7.2",
+ "resolved": "https://registry.npmjs.org/cookie/-/cookie-0.7.2.tgz",
+ "integrity": "sha512-yki5XnKuf750l50uGTllt6kKILY4nQ1eNIQatoXEByZ5dWgnKqbnqmTrBE5B4N7lrMJKQ2ytWMiTO2o0v6Ew/w==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/cookie-signature": {
+ "version": "1.2.2",
+ "resolved": "https://registry.npmjs.org/cookie-signature/-/cookie-signature-1.2.2.tgz",
+ "integrity": "sha512-D76uU73ulSXrD1UXF4KE2TMxVVwhsnCgfAyTg9k8P6KGZjlXKrOLe4dJQKI3Bxi5wjesZoFXJWElNWBjPZMbhg==",
+ "license": "MIT",
+ "engines": {
+ "node": ">=6.6.0"
+ }
+ },
+ "node_modules/debug": {
+ "version": "4.4.3",
+ "resolved": "https://registry.npmjs.org/debug/-/debug-4.4.3.tgz",
+ "integrity": "sha512-RGwwWnwQvkVfavKVt22FGLw+xYSdzARwm0ru6DhTVA3umU5hZc28V3kO4stgYryrTlLpuvgI9GiijltAjNbcqA==",
+ "license": "MIT",
+ "dependencies": {
+ "ms": "^2.1.3"
+ },
+ "engines": {
+ "node": ">=6.0"
+ },
+ "peerDependenciesMeta": {
+ "supports-color": {
+ "optional": true
+ }
+ }
+ },
+ "node_modules/depd": {
+ "version": "2.0.0",
+ "resolved": "https://registry.npmjs.org/depd/-/depd-2.0.0.tgz",
+ "integrity": "sha512-g7nH6P6dyDioJogAAGprGpCtVImJhpPk/roCzdb3fIh61/s/nPsfR6onyMwkCAR/OlC3yBC0lESvUoQEAssIrw==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.8"
+ }
+ },
+ "node_modules/dotenv": {
+ "version": "17.4.2",
+ "resolved": "https://registry.npmjs.org/dotenv/-/dotenv-17.4.2.tgz",
+ "integrity": "sha512-nI4U3TottKAcAD9LLud4Cb7b2QztQMUEfHbvhTH09bqXTxnSie8WnjPALV/WMCrJZ6UV/qHJ6L03OqO3LcdYZw==",
+ "license": "BSD-2-Clause",
+ "engines": {
+ "node": ">=12"
+ },
+ "funding": {
+ "url": "https://dotenvx.com"
+ }
+ },
+ "node_modules/dunder-proto": {
+ "version": "1.0.1",
+ "resolved": "https://registry.npmjs.org/dunder-proto/-/dunder-proto-1.0.1.tgz",
+ "integrity": "sha512-KIN/nDJBQRcXw0MLVhZE9iQHmG68qAVIBg9CqmUYjmQIhgij9U5MFvrqkUL5FbtyyzZuOeOt0zdeRe4UY7ct+A==",
+ "license": "MIT",
+ "dependencies": {
+ "call-bind-apply-helpers": "^1.0.1",
+ "es-errors": "^1.3.0",
+ "gopd": "^1.2.0"
+ },
+ "engines": {
+ "node": ">= 0.4"
+ }
+ },
+ "node_modules/ee-first": {
+ "version": "1.1.1",
+ "resolved": "https://registry.npmjs.org/ee-first/-/ee-first-1.1.1.tgz",
+ "integrity": "sha512-WMwm9LhRUo+WUaRN+vRuETqG89IgZphVSNkdFgeb6sS/E4OrDIN7t48CAewSHXc6C8lefD8KKfr5vY61brQlow==",
+ "license": "MIT"
+ },
+ "node_modules/encodeurl": {
+ "version": "2.0.0",
+ "resolved": "https://registry.npmjs.org/encodeurl/-/encodeurl-2.0.0.tgz",
+ "integrity": "sha512-Q0n9HRi4m6JuGIV1eFlmvJB7ZEVxu93IrMyiMsGC0lrMJMWzRgx6WGquyfQgZVb31vhGgXnfmPNNXmxnOkRBrg==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.8"
+ }
+ },
+ "node_modules/es-define-property": {
+ "version": "1.0.1",
+ "resolved": "https://registry.npmjs.org/es-define-property/-/es-define-property-1.0.1.tgz",
+ "integrity": "sha512-e3nRfgfUZ4rNGL232gUgX06QNyyez04KdjFrF+LTRoOXmrOgFKDg4BCdsjW8EnT69eqdYGmRpJwiPVYNrCaW3g==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.4"
+ }
+ },
+ "node_modules/es-errors": {
+ "version": "1.3.0",
+ "resolved": "https://registry.npmjs.org/es-errors/-/es-errors-1.3.0.tgz",
+ "integrity": "sha512-Zf5H2Kxt2xjTvbJvP2ZWLEICxA6j+hAmMzIlypy4xcBg1vKVnx89Wy0GbS+kf5cwCVFFzdCFh2XSCFNULS6csw==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.4"
+ }
+ },
+ "node_modules/es-object-atoms": {
+ "version": "1.1.2",
+ "resolved": "https://registry.npmjs.org/es-object-atoms/-/es-object-atoms-1.1.2.tgz",
+ "integrity": "sha512-HWcBoN6NileqtSydK2FqHbS/LoDd2pqrnQHLyJzBj4kOp/ky2MWMN694xOfkK8/SnUsW2DH7EfyVlydKCsm1Zw==",
+ "license": "MIT",
+ "dependencies": {
+ "es-errors": "^1.3.0"
+ },
+ "engines": {
+ "node": ">= 0.4"
+ }
+ },
+ "node_modules/escape-html": {
+ "version": "1.0.3",
+ "resolved": "https://registry.npmjs.org/escape-html/-/escape-html-1.0.3.tgz",
+ "integrity": "sha512-NiSupZ4OeuGwr68lGIeym/ksIZMJodUGOSCZ/FSnTxcrekbvqrgdUxlJOMpijaKZVjAJrWrGs/6Jy8OMuyj9ow==",
+ "license": "MIT"
+ },
+ "node_modules/etag": {
+ "version": "1.8.1",
+ "resolved": "https://registry.npmjs.org/etag/-/etag-1.8.1.tgz",
+ "integrity": "sha512-aIL5Fx7mawVa300al2BnEE4iNvo1qETxLrPI/o05L7z6go7fCw1J6EQmbK4FmJ2AS7kgVF/KEZWufBfdClMcPg==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/express": {
+ "version": "5.2.1",
+ "resolved": "https://registry.npmjs.org/express/-/express-5.2.1.tgz",
+ "integrity": "sha512-hIS4idWWai69NezIdRt2xFVofaF4j+6INOpJlVOLDO8zXGpUVEVzIYk12UUi2JzjEzWL3IOAxcTubgz9Po0yXw==",
+ "license": "MIT",
+ "dependencies": {
+ "accepts": "^2.0.0",
+ "body-parser": "^2.2.1",
+ "content-disposition": "^1.0.0",
+ "content-type": "^1.0.5",
+ "cookie": "^0.7.1",
+ "cookie-signature": "^1.2.1",
+ "debug": "^4.4.0",
+ "depd": "^2.0.0",
+ "encodeurl": "^2.0.0",
+ "escape-html": "^1.0.3",
+ "etag": "^1.8.1",
+ "finalhandler": "^2.1.0",
+ "fresh": "^2.0.0",
+ "http-errors": "^2.0.0",
+ "merge-descriptors": "^2.0.0",
+ "mime-types": "^3.0.0",
+ "on-finished": "^2.4.1",
+ "once": "^1.4.0",
+ "parseurl": "^1.3.3",
+ "proxy-addr": "^2.0.7",
+ "qs": "^6.14.0",
+ "range-parser": "^1.2.1",
+ "router": "^2.2.0",
+ "send": "^1.1.0",
+ "serve-static": "^2.2.0",
+ "statuses": "^2.0.1",
+ "type-is": "^2.0.1",
+ "vary": "^1.1.2"
+ },
+ "engines": {
+ "node": ">= 18"
+ },
+ "funding": {
+ "type": "opencollective",
+ "url": "https://opencollective.com/express"
+ }
+ },
+ "node_modules/finalhandler": {
+ "version": "2.1.1",
+ "resolved": "https://registry.npmjs.org/finalhandler/-/finalhandler-2.1.1.tgz",
+ "integrity": "sha512-S8KoZgRZN+a5rNwqTxlZZePjT/4cnm0ROV70LedRHZ0p8u9fRID0hJUZQpkKLzro8LfmC8sx23bY6tVNxv8pQA==",
+ "license": "MIT",
+ "dependencies": {
+ "debug": "^4.4.0",
+ "encodeurl": "^2.0.0",
+ "escape-html": "^1.0.3",
+ "on-finished": "^2.4.1",
+ "parseurl": "^1.3.3",
+ "statuses": "^2.0.1"
+ },
+ "engines": {
+ "node": ">= 18.0.0"
+ },
+ "funding": {
+ "type": "opencollective",
+ "url": "https://opencollective.com/express"
+ }
+ },
+ "node_modules/forwarded": {
+ "version": "0.2.0",
+ "resolved": "https://registry.npmjs.org/forwarded/-/forwarded-0.2.0.tgz",
+ "integrity": "sha512-buRG0fpBtRHSTCOASe6hD258tEubFoRLb4ZNA6NxMVHNw2gOcwHo9wyablzMzOA5z9xA9L1KNjk/Nt6MT9aYow==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/fresh": {
+ "version": "2.0.0",
+ "resolved": "https://registry.npmjs.org/fresh/-/fresh-2.0.0.tgz",
+ "integrity": "sha512-Rx/WycZ60HOaqLKAi6cHRKKI7zxWbJ31MhntmtwMoaTeF7XFH9hhBp8vITaMidfljRQ6eYWCKkaTK+ykVJHP2A==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.8"
+ }
+ },
+ "node_modules/function-bind": {
+ "version": "1.1.2",
+ "resolved": "https://registry.npmjs.org/function-bind/-/function-bind-1.1.2.tgz",
+ "integrity": "sha512-7XHNxH7qX9xG5mIwxkhumTox/MIRNcOgDrxWsMt2pAr23WHp6MrRlN7FBSFpCpr+oVO0F744iUgR82nJMfG2SA==",
+ "license": "MIT",
+ "funding": {
+ "url": "https://github.com/sponsors/ljharb"
+ }
+ },
+ "node_modules/get-intrinsic": {
+ "version": "1.3.0",
+ "resolved": "https://registry.npmjs.org/get-intrinsic/-/get-intrinsic-1.3.0.tgz",
+ "integrity": "sha512-9fSjSaos/fRIVIp+xSJlE6lfwhES7LNtKaCBIamHsjr2na1BiABJPo0mOjjz8GJDURarmCPGqaiVg5mfjb98CQ==",
+ "license": "MIT",
+ "dependencies": {
+ "call-bind-apply-helpers": "^1.0.2",
+ "es-define-property": "^1.0.1",
+ "es-errors": "^1.3.0",
+ "es-object-atoms": "^1.1.1",
+ "function-bind": "^1.1.2",
+ "get-proto": "^1.0.1",
+ "gopd": "^1.2.0",
+ "has-symbols": "^1.1.0",
+ "hasown": "^2.0.2",
+ "math-intrinsics": "^1.1.0"
+ },
+ "engines": {
+ "node": ">= 0.4"
+ },
+ "funding": {
+ "url": "https://github.com/sponsors/ljharb"
+ }
+ },
+ "node_modules/get-proto": {
+ "version": "1.0.1",
+ "resolved": "https://registry.npmjs.org/get-proto/-/get-proto-1.0.1.tgz",
+ "integrity": "sha512-sTSfBjoXBp89JvIKIefqw7U2CCebsc74kiY6awiGogKtoSGbgjYE/G/+l9sF3MWFPNc9IcoOC4ODfKHfxFmp0g==",
+ "license": "MIT",
+ "dependencies": {
+ "dunder-proto": "^1.0.1",
+ "es-object-atoms": "^1.0.0"
+ },
+ "engines": {
+ "node": ">= 0.4"
+ }
+ },
+ "node_modules/gopd": {
+ "version": "1.2.0",
+ "resolved": "https://registry.npmjs.org/gopd/-/gopd-1.2.0.tgz",
+ "integrity": "sha512-ZUKRh6/kUFoAiTAtTYPZJ3hw9wNxx+BIBOijnlG9PnrJsCcSjs1wyyD6vJpaYtgnzDrKYRSqf3OO6Rfa93xsRg==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.4"
+ },
+ "funding": {
+ "url": "https://github.com/sponsors/ljharb"
+ }
+ },
+ "node_modules/has-symbols": {
+ "version": "1.1.0",
+ "resolved": "https://registry.npmjs.org/has-symbols/-/has-symbols-1.1.0.tgz",
+ "integrity": "sha512-1cDNdwJ2Jaohmb3sg4OmKaMBwuC48sYni5HUw2DvsC8LjGTLK9h+eb1X6RyuOHe4hT0ULCW68iomhjUoKUqlPQ==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.4"
+ },
+ "funding": {
+ "url": "https://github.com/sponsors/ljharb"
+ }
+ },
+ "node_modules/hasown": {
+ "version": "2.0.4",
+ "resolved": "https://registry.npmjs.org/hasown/-/hasown-2.0.4.tgz",
+ "integrity": "sha512-T2UbfbBEF32wiepXIsMlTW9+dDYC6wMh/t/vYA4tuOMKqWz/n3vr1NFSxQiyP+zk2mXsoMA/i/7qV6LKut1t1A==",
+ "license": "MIT",
+ "dependencies": {
+ "function-bind": "^1.1.2"
+ },
+ "engines": {
+ "node": ">= 0.4"
+ }
+ },
+ "node_modules/http-errors": {
+ "version": "2.0.1",
+ "resolved": "https://registry.npmjs.org/http-errors/-/http-errors-2.0.1.tgz",
+ "integrity": "sha512-4FbRdAX+bSdmo4AUFuS0WNiPz8NgFt+r8ThgNWmlrjQjt1Q7ZR9+zTlce2859x4KSXrwIsaeTqDoKQmtP8pLmQ==",
+ "license": "MIT",
+ "dependencies": {
+ "depd": "~2.0.0",
+ "inherits": "~2.0.4",
+ "setprototypeof": "~1.2.0",
+ "statuses": "~2.0.2",
+ "toidentifier": "~1.0.1"
+ },
+ "engines": {
+ "node": ">= 0.8"
+ },
+ "funding": {
+ "type": "opencollective",
+ "url": "https://opencollective.com/express"
+ }
+ },
+ "node_modules/iconv-lite": {
+ "version": "0.7.3",
+ "resolved": "https://registry.npmjs.org/iconv-lite/-/iconv-lite-0.7.3.tgz",
+ "integrity": "sha512-IKXpvIzjnC9XTAUbVBcMfGS0EPaIXtW6v+zr+RRp+hqULEpo0owZax6wyRwPOJbWbzjYspQwusTsfVr0ifh4uQ==",
+ "license": "MIT",
+ "dependencies": {
+ "safer-buffer": ">= 2.1.2 < 3.0.0"
+ },
+ "engines": {
+ "node": ">=0.10.0"
+ },
+ "funding": {
+ "type": "opencollective",
+ "url": "https://opencollective.com/express"
+ }
+ },
+ "node_modules/inherits": {
+ "version": "2.0.4",
+ "resolved": "https://registry.npmjs.org/inherits/-/inherits-2.0.4.tgz",
+ "integrity": "sha512-k/vGaX4/Yla3WzyMCvTQOXYeIHvqOKtnqBduzTHpzpQZzAskKMhZ2K+EnBiSM9zGSoIFeMpXKxa4dYeZIQqewQ==",
+ "license": "ISC"
+ },
+ "node_modules/ipaddr.js": {
+ "version": "1.9.1",
+ "resolved": "https://registry.npmjs.org/ipaddr.js/-/ipaddr.js-1.9.1.tgz",
+ "integrity": "sha512-0KI/607xoxSToH7GjN1FfSbLoU0+btTicjsQSWQlh/hZykN8KpmMf7uYwPW3R+akZ6R/w18ZlXSHBYXiYUPO3g==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.10"
+ }
+ },
+ "node_modules/is-promise": {
+ "version": "4.0.0",
+ "resolved": "https://registry.npmjs.org/is-promise/-/is-promise-4.0.0.tgz",
+ "integrity": "sha512-hvpoI6korhJMnej285dSg6nu1+e6uxs7zG3BYAm5byqDsgJNWwxzM6z6iZiAgQR4TJ30JmBTOwqZUw3WlyH3AQ==",
+ "license": "MIT"
+ },
+ "node_modules/math-intrinsics": {
+ "version": "1.1.0",
+ "resolved": "https://registry.npmjs.org/math-intrinsics/-/math-intrinsics-1.1.0.tgz",
+ "integrity": "sha512-/IXtbwEk5HTPyEwyKX6hGkYXxM9nbj64B+ilVJnC/R6B0pH5G4V3b0pVbL7DBj4tkhBAppbQUlf6F6Xl9LHu1g==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.4"
+ }
+ },
+ "node_modules/media-typer": {
+ "version": "1.1.0",
+ "resolved": "https://registry.npmjs.org/media-typer/-/media-typer-1.1.0.tgz",
+ "integrity": "sha512-aisnrDP4GNe06UcKFnV5bfMNPBUw4jsLGaWwWfnH3v02GnBuXX2MCVn5RbrWo0j3pczUilYblq7fQ7Nw2t5XKw==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.8"
+ }
+ },
+ "node_modules/merge-descriptors": {
+ "version": "2.0.0",
+ "resolved": "https://registry.npmjs.org/merge-descriptors/-/merge-descriptors-2.0.0.tgz",
+ "integrity": "sha512-Snk314V5ayFLhp3fkUREub6WtjBfPdCPY1Ln8/8munuLuiYhsABgBVWsozAG+MWMbVEvcdcpbi9R7ww22l9Q3g==",
+ "license": "MIT",
+ "engines": {
+ "node": ">=18"
+ },
+ "funding": {
+ "url": "https://github.com/sponsors/sindresorhus"
+ }
+ },
+ "node_modules/mime-db": {
+ "version": "1.54.0",
+ "resolved": "https://registry.npmjs.org/mime-db/-/mime-db-1.54.0.tgz",
+ "integrity": "sha512-aU5EJuIN2WDemCcAp2vFBfp/m4EAhWJnUNSSw0ixs7/kXbd6Pg64EmwJkNdFhB8aWt1sH2CTXrLxo/iAGV3oPQ==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/mime-types": {
+ "version": "3.0.2",
+ "resolved": "https://registry.npmjs.org/mime-types/-/mime-types-3.0.2.tgz",
+ "integrity": "sha512-Lbgzdk0h4juoQ9fCKXW4by0UJqj+nOOrI9MJ1sSj4nI8aI2eo1qmvQEie4VD1glsS250n15LsWsYtCugiStS5A==",
+ "license": "MIT",
+ "dependencies": {
+ "mime-db": "^1.54.0"
+ },
+ "engines": {
+ "node": ">=18"
+ },
+ "funding": {
+ "type": "opencollective",
+ "url": "https://opencollective.com/express"
+ }
+ },
+ "node_modules/ms": {
+ "version": "2.1.3",
+ "resolved": "https://registry.npmjs.org/ms/-/ms-2.1.3.tgz",
+ "integrity": "sha512-6FlzubTLZG3J2a/NVCAleEhjzq5oxgHyaCU9yYXvcLsvoVaHJq/s5xXI6/XXP6tz7R9xAOtHnSO/tXtF3WRTlA==",
+ "license": "MIT"
+ },
+ "node_modules/negotiator": {
+ "version": "1.0.0",
+ "resolved": "https://registry.npmjs.org/negotiator/-/negotiator-1.0.0.tgz",
+ "integrity": "sha512-8Ofs/AUQh8MaEcrlq5xOX0CQ9ypTF5dl78mjlMNfOK08fzpgTHQRQPBxcPlEtIw0yRpws+Zo/3r+5WRby7u3Gg==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.6"
+ }
+ },
+ "node_modules/object-inspect": {
+ "version": "1.13.4",
+ "resolved": "https://registry.npmjs.org/object-inspect/-/object-inspect-1.13.4.tgz",
+ "integrity": "sha512-W67iLl4J2EXEGTbfeHCffrjDfitvLANg0UlX3wFUUSTx92KXRFegMHUVgSqE+wvhAbi4WqjGg9czysTV2Epbew==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.4"
+ },
+ "funding": {
+ "url": "https://github.com/sponsors/ljharb"
+ }
+ },
+ "node_modules/on-finished": {
+ "version": "2.4.1",
+ "resolved": "https://registry.npmjs.org/on-finished/-/on-finished-2.4.1.tgz",
+ "integrity": "sha512-oVlzkg3ENAhCk2zdv7IJwd/QUD4z2RxRwpkcGY8psCVcCYZNq4wYnVWALHM+brtuJjePWiYF/ClmuDr8Ch5+kg==",
+ "license": "MIT",
+ "dependencies": {
+ "ee-first": "1.1.1"
+ },
+ "engines": {
+ "node": ">= 0.8"
+ }
+ },
+ "node_modules/once": {
+ "version": "1.4.0",
+ "resolved": "https://registry.npmjs.org/once/-/once-1.4.0.tgz",
+ "integrity": "sha512-lNaJgI+2Q5URQBkccEKHTQOPaXdUxnZZElQTZY0MFUAuaEqe1E+Nyvgdz/aIyNi6Z9MzO5dv1H8n58/GELp3+w==",
+ "license": "ISC",
+ "dependencies": {
+ "wrappy": "1"
+ }
+ },
+ "node_modules/parseurl": {
+ "version": "1.3.3",
+ "resolved": "https://registry.npmjs.org/parseurl/-/parseurl-1.3.3.tgz",
+ "integrity": "sha512-CiyeOxFT/JZyN5m0z9PfXw4SCBJ6Sygz1Dpl0wqjlhDEGGBP1GnsUVEL0p63hoG1fcj3fHynXi9NYO4nWOL+qQ==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.8"
+ }
+ },
+ "node_modules/path-to-regexp": {
+ "version": "8.4.2",
+ "resolved": "https://registry.npmjs.org/path-to-regexp/-/path-to-regexp-8.4.2.tgz",
+ "integrity": "sha512-qRcuIdP69NPm4qbACK+aDogI5CBDMi1jKe0ry5rSQJz8JVLsC7jV8XpiJjGRLLol3N+R5ihGYcrPLTno6pAdBA==",
+ "license": "MIT",
+ "funding": {
+ "type": "opencollective",
+ "url": "https://opencollective.com/express"
+ }
+ },
+ "node_modules/proxy-addr": {
+ "version": "2.0.7",
+ "resolved": "https://registry.npmjs.org/proxy-addr/-/proxy-addr-2.0.7.tgz",
+ "integrity": "sha512-llQsMLSUDUPT44jdrU/O37qlnifitDP+ZwrmmZcoSKyLKvtZxpyV0n2/bD/N4tBAAZ/gJEdZU7KMraoK1+XYAg==",
+ "license": "MIT",
+ "dependencies": {
+ "forwarded": "0.2.0",
+ "ipaddr.js": "1.9.1"
+ },
+ "engines": {
+ "node": ">= 0.10"
+ }
+ },
+ "node_modules/qs": {
+ "version": "6.15.3",
+ "resolved": "https://registry.npmjs.org/qs/-/qs-6.15.3.tgz",
+ "integrity": "sha512-O9gl3zCl5h5blw1KGUzQKhA5oUXSl8rwUIM5o0S3nCXMliSvy5Dzx7/DJcI+SwgICv+IneSZwhBh1oSyEHA71A==",
+ "license": "BSD-3-Clause",
+ "dependencies": {
+ "es-define-property": "^1.0.1",
+ "side-channel": "^1.1.1"
+ },
+ "engines": {
+ "node": ">=0.6"
+ },
+ "funding": {
+ "url": "https://github.com/sponsors/ljharb"
+ }
+ },
+ "node_modules/range-parser": {
+ "version": "1.3.0",
+ "resolved": "https://registry.npmjs.org/range-parser/-/range-parser-1.3.0.tgz",
+ "integrity": "sha512-hek2mFQpPuI4E1BBKrSto+BU3e3x4xuarsbiwr3+lf7p44juvFMV0XFWQAP3xUyqXA4RrXLIoaSUGbSt056ZMw==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.6"
+ },
+ "funding": {
+ "type": "opencollective",
+ "url": "https://opencollective.com/express"
+ }
+ },
+ "node_modules/raw-body": {
+ "version": "3.0.2",
+ "resolved": "https://registry.npmjs.org/raw-body/-/raw-body-3.0.2.tgz",
+ "integrity": "sha512-K5zQjDllxWkf7Z5xJdV0/B0WTNqx6vxG70zJE4N0kBs4LovmEYWJzQGxC9bS9RAKu3bgM40lrd5zoLJ12MQ5BA==",
+ "license": "MIT",
+ "dependencies": {
+ "bytes": "~3.1.2",
+ "http-errors": "~2.0.1",
+ "iconv-lite": "~0.7.0",
+ "unpipe": "~1.0.0"
+ },
+ "engines": {
+ "node": ">= 0.10"
+ }
+ },
+ "node_modules/router": {
+ "version": "2.2.0",
+ "resolved": "https://registry.npmjs.org/router/-/router-2.2.0.tgz",
+ "integrity": "sha512-nLTrUKm2UyiL7rlhapu/Zl45FwNgkZGaCpZbIHajDYgwlJCOzLSk+cIPAnsEqV955GjILJnKbdQC1nVPz+gAYQ==",
+ "license": "MIT",
+ "dependencies": {
+ "debug": "^4.4.0",
+ "depd": "^2.0.0",
+ "is-promise": "^4.0.0",
+ "parseurl": "^1.3.3",
+ "path-to-regexp": "^8.0.0"
+ },
+ "engines": {
+ "node": ">= 18"
+ }
+ },
+ "node_modules/safer-buffer": {
+ "version": "2.1.2",
+ "resolved": "https://registry.npmjs.org/safer-buffer/-/safer-buffer-2.1.2.tgz",
+ "integrity": "sha512-YZo3K82SD7Riyi0E1EQPojLz7kpepnSQI9IyPbHHg1XXXevb5dJI7tpyN2ADxGcQbHG7vcyRHk0cbwqcQriUtg==",
+ "license": "MIT"
+ },
+ "node_modules/send": {
+ "version": "1.2.1",
+ "resolved": "https://registry.npmjs.org/send/-/send-1.2.1.tgz",
+ "integrity": "sha512-1gnZf7DFcoIcajTjTwjwuDjzuz4PPcY2StKPlsGAQ1+YH20IRVrBaXSWmdjowTJ6u8Rc01PoYOGHXfP1mYcZNQ==",
+ "license": "MIT",
+ "dependencies": {
+ "debug": "^4.4.3",
+ "encodeurl": "^2.0.0",
+ "escape-html": "^1.0.3",
+ "etag": "^1.8.1",
+ "fresh": "^2.0.0",
+ "http-errors": "^2.0.1",
+ "mime-types": "^3.0.2",
+ "ms": "^2.1.3",
+ "on-finished": "^2.4.1",
+ "range-parser": "^1.2.1",
+ "statuses": "^2.0.2"
+ },
+ "engines": {
+ "node": ">= 18"
+ },
+ "funding": {
+ "type": "opencollective",
+ "url": "https://opencollective.com/express"
+ }
+ },
+ "node_modules/serve-static": {
+ "version": "2.2.1",
+ "resolved": "https://registry.npmjs.org/serve-static/-/serve-static-2.2.1.tgz",
+ "integrity": "sha512-xRXBn0pPqQTVQiC8wyQrKs2MOlX24zQ0POGaj0kultvoOCstBQM5yvOhAVSUwOMjQtTvsPWoNCHfPGwaaQJhTw==",
+ "license": "MIT",
+ "dependencies": {
+ "encodeurl": "^2.0.0",
+ "escape-html": "^1.0.3",
+ "parseurl": "^1.3.3",
+ "send": "^1.2.0"
+ },
+ "engines": {
+ "node": ">= 18"
+ },
+ "funding": {
+ "type": "opencollective",
+ "url": "https://opencollective.com/express"
+ }
+ },
+ "node_modules/setprototypeof": {
+ "version": "1.2.0",
+ "resolved": "https://registry.npmjs.org/setprototypeof/-/setprototypeof-1.2.0.tgz",
+ "integrity": "sha512-E5LDX7Wrp85Kil5bhZv46j8jOeboKq5JMmYM3gVGdGH8xFpPWXUMsNrlODCrkoxMEeNi/XZIwuRvY4XNwYMJpw==",
+ "license": "ISC"
+ },
+ "node_modules/side-channel": {
+ "version": "1.1.1",
+ "resolved": "https://registry.npmjs.org/side-channel/-/side-channel-1.1.1.tgz",
+ "integrity": "sha512-6x6dK6zJdpTzF4sQeNYxwtvBzf6Eg4GtlesS94HOvTudUeyK2WXAaIfmDgsyslYrRBeFIlsi54AYsFGUuhmvrQ==",
+ "license": "MIT",
+ "dependencies": {
+ "es-errors": "^1.3.0",
+ "object-inspect": "^1.13.4",
+ "side-channel-list": "^1.0.1",
+ "side-channel-map": "^1.0.1",
+ "side-channel-weakmap": "^1.0.2"
+ },
+ "engines": {
+ "node": ">= 0.4"
+ },
+ "funding": {
+ "url": "https://github.com/sponsors/ljharb"
+ }
+ },
+ "node_modules/side-channel-list": {
+ "version": "1.0.1",
+ "resolved": "https://registry.npmjs.org/side-channel-list/-/side-channel-list-1.0.1.tgz",
+ "integrity": "sha512-mjn/0bi/oUURjc5Xl7IaWi/OJJJumuoJFQJfDDyO46+hBWsfaVM65TBHq2eoZBhzl9EchxOijpkbRC8SVBQU0w==",
+ "license": "MIT",
+ "dependencies": {
+ "es-errors": "^1.3.0",
+ "object-inspect": "^1.13.4"
+ },
+ "engines": {
+ "node": ">= 0.4"
+ },
+ "funding": {
+ "url": "https://github.com/sponsors/ljharb"
+ }
+ },
+ "node_modules/side-channel-map": {
+ "version": "1.0.1",
+ "resolved": "https://registry.npmjs.org/side-channel-map/-/side-channel-map-1.0.1.tgz",
+ "integrity": "sha512-VCjCNfgMsby3tTdo02nbjtM/ewra6jPHmpThenkTYh8pG9ucZ/1P8So4u4FGBek/BjpOVsDCMoLA/iuBKIFXRA==",
+ "license": "MIT",
+ "dependencies": {
+ "call-bound": "^1.0.2",
+ "es-errors": "^1.3.0",
+ "get-intrinsic": "^1.2.5",
+ "object-inspect": "^1.13.3"
+ },
+ "engines": {
+ "node": ">= 0.4"
+ },
+ "funding": {
+ "url": "https://github.com/sponsors/ljharb"
+ }
+ },
+ "node_modules/side-channel-weakmap": {
+ "version": "1.0.2",
+ "resolved": "https://registry.npmjs.org/side-channel-weakmap/-/side-channel-weakmap-1.0.2.tgz",
+ "integrity": "sha512-WPS/HvHQTYnHisLo9McqBHOJk2FkHO/tlpvldyrnem4aeQp4hai3gythswg6p01oSoTl58rcpiFAjF2br2Ak2A==",
+ "license": "MIT",
+ "dependencies": {
+ "call-bound": "^1.0.2",
+ "es-errors": "^1.3.0",
+ "get-intrinsic": "^1.2.5",
+ "object-inspect": "^1.13.3",
+ "side-channel-map": "^1.0.1"
+ },
+ "engines": {
+ "node": ">= 0.4"
+ },
+ "funding": {
+ "url": "https://github.com/sponsors/ljharb"
+ }
+ },
+ "node_modules/statuses": {
+ "version": "2.0.2",
+ "resolved": "https://registry.npmjs.org/statuses/-/statuses-2.0.2.tgz",
+ "integrity": "sha512-DvEy55V3DB7uknRo+4iOGT5fP1slR8wQohVdknigZPMpMstaKJQWhwiYBACJE3Ul2pTnATihhBYnRhZQHGBiRw==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.8"
+ }
+ },
+ "node_modules/stripe": {
+ "version": "22.3.1",
+ "resolved": "https://registry.npmjs.org/stripe/-/stripe-22.3.1.tgz",
+ "integrity": "sha512-6XSLN0KK0IdfXqDHqMg6CDoO3eO62ye9dhzw0fZp55AUOzHR1YRJOqYHTsuCi4QJ4Ni/usEmXtq69c9ghKDmYw==",
+ "license": "MIT",
+ "engines": {
+ "node": ">=18"
+ },
+ "peerDependencies": {
+ "@types/node": ">=18"
+ },
+ "peerDependenciesMeta": {
+ "@types/node": {
+ "optional": true
+ }
+ }
+ },
+ "node_modules/toidentifier": {
+ "version": "1.0.1",
+ "resolved": "https://registry.npmjs.org/toidentifier/-/toidentifier-1.0.1.tgz",
+ "integrity": "sha512-o5sSPKEkg/DIQNmH43V0/uerLrpzVedkUh8tGNvaeXpfpuwjKenlSox/2O/BTlZUtEe+JG7s5YhEz608PlAHRA==",
+ "license": "MIT",
+ "engines": {
+ "node": ">=0.6"
+ }
+ },
+ "node_modules/type-is": {
+ "version": "2.1.0",
+ "resolved": "https://registry.npmjs.org/type-is/-/type-is-2.1.0.tgz",
+ "integrity": "sha512-faYHw0anBbc/kWF3zFTEnxSFOAGUX9GFbOBthvDdLsIlEoWOFOtS0zgCiQYwIskL9iGXZL3kAXD8OoZ4GmMATA==",
+ "license": "MIT",
+ "dependencies": {
+ "content-type": "^2.0.0",
+ "media-typer": "^1.1.0",
+ "mime-types": "^3.0.0"
+ },
+ "engines": {
+ "node": ">= 18"
+ },
+ "funding": {
+ "type": "opencollective",
+ "url": "https://opencollective.com/express"
+ }
+ },
+ "node_modules/type-is/node_modules/content-type": {
+ "version": "2.0.0",
+ "resolved": "https://registry.npmjs.org/content-type/-/content-type-2.0.0.tgz",
+ "integrity": "sha512-j/O/d7GcZCyNl7/hwZAb606rzqkyvaDctLmckbxLzHvFBzTJHuGEdodATcP3yIRoDrLHkIATJuvzbFlp/ki2cQ==",
+ "license": "MIT",
+ "engines": {
+ "node": ">=18"
+ },
+ "funding": {
+ "type": "opencollective",
+ "url": "https://opencollective.com/express"
+ }
+ },
+ "node_modules/unpipe": {
+ "version": "1.0.0",
+ "resolved": "https://registry.npmjs.org/unpipe/-/unpipe-1.0.0.tgz",
+ "integrity": "sha512-pjy2bYhSsufwWlKwPc+l3cN7+wuJlK6uz0YdJEOlQDbl6jo/YlPi4mb8agUkVC8BF7V8NuzeyPNqRksA3hztKQ==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.8"
+ }
+ },
+ "node_modules/vary": {
+ "version": "1.1.2",
+ "resolved": "https://registry.npmjs.org/vary/-/vary-1.1.2.tgz",
+ "integrity": "sha512-BNGbWLfd0eUPabhkXUVm0j8uuvREyTh5ovRa/dyow/BqAbZJyC+5fU+IzQOzmAKzYqYRAISoRhdQr3eIZ/PXqg==",
+ "license": "MIT",
+ "engines": {
+ "node": ">= 0.8"
+ }
+ },
+ "node_modules/wrappy": {
+ "version": "1.0.2",
+ "resolved": "https://registry.npmjs.org/wrappy/-/wrappy-1.0.2.tgz",
+ "integrity": "sha512-l4Sp/DRseor9wL6EvV2+TuQn63dMkPjZ/sp9XkghTEbV9KlPS1xUsZ3u7/IQO4wxtcFB4bgpQPRcR3QCvezPcQ==",
+ "license": "ISC"
+ }
+ }
+}
diff --git a/package.json b/package.json
new file mode 100644
index 0000000..faa1857
--- /dev/null
+++ b/package.json
@@ -0,0 +1,15 @@
+{
+ "name": "instant-audit",
+ "version": "0.1.0",
+ "private": true,
+ "description": "Instant Website Audit — a $2,000 consultant audit for $99, delivered in minutes.",
+ "type": "module",
+ "scripts": {
+ "start": "node server.js"
+ },
+ "dependencies": {
+ "dotenv": "^16.4.5",
+ "express": "^4.21.0",
+ "stripe": "^17.0.0"
+ }
+}
diff --git a/public/index.html b/public/index.html
new file mode 100644
index 0000000..067850b
--- /dev/null
+++ b/public/index.html
@@ -0,0 +1,248 @@
+<!doctype html>
+<html lang="en">
+<head>
+<meta charset="utf-8">
+<meta name="viewport" content="width=device-width,initial-scale=1">
+<title>Instant Website Audit — a $2,000 consultant audit for $99, in minutes</title>
+<meta name="description" content="A professional, consultant-grade website audit delivered in minutes. SEO, accessibility, competitor teardown, homepage concepts, and working tools — from $49.">
+<style>
+:root{
+ --ink:#1a1a1a; --paper:#faf8f4; --card:#ffffff; --line:#e4ddd2;
+ --accent:#8a7355; --accent-ink:#6b5840; --muted:#6b6257; --ok:#3f7d54;
+}
+*{box-sizing:border-box;margin:0;padding:0}
+html{scroll-behavior:smooth}
+body{font-family:Georgia,'Times New Roman',serif;background:var(--paper);color:var(--ink);line-height:1.6}
+.sans{font-family:-apple-system,'Segoe UI',Helvetica,Arial,sans-serif}
+.wrap{max-width:1040px;margin:0 auto;padding:0 24px}
+header{border-bottom:1px solid var(--line);background:var(--paper)}
+.hd{display:flex;align-items:center;justify-content:space-between;padding:18px 24px;max-width:1040px;margin:0 auto}
+.logo{font-family:-apple-system,sans-serif;font-weight:700;letter-spacing:.02em;font-size:17px}
+.logo b{color:var(--accent)}
+.hd .rb{font-family:-apple-system,sans-serif;font-size:12px;color:var(--muted)}
+
+/* hero */
+.hero{text-align:center;padding:70px 24px 40px}
+.eyebrow{font-family:-apple-system,sans-serif;text-transform:uppercase;letter-spacing:.22em;font-size:12px;color:var(--accent)}
+.hero h1{font-size:46px;line-height:1.12;letter-spacing:-.02em;margin:14px auto 10px;max-width:16ch}
+.hero .sub{font-size:19px;color:var(--muted);max-width:56ch;margin:0 auto}
+.hero .strike{color:#a99;text-decoration:line-through}
+
+/* CTA form */
+.auditform{max-width:620px;margin:30px auto 6px;display:flex;gap:10px;flex-wrap:wrap;justify-content:center}
+.auditform input{font-family:-apple-system,sans-serif;font-size:16px;padding:14px 16px;border:1px solid var(--line);border-radius:6px;background:#fff;min-width:280px;flex:1}
+.auditform button{font-family:-apple-system,sans-serif;font-size:16px;font-weight:600;padding:14px 26px;border:0;border-radius:6px;background:var(--ink);color:#fff;cursor:pointer}
+.auditform button:hover{background:var(--accent)}
+.modehint{font-family:-apple-system,sans-serif;font-size:12px;color:var(--muted);margin-top:8px}
+
+/* tiers */
+.tiers{display:grid;grid-template-columns:repeat(3,1fr);gap:18px;margin:56px 0}
+.tier{background:var(--card);border:1px solid var(--line);border-radius:10px;padding:26px 22px;display:flex;flex-direction:column}
+.tier.feat{border-color:var(--accent);box-shadow:0 6px 26px rgba(138,115,85,.12)}
+.tier .name{font-family:-apple-system,sans-serif;font-weight:700;font-size:15px;letter-spacing:.02em}
+.tier .price{font-size:40px;margin:8px 0 2px}
+.tier .price span{font-size:16px;color:var(--muted)}
+.tier .blurb{font-size:15px;color:var(--muted);min-height:44px}
+.tier ul{list-style:none;margin:16px 0;font-family:-apple-system,sans-serif;font-size:14px}
+.tier li{padding:6px 0;padding-left:22px;position:relative}
+.tier li::before{content:'✓';position:absolute;left:0;color:var(--ok);font-weight:700}
+.tier li.no{color:#b6ada0}
+.tier li.no::before{content:'–';color:#cfc7ba}
+.tier .buy{margin-top:auto;font-family:-apple-system,sans-serif;font-weight:600;font-size:15px;padding:12px;border:1px solid var(--ink);border-radius:6px;background:#fff;color:var(--ink);cursor:pointer}
+.tier.feat .buy{background:var(--ink);color:#fff}
+.tier .buy:hover{background:var(--accent);color:#fff;border-color:var(--accent)}
+.pill{display:inline-block;font-family:-apple-system,sans-serif;font-size:11px;letter-spacing:.06em;text-transform:uppercase;background:var(--accent);color:#fff;padding:2px 9px;border-radius:20px;margin-bottom:6px}
+
+/* preview */
+.section-title{text-align:center;font-size:30px;margin:12px 0 4px}
+.section-sub{text-align:center;color:var(--muted);font-family:-apple-system,sans-serif;font-size:15px;margin-bottom:26px}
+.preview{background:var(--card);border:1px solid var(--line);border-radius:10px;padding:0;overflow:hidden;position:relative}
+.preview .bar{background:#f0ebe1;border-bottom:1px solid var(--line);padding:10px 16px;font-family:-apple-system,sans-serif;font-size:13px;color:var(--muted)}
+.preview .body{padding:26px 28px;position:relative}
+.preview h3{font-family:-apple-system,sans-serif;font-size:16px;margin:14px 0 6px}
+.preview table{border-collapse:collapse;width:100%;font-family:-apple-system,sans-serif;font-size:13px;margin:8px 0}
+.preview th,.preview td{border:1px solid var(--line);padding:7px 9px;text-align:left}
+.preview th{background:#f0ebe1}
+.redact{background:#d9d2c6;color:transparent;border-radius:2px;user-select:none}
+.fade{position:absolute;left:0;right:0;bottom:0;height:120px;background:linear-gradient(transparent,var(--card))}
+.grade{display:inline-block;font-family:-apple-system,sans-serif;font-weight:700;padding:2px 10px;border:1px solid var(--line);border-radius:3px;background:#fff}
+
+/* trust + faq */
+.trust{display:grid;grid-template-columns:repeat(3,1fr);gap:16px;margin:56px 0;font-family:-apple-system,sans-serif}
+.trust .t{background:var(--card);border:1px solid var(--line);border-radius:10px;padding:22px;text-align:center}
+.trust .t b{display:block;font-size:26px;margin-bottom:4px}
+.trust .t span{color:var(--muted);font-size:14px}
+.faq{max-width:760px;margin:0 auto 70px}
+.faq details{background:var(--card);border:1px solid var(--line);border-radius:8px;padding:16px 20px;margin:10px 0}
+.faq summary{font-family:-apple-system,sans-serif;font-weight:600;cursor:pointer;font-size:16px}
+.faq p{margin-top:10px;color:var(--muted);font-size:15px}
+footer{border-top:1px solid var(--line);text-align:center;padding:30px;font-family:-apple-system,sans-serif;font-size:12px;color:var(--muted)}
+@media(max-width:820px){.tiers,.trust{grid-template-columns:1fr}.hero h1{font-size:34px}}
+</style>
+</head>
+<body>
+<header>
+ <div class="hd">
+ <div class="logo">Instant<b>Audit</b></div>
+ <div class="rb">Delivered in minutes · from $49</div>
+ </div>
+</header>
+
+<section class="hero">
+ <div class="eyebrow">Website Audit, Productized</div>
+ <h1>A <span class="strike">$2,000</span> consultant website audit for $99, delivered in minutes</h1>
+ <p class="sub">Enter your website. Our generators run a consultant-grade audit — SEO, accessibility,
+ a competitor teardown, hand-built homepage concepts, and working visitor tools — and assemble a
+ multi-page report you can open in any browser.</p>
+
+ <form class="auditform" id="ctaForm" onsubmit="return false">
+ <input type="url" id="ctaUrl" placeholder="https://your-website.com" required autocomplete="url">
+ <button type="button" onclick="scrollToTiers()">Get my audit →</button>
+ </form>
+ <div class="modehint" id="modehint">Loading pricing…</div>
+</section>
+
+<div class="wrap">
+ <!-- TIERS -->
+ <section id="tiers">
+ <h2 class="section-title">Choose your depth</h2>
+ <p class="section-sub sans">One-time payment. No subscription. Report delivered as a private link.</p>
+ <div class="tiers">
+ <div class="tier">
+ <div class="name">AUDIT LITE</div>
+ <div class="price">$49</div>
+ <div class="blurb">The fast-win report to fix your fundamentals.</div>
+ <ul>
+ <li>Full site audit & grade</li>
+ <li>Pack of working visitor tools</li>
+ <li class="no">Peer survey</li>
+ <li class="no">Trusted-sources hub</li>
+ <li class="no">Competitor teardown</li>
+ <li class="no">Homepage concepts</li>
+ </ul>
+ <button class="buy" data-tier="lite">Get Lite — $49</button>
+ </div>
+ <div class="tier feat">
+ <span class="pill">Most popular</span>
+ <div class="name">AUDIT STANDARD</div>
+ <div class="price">$99</div>
+ <div class="blurb">The complete positioning report for your niche.</div>
+ <ul>
+ <li>Full site audit & grade</li>
+ <li>Pack of working visitor tools</li>
+ <li>Peer survey (what rivals do)</li>
+ <li>Trusted-sources hub</li>
+ <li class="no">Competitor teardown</li>
+ <li class="no">Homepage concepts</li>
+ </ul>
+ <button class="buy" data-tier="standard">Get Standard — $99</button>
+ </div>
+ <div class="tier">
+ <div class="name">AUDIT PRO</div>
+ <div class="price">$199</div>
+ <div class="blurb">Everything, plus a teardown and new homepage concepts.</div>
+ <ul>
+ <li>Full site audit & grade</li>
+ <li>Pack of working visitor tools</li>
+ <li>Peer survey (what rivals do)</li>
+ <li>Trusted-sources hub</li>
+ <li>Competitor teardown</li>
+ <li>Hand-built homepage concepts</li>
+ </ul>
+ <button class="buy" data-tier="pro">Get Pro — $199</button>
+ </div>
+ </div>
+ </section>
+
+ <!-- PREVIEW -->
+ <section style="margin:20px 0 56px">
+ <h2 class="section-title">A peek at the report</h2>
+ <p class="section-sub sans">Sample page — names and specifics redacted until you buy.</p>
+ <div class="preview">
+ <div class="bar">report.html · Site Audit — <span class="redact">yoursite.com</span></div>
+ <div class="body">
+ <h3>Executive grade <span class="grade">B+</span></h3>
+ <p class="sans" style="font-size:14px;color:var(--muted)">Homepage fundamentals for
+ <span class="redact">████████████</span> — the signals that drive search visibility and first-impression conversion.</p>
+ <h3>Core signals</h3>
+ <table>
+ <tr><th>Signal</th><th>Observed</th><th>Verdict</th></tr>
+ <tr><td><title> tag</td><td><span class="redact">████████████</span></td><td>Good length</td></tr>
+ <tr><td>Meta description</td><td>MISSING</td><td>Add one (150–160 chars)</td></tr>
+ <tr><td><h1> heading</td><td>Present</td><td>Pass</td></tr>
+ <tr><td>Schema.org markup</td><td><span class="redact">████</span></td><td>Add Organization JSON-LD</td></tr>
+ </table>
+ <h3>Top recommended additions</h3>
+ <p class="sans" style="font-size:14px"><span class="redact">██████████████████████████████████████████</span></p>
+ <p class="sans" style="font-size:14px"><span class="redact">████████████████████████████████</span></p>
+ <div class="fade"></div>
+ </div>
+ </div>
+ </section>
+
+ <!-- TRUST -->
+ <section class="trust">
+ <div class="t"><b>~ minutes</b><span>From URL to finished multi-page report</span></div>
+ <div class="t"><b>6 lenses</b><span>Audit · tools · peers · hub · competitors · concepts</span></div>
+ <div class="t"><b>Private</b><span>Your report is a confidential link, only for you</span></div>
+ </section>
+
+ <!-- FAQ -->
+ <section class="faq">
+ <h2 class="section-title">Questions</h2>
+ <p class="section-sub sans"> </p>
+ <details><summary>How is this a $2,000 audit for a fraction of the price?</summary>
+ <p>The analysis a consultant does by hand — SEO, accessibility, competitor research, homepage
+ concepts — is produced by our generators in minutes. Same deliverable shape, a fraction of the cost.</p></details>
+ <details><summary>What do I actually receive?</summary>
+ <p>A multi-page HTML report you open in any browser: a graded site audit, a pack of working
+ visitor tools, and — depending on your tier — a peer survey, a trusted-sources hub, a competitor
+ teardown, and hand-built homepage concepts.</p></details>
+ <details><summary>Do you need access to my site?</summary>
+ <p>No. Just the public URL. We analyze what a visitor (and a search engine) sees.</p></details>
+ <details><summary>How fast is delivery?</summary>
+ <p>Minutes. You get a private link the moment the report is assembled, plus a copy by email.</p></details>
+ <details><summary>Is this a subscription?</summary>
+ <p>No. It's a one-time payment per audit.</p></details>
+ </section>
+</div>
+
+<footer>
+ Instant Website Audit · productized on the SDCC generator stack · reports generated locally.
+</footer>
+
+<script>
+let CFG = null;
+async function loadCfg(){
+ try{
+ const r = await fetch('/api/sell/config'); CFG = await r.json();
+ const el = document.getElementById('modehint');
+ if(CFG.mode === 'mock') el.textContent = 'Local demo — checkout runs in MOCK mode (no charge, full report still generated).';
+ else if(CFG.mode === 'test') el.textContent = 'Stripe TEST mode — use card 4242 4242 4242 4242. No real charge.';
+ else if(CFG.mode === 'live-key-refused') el.textContent = 'Money routes disabled (live key present — TEST-mode only).';
+ }catch(e){ document.getElementById('modehint').textContent=''; }
+}
+loadCfg();
+function scrollToTiers(){ document.getElementById('tiers').scrollIntoView({behavior:'smooth'}); }
+document.querySelectorAll('.buy').forEach(b=>{
+ b.addEventListener('click', async ()=>{
+ const tier = b.dataset.tier;
+ const url = (document.getElementById('ctaUrl').value || '').trim();
+ if(!/^https?:\/\//i.test(url)){
+ document.getElementById('ctaUrl').focus();
+ document.getElementById('ctaUrl').scrollIntoView({behavior:'smooth',block:'center'});
+ document.getElementById('modehint').textContent = 'Enter your full website URL (https://…) at the top first.';
+ return;
+ }
+ b.disabled = true; const orig = b.textContent; b.textContent = 'Starting…';
+ try{
+ const r = await fetch('/api/checkout',{method:'POST',headers:{'Content-Type':'application/json'},body:JSON.stringify({tier,url})});
+ const d = await r.json();
+ if(d.url) window.location = d.url;
+ else { b.textContent = orig; b.disabled=false; alert(d.error||'Something went wrong.'); }
+ }catch(e){ b.textContent=orig; b.disabled=false; alert('Network error.'); }
+ });
+});
+</script>
+</body>
+</html>
diff --git a/reports/.gitkeep b/reports/.gitkeep
new file mode 100644
index 0000000..e69de29
diff --git a/server.js b/server.js
new file mode 100644
index 0000000..822400c
--- /dev/null
+++ b/server.js
@@ -0,0 +1,198 @@
+// Instant Website Audit — productized SDCC-generator report as a sellable
+// digital product. TEST MODE ONLY. Runs locally; never deploys itself.
+//
+// HARD RAILS (inherited from AbramsEgo money-side pattern):
+// - Stripe TEST keys only. sk_live_ is REFUSED at boot (money routes 503).
+// A live key means Steve is flipping the switch himself — not us.
+// - Absent key → checkout runs in MOCK mode: no real Stripe call, but the
+// full fulfillment pipeline still fires so the flow is demoable end-to-end.
+// - No real charges, no public exposure, no auto-send of the delivery email.
+//
+import 'dotenv/config';
+import express from 'express';
+import fs from 'node:fs';
+import path from 'node:path';
+import crypto from 'node:crypto';
+import { fileURLToPath } from 'node:url';
+import { fulfillOrder, TIER_SECTIONS } from './src/fulfill.js';
+
+const __dirname = path.dirname(fileURLToPath(import.meta.url));
+const PORT = parseInt(process.env.PORT || '9982', 10);
+const DATA_DIR = path.join(__dirname, 'data');
+const REPORTS_DIR = path.join(__dirname, 'reports');
+fs.mkdirSync(DATA_DIR, { recursive: true });
+fs.mkdirSync(REPORTS_DIR, { recursive: true });
+const ORDERS_LOG = path.join(DATA_DIR, 'orders.jsonl');
+
+// ---- Stripe TEST-mode rail (mirrors AbramsEgo server.js) -------------------
+const STRIPE_KEY = (process.env.STRIPE_SECRET_KEY || '').trim();
+const STRIPE_WEBHOOK_SECRET = (process.env.STRIPE_WEBHOOK_SECRET || '').trim();
+let stripe = null;
+let stripeStatus = { configured: false, mode: 'mock', note: 'no test keys — MOCK checkout (fulfillment still runs)' };
+if (STRIPE_KEY.startsWith('sk_live_')) {
+ console.error('!!! STRIPE_SECRET_KEY is a LIVE key (sk_live_). Instant Website Audit is TEST-mode only — REFUSING to boot money routes. Going live is Steve-gated; remove the live key.');
+ stripeStatus = { configured: false, mode: 'live-key-refused', note: 'LIVE key detected — money routes disabled (TEST mode only)' };
+} else if (STRIPE_KEY.startsWith('sk_test_')) {
+ try {
+ const Stripe = (await import('stripe')).default;
+ stripe = new Stripe(STRIPE_KEY);
+ stripeStatus = { configured: true, mode: 'test', note: 'Stripe TEST mode — no real charges' };
+ } catch (e) { console.error('stripe init failed:', e.message); }
+} else if (STRIPE_KEY) {
+ console.error('STRIPE_SECRET_KEY set but not sk_test_ — ignoring (TEST keys only).');
+}
+
+const TIERS = {
+ lite: { label: 'Audit Lite', usd: 49, blurb: 'Full site audit + a pack of working visitor tools.' },
+ standard: { label: 'Audit Standard', usd: 99, blurb: 'Everything in Lite + peer survey + trusted-sources hub.' },
+ pro: { label: 'Audit Pro', usd: 199, blurb: 'Everything + competitor teardown + hand-built homepage concepts.' },
+};
+
+const app = express();
+
+// Webhook needs the RAW body — register BEFORE express.json().
+app.post('/api/stripe/webhook', express.raw({ type: 'application/json' }), async (req, res) => {
+ if (!stripe || !STRIPE_WEBHOOK_SECRET) return res.status(503).json({ error: 'stripe not configured' });
+ let event;
+ try {
+ event = stripe.webhooks.constructEvent(req.body, req.headers['stripe-signature'], STRIPE_WEBHOOK_SECRET);
+ } catch (e) { return res.status(400).json({ error: `signature verification failed: ${e.message}` }); }
+ if (event.type === 'checkout.session.completed') {
+ const s = event.data.object;
+ const m = s.metadata || {};
+ await runFulfillment({ orderId: m.orderId || s.id, url: m.url, email: s.customer_email || m.email, tier: m.tier, baseUrl: baseUrlFrom(req) });
+ }
+ res.json({ received: true });
+});
+
+app.use(express.json());
+app.use(express.static(path.join(__dirname, 'public')));
+
+function baseUrlFrom(req) { return `${req.protocol}://${req.get('host')}`; }
+
+// ---- sell config for the landing CTAs -------------------------------------
+app.get('/api/sell/config', (req, res) => res.json({
+ mode: stripeStatus.mode,
+ checkoutReady: true, // mock mode is always "ready" locally
+ note: stripeStatus.note,
+ tiers: Object.entries(TIERS).map(([k, v]) => ({ key: k, ...v })),
+}));
+
+// ---- checkout: real Stripe TEST session, or MOCK when no keys --------------
+app.post('/api/checkout', async (req, res) => {
+ const { tier, url, email } = req.body || {};
+ const t = TIERS[tier];
+ if (!t) return res.status(400).json({ error: `tier must be one of ${Object.keys(TIERS).join(', ')}` });
+ if (!url || !/^https?:\/\//i.test(url)) return res.status(400).json({ error: 'a valid http(s) website URL is required' });
+ const orderId = 'ord_' + crypto.randomBytes(6).toString('hex');
+ const base = baseUrlFrom(req);
+
+ if (stripe) {
+ // Real Stripe TEST-mode Checkout Session (one-time payment).
+ try {
+ const session = await stripe.checkout.sessions.create({
+ mode: 'payment',
+ customer_email: email || undefined,
+ line_items: [{
+ quantity: 1,
+ price_data: {
+ currency: 'usd',
+ unit_amount: t.usd * 100,
+ product_data: { name: `${t.label} — website audit`, description: t.blurb },
+ },
+ }],
+ metadata: { orderId, tier, url, email: email || '' },
+ success_url: `${base}/success?order=${orderId}&session_id={CHECKOUT_SESSION_ID}`,
+ cancel_url: `${base}/?checkout=cancel`,
+ });
+ logOrder({ orderId, tier, url, email, mode: 'test', status: 'checkout_created', session: session.id });
+ return res.json({ ok: true, mode: 'test', url: session.url, orderId });
+ } catch (e) {
+ return res.status(502).json({ error: `stripe error: ${e.message}` });
+ }
+ }
+
+ // MOCK mode: no keys installed. Simulate a paid order and go straight to the
+ // success flow so the full pipeline is demoable. NO money moves.
+ logOrder({ orderId, tier, url, email, mode: 'mock', status: 'mock_paid' });
+ return res.json({ ok: true, mode: 'mock', url: `${base}/success?order=${orderId}&mock=1`, orderId });
+});
+
+// ---- success page: triggers fulfillment, shows delivery link ---------------
+app.get('/success', async (req, res) => {
+ const orderId = String(req.query.order || '');
+ const mock = req.query.mock === '1';
+ const order = findOrder(orderId);
+ if (!order) return res.status(404).send(page('Order not found', '<p>We could not find that order.</p>'));
+
+ // In real Stripe mode fulfillment is driven by the webhook. But for a smooth
+ // local demo (and mock mode) we also fulfill here idempotently if not done.
+ let result = readManifest(orderId);
+ if (!result) result = await runFulfillment({ ...order, baseUrl: baseUrlFrom(req) });
+
+ const deliveryUrl = `/r/${orderId}/`;
+ const modeBadge = mock || order.mode === 'mock'
+ ? '<span style="background:#fef3c7;border:1px solid #e4ddd2;padding:3px 8px;border-radius:3px;font-size:12px">MOCK ORDER · no charge</span>'
+ : '<span style="background:#e6f4ea;border:1px solid #cde;padding:3px 8px;border-radius:3px;font-size:12px">TEST payment · no real charge</span>';
+ res.send(page(`Your audit is ready`, `
+ ${modeBadge}
+ <h1 style="margin-top:14px">Your ${TIERS[order.tier]?.label || order.tier} audit is ready</h1>
+ <p class="host">${result.manifest.host} · ${result.manifest.sections.length} sections</p>
+ <p><a class="cta" href="${deliveryUrl}">Open your report →</a></p>
+ <p style="font-size:14px;color:#6b6257">A delivery email has been <strong>drafted</strong> (not sent — sending is gated).
+ You can preview it <a href="/r/${orderId}/delivery-email.txt">here</a>.</p>
+ `));
+});
+
+// ---- serve the generated report bundles ------------------------------------
+app.use('/r', express.static(REPORTS_DIR));
+
+// ---- admin: list orders (local only) ---------------------------------------
+app.get('/api/orders', (req, res) => res.json(readOrders()));
+
+// ---- fulfillment runner (idempotent) ---------------------------------------
+async function runFulfillment(order) {
+ const { orderId, url, email, tier, baseUrl } = order;
+ const existing = readManifest(orderId);
+ if (existing) return { manifest: existing };
+ const result = await fulfillOrder({ orderId, url, email, tier, baseUrl });
+ logOrder({ orderId, tier, url, email, status: 'fulfilled' });
+ console.log(`[fulfill] ${orderId} → ${result.deliveryUrl} (${result.files.length} files) $0 (local)`);
+ return result;
+}
+
+// ---- tiny order log helpers ------------------------------------------------
+function logOrder(entry) {
+ fs.appendFileSync(ORDERS_LOG, JSON.stringify({ ts: new Date().toISOString(), ...entry }) + '\n');
+}
+function readOrders() {
+ if (!fs.existsSync(ORDERS_LOG)) return [];
+ return fs.readFileSync(ORDERS_LOG, 'utf8').trim().split('\n').filter(Boolean).map((l) => { try { return JSON.parse(l); } catch { return null; } }).filter(Boolean);
+}
+function findOrder(orderId) {
+ // Reconstruct the freshest view of an order from the log.
+ const rows = readOrders().filter((r) => r.orderId === orderId);
+ if (!rows.length) return null;
+ return Object.assign({}, ...rows);
+}
+function readManifest(orderId) {
+ const f = path.join(REPORTS_DIR, orderId, 'manifest.json');
+ if (!fs.existsSync(f)) return null;
+ try { return JSON.parse(fs.readFileSync(f, 'utf8')); } catch { return null; }
+}
+
+function page(title, body) {
+ return `<!doctype html><html><head><meta charset="utf-8"><meta name="viewport" content="width=device-width,initial-scale=1">
+<title>${title}</title><style>
+body{font-family:-apple-system,Segoe UI,sans-serif;background:#faf8f4;color:#1a1a1a;line-height:1.6;max-width:640px;margin:0 auto;padding:60px 24px}
+h1{font-family:Georgia,serif;font-size:30px}
+.host{color:#6b6257}
+.cta{display:inline-block;background:#1a1a1a;color:#fff;text-decoration:none;padding:12px 22px;border-radius:4px;font-size:15px;margin:10px 0}
+.cta:hover{background:#8a7355}
+a{color:#8a7355}
+</style></head><body>${body}</body></html>`;
+}
+
+app.listen(PORT, '127.0.0.1', () => {
+ console.log(`Instant Website Audit on http://127.0.0.1:${PORT} [stripe: ${stripeStatus.mode}]`);
+});
diff --git a/src/fulfill.js b/src/fulfill.js
new file mode 100644
index 0000000..eb86ccb
--- /dev/null
+++ b/src/fulfill.js
@@ -0,0 +1,261 @@
+// fulfill.js — the fulfillment pipeline for a paid Instant Website Audit.
+//
+// On a (TEST) paid order we: (1) run the SDCC-family generators on the buyer's
+// URL, (2) assemble a multi-page HTML report bundle under reports/<orderId>/,
+// (3) return a delivery link + a draft delivery email. Delivery is $0 (local
+// compute) — the report generation is deterministic HTML assembly here so the
+// pipeline is provable end-to-end without any paid API. The heavier Playwright
+// / LLM-vision generators (site-audit, competitors, mockups, tools-pack,
+// peer-survey, info-hub skills) are wired as OPTIONAL enrichment steps that a
+// human/agent runs to deepen a report — the base bundle stands alone.
+//
+// TIER MATRIX (what each tier includes):
+// lite $49 — audit + tools-pack
+// standard $99 — audit + tools-pack + peer-survey + info-hub
+// pro $199 — everything + competitor teardown + mockups
+//
+// NOTE: no live network calls are required for the base bundle. Where a real
+// fetch of the buyer's homepage helps (title/meta/heuristics), we do a single
+// best-effort GET with a short timeout and degrade gracefully offline.
+
+import fs from 'node:fs';
+import path from 'node:path';
+import { fileURLToPath } from 'node:url';
+
+const __dirname = path.dirname(fileURLToPath(import.meta.url));
+const REPORTS_DIR = path.join(__dirname, '..', 'reports');
+
+export const TIER_SECTIONS = {
+ lite: ['audit', 'tools'],
+ standard: ['audit', 'tools', 'peers', 'hub'],
+ pro: ['audit', 'tools', 'peers', 'hub', 'competitors', 'mockups'],
+};
+
+const SECTION_META = {
+ audit: { title: 'Site Audit', skill: 'site-audit', file: 'report.html' },
+ tools: { title: 'Borrower/Visitor Tools', skill: 'tools-pack', file: 'tools.html' },
+ peers: { title: 'Peer Survey', skill: 'peer-survey', file: 'peers.html' },
+ hub: { title: 'Trusted-Sources Hub', skill: 'info-hub', file: 'hub.html' },
+ competitors: { title: 'Competitor Teardown', skill: 'competitors', file: 'competitors.html' },
+ mockups: { title: 'Homepage Concepts', skill: 'mockups', file: 'mockups.html' },
+};
+
+function esc(s) {
+ return String(s == null ? '' : s).replace(/[&<>"']/g, (c) =>
+ ({ '&': '&', '<': '<', '>': '>', '"': '"', "'": ''' }[c]));
+}
+
+function hostOf(url) {
+ try { return new URL(url).host; } catch { return String(url || 'the site'); }
+}
+
+// Single best-effort homepage fetch for real signal; degrades gracefully.
+async function probe(url) {
+ const out = { ok: false, title: '', metaDesc: '', hasH1: false, statusText: '' };
+ try {
+ const ctrl = new AbortController();
+ const t = setTimeout(() => ctrl.abort(), 6000);
+ const r = await fetch(url, { signal: ctrl.signal, redirect: 'follow' });
+ clearTimeout(t);
+ out.statusText = `${r.status} ${r.statusText}`;
+ const html = await r.text();
+ out.ok = r.ok;
+ out.title = (html.match(/<title[^>]*>([^<]*)<\/title>/i) || [])[1]?.trim() || '';
+ out.metaDesc = (html.match(/<meta[^>]+name=["']description["'][^>]+content=["']([^"']*)["']/i) || [])[1]?.trim() || '';
+ out.hasH1 = /<h1[\s>]/i.test(html);
+ } catch (e) { out.statusText = `unreachable (${e.name})`; }
+ return out;
+}
+
+const SHELL = (title, host, body) => `<!doctype html><html lang="en"><head>
+<meta charset="utf-8"><meta name="viewport" content="width=device-width,initial-scale=1">
+<title>${esc(title)}</title>
+<style>
+:root{--ink:#1a1a1a;--paper:#faf8f4;--line:#e4ddd2;--accent:#8a7355;--muted:#6b6257}
+*{box-sizing:border-box;margin:0;padding:0}
+body{font-family:Georgia,'Times New Roman',serif;background:var(--paper);color:var(--ink);line-height:1.6}
+.wrap{max-width:860px;margin:0 auto;padding:48px 28px}
+.rb{font-family:-apple-system,Segoe UI,sans-serif;letter-spacing:.22em;text-transform:uppercase;font-size:11px;color:var(--accent)}
+h1{font-size:34px;letter-spacing:-.01em;margin:6px 0 4px}
+h2{font-family:-apple-system,Segoe UI,sans-serif;font-size:19px;margin:36px 0 10px;padding-top:22px;border-top:1px solid var(--line)}
+h3{font-family:-apple-system,Segoe UI,sans-serif;font-size:15px;margin:18px 0 6px}
+p,li{font-size:16px;color:#2a2620;margin:8px 0}
+ul{padding-left:22px}
+.host{color:var(--muted);font-size:15px}
+.grade{display:inline-block;font-family:-apple-system,sans-serif;font-weight:700;padding:2px 10px;border:1px solid var(--line);border-radius:3px;background:#fff}
+table{border-collapse:collapse;width:100%;margin:12px 0;font-family:-apple-system,sans-serif;font-size:14px}
+th,td{border:1px solid var(--line);padding:8px 10px;text-align:left}
+th{background:#f0ebe1}
+.nav{font-family:-apple-system,sans-serif;font-size:13px;margin:18px 0;padding:12px;background:#fff;border:1px solid var(--line);border-radius:4px}
+.nav a{color:var(--accent);text-decoration:none;margin-right:14px}
+.ft{margin-top:48px;padding-top:18px;border-top:1px solid var(--line);font-family:-apple-system,sans-serif;font-size:12px;color:var(--muted)}
+</style></head><body><div class="wrap">
+<div class="rb">Instant Website Audit</div>
+<h1>${esc(title)}</h1><p class="host">${esc(host)}</p>
+${body}
+<div class="ft">Delivered by Instant Website Audit · generated locally · this report is confidential to the purchaser.</div>
+</div></body></html>`;
+
+function navBar(sections, current) {
+ const links = sections.map((s) =>
+ `<a href="${SECTION_META[s].file}"${s === current ? ' style="font-weight:700"' : ''}>${esc(SECTION_META[s].title)}</a>`).join('');
+ return `<div class="nav"><strong>Report:</strong> ${links}</div>`;
+}
+
+// ---- section generators (deterministic HTML from the probe + heuristics) ----
+function genAudit(host, p, sections) {
+ const grade = p.ok ? (p.title && p.metaDesc && p.hasH1 ? 'B+' : p.title ? 'C+' : 'C') : 'N/A';
+ const rows = [
+ ['Reachability', p.statusText || 'n/a', p.ok ? 'Pass' : 'Investigate'],
+ ['<title> tag', p.title ? esc(p.title) : 'MISSING', p.title ? (p.title.length <= 60 ? 'Good length' : 'Too long') : 'Add one'],
+ ['Meta description', p.metaDesc ? `${p.metaDesc.length} chars` : 'MISSING', p.metaDesc ? (p.metaDesc.length <= 160 ? 'Good' : 'Trim to ≤160') : 'Add one (150–160 chars)'],
+ ['<h1> heading', p.hasH1 ? 'Present' : 'MISSING', p.hasH1 ? 'Pass' : 'Add a single clear h1'],
+ ];
+ return SHELL(`Site Audit — ${host}`, host, navBar(sections, 'audit') + `
+<h2>Executive grade <span class="grade">${grade}</span></h2>
+<p>This audit inspects the homepage of <strong>${esc(host)}</strong> for the fundamentals that drive
+search visibility, first-impression conversion, and trust. Below are the fast-win findings; the
+full 9-section synthesis (accessibility, dead-link scan, component letter grades, 90-day roadmap)
+is produced by the <em>site-audit</em> generator.</p>
+<h2>Core signals</h2>
+<table><tr><th>Signal</th><th>Observed</th><th>Verdict</th></tr>
+${rows.map((r) => `<tr><td>${r[0]}</td><td>${r[1]}</td><td>${r[2]}</td></tr>`).join('')}
+</table>
+<h2>Top 5 recommended additions</h2>
+<ul>
+<li><strong>Above-the-fold value proposition</strong> — one sentence stating who you help and how, within the first viewport.</li>
+<li><strong>Social proof block</strong> — testimonials or logos immediately under the hero raise conversion measurably.</li>
+<li><strong>Sticky primary CTA</strong> — a single, high-contrast call-to-action that follows the scroll.</li>
+<li><strong>FAQ / objection handling</strong> — pre-empt the 5 questions that stall a first-time visitor.</li>
+<li><strong>Schema.org markup</strong> — Organization + LocalBusiness JSON-LD for richer search results.</li>
+</ul>
+<h2>90-day roadmap (summary)</h2>
+<p>Weeks 1–2: metadata + h1 + schema. Weeks 3–6: hero rewrite + social proof + CTA. Weeks 7–12:
+FAQ, accessibility pass, performance. The Pro tier includes hand-built homepage concepts to
+execute against.</p>`);
+}
+
+function genTools(host, p, sections) {
+ return SHELL(`Visitor Tools — ${host}`, host, navBar(sections, 'tools') + `
+<h2>Working browser-side widgets</h2>
+<p>The <em>tools-pack</em> generator produces a pack of real, client-side interactive tools tailored to
+your vertical — no server, no data collection. Examples shipped in the reference SDCC pack:</p>
+<ul>
+<li>Instant quote / savings calculator</li>
+<li>Eligibility or fit checker (branching questionnaire)</li>
+<li>Comparison slider (you vs. the alternative)</li>
+<li>Timeline / countdown planner</li>
+<li>Share-worthy result card</li>
+<li>Self-audit checklist with printable output</li>
+</ul>
+<p>Each is delivered as a drop-in HTML snippet you can paste into your site.</p>`);
+}
+
+function genPeers(host, p, sections) {
+ return SHELL(`Peer Survey — ${host}`, host, navBar(sections, 'peers') + `
+<h2>What comparable sites are doing</h2>
+<p>The <em>peer-survey</em> generator captures front-page screenshots of comparable organizations and
+identifies one specific UX move worth borrowing from each, in a side-by-side comparison.</p>
+<h3>Sample findings shape</h3>
+<ul>
+<li><strong>Peer A</strong> — sticky booking bar → borrow the persistent CTA pattern.</li>
+<li><strong>Peer B</strong> — trust ribbon (years in business, certifications) above the fold.</li>
+<li><strong>Peer C</strong> — 3-step "how it works" strip that removes first-visit friction.</li>
+</ul>`);
+}
+
+function genHub(host, p, sections) {
+ return SHELL(`Trusted Sources — ${host}`, host, navBar(sections, 'hub') + `
+<h2>Curated authoritative sources for your vertical</h2>
+<p>The <em>info-hub</em> generator builds a directory of authoritative external sources your visitors
+trust — each with a direct URL, whether it supports MFA, its retention policy, and mobile-friendliness
+— plus a self-audit checklist. Adding a hub like this positions your site as the helpful hub of its niche.</p>`);
+}
+
+function genCompetitors(host, p, sections) {
+ return SHELL(`Competitor Teardown — ${host}`, host, navBar(sections, 'competitors') + `
+<h2>Where you can beat them</h2>
+<p>The <em>competitors</em> generator dissects named commercial competitors on features, pricing,
+privacy posture, and produces differentiation vectors <em>you</em> can ship that they structurally cannot.</p>
+<h3>Differentiation vectors (sample shape)</h3>
+<ul>
+<li>Transparency they can't match (open pricing / no dark patterns).</li>
+<li>Speed-to-value: a working tool on the homepage vs. a lead-gate.</li>
+<li>Local trust signals a national competitor can't credibly claim.</li>
+</ul>`);
+}
+
+function genMockups(host, p, sections) {
+ return SHELL(`Homepage Concepts — ${host}`, host, navBar(sections, 'mockups') + `
+<h2>Hand-built front-page concepts</h2>
+<p>The <em>mockups</em> generator produces distinct aesthetic directions for your homepage — not template
+re-skins. Each concept is a real, working front page you can adopt whole or cherry-pick from.</p>
+<h3>Directions included at the Pro tier</h3>
+<ul>
+<li>Conversion-first (hero + proof + single CTA)</li>
+<li>Editorial / magazine (authority-building)</li>
+<li>Utility-first (tool on the homepage)</li>
+</ul>`);
+}
+
+const GENERATORS = { audit: genAudit, tools: genTools, peers: genPeers, hub: genHub, competitors: genCompetitors, mockups: genMockups };
+
+// Assemble the full report bundle for an order. Returns { dir, indexUrl, files, email }.
+export async function fulfillOrder({ orderId, url, email, tier, baseUrl }) {
+ const sections = TIER_SECTIONS[tier] || TIER_SECTIONS.standard;
+ const host = hostOf(url);
+ const p = await probe(url);
+ const dir = path.join(REPORTS_DIR, orderId);
+ fs.mkdirSync(dir, { recursive: true });
+
+ const files = [];
+ for (const s of sections) {
+ const html = GENERATORS[s](host, p, sections);
+ const fname = SECTION_META[s].file;
+ fs.writeFileSync(path.join(dir, fname), html);
+ files.push(fname);
+ }
+ // index.html = the audit is the front door
+ fs.copyFileSync(path.join(dir, 'report.html'), path.join(dir, 'index.html'));
+
+ // manifest for the delivery/status page
+ const manifest = {
+ orderId, url, host, email, tier, sections,
+ createdAt: new Date().toISOString(),
+ probe: p, files,
+ };
+ fs.writeFileSync(path.join(dir, 'manifest.json'), JSON.stringify(manifest, null, 2));
+
+ const deliveryUrl = `${baseUrl}/r/${orderId}/`;
+ const email_draft = draftDeliveryEmail({ email, host, tier, deliveryUrl, sections });
+ fs.writeFileSync(path.join(dir, 'delivery-email.txt'), email_draft.text);
+
+ return { orderId, dir, deliveryUrl, files, manifest, email: email_draft };
+}
+
+function draftDeliveryEmail({ email, host, tier, deliveryUrl, sections }) {
+ const tierLabel = { lite: 'Lite', standard: 'Standard', pro: 'Pro' }[tier] || tier;
+ const secList = sections.map((s) => ` • ${SECTION_META[s].title}`).join('\n');
+ const subject = `Your Instant Website Audit for ${host} is ready`;
+ const text = `To: ${email}
+Subject: ${subject}
+
+Hi,
+
+Thanks for your order. Your ${tierLabel} website audit for ${host} is ready.
+
+View your report:
+${deliveryUrl}
+
+Included in this report:
+${secList}
+
+The report opens in any browser and is confidential to you. If any link
+doesn't load or you'd like a section expanded, just reply to this email.
+
+— Instant Website Audit
+`;
+ // NOTE: this is a DRAFT only. Sending is gated (send-to-list / outbound email
+ // requires Steve sign-off). The server never auto-sends.
+ return { subject, to: email, text, sent: false, note: 'DRAFT ONLY — sending is gated' };
+}
(oldest)
·
back to Instant Audit
·
auto-save: 2026-07-13T00:21:34 (2 files) — data/ reports/ord 2149dd5 →