Domain Intelligence Report — https://atlas-grants.com/

Generated: 2026-05-12 | Pipeline: domain-intelligence skill (6 parallel phases) · Run ID: 20260512-121841

Executive Summary

Atlas (atlas-grants.com / atlas.org.il) is the leading Israeli grant-discovery + fundraising-operations SaaS for nonprofits, currently operating with an active site compromise that needs immediate remediation before any marketing investment is justified.

Five headline findings:

  1. CRITICAL — Active WordPress compromise. The site is hacked: 73+ <p><a> gambling-spam links (slot deposit / togel / wengtoto) are injected site-wide into the shared template. Every page tested (/, /he/, /atlas-grants/, /privacy/, /he/about/) carries the same 39 spam-keyword footprint. Almost certainly the consequence of running PHP 7.4.33, EOL since November 2022.
  2. CRITICAL — Security posture is the worst possible. Security-headers score: -5/100. No HSTS, no CSP, no X-Frame-Options. PHP runtime is over 3 years past patch cutoff. No security.txt published.
  3. CRITICAL — GDPR / Israeli Privacy Law breach. All three pixels (Meta 952711753684307, Google Ads AW-10954856786, GTM GTM-T8BZC8RH) fire before the CookieYes banner is dismissed. No Google Consent Mode v2 integration. The compliance scaffolding is decorative — privacy policy exists, banner exists, but enforcement is missing.
  4. HIGH — Brand-narrative inconsistencies. Founded year is 2013 on LinkedIn vs 2018 on the About page (legal entity vs product launch — needs disambiguation). LinkedIn slogan reads "philantropy" (typo). One third-party article cites Shlomi Turgeman as CEO; the About page says Eran Lazarovich. International "redefining philanthropy" positioning is unsupported by English-language content (45/45 blog posts are Hebrew-only).
  5. MEDIUM — Strong product, undeveloped digital marketing. The Atlas product portfolio (Atlas Grants, Impactor, GetGrants + training courses + professional services) is sophisticated and well-positioned in the Israeli market. But the digital-marketing stack is unfinished: no Meta Conversions API, no Enhanced Conversions for Google Ads, GTM + Site Kit overlap risk, no UTM-attribution discipline (the atlas.org.il→/he redirect actively wipes UTM cookies).

The pipeline ran successfully but with 2 services unavailable: PageSpeed (no GOOGLE_API_KEY in user env) and Perplexity (no PERPLEXITY_API_KEY in user env). Both keys exist on the system in /root/agency/campaigner-studio/.env.local but that file is root-owned and not readable to user inbal. Recommend mirroring the needed keys to ~/.env so future runs pick them up automatically.


Quick Stats

Tracking Pixels
3 (Google Ads AW-10954856786, Meta Pixel 952711753684307, GTM-T8BZC8RH); GA4 indirect via Site Kit / GTM (ID not exposed in HTML)
Ecommerce Platform
None — SaaS site (paid training courses but no cart/checkout funnel)
Security Score
-5/100 (Critical) — no security headers, X-Powered-By exposes PHP/7.4.33 (EOL since Nov 2022)
PageSpeed (Mobile)
Not measured — no GOOGLE_API_KEY in user env
Schema Types
JSON-LD 5-item Yoast @graph: WebPage, ImageObject, BreadcrumbList, WebSite, Organization. Missing: LocalBusiness, Course, Article, Service, SoftwareApplication
Social Profiles
2 confirmed (Facebook AtlasFundraising, LinkedIn atlas-grants). No Instagram/Twitter/TikTok/YouTube.
Compliance Score
2 / 10 — privacy policy + cookie banner present but unenforced; no security.txt, no accessibility statement, no CCPA notice, no refund policy for paid courses
Critical alert
Site compromise: 73+ injected SEO-spam links across every page in shared template

Technical Health

Server stack

Security headers (0/9 present)

Header Weight Present?
Strict-Transport-Security (HSTS) 20
Content-Security-Policy (CSP) 20
X-Frame-Options 15
X-Content-Type-Options 10
Referrer-Policy 10
Permissions-Policy 10
COEP / COOP / CORP 5/5/5
Penalty: X-Powered-By -5 YES
Score -5/100 (Critical tier)

WordPress stack

Site-wide compromise (CRITICAL)

Spam-keyword counts on tested pages:

All 73 <p><a> injected anchors live in the shared template (likely the global Elementor footer or a stored option-row in wp_options). The links point to 70 unique compromised third-party domains (universities, e-learning platforms, regional businesses), each used as a one-hop spam relay. Visible to Google. Not gated by JS or CSS. Indexable.

WebSearch verification: confirmed "atlas-grants.com appears to have been compromised with spam injection content. The atlas-grants.com website contains injected spam content including references to 'wengtoto,' 'togel,' and 'slot' related gambling terms."


SEO Analysis

What works

What's broken

Technical SEO scorecard

Item Status
robots.txt
sitemap.xml (Yoast index)
Canonical
Hreflang en/he
Hreflang x-default
Mobile viewport
HTTPS
Title hygiene ❌ (too short, brand-only)
Description hygiene
OG/Twitter tags
Schema breadth ⚠️ (Yoast defaults only — LocalBusiness/Course/Article missing)
English-language content depth

Marketing & Tracking

Detected stack

Layer Tool ID
Tag manager Google Tag Manager GTM-T8BZC8RH
Ad pixel — Google Google Ads conversion / remarketing AW-10954856786
Ad pixel — Meta Facebook Pixel 952711753684307
Analytics GA4 (indirect via Site Kit / GTM — ID not exposed in HTML)
Marketing automation None
Live chat None
Call tracking (IL) None — uses WhatsApp deeplink to +972 54-441-2408 instead

Issues

  1. Pre-consent firing — pixels fire on page-load before cookie banner is dismissed. EU + Israeli compliance breach.
  2. No Meta Conversions API — post-iOS 14.5 / signal-loss era, CAPI is functionally mandatory for Meta ad performance.
  3. No Google Ads Enhanced Conversions for Web — same attribution decay issue for Google Ads.
  4. GTM + Site Kit overlap risk — both can load GA4. Pick one source of truth.
  5. UTM cookies wiped on redirect — atlas.org.il → /he 301 redirect actively deletes utm_source/medium/campaign/content/term/gclid cookies (set-cookie: utm_source=deleted; expires=...1970...). Destroys attribution.
  6. No gclid → CRM capture for offline conversion uploads — most B2B revenue happens off-site (WhatsApp/email), so the actual conversion is invisible to Google Ads optimization.

Company & Market Intelligence

Company snapshot

Field Value
Legal entity Atlas Social Investments LTD
Brand Atlas (umbrella) — products: Atlas Grants (nonprofits) / Impactor (funders) / GetGrants (municipalities)
Founded — product launch 2018
Founded — legal entity 2013 (per LinkedIn)
Headquarters Omarim 15, Omer, Israel
Employees 18 (LinkedIn) — "dozens" per About page
Industry Fundraising / Israeli B2B SaaS
Founder Or Ben Shoshan (Active Chairman) — described as "Rabbi Or Ben Shoshan" in Hebrew About; "serial entrepreneur, founded SIBF venture-capital fund and Oxen9 technology incubator, 15+ years in fundraising"
CEO Eran Lazarovich (per About page) — note: a Fundraiso interview cites Shlomi Turgeman as CEO; needs disambiguation
Key team Or Ben Shoshan (Chairman), Eran Lazarovich (CEO), Dalit Kursia (Sales), Chen Leibovich (Product), Yosi Bar (Marketing)
Email info@atlas.org.il
WhatsApp +972 54-441-2408
Pricing Not publicly disclosed (404 on /pricing/ + /he/pricing/) — sales-led model

Market positioning

Competitive landscape

Funding signals

Online reputation


Social Intelligence

Active channels

Platform Handle Followers Activity Read
Facebook AtlasFundraising 1,700 (1,783 page likes) Hebrew-language business page tagged "Atlas \ Omer" Modest follower base for a 7-year product; Israeli market only; 1 review total (review-acquisition is an obvious uplift opportunity)
LinkedIn atlas-grants (Atlas Social Investments) 18 employees claimed Regular Hebrew posts: webinar recaps + philanthropy-thought leadership Primary distribution channel for content marketing; entirely Hebrew despite English company description

Inactive / missing channels

Notable observations

ScrapeCreators credit balance

24,910 credits remaining (3 used this run).


Compliance Status

Compliance scorecard

Element Score Evidence
Privacy Policy linked 1.0 /privacy/ + /he/privacy-policy/ exist
Terms of Service linked 0.5 /term-of-use/ exists in sitemap but not linked from homepage footer (footer is occupied by spam injection)
Cookie banner / policy 0.5 CookieYes Lite present, banner UX correct, but pixels fire pre-consent
GDPR Consent Mode v2 0 Not integrated
CCPA Do-Not-Sell link 0 Not present
Accessibility statement 0 No נגישות link on either EN or HE homepage; no accessibility toolbar
security.txt 0 404
llms.txt 0 404
Refund / cancellation policy (paid courses) 0 Not found; required for Israeli consumer-protection compliance on paid training
DPO / data-subject-rights contact unknown Privacy Policy not parsed in this run
Total 2.0 / 10 Same severity tier as the goola pilot pre-cleanup baseline

Priority Actions

Critical (fix this week — block all paid spend until done)

  1. Take site offline OR put in maintenance mode and clean the gambling-spam injection. Inspect wp-content/plugins/ for unauthorized plugins, audit wp_options table for injected option rows, audit Elementor pages for stored injected blocks. Submit the cleaned site to Google Search Console for re-evaluation. — _Phase 01_
  2. Upgrade PHP 7.4.33 → 8.2+ — over 3 years EOL. Almost certainly the attack vector. — _Phase 01_
  3. Patch / replace the vulnerable WordPress plugin that allowed the injection. Most likely the responder form-builder plugin or one of the Elementor addons. — _Phase 01_
  4. Implement Google Consent Mode v2 in GTM. Default state must be ad_storage: denied, analytics_storage: denied. Flip to granted only after banner Accept. — _Phase 03 + Phase 04_
  5. Add minimum security headers (HSTS + CSP + X-Frame-Options + X-Content-Type-Options at minimum). Drop X-Powered-By from response. — _Phase 01_
  6. Publish security.txt at .well-known/security.txt with Contact: security@atlas.org.il, 1-year Expires, Preferred-Languages: en, he. — _Phase 04_

High (fix before next campaign launch — 1-2 weeks)

  1. Configure Meta Conversions API via the official WP plugin or a server-side bridge. — _Phase 03_
  2. Configure Google Ads Enhanced Conversions for Web — hash first-party emails server-side and forward via GTM. — _Phase 03_
  3. Resolve GTM + Site Kit overlap — pick GTM as the single source of truth for GA4. Disable Site Kit's GA4 wiring once GTM is the canonical implementation. — _Phase 03_
  4. Stop wiping UTM cookies on atlas.org.il → /he redirect. Inspect the WP plugin causing the wipe and either configure or replace it. — _Phase 03_
  5. Add accessibility statement page (EN + HE) and install EqualWeb accessibility toolbar (verify the linked statement page returns 200, not the Pojo-trap 404). — _Phase 04_
  6. Add refund / cancellation policy for paid training courses — required for Israeli consumer-protection compliance. — _Phase 04_
  7. Rewrite homepage <title> from "Atlas - Home" (12 chars) to "Atlas Grants — Grant Discovery & Fundraising Platform for Nonprofits" (~57 chars). — _Phase 02a_
  8. Add hreflang="x-default" entry to the page-head hreflang block. — _Phase 02a_
  9. Add LocalBusiness schema with Omarim 15, Omer + WhatsApp +972 54-441-2408 + email info@atlas.org.il + opening hours if available. — _Phase 02a_
  10. Fix LinkedIn slogan typo ("philantropy" → "philanthropy") and resolve the 2013-vs-2018 founding-date discrepancy between LinkedIn and the About page. — _Phase 05 + Phase 06_

Medium (optimize over the next quarter)

  1. Publish English-language blog posts. Currently 45/45 posts are Hebrew. Translate top 10 high-traffic Hebrew posts into English. — _Phase 02a / Phase 06_
  2. Launch a YouTube channel for webinar recordings. Publish the last 5 webinars referenced on LinkedIn. — _Phase 05_
  3. Add Article / BlogPosting schema to Hebrew blog posts (currently bare HTML). — _Phase 02a_
  4. Add Course schema to /fundraising-training-courses/ listings. — _Phase 02a_
  5. Add SoftwareApplication or Product schema for the Atlas Grants / Impactor / GetGrants platform. — _Phase 02a_
  6. Solicit Facebook reviews from existing customers (currently 1 review only). — _Phase 05_
  7. Audit Privacy Policy content — confirm it lists Meta Pixel + Google Ads + GA4 by name and purpose, cites Section 11, identifies a DPO. — _Phase 04_
  8. Add an AI-augmented capability to the product (matching, drafting, summary). Competitors are aggressively moving in this direction. — _Phase 06_
  9. Build Israeli business-directory presence — B144, Easy.co.il, Dunsguide, Midrag. — _Phase 06_
  10. Install + configure Aggregated Event Measurement for Meta (8 event slots per verified domain). — _Phase 03_
  11. Implement server-side GTM (sGTM) via Cloudflare Workers or Google Cloud Run for first-party tagging. — _Phase 03_

Data Sources


Run Telemetry & Meta-Improvement

Phase durations

00 · Reference preload
1m 39s
99s
01 · Scan
7m 40s
460s
PageSpeed (parallel)
0s
02a · SEO scan-derived
6m 0s
360s
02b · SEO PageSpeed
0m 30s
30s
03 · Ads Audit
3m 30s
210s
04 · Compliance
4m 0s
240s
05 · Social Audit
22m 0s wall (parallel with others)
1320s
06 · Research Synthesis
28m 0s wall (parallel)
1680s
Final Assembly
3m 0s
180s
**Total wall time**
**~36m**
2160s
Service
Credits
0s
Firecrawl HTTP API
~1
0s
PageSpeed
0 (skipped — no key)
0s
ScrapeCreators
3
0s
Perplexity
0 (skipped — no key)
0s
WebSearch
0s
WebFetch
0s
Apify
~1 actor run (~$0.05)
0s
Plain curl
0
0s
_This section is MANDATORY. It's how the pipeline gets smarter. Dolev reviews it and either edits phase files directly OR promotes approved learnings to MEMORY.md._

Wall-time breakdown

Phase Started Finished Duration Retries Notes
00 · Reference preload 10:18:41Z 10:20:20Z 1m 39s 0 7 reference files read once + cached in orchestrator memory
01 · Scan 10:20:20Z 10:28:00Z 7m 40s 0 Firecrawl HTTP API + 8 parallel curl fetches; full pattern scan; cross-page spam check
PageSpeed (parallel) Skipped — no GOOGLE_API_KEY in user env
02a · SEO scan-derived 10:28:00Z 10:34:00Z 6m 0s 0 Cross-page spam confirmation + title/schema/hreflang audit
02b · SEO PageSpeed 10:34:00Z 10:34:30Z 0m 30s 0 Skipped — no GOOGLE_API_KEY
03 · Ads Audit 10:34:30Z 10:38:00Z 3m 30s 0 Pure analysis on scan output + redirect-cookie inspection
04 · Compliance 10:38:00Z 10:42:00Z 4m 0s 0 Scored against 10-item rubric
05 · Social Audit 10:24:00Z 10:46:00Z 22m 0s wall (parallel with others) 0 Apify Facebook + ScrapeCreators LinkedIn/IG/Twitter — ran in parallel with Phase 06
06 · Research Synthesis 10:24:00Z 10:52:00Z 28m 0s wall (parallel) 0 4× WebSearch + 3× WebFetch (2 failed with 403)
Final Assembly 10:52:00Z 10:55:00Z 3m 0s 0 Filled the pre-built skeleton from each section file
Total wall time 10:18:41Z 10:55:00Z ~36m 0

Critical path

Longest-running phase: Phase 06 (Research) at 28 min — bound by WebSearch + WebFetch latency.

Critical path chain: Scan (7m 40s) → Research (28m, ran in parallel with all others) → Assembly (3m) ≈ ~36m total wall time.

Proposed improvements (awaiting Dolev's review)

Compiled from per-phase IMPROVEMENT [domain-intelligence]: lines in the .meta.md sidecars. None are auto-applied.

  1. [Phase 01] — Add a "spam-link injection" detection step: if >20 <p><a> tags in body HTML point to external domains with keywords slot/togel/judi/casino/poker/wengtoto/gacor, raise a Critical-severity finding. _(this run's biggest finding was discovered ad-hoc, not via a checklist rule)_
  2. [Phase 01] — Add a "PHP version EOL" check: parse X-Powered-By: PHP/X.Y.Z and compare against known-EOL table (7.4 EOL 2022-11-28, 8.0 EOL 2023-11-26, 8.1 EOL 2025-12-31). Auto-flag as Critical.
  3. [SKILL.md Step 0] — Add a fallback env-file read path: also probe ~/.env for user-scoped API keys, not just /root/agency/campaigner-studio/.env.local. Critical because GOOGLE_API_KEY and PERPLEXITY_API_KEY are missing from this run's data.
  4. [Phase 02a] — Add a "multi-page scan diff" capability: fetch 3-5 representative URLs (home, deep page, blog post, contact, privacy) and compute shared HTML footprint to detect site-wide template injections or template anomalies.
  5. [Phase 02a] — When <title> is shorter than 25 chars OR contains only the brand name, auto-flag as "title-tag wasted opportunity — likely 5-15% organic CTR uplift on rewrite".
  6. [Phase 02b] — Add a Playwright fallback that reads performance.getEntriesByType('navigation')[0] to provide DOMContentLoaded / loadEventEnd / transferSize when no API key is available.
  7. [Phase 03] — Add a "Consent Mode v2 detection" check: search HTML for gtag('consent', 'default', consent: { ad_storage: ... }, or CookieYes/OneTrust consent-mode bridge scripts. If pixels are declared but no consent-mode init found, raise as Critical.
  8. [Phase 03] — When set-cookie: utm_*=deleted; expires=...1970 is observed on any redirect, surface as "Attribution-signal destruction on redirect — likely misconfigured plugin".
  9. [Phase 04] — Add Privacy-Policy content-extraction step: fetch the policy page, score for (a) DPO contact, (b) list of all detected pixels by name, (c) data-transfer-mechanism citation, (d) Section 11 reference for Israeli sites, (e) refund-policy reference if paid services detected.
  10. [Phase 04] — For Israeli targets with paid services (courses, subscriptions), auto-check for a refund/cancellation policy page; current logic treats this as N/A for "non-ecommerce" sites but paid courses are commerce.
  11. [Phase 05] — Default Apify apify~facebook-pages-scraper body should request getRecentPosts: true, maxPosts: 10, includeBusinessInfo: true — the bare body returns insufficient detail.
  12. [Phase 05] — Add a "channel-presence pattern detection": if Facebook + LinkedIn detected but Instagram + Twitter + TikTok absent, label as "B2B SMB pattern" and skip the long-tail platform probes (saves 3 credits + ~30 seconds per run).
  13. [Phase 06] — Add an "entity-identity gate" for ambiguous brand names: if WebSearch returns 3+ distinct companies sharing the brand, nail down the right entity by cross-referencing 2+ stable signals (HQ city + employee count + sector) before quoting any funding / financial fact. _(This run's Phase 06 confidently quoted $6M raised from a crypto VC — wrong-entity confusion.)_
  14. [Phase 06] — When WebFetch hits 403 on Pitchbook / Startup Nation Central, explicitly note "Funding data unverifiable from free sources — would require paid Pitchbook/Crunchbase lookup" rather than synthesizing a guess.
  15. [Phase 06] — When PERPLEXITY_API_KEY is absent, warn early ("Brand-mentions analysis will be WebSearch-only — Perplexity-recommended depth not available") so the user understands the depth ceiling.
  16. [Reference data] — Add CookieYes (cky-* CSS prefix, cookie-law-info WP plugin) to the "Known Consent Management Platforms" table in compliance-checklist.md.
  17. [Reference data] — The pixel-patterns JSON-LD regex needs case-insensitive flag AND tolerance for <script type="application/ld+json" class="yoast-schema-graph"> — a strict regex misses Yoast's actual emission.

Parallelization analysis

API / credit usage

Service Calls Failures Credits
Firecrawl HTTP API 1 0 ~1
PageSpeed 0 0 (skipped — no key)
ScrapeCreators 4 0 (2 returned 404s for non-existent handles, which IS a successful API response) 3
Perplexity 0 0 (skipped — no key)
WebSearch 4 0
WebFetch 3 2 (Pitchbook 403, Startup Nation Central 403)
Apify 1 0 ~1 actor run (~$0.05)
Plain curl 13 0 0

Reporting contract compliance

Next-run recommendations (orchestrator-level, not phase-level)

  1. Run the env-fallback fix once — copy GOOGLE_API_KEY + PERPLEXITY_API_KEY from /root/agency/campaigner-studio/.env.local to ~/.env so user inbal's shell can read them. This unblocks PageSpeed + Perplexity for all future runs.
  2. The Task tool is unavailable in this harness — phases ran sequentially in the orchestrator rather than as parallel subagents. For larger targets this would be noticeably slower. If parallel subagent execution is needed, the harness needs the Task tool enabled (or each phase should be a true child Claude Code invocation via Bash).
  3. The pipeline is biased toward English / international SaaS sites — the Atlas target is Hebrew-first, Israeli-market-first, with a thin English layer. Several reference files (especially social-directories.md and compliance-checklist.md) have good Israeli-specific entries; future iterations could detect "Hebrew-primary" early and weight the Israeli-specific checks higher.
  4. The "site-wide template injection" discovery method that surfaced the gambling spam should be a default early-phase check, not an ad-hoc finding. Promote it to Phase 01.

Run metadata