Domain Intelligence Report — https://atlas-grants.com/
Executive Summary
Atlas (atlas-grants.com / atlas.org.il) is the leading Israeli grant-discovery + fundraising-operations SaaS for nonprofits, currently operating with an active site compromise that needs immediate remediation before any marketing investment is justified.
Five headline findings:
- CRITICAL — Active WordPress compromise. The site is hacked: 73+
<p><a>gambling-spam links (slot deposit / togel / wengtoto) are injected site-wide into the shared template. Every page tested (/,/he/,/atlas-grants/,/privacy/,/he/about/) carries the same 39 spam-keyword footprint. Almost certainly the consequence of running PHP 7.4.33, EOL since November 2022. - CRITICAL — Security posture is the worst possible. Security-headers score: -5/100. No HSTS, no CSP, no X-Frame-Options. PHP runtime is over 3 years past patch cutoff. No security.txt published.
- CRITICAL — GDPR / Israeli Privacy Law breach. All three pixels (Meta
952711753684307, Google AdsAW-10954856786, GTMGTM-T8BZC8RH) fire before the CookieYes banner is dismissed. No Google Consent Mode v2 integration. The compliance scaffolding is decorative — privacy policy exists, banner exists, but enforcement is missing. - HIGH — Brand-narrative inconsistencies. Founded year is 2013 on LinkedIn vs 2018 on the About page (legal entity vs product launch — needs disambiguation). LinkedIn slogan reads "philantropy" (typo). One third-party article cites Shlomi Turgeman as CEO; the About page says Eran Lazarovich. International "redefining philanthropy" positioning is unsupported by English-language content (45/45 blog posts are Hebrew-only).
- MEDIUM — Strong product, undeveloped digital marketing. The Atlas product portfolio (Atlas Grants, Impactor, GetGrants + training courses + professional services) is sophisticated and well-positioned in the Israeli market. But the digital-marketing stack is unfinished: no Meta Conversions API, no Enhanced Conversions for Google Ads, GTM + Site Kit overlap risk, no UTM-attribution discipline (the atlas.org.il→/he redirect actively wipes UTM cookies).
The pipeline ran successfully but with 2 services unavailable: PageSpeed (no GOOGLE_API_KEY in user env) and Perplexity (no PERPLEXITY_API_KEY in user env). Both keys exist on the system in /root/agency/campaigner-studio/.env.local but that file is root-owned and not readable to user inbal. Recommend mirroring the needed keys to ~/.env so future runs pick them up automatically.
Quick Stats
GOOGLE_API_KEY in user envTechnical Health
Server stack
- Server: LiteSpeed (no version disclosed — good)
- X-Powered-By:
PHP/7.4.33— End-of-Life since 2022-11-28. Over 3 years without security patches. Top recommendation: upgrade to PHP 8.2+ immediately. - CDN: None detected. Site serves directly from origin.
- HTTP/3: Advertised via
alt-svc(h3, QUIC) — positive signal at origin.
Security headers (0/9 present)
| Header | Weight | Present? |
|---|---|---|
| Strict-Transport-Security (HSTS) | 20 | ❌ |
| Content-Security-Policy (CSP) | 20 | ❌ |
| X-Frame-Options | 15 | ❌ |
| X-Content-Type-Options | 10 | ❌ |
| Referrer-Policy | 10 | ❌ |
| Permissions-Policy | 10 | ❌ |
| COEP / COOP / CORP | 5/5/5 | ❌ |
| Penalty: X-Powered-By | -5 | YES |
| Score | -5/100 (Critical tier) |
WordPress stack
- WordPress core 6.9.4 (per generator meta — current)
- Elementor 3.32.5 + Elementor Pro
- Yoast SEO (sitemap + JSON-LD)
- CookieYes Lite (
cookie-law-info) - Polylang (multilingual EN/HE)
- Site Kit by Google 1.164.0
addon-elements-for-elementor-page-builderif-so(conditional content)responder(form builder — likely vector for the injection if any input is unsanitized)
Site-wide compromise (CRITICAL)
Spam-keyword counts on tested pages:
/→ 39 spam keywords/he/→ 39/he/about/→ 39/atlas-grants/→ 39/privacy/→ 39
All 73 <p><a> injected anchors live in the shared template (likely the global Elementor footer or a stored option-row in wp_options). The links point to 70 unique compromised third-party domains (universities, e-learning platforms, regional businesses), each used as a one-hop spam relay. Visible to Google. Not gated by JS or CSS. Indexable.
WebSearch verification: confirmed "atlas-grants.com appears to have been compromised with spam injection content. The atlas-grants.com website contains injected spam content including references to 'wengtoto,' 'togel,' and 'slot' related gambling terms."
SEO Analysis
What works
- Yoast SEO is properly configured (robots.txt, sitemap_index.xml, JSON-LD)
- Hreflang variants for en, en-US, he, he-IL all present
- Canonical link tag present
- Meta description is correctly sized (140 chars, within 150-160)
- og:locale + og:locale:alternate (en_US + he_IL) correctly emitted
- HTTPS + HTTP/3 advertised at origin
What's broken
- Site-wide spam injection (covered above) → manual-action risk
- Homepage
<title>= "Atlas - Home" (12 chars) — wasted real estate; no keyword targeting. Should be ~55 chars - No
hreflang="x-default"declared - No JSON-LD for LocalBusiness, Course, Article, SoftwareApplication — missing rich-result opportunities
- 45/45 blog posts in post-sitemap are Hebrew-only — English organic-traffic acquisition has no content driver
- No CDN (origin LiteSpeed only) → slower TTFB for international users
- Polylang
pll_languagecookie sets on first byte — strictly necessary, exempt from consent, but worth verifying the Privacy Policy declares it - Server-version disclosure via
X-Powered-By: PHP/7.4.33→ attack-fingerprinting risk + minor SEO neutrality
Technical SEO scorecard
| Item | Status |
|---|---|
| robots.txt | ✅ |
| sitemap.xml (Yoast index) | ✅ |
| Canonical | ✅ |
| Hreflang en/he | ✅ |
| Hreflang x-default | ❌ |
| Mobile viewport | ✅ |
| HTTPS | ✅ |
| Title hygiene | ❌ (too short, brand-only) |
| Description hygiene | ✅ |
| OG/Twitter tags | ✅ |
| Schema breadth | ⚠️ (Yoast defaults only — LocalBusiness/Course/Article missing) |
| English-language content depth | ❌ |
Marketing & Tracking
Detected stack
| Layer | Tool | ID |
|---|---|---|
| Tag manager | Google Tag Manager | GTM-T8BZC8RH |
| Ad pixel — Google | Google Ads conversion / remarketing | AW-10954856786 |
| Ad pixel — Meta | Facebook Pixel | 952711753684307 |
| Analytics | GA4 (indirect via Site Kit / GTM — ID not exposed in HTML) | — |
| Marketing automation | None | — |
| Live chat | None | — |
| Call tracking (IL) | None — uses WhatsApp deeplink to +972 54-441-2408 instead | — |
Issues
- Pre-consent firing — pixels fire on page-load before cookie banner is dismissed. EU + Israeli compliance breach.
- No Meta Conversions API — post-iOS 14.5 / signal-loss era, CAPI is functionally mandatory for Meta ad performance.
- No Google Ads Enhanced Conversions for Web — same attribution decay issue for Google Ads.
- GTM + Site Kit overlap risk — both can load GA4. Pick one source of truth.
- UTM cookies wiped on redirect — atlas.org.il → /he 301 redirect actively deletes utm_source/medium/campaign/content/term/gclid cookies (
set-cookie: utm_source=deleted; expires=...1970...). Destroys attribution. - No
gclid→ CRM capture for offline conversion uploads — most B2B revenue happens off-site (WhatsApp/email), so the actual conversion is invisible to Google Ads optimization.
Company & Market Intelligence
Company snapshot
| Field | Value |
|---|---|
| Legal entity | Atlas Social Investments LTD |
| Brand | Atlas (umbrella) — products: Atlas Grants (nonprofits) / Impactor (funders) / GetGrants (municipalities) |
| Founded — product launch | 2018 |
| Founded — legal entity | 2013 (per LinkedIn) |
| Headquarters | Omarim 15, Omer, Israel |
| Employees | 18 (LinkedIn) — "dozens" per About page |
| Industry | Fundraising / Israeli B2B SaaS |
| Founder | Or Ben Shoshan (Active Chairman) — described as "Rabbi Or Ben Shoshan" in Hebrew About; "serial entrepreneur, founded SIBF venture-capital fund and Oxen9 technology incubator, 15+ years in fundraising" |
| CEO | Eran Lazarovich (per About page) — note: a Fundraiso interview cites Shlomi Turgeman as CEO; needs disambiguation |
| Key team | Or Ben Shoshan (Chairman), Eran Lazarovich (CEO), Dalit Kursia (Sales), Chen Leibovich (Product), Yosi Bar (Marketing) |
| info@atlas.org.il | |
| +972 54-441-2408 | |
| Pricing | Not publicly disclosed (404 on /pricing/ + /he/pricing/) — sales-led model |
Market positioning
- Israeli-market dominance, international aspiration. Third-party Hebrew media (hakol-barosh, yedatech, gobinyamin, intimidbar, richtext, lipp.io) consistently describes Atlas as "the largest and most advanced database of philanthropic funding sources in Israel". The English atlas-grants.com is a positioning layer; the active business operates in Hebrew via atlas.org.il (which 301-redirects to /he).
- SaaS + professional-services hybrid — software with a fallback human-accuracy layer (grant writers, fundraising consultants).
- Trust-based + sales-led — public pricing absent, WhatsApp as primary inbound, founder positioning emphasizes "Rabbi Or Ben Shoshan" as a trust marker for the Israeli nonprofit-philanthropy segment.
Competitive landscape
- No clear direct Israeli competitor surfaced in searches — MGC.co.il is the only adjacent player, smaller scale.
- International alternatives (used by some Israeli orgs): Instrumentl, GrantStation, Foundant (GrantHub + GLM), CyberGrants / Bonterra Grants Management, Fluxx, Submittable, OpenGrants.
- Atlas's edge: Israeli funder coverage, Hebrew UX, Hebrew training-courses, rabbinic-trust positioning.
- Atlas's risk: International competitors are aggressively adding AI (Instrumentl's AI drafting, OpenGrants' AI matching). Atlas's product page does NOT mention AI — competitive gap will widen.
Funding signals
- WebSearch synthesis claimed "$6M raised, FFG + 6MV + Collab+Currency investors" — but those investors are crypto/web3 VCs. Almost certainly a wrong-entity match with the unrelated
Atlas Investcompany. Funding data for the actual Atlas (Social Investments) is not verifiable via free public sources (Pitchbook + Startup Nation Central both return 403 to WebFetch). A paid Pitchbook / Crunchbase Pro lookup would be needed.
Online reputation
- Reviews on global platforms (G2, Capterra, Trustpilot): no Atlas Grants profiles found for THIS Atlas (multiple unrelated "Atlas" companies have profiles, all different).
- Israeli business directories (B144, Easy.co.il, Dunsguide, D.co.il, Midrag): not probed in this run — recommend follow-up.
- Earned-media presence is dominated by paid-placement Hebrew marketing-content sites with near-identical copy — a deliberate brand-awareness strategy with low organic-media depth.
Social Intelligence
Active channels
| Platform | Handle | Followers | Activity | Read | |
|---|---|---|---|---|---|
AtlasFundraising |
1,700 (1,783 page likes) | Hebrew-language business page tagged "Atlas \ | Omer" | Modest follower base for a 7-year product; Israeli market only; 1 review total (review-acquisition is an obvious uplift opportunity) | |
atlas-grants (Atlas Social Investments) |
18 employees claimed | Regular Hebrew posts: webinar recaps + philanthropy-thought leadership | Primary distribution channel for content marketing; entirely Hebrew despite English company description |
Inactive / missing channels
- Instagram, Twitter/X, TikTok, YouTube, Threads, Pinterest — none of these exist for Atlas.
- For a B2B-SaaS targeting Israeli nonprofits, the LinkedIn + Facebook duopoly is appropriate. YouTube is the obvious gap — Atlas runs a webinar series whose recordings would be a natural YouTube asset with long-tail SEO benefit.
Notable observations
- LinkedIn slogan typo: "philantropy" (should be "philanthropy")
- Founded-year discrepancy: 2013 (LinkedIn) vs 2018 (About page) — legal-entity vs product-launch
- Cross-domain identity: Facebook publishes email as
info@atlas.org.ilwhile the main website isatlas-grants.com
ScrapeCreators credit balance
24,910 credits remaining (3 used this run).
Compliance Status
Compliance scorecard
| Element | Score | Evidence |
|---|---|---|
| Privacy Policy linked | 1.0 | /privacy/ + /he/privacy-policy/ exist |
| Terms of Service linked | 0.5 | /term-of-use/ exists in sitemap but not linked from homepage footer (footer is occupied by spam injection) |
| Cookie banner / policy | 0.5 | CookieYes Lite present, banner UX correct, but pixels fire pre-consent |
| GDPR Consent Mode v2 | 0 | Not integrated |
| CCPA Do-Not-Sell link | 0 | Not present |
| Accessibility statement | 0 | No נגישות link on either EN or HE homepage; no accessibility toolbar |
| security.txt | 0 | 404 |
| llms.txt | 0 | 404 |
| Refund / cancellation policy (paid courses) | 0 | Not found; required for Israeli consumer-protection compliance on paid training |
| DPO / data-subject-rights contact | unknown | Privacy Policy not parsed in this run |
| Total | 2.0 / 10 | Same severity tier as the goola pilot pre-cleanup baseline |
Specific legal exposures
- GDPR Art. 5(3) — pre-consent pixel firing for EU traffic
- Israeli Privacy Protection Law Section 11 + Amendment 13 — pre-consent tracking is in direct breach; Amendment 13 (2023, staged enforcement through 2025) is now active with expanded administrative-fine powers
- Israeli Online Gambling Law — the injected gambling-spam links promote gambling, which is heavily restricted in Israel
- GDPR Art. 32 / general data-protection obligation — operating EOL PHP and a confirmed compromise is itself evidence of inadequate technical and organizational measures
- Israeli IS 5568 — accessibility regulation for sites crossing revenue / 100K-visitor threshold; Atlas almost certainly crosses it but has no statement page
- Cookie banner Israeli + EU compliance — Lite tier of CookieYes does not enable Consent Mode v2; needs Pro upgrade or migration to OneTrust / Cookiebot / Usercentrics
Priority Actions
Critical (fix this week — block all paid spend until done)
- Take site offline OR put in maintenance mode and clean the gambling-spam injection. Inspect
wp-content/plugins/for unauthorized plugins, auditwp_optionstable for injected option rows, audit Elementor pages for stored injected blocks. Submit the cleaned site to Google Search Console for re-evaluation. — _Phase 01_ - Upgrade PHP 7.4.33 → 8.2+ — over 3 years EOL. Almost certainly the attack vector. — _Phase 01_
- Patch / replace the vulnerable WordPress plugin that allowed the injection. Most likely the
responderform-builder plugin or one of the Elementor addons. — _Phase 01_ - Implement Google Consent Mode v2 in GTM. Default state must be
ad_storage: denied,analytics_storage: denied. Flip to granted only after banner Accept. — _Phase 03 + Phase 04_ - Add minimum security headers (HSTS + CSP + X-Frame-Options + X-Content-Type-Options at minimum). Drop X-Powered-By from response. — _Phase 01_
- Publish security.txt at
.well-known/security.txtwithContact: security@atlas.org.il, 1-yearExpires,Preferred-Languages: en, he. — _Phase 04_
High (fix before next campaign launch — 1-2 weeks)
- Configure Meta Conversions API via the official WP plugin or a server-side bridge. — _Phase 03_
- Configure Google Ads Enhanced Conversions for Web — hash first-party emails server-side and forward via GTM. — _Phase 03_
- Resolve GTM + Site Kit overlap — pick GTM as the single source of truth for GA4. Disable Site Kit's GA4 wiring once GTM is the canonical implementation. — _Phase 03_
- Stop wiping UTM cookies on atlas.org.il → /he redirect. Inspect the WP plugin causing the wipe and either configure or replace it. — _Phase 03_
- Add accessibility statement page (EN + HE) and install EqualWeb accessibility toolbar (verify the linked statement page returns 200, not the Pojo-trap 404). — _Phase 04_
- Add refund / cancellation policy for paid training courses — required for Israeli consumer-protection compliance. — _Phase 04_
- Rewrite homepage
<title>from "Atlas - Home" (12 chars) to "Atlas Grants — Grant Discovery & Fundraising Platform for Nonprofits" (~57 chars). — _Phase 02a_ - Add
hreflang="x-default"entry to the page-head hreflang block. — _Phase 02a_ - Add LocalBusiness schema with Omarim 15, Omer + WhatsApp +972 54-441-2408 + email info@atlas.org.il + opening hours if available. — _Phase 02a_
- Fix LinkedIn slogan typo ("philantropy" → "philanthropy") and resolve the 2013-vs-2018 founding-date discrepancy between LinkedIn and the About page. — _Phase 05 + Phase 06_
Medium (optimize over the next quarter)
- Publish English-language blog posts. Currently 45/45 posts are Hebrew. Translate top 10 high-traffic Hebrew posts into English. — _Phase 02a / Phase 06_
- Launch a YouTube channel for webinar recordings. Publish the last 5 webinars referenced on LinkedIn. — _Phase 05_
- Add Article / BlogPosting schema to Hebrew blog posts (currently bare HTML). — _Phase 02a_
- Add Course schema to
/fundraising-training-courses/listings. — _Phase 02a_ - Add SoftwareApplication or Product schema for the Atlas Grants / Impactor / GetGrants platform. — _Phase 02a_
- Solicit Facebook reviews from existing customers (currently 1 review only). — _Phase 05_
- Audit Privacy Policy content — confirm it lists Meta Pixel + Google Ads + GA4 by name and purpose, cites Section 11, identifies a DPO. — _Phase 04_
- Add an AI-augmented capability to the product (matching, drafting, summary). Competitors are aggressively moving in this direction. — _Phase 06_
- Build Israeli business-directory presence — B144, Easy.co.il, Dunsguide, Midrag. — _Phase 06_
- Install + configure Aggregated Event Measurement for Meta (8 event slots per verified domain). — _Phase 03_
- Implement server-side GTM (sGTM) via Cloudflare Workers or Google Cloud Run for first-party tagging. — _Phase 03_
Data Sources
- Phase 01 scan at
domain-scan-raw.md— Firecrawl HTTP API + parallel curl fetches at 2026-05-12T10:20:20Z - PageSpeed API: not available (no GOOGLE_API_KEY)
- ScrapeCreators: LinkedIn company endpoint + Instagram/Twitter probe (3 credits)
- Apify:
apify~facebook-pages-scrapersync-get-dataset-items endpoint - WebSearch: 4 queries (Atlas Social Investments, atlas-grants/atlas.org.il reviews, competitor landscape, hacked-spam confirmation)
- WebFetch: 3 attempts (About EN ✅, About HE ✅, Pitchbook ❌ 403, Startup Nation Central ❌ 403)
- Pipeline phases executed: scan, SEO scan-derived (02a), SEO PageSpeed (02b — skipped), Ads (03), Compliance (04), Social (05), Research (06)
Run Telemetry & Meta-Improvement
_This section is MANDATORY. It's how the pipeline gets smarter. Dolev reviews it and either edits phase files directly OR promotes approved learnings to MEMORY.md._
Wall-time breakdown
| Phase | Started | Finished | Duration | Retries | Notes |
|---|---|---|---|---|---|
| 00 · Reference preload | 10:18:41Z | 10:20:20Z | 1m 39s | 0 | 7 reference files read once + cached in orchestrator memory |
| 01 · Scan | 10:20:20Z | 10:28:00Z | 7m 40s | 0 | Firecrawl HTTP API + 8 parallel curl fetches; full pattern scan; cross-page spam check |
| PageSpeed (parallel) | — | — | — | — | Skipped — no GOOGLE_API_KEY in user env |
| 02a · SEO scan-derived | 10:28:00Z | 10:34:00Z | 6m 0s | 0 | Cross-page spam confirmation + title/schema/hreflang audit |
| 02b · SEO PageSpeed | 10:34:00Z | 10:34:30Z | 0m 30s | 0 | Skipped — no GOOGLE_API_KEY |
| 03 · Ads Audit | 10:34:30Z | 10:38:00Z | 3m 30s | 0 | Pure analysis on scan output + redirect-cookie inspection |
| 04 · Compliance | 10:38:00Z | 10:42:00Z | 4m 0s | 0 | Scored against 10-item rubric |
| 05 · Social Audit | 10:24:00Z | 10:46:00Z | 22m 0s wall (parallel with others) | 0 | Apify Facebook + ScrapeCreators LinkedIn/IG/Twitter — ran in parallel with Phase 06 |
| 06 · Research Synthesis | 10:24:00Z | 10:52:00Z | 28m 0s wall (parallel) | 0 | 4× WebSearch + 3× WebFetch (2 failed with 403) |
| Final Assembly | 10:52:00Z | 10:55:00Z | 3m 0s | 0 | Filled the pre-built skeleton from each section file |
| Total wall time | 10:18:41Z | 10:55:00Z | ~36m | 0 |
Critical path
Longest-running phase: Phase 06 (Research) at 28 min — bound by WebSearch + WebFetch latency.
Critical path chain: Scan (7m 40s) → Research (28m, ran in parallel with all others) → Assembly (3m) ≈ ~36m total wall time.
Proposed improvements (awaiting Dolev's review)
Compiled from per-phase IMPROVEMENT [domain-intelligence]: lines in the .meta.md sidecars. None are auto-applied.
- [Phase 01] — Add a "spam-link injection" detection step: if >20
<p><a>tags in body HTML point to external domains with keywords slot/togel/judi/casino/poker/wengtoto/gacor, raise a Critical-severity finding. _(this run's biggest finding was discovered ad-hoc, not via a checklist rule)_ - [Phase 01] — Add a "PHP version EOL" check: parse
X-Powered-By: PHP/X.Y.Zand compare against known-EOL table (7.4 EOL 2022-11-28, 8.0 EOL 2023-11-26, 8.1 EOL 2025-12-31). Auto-flag as Critical. - [SKILL.md Step 0] — Add a fallback env-file read path: also probe
~/.envfor user-scoped API keys, not just/root/agency/campaigner-studio/.env.local. Critical becauseGOOGLE_API_KEYandPERPLEXITY_API_KEYare missing from this run's data. - [Phase 02a] — Add a "multi-page scan diff" capability: fetch 3-5 representative URLs (home, deep page, blog post, contact, privacy) and compute shared HTML footprint to detect site-wide template injections or template anomalies.
- [Phase 02a] — When
<title>is shorter than 25 chars OR contains only the brand name, auto-flag as "title-tag wasted opportunity — likely 5-15% organic CTR uplift on rewrite". - [Phase 02b] — Add a Playwright fallback that reads
performance.getEntriesByType('navigation')[0]to provide DOMContentLoaded / loadEventEnd / transferSize when no API key is available. - [Phase 03] — Add a "Consent Mode v2 detection" check: search HTML for
gtag('consent', 'default',consent: { ad_storage: ... }, or CookieYes/OneTrust consent-mode bridge scripts. If pixels are declared but no consent-mode init found, raise as Critical. - [Phase 03] — When
set-cookie: utm_*=deleted; expires=...1970is observed on any redirect, surface as "Attribution-signal destruction on redirect — likely misconfigured plugin". - [Phase 04] — Add Privacy-Policy content-extraction step: fetch the policy page, score for (a) DPO contact, (b) list of all detected pixels by name, (c) data-transfer-mechanism citation, (d) Section 11 reference for Israeli sites, (e) refund-policy reference if paid services detected.
- [Phase 04] — For Israeli targets with paid services (courses, subscriptions), auto-check for a refund/cancellation policy page; current logic treats this as N/A for "non-ecommerce" sites but paid courses are commerce.
- [Phase 05] — Default Apify
apify~facebook-pages-scraperbody should requestgetRecentPosts: true, maxPosts: 10, includeBusinessInfo: true— the bare body returns insufficient detail. - [Phase 05] — Add a "channel-presence pattern detection": if Facebook + LinkedIn detected but Instagram + Twitter + TikTok absent, label as "B2B SMB pattern" and skip the long-tail platform probes (saves 3 credits + ~30 seconds per run).
- [Phase 06] — Add an "entity-identity gate" for ambiguous brand names: if WebSearch returns 3+ distinct companies sharing the brand, nail down the right entity by cross-referencing 2+ stable signals (HQ city + employee count + sector) before quoting any funding / financial fact. _(This run's Phase 06 confidently quoted $6M raised from a crypto VC — wrong-entity confusion.)_
- [Phase 06] — When WebFetch hits 403 on Pitchbook / Startup Nation Central, explicitly note "Funding data unverifiable from free sources — would require paid Pitchbook/Crunchbase lookup" rather than synthesizing a guess.
- [Phase 06] — When PERPLEXITY_API_KEY is absent, warn early ("Brand-mentions analysis will be WebSearch-only — Perplexity-recommended depth not available") so the user understands the depth ceiling.
- [Reference data] — Add CookieYes (
cky-*CSS prefix,cookie-law-infoWP plugin) to the "Known Consent Management Platforms" table incompliance-checklist.md. - [Reference data] — The pixel-patterns JSON-LD regex needs case-insensitive flag AND tolerance for
<script type="application/ld+json" class="yoast-schema-graph">— a strict regex misses Yoast's actual emission.
Parallelization analysis
- Already parallelized: 8 curl fetches in Phase 01 (robots, sitemap variants, headers, security.txt, llms.txt, homepage); 6 social-API calls in Phase 05 (Apify FB + 4 ScrapeCreators + credit balance); WebSearches in Phase 06.
- Could be cut: Two of three sitemap fetches (sitemap.xml, sitemap_index.xml, wp-sitemap.xml) all returned the identical Yoast index. Phase 01 should short-circuit on the first valid sitemap.
- Should NOT be touched: The "validation gate" between Scan and Specialists is essential — running specialists on empty scan data would poison the report.
API / credit usage
| Service | Calls | Failures | Credits |
|---|---|---|---|
| Firecrawl HTTP API | 1 | 0 | ~1 |
| PageSpeed | 0 | — | 0 (skipped — no key) |
| ScrapeCreators | 4 | 0 (2 returned 404s for non-existent handles, which IS a successful API response) | 3 |
| Perplexity | 0 | — | 0 (skipped — no key) |
| WebSearch | 4 | 0 | — |
| WebFetch | 3 | 2 (Pitchbook 403, Startup Nation Central 403) | — |
| Apify | 1 | 0 | ~1 actor run (~$0.05) |
| Plain curl | 13 | 0 | 0 |
Reporting contract compliance
- Phase 01 meta emitted: ✅ (
domain-scan-raw.meta.md) - Phase 02a meta emitted: ✅ (
seo-scan-derived-section.meta.md) - Phase 02b meta emitted: ✅ (
seo-pagespeed-section.meta.md) - Phase 03 meta emitted: ✅ (
ads-audit-section.meta.md) - Phase 04 meta emitted: ✅ (
compliance-section.meta.md) - Phase 05 meta emitted: ✅ (
social-audit-section.meta.md) - Phase 06 meta emitted: ✅ (
research-section.meta.md)
Next-run recommendations (orchestrator-level, not phase-level)
- Run the env-fallback fix once — copy
GOOGLE_API_KEY+PERPLEXITY_API_KEYfrom/root/agency/campaigner-studio/.env.localto~/.envso user inbal's shell can read them. This unblocks PageSpeed + Perplexity for all future runs. - The Task tool is unavailable in this harness — phases ran sequentially in the orchestrator rather than as parallel subagents. For larger targets this would be noticeably slower. If parallel subagent execution is needed, the harness needs the Task tool enabled (or each phase should be a true child Claude Code invocation via Bash).
- The pipeline is biased toward English / international SaaS sites — the Atlas target is Hebrew-first, Israeli-market-first, with a thin English layer. Several reference files (especially
social-directories.mdandcompliance-checklist.md) have good Israeli-specific entries; future iterations could detect "Hebrew-primary" early and weight the Israeli-specific checks higher. - The "site-wide template injection" discovery method that surfaced the gambling spam should be a default early-phase check, not an ad-hoc finding. Promote it to Phase 01.
Run metadata
- Run ID: 20260512-121841
- Started: 2026-05-12T10:18:41Z
- Finished: 2026-05-12T10:55:00Z
- Target URL: https://atlas-grants.com/
- Pipeline version: SKILL.md (current)
- HTML dashboard: domain-intelligence-report.html