Domain Intelligence Report — https://mgc.co.il/
Executive Summary
MGC (מל"כ — המרכז לגיוס כספים) is a 15-year-old Israeli B2B fundraising consultancy that helps nonprofits raise capital from international philanthropic foundations. The site is on a mature WordPress/Elementor stack with substantial content depth (127 posts, 56 pages, real-name client testimonials including Krembo Wings). Active paid acquisition is operational (Google Ads + GA4). The brand has real assets — domain age, content library, founder visibility (חני סודרי), bilingual delivery.
However, the technical and compliance hygiene is poor enough to be a real exposure:
- Direct breach of Israeli Privacy Protection Law Section 11 — GA4 + Google Ads pixels fire on first page load with no privacy policy, no cookie banner, no consent mechanism. Privacy policy URL paths all return 404.
- GA Universal (UA-41081389-1) still loading 22 months after Google's sunset — data has been silently dropped since July 2024.
- Robots.txt is broken — declares 2,000 phantom sitemap paths (
/abu1.xml→/abu2000.xml), all 404. Possible past hack or misconfig; wastes crawl budget. - Broken class-action settlement page in the brand's own footer (
/הסכם-פשרה-בת״צ-2555-02-21/— 404), suggesting unmet publication obligations from a 2021 consumer class action. - PHP 7.4.33 (EOL since Nov 2022) + Slider Revolution 5.4.6.3.1 (2017-era, CVE-prone) — real security and performance exposure.
- Meta Pixel missing on a brand that has an active Facebook page (2,885 followers); LinkedIn Insight Tag missing on a B2B consultancy.
The pattern is consistent: the brand has been operating on autopilot for a long time. A 1-2 week tactical fix sprint (cookie banner + privacy policy + GTM cleanup + robots.txt + missing pixels) would materially improve compliance posture and measurement.
Quick Stats
GOOGLE_API_KEYTechnical Health
- Server: LiteSpeed, HTTP/2 + HTTP/3 (QUIC) advertised
- CDN: None — direct origin
- PHP: 7.4.33 — EOL since Nov 2022, real security exposure
- Slider Revolution 5.4.6.3.1 — 2017-era version with CVE history
- 48 script tags on homepage — heavy JS footprint
- 5 empty
alt=""images on homepage - 0
<h1>tags on homepage (likely styled<h2>doing the visual job) - 2,000 phantom sitemap declarations in robots.txt
- No security headers of any kind (HSTS / CSP / X-Frame / X-CTO / Referrer-Policy / Permissions-Policy — all missing)
x-powered-by: PHP/7.4.33leaked to every response
SEO Analysis
Baseline good:
<html lang="he-IL" dir="rtl">correct- hreflang
he/en/x-defaultemitted via WPML <meta name="robots">correct (index, follow)- Canonical present
- Rich Organization + Article + WebSite JSON-LD
- Google Search Console verified
- Rank Math SEO sitemap generating valid index → 127 posts + 56 pages
- 15-year domain age + ~48+ Hebrew-language articles → strong topical authority signal
Issues:
- No H1 on homepage (styled H2 is doing the visual job)
- Title 38 chars — could grow to 50-60 with a value verb
- Meta description 99 chars — could grow to 150-160 for max SERP snippet
- Robots.txt declares 2,000 phantom sitemaps — broken / suspicious
<meta name="google" content="aHR0cHM6...">decodes to/wp-login.php— stale leftover- 5 empty
alt=""including testimonial portraits - Missing schema types:
LocalBusiness(physical office present),Review/AggregateRating(4+ testimonials unmarked),FAQPage(Q&A page exists),BreadcrumbList - No CDN — international foundation prospects browsing from US/UK get RTT penalty
- Heavy JS + Slider Revolution 5.x → likely Mobile Performance in 30-55 range (proxy estimate; PageSpeed unavailable)
Marketing & Tracking
| Layer | State |
|---|---|
| GTM | GTM-TX9W78N active |
| GA4 | G-V3WVK7HQ5E active (loaded via GTM) |
| GA Universal | UA-41081389-1 still loaded (DEAD since Jul 2024) — must remove |
| Google Ads | AW-995960650 + Conversion Linker active. Conversion label CyTACMvx28kDEMrO9NoD. Duplicate config — inline JSON + GTM — risk of double-firing. |
| Meta Pixel | MISSING despite active FB page |
| LinkedIn Insight Tag | MISSING despite active LinkedIn company page targeting B2B audience |
| Microsoft Bing UET | Missing |
| Lead-form conversion event | Not visible — no dataLayer.push or gtag('event','generate_lead') |
| Call-conversion tracking | Missing on both phone CTAs (1-800-455-455, +972-2-633-6058) |
| JoinChat plugin loaded but no phone configured / button not rendered | |
| Cookie consent / Google Consent Mode v2 | Absent |
Company & Market Intelligence
Brand: MGC / מל"כ — המרכז לגיוס כספים בע"מ (a Ltd company, NOT a nonprofit)
Founder/CEO: חני סודרי (Chani Sudri), in resource development since 2004
Address: רחוב ברקת 13, גבעת זאב
Contact: chani@mgc.co.il / 1-800-455-455 / +972-2-633-6058
Service: Grant-writing + consulting to help Israeli nonprofits raise from international philanthropic foundations
Pricing model: Success-based ("win-win") — strongly suggests a percentage-of-funds-raised fee
Named clients (homepage): Krembo Wings (כנפיים של קרמבו), העמותה לחבר הותיק דורות זבולון, האגודה למען העוור הרצליה והשרון, + others
Competitors: Atlas Grants (atlas-grants.com), Philantrom (philantrom.com), Plateck & Shacham (fundraising.org.il), Shapar (ezvonot.com), המרכז לניהול עמותות (amutotcenter.co.il), Tamir-S (solo)
Substitutes: nonprofit's in-house development team; direct-donation platforms like JGive.com
Class-action exposure: Footer links to settlement in ת״צ 2555-02-21 (Jan 2021 case) — link is 404. Substance not publicly indexed. Requires client interview + Israeli court records lookup.
Online reputation: Not found on B144 / dunsguide / easy.co.il / d.co.il directly. No press hits in TheMarker / Globes / Calcalist / Ynet under the brand name. Topical authority is mostly on-domain.
Social Intelligence
| Platform | Status | Followers / Notes |
|---|---|---|
| Facebook (facebook.com/mgc.co.il) | ✓ active | 2,885 followers/likes • Professional Service category • Phone matches site • No cross-linked socials |
| LinkedIn (company/mgc-מלכ-מרכז-גיוס-כספים-לעמותות) | ✓ exists | Metrics unavailable (anti-bot 999 + ScrapeCreators 404 on Hebrew slug) • Site links via authwall redirector (not clean direct URL) |
| YouTube (@MGCisrael) | ⚠️ abandoned | 3 subscribers • Empty description • Lowercase display name • Not linked from site |
| ❌ none | (5 candidate handles all 404) | |
| TikTok | ❌ none | (3 candidates all 404) |
| X / Twitter | ❌ none | (4 candidates all 404) |
| WhatsApp public CTA | ❌ not configured | JoinChat plugin loaded, but no number bound |
Compliance Status — 1/6 — **Poor**
| Element | Present? |
|---|---|
| Privacy Policy | ❌ — all probed URLs 404 |
| Terms of Service | ❌ — all probed URLs 404 |
| Cookies Policy | ❌ |
| Cookie consent banner | ❌ — no CMP detected |
| Accessibility Statement | ✓ — /הצהרת-נגישות/ exists |
| Accessibility widget | ✓ — Anditek (system.user-a.co.il customer 551189819) |
Critical issue: GA4 + Google Ads fire on first page load with no consent banner and no privacy notice. This is a direct breach of Israeli Privacy Protection Law Section 11 + Internet Data Regulations 2002. With Amendment 13 enforcement powers staged through 2025, this is real exposure.
Secondary: Broken footer link to settlement in ת״צ 2555-02-21 — if the original settlement required ongoing publication of the agreement (common remedy in IL consumer class actions), the broken link may itself be a compliance failure.
Priority Actions
Critical (fix immediately)
- Publish a privacy policy at
/מדיניות-פרטיות/covering GA4, Google Ads, contact-form retention, third-party transfers — link from footer. Why: direct breach of IL Privacy Protection Law Section 11; tracking pixels firing without notice. Fix: 4-6 hours including legal review. - Add a cookie consent banner (Cookiebot / OneTrust / Iubenda — most have free tiers for SMB sites) and wire to GTM with Google Consent Mode v2. Why: same Section 11 breach; required to throttle pixels until consent. Fix: 2-3 hours.
- Remove
UA-41081389-1from GTM container. Why: Google Universal Analytics has been sunset for 22 months; the tag does nothing but bloat the GTM payload. Fix: 5 minutes. - Fix
robots.txt— remove the 2,000 phantomabu*.xmlsitemap directives; replace with the valid Rank Math sitemap index. Why: wastes crawler budget; possible past-hack signal that warrants a deeper site-malware scan. Fix: 10 minutes. - Investigate and resolve the broken settlement link
/הסכם-פשרה-בת״צ-2555-02-21/. Why: if the original settlement (case 2555-02-21) required publication, the broken link is itself a compliance failure. Fix: legal consult + 1 hour. - Update PHP from 7.4 to 8.2 or 8.3. Why: PHP 7.4 has been EOL since Nov 2022 — actively unpatched CVEs. Fix: 1-2 hours (server admin task; verify WP+Elementor+WPML compat first).
High (fix before any new campaign launch)
- Install Meta Pixel + CAPI — the brand has 2,885 FB followers and no measurement. Effort: 1 hour.
- Install LinkedIn Insight Tag — primary B2B channel for nonprofit decision-makers. Effort: 30 min.
- Add lead-form conversion event (
dataLayer.push({event: 'generate_lead'})) on the Pojo contact form, wired as a Google Ads conversion. Effort: 1 hour. - Add call-conversion tracking for both phone CTAs (Google Ads call-conversion tag minimum; Maskyoo / CallApp for source attribution if budget allows). Effort: 2-4 hours.
- Update Slider Revolution from 5.4.6.3.1 to current 6.x — security + performance. Effort: 1-2 hours.
- Add an
<h1>to homepage + extend the meta description from 99 → 150 chars. Effort: 30 min. - Promote
Organizationschema toLocalBusinesswithgeo+openingHoursto qualify for local-pack. Effort: 1 hour.
Medium (optimize over time)
- Add
Review/AggregateRatingschema for existing client testimonials +FAQPageschema on/שאלות-ותשובות/. - Remove duplicate Google Ads conversion config — keep one source (GTM OR inline JSON, not both).
- De-dupe Pojo a11y CSS (Anditek is the active provider; clean up Pojo legacy classes).
- Replace LinkedIn authwall-routed link with a clean direct URL.
- Decide YouTube channel fate — revive
@MGCisraelwith content + brand rename, or abandon officially. - Configure or remove the JoinChat WhatsApp plugin (currently loads ~50KB+ of dead weight).
- Add 4 security headers:
Strict-Transport-Security,Content-Security-Policy,X-Frame-Options,X-Content-Type-Options— minimal effort, big security-score lift. - Audit empty
alt=""on testimonial portraits — replace with meaningful descriptions for screen-reader users. - Add
/.well-known/security.txtwith a security contact email.
Low
- Remove stale
<meta name="google">(decodes towp-login.php). - Set up a Google Business Profile for גבעת זאב location (if not already present).
Data Sources
- Firecrawl (
/v1/scrape) — 1 call (homepage HTML+markdown+links) - Raw curl — 4 calls (homepage HTML for script extraction, robots.txt, security.txt probe, llms.txt probe, headers)
- Sitemap probes —
/sitemap.xml,/post-sitemap.xml,/page-sitemap.xml,/wp-sitemap.xml,/sitemap_index.xml,/abu1.xml - Compliance URL probes — 8 path candidates × HEAD requests
- Apify (
apify~facebook-pages-scraper) — 1 run (Facebook profile metrics) - ScrapeCreators — 18 credits used (IG×5, YT×4, X×4, TT×3, LI×2)
- WebSearch — 5 queries (brand mentions, founder, class action, B144 listing)
- GTM container fetch — direct curl to
googletagmanager.com/gtm.js?id=GTM-TX9W78N - whois —
mgc.co.ilregistration record
Not used (API key unavailable): Google PageSpeed Insights, Perplexity. Documented as gaps in the Run Telemetry section.
Run Telemetry & Meta-Improvement
_Section is MANDATORY per skill spec. Compiled from per-phase .meta.md sidecars + orchestrator observations._
Wall-time breakdown
This run executed serially in the orchestrator's own context rather than via parallel Task() subagents — the host environment exposes WebSearch, Bash, Read, Write, and Edit but not the Task tool. So the parallelization analysis in the spec doesn't apply this run.
| Phase | Started | Finished | Duration | Retries | Notes |
|---|---|---|---|---|---|
| Pre-load + Setup | 10:01:41Z | 10:02:30Z | 49 s | 0 | Read 4 of 7 reference files (pixel-patterns, ecommerce-signatures, compliance-checklist, social-directories) |
| 01 · Scan | 10:02:30Z | 10:04:30Z | 2 m 0 s | 0 | Firecrawl + raw curl + sitemap probes + GTM container fetch |
| 02 · SEO Audit | 10:04:30Z | 10:05:30Z | 1 m 0 s | 0 | Derived from scan + GTM container; no PageSpeed signal |
| 03 · Ads Audit | 10:05:30Z | 10:06:00Z | 30 s | 0 | Derived from scan |
| 04 · Compliance | 10:06:00Z | 10:06:30Z | 30 s | 0 | Probed 8 privacy/terms paths |
| 05 · Social Audit | 10:06:30Z | 10:07:30Z | 1 m 0 s | 0 | Apify FB + ScrapeCreators IG/TT/X/YT/LI |
| 06 · Research | 10:07:30Z | 10:09:30Z | 2 m 0 s | 0 | 5 WebSearch queries + WebFetch attempt at PageSpeed |
| Final Assembly | 10:09:30Z | 10:11:00Z | 1 m 30 s | 0 | Skeleton pre-built then filled |
| Total wall time | ~9 m 20 s | 0 |
Critical path
Longest-running phases: Phase 01 Scan (2 min) + Phase 06 Research (2 min). Total critical path ≈ 9 min, dominated by Firecrawl latency + GTM container fetch in Phase 01, and serial WebSearch in Phase 06.
Proposed improvements (awaiting Dolev's review in PROPOSED.md)
_Extracted from each phase's IMPROVEMENT [domain-intelligence]: lines in its .meta.md sidecar. None are auto-applied._
- Phase 01 — Mandate the GTM container fetch when GTM is detected — this is what surfaced GA4 + dead UA Universal that the static scan missed.
- Phase 01 — Add an early "validate-firecrawl-output" gate: if Firecrawl HTML has zero
<script>tags, auto-fallback to raw curl with browser UA before pattern detection. - Phase 01 — Add Anditek (
system.user-a.co.il) to compliance-checklist.md section 8 (Israeli accessibility widgets) with its/הצהרת-נגישות/URL pattern. - Phase 02 — Mandate parsing the gtm.js container body for legacy GA Universal (UA-) tags; any UA tag in 2026+ is Critical (Universal sunset Jul 2024).
- Phase 02 — Add a robots.txt-suspicion rule: if >50
Sitemap:directives are declared, sample 1 — if 404 → flag as "suspect, possible past hack." - Phase 03 — Consume the scan phase's tracking inventory directly rather than re-running pixel detection (DRY).
- Phase 03 — Add a Critical rule:
tel:link +AW-conversion present but no call-conversion script → flag immediately. - Phase 04 — Auto-narrow the compliance checklist by detected jurisdiction (
html lang=he-IL+.co.il→ drop CCPA, prioritize IL Privacy Law). - Phase 04 — Probe any nav/footer link containing "פשרה" / "settlement" / "ת״צ" / "class action" — broken settlement-publication pages are themselves a compliance signal.
- Phase 05 — Add an ASCII / numeric-ID fallback for LinkedIn when the slug contains Hebrew / non-ASCII characters.
- Phase 05 — Add an "abandoned-channel detector" rule: subs < 100 AND empty description AND not linked from site → flag as abandoned, not as an active channel.
- Phase 06 — Auto-escalate any "ת״צ" / "פשרה" / "class action" references in nav to client-interview questions rather than wasting WebSearch budget on un-indexed cases.
- Phase 06 — Add a B144-verification rule: only report a B144 hit if the URL is a specific business slug, not a category page.
Parallelization analysis
- Already parallelized this run: HTTP probes ran in parallel via
curl -Z-style chained&(robots.txt, security.txt, llms.txt, headers). - Could be cut: Phase 06's serial WebSearch loop (~30s × 5) could run as 3 parallel
WebSearchcalls in a single tool batch. Phase 05's IG/TT/X candidate-handle scans were sequential — would benefit from batching. - Should NOT be touched: Phase 01's pre-fetch must complete before Phases 02-06 read it. The Validation Gate (>50 lines in scan output) is correct.
API / credit usage
| Service | Calls | Failures | Credits |
|---|---|---|---|
| Firecrawl | 1 | 0 | 1 credit (basic scrape) |
| Apify (FB Pages) | 1 | 0 | 1 actor run |
| ScrapeCreators | 18 | 1 (LI 404 on Hebrew slug) | 18 credits (balance: 24905 remaining) |
| PageSpeed | 1 | 1 (429 quota) | — — no key in env |
| WebSearch | 5 | 0 | n/a |
| WebFetch | 1 | 1 (PageSpeed page is JS-rendered) | n/a |
| curl (direct HTTP) | ~15 | 0 | free |
| whois | 1 | 0 | free |
Reporting contract compliance
- Phase 01 meta emitted: ✅ (
domain-scan-raw.meta.md) - Phase 02 meta emitted: ✅ (
seo-audit-section.meta.md) - Phase 03 meta emitted: ✅ (
ads-audit-section.meta.md) - Phase 04 meta emitted: ✅ (
compliance-section.meta.md) - Phase 05 meta emitted: ✅ (
social-audit-section.meta.md) - Phase 06 meta emitted: ✅ (
research-section.meta.md)
All 6 section files + 6 sidecar .meta.md files written. All emit LEARNING / FAILURE / IMPROVEMENT tagged lines.
Next-run recommendations (orchestrator's own observations)
- The skill assumes Task tool is available — this run executed serially because Task wasn't exposed in this environment. Worth adding a fall-through note in SKILL.md: "if Task tool is unavailable, the orchestrator can execute phases serially in the same context, but should note this in Run Telemetry and budget accordingly."
- Multiple API keys are now optional (GOOGLE_API_KEY, PERPLEXITY_API_KEY) — the skill should gracefully degrade per missing key rather than treating these as required. This run did.
- Reference preload was partial — 4/7 reference files loaded directly into orchestrator memory; the remaining 3 (security-headers, sitemap-locations, social-api-endpoints) were read on-demand. This worked but a stricter preload would have been cleaner.
- The phantom-sitemap robots.txt at MGC suggests a useful new "site-hygiene" sub-phase could be added: a quick set of red-flag checks (broken own-footer links + EOL versions + dead pixel IDs + phantom sitemap declarations) that produces a "technical hygiene score" 0-100.
- The Israeli market specifics worked well — MEMORY.md's entries on Maskyoo / IL call-tracking / IS-5568 / Pojo trap were directly useful. The new Anditek finding fits the same pattern and should be promoted.
Run metadata
- Run ID: 20260512-100141
- Started: 2026-05-12T10:01:41Z (13:01:41 IDT)
- Finished: 2026-05-12T10:11:00Z (13:11:00 IDT) — approximate, including report assembly
- Target URL: https://mgc.co.il/
- Pipeline version: SKILL.md last modified date — see
/home/inbal/.claude/skills/domain-intelligence/SKILL.md - Execution mode: Single-orchestrator serial (Task tool not exposed in this env — fall-through to in-context execution)
- HTML dashboard: domain-intelligence-report.html — generated by
/root/agency/.claude/skills/domain-intelligence/scripts/generate_html_report.py