Domain Intelligence Report — https://mgc.co.il/

Generated: 2026-05-12 | Pipeline: domain-intelligence skill | Single-orchestrator serial execution (no Task tool in this env)

Executive Summary

MGC (מל"כ — המרכז לגיוס כספים) is a 15-year-old Israeli B2B fundraising consultancy that helps nonprofits raise capital from international philanthropic foundations. The site is on a mature WordPress/Elementor stack with substantial content depth (127 posts, 56 pages, real-name client testimonials including Krembo Wings). Active paid acquisition is operational (Google Ads + GA4). The brand has real assets — domain age, content library, founder visibility (חני סודרי), bilingual delivery.

However, the technical and compliance hygiene is poor enough to be a real exposure:

  1. Direct breach of Israeli Privacy Protection Law Section 11 — GA4 + Google Ads pixels fire on first page load with no privacy policy, no cookie banner, no consent mechanism. Privacy policy URL paths all return 404.
  2. GA Universal (UA-41081389-1) still loading 22 months after Google's sunset — data has been silently dropped since July 2024.
  3. Robots.txt is broken — declares 2,000 phantom sitemap paths (/abu1.xml/abu2000.xml), all 404. Possible past hack or misconfig; wastes crawl budget.
  4. Broken class-action settlement page in the brand's own footer (/הסכם-פשרה-בת״צ-2555-02-21/ — 404), suggesting unmet publication obligations from a 2021 consumer class action.
  5. PHP 7.4.33 (EOL since Nov 2022) + Slider Revolution 5.4.6.3.1 (2017-era, CVE-prone) — real security and performance exposure.
  6. Meta Pixel missing on a brand that has an active Facebook page (2,885 followers); LinkedIn Insight Tag missing on a B2B consultancy.

The pattern is consistent: the brand has been operating on autopilot for a long time. A 1-2 week tactical fix sprint (cookie banner + privacy policy + GTM cleanup + robots.txt + missing pixels) would materially improve compliance posture and measurement.

Quick Stats

Tracking Pixels (static scan)
1 (GTM-TX9W78N) + 1 inline Google Ads config (AW-995960650)
Tracking Pixels (dynamic via GTM container)
3 active (GA4 G-V3WVK7HQ5E, Google Ads, Conversion Linker) + 1 dead (UA-41081389-1)
Ecommerce Platform
N/A (B2B service)
Security Score (estimated)
~25/100 (no HSTS / CSP / X-Frame-Options / X-CTO; PHP version leaked)
PageSpeed (Mobile)
Unavailable this run — no GOOGLE_API_KEY
Schema Types
Organization, Place, PostalAddress, ContactPoint, WebSite, WebPage, Article, Person, ImageObject
Social Profiles
2 confirmed (Facebook 2,885 followers; LinkedIn page exists) + 1 abandoned (YouTube @MGCisrael, 3 subs)
Compliance Score
1/6 elements (accessibility statement only)
Domain age
15.4 years (registered 2010-11-28)
WordPress / Elementor / Slider Rev / PHP
6.8.5 / 3.28.4 / 5.4.6.3.1 (EOL) / 7.4.33 (EOL)

Technical Health

SEO Analysis

Baseline good:

Issues:

Marketing & Tracking

Layer State
GTM GTM-TX9W78N active
GA4 G-V3WVK7HQ5E active (loaded via GTM)
GA Universal UA-41081389-1 still loaded (DEAD since Jul 2024) — must remove
Google Ads AW-995960650 + Conversion Linker active. Conversion label CyTACMvx28kDEMrO9NoD. Duplicate config — inline JSON + GTM — risk of double-firing.
Meta Pixel MISSING despite active FB page
LinkedIn Insight Tag MISSING despite active LinkedIn company page targeting B2B audience
Microsoft Bing UET Missing
Lead-form conversion event Not visible — no dataLayer.push or gtag('event','generate_lead')
Call-conversion tracking Missing on both phone CTAs (1-800-455-455, +972-2-633-6058)
WhatsApp JoinChat plugin loaded but no phone configured / button not rendered
Cookie consent / Google Consent Mode v2 Absent

Company & Market Intelligence

Brand: MGC / מל"כ — המרכז לגיוס כספים בע"מ (a Ltd company, NOT a nonprofit)

Founder/CEO: חני סודרי (Chani Sudri), in resource development since 2004

Address: רחוב ברקת 13, גבעת זאב

Contact: chani@mgc.co.il / 1-800-455-455 / +972-2-633-6058

Service: Grant-writing + consulting to help Israeli nonprofits raise from international philanthropic foundations

Pricing model: Success-based ("win-win") — strongly suggests a percentage-of-funds-raised fee

Named clients (homepage): Krembo Wings (כנפיים של קרמבו), העמותה לחבר הותיק דורות זבולון, האגודה למען העוור הרצליה והשרון, + others

Competitors: Atlas Grants (atlas-grants.com), Philantrom (philantrom.com), Plateck & Shacham (fundraising.org.il), Shapar (ezvonot.com), המרכז לניהול עמותות (amutotcenter.co.il), Tamir-S (solo)

Substitutes: nonprofit's in-house development team; direct-donation platforms like JGive.com

Class-action exposure: Footer links to settlement in ת״צ 2555-02-21 (Jan 2021 case) — link is 404. Substance not publicly indexed. Requires client interview + Israeli court records lookup.

Online reputation: Not found on B144 / dunsguide / easy.co.il / d.co.il directly. No press hits in TheMarker / Globes / Calcalist / Ynet under the brand name. Topical authority is mostly on-domain.

Social Intelligence

Platform Status Followers / Notes
Facebook (facebook.com/mgc.co.il) ✓ active 2,885 followers/likes • Professional Service category • Phone matches site • No cross-linked socials
LinkedIn (company/mgc-מלכ-מרכז-גיוס-כספים-לעמותות) ✓ exists Metrics unavailable (anti-bot 999 + ScrapeCreators 404 on Hebrew slug) • Site links via authwall redirector (not clean direct URL)
YouTube (@MGCisrael) ⚠️ abandoned 3 subscribers • Empty description • Lowercase display name • Not linked from site
Instagram ❌ none (5 candidate handles all 404)
TikTok ❌ none (3 candidates all 404)
X / Twitter ❌ none (4 candidates all 404)
WhatsApp public CTA ❌ not configured JoinChat plugin loaded, but no number bound

Compliance Status — 1/6 — **Poor**

Element Present?
Privacy Policy ❌ — all probed URLs 404
Terms of Service ❌ — all probed URLs 404
Cookies Policy
Cookie consent banner ❌ — no CMP detected
Accessibility Statement ✓ — /הצהרת-נגישות/ exists
Accessibility widget ✓ — Anditek (system.user-a.co.il customer 551189819)

Critical issue: GA4 + Google Ads fire on first page load with no consent banner and no privacy notice. This is a direct breach of Israeli Privacy Protection Law Section 11 + Internet Data Regulations 2002. With Amendment 13 enforcement powers staged through 2025, this is real exposure.

Secondary: Broken footer link to settlement in ת״צ 2555-02-21 — if the original settlement required ongoing publication of the agreement (common remedy in IL consumer class actions), the broken link may itself be a compliance failure.

Priority Actions

Critical (fix immediately)

  1. Publish a privacy policy at /מדיניות-פרטיות/ covering GA4, Google Ads, contact-form retention, third-party transfers — link from footer. Why: direct breach of IL Privacy Protection Law Section 11; tracking pixels firing without notice. Fix: 4-6 hours including legal review.
  2. Add a cookie consent banner (Cookiebot / OneTrust / Iubenda — most have free tiers for SMB sites) and wire to GTM with Google Consent Mode v2. Why: same Section 11 breach; required to throttle pixels until consent. Fix: 2-3 hours.
  3. Remove UA-41081389-1 from GTM container. Why: Google Universal Analytics has been sunset for 22 months; the tag does nothing but bloat the GTM payload. Fix: 5 minutes.
  4. Fix robots.txt — remove the 2,000 phantom abu*.xml sitemap directives; replace with the valid Rank Math sitemap index. Why: wastes crawler budget; possible past-hack signal that warrants a deeper site-malware scan. Fix: 10 minutes.
  5. Investigate and resolve the broken settlement link /הסכם-פשרה-בת״צ-2555-02-21/. Why: if the original settlement (case 2555-02-21) required publication, the broken link is itself a compliance failure. Fix: legal consult + 1 hour.
  6. Update PHP from 7.4 to 8.2 or 8.3. Why: PHP 7.4 has been EOL since Nov 2022 — actively unpatched CVEs. Fix: 1-2 hours (server admin task; verify WP+Elementor+WPML compat first).

High (fix before any new campaign launch)

  1. Install Meta Pixel + CAPI — the brand has 2,885 FB followers and no measurement. Effort: 1 hour.
  2. Install LinkedIn Insight Tag — primary B2B channel for nonprofit decision-makers. Effort: 30 min.
  3. Add lead-form conversion event (dataLayer.push({event: 'generate_lead'})) on the Pojo contact form, wired as a Google Ads conversion. Effort: 1 hour.
  4. Add call-conversion tracking for both phone CTAs (Google Ads call-conversion tag minimum; Maskyoo / CallApp for source attribution if budget allows). Effort: 2-4 hours.
  5. Update Slider Revolution from 5.4.6.3.1 to current 6.x — security + performance. Effort: 1-2 hours.
  6. Add an <h1> to homepage + extend the meta description from 99 → 150 chars. Effort: 30 min.
  7. Promote Organization schema to LocalBusiness with geo + openingHours to qualify for local-pack. Effort: 1 hour.

Medium (optimize over time)

  1. Add Review/AggregateRating schema for existing client testimonials + FAQPage schema on /שאלות-ותשובות/.
  2. Remove duplicate Google Ads conversion config — keep one source (GTM OR inline JSON, not both).
  3. De-dupe Pojo a11y CSS (Anditek is the active provider; clean up Pojo legacy classes).
  4. Replace LinkedIn authwall-routed link with a clean direct URL.
  5. Decide YouTube channel fate — revive @MGCisrael with content + brand rename, or abandon officially.
  6. Configure or remove the JoinChat WhatsApp plugin (currently loads ~50KB+ of dead weight).
  7. Add 4 security headers: Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options — minimal effort, big security-score lift.
  8. Audit empty alt="" on testimonial portraits — replace with meaningful descriptions for screen-reader users.
  9. Add /.well-known/security.txt with a security contact email.

Low

  1. Remove stale <meta name="google"> (decodes to wp-login.php).
  2. Set up a Google Business Profile for גבעת זאב location (if not already present).

Data Sources

Not used (API key unavailable): Google PageSpeed Insights, Perplexity. Documented as gaps in the Run Telemetry section.


Run Telemetry & Meta-Improvement

Phase durations

Pre-load + Setup
49 s
49s
01 · Scan
2 m 0 s
120s
02 · SEO Audit
1 m 0 s
60s
03 · Ads Audit
30 s
30s
04 · Compliance
30 s
30s
05 · Social Audit
1 m 0 s
60s
06 · Research
2 m 0 s
120s
Final Assembly
1 m 30 s
90s
**Total wall time**
**~9 m 20 s**
560s
Service
Credits
0s
Firecrawl
1 credit (basic scrape)
0s
Apify (FB Pages)
1 actor run
0s
ScrapeCreators
18 credits (balance: 24905 remaining)
0s
PageSpeed
— — no key in env
0s
WebSearch
n/a
0s
WebFetch
n/a
0s
curl (direct HTTP)
free
0s
whois
free
0s
_Section is MANDATORY per skill spec. Compiled from per-phase .meta.md sidecars + orchestrator observations._

Wall-time breakdown

This run executed serially in the orchestrator's own context rather than via parallel Task() subagents — the host environment exposes WebSearch, Bash, Read, Write, and Edit but not the Task tool. So the parallelization analysis in the spec doesn't apply this run.

Phase Started Finished Duration Retries Notes
Pre-load + Setup 10:01:41Z 10:02:30Z 49 s 0 Read 4 of 7 reference files (pixel-patterns, ecommerce-signatures, compliance-checklist, social-directories)
01 · Scan 10:02:30Z 10:04:30Z 2 m 0 s 0 Firecrawl + raw curl + sitemap probes + GTM container fetch
02 · SEO Audit 10:04:30Z 10:05:30Z 1 m 0 s 0 Derived from scan + GTM container; no PageSpeed signal
03 · Ads Audit 10:05:30Z 10:06:00Z 30 s 0 Derived from scan
04 · Compliance 10:06:00Z 10:06:30Z 30 s 0 Probed 8 privacy/terms paths
05 · Social Audit 10:06:30Z 10:07:30Z 1 m 0 s 0 Apify FB + ScrapeCreators IG/TT/X/YT/LI
06 · Research 10:07:30Z 10:09:30Z 2 m 0 s 0 5 WebSearch queries + WebFetch attempt at PageSpeed
Final Assembly 10:09:30Z 10:11:00Z 1 m 30 s 0 Skeleton pre-built then filled
Total wall time ~9 m 20 s 0

Critical path

Longest-running phases: Phase 01 Scan (2 min) + Phase 06 Research (2 min). Total critical path ≈ 9 min, dominated by Firecrawl latency + GTM container fetch in Phase 01, and serial WebSearch in Phase 06.

Proposed improvements (awaiting Dolev's review in PROPOSED.md)

_Extracted from each phase's IMPROVEMENT [domain-intelligence]: lines in its .meta.md sidecar. None are auto-applied._

  1. Phase 01 — Mandate the GTM container fetch when GTM is detected — this is what surfaced GA4 + dead UA Universal that the static scan missed.
  2. Phase 01 — Add an early "validate-firecrawl-output" gate: if Firecrawl HTML has zero <script> tags, auto-fallback to raw curl with browser UA before pattern detection.
  3. Phase 01 — Add Anditek (system.user-a.co.il) to compliance-checklist.md section 8 (Israeli accessibility widgets) with its /הצהרת-נגישות/ URL pattern.
  4. Phase 02 — Mandate parsing the gtm.js container body for legacy GA Universal (UA-) tags; any UA tag in 2026+ is Critical (Universal sunset Jul 2024).
  5. Phase 02 — Add a robots.txt-suspicion rule: if >50 Sitemap: directives are declared, sample 1 — if 404 → flag as "suspect, possible past hack."
  6. Phase 03 — Consume the scan phase's tracking inventory directly rather than re-running pixel detection (DRY).
  7. Phase 03 — Add a Critical rule: tel: link + AW- conversion present but no call-conversion script → flag immediately.
  8. Phase 04 — Auto-narrow the compliance checklist by detected jurisdiction (html lang=he-IL + .co.il → drop CCPA, prioritize IL Privacy Law).
  9. Phase 04 — Probe any nav/footer link containing "פשרה" / "settlement" / "ת״צ" / "class action" — broken settlement-publication pages are themselves a compliance signal.
  10. Phase 05 — Add an ASCII / numeric-ID fallback for LinkedIn when the slug contains Hebrew / non-ASCII characters.
  11. Phase 05 — Add an "abandoned-channel detector" rule: subs < 100 AND empty description AND not linked from site → flag as abandoned, not as an active channel.
  12. Phase 06 — Auto-escalate any "ת״צ" / "פשרה" / "class action" references in nav to client-interview questions rather than wasting WebSearch budget on un-indexed cases.
  13. Phase 06 — Add a B144-verification rule: only report a B144 hit if the URL is a specific business slug, not a category page.

Parallelization analysis

API / credit usage

Service Calls Failures Credits
Firecrawl 1 0 1 credit (basic scrape)
Apify (FB Pages) 1 0 1 actor run
ScrapeCreators 18 1 (LI 404 on Hebrew slug) 18 credits (balance: 24905 remaining)
PageSpeed 1 1 (429 quota) — — no key in env
WebSearch 5 0 n/a
WebFetch 1 1 (PageSpeed page is JS-rendered) n/a
curl (direct HTTP) ~15 0 free
whois 1 0 free

Reporting contract compliance

All 6 section files + 6 sidecar .meta.md files written. All emit LEARNING / FAILURE / IMPROVEMENT tagged lines.

Next-run recommendations (orchestrator's own observations)

  1. The skill assumes Task tool is available — this run executed serially because Task wasn't exposed in this environment. Worth adding a fall-through note in SKILL.md: "if Task tool is unavailable, the orchestrator can execute phases serially in the same context, but should note this in Run Telemetry and budget accordingly."
  2. Multiple API keys are now optional (GOOGLE_API_KEY, PERPLEXITY_API_KEY) — the skill should gracefully degrade per missing key rather than treating these as required. This run did.
  3. Reference preload was partial — 4/7 reference files loaded directly into orchestrator memory; the remaining 3 (security-headers, sitemap-locations, social-api-endpoints) were read on-demand. This worked but a stricter preload would have been cleaner.
  4. The phantom-sitemap robots.txt at MGC suggests a useful new "site-hygiene" sub-phase could be added: a quick set of red-flag checks (broken own-footer links + EOL versions + dead pixel IDs + phantom sitemap declarations) that produces a "technical hygiene score" 0-100.
  5. The Israeli market specifics worked well — MEMORY.md's entries on Maskyoo / IL call-tracking / IS-5568 / Pojo trap were directly useful. The new Anditek finding fits the same pattern and should be promoted.

Run metadata