Domain Intelligence Report — https://minuf.co.il/

Generated: 2026-05-12 | Pipeline: domain-intelligence skill (6 phases, sequential execution due to harness lacking Task spawn) | Run ID: 20260512-131423

Executive Summary

Minuf Group (קבוצת מינוף) is a 24-year-old Israeli services agency serving the third sector — nonprofits, foundations, and philanthropic organizations. The brand is technically sound on schema and policy text but weak on three high-stakes axes: compliance implementation, performance, and social presence.

Top 5 findings (impact-ordered):

  1. CRITICAL — Pre-consent pixel firing. GA4 + Facebook Pixel + Google Ads conversion tag fire on first page-load with no consent banner anywhere on the site. The privacy policy explicitly cites חוק הגנת הפרטיות 1981 + תיקון 13 (Amendment 13, administrative-fine authority active since 2024) — making this a credible regulatory exposure, not theoretical.
  2. HIGH — Performance bottleneck at Cloudflare layer. TTFB averaged 858 ms across 3 fetches. cf-cache-status: DYNAMIC proves Cloudflare is used for DNS/TLS/WAF only, not HTML caching. A single Cache Rule fix would 10x TTFB. Compounded by 26 external JS files + 25 PNG images (zero WebP/AVIF).
  3. HIGH — Social presence paradox. A digital-marketing agency selling social-media services has the weakest social footprint among its IL competitors: zero claimed Facebook page, dormant LinkedIn (0 posts), no Instagram, no YouTube. Worse, two different companies share the "Minuf" Hebrew name with active Facebook presences, polluting brand search.
  4. MEDIUM — Tracking maturity gaps. Legacy UA-62376316-2 still firing (sunset since 2023). No LinkedIn Insight Tag (key B2B retargeting channel). No Meta CAPI. No WhatsApp click event tracking despite WhatsApp being the primary CTA.
  5. MEDIUM — Title tag too long + duplicate H1. Home <title> is 83 chars (Google truncates ~60). Two identical <h1> tags on home (Elementor desktop/mobile duplicate).

Headline metrics — what's strong: privacy policy is unusually thorough (names a privacy coordinator, dated 2025-08-18, cites Amendment 13). Accessibility statement is comprehensive (WCAG 2.2 AA via Vee). Schema markup is properly structured. Sitemap is active. Hebrew RTL setup is correct. A 24-year client roster spanning the Movement for Quality Government, Krembo Wings, Israel Nature Heritage Fund, Chimes Israel, Tag Meir, Midot, etc. is genuine credibility.

Quick Stats

Tracking Pixels
4 (Facebook 293761334139344, Google Ads AW-952982155, GA4 G-KG69PSVM1F, legacy UA UA-62376316-2)
Ecommerce Platform
N/A — WordPress 6.9.4 + Elementor 4.0.7 + WPML 4.9.2.1 + OceanWP + Yoast SEO
Security Score
~25/100 (only referrer-policy set; HSTS / CSP / X-Frame-Options / X-Content-Type-Options / Permissions-Policy all missing)
PageSpeed (Mobile)
UNAVAILABLE — Google PageSpeed API daily quota exhausted (HTTP 429); no GOOGLE_API_KEY in env
TTFB (curl avg)
858 ms (target <500 ms)
Home HTML weight
165 KB raw, 26 JS files, 25 PNG images (0 WebP)
Schema Types
JSON-LD: WebPage, ImageObject, BreadcrumbList, WebSite, Organization (Organization missing sameAs, contactPoint, address)
Social Profiles
1 dormant (LinkedIn linkedin.com/company/minuf-group); 0 claimed Facebook/Instagram/YouTube/TikTok/X
Compliance Score
2/8 (privacy + accessibility statements present; terms, cookie policy, consent banner all missing)

Technical Health

SEO Analysis

On-page (home)

Schema markup

i18n / RTL

Indexability

PageSpeed deep-dive

UNAVAILABLE — Google PageSpeed API returned HTTP 429 "Quota exceeded" on initial call + 30-second retry. The shared/unauthenticated daily quota is exhausted; no GOOGLE_API_KEY in .env. Lab + CrUX data unavailable. Surrogate signals captured: TTFB 858 ms, 165 KB home HTML, 26 JS files, 25 images (100% PNG, 0 WebP).

Top performance recommendations (from surrogates)

  1. Enable Cloudflare HTML caching on /cf-cache-status: DYNAMIC is the smoking gun. Single Cache Rule with 1h TTL cuts TTFB ~10x.
  2. Convert PNG → WebP via Imagify/ShortPixel/EWWW. Expected ~50-70% home image weight reduction.
  3. Remove the legacy UA-62376316-2 tag — Universal Analytics sunset 2023-07-01, the tag fires but data is never collected.
  4. Lazy-load below-the-fold images (Elementor native loading="lazy").
  5. Defer non-critical JS; load FB Pixel + Google Ads tags post-consent (also fixes compliance).
  6. Self-host Google Fonts (Elementor "Google Fonts: Local" toggle).

Marketing & Tracking

Platform ID Status Notes
Facebook Pixel 293761334139344 ✅ Active PageView only visible; no event-level instrumentation in static HTML; no CAPI; no domain verification meta
Google Ads AW-952982155 ✅ Active Conversion tag installed; specific conversion label not visible in static HTML
Google Analytics 4 G-KG69PSVM1F ✅ Active Primary analytics
Universal Analytics UA-62376316-2 ⚠️ Sunset Dead since 2023-07-01 — remove

Conversion-tracking gaps (priority)

  1. Track WhatsApp click as generate_lead GA4 + Lead Meta event (joinchat plugin supports it).
  2. Track tel: link clicks identically.
  3. Verify contact-form submissions fire Lead in BOTH platforms.
  4. Add Meta CAPI (via PixelYourSite or similar).
  5. Add Facebook Domain Verification meta.
  6. Add LinkedIn Insight Tag — B2B retargeting is the most under-utilized channel.
  7. Remove UA-62376316-2 legacy tag.
  8. Migrate to Google Tag Manager (1 container vs 5+ direct tags).
  9. Implement Consent Mode v2 (gtag('consent', 'default', ...)) — also required for EEA traffic on Google Ads.

Untracked Israeli signal

Company & Market Intelligence

Snapshot

Service mix

  1. Resource development / fundraising (IL + abroad)
  2. Strategic + capacity-building consulting
  3. Digital media + paid campaigns
  4. Tech / WordPress / landing pages / donor systems
  5. Monday.com implementation for NGOs
  6. Google Ad Grants for NGOs (the $10K/month free program)
  7. Grant writing
  8. NGO recruitment / staffing

Client roster (highlights from /portfolio/)

התנועה לאיכות השלטון · כנפיים של קרמבו · מגמה ירוקה · צופן-תשביק · הקרן לשמירת הטבע והמורשת (רט"ג) · מכינה קדם צבאית תלם · האגודה הישראלי לכלבי נחיה · OA · עורכי דין למנהל תקין · פורום תג מאיר · קו אימפקט · עמותת עמדא · ארגון מידות · מכון כרם לחינוך · ידידי דמנציה ישראל · צ'יימס ישראל · תנועת נוער תלם · נרות של תקווה. Case study: בנקי / דרך שירה — "raised >₪1M in an ambassador campaign via smart digital."

Competitor landscape

Competitor URL Differentiation Social activity
Philantrom philantrom.com Pure fundraising consulting Active LI + FB
Millionim millionim.co.il Fundraising + telemarketing + crowdfunding Active LI + FB + YouTube
MGC mgc.co.il Individual-donor focus, "ידידי עמותה" methodology Active LI + FB
Atlas Grants atlas-grants.com Pure grant writing LI + FB
JGive jgive.com Donation SaaS (vendor relationship) Full social stack
שפר / ezvonot.com ezvonot.com Fundraising training/courses FB + YouTube

Minuf's edge: 24-year tenure, holistic stack, in-house tech, bilingual writers. Minuf's gap: weakest social footprint in the segment.

Press / reviews

Brand collision (paid-acquisition risk)

"מינוף" (leverage) is a dictionary word and three distinct businesses share variations:

Plus financial-leverage entities (Manof.fin, Manifa, etc.). Brand-keyword Google Ads will be expensive; claiming LinkedIn + Facebook profiles is defensively necessary.

Social Intelligence

Platform Status Detail
LinkedIn ✅ Page exists, ⚠️ dormant linkedin.com/company/minuf-group — 14 employees, founded 2002, Fundraising industry, HQ Maccabim. 0 posts returned by API. Followers field null (typical for sub-500-follower pages).
Facebook ❌ No claimed page The facebook.com/MinufIsrael/ hit is a different company (different domain minuf-israel.co.il, different phone, "Marketing Agency" category). The legacy facebook.com/pages/Minuf-Group/214018445430924 is an auto-generated Facebook directory page (3 likes, created 2013-09-08, never claimed).
Instagram ❌ Not found No claimed profile via WebSearch
YouTube ❌ Not found No claimed channel
TikTok ❌ Not found
X / Twitter ❌ Not found
Threads ❌ Not found
Pinterest ❌ Not found
Site footer social links ❌ ZERO No social icon links anywhere on 9 crawled pages

Implication: a digital-marketing agency that sells social-media services has the weakest social footprint among its IL competitors — credibility gap for any prospect who Googles them. The Meta Pixel installed is for ad audience-building, not organic posting.

Compliance Status

Element Status Notes
Privacy Policy ✅ Present, high quality /privacy-policy/ — Hebrew, cites חוק הגנת הפרטיות 1981 + תיקון 13 explicitly, names privacy coordinator (חנן סרפוס, 052-5345956), policy update 2025-08-18
Terms of Service / תקנון ❌ Missing Not linked anywhere
Cookie Policy ❌ Missing No dedicated cookies section even in privacy policy
Cookie Consent Banner ❌ Missing CRITICAL — see below
Accessibility Statement ✅ Present, comprehensive /הצהרת-נגישות/ — declares WCAG 2.2 AA via "Vee הנגשת אתרים"; cites IS 5568
Refund/Returns N/A Not ecommerce
Capital Markets Authority disclosure N/A Not regulated financial entity
security.txt (RFC 9116) ❌ Missing Not legally required but recommended

GA4 + Facebook Pixel + Google Ads conversion tag all fire on first page-load. No consent banner anywhere. The site's own privacy policy explicitly acknowledges Amendment 13 compliance is intended — implementation contradicts the policy. Direct breach of:

Fix path: install Hebrew-native consent banner (Cookiebot / Iubenda / Complianz / Tarteaucitron), configure block-until-consent, wire Consent Mode v2 defaults to "denied" with update-on-accept, add cookie inventory to policy or dedicated /cookie-policy/ page.

Privacy-policy review (gaps)

The policy itself is unusually strong but has 4 gaps under Amendment 13:

Priority Actions

Critical (fix immediately)

  1. Install consent banner with Consent Mode v2 — block GA4 + Meta Pixel + Google Ads until explicit consent. Fixes Amendment 13 exposure + restores EEA-traffic eligibility. Vendor: Cookiebot, Iubenda, or Complianz-WordPress. Estimated: ~half-day implementation.
  2. Enumerate cookies + retention windows in the privacy policy — Amendment 13 expects specifics. Add a /cookie-policy/ page or expand the existing /privacy-policy/. Estimated: ~2 hours of writing.
  3. Enable Cloudflare HTML caching for / and inner pages (bypass /wp-admin, /wp-login.php, search). Single Cache Rule. TTFB drops ~10x. Estimated: ~30 minutes.

High (fix before campaign launch)

  1. Remove legacy UA-62376316-2 tag — dead data, +bundle weight. ~10 minutes.
  2. Convert all PNG home images to WebP — Imagify/ShortPixel plugin auto-generates fallbacks. Expected ~50-70% image-byte reduction.
  3. Fix duplicate H1 on home (Elementor desktop/mobile template artifact). Edit template once.
  4. Shorten <title> to ~52 charsגיוס משאבים ומדיה דיגיטלית לעמותות | קבוצת מינוף.
  5. Add sameAs to Organization JSON-LD — link LinkedIn company URL. ~10 minutes (Yoast SEO has a field for this).
  6. Add Facebook Domain Verification meta — unlocks Meta AEM priority ordering.
  7. Add LinkedIn Insight Tag — B2B retargeting + Conversion API potential. ~30 minutes.
  8. Track WhatsApp + tel: clicks as generate_lead / Lead events in GA4 + Meta.
  9. Claim the LinkedIn company page (already exists) — post at least monthly. Defuse the social paradox.
  10. Enable HSTS + CSP + X-Frame-Options + X-Content-Type-Options + Permissions-Policy in Cloudflare — all one-click toggles. ~15 minutes.

Medium (optimize over time)

  1. Add contactPoint + address + description to Organization JSON-LD.
  2. Add Service schema on each services page.
  3. Add Person schema + founder bio page for Hannan Serphos — E-E-A-T signal.
  4. Self-host Google Fonts — Elementor toggle. Fixes EU GDPR concern + perf.
  5. Add preconnect hints for connect.facebook.net, www.googletagmanager.com, www.google-analytics.com.
  6. Lazy-load below-the-fold images via Elementor native loading="lazy".
  7. Disable /author-sitemap.xml in Yoast — closes admin-username enumeration.
  8. Block xmlrpc.php at Cloudflare WAF unless used.
  9. Implement Meta CAPI via PixelYourSite Pro.
  10. Add Google Tag Manager container — consolidate the 5+ direct tags.
  11. Claim a Facebook business page (defensive — there's a brand-collision risk with MinufIsrael and Minuf Digital).
  12. Update Crunchbase + ZoomInfo + Devex profiles — Devex specifically is high-value for international-foundation discovery.
  13. Switch self-referencing hreflang from he to he-IL.
  14. Add security.txt at /.well-known/security.txt with at minimum Contact: + Expires:.

Data Sources


Run Telemetry & Meta-Improvement

Phase durations

01 · Scan
6m 07s
367s
— PageSpeed (parallel)
30s + 30s retry
60s
02a · SEO (scan-derived)
1m 30s
90s
02b · SEO (PageSpeed surrogate)
4m (overlapping w/ 02a)
240s
03 · Ads Audit
1m 30s
90s
04 · Compliance
1m 30s
90s
05 · Social Audit
3m 00s
180s
06 · Research
4m 30s
270s
Final Assembly
1m 30s
90s
**Total wall time**
**~20 min**
1200s
Service
Credits
0s
curl (scraping)
0
0s
Google PageSpeed
0
0s
ScrapeCreators
1
0s
Apify (Facebook Pages Scraper)
2 actor runs (~38 sec compute)
38s
BrightData
0
0s
Perplexity
0
0s
WebSearch
0s
WebFetch
0s

Wall-time breakdown

Phase Started Finished Duration Retries Notes
01 · Scan 2026-05-12T11:14:23Z 2026-05-12T11:20:30Z 6m 07s 1 (PageSpeed) curl x ~25 URLs, python pattern detection
— PageSpeed (parallel) 2026-05-12T11:18:30Z 2026-05-12T11:19:00Z 30s + 30s retry 1 HTTP 429 daily-quota; abandoned
02a · SEO (scan-derived) 2026-05-12T11:20:30Z 2026-05-12T11:22:00Z 1m 30s 0 pattern checks on cached HTML
02b · SEO (PageSpeed surrogate) 2026-05-12T11:18:30Z 2026-05-12T11:22:30Z 4m (overlapping w/ 02a) 1 PageSpeed unavailable; used curl TTFB + HTML weight
03 · Ads Audit 2026-05-12T11:22:30Z 2026-05-12T11:24:00Z 1m 30s 0 pixel inventory + recommendations
04 · Compliance 2026-05-12T11:24:00Z 2026-05-12T11:25:30Z 1m 30s 0 manual page extraction + reference checklist
05 · Social Audit 2026-05-12T11:25:30Z 2026-05-12T11:28:30Z 3m 00s 0 ScrapeCreators 1 credit + Apify 2 runs
06 · Research 2026-05-12T11:28:30Z 2026-05-12T11:33:00Z 4m 30s 0 5 WebSearch passes + 2 failed WebFetch
Final Assembly 2026-05-12T11:33:00Z 2026-05-12T11:34:30Z 1m 30s Skeleton fill from section files
Total wall time ~20 min 2 (both PageSpeed)

Critical path

Longest-running phase: Phase 01 · Scan at ~6 min (curl + Python pattern detection across 9 inner pages + PageSpeed retry).

Critical path chain: Scan (6m) → Research (4.5m) → Assembly (1.5m) ≈ 12 min sequentially-blocking critical path.

Note: This run executed phases sequentially in a single agent (the harness in this session doesn't expose the Task subagent-spawn tool used by SKILL.md's design). True parallel execution via 6 spawned subagents would have cut wall time to roughly: Scan (6m) → max(specialist phases ~5m) → Assembly (1.5m) ≈ 12-13 min. Marginal gain in this case because the heaviest phase (01) is already sequential — and Phase 06 (research) is the second longest.

Proposed improvements (awaiting Dolev's review in PROPOSED.md)

_Aggregated from each phase's .meta.md IMPROVEMENT lines._

  1. Phase 01 — Treat PageSpeed HTTP 429 as terminal failure (daily quota, won't recover); skip retry, fall back to curl TTFB + HTML weight + asset-count surrogates.
  2. Phase 01 — Add joinchat (WordPress WhatsApp plugin) signature to pixel-patterns.md under "Israeli Market Pixels — conversion channels": pattern data-settings='{"telephone":"972, extract phone from JSON.
  3. Phase 01 — When on-page social-link extraction returns 0 profiles, set social_search_fallback: true flag in scan output so Phase 06 runs WebSearch site:facebook.com / site:linkedin.com queries.
  4. Phase 02a — Add explicit "duplicate H1 from Elementor desktop/mobile sections" check — common false-positive that's actually a single template artifact.
  5. Phase 02a — Add author-sitemap user-enumeration check (/author-sitemap.xml + /?author=1 redirect) as WordPress-specific indexability concern.
  6. Phase 02b — Add a "PageSpeed unavailable" fallback playbook with TTFB + HTML weight + JS/CSS/IMG counts as surrogate signals, AND map each surrogate to a recommendation.
  7. Phase 02b — Cloudflare cache-status check: if cf-cache-status: DYNAMIC on homepage, always recommend enabling HTML Cache Rules — single highest-impact perf fix on WordPress + Cloudflare sites.
  8. Phase 03 — Add explicit "WhatsApp / tel: click tracking" recommendation as default High when joinchat or tel: is detected on an Israeli site.
  9. Phase 03 — Add Consent Mode v2 verification — check for gtag('consent', 'default', ...) calls; missing CMv2 + active Google Ads is an EEA-traffic deliverability risk.
  10. Phase 04 — Promote "pre-consent pixel firing detected" to default-Critical whenever Phase 01 reports any pixel + no consent banner — currently described as contextual but it's the #1 administrative-fine risk in IL.
  11. Phase 04 — Add Vee (חברת הנגשה Vee) to the accessibility-toolbar table in compliance-checklist.md alongside Pojo / UserWay / Accessibly / EqualWeb.
  12. Phase 04 — Add a default cookie-inventory template for the common GA4 + Meta + Google Ads stack to compliance-checklist.md.
  13. Phase 05 — Add "brand-collision detection" routine: when Apify returns a Facebook page, compare its website/email/phone to audited domain; if mismatched, flag as brand_collision, not claimed_profile.
  14. Phase 05 — Document the autoGeneratedPage block in Apify's response as a "not claimed" signal.
  15. Phase 05 — Note that ScrapeCreators LinkedIn followers can be null for sub-500-follower pages; do not retry, this is by design.
  16. Phase 06 — Add Devex.com to the directory-check list in social-directories.md — high-relevance for IL NGO-services firms; currently missing.
  17. Phase 06 — Skip WebFetch on Crunchbase + LinkedIn first attempt — both reliably anti-bot (403 / 999); route directly to APIs.
  18. Phase 06 — Add "Hebrew brand-keyword disambiguation" sub-section: when brand name is a dictionary Hebrew word (here "מינוף" = leverage), wrap WebSearch queries with the domain or English variant.

Parallelization analysis

API / credit usage

Service Calls Failures Credits
curl (scraping) ~25 3 (security.txt, llms.txt — expected 404s) 0
Google PageSpeed 2 2 (HTTP 429 daily quota) 0
ScrapeCreators 2 (1 LinkedIn + 1 credit-balance) 0 1
Apify (Facebook Pages Scraper) 2 0 2 actor runs (~38 sec compute)
BrightData 0 0
Perplexity 0 (no PERPLEXITY_API_KEY in env) 0
WebSearch 5 0
WebFetch 2 2 (Crunchbase 403, LinkedIn 999)

Reporting contract compliance

Next-run recommendations

_Orchestrator's own observations (separate from per-phase improvements above):_

  1. Provision a per-skill GOOGLE_API_KEY — the shared/unauthenticated PageSpeed quota is reliably exhausted by mid-day. Either route through /root/agency/campaigner-studio/.env.local if that key exists (file is root-readable only — escalate or copy to Inbal-readable location), or have Inbal create a dedicated Google Cloud project key with PageSpeed Insights + YouTube Data API enabled.
  2. Add a PERPLEXITY_API_KEY to Inbal's .env — brand-mentions / reputation research would be richer than 5 WebSearch passes.
  3. Add the Task subagent-spawn tool to this harness profile — the skill is designed for parallel subagent execution but the active harness only had Bash/Read/Write/WebSearch/WebFetch. Sequential execution still completed in ~20 min but parallel would have hit the design target of ~10-12 min.
  4. Stage a .firecrawl/ cache hygiene step in the skill — this run found leftover JSON/HTML files from a previous run on a different target. A pre-Step-0 rm -f .firecrawl/*.{json,html,xml,txt} would prevent confusion.
  5. Brand-collision check could become a Phase 00.5 — for any Hebrew target whose brand name is in the Hebrew dictionary, run a "is this name shared with other businesses" check upfront and pass the disambiguator to all downstream phases.

Run metadata