# Audeep audit report: pointaro.app

- **Grade:** A (97/100)
- **Target:** https://pointaro.app/
- **Tier:** quick
- **Audited:** 2026-07-31T15:18:46.223Z (UTC)
- **Pages crawled:** 1 (single page)
- **Observe-only:** Verified ✓. 0 write attempts, 34/34 requests to target

## Summary

3 evidence-backed findings: 0 critical, 0 high, 0 medium, 3 low.

By category: Design 2 · Security 1.

### Report card

| Dimension | Grade | Score | Findings |
| --- | --- | --- | --- |
| Functional | A | 100/100 | 0 |
| Security | A | 99/100 | 1 |
| Accessibility | A | 100/100 | 0 |
| UX | A | 100/100 | 0 |
| Performance | A | 100/100 | 0 |
| SEO | A | 100/100 | 0 |
| Design | A | 98/100 | 2 |

## Product understanding

- Source: surface-observation
- Product: Not identified
- Category: unknown
- Summary: This report used the audited public surface without paid discovery context.

## Coverage

- Access: public
- Status: complete
- Rendered pages: 1/1
- Target requests: 34/80
- Synthetic signup completed: no
- Post-signup target writes: 0

## Observed actions

No target actions were recorded for this report.

## Safe stops

No safe stop was triggered.

## Cleanup and residue

- Status: not-required
- Summary: No synthetic account or target records were created by this audit.

## Finding verification

- e52f3b25-7fe6-451b-ab39-432074a3ee83-missing-security-header-0: evidence-backed (request). The finding is tied to evidence captured during this audit.
- e52f3b25-7fe6-451b-ab39-432074a3ee83-design-control-drift-2: evidence-backed (screenshot, dom-selector). The finding is tied to evidence captured during this audit.
- e52f3b25-7fe6-451b-ab39-432074a3ee83-design-color-drift-1: evidence-backed (screenshot, dom-selector). The finding is tied to evidence captured during this audit.

## Headline finding

### [LOW] Important browser security headers are missing

- Category: Security · Confidence: confirmed · Type: `missing-security-header`
- Detail: Missing: content-security-policy, x-frame-options, x-content-type-options
- Evidence: `GET / -> 200`
- Request: GET https://pointaro.app/ → 200
- Page: https://pointaro.app/

## All findings, grouped by severity

### LOW: 3 issues

#### 1. Important browser security headers are missing

- Severity: low · Category: Security · Confidence: confirmed · Type: `missing-security-header`
- Detail: Missing: content-security-policy, x-frame-options, x-content-type-options
- Evidence: `GET / -> 200`
- Request: GET https://pointaro.app/ → 200
- Page: https://pointaro.app/

#### 2. Buttons on this page are styled inconsistently

- Severity: low · Category: Design · Confidence: confirmed · Type: `design-control-drift`
- Detail: 5 visually distinct button treatments render on one page, counting background, text colour, border, corner radius and weight (including "Create Room", "What is Scrum Poker?", "Legal Notice"). When every button looks different, none of them reads as the primary action, and people hesitate over which one to press.
- Evidence: `button[aria-label="Open navigation menu"]`
- Screenshot: /audit-artifacts/e52f3b25-7fe6-451b-ab39-432074a3ee83/page.png
- Page: https://pointaro.app/

#### 3. Text colours are not on a shared scale

- Severity: low · Category: Design · Confidence: confirmed · Type: `design-color-drift`
- Detail: 11 distinct text colours render on this page (for example rgb(0, 0, 0), color(srgb 0 0 0 / 0.72), color(srgb 0 0 0 / 0.66), color(srgb 0 0 0 / 0.67), color(srgb 0 0 0 / 0.68)). A designed palette usually lands under 10. Near-duplicate greys and one-off hex values are the usual cause, and they make the page read as assembled rather than designed.
- Evidence: `#top > div:nth-of-type(2) > p:nth-of-type(1)`
- Screenshot: /audit-artifacts/e52f3b25-7fe6-451b-ab39-432074a3ee83/page.png
- Page: https://pointaro.app/

---

Generated by Audeep (observe-only QA audits) · report id e52f3b25-7fe6-451b-ab39-432074a3ee83
