An independent, best-practice audit of https://chj.com.my/ across six dimensions that decide whether buyers find you, trust you, and act. No charge, no obligation — 11 August 2026.
Weighted across AI visibility, performance, SEO, conversion, accessibility and security. Most of the gaps below are quick, high-leverage fixes.
Performance & accessibility scores pending a full Lighthouse run.
No structured data (JSON-LD)
The site has zero schema markup. LLMs and search engines have no machine-readable description of who you are — so you're far less likely to be cited or featured.
No Organization schema
No Organization/LocalBusiness entity defined. AI assistants can't reliably identify or recommend the business.
Missing HSTS header
The site does not send the HSTS header.
Full six-point breakdown
Whether AI assistants can find, understand and recommend you.
No structured data (JSON-LD)
The site has zero schema markup. LLMs and search engines have no machine-readable description of who you are — so you're far less likely to be cited or featured.
Fix: Add Organization + relevant schema (Service, Product, FAQPage) as JSON-LD.
No Organization schema
No Organization/LocalBusiness entity defined. AI assistants can't reliably identify or recommend the business.
Fix: Add Organization schema with name, url, logo, sameAs, contactPoint.
No answer-shaped content
No FAQ schema or question-style headings. AI answer engines pull from Q&A-structured content.
Fix: Add an FAQ section with FAQPage schema targeting real buyer questions.
No llms.txt
No /llms.txt file to guide AI crawlers to your key pages.
Fix: Publish an llms.txt summarizing the business and linking priority pages.
No Open Graph tags
Missing og: tags — poor link previews when shared.
Fix: Add Open Graph title/description/image.
Load speed on mobile — every second costs enquiries.
Performance not measured
PageSpeed Insights did not return data (rate limit or blocked).
Fix: Re-run; add a PSI API key for reliability.
Whether search engines can crawl and rank the site.
No canonical tag
No rel=canonical — duplicate-content risk.
Fix: Add a self-referencing canonical on each page.
No H1 heading
Page has no H1.
Fix: Add exactly one descriptive H1 per page.
Whether visitors can act — clear CTA and contact path.
No click-to-call
No tel: link — mobile visitors can't tap to call.
Fix: Add a tel: link for the main line.
Usable by everyone; also a corporate legal risk.
No issues detected — nicely done.
Headers and HTTPS hygiene that protect visitors.
Missing HSTS header
The site does not send the HSTS header.
Fix: Add Strict-Transport-Security header to force HTTPS.
Missing Content-Security-Policy header
The site does not send the Content-Security-Policy header.
Fix: Add a CSP to reduce XSS / injection surface.
Missing X-Content-Type-Options header
The site does not send the X-Content-Type-Options header.
Fix: Set X-Content-Type-Options: nosniff.
Missing X-Frame-Options / frame-ancestors header
The site does not send the X-Frame-Options / frame-ancestors header.
Fix: Prevent clickjacking with X-Frame-Options or CSP frame-ancestors.
Server version exposed
Server header: "Google Frontend"
Fix: Suppress or genericize the Server header to avoid version fingerprinting.
We rebuild sites to best practice, then keep them fast, found by AI, and converting on an ongoing basis. If a revamp is on your roadmap this year, let's talk through these findings. No pitch.
Discuss the findings →Prepared by STEGG · khairulazri.site
Audit reflects the site at time of scan. Methodology available on request.