An independent, best-practice audit of https://www.dnex.com.my/ across six dimensions that decide whether buyers find you, trust you, and act. No charge, no obligation — 11 August 2026.
Weighted across AI visibility, performance, SEO, conversion, accessibility and security. Most of the gaps below are quick, high-leverage fixes.
Performance & accessibility scores pending a full Lighthouse run.
No Organization schema
No Organization/LocalBusiness entity defined. AI assistants can't reliably identify or recommend the business.
Missing HSTS header
The site does not send the HSTS header.
No answer-shaped content
No FAQ schema or question-style headings. AI answer engines pull from Q&A-structured content.
Full six-point breakdown
Whether AI assistants can find, understand and recommend you.
No Organization schema
No Organization/LocalBusiness entity defined. AI assistants can't reliably identify or recommend the business.
Fix: Add Organization schema with name, url, logo, sameAs, contactPoint.
No answer-shaped content
No FAQ schema or question-style headings. AI answer engines pull from Q&A-structured content.
Fix: Add an FAQ section with FAQPage schema targeting real buyer questions.
No llms.txt
No /llms.txt file to guide AI crawlers to your key pages.
Fix: Publish an llms.txt summarizing the business and linking priority pages.
Load speed on mobile — every second costs enquiries.
Performance not measured
PageSpeed Insights did not return data (rate limit or blocked).
Fix: Re-run; add a PSI API key for reliability.
Whether search engines can crawl and rank the site.
Missing meta description
No meta description — search + AI snippets are auto-generated.
Fix: Write a 120–158 char description per key page.
Multiple H1s
Found 7 H1 tags.
Fix: Use one H1; demote the rest to H2.
Whether visitors can act — clear CTA and contact path.
No issues detected — nicely done.
Usable by everyone; also a corporate legal risk.
No issues detected — nicely done.
Headers and HTTPS hygiene that protect visitors.
Missing HSTS header
The site does not send the HSTS header.
Fix: Add Strict-Transport-Security header to force HTTPS.
Missing X-Content-Type-Options header
The site does not send the X-Content-Type-Options header.
Fix: Set X-Content-Type-Options: nosniff.
Missing X-Frame-Options / frame-ancestors header
The site does not send the X-Frame-Options / frame-ancestors header.
Fix: Prevent clickjacking with X-Frame-Options or CSP frame-ancestors.
Server version exposed
Server header: "nginx"
Fix: Suppress or genericize the Server header to avoid version fingerprinting.
We rebuild sites to best practice, then keep them fast, found by AI, and converting on an ongoing basis. If a revamp is on your roadmap this year, let's talk through these findings. No pitch.
Discuss the findings →Prepared by STEGG · khairulazri.site
Audit reflects the site at time of scan. Methodology available on request.