Skip to report

Competitor intelligence dossier

Data-Driven Digital Marketing Agency in Dubai

acquisit.io

Acquisit, a leading digital marketing agency in Dubai, specializes in data-driven strategies. Discover our digital and social media marketing services.

ObservedScanned 4 September 2026 at 10:07 UTCOpen sampled website ↗

The useful bits first

What the site appears to sell, how it converts visitors, what is measurable and where the evidence is incomplete.

Verified public adsNeeds verification
No verified match

No matching public ad was verified in the sampled libraries. This does not prove that no campaigns are running.

Show evidence
  • Bounded public ad-library checks; unmatched records were excluded
Measurement stackObserved
Insight Tag, Clarity and Google tag / GA4

5 public measurement or advertising signals were observed, including 1 legacy signal. Presence does not prove configuration quality or report receipt.

Show evidence
  • Insight Tag observed
  • Clarity observed
  • Google tag / GA4 observed
  • Universal Analytics (legacy) observed
Platform and edgeObserved
WordPress · Cloudflare

Cloudflare was observed at the public edge and WordPress was fingerprinted as the site platform. The origin host may remain hidden.

Show evidence
  • WordPress: CMS
  • Cloudflare: CDN and WAF
Backlink authorityObserved
DR 21

Ahrefs Domain Rating is a logarithmic backlink-strength metric. It is not a traffic estimate or a search-position score.

Show evidence
PerformanceNeeds verification
No lab result

No completed Lighthouse lab result was available.

Show evidence
  • Bounded scanner page fetch: 29 ms

What they appear to be doing

A cautious interpretation of the public positioning, offers, proof, conversion routes, acquisition signals and content footprint.

OffersNeeds verification

No distinct offer was confirmed from the sampled headings and routes.

ProofObserved

Dedicated proof pages and supporting case-study, review or results routes provide public trust signals.

Show evidence
Conversion routesObserved

Website form, Click-to-call link and Marketing or CRM route were observed. Submission handling and conversion firing were not tested.

Show evidence
  • Public forms with 8 distinct field names
AcquisitionInferred

LinkedIn, Microsoft, Google and Google Analytics measurement or advertising technology is present. This suggests channel instrumentation, but does not prove that campaigns are active.

Show evidence
  • Insight Tag observed
  • Clarity observed
  • Google tag / GA4 observed
  • Universal Analytics (legacy) observed

Next moves worth making

Up to five practical actions, deduplicated and ordered by likely impact. Open each one for the evidence and verification path.

  1. Marketing tags observed without a supported consent signal

    high impactObserved

    Implement and test a consent platform appropriate to the site's regions and data uses.

    Show evidence and next steps

    Why it matters: Consent state can determine which storage and requests are permitted. Automated detection is not a legal conclusion.

    How to verify: Trace baseline, reject and accept sessions in fresh browser contexts.

    Confidence: highSuggested owner: MarketerEstimated effort: days

  2. Remove or justify legacy Universal Analytics code

    high impactObserved

    Confirm whether the legacy bootstrap is still needed and remove it if not.

    Show evidence and next steps

    Why it matters: Retired measurement code can add requests and create misleading expectations without a supported destination.

    What we found:
    • Public source fingerprint

    How to verify: Rescan the published page and container after removal.

    Confidence: highSuggested owner: MarketerEstimated effort: hours

  3. Mobile Core Web Vitals do not all pass

    high impactObserved

    Investigate the failing field metric with route-level RUM and repeatable lab traces. Do not substitute TBT for INP.

    Show evidence and next steps

    Why it matters: Core Web Vitals reflect real-user loading, responsiveness and visual stability at the 75th percentile.

    What we found:
    • Chrome UX Report API
    • origin scope

    How to verify: Recheck the next CrUX rolling period and compare owned-site RUM if available.

    Confidence: highSuggested owner: DeveloperEstimated effort: days

  4. 2 sampled fields lack an explicit accessible label

    high impactInferred

    Associate visible labels with controls or supply an equivalent accessible name.

    Show evidence and next steps

    Why it matters: Labels make controls understandable and enlarge the reliable interaction target.

    What we found:
    • Static label, aria-label and aria-labelledby checks

    How to verify: Inspect each rendered control in the accessibility tree.

    Confidence: mediumSuggested owner: DeveloperEstimated effort: hours

  5. 4 potentially parser-blocking external scripts

    medium impactInferred

    Use defer, async or modules where dependency ordering allows.

    Show evidence and next steps

    Why it matters: Parser-blocking scripts can delay initial rendering. Browser preload and response timing can change the actual effect.

    What we found:
    • acquisit.io
    • js-eu1.hsforms.net
    • www.google.com

    How to verify: Confirm with a Lighthouse trace and rendered waterfall.

    Confidence: mediumSuggested owner: DeveloperEstimated effort: hours

Performance with honest limits

Lighthouse is a one-off lab test. CrUX is 28-day real-user data and may be unavailable on lower-traffic sites.

No lab result

No completed Lighthouse lab result was available.

Mobile lab No result

Configure PAGESPEED_API_KEY to run Lighthouse through PageSpeed Insights.

Desktop lab No result

Configure PAGESPEED_API_KEY to run Lighthouse through PageSpeed Insights.

Real-user Core Web Vitals

Public real-user field data was returned.

Observed
Open full Lighthouse and Core Web Vitals evidence

Performance and Core Web Vitals

Core Web Vitals are LCP, INP and CLS measured from real users at the 75th percentile. Lighthouse is a synthetic test: it can diagnose LCP and CLS, while TBT is only a laboratory proxy for responsiveness and is not INP.

Current read

At least one published real-user profile needs improvement. Lighthouse remains a diagnostic snapshot, not the field verdict.

Lighthouse lab diagnostics

Synthetic lab test

Mobile Lighthouse

Not measured
No result

Configure PAGESPEED_API_KEY to run Lighthouse through PageSpeed Insights.

Why the mobile Lighthouse test has no score

Configure PAGESPEED_API_KEY to run Lighthouse through PageSpeed Insights.

Source: Google PageSpeed Insights / Lighthouse · Profile: mobile

Synthetic lab test

Desktop Lighthouse

Test did not finish
No result

Configure PAGESPEED_API_KEY to run Lighthouse through PageSpeed Insights.

Why the desktop Lighthouse test has no score

Configure PAGESPEED_API_KEY to run Lighthouse through PageSpeed Insights.

Source: Google PageSpeed Insights / Lighthouse · Profile: desktop

Real-user Core Web Vitals

Real users · rolling 28 days

Mobile real-user Core Web Vitals

Needs improvement
Needs improvement

75th-percentile Chrome experience · whole origin · 6 Aug 2026 to 2 Sept 2026.

LCP3.8 sNeeds improvement · Good at 2.5 s or faster
INP103 msGood · Good at 200 ms or faster
CLS0Good · Good at 0.1 or lower
Show mobile CrUX evidence and fixes
  • Improve LCP

    Improve LCP by optimising and prioritising the main image or content block, removing render-blocking resources and reducing server delay.

Source: Chrome UX Report API · CrUX eligibility methodology

Real users · rolling 28 days

Desktop real-user Core Web Vitals

Needs improvement
Needs improvement

75th-percentile Chrome experience · whole origin · 6 Aug 2026 to 2 Sept 2026.

LCP3.3 sNeeds improvement · Good at 2.5 s or faster
INP59 msGood · Good at 200 ms or faster
CLS0.01Good · Good at 0.1 or lower
Show desktop CrUX evidence and fixes
  • Improve LCP

    Improve LCP by optimising and prioritising the main image or content block, removing render-blocking resources and reducing server delay.

Source: Chrome UX Report API · CrUX eligibility methodology

What to fix or verify

  • Mobile: rerun the Lighthouse test

    Configure PAGESPEED_API_KEY to run Lighthouse through PageSpeed Insights. This is not a poor score.

SEO baselineGoogle Lighthouse available run
Accessibility baselineGoogle Lighthouse available run · manual follow-up still required

Technical evidence

The supporting stack, measurement, infrastructure, reputation and raw collection modules. Kept compact until you need it.

Technology fingerprints10

Insight Tag · Google tag, GA4, Ads or Floodlight · Clarity · Google reCAPTCHA · Cloudflare

Measurement signals5

Insight Tag · Clarity · Google tag / GA4 · Universal Analytics (legacy) · Google Tag Manager

Hosting / edgeCloudflare

Cloudflare was observed at the edge. The origin hosting provider may be hidden behind it.

Open stack, registration and safety evidence

Technology and measurement fingerprints

Insight Tag · AdvertisingGoogle tag, GA4, Ads or Floodlight · Analytics and dataClarity · Analytics and dataGoogle reCAPTCHA · Bot protectionCloudflare · CDN and edgeWordPress · CMSjQuery · JavaScript libraryUniversal Analytics code · Legacy technologyHubSpot tracking code · Marketing and CRMContainer bootstrap · Tag management
  • Insight TagAdvertising

    published Google Tag Manager container · 2 signals · view sampled page

  • ClarityExperience analytics

    browser network request · 1 signal · view sampled page

  • Google tag, GA4, Ads or FloodlightGoogle measurement

    published Google Tag Manager container · 1 signal · view sampled page
    browser network request · 1 signal · view sampled page

  • Universal Analytics codeLegacy

    published Google Tag Manager container · 1 signal · view sampled page

  • HubSpot tracking codeMarketing and calls

    published Google Tag Manager container · 1 signal · view sampled page

  • Container bootstrapTag management

    browser network request · 1 signal · view sampled page

Hosting, registration and authority

Hosting or edge
Cloudflare
Registered domain
acquisit.io
Registrar
Not published
Registry source
Registry RDAP via the IANA bootstrap
Registered
Not published
Expires
Not published
Domain Rating · Domain Rating by Ahrefs
21 / 100

Reputation check

Google Web Risk
No current Google Web Risk match

No match is not a safety guarantee. Investigate any warning independently.

Open all evidence modules and methodology

Evidence and key metrics

Open any card to inspect the public evidence, source and collection details.

Public page and headers

1page fetched

132.8 KB of public HTML inspected

Show evidence

HTTP 200 · 132.8 KB · 29 ms · view sampled page

Source: Direct fetch · Collected in 29 ms

Rendered browser and network

1page rendered

189 browser requests observed before interaction

Show evidence

HTTP 200 · 189 requests · 14 third-party hosts · view sampled page

Fresh browser context; no forms or logins submitted

Source: Hardened Chromium provider · Collected in 5.2 s

Technology fingerprinting

10technologies

Insight Tag · Google tag, GA4, Ads or Floodlight · Clarity

Show evidence

Insight Tag · Advertising · 100% confidence

Google tag, GA4, Ads or Floodlight · Analytics and data · 100% confidence

Clarity · Analytics and data · 100% confidence

Google reCAPTCHA · Bot protection · 95% confidence

Cloudflare · CDN and edge · 100% confidence

WordPress · CMS · 95% confidence

jQuery · JavaScript library · 95% confidence

Universal Analytics code · Legacy technology · 100% confidence

Source: First-party signatures and public container evidence

DNS and email records

12DNS records

1 address · 3 nameservers · 1 mail routes

Show evidence

Domain: acquisit.io

A: 1 record

NS: 3 records

MX: 1 record

TXT: 6 records

SOA: 1 record

Email policy: SPF present · DMARC present

Source: DNS over HTTPS · Collected in 111 ms

WHOIS / registration

acquisit.io

Public registry record inspected

Show evidence

No additional public evidence was returned.

Source: Registry RDAP via the IANA bootstrap · Coverage: Not found

IP allocation and hosting

CloudflareCDN and WAF

104.19.154.92

Show evidence

Network allocation: CLOUDFLARENET

Address: 104.19.154.92

Edge detection confidence: high

Cloudflare was observed at the edge. The origin hosting provider may be hidden behind it.

Source: IP RDAP · Collected in 1 s

Lighthouse and Core Web Vitals

Unavailable

No Lighthouse run completed

Show evidence

Mobile real-user Core Web Vitals: Needs improvement · origin scope

Desktop real-user Core Web Vitals: Needs improvement · origin scope

Source: Google PSI and CrUX · Coverage: Partial coverage · Collected in 50 s

Google Web Risk

0threat matches

No current Google Web Risk match

Show evidence

Google Web Risk: no current match

Reputation data is a provider snapshot, not a warranty that a site is safe. Timestamps and coverage matter.

Source: Google Web Risk · Coverage: Partial coverage · Collected in 74 ms

Backlink authority

21/ 100

Backlink profile strength on a logarithmic 0-100 scale. It is not a Google ranking or traffic metric.

Show evidence

Target domain: acquisit.io

Domain Rating by Ahrefs · https://ahrefs.com/

Scale: 0–100 · logarithmic

Source: Domain Rating by Ahrefs · Collected in 92 ms

robots.txt

11disallow rules

robots.txt found · 1 sitemap declaration

Show evidence

robots.txt · 491 B · view sampled page

User-agent directives: present

Declared sitemap · view sampled page

Source: Direct public fetch

XML sitemap sample

6child sitemaps

XML index · 1013 B

Show evidence

Default sitemap · 1013 B · view sampled page

Document type: index

Entries in bounded sample: 6

Source: Direct public fetch

security.txt

Not found

No file returned from the standard public location

Show evidence

Checked /.well-known/security.txt · view sampled page

Absence is informational and is not a vulnerability by itself

Source: Direct public fetch · Coverage: Not found

Scoring and action plan

57/ 100

15 priority findings · 77% scored evidence coverage

Show evidence

Deterministic ruleset 0.1.0

Report generated: 4 September 2026 at 10:07 UTC

Rules produced 15 prioritised findings

Source: Deterministic ruleset 0.1.0

All corrected findings

  • Mobile Core Web Vitals do not all passhigh

    CrUX origin p75: LCP 3801ms, INP 103ms, CLS 0.

    Suggested fix: Investigate the failing field metric with route-level RUM and repeatable lab traces. Do not substitute TBT for INP.

    Show evidence and next steps

    Why it matters: Core Web Vitals reflect real-user loading, responsiveness and visual stability at the 75th percentile.

    What we found:
    • Chrome UX Report API
    • origin scope

    How to verify: Recheck the next CrUX rolling period and compare owned-site RUM if available.

    Confidence: observedSuggested owner: DeveloperEstimated effort: days

  • Marketing tags observed without a supported consent signalhigh

    No supported consent interface was identified in the fresh pre-consent browser state. This is not proof that the site has no banner: region, timing, prior-state logic and unsupported CMPs can change the result.

    Suggested fix: Implement and test a consent platform appropriate to the site's regions and data uses.

    Show evidence and next steps

    Why it matters: Consent state can determine which storage and requests are permitted. Automated detection is not a legal conclusion.

    How to verify: Trace baseline, reject and accept sessions in fresh browser contexts.

    Confidence: observedSuggested owner: MarketerEstimated effort: days

  • 2 sampled fields lack an explicit accessible labelhigh

    2 forms were inspected with static label heuristics.

    Suggested fix: Associate visible labels with controls or supply an equivalent accessible name.

    Show evidence and next steps

    Why it matters: Labels make controls understandable and enlarge the reliable interaction target.

    What we found:
    • Static label, aria-label and aria-labelledby checks

    How to verify: Inspect each rendered control in the accessibility tree.

    Confidence: inferredSuggested owner: DeveloperEstimated effort: hours

  • 4 potentially parser-blocking external scriptshigh

    29 external script tags were found in source HTML.

    Suggested fix: Use defer, async or modules where dependency ordering allows.

    Show evidence and next steps

    Why it matters: Parser-blocking scripts can delay initial rendering. Browser preload and response timing can change the actual effect.

    What we found:
    • acquisit.io
    • js-eu1.hsforms.net
    • www.google.com

    How to verify: Confirm with a Lighthouse trace and rendered waterfall.

    Confidence: inferredSuggested owner: DeveloperEstimated effort: hours

  • Legacy tracking technology observedhigh

    Universal Analytics code

    Suggested fix: Confirm whether the legacy bootstrap is still needed and remove it if not.

    Show evidence and next steps

    Why it matters: Retired measurement code can add requests and create misleading expectations without a supported destination.

    What we found:
    • Public source fingerprint

    How to verify: Rescan the published page and container after removal.

    Confidence: observedSuggested owner: MarketerEstimated effort: hours

  • Content Security Policy not observedmedium

    The header was absent from the sampled final HTML response.

    Suggested fix: Add a tested Content-Security-Policy. Start in report-only mode if necessary.

    Show evidence and next steps

    Why it matters: CSP can limit the impact of injected content.

    What we found:
    • Final HTTP response headers

    How to verify: Inspect the final response headers after deployment.

    Confidence: observedSuggested owner: DeveloperEstimated effort: hours

  • No click-ID field was visible on sampled formsmedium

    2 forms were observed; 0 exposed a supported click-ID field.

    Suggested fix: Verify click IDs are captured, stored on the CRM record and returned with eligible outcomes.

    Show evidence and next steps

    Why it matters: Persisting ad click identifiers can make later qualified outcomes joinable to the original ad interaction.

    What we found:
    • Public form field names only

    How to verify: Submit an authorised test lead manually and inspect the receiving record.

    Confidence: inferredSuggested owner: MarketerEstimated effort: hours

  • Strict-Transport-Security not observedmedium

    The header was absent from the sampled final HTML response.

    Suggested fix: Add a suitable Strict-Transport-Security policy after confirming every subdomain is HTTPS-ready.

    Show evidence and next steps

    Why it matters: HSTS tells supporting browsers to keep using HTTPS.

    What we found:
    • Final HTTP response headers

    How to verify: Inspect the final response headers after deployment.

    Confidence: observedSuggested owner: DeveloperEstimated effort: hours

  • 2 H1 headings foundmedium

    37 headings were found in the source HTML.

    Suggested fix: Use one useful top-level heading and a logical nested hierarchy.

    Show evidence and next steps

    Why it matters: A clear top-level heading helps users and automated systems understand the page structure.

    What we found:
    • H2: Let’s Talk Growth
    • H1: Growth marketing for clear-cut impact
    • H2: We deliver growth through Traffic Generation, Conversion Rate, and Lifetime Value Optimization.
    • H2: What we do
    • H3: Performance Marketing
    • H3: SEO/GEO/ASO

    How to verify: Inspect the rendered heading outline.

    Confidence: observedSuggested owner: SEOEstimated effort: minutes

  • Heading levels are skipped in source ordermedium

    H1 to H3, H2 to H6, H2 to H6, H2 to H6, H2 to H6

    Suggested fix: Use headings to represent nested document structure, not visual size.

    Show evidence and next steps

    Why it matters: A logical heading outline helps keyboard and screen-reader navigation.

    What we found:
    • Static heading order

    How to verify: Inspect the rendered heading outline.

    Confidence: inferredSuggested owner: DeveloperEstimated effort: hours

  • MIME sniffing protection not observedmedium

    The header was absent from the sampled final HTML response.

    Suggested fix: Set X-Content-Type-Options: nosniff.

    Show evidence and next steps

    Why it matters: X-Content-Type-Options reduces MIME confusion.

    What we found:
    • Final HTTP response headers

    How to verify: Inspect the final response headers after deployment.

    Confidence: observedSuggested owner: DeveloperEstimated effort: hours

  • No frame-embedding restriction was observedmedium

    No frame-embedding restriction was observed

    Suggested fix: Set CSP frame-ancestors or X-Frame-Options where legacy support is needed.

    Show evidence and next steps

    Why it matters: Clickjacking protection reduces unwanted framing.

    What we found:
    • HTTP response headers

    How to verify: Repeat the same public check after the change.

    Confidence: observedSuggested owner: DeveloperEstimated effort: minutes

  • Permissions policy not observedmedium

    The header was absent from the sampled final HTML response.

    Suggested fix: Set a restrictive Permissions-Policy for unused browser capabilities.

    Show evidence and next steps

    Why it matters: Permissions-Policy limits access to powerful browser features.

    What we found:
    • Final HTTP response headers

    How to verify: Inspect the final response headers after deployment.

    Confidence: observedSuggested owner: DeveloperEstimated effort: hours

  • Referrer policy not observedmedium

    The header was absent from the sampled final HTML response.

    Suggested fix: Set an explicit Referrer-Policy appropriate to the site.

    Show evidence and next steps

    Why it matters: A referrer policy limits URL information sent to other origins.

    What we found:
    • Final HTTP response headers

    How to verify: Inspect the final response headers after deployment.

    Confidence: observedSuggested owner: DeveloperEstimated effort: hours

  • No DNSSEC DS record observedlow

    No DS record was returned. This does not test every resolver or validate the complete chain.

    Suggested fix: Consider enabling DNSSEC with coordinated registrar and DNS-provider configuration.

    Show evidence and next steps

    Why it matters: DNSSEC can provide origin authentication for DNS answers when the validation chain is correct.

    What we found:
    • DS query through DNS over HTTPS

    How to verify: Validate the complete chain with an independent DNSSEC tool.

    Confidence: inferredSuggested owner: ITEstimated effort: hours

Methodology and limitations

Bounded analysis of publicly accessible pages, DNS, registries and configured providers. No login, form submission, port scan or exploit testing.

  • The report is a bounded public sample, not a complete crawl, account audit, accessibility certification, legal compliance review or penetration test.
  • Technology and hosting detections are confidence-ranked fingerprints. They do not prove ownership, configuration quality, exact version or vulnerability.
  • A browser request shows that the page attempted a destination. It does not prove storage, reporting, attribution or use by an advertising algorithm.
  • The public scanner does not log in, submit forms, complete checkout, download files, scan ports or test exploits.