Skip to report

Competitor intelligence dossier

firepixel.co.uk

firepixel.co.uk

Separate advanced Google Ads management for lead generation and ecommerce: qualified CRM outcomes for leads, or Merchant Center feeds and order-line economics for retail.

ObservedScanned 4 September 2026 at 14:31 UTCOpen sampled website ↗

The useful bits first

What the site appears to sell, how it converts visitors, what is measurable and where the evidence is incomplete.

Verified public adsNeeds verification
No verified match

No matching public ad was verified in the sampled libraries. This does not prove that no campaigns are running.

Show evidence
  • Bounded public ad-library checks; unmatched records were excluded
Measurement stackObserved
Clarity, Google tag / GA4 and Google Tag Manager

3 public measurement or advertising signals were observed. Presence does not prove configuration quality or report receipt.

Show evidence
  • Clarity observed
  • Google tag / GA4 observed
  • Google Tag Manager observed
Platform and edgeObserved
Cloudflare

Cloudflare was observed at the public edge. The origin host may remain hidden.

Show evidence
  • Cloudflare: CDN and WAF
Backlink authorityObserved
DR 3

Ahrefs Domain Rating is a logarithmic backlink-strength metric. It is not a traffic estimate or a search-position score.

Show evidence
PerformanceNeeds verification
No lab result

No completed Lighthouse lab result was available. No eligible public CrUX field sample was available; that is not a failed Core Web Vitals result.

Show evidence
  • Bounded scanner page fetch: 98 ms

What they appear to be doing

A cautious interpretation of the public positioning, offers, proof, conversion routes, acquisition signals and content footprint.

OffersObserved

Dedicated pricing routes were observed.

ProofNeeds verification

No case-study, testimonial or review proof was confirmed in the bounded sample.

Conversion routesObserved

Website form was observed, alongside a booking or contact route. Submission handling and conversion firing were not tested.

Show evidence
  • Public forms with 9 distinct field names
  • Booking/contact route or booking service observed
AcquisitionInferred

Microsoft, Google and Google Tag Manager measurement or advertising technology is present. This suggests channel instrumentation, but does not prove that campaigns are active.

Show evidence
  • Clarity observed
  • Google tag / GA4 observed
  • Google Tag Manager observed
Content footprintObserved

1,605 words were found on the sampled homepage. 5 exact-domain pages appeared in the bounded index-presence check.

Show evidence

Next moves worth making

Up to five practical actions, deduplicated and ordered by likely impact. Open each one for the evidence and verification path.

No material action was confirmed.

Keep monitoring and rerun the dossier after meaningful site changes.

Performance with honest limits

Lighthouse is a one-off lab test. CrUX is 28-day real-user data and may be unavailable on lower-traffic sites.

No lab result

No completed Lighthouse lab result was available. No eligible public CrUX field sample was available; that is not a failed Core Web Vitals result.

Mobile lab No result

Configure PAGESPEED_API_KEY to run Lighthouse through PageSpeed Insights.

Desktop lab No result

Configure PAGESPEED_API_KEY to run Lighthouse through PageSpeed Insights.

Real-user Core Web Vitals

No eligible public 28-day CrUX sample was returned for phone or desktop.

Needs verification
Open full Lighthouse and Core Web Vitals evidence

Performance and Core Web Vitals

Core Web Vitals are LCP, INP and CLS measured from real users at the 75th percentile. Lighthouse is a synthetic test: it can diagnose LCP and CLS, while TBT is only a laboratory proxy for responsiveness and is not INP.

Current read

No completed lab or eligible public real-user sample was returned, so this report cannot make a performance verdict.

Lighthouse lab diagnostics

Synthetic lab test

Mobile Lighthouse

Test did not finish
No result

Configure PAGESPEED_API_KEY to run Lighthouse through PageSpeed Insights.

Why the mobile Lighthouse test has no score

Configure PAGESPEED_API_KEY to run Lighthouse through PageSpeed Insights.

Source: Google PageSpeed Insights / Lighthouse · Profile: mobile

Synthetic lab test

Desktop Lighthouse

Test did not finish
No result

Configure PAGESPEED_API_KEY to run Lighthouse through PageSpeed Insights.

Why the desktop Lighthouse test has no score

Configure PAGESPEED_API_KEY to run Lighthouse through PageSpeed Insights.

Source: Google PageSpeed Insights / Lighthouse · Profile: desktop

Real-user Core Web Vitals

Real users · rolling 28 days

Mobile real-user Core Web Vitals

Not measured
No public sample

CrUX found no eligible mobile record for either the exact URL or the whole origin. This usually means there is not enough eligible public Chrome traffic for publication; it is not a failed performance score.

Why mobile CrUX is unavailable

Use the Lighthouse lab result for today’s diagnosis. For a site you own, Search Console may show grouped CrUX data for the verified property. First-party real-user monitoring is the independent fallback when public data is absent.

Source: Chrome UX Report API · Exact URL and origin fallback checked · CrUX eligibility methodology

Real users · rolling 28 days

Desktop real-user Core Web Vitals

Not measured
No public sample

CrUX found no eligible desktop record for either the exact URL or the whole origin. This usually means there is not enough eligible public Chrome traffic for publication; it is not a failed performance score.

Why desktop CrUX is unavailable

Use the Lighthouse lab result for today’s diagnosis. For a site you own, Search Console may show grouped CrUX data for the verified property. First-party real-user monitoring is the independent fallback when public data is absent.

Source: Chrome UX Report API · Exact URL and origin fallback checked · CrUX eligibility methodology

What to fix or verify

  • Mobile: rerun the Lighthouse test

    Configure PAGESPEED_API_KEY to run Lighthouse through PageSpeed Insights. This is not a poor score.

  • Verify real-user experience on owned sites

    Search Console may show grouped CrUX data for a verified property. If it does not, install privacy-conscious first-party real-user monitoring; INP cannot be judged from Lighthouse alone.

SEO baselineGoogle Lighthouse available run
Accessibility baselineGoogle Lighthouse available run · manual follow-up still required

Technical evidence

The supporting stack, measurement, infrastructure, reputation and raw collection modules. Kept compact until you need it.

Technology fingerprints6

Google tag, GA4, Ads or Floodlight · Clarity · Cloudflare · Cloudflare DNS · Container bootstrap

Measurement signals3

Clarity · Google tag / GA4 · Google Tag Manager

Hosting / edgeCloudflare

Cloudflare was observed at the edge. The origin hosting provider may be hidden behind it.

Open stack, registration and safety evidence

Technology and measurement fingerprints

Google tag, GA4, Ads or Floodlight · Analytics and dataClarity · Analytics and dataCloudflare · CDN and edgeCloudflare DNS · DNS providerContainer bootstrap · Tag managementAstro · Web framework

Hosting, registration and authority

Hosting or edge
Cloudflare
Registered domain
firepixel.co.uk
Registrar
Namecheap, Inc. (NAMECHEAP-INC)
Registered
8 June 2010 at 21:46 UTC
Expires
8 June 2027 at 21:46 UTC
Domain Rating · Domain Rating by Ahrefs
2.7 / 100

Reputation check

Google Web Risk
No current Google Web Risk match

No match is not a safety guarantee. Investigate any warning independently.

Open all evidence modules and methodology

Evidence and key metrics

Open any card to inspect the public evidence, source and collection details.

Public page and headers

2pages fetched

41.7 KB of public HTML inspected

Show evidence

HTTP 200 · 30.6 KB · 98 ms · view sampled page

HTTP 200 · 11.1 KB · 44 ms · view sampled page

Source: Direct fetch · Collected in 98 ms

Rendered browser and network

2pages rendered

155 browser requests observed before interaction

Show evidence

HTTP 200 · 34 requests · 7 third-party hosts · view sampled page

HTTP 200 · 121 requests · 9 third-party hosts · view sampled page

Fresh browser context; no forms or logins submitted

Source: Hardened Chromium provider · Collected in 8.1 s

Technology fingerprinting

6technologies

Google tag, GA4, Ads or Floodlight · Clarity · Cloudflare

Show evidence

Google tag, GA4, Ads or Floodlight · Analytics and data · 100% confidence

Clarity · Analytics and data · 100% confidence

Cloudflare · CDN and edge · 100% confidence

Cloudflare DNS · DNS provider · 100% confidence

Container bootstrap · Tag management · 100% confidence

Astro · Web framework · 95% confidence

Source: First-party signatures and public container evidence

DNS and email records

9DNS records

4 addresses · 2 nameservers · 1 mail routes

Show evidence

Domain: firepixel.co.uk

A: 2 records

AAAA: 2 records

NS: 2 records

MX: 1 record

TXT: 1 record

SOA: 1 record

Email policy: SPF present · DMARC not observed

Source: DNS over HTTPS · Collected in 86 ms

WHOIS / registration

firepixel.co.uk16.2 years old

Registration currently expires 8 Jun 2027

Show evidence

Registrar: Namecheap, Inc. (NAMECHEAP-INC)

Registered: 8 Jun 2010

Expires: 8 Jun 2027

Nameservers: dahlia.ns.cloudflare.com, salvador.ns.cloudflare.com

Registry RDAP via the IANA bootstrap · https://rdap.nominet.uk/uk/domain/firepixel.co.uk

Source: Registry RDAP via the IANA bootstrap

IP allocation and hosting

CloudflareCDN and WAF

172.67.172.21

Show evidence

Network allocation: CLOUDFLARENET

Address: 172.67.172.21

Edge detection confidence: high

Cloudflare was observed at the edge. The origin hosting provider may be hidden behind it.

Source: IP RDAP · Collected in 659 ms

Lighthouse and Core Web Vitals

Unavailable

No Lighthouse run completed

Show evidence

Mobile real-user Core Web Vitals: no public CrUX sample; this is not a failed score

Desktop real-user Core Web Vitals: no public CrUX sample; this is not a failed score

Source: Google PSI and CrUX · Coverage: Unavailable · Collected in 178 ms

Google Web Risk

0threat matches

No current Google Web Risk match

Show evidence

Google Web Risk: no current match

Reputation data is a provider snapshot, not a warranty that a site is safe. Timestamps and coverage matter.

Source: Google Web Risk · Coverage: Partial coverage · Collected in 69 ms

Backlink authority

3/ 100

Backlink profile strength on a logarithmic 0-100 scale. It is not a Google ranking or traffic metric.

Show evidence

Target domain: firepixel.co.uk

Domain Rating by Ahrefs · https://ahrefs.com/

Scale: 0–100 · logarithmic

Source: Domain Rating by Ahrefs · Collected in 80 ms

XML sitemap sample

Not found

No default XML sitemap was returned

Show evidence

Default sitemap · 0 B · view sampled page

Entries in bounded sample: 0

Source: Direct public fetch · Coverage: Not found

security.txt

Not found

No file returned from the standard public location

Show evidence

Checked /.well-known/security.txt · view sampled page

Absence is informational and is not a vulnerability by itself

Source: Direct public fetch · Coverage: Not found

Scoring and action plan

90/ 100

8 priority findings · 68% scored evidence coverage

Show evidence

Deterministic ruleset 0.1.0

Report generated: 4 September 2026 at 14:31 UTC

Rules produced 8 prioritised findings

Source: Deterministic ruleset 0.1.0

All corrected findings

  • Content Security Policy not observedmedium

    The header was absent from the sampled final HTML response.

    Suggested fix: Add a tested Content-Security-Policy. Start in report-only mode if necessary.

    Show evidence and next steps

    Why it matters: CSP can limit the impact of injected content.

    What we found:
    • Final HTTP response headers

    How to verify: Inspect the final response headers after deployment.

    Confidence: observedSuggested owner: DeveloperEstimated effort: hours

  • No click-ID field was visible on sampled formsmedium

    1 form were observed; 0 exposed a supported click-ID field.

    Suggested fix: Verify click IDs are captured, stored on the CRM record and returned with eligible outcomes.

    Show evidence and next steps

    Why it matters: Persisting ad click identifiers can make later qualified outcomes joinable to the original ad interaction.

    What we found:
    • Public form field names only

    How to verify: Submit an authorised test lead manually and inspect the receiving record.

    Confidence: inferredSuggested owner: MarketerEstimated effort: hours

  • Page title is 66 charactersmedium

    Advanced Google Ads for lead generation and ecommerce | Fire Pixel

    Suggested fix: Write a unique, descriptive title that matches the page purpose.

    Show evidence and next steps

    Why it matters: Page title helps people and search systems understand the page before visiting.

    What we found:
    • Page title: Advanced Google Ads for lead generation and ecommerce | Fire Pixel

    How to verify: Inspect the rendered head and a search preview.

    Confidence: observedSuggested owner: SEOEstimated effort: minutes

  • Strict-Transport-Security not observedmedium

    The header was absent from the sampled final HTML response.

    Suggested fix: Add a suitable Strict-Transport-Security policy after confirming every subdomain is HTTPS-ready.

    Show evidence and next steps

    Why it matters: HSTS tells supporting browsers to keep using HTTPS.

    What we found:
    • Final HTTP response headers

    How to verify: Inspect the final response headers after deployment.

    Confidence: observedSuggested owner: DeveloperEstimated effort: hours

  • No frame-embedding restriction was observedmedium

    No frame-embedding restriction was observed

    Suggested fix: Set CSP frame-ancestors or X-Frame-Options where legacy support is needed.

    Show evidence and next steps

    Why it matters: Clickjacking protection reduces unwanted framing.

    What we found:
    • HTTP response headers

    How to verify: Repeat the same public check after the change.

    Confidence: observedSuggested owner: DeveloperEstimated effort: minutes

  • Permissions policy not observedmedium

    The header was absent from the sampled final HTML response.

    Suggested fix: Set a restrictive Permissions-Policy for unused browser capabilities.

    Show evidence and next steps

    Why it matters: Permissions-Policy limits access to powerful browser features.

    What we found:
    • Final HTTP response headers

    How to verify: Inspect the final response headers after deployment.

    Confidence: observedSuggested owner: DeveloperEstimated effort: hours

  • Referrer policy not observedmedium

    The header was absent from the sampled final HTML response.

    Suggested fix: Set an explicit Referrer-Policy appropriate to the site.

    Show evidence and next steps

    Why it matters: A referrer policy limits URL information sent to other origins.

    What we found:
    • Final HTTP response headers

    How to verify: Inspect the final response headers after deployment.

    Confidence: observedSuggested owner: DeveloperEstimated effort: hours

  • No DNSSEC DS record observedlow

    No DS record was returned. This does not test every resolver or validate the complete chain.

    Suggested fix: Consider enabling DNSSEC with coordinated registrar and DNS-provider configuration.

    Show evidence and next steps

    Why it matters: DNSSEC can provide origin authentication for DNS answers when the validation chain is correct.

    What we found:
    • DS query through DNS over HTTPS

    How to verify: Validate the complete chain with an independent DNSSEC tool.

    Confidence: inferredSuggested owner: ITEstimated effort: hours

Methodology and limitations

Bounded analysis of publicly accessible pages, DNS, registries and configured providers. No login, form submission, port scan or exploit testing.

  • The report is a bounded public sample, not a complete crawl, account audit, accessibility certification, legal compliance review or penetration test.
  • Technology and hosting detections are confidence-ranked fingerprints. They do not prove ownership, configuration quality, exact version or vulnerability.
  • A browser request shows that the page attempted a destination. It does not prove storage, reporting, attribution or use by an advertising algorithm.
  • The public scanner does not log in, submit forms, complete checkout, download files, scan ports or test exploits.