Site sweep report · Tuesday 11 August 2026

Ken's sweep is live. The instruction to count first is what made it work.

Every Priority-1 finding in Ken's sweep checked out against the live site — which is unusual and worth saying plainly. But the line that earned its keep was "each should be a search across every file, with a count reported before anything changes." Page-by-page would have missed about a third of it, including the worst page on the list, which the sweep had marked lowest-risk.

21pages searched
14pages changed
29files in the merge
18test files green
5held for Ken
The short version

Applied and live: every backlink claim on Authority Builder, the four ROI promises on Paid Ads, the retired Google Q&A feature, the paid endorsement and phantom vetting on Home Pro Network, 14 phone-Spanish claims, 13 "trusted/recommend" instances, the Business Center rename with a redirect, and the agreement acceptance that did not exist.

Held for Ken: five items — four because his own document says they need his ruling, one because it needs a number nobody has yet.

The one finding that didn't hold: the privacy/terms link paths. All four return 200. It's inconsistent styling, not a broken link.

What the cross-file count found that page-by-page could not

This is the part worth reading. Three patterns, counted across all 21 pages plus the file that generates six of them.


1

Phone Spanish — 14 wrong, not 7

The sweep named Engine 4, Josh and Paid Ads. The claim was also on three pages it never reached:

PageWrongWhat it said
paid-ads10Sweep counted 7 — the Bilingual block holds three on its own
business-center2"answers on the first ring… in English and Spanish", and demo data showing a whole phone call in Spanish
gbp-microsites1The microsite call-to-action — "answers immediately, in English or Spanish"
engine-3-retention1"Every call answered immediately, in English or Spanish"

The Bilingual section on Paid Ads is rewritten for the website and now states the limit rather than leaving it to be discovered: "Calls from your ads are answered in English."

14 fixedwebsite-scoped ones left alone
2

The page marked "lowest risk" was the worst offender

47 raw matches for "trusted" and "recommend". 13 were real. The test applied everywhere: does the word attach to a vendor who pays? An agent recommending the inspector, a client trusting him, Google's own LSA "trusted badge" and the third-party clauses in Privacy and Terms are all legitimate and were left untouched.

engine-3-retention had six — more than any other page — including "local tradespeople pay monthly to be listed and recommended" and "whoever you personally recommend" twice. It was on the unswept list, described as lowest risk.

This is the whole argument for counting first. That page carries no pricing, no earnings figures and no SEO claims, so it read as safe — and it held the highest concentration of the exact language that creates the Standards of Practice problem.

13 fixed across 4 files34 legitimate uses kept
3

One call in the sweep was wrong, and correcting it protects the client

The sweep grouped Home Pro Network's six "you approve" instances with the approval-before-send pattern that contradicts A3. They are a different thing.

Approving who is listed on your own website is not approval-before-send of content we produce. It is the inspector's control over his own directory — and the sweep's own replacement wording for the vetting claim makes that control stronger, not weaker. Rewriting those six would have removed a protection while trying to add one.

left as written, deliberately

The trap that caught me


A verification pass can be green and wrong

I fixed Authority Builder's backlink claims by hand and asserted zero remained. The assertion passed. The next FAQ rebuild put them straight back.

The FAQ blocks on six pages are generated from api/inspector/subscription.js. Editing the HTML looks correct, verifies correct, and is reverted the next time anyone runs the builder. The same was true of two Google Q&A mentions.

It bit twice before I stopped trusting the page and went to the source. Anything inside a FAQ:GENERATED block has to be fixed in that file — and a verification that runs before the rebuild proves nothing.

What is now live

Checked against the live site after the deploy, not against the repository.


4

The claims with consequences beyond copy

Authority Builder — every backlink claim and every "400+" count is gone. Google discounts syndicated press-release links, so the page's central promise was one Google specifically does not honour; presenting bulk syndicated links as an SEO benefit describes a link scheme, which is a risk to the client's own site; and "400 news publications" implied editorial coverage the MSA already denies. The page now carries the disclosure the contract contains: "This is paid distribution, not editorial coverage. No journalist is obliged to write about you, and we don't promise that any will."

Paid Ads — four promises of a positive return, removed. The MSA says we do not guarantee return on ad spend, and ad performance is the thing least in our control. What replaced them is true and is the actual differentiator: every lead the ads generate gets answered. Also removed the meta description's claim that Meta ads are managed — the page only covers Google.

Home Pro Network — the paid endorsement is gone from the Featured tier and the report P.S., and so is the "vetting process" the MSA explicitly excludes. The page's own FAQ already agreed with the MSA; only that one block claimed a process that does not exist.

verified live
5

The agreement acceptance now exists

The MSA opens "By clicking 'I Agree' at checkout… Customer agrees to this Agreement." There was no such click anywhere in the flow. Every liability cap, indemnity and arbitration clause rested on a checkbox that did not exist — and nothing would ever have said so, because the page looked finished.

It is now an unchecked box linking both documents, it blocks the payment step, and it is refused server-side as well — anyone can post straight to the endpoint, and the enrollment we would be holding in a dispute is the one created without acceptance. Confirmed against the live endpoint: it returns 400.

Stored with the timestamp and the exact wording shown, read off the page rather than retyped in code, so the record cannot drift from what the customer actually read. That is the standard the SMS consent ledger already set; this now matches it. Eleven tests guard the three variants that look fine and are not — pre-ticked, present-but-unenforced, and enforced in the browser only.

SMS consent still does not block checkout, and a test asserts it never starts to. The disclosure says consent is not a condition of purchase.

live, and refused server-side11 tests
6

The Business Center rename, with the redirect that stops a silent failure

The page had already been retitled Business Center; the file and URL had not moved. Without a redirect, /command-center hits the fallback and returns the marketing homepage with a 200 — the same silent-success failure documented two lines above it in the server code, and this URL is printed on the Josh page and in the decisions log.

Confirmed live: /command-center → 301 → /business-center.

Part 1 had also left the homepage's step-4 heading reading "Dashboard" while the body directly beneath it read "Business Center". Eight places corrected in total. Two keep the word deliberately — "Not a dashboard of metrics nobody reads" is the pejorative sense, and the word is doing real work there.

301 verified

Held for Ken

Four because his own document asks for a ruling. One because it needs a number.


These are decisions, not work items

  1. Approval before send — 34 instances across four pages. Newsletter 13, Converting Website 8, the generated source 10, Paid Ads 3. It contradicts A3's publish-by-default. The sweep says twice that this needs a ruling and not an edit, and it is right: applying it would be choosing a business policy. The exact locations are ready the moment Ken decides.
  2. The product is called "The Trusted Home Pro Network." The word being stripped everywhere else sits in the product's own name.
  3. Backlink language on two other pages (5 mentions). The sweep scoped the backlink item to Authority Builder, and its reasoning — Google discounts syndicated press-release links — does not obviously extend to a microsite ageing or a vendor sharing their own page. Flagged rather than assumed.
  4. Engine 4, Call 4 — the garbled price. Marked "Ken's call" in the sweep. One thing he may not know before deciding: the existing Notice on that call praises the price explanation, which points a careful reader straight at the fumble.
  5. 2,940 sq ft at $572 against 3,000 sq ft at $622. I tried to settle this from the code and cannot — GC's square-footage tiers are not in the repository at all. It needs Chad's price sheet.

And the rest of enroll.html, which needs decisions rather than a developer

  1. The TCPA attestation and the three other accelerant acknowledgments. Legal text we do not have — and the sweep's own note says the attestation must be captured when the list is uploaded, not inferred from terms accepted at signup.
  2. The founding-subscriber counter. It needs a real number. The last one counted three clients who were never real, and inventing a second one would repeat exactly that.
  3. Accelerants at checkout, and the porting step.

For whoever runs the next sweep


7

Three things to carry forward

The count-first instruction was right and should be standard. It is what surfaced the three missed pages and the six instances on the page marked lowest-risk. A page with no pricing and no earnings claims is not therefore safe — it can still be carrying the language that creates the legal problem.

Sweeping the live HTML will mislead you on six pages. Their FAQ blocks are generated. A future sweep will read correct text on the page that regenerates wrong from the source. Check for FAQ:GENERATED before trusting what a page says.

The repository moved 117 commits while this work was in flight. My first countercheck of the orphaned Notice said the sweep was wrong — because I was reading a three-day-old copy. It was right. Anything that compares against "the live site" has to start by proving the local copy matches it; mine did, byte for byte, only after rebasing.

Worth saying about the sweep itself

Every Priority-1 finding was accurate against the live site, including the subtle one — Call 7's second Notice really did belong to a call that had been replaced by the 11 August recordings and left its description behind. One item out of roughly forty did not hold, and it was a guess the document flagged as a guess.