
Marks & Spencer scored B (85%) with 219 issues across 7 tested pages, ranking #22 of 22 UK retail sites. That's 95 more than the 123.7 category average (0th percentile).
Top issues to fix immediately: "JWT Token Exposed in Network Request URL" โ 1) Move authentication token from URL query parameter to HTTP Authorization header or POST body; "Multiple JWT Tokens Exposed in Session Data URLs" โ 1) Remove authentication tokens from URL-transmitted data; "Unencrypted User Email and Account Data Sent to Tracking Service in Im" โ 1) Never send user personal data (email, name, gender, account type) to third-party analytics via tracking pixels.
Weakest area โ accessibility (6/10): Text contrast appears adequate in most areas, but some smaller text may be difficult for vision-impaired users.
Quick wins: Enhance color contrast ratios for better readability, especially for smaller text elements. Implement clearer ARIA labels and alt text for all product images to improve screen reader compatibility.








Sharon ยท Security Console Log Analyzer[INFO] Connecting to 'https://click.prod.mplat-ppcprotect.com/v2/recv?lpn=n&plat=&data=eyJjbGllbnRfZGF0YSI6eyJocmVmIjoiaHR0cHM6Ly93d3cubWFya3NhbmRzcGVuY2VyLmNvbS91cy9sL29mZmVycy9zcGFya3MvIiwidG9rZW4iOiJleUpoYkdjaU9pSklVekkxTmlJc0luUjVjQ0k2SWtwWFZDSjkuZXlKaFkyTnZkVzUwWDJsa0lqb3hOalF3TVgwLjktb1lhX0pxekQ3Nll4WGR5VUdvTmpQYU82X1dEalBSZHlVVVR6M0ktSXMiLCJjbGllbnRfaWQiOjAsImx1bmlvX3Nlc3Npb25faWQiOiJhMDY2YjE2Yi00YTgwLTQ1MjMtYjdkMi1lZGVlMzhkNzIwZjAifX0'POST to click.prod.mplat-ppcprotect.com with JWT token in URL
Sharon ยท Security Console Log Analyzer[INFO] Connecting to 'https://click.prod.mplat-ppcprotect.com/v2/recv?lpn=n&plat=&data=eyJjbGllbnRfZGF0YSI6eyJocmVmIjoiaHR0cHM6Ly93d3cubWFya3NhbmRzcGVuY2VyLmNvbS91cy9sL29mZmVycy9zcGFya3MvIiwidG9rZW4iOiJleUpoYkdjaU9pSklVekkxTmlJc0luUjVjQ0k2SWtwWFZDSjkuZXlKaFkyTnZkVzUwWDJsa0lqb3hOalF3TVgwLjktb1lhX0pxekQ3Nll4WGR5VUdvTmpQYU82X1dEalBSZHlVVVR6M0ktSXMiLCJjbGllbnRfaWQiOjAsImx1bmlvX3Nlc3Npb25faWQiOiJhMDY2YjE2Yi00YTgwLTQ1MjMtYjdkMi1lZGVlMzhkNzIwZjAifX0' violates the following Content Security Policy directiveMultiple POST requests to click.prod.mplat-ppcprotect.com containing JWT and session tokens
Pete ยท Privacy Console Log Analyzer[INFO] Loading the image 'https://nova.collect.igodigital.com/c2/1395628/track_page_view?payload=%7B%22title%22%3A%22Join%20M%26S%20Sparks%20%7C%20Sparks%20Card%20Rewards%20%7C%20M%26S%20US%20US%22%2C%22url%22%3A%22https%3A%2F%2Fwww.marksandspencer.com%2Fus%2Fl%2Foffers%2Fsparks%2F%22%2C%22referrer%22%3A%22%22%2C%22user_info%22%3A%7B%22email%22%3A%22%22%2C%22details%22%3A%7B%22gender%22%3A%22N%2FA%22%2C%22name%22%3A%22%22%2C%22account_type%22%3A%22Anonymous%22%7D%7D%7D'nova.collect.igodigital.com tracking pixel containing user profile data structure