New: The State of Indie Launches: May 2026. What 17,652 indie launch pages run on once you strip Vercel out. Read

← Back to browse

The Client Onboarding Blueprint

Practical AI guides and automation tools built for small business owners and entrepreneurs. No tech skills needed. Start growing smarter today.

bluination.myshopify.com · Added June 4, 2026 · Last analysed June 4, 2026 · via · 70% unique tagline

StackScope is a free public catalogue of indie launches. We find launches on Product Hunt, Hacker News and similar feeds, then crawl each site to detect its tech stack and score it for launch readiness: DNS, security headers, SEO basics. This page is what we saw on 4 June 2026; the live site may have changed since.

The Client Onboarding Blueprint ships with the launch fundamentals in place, with complete legal pages, a thorough launch checklist, and clean crawl signals. What needs work: missing Referrer-Policy and Permissions-Policy and no email security records.

Launched on Product Hunt on June 4, 2026. The site is hosted on Cloudflare in Canada. Our crawler found 10 technologies on this site, covering advertising, build tooling, CDN, and ecommerce. The stack includes Shopify, Vite, and Bugsnag.

Notably, it's one of 50 launches on this exact stack and tighter on security headers than most Product Hunt launches.

If you own this site, refresh the snapshot and see the full fix list any time →

8.7
StackScope Score
Excellent
88/100 Launch Readiness
Launch ready
3/3 Legal
Complete
2/2 Web Standards
Complete
Vibe Score 5 · Few AI signals
Informational pattern-match signal. Does not feed the StackScope Score. See which fingerprints fired →

Tech Stack (10)

Infrastructure
CDN Cloudflare
Protocol HTTP/3
Security HSTS
Build & Framework
Build tool Vite
WordPress plugin WooCommerce Pixel Manager
Analytics & Marketing
Advertising TikTok
Commerce & Payments
Ecommerce Shopify
Business Tools
Error tracking Bugsnag
Fraud prevention Riskified
Reviews Judge.me

Infrastructure

Network
AS13335 · CA
DNSSEC
Enabled
DNSKEY records published. DNS responses signed.
SSL Certificate
Let's Encrypt
Valid 10 May 2026 to 8 Aug 2026
Certificate as captured in this snapshot, not a live check.

Email Security

SPF Not published. Your domain can be spoofed in phishing emails.
?
DKIM Not detected at common selectors. Your provider may use a custom one.
DMARC Not published. Receivers fall back to permissive defaults.
?
MTA-STS Not deployed. Mail to your domain can be downgraded to plaintext en route.
?
TLS-RPT Not configured. You won't hear about silent SMTP TLS handshake failures.

Storage (19)

Cookies (10)
NameLifetimeDetected as
localization 1y -
ttcsid 3mo TikTok
ttcsid_D8483VBC77U37PM8A5N0 3mo TikTok
_shopify_analytics 1y Shopify
_shopify_essential 1y Shopify
_shopify_marketing 1y Shopify
_shopify_s < 1h Shopify
_shopify_y 1y Shopify
_shop_app_essential 1y Shopify
_ttp 3mo TikTok
Local storage (2)
KeySizeDetected as
bugsnag-anonymous-id 25 B Bugsnag
shopifyChatData 97 B Shopify
Session storage (7)
KeySizeDetected as
consentHeader 38 B Shopify
ri-cZAkR9LRSdGz1PJAgNNH4ReAVjOV-z 13 B Riskified
tt_appInfo_v2 17 B TikTok
tt_sessionId 60 B TikTok
tt_s_pixel_session_index 20 B TikTok
wpm-ri-71902447-d2d1-49d1-b3d4-f24080d347e1-1780563395-z 13 B WooCommerce Pixel Manager
_shs_state 129 B Shopify

Readiness Breakdown How?

Custom title and meta description
Open Graph tags (title, image, description)
Twitter card meta tags
Canonical URL declared
Responsive viewport meta tag
Semantic HTML (nav, main, article)
- Favicon present

Performance How?

155 ms Server response
79% Faster than peers
608 ms Largest contentful paint
0.00 Cumulative layout shift
2.8 MB Page weight
451 KB Image weight
6 Third-party domains
0 Console errors
0 Failed requests

11 images: 1 oversized, 9 missing alt text

Indicative grade from a single automated render, not a substitute for Lighthouse or field data, and not part of the StackScope score.

Vibe Score Breakdown How?

SignalPoints
AI writing signals +5

This score is based on structural patterns and is not definitive. Many legitimate sites may trigger signals, and AI-built sites may go undetected. It should be treated as an indicator, not a verdict.

AI Stance

Welcomes AI crawlers
llms.txt published
No AI bots blocked in robots.txt
? No directive declared
? None advertised

Well-Known Files

sitemap.xml (5 URLs)
security.txt
llms.txt
ads.txt
humans.txt
38% unique

Security Headers (4/6)

Permissions-Policy experimental (check browser support)
Content-Security-Policy ⚠ CSP violation detected: your policy is blocking 1 of your own resource
X-XSS-Protection deprecated (use Content-Security-Policy)

Build

HTML minified
CSS minified
JS minified
Code splitting
Source maps exposed
57 JS files
4 CSS files
6 Third-party domains

Brand Colours

Something not look right? If a technology shown here is wrong or out of date, email [email protected] and we'll review it.