All checks
Content & UXhighlegal-page-placeholderchecked on every page we scan

Legal page placeholder

This page is a legal document your visitors are asked to accept, and it still contains fields nobody filled in.

Why it matters

This page is a legal document your visitors are asked to accept, and it still contains fields nobody filled in. Unfilled terms are unenforceable where they matter, and a policy that visibly says “[Your State/Country]” tells every reader that no one checked the page that governs their refunds and their data.

How ShipReady detects it

Six page-readable Content & UX rules. Genuinely per-page: a polished homepage routinely hides a /pricing that still shows `{{plan_name}}` and a /terms governed by the laws of `[Your State]`. Reads only already-fetched HTML. Detection is uniform across all six: match a maintained pattern corpus against the page's READABLE TEXT — markup stripped, scripts stripped, and `<code>`/`<pre>`/`<kbd>`/`<samp>` stripped first — never against raw HTML. A minified bundle contains the very strings these rules look for, and a docs page legitimately displays them inside a code sample; matching source rather than prose would fire on both. Pages the crawler labelled Docs or Content are skipped entirely by the two artifact rules, because quoting an artifact is what those pages are for.

Detection is deterministic. ShipReady reports this only when it observes the condition directly, and prefers to miss a real problem over inventing one. Rule version 1.0.0.

How to fix it

This is the prompt ShipReady puts in your report — written to be pasted straight into Cursor, Claude Code, or whichever assistant built the app.

Your Terms or Privacy page still contains unfilled placeholders — bracketed fields, TBD markers, or an effective date that has not arrived. Fill in every one: your legal entity name, your jurisdiction (the state or country whose law governs the agreement), your contact address for legal and privacy requests, and a real effective date. Then read the document through once as a whole; generated policies routinely describe practices that do not match what your app actually does, such as data you do not collect or a retention period you do not enforce. If the document covers anything consequential — payments, health data, children's data, EU users — have a lawyer read it. An unfilled term is unenforceable exactly where it matters.

Frequently asked questions

What does "Legal page placeholder" mean?
This page is a legal document your visitors are asked to accept, and it still contains fields nobody filled in.
How serious is it?
ShipReady rates this high. Fix before launch. A real weakness that an attacker can act on.
How do I fix it?
Paste the fix prompt on this page into Cursor, Claude Code or your AI editor. It is the same prompt ShipReady puts in your report.
Can I check my own site?
Yes — ShipReady scans up to ten pages of any public site for free and reports this alongside every other check. The free report lists every issue it finds and shows full evidence and a fix prompt for the critical and high-severity ones; medium and low findings are counted and unlock on Pro.

Related checks

Run this check on your site

ShipReady checks this and 193 other things across up to ten pages of your site, with an AI-ready fix for each. Free, no signup.