Cavmir Image Licensing & Copyright Compliance Audit — The Cerulean
Download PDF
Prepared for
The Cerulean
theceruleanstcroix.com · DEV preview: cerulean-stcroix.pages.dev

Website Image Licensing & Copyright Compliance Audit

Prepared byCavmir
DateSeptember 2026
Scope432 image assets · 126 pages (DEV)
StandardCC 2.0–4.0 · render-the-credit
©
Cavmir · Image Compliance AuditThe Cerulean
Executive summary

Self-hosting is airtight. Attribution is not.

The site owns and hosts every image and carries no exposure to the photographer behind the recent Pixsy claim — but a licensed-photo credit gap and a set of unlicensed scraped photos both need clearing before launch.
Action needed

Not launch-ready as it stands. Zero images are hotlinked and the enforcement-photographer scan is clean, yet 57 licensed photos are shown without the credit their licence requires, and 51 scraped commercial photos carry no licence at all.

432
Image assets reviewed
0
External hotlinks
57
CC photos shown uncredited
51
Photos with no licence
Your three questions, answered
Not yet

Are all the images legal?

No, on two counts. 51 photos scraped from businesses' own websites are self-hosted with no licence on record (commercial photos are all-rights-reserved by default), and 57 Creative-Commons photos are used in breach of their licence because the required credit isn't shown where they appear.

Partly

Do we follow the CC 2.0 & 4.0 rules?

On article pages, yes — every credit renders correctly. On hub pages, cross-link thumbnails and the global menu, no. 11 of the uncredited photos are CC BY 2.0 — the same licence, with no cure window, as the photo in the Pixsy / Ermert claim.

Half

Is there double protection?

Provenance is recorded at rest for every CC photo (credits.json), so the first layer holds. The second layer — the credit rendered on the page — is missing for those 57. The 51 scraped photos have neither layer.

Cavmir02
Cavmir · Image Compliance AuditThe Cerulean
Scope & method

What we checked, and against what.

Every image the DEV build actually ships — 432 unique files across 126 pages — enumerated three independent ways and matched to its licence.

We collected every image reference in the built site (img, srcset, source, video and poster, Open Graph, icons, inline styles, CSS backgrounds and JSON-LD), cross-checked the set with the site's own image audit and a raw off-domain host scan, then mapped each file to its licence and author from the project's credit records. We measured against Creative Commons 2.0–4.0 licence terms and the rule that every third-party CC image must render its credit on the page that displays it. We also scanned every author field for the photographer behind the recent claim.

The two layers of "double protection"

Layer 1 — provenance recorded: the licence, author and source URL are stored when the image is downloaded. Layer 2 — credit rendered: a visible, linked credit appears on every page the image is shown. A CC image needs both. Recorded-but-not-rendered still breaches the licence — and it is exactly how the Pixsy image slipped through elsewhere in the portfolio.

Licence bucketFilesAttributionStatus
Public Domain / CC0 (Wikimedia)73Not requiredCompliant
CC BY (2.0–4.0)68Required20 shown uncredited
CC BY-SA (2.0–4.0)88Required + share-alike37 shown uncredited
GFDL2RequiredCredited
CC-derived guide-hero cutouts6RequiredCredited
Own — property / brand / AI art / cutouts139Compliant
Own — hero video (Veo)2Compliant
Airline logos (trademark)3TrademarkNoted
Scraped — restaurant photos31UnknownNo licence — high risk
Scraped — directory photos20UnknownNo licence — high risk

Good: the provenance record (credits.json) is not served publicly. Of 158 attribution-required Wikimedia photos in use, 101 are credited everywhere; 57 are the gap.

Cavmir03
Cavmir · Image Compliance AuditThe Cerulean
Exposure 1 — licence breach (attribution)

Licensed, but shown without the credit.

57 distinct CC photos appear on at least one page with no rendered credit — 1,021 uncredited placements in total. It is structural, living in two shared components, not scattered mistakes.
All 126 pages

The dining mega-menu shows 7 CC photos, uncredited, site-wide.

The global navigation dropdown renders seven food and drink photos as thumbnails on every page. About 854 of the 1,021 uncredited placements come from this one component.

PhotoLicenceAuthor
farmers-market-1.jpgCC BY-SA 2.0Connie Ma
island-food-1.jpgCC BY-SA 4.0Dqfn13
island-food-2.jpgCC BY-SA 4.0GeoTrinity
island-food-5.jpgCC BY-SA 4.0Grueslayer
roti-1.jpgCC BY 3.0AFRICAN TIGRESS
rum-3.jpgCC BY-SA 3.0Achim Schleuning
rum-distilleries-1.jpgCC BY-SA 4.0CaptJayRuffins
Fix — one change

Add the credit line to the shared nav partial once; it then renders on all 126 pages. Or swap the menu thumbnails for owned property / AI imagery, which removes the obligation entirely.

Hub & thumbnail pages

50 more CC photos on listing pages carry no credit.

Hub and index pages and cross-link thumbnails display CC photos without the credit line the article pages use — worst on guides/index (46 photos, 0 credits), directory/index (18/0), journal/index (17/0) and the homepage (12/0).

Fix

Render the credit component wherever a CC photo appears — extend it to the hub grid and the thumbnail / card template, not just the article body.

Cavmir04
Cavmir · Image Compliance AuditThe Cerulean
Exposure 1 — highest-risk subset

Eleven of them are the Pixsy licence.

CC BY 2.0 has no cure window: once an image is used without credit, adding it later does not undo the breach. These 11 CC BY 2.0 photos are shown uncredited and should be fixed or replaced first.
CC BY 2.0 photo (uncredited)Author of record
birds-1.jpgAndy Reago & Chrissy McClarren
christiansted-13.jpgPrayitno (Flickr)
christiansted-14.jpgPrayitno (Flickr)
christiansted-16.jpgPrayitno (Flickr)
christiansted-28.jpgPrayitno (Flickr)
fishing-10.jpgSean Linehan, NOAA NGS
frederiksted-22.jpgPrayitno (Flickr)
frederiksted-29.jpgPrayitno (Flickr)
frederiksted-pier-6.jpgPrayitno (Flickr)
golf-courses-2.jpgevan p. cordes (Flickr)
rainbow-beach-1.jpgPrayitno (Flickr)
All 57 uncredited photos, by licence
LicencePhotosObligation
CC BY 2.011Attribution — no cure window (highest risk)
CC BY 3.09Attribution
CC BY-SA 2.04Attribution + share-alike
CC BY-SA 3.014Attribution + share-alike
CC BY-SA 4.019Attribution + share-alike
Total distinct photos571,021 uncredited placements

The complete file-by-file list of all 57 photos, with every page each one appears on, is in the machine-readable appendix _image-legal-audit.md delivered with this report.

Cavmir05
Cavmir · Image Compliance AuditThe Cerulean
Exposure 2 — no licence (highest legal risk)

Thirty-one restaurant photos, no licence.

Each was downloaded from the restaurant's own website or CDN and self-hosted on the directory's Restaurants page. Commercial photos are all-rights-reserved by default, and a claim direct from the owner is stronger than a CC-attribution claim — so this is the highest-risk set. All 31 appear on directory/restaurants/.

Image fileScraped from
1756-grotto.jpg1756grotto.com
ama-at-cane-bay.jpgsquarespace-cdn
b-and-b-kitchen.jpgwsimg.com
beach-side-cafe.jpgtripadvisor.com
beauregard-s-sushi.jpgthebuccaneer.com
brew-stx.jpgbrewstx.com
bungalows-on-the-bay.jpgcdn-website.com
caroline-s.jpgsquarespace-cdn
ciba-matta.jpgcibamatta.com
deep-end-bar-and-grill.jpgwsimg.com
duggan-s-reef.jpgwixstatic.com
east-end-bar.jpggrapetreebayhotel
eden-s-vegan-eatery.jpgwixstatic.com
far-east-steakhouse.jpggrapetreebayhotel
galangal.jpgsquarespace.com
in-the-mix-cakery-and-desserts.jpgwixstatic
Image fileScraped from
ital-in-paradise.jpgwebsite-editor.net
maria-s-cantina.jpgwsimg.com
off-the-wall.jpgwsimg.com
rhythms-at-rainbow-beach.jpgwixstatic.com
rum-runners.jpgrumrunnersstcroix
sea-terrace.jpggrapetreebayhotel
sharkey-s-bait-stand.jpgs4shops.com
shupe-s-on-the-boardwalk.jpgshupesboardwalk
st-croix-cellars.jpgstcroixcellars.com
the-fred.jpgeatwithfred.com
the-landing-beach-bar.jpgthelandingbeachbar
the-mermaid.jpgthebuccaneer.com
the-terrace-at-the-buccaneer.jpgthebuccaneer
umami-sushi.jpgsquarespace-cdn
z-cafe.jpgsquarespace-cdn
Cavmir06
Cavmir · Image Compliance AuditThe Cerulean
Exposure 2 — no licence (continued)

Twenty directory photos, same problem.

Scraped from each business's website and self-hosted on the directory category pages, with no licence or author recorded. (Two more — en-wikipedia-org.jpg, sleepwithfred-com.jpg — sit on disk, unused.)
Image fileCategory page
bigbeards-com.jpgboat-charters
bluesaltdivers-com.jpgscuba-diving
budgetstcroix-com.jpgcar-rentals
captaincookchartersvi-com.jpgfishing
captainmorganvisitorcenter-com.jpgrum-distilleries
carambola-golf.jpggolf
caribbeanseaadventures-com.jpgboat-charters, fishing
cruzanrum-com.jpgrum-distilleries
dominoclubstx-com.jpgbars-nightlife
downsouthstx-com.jpgfishing
lyricsails-com.jpgboat-charters
olympicstcroix-com.jpgcar-rentals
premierpropertiesusvi-com.jpgcatering-private-chefs
reefgolfstcroixusvi-com.jpggolf
seasidemarketstx-com.jpgcatering, groceries
seathrukayaksvi-com.jpgwatersports
spastx-com.jpgspas-wellness
sweetbottomdive-com.jpgscuba-diving
thebuccaneer-com.jpggolf
wfmpueblo-com.jpggroceries-provisioning
Fix — both scraped sets

Replace scraped commercial photos with owned property photography, licensed CC0 / public-domain imagery, or original AI art (as already done for the restaurants hero) — or obtain written permission from each business. Never ship an all-rights-reserved photo taken from a third party's site.

Cavmir07
Cavmir · Image Compliance AuditThe Cerulean
Verified compliant

What is already right.

The foundations are sound. These need no action — and several are the exact things that go wrong on other sites.
  • Self-hosting — 0 external hotlinks across img, srcset, source, video, poster, Open Graph, icons, inline styles, CSS and JSON-LD. The 665 Commons / Flickr URLs in the HTML are all attribution links, not image sources.
  • No phantom files — every one of the 432 referenced images exists on disk (0 broken references).
  • Enforcement scan clean — 0 hits for the photographer in the current Pixsy claim (dronepicr / Ermert). The only "falco" matches are "Dassault Falcon" jets.
  • Article-page attribution works — all 205 rendered credits match the provenance record exactly, as linked title / author / licence.
  • Map data credited — the island map credits geoBoundaries (CC BY 4.0); Natural Earth is public domain.
  • Own work confirmed — the Veo hero video, the AI restaurant painting, homepage cutouts and all property / brand imagery are original; airline logos are trademark, noted separately.
  • Provenance record not exposedcredits.json is not served publicly.
Secondary notes (not copyright)

Worth a pass, but not licence breaches: 12 photos flagged "kill" in the record are still in use (all verified still credited); 6 photos carry a Commons title naming another place — birds-1 (San Diego), birds-6 (Mexico), coral-5/6 (Florida), pate-3 / rum-4 (Jamaica) — an accuracy nit, not a licence issue; and 8 meaningful images are missing alt text.

Scanner note: the automated pre-launch scanner reports an "external hotlink" critical that is a false positive — its check matches the required attribution links, not image sources. Manually confirmed: zero off-domain image sources.

Cavmir08
Cavmir · Image Compliance AuditThe Cerulean
Remediation

Clearing it before launch.

Ordered by risk. The site is DEV / noindex today, so none of this is live yet — but it should be cleared before the domain cutover flips it public.
Priority 1

Replace or license the 51 scraped photos.

Highest legal risk. Swap for owned, CC0/PD, or original AI imagery, or get written permission from each business. Removes an all-rights-reserved claim entirely.

Priority 2

Fix the 11 CC BY 2.0 photos first.

No cure window. Either render their credit everywhere they appear, or replace them with owned / CC0 imagery.

Priority 3

Render credits in the two shared templates.

Add the credit to the nav partial (clears ~854 placements at once) and to the hub grid and thumbnail / card template (the remaining 46 CC photos). This restores the second layer of protection site-wide.

Priority 4

Housekeeping.

Add alt text to the 8 flagged images; optionally correct the 6 wrong-location photos.

Beyond images — flagged for a separate pass

Outside this audit's image scope, the pre-launch legal scan also surfaced: Google Fonts loaded from Google's servers on every page (a GDPR item — self-host the fonts), no Accessibility Statement or Terms of Use page, a privacy policy without a data-retention clause, analytics without a default-deny consent mode, one unlabeled contact-form control, minor heading / skip-link accessibility gaps, "guarantee" and superlative wording on 14 guide pages, and Review / AggregateRating structured data on the home and villa pages. A dedicated compliance pass is recommended before go-live.

Bottom line

Nothing is hotlinked and there is no exposure to the photographer in the current claim — the hard parts are right. Close the credit gap in two shared templates and replace the 51 scraped photos, and the site clears its image-licensing risk for launch.

Cavmir09