
Not launch-ready as it stands. Zero images are hotlinked and the enforcement-photographer scan is clean, yet 57 licensed photos are shown without the credit their licence requires, and 51 scraped commercial photos carry no licence at all.
No, on two counts. 51 photos scraped from businesses' own websites are self-hosted with no licence on record (commercial photos are all-rights-reserved by default), and 57 Creative-Commons photos are used in breach of their licence because the required credit isn't shown where they appear.
On article pages, yes — every credit renders correctly. On hub pages, cross-link thumbnails and the global menu, no. 11 of the uncredited photos are CC BY 2.0 — the same licence, with no cure window, as the photo in the Pixsy / Ermert claim.
Provenance is recorded at rest for every CC photo (credits.json), so the first layer holds. The second layer — the credit rendered on the page — is missing for those 57. The 51 scraped photos have neither layer.
We collected every image reference in the built site (img, srcset, source, video and poster, Open Graph, icons, inline styles, CSS backgrounds and JSON-LD), cross-checked the set with the site's own image audit and a raw off-domain host scan, then mapped each file to its licence and author from the project's credit records. We measured against Creative Commons 2.0–4.0 licence terms and the rule that every third-party CC image must render its credit on the page that displays it. We also scanned every author field for the photographer behind the recent claim.
Layer 1 — provenance recorded: the licence, author and source URL are stored when the image is downloaded. Layer 2 — credit rendered: a visible, linked credit appears on every page the image is shown. A CC image needs both. Recorded-but-not-rendered still breaches the licence — and it is exactly how the Pixsy image slipped through elsewhere in the portfolio.
| Licence bucket | Files | Attribution | Status |
|---|---|---|---|
| Public Domain / CC0 (Wikimedia) | 73 | Not required | Compliant |
| CC BY (2.0–4.0) | 68 | Required | 20 shown uncredited |
| CC BY-SA (2.0–4.0) | 88 | Required + share-alike | 37 shown uncredited |
| GFDL | 2 | Required | Credited |
| CC-derived guide-hero cutouts | 6 | Required | Credited |
| Own — property / brand / AI art / cutouts | 139 | — | Compliant |
| Own — hero video (Veo) | 2 | — | Compliant |
| Airline logos (trademark) | 3 | Trademark | Noted |
| Scraped — restaurant photos | 31 | Unknown | No licence — high risk |
| Scraped — directory photos | 20 | Unknown | No licence — high risk |
Good: the provenance record (credits.json) is not served publicly. Of 158 attribution-required Wikimedia photos in use, 101 are credited everywhere; 57 are the gap.
The global navigation dropdown renders seven food and drink photos as thumbnails on every page. About 854 of the 1,021 uncredited placements come from this one component.
| Photo | Licence | Author |
|---|---|---|
| farmers-market-1.jpg | CC BY-SA 2.0 | Connie Ma |
| island-food-1.jpg | CC BY-SA 4.0 | Dqfn13 |
| island-food-2.jpg | CC BY-SA 4.0 | GeoTrinity |
| island-food-5.jpg | CC BY-SA 4.0 | Grueslayer |
| roti-1.jpg | CC BY 3.0 | AFRICAN TIGRESS |
| rum-3.jpg | CC BY-SA 3.0 | Achim Schleuning |
| rum-distilleries-1.jpg | CC BY-SA 4.0 | CaptJayRuffins |
Add the credit line to the shared nav partial once; it then renders on all 126 pages. Or swap the menu thumbnails for owned property / AI imagery, which removes the obligation entirely.
Hub and index pages and cross-link thumbnails display CC photos without the credit line the article pages use — worst on guides/index (46 photos, 0 credits), directory/index (18/0), journal/index (17/0) and the homepage (12/0).
Render the credit component wherever a CC photo appears — extend it to the hub grid and the thumbnail / card template, not just the article body.
| CC BY 2.0 photo (uncredited) | Author of record |
|---|---|
| birds-1.jpg | Andy Reago & Chrissy McClarren |
| christiansted-13.jpg | Prayitno (Flickr) |
| christiansted-14.jpg | Prayitno (Flickr) |
| christiansted-16.jpg | Prayitno (Flickr) |
| christiansted-28.jpg | Prayitno (Flickr) |
| fishing-10.jpg | Sean Linehan, NOAA NGS |
| frederiksted-22.jpg | Prayitno (Flickr) |
| frederiksted-29.jpg | Prayitno (Flickr) |
| frederiksted-pier-6.jpg | Prayitno (Flickr) |
| golf-courses-2.jpg | evan p. cordes (Flickr) |
| rainbow-beach-1.jpg | Prayitno (Flickr) |
| Licence | Photos | Obligation |
|---|---|---|
| CC BY 2.0 | 11 | Attribution — no cure window (highest risk) |
| CC BY 3.0 | 9 | Attribution |
| CC BY-SA 2.0 | 4 | Attribution + share-alike |
| CC BY-SA 3.0 | 14 | Attribution + share-alike |
| CC BY-SA 4.0 | 19 | Attribution + share-alike |
| Total distinct photos | 57 | 1,021 uncredited placements |
The complete file-by-file list of all 57 photos, with every page each one appears on, is in the machine-readable appendix _image-legal-audit.md delivered with this report.
directory/restaurants/.| Image file | Scraped from |
|---|---|
| 1756-grotto.jpg | 1756grotto.com |
| ama-at-cane-bay.jpg | squarespace-cdn |
| b-and-b-kitchen.jpg | wsimg.com |
| beach-side-cafe.jpg | tripadvisor.com |
| beauregard-s-sushi.jpg | thebuccaneer.com |
| brew-stx.jpg | brewstx.com |
| bungalows-on-the-bay.jpg | cdn-website.com |
| caroline-s.jpg | squarespace-cdn |
| ciba-matta.jpg | cibamatta.com |
| deep-end-bar-and-grill.jpg | wsimg.com |
| duggan-s-reef.jpg | wixstatic.com |
| east-end-bar.jpg | grapetreebayhotel |
| eden-s-vegan-eatery.jpg | wixstatic.com |
| far-east-steakhouse.jpg | grapetreebayhotel |
| galangal.jpg | squarespace.com |
| in-the-mix-cakery-and-desserts.jpg | wixstatic |
| Image file | Scraped from |
|---|---|
| ital-in-paradise.jpg | website-editor.net |
| maria-s-cantina.jpg | wsimg.com |
| off-the-wall.jpg | wsimg.com |
| rhythms-at-rainbow-beach.jpg | wixstatic.com |
| rum-runners.jpg | rumrunnersstcroix |
| sea-terrace.jpg | grapetreebayhotel |
| sharkey-s-bait-stand.jpg | s4shops.com |
| shupe-s-on-the-boardwalk.jpg | shupesboardwalk |
| st-croix-cellars.jpg | stcroixcellars.com |
| the-fred.jpg | eatwithfred.com |
| the-landing-beach-bar.jpg | thelandingbeachbar |
| the-mermaid.jpg | thebuccaneer.com |
| the-terrace-at-the-buccaneer.jpg | thebuccaneer |
| umami-sushi.jpg | squarespace-cdn |
| z-cafe.jpg | squarespace-cdn |
en-wikipedia-org.jpg, sleepwithfred-com.jpg — sit on disk, unused.)| Image file | Category page |
|---|---|
| bigbeards-com.jpg | boat-charters |
| bluesaltdivers-com.jpg | scuba-diving |
| budgetstcroix-com.jpg | car-rentals |
| captaincookchartersvi-com.jpg | fishing |
| captainmorganvisitorcenter-com.jpg | rum-distilleries |
| carambola-golf.jpg | golf |
| caribbeanseaadventures-com.jpg | boat-charters, fishing |
| cruzanrum-com.jpg | rum-distilleries |
| dominoclubstx-com.jpg | bars-nightlife |
| downsouthstx-com.jpg | fishing |
| lyricsails-com.jpg | boat-charters |
| olympicstcroix-com.jpg | car-rentals |
| premierpropertiesusvi-com.jpg | catering-private-chefs |
| reefgolfstcroixusvi-com.jpg | golf |
| seasidemarketstx-com.jpg | catering, groceries |
| seathrukayaksvi-com.jpg | watersports |
| spastx-com.jpg | spas-wellness |
| sweetbottomdive-com.jpg | scuba-diving |
| thebuccaneer-com.jpg | golf |
| wfmpueblo-com.jpg | groceries-provisioning |
Replace scraped commercial photos with owned property photography, licensed CC0 / public-domain imagery, or original AI art (as already done for the restaurants hero) — or obtain written permission from each business. Never ship an all-rights-reserved photo taken from a third party's site.
credits.json is not served publicly.Worth a pass, but not licence breaches: 12 photos flagged "kill" in the record are still in use (all verified still credited); 6 photos carry a Commons title naming another place — birds-1 (San Diego), birds-6 (Mexico), coral-5/6 (Florida), pate-3 / rum-4 (Jamaica) — an accuracy nit, not a licence issue; and 8 meaningful images are missing alt text.
Scanner note: the automated pre-launch scanner reports an "external hotlink" critical that is a false positive — its check matches the required attribution links, not image sources. Manually confirmed: zero off-domain image sources.
Highest legal risk. Swap for owned, CC0/PD, or original AI imagery, or get written permission from each business. Removes an all-rights-reserved claim entirely.
No cure window. Either render their credit everywhere they appear, or replace them with owned / CC0 imagery.
Add the credit to the nav partial (clears ~854 placements at once) and to the hub grid and thumbnail / card template (the remaining 46 CC photos). This restores the second layer of protection site-wide.
Add alt text to the 8 flagged images; optionally correct the 6 wrong-location photos.
Outside this audit's image scope, the pre-launch legal scan also surfaced: Google Fonts loaded from Google's servers on every page (a GDPR item — self-host the fonts), no Accessibility Statement or Terms of Use page, a privacy policy without a data-retention clause, analytics without a default-deny consent mode, one unlabeled contact-form control, minor heading / skip-link accessibility gaps, "guarantee" and superlative wording on 14 guide pages, and Review / AggregateRating structured data on the home and villa pages. A dedicated compliance pass is recommended before go-live.
Nothing is hotlinked and there is no exposure to the photographer in the current claim — the hard parts are right. Close the credit gap in two shared templates and replace the 51 scraped photos, and the site clears its image-licensing risk for launch.