Skip to content
Audit Complete

Results for https://shotprep.io

Visit site
Netherlands Netherlands · Amsterdam Completed: Apr 17, 2026 03:52 UTC
Download Markdown Report
D60

Site Health

Score: 60 / 100

Based on 4 categories, 27 sections

Several missing protections leave your users and data exposed.

Major barriers for users with disabilities — up to 15% of your audience.

Solid infrastructure — fast server responses across the board.

Several regulatory requirements are not yet met.

How is this calculated?

The overall score is a weighted average of individual category scores. Categories with more impact on user experience and security carry more weight.

Security 25%Accessibility 15%Infrastructure 10%Compliance 8%

Weights reflect general web best practices. Individual needs may differ.

How the composite score is calculated

How you compare

Google Search Console sites average 73
-13 below average
Google Workspace sites average 74
-14 below average

Top Priorities (5)

1

Content-Security-Policy header is missing

Security gaps expose your site and users to attacks, eroding trust.

Security › Security Headers
2

No Content-Security-Policy header found

Security gaps expose your site and users to attacks, eroding trust.

Security › Content Security Policy
3

Cross-Origin-Embedder-Policy header is missing

Security gaps expose your site and users to attacks, eroding trust.

Security › Security Headers
4

Cross-Origin-Opener-Policy header is missing

Security gaps expose your site and users to attacks, eroding trust.

Security › Security Headers
5

HSTS is missing includeSubDomains

Security gaps expose your site and users to attacks, eroding trust.

Security › Security Headers
View fix priority matrix

Fix Priority Matrix

5 findings

Quick Wins

5

High impact, low effort — start here.

Strategic

0

High impact, requires investment.

Nothing in this quadrant — good news.

Easy Improvements

0

Small gains, minimal effort.

Nothing in this quadrant — good news.

Deprioritize

0

Low impact, high effort — do last.

Nothing in this quadrant — good news.

← Low effort High effort →
BeaverCheck badge
Embed this badge
[![BeaverCheck](https://beavercheck.com/badge?url=https%3A%2F%2Fshotprep.io)](https://beavercheck.com/results/10ed841b-abd5-4cf4-bb47-e0c0264eeba3)
<a href="https://beavercheck.com/results/10ed841b-abd5-4cf4-bb47-e0c0264eeba3"><img src="https://beavercheck.com/badge?url=https%3A%2F%2Fshotprep.io" alt="BeaverCheck Score"></a>
https://beavercheck.com/badge?url=https%3A%2F%2Fshotprep.io

This badge auto-updates with your latest scan result.

What fixing these means

Your site has several issues that may be affecting user experience and business outcomes. Addressing the critical issues below would have the most immediate impact on your user trust.

5 security gaps detected — browsers may warn visitors about your site.

Conversion Barriers

1 critical 2 warning

3 barrier(s) likely increasing bounce by ~22%.

Trust (2)

No HSTS header

+1% bounce

Returning visitors are briefly exposed to downgrade attacks on first request

Fix: Set Strict-Transport-Security: max-age=31536000; includeSubDomains

No Content-Security-Policy header

+1% bounce

Higher XSS blast radius — one compromised script can exfiltrate the checkout form

Fix: Ship a reporting-only CSP first, then enforce once violations are clean

Usability (1)

No viewport meta tag

+15% bounce

Mobile browsers render at desktop width and shrink — text unreadable, tap targets miniature

Fix: Add <meta name="viewport" content="width=device-width, initial-scale=1">

Preliminary CRO audit — each barrier links to the tab with detailed analysis.

Return on Investment

$250 investment → $0.00/month returns + USD 7,500 risk avoided

First-year ROI: -100%

Investment

$250

2h · 5 findings

Monthly returns

$0.00 /mo

~$0.00 / year

    Regulatory risk avoided

    USD 7,500

    if kept compliant

    • CCPA/CPRA USD 7,500

    Figures combine localized regulatory fine ceilings, search/conversion value priced against local CPC, and bandwidth waste estimates. Results depend on implementation quality and audience composition. Not legal or financial advice.

    Full methodology & sources

    Estimated Remediation Cost

    $250

    2.5 developer hours at $100/hr

    Based on United States rates ($100/hr)

    Quick wins
    $250 5 fixes in ~150 minutes

    Start here for the best return on investment

    Cost by category

    Cost by effort level

    Adjust assumptions
    $ /hr

    Rates reflect fully-loaded developer cost including overhead

    How developer rates are sourced

    What Inaction Is Costing You

    $625 / month at risk

    ~$7,500 / year if left unfixed

    Compliance Risk

    $7,500

    CCPA/CPRA
    • No privacy policy link detected
      CCPA/CPRA: USD 2,500 – USD 7,500

    Compliance figures represent the statutory maximum fine for the most severe triggered category, capped per regulation — not the sum of per-finding penalties. Based on published regulatory fine ranges. This is not legal advice.

    Compliance methodology · SEO assumptions · Bandwidth model

    Was this report useful?

    Thanks for your feedback!

    Global Performance 6/6 locations
    US Santa Clara
    Full audit
    282ms
    DNS 19ms · TLS 14ms
    BR Sao Paulo
    1524ms
    DNS 8ms · TLS 128ms
    UN New York
    840ms
    DNS 28ms · TLS 17ms
    SG Singapore
    1749ms
    DNS 8ms · TLS 13ms
    ES Madrid
    1273ms
    DNS 34ms · TLS 40ms
    NL Amsterdam
    614ms
    DNS 9ms · TLS 134ms
    CDN: Vercel (MISS) · Avg TTFB: 1047ms · Cache: no-store
    Recent Trends
    Performance stable →
    58
    TTFB stable →
    1.5s
    FCP stable →
    1.2s
    LCP stable →
    4.9s

    We'll use a cached audit if available, or offer to scan.

    Checking for existing audit...

    Lighthouse Scores

    Industry-standard audits powered by Google Lighthouse.

    Core Web Vitals

    Key metrics that affect user experience.

    Desktop audit not available for this result.

    Send Feedback