Skip to content

Changes

https://costdown.org
Compared to previous audit · 5 hours ago View previous audit
2
New issues
0
Resolved
13
score changes
CategoryPreviousCurrentChange
CompositeA (91)A (91)
PerformanceA+ (97)A+ (97)
SecurityB (89)B (89)
AccessibilityA (90)A (90)
SEOA (95)A (95)
InfrastructureA (90)B (88) -2.000
ComplianceB (82)B (85) +3.000
ContentB (85)B (85)
SustainabilityA+ (98)A+ (98)
MetricPreviousCurrentChange
Performance 89008600 -300
Accessibility 96009600
Best Practices 1000010000
SEO 91009100
PWA 00
Desktop Performance 98009800
Desktop Accessibility 96009600
Desktop Best Practices 1000010000
Desktop SEO 92009200
FCP 1.47 s1.49 s +19 ms
LCP 3.50 s3.81 s +310 ms
TBT 130 ms134 ms +4 ms
CLS 0.0000.000
Desktop FCP 537 ms558 ms +20 ms
Desktop LCP 1.08 s1.06 s -17 ms
Desktop TBT 0 ms0 ms
Desktop CLS 0.0000.000
TTFB 337 ms341 ms +4 ms
DNS 1 ms37 ms +36 ms
TLS 24 ms28 ms +4 ms
Connect 17 ms16 ms -0 ms
Total 705 ms357 ms -348 ms

† Timing metrics may vary by worker location and do not necessarily indicate site changes.

WARNING https://costdown.org/: 254ms CPU time performance
WARNING 1 render-blocking <script src> tag(s) without async/defer performance

No issues were resolved

CRITICAL Both www and non-www versions serve content infrastructure
WARNING No accessibility statement detected compliance
WARNING Cross-Origin-Embedder-Policy header is missing security
WARNING Permissions-Policy header not set -- features default to allow-on-same-origin security
WARNING No DMARC record found security
WARNING No Permissions-Policy header security
WARNING 1 images significantly larger than display size content
WARNING Permissions-Policy header is missing security
WARNING X-Powered-By header reveals technology stack security
WARNING No SPF record found security
WARNING Skip navigation link is missing (WCAG 2.4.1) accessibility
WARNING All 1 images use legacy formats (JPEG/PNG/GIF) content
WARNING Cross-Origin-Opener-Policy header is missing security
WARNING Registrar lock is NOT enabled infrastructure
link
</_next/static/media/62c97acc3aa63787-s.p.woff2>; rel=preload; as="font"; cro... </_next/static/media/62c97acc3aa63787-s.p.woff2>; rel=preload; as="font"; cro...
content-security-policy
default-src 'self'; script-src 'self' 'nonce-ZNm8y/uBD8sAbTKAbySrCA==' https:... default-src 'self'; script-src 'self' 'nonce-qahhE5l5vHRP+Ponwit1aw==' https:...

13 headers unchanged

Technology stack unchanged

11 technologies unchanged

Looking ahead

+6 pts
A (91) Could reach A+ (97)
Infrastructure +12Security +11Content +8Accessibility +4Compliance +4Performance +3

Estimate — actual results may vary (16 issues to fix)

Website improvement report — Costdown

August 27, 2026 → August 27, 2026

A A 91 → 91 0 pts

0

Resolved

2

New issues

14

Still remaining

Financial summary

Investment remaining

₫6,900,000 to complete the remaining items

Ongoing risk

₫3,348/month in ongoing exposure

Figures are estimates based on local developer hourly rate, industry CPC, and regulatory fine ranges.

Performance by category

MetricBeforeAfterChange
Overall score91 (A)91 (A)0
Performance97 (A+)97 (A+)0
Security89 (B)89 (B)0
Accessibility90 (A)90 (A)0
SEO95 (A)95 (A)0
Infrastructure90 (A)88 (B)-2
Compliance82 (B)85 (B)+3
Content85 (B)85 (B)0
Sustainability98 (A+)98 (A+)0

Recommended next steps (16)

  • Sprint 1

    Both www and non-www versions serve content (Infrastructure)

  • Sprint 1

    https://costdown.org/: 254ms CPU time (Performance)

  • Sprint 2

    1 render-blocking <script src> tag(s) without async/defer (Performance)

  • Sprint 1

    No accessibility statement detected (Compliance)

  • Sprint 2

    Cross-Origin-Embedder-Policy header is missing (Security)

  • Sprint 1

    Permissions-Policy header not set -- features default to allow-on-same-origin (Security)

  • Sprint 2

    No DMARC record found (Security)

  • Sprint 1

    No Permissions-Policy header (Security)

  • Sprint 2

    1 images significantly larger than display size (Content)

  • Sprint 1

    Permissions-Policy header is missing (Security)

  • Sprint 1

    X-Powered-By header reveals technology stack (Security)

  • Sprint 1

    No SPF record found (Security)

  • Sprint 1

    Skip navigation link is missing (WCAG 2.4.1) (Accessibility)

  • Sprint 2

    All 1 images use legacy formats (JPEG/PNG/GIF) (Content)

  • Sprint 1

    Cross-Origin-Opener-Policy header is missing (Security)

…and 1 more recommended item(s)

Send Feedback