Skip to content

Changes

https://stripe.com
Compared to previous audit · 1 day ago View previous audit

New York, United Stated Amsterdam, Netherlands

These audits ran from different locations. Timing metrics (TTFB, DNS, TLS) may reflect network path differences rather than site changes.

24
New issues
17
Resolved
22
score changes
CategoryPreviousCurrentChange
CompositeB (81)B (82) +1.000
PerformanceC (78)C (79) +1.000
SecurityB (84)B (85) +1.000
AccessibilityC (72)C (76) +4.000
SEOA (93)A (95) +2.000
InfrastructureA (91)A (92) +1.000
ComplianceC (71)C (70) -1.000
ContentB (81)B (84) +3.000
SustainabilityC (75)C (75)
MetricPreviousCurrentChange
Performance 30003200 +200
Accessibility 1000010000
Best Practices 1000010000
SEO 92009200
PWA 00
Desktop Performance 51005100
Desktop Accessibility 1000010000
Desktop Best Practices 960010000 +400
Desktop SEO 92009200
FCP 3.09 s2.75 s -338 ms
LCP 7.74 s9.39 s +1.65 s
TBT 101.26 s89.51 s -11.75 s
CLS 0.0280.000 -0.028
Desktop FCP 1.01 s833 ms -175 ms
Desktop LCP 1.76 s1.99 s +237 ms
Desktop TBT 23.02 s23.11 s
Desktop CLS 0.0150.009 -0.006
TTFB 252 ms45 ms -206 ms
DNS 4 ms3 ms -2 ms
TLS 25 ms12 ms -14 ms
Connect 21 ms8 ms -13 ms
Total 252 ms69 ms -183 ms

† Timing metrics may vary by worker location and do not necessarily indicate site changes.

CRITICAL 1 tracking cookie(s) set before consent interaction compliance
CRITICAL 1 non-essential cookie(s) set without consent banner compliance
WARNING Page weight 2.4 MB exceeds 1 MB target by 1.4 MB performance
WARNING Referrer-Policy: `no-referrer-when-downgrade` -- leaky -- legacy default that sends full URL cross-origin on HTTPS-to-HTTPS security
WARNING https://stripe.com/: 2717ms CPU time performance
WARNING All 46 images use legacy formats (JPEG/PNG/GIF) content
WARNING SRI adoption: 0/77 third-party resources protected (0%) security
WARNING Permissions-Policy header not set -- features default to allow-on-same-origin security
WARNING https://b.stripecdn.com/mkt-ssr-statics/assets/_ne...: 117342ms CPU time performance
WARNING 170 HTTP requests — consider bundling or reducing performance
WARNING https://b.stripecdn.com/mkt-ssr-statics/assets/_ne...: 3169ms CPU time performance
WARNING Unattributable: 2387ms CPU time performance
WARNING Cookie 'cid' is missing the HttpOnly flag security
WARNING Third-party scripts: 125750ms (98% of total) performance
WARNING Total JS execution time is 128.5 s -- over the 3.5s budget performance
WARNING 6 render-blocking stylesheet(s) -- recommended: <=3 performance
WARNING 38 images missing alt text content
WARNING https://b.stripecdn.com/mkt-ssr-statics/assets/_ne...: 937ms CPU time performance
WARNING 133 text node(s) render below 12 CSS pixels on mobile accessibility
WARNING JavaScript is 1.8 MB — consider code splitting or lazy loading performance
WARNING https://b.stripecdn.com/mkt-ssr-statics/assets/_ne...: 71 KB unused (21%) performance
WARNING 163 third-party resources (93% of weight) performance
WARNING Third-party code accounts for 93% of page weight (2.2 MiB of 2.4 MiB) performance
WARNING 0.68g CO2 — above the median website (0.60g) sustainability
WARNING JavaScript is 1.3 MB — consider code splitting or lazy loading performance
WARNING Unattributable: 2454ms CPU time performance
WARNING Page weight 1.8 MB exceeds 1 MB target by 819 KB performance
WARNING 2 heading(s) are over 120 characters -- likely a misformatted paragraph accessibility
WARNING https://b.stripecdn.com/mkt-ssr-statics/assets/_ne...: 70 KB unused (21%) performance
WARNING 107 third-party resources (90% of weight) performance
WARNING https://b.stripecdn.com/mkt-ssr-statics/assets/_ne...: 4437ms CPU time performance
WARNING Canonical does not match final URL (https://stripe.com/nl) seo
WARNING https://b.stripecdn.com/mkt-ssr-statics/assets/_ne...: 1324ms CPU time performance
WARNING 115 HTTP requests — consider bundling or reducing performance
WARNING Third-party code accounts for 90% of page weight (1.6 MiB of 1.8 MiB) performance
WARNING https://b.stripecdn.com/mkt-ssr-statics/assets/_ne...: 124694ms CPU time performance
WARNING Privacy Policy not detected compliance
WARNING https://stripe.com/en-nl: 3116ms CPU time performance
WARNING 34 images missing alt text content
WARNING Third-party scripts: 133211ms (96% of total) performance
WARNING All 42 images use legacy formats (JPEG/PNG/GIF) content
CRITICAL 28 link(s) with no accessible text accessibility
CRITICAL og:image is not reachable content
WARNING Skip navigation link is missing (WCAG 2.4.1) accessibility
WARNING GDPR Article 13 disclosure coverage: 1 / 8 categories compliance
WARNING 197 of 200 links are healthy content
WARNING Broken link: https://images.stripeassets.com content
WARNING Broken link: https://assets.stripeassets.com content
WARNING External link from b.stripecdn.com lacks integrity attribute security
WARNING External script from b.stripecdn.com lacks integrity attribute security
WARNING https://b.stripecdn.com/mkt-ssr-statics/assets/_ne...: 42 KB unused (76%) performance
WARNING Missing required property "name" for WebSite content
WARNING 4 images significantly larger than display size content
WARNING 1 empty heading(s) accessibility
WARNING https://b.stripecdn.com/mkt-ssr-statics/assets/_ne...: 106 KB unused (45%) performance
WARNING Registrar lock is NOT enabled infrastructure
WARNING 2 images missing explicit width/height content
WARNING Cross-Origin-Embedder-Policy header is missing security
WARNING security.txt has expired security
WARNING 1 link(s) with generic text accessibility
WARNING <iframe> missing title attribute (src="https://b.stripecdn.com/stripethirdparty-srv/assets/v32.1/PrivacyCompliance.htm…") accessibility
WARNING No accessibility statement detected compliance
WARNING Missing required property "url" for WebSite content
WARNING Multiple H1 headings (2 found) accessibility
WARNING 175 inline style attribute(s) detected security
WARNING No Permissions-Policy header security
WARNING 1 link(s) open in new tab without warning accessibility
WARNING <iframe> missing title attribute (src="https://b.stripecdn.com/stripethirdparty-srv/assets/v32.1/GoogleTagManager.html…") accessibility
WARNING Broken link: https://stripe.com/b.stripecdn.com content
WARNING Permissions-Policy header is missing security
+ set-cookie cid=bd69674e-20b9-f51b-89ea-f350e2224b43; Path=/; Domain=stripe.com; Max-Age=...
+ x-mkt-cache HIT
content-length 0
location https://stripe.com/nl
content-security-policy
base-uri 'none'; child-src 'none'; connect-src https://c.increment.com https:... base-uri 'none'; child-src 'none'; connect-src https://c.increment.com https:...
x-stripe-server-rpc-duration-micros
55228 56211
reporting-endpoints
coop="https://q.stripe.com/coop-report", wsp_coop="https://q.stripe.com/coop-... coop="https://q.stripe.com/coop-report", wsp_coop="https://q.stripe.com/coop-...

10 headers unchanged

Technology stack unchanged

21 technologies unchanged

Looking ahead

+16 pts
B (82) Could reach A+ (98)
Accessibility +24Compliance +22Performance +21Content +16Security +15Infrastructure +4Sustainability +4

Estimate — actual results may vary (53 issues to fix)

Website improvement report — Stripe

May 8, 2026 → May 10, 2026

B B 81 → 82 +1 pts

17

Resolved

24

New issues

29

Still remaining

Financial summary

Investment delivered

$4,325 in development time

Investment remaining

$9,158 to complete the remaining items

Ongoing risk

$13,126/month in ongoing exposure

Figures are estimates based on local developer hourly rate, industry CPC, and regulatory fine ranges.

Performance by category

MetricBeforeAfterChange
Overall score81 (B)82 (B)+1
Performance78 (C)79 (C)+1
Security84 (B)85 (B)+1
Accessibility72 (C)76 (C)+4
SEO93 (A)95 (A)+2
Infrastructure91 (A)92 (A)+1
Compliance71 (C)70 (C)-1
Content81 (B)84 (B)+3
Sustainability75 (C)75 (C)0

Resolved (17)

  • JavaScript is 1.3 MB — consider code splitting or lazy loading (Performance)

    → Page loads faster for users

  • Unattributable: 2454ms CPU time (Performance)

    → Page loads faster for users

  • Page weight 1.8 MB exceeds 1 MB target by 819 KB (Performance)

    → Page loads faster for users

  • 2 heading(s) are over 120 characters -- likely a misformatted paragraph (Accessibility)

    → Improved usability for assistive technology users

  • https://b.stripecdn.com/mkt-ssr-statics/assets/_ne...: 70 KB unused (21%) (Performance)

    → Page loads faster for users

  • 107 third-party resources (90% of weight) (Performance)

    → Page loads faster for users

  • https://b.stripecdn.com/mkt-ssr-statics/assets/_ne...: 4437ms CPU time (Performance)

    → Page loads faster for users

  • Canonical does not match final URL (https://stripe.com/nl) (SEO)

    → Better search engine visibility

  • https://b.stripecdn.com/mkt-ssr-statics/assets/_ne...: 1324ms CPU time (Performance)

    → Page loads faster for users

  • 115 HTTP requests — consider bundling or reducing (Performance)

    → Page loads faster for users

  • Third-party code accounts for 90% of page weight (1.6 MiB of 1.8 MiB) (Performance)

    → Page loads faster for users

  • https://b.stripecdn.com/mkt-ssr-statics/assets/_ne...: 124694ms CPU time (Performance)

    → Page loads faster for users

  • Privacy Policy not detected (Compliance)

    → Reduced regulatory exposure

  • https://stripe.com/en-nl: 3116ms CPU time (Performance)

    → Page loads faster for users

  • 34 images missing alt text (Content)

    → Stronger social sharing and on-page quality

…and 2 more resolved issue(s)

Recommended next steps (53)

  • Sprint 2

    1 tracking cookie(s) set before consent interaction (Compliance)

  • Sprint 2

    1 non-essential cookie(s) set without consent banner (Compliance)

  • Sprint 1

    28 link(s) with no accessible text (Accessibility)

  • Sprint 1

    og:image is not reachable (Content)

  • Sprint 2

    Page weight 2.4 MB exceeds 1 MB target by 1.4 MB (Performance)

  • Sprint 1

    Referrer-Policy: `no-referrer-when-downgrade` -- leaky -- legacy default that sends full URL cross-origin on HTTPS-to-HTTPS (Security)

  • Sprint 1

    https://stripe.com/: 2717ms CPU time (Performance)

  • Sprint 2

    All 46 images use legacy formats (JPEG/PNG/GIF) (Content)

  • Sprint 1

    SRI adoption: 0/77 third-party resources protected (0%) (Security)

  • Sprint 1

    Permissions-Policy header not set -- features default to allow-on-same-origin (Security)

  • Sprint 1

    https://b.stripecdn.com/mkt-ssr-statics/assets/_ne...: 117342ms CPU time (Performance)

  • Sprint 2

    170 HTTP requests — consider bundling or reducing (Performance)

  • Sprint 1

    https://b.stripecdn.com/mkt-ssr-statics/assets/_ne...: 3169ms CPU time (Performance)

  • Sprint 1

    Unattributable: 2387ms CPU time (Performance)

  • Sprint 1

    Cookie 'cid' is missing the HttpOnly flag (Security)

…and 38 more recommended item(s)

Send Feedback