Changes
| Category | Previous | Current | Change |
|---|---|---|---|
| Composite | B (87) | B (88) | +1.000 |
| Performance | B (87) | B (87) | — |
| Security | B (87) | B (89) | +2.000 |
| Accessibility | B (86) | B (86) | — |
| SEO | A+ (99) | A+ (99) | — |
| Infrastructure | A (90) | A (90) | — |
| Compliance | C (75) | C (75) | — |
| Content | A (90) | A (90) | — |
| Sustainability | C (75) | C (75) | — |
| Metric | Previous | Current | Change |
|---|---|---|---|
| Performance | 6300 | 6500 | +200 |
| Accessibility | 9200 | 9700 | +500 |
| Best Practices | 10000 | 10000 | — |
| SEO | 10000 | 10000 | — |
| PWA | 0 | 0 | — |
| Desktop Performance | 8200 | 9100 | +900 |
| Desktop Accessibility | 9200 | 9700 | +500 |
| Desktop Best Practices | 10000 | 10000 | — |
| Desktop SEO | 10000 | 10000 | — |
| FCP | 4.05 s | 4.06 s | — |
| LCP | 11.52 s | 12.44 s | +921 ms |
| TBT | 0 ms | 87 ms | +87 ms |
| CLS | 0.000 | 0.000 | — |
| Desktop FCP | 1.07 s | 1.22 s | +150 ms |
| Desktop LCP | 2.84 s | 1.41 s | -1.43 s |
| Desktop TBT | 0 ms | 0 ms | — |
| Desktop CLS | 0.000 | 0.000 | — |
| TTFB † | 440 ms | 471 ms | +31 ms |
| DNS † | 29 ms | 39 ms | +10 ms |
| TLS | 25 ms | 25 ms | — |
| Connect † | 17 ms | 17 ms | -0 ms |
| Total † | 539 ms | 572 ms | +33 ms |
† Timing metrics may vary by worker location and do not necessarily indicate site changes.
vary Accept-Encodingcross-origin-opener-policy same-origincontent-security-policy default-src 'self'; script-src 'self' 'nonce-ffefd6c7-7ce3-4f08-a296-eacca450... → default-src 'self'; script-src 'self' 'nonce-f3a38804-4bbf-4c19-a4b2-620edffb...11 headers unchanged
10 technologies unchanged
Looking ahead
+10 ptsEstimate — actual results may vary (28 issues to fix)
Website improvement report — Tomorrowspayment
September 19, 2026 → September 20, 2026
6
Resolved
4
New issues
24
Still remaining
Financial summary
Investment delivered
€213 in development time
Investment remaining
€1,828 to complete the remaining items
Ongoing risk
€1/month in ongoing exposure
Figures are estimates based on local developer hourly rate, industry CPC, and regulatory fine ranges.
Performance by category
| Metric | Before | After | Change |
|---|---|---|---|
| Overall score | 87 (B) | 88 (B) | +1 |
| Performance | 87 (B) | 87 (B) | 0 |
| Security | 87 (B) | 89 (B) | +2 |
| Accessibility | 86 (B) | 86 (B) | 0 |
| SEO | 99 (A+) | 99 (A+) | 0 |
| Infrastructure | 90 (A) | 90 (A) | 0 |
| Compliance | 75 (C) | 75 (C) | 0 |
| Content | 90 (A) | 90 (A) | 0 |
| Sustainability | 75 (C) | 75 (C) | 0 |
Resolved (6)
Unattributable: 584ms CPU time (Performance)
→ Page loads faster for users
https://tomorrowspayment.com/: 615ms CPU time (Performance)
→ Page loads faster for users
https://tomorrowspayment.com/_astro/hoisted.D3uQPd...: 824ms CPU time (Performance)
→ Page loads faster for users
Compressed response missing `Vary` header (Performance)
→ Page loads faster for users
Cross-Origin-Opener-Policy header is missing (Security)
→ Reduced attack surface for visitors
1 software version(s) disclosed in HTML: Astro v4.16.19 (Security)
→ Reduced attack surface for visitors
Recommended next steps (28)
- Sprint 1
Page weighs 6.1 MB (6.0 MB transferred) (Performance)
- Sprint 1
HTTP version does not redirect to HTTPS (Infrastructure)
- Sprint 1
112 text node(s) render below 12 CSS pixels on mobile (Accessibility)
- Sprint 1
Unattributable: 694ms CPU time (Performance)
- Sprint 1
https://tomorrowspayment.com/: 942ms CPU time (Performance)
- Sprint 1
https://tomorrowspayment.com/_astro/hoisted.D3uQPd...: 725ms CPU time (Performance)
- Sprint 2
GDPR Article 13 disclosure coverage: 1 / 8 categories (Compliance)
- Sprint 1
62 of 64 links are healthy (Content)
- Sprint 2
Images are 3.1 MB — compress or use modern formats (Performance)
- Sprint 1
https://tomorrowspayment.com/media/production/imag... is missing width/height — may cause layout shift (Performance)
- Sprint 2
Page weight 6.0 MB exceeds 1 MB target by 5.0 MB (Performance)
- Sprint 1
Registrar lock is NOT enabled (Infrastructure)
- Sprint 2
All 4 images use legacy formats (JPEG/PNG/GIF) (Content)
- Sprint 1
HSTS is enabled but max-age is short (15552000s, should be >= 31536000s) (Security)
- Sprint 1
2 field(s) would benefit from inputmode attribute (Accessibility)
…and 13 more recommended item(s)