Skip to content

Changes

https://nextjs.org
Compared to previous audit · 29 minutes ago View previous audit

New York, United Stated Madrid, Spain

These audits ran from different locations. Timing metrics (TTFB, DNS, TLS) may reflect network path differences rather than site changes.

7
New issues
5
Resolved
13
score changes
CategoryPreviousCurrentChange
CompositeB (82)B (81) -1.000
PerformanceB (89)B (88) -1.000
SecurityB (85)B (85)
AccessibilityC (75)C (75)
SEOC (76)C (76)
InfrastructureB (88)B (88)
ComplianceD (63)D (63)
ContentC (73)C (73)
SustainabilityA (92)A (90) -2.000
MetricPreviousCurrentChange
Performance 61006700 +600
Accessibility 960010000 +400
Best Practices 92009200
SEO 1000010000
PWA 00
FCP 3.08 s2.16 s -923 ms
LCP 5.75 s5.35 s -397 ms
TBT 389 ms399 ms +10 ms
CLS 0.0000.000
TTFB 111 ms67 ms -43 ms
DNS 29 ms3 ms -26 ms
TLS 35 ms18 ms -18 ms
Connect 1 ms1 ms +0 ms
Total 116 ms73 ms -43 ms

† Timing metrics may vary by worker location and do not necessarily indicate site changes.

WARNING https://nextjs.org/_next/static/chunks/0a1x1u7w7w_...: 1526ms CPU time performance
WARNING https://nextjs.org/: 1349ms CPU time performance
WARNING JavaScript is 515 KB — consider code splitting or lazy loading performance
WARNING https://nextjs.org/_next/static/chunks/23n3nv5rywu...: 823ms CPU time performance
WARNING Unattributable: 567ms CPU time performance
WARNING Trackers detected but no cookie policy found compliance
WARNING Trackers detected but no privacy policy found compliance
WARNING https://nextjs.org/: 936ms CPU time performance
WARNING No SPF record found security
WARNING JavaScript is 510 KB — consider code splitting or lazy loading performance
WARNING Unattributable: 329ms CPU time performance
WARNING https://nextjs.org/_next/static/chunks/0a1x1u7w7w_...: 1545ms CPU time performance
CRITICAL 'unsafe-inline' found in script source security
CRITICAL Page has only 18 words — nearly empty seo
CRITICAL 'unsafe-eval' found in script source security
WARNING Terms of Service not detected compliance
WARNING form-action directive is missing security
WARNING HTTP→HTTPS redirect uses 302 instead of 301 infrastructure
WARNING Permissions-Policy header is missing security
WARNING base-uri directive is missing security
WARNING Registrar lock is NOT enabled infrastructure
WARNING GDPR Article 13 disclosure coverage: 0 / 8 categories compliance
WARNING frame-ancestors directive is missing security
WARNING Skip navigation link is missing (WCAG 2.4.1) accessibility
WARNING Thin content — only 18 words seo
WARNING 1 link(s) open in new tab without warning accessibility
WARNING Referrer-Policy has a weak value security
WARNING No <nav> landmark found accessibility
WARNING https://nextjs.org/_next/static/chunks/0la2krl14st...: 28 KB unused (58%) performance
WARNING No meta description tag found seo
WARNING No internal links found seo
WARNING No canonical tag found seo
WARNING No privacy policy link detected compliance
WARNING No Open Graph meta tags found content
WARNING Cross-Origin-Opener-Policy header is missing security
WARNING X-Powered-By header reveals technology stack security
WARNING https://nextjs.org/_next/static/chunks/0a1x1u7w7w_...: 23 KB unused (32%) performance
WARNING Title is only 26 characters — consider expanding seo
WARNING Cross-Origin-Embedder-Policy header is missing security
WARNING https://nextjs.org/_next/static/chunks/3u6nxjif50j...: 35 KB unused (99%) performance
WARNING No headings found accessibility
WARNING Dead-end page — no outgoing internal links seo
WARNING No accessibility statement detected compliance
WARNING Privacy Policy not detected compliance
x-vercel-id
cdg1::pdx1::77jgq-1778265152395-382bd28bd3e2 iad1::pdx1::pqb7k-1778266924759-a0bcea4b2e3f

19 headers unchanged

Technology stack unchanged

8 technologies unchanged

Looking ahead

+13 pts
B (81) Could reach A (94)
SEO +20Compliance +17Security +15Accessibility +13Performance +12Infrastructure +8Content +4

Estimate — actual results may vary (39 issues to fix)

Website improvement report — Nextjs

May 8, 2026 → May 8, 2026

B B 82 → 81 -1 pts

5

Resolved

7

New issues

32

Still remaining

Financial summary

Investment delivered

$850 in development time

Investment remaining

$7,800 to complete the remaining items

Ongoing risk

$13,125/month in ongoing exposure

Figures are estimates based on local developer hourly rate, industry CPC, and regulatory fine ranges.

Performance by category

MetricBeforeAfterChange
Overall score82 (B)81 (B)-1
Performance89 (B)88 (B)-1
Security85 (B)85 (B)0
Accessibility75 (C)75 (C)0
SEO76 (C)76 (C)0
Infrastructure88 (B)88 (B)0
Compliance63 (D)63 (D)0
Content73 (C)73 (C)0
Sustainability92 (A)90 (A)-2

Resolved (5)

  • https://nextjs.org/: 936ms CPU time (Performance)

    → Page loads faster for users

  • No SPF record found (Security)

    → Reduced attack surface for visitors

  • JavaScript is 510 KB — consider code splitting or lazy loading (Performance)

    → Page loads faster for users

  • Unattributable: 329ms CPU time (Performance)

    → Page loads faster for users

  • https://nextjs.org/_next/static/chunks/0a1x1u7w7w_...: 1545ms CPU time (Performance)

    → Page loads faster for users

Recommended next steps (39)

  • Sprint 3

    'unsafe-inline' found in script source (Security)

  • Sprint 3

    Page has only 18 words — nearly empty (SEO)

  • Sprint 3

    'unsafe-eval' found in script source (Security)

  • Sprint 1

    https://nextjs.org/_next/static/chunks/0a1x1u7w7w_...: 1526ms CPU time (Performance)

  • Sprint 1

    https://nextjs.org/: 1349ms CPU time (Performance)

  • Sprint 3

    JavaScript is 515 KB — consider code splitting or lazy loading (Performance)

  • Sprint 1

    https://nextjs.org/_next/static/chunks/23n3nv5rywu...: 823ms CPU time (Performance)

  • Sprint 1

    Unattributable: 567ms CPU time (Performance)

  • Sprint 2

    Trackers detected but no cookie policy found (Compliance)

  • Sprint 2

    Trackers detected but no privacy policy found (Compliance)

  • Sprint 1

    Terms of Service not detected (Compliance)

  • Sprint 1

    form-action directive is missing (Security)

  • Sprint 1

    HTTP→HTTPS redirect uses 302 instead of 301 (Infrastructure)

  • Sprint 1

    Permissions-Policy header is missing (Security)

  • Sprint 1

    base-uri directive is missing (Security)

…and 24 more recommended item(s)

Send Feedback