https://static.winc.com.au/jpeg/ab/853332ce43e9b53... is missing width/height — may cause layout shift
Set explicit width and height to prevent CLS.
Warning::
!
https://www.winc.com.au/media/images/new/winc_prim... is missing width/height — may cause layout shift
Set explicit width and height to prevent CLS.
Warning::
!
is missing width/height — may cause layout shift
Set explicit width and height to prevent CLS.
Warning::
!
https://static.winc.com.au/jpeg/76/c9f5400b8ba0e93... is missing width/height — may cause layout shift
Set explicit width and height to prevent CLS.
37images1.5 MB
0oversized-0 KB
36legacy format
4missing dimensionsCLS risk
Set explicit width and height to prevent CLS.
Why this matters
Image without explicit width/height — browser can't reserve space; CLS jumps when image loads.
Source: web.dev / Core Web Vitals
Set explicit width and height to prevent CLS.
Why this matters
Image without explicit width/height — browser can't reserve space; CLS jumps when image loads.
Source: web.dev / Core Web Vitals
Set explicit width and height to prevent CLS.
Why this matters
Performance issues directly impact user engagement and conversion rates.
Set explicit width and height to prevent CLS.
Why this matters
Image without explicit width/height — browser can't reserve space; CLS jumps when image loads.
Source: web.dev / Core Web Vitals
B
HTTP/3 (QUIC)
HTTP/3 not advertised
REVIEW
HTTP/3 not advertised
Info::
i
HTTP/3 (QUIC) is not advertised
HTTP/3 isn't advertised via Alt-Svc and the worker didn't negotiate h3. HTTP/3 reduces handshake latency (1-RTT instead of 2-3 RTTs) and is more resilient on lossy connections. Most modern CDNs (Cloudflare, Fastly, AWS CloudFront, Google Cloud CDN) support HTTP/3 with a single config switch -- consider enabling for mobile-heavy workloads.
B
Document Compression
Document response uses gzip; brotli would be ~20% smaller
REVIEW
Document response uses gzip; brotli would be ~20% smaller
Info::
i
Main HTML response uses gzip (brotli would be ~20% smaller)
All current browsers support brotli. Most CDNs (Cloudflare, Fastly, AWS CloudFront, Vercel, Netlify) can switch from gzip to brotli with a single config flag. Origin servers (nginx, Apache) need a brotli module compiled in -- nginx-brotli or Apache mod_brotli.
B
Server-Timing Observability
No Server-Timing header found
REVIEW
No Server-Timing header found
Info::
i
No Server-Timing header found
Server-Timing exposes backend timing breakdowns to browser DevTools (e.g., `db: 45ms; render: 120ms; cache: 2ms`). Useful for diagnosing slow pages without backend log access. Most modern frameworks (Next.js, Cloudflare Workers, Fastly) emit it automatically; absence on a managed platform usually means telemetry headers are stripped at the edge.
C
JavaScript Blocking
Action
3 JS blocking issue(s) detected
REVIEW
3 JS blocking issue(s) detected
Warning::
!
18 render-blocking <script src> tag(s) without async/defer
Each `<script src=...>` without `async`, `defer`, or `type="module"` blocks HTML parsing while the browser fetches and executes it. The block lasts the entire round-trip + execution time -- on slow networks this translates directly into LCP delay. Add `defer` (executes after parse, in source order) for scripts that interact with the DOM, or `async` (executes whenever ready) for analytics / independent scripts. Module scripts (`type="module"`) are deferred by default.
`document.write()` blocks all parallel resource discovery while it executes. Chrome explicitly disables the preload scanner on connections it judges slow when document.write is detected, serializing the entire subtree load. Almost always third-party ad / analytics legacy code; replacing with createElement + appendChild (or refusing to integrate the offending vendor) recovers significant load-time on mobile.
Warning::
!
Total JS execution time is 4.4 s -- over the 3.5s budget
Total JavaScript execution (parse + compile + run) across all scripts exceeds 3.5 seconds. On low-end devices that becomes 7-15+ seconds and shows up directly in TBT and INP. Reduce by: tree-shaking unused dependencies, code-splitting (dynamic `import()`), removing or deferring third-party tracking, and replacing heavy frameworks where they're not needed.
C
Green Hosting
Action
Whether the site is served from green-energy infrastructure
REVIEW
Green Hosting
No green hosting detected
B
HTTP Caching
no-cache
REVIEW
no-cache
Info::
✓
Cache-Control header is set
Got: no-cache
Info::
i
No ETag or Last-Modified header
Conditional requests (304 Not Modified) are not possible without validators.
Cache-Control
no-cache
Directive
Value
Meaning
no-cache
—
Cache but always revalidate first
A+
Text Compression
All text resources are compressed
PASS
All text resources are compressed
Info::
✓
All text resources are compressed
All text resources are properly compressed.
A+
Font Loading
3 fonts (233 KB)
PASS
3 fonts (233 KB)
Info::
i
3 font(s) use font-display: swap (FOUT risk but functional)
Web fonts
3
233 KB total
Render-blocking
0
of 3
Dominant font-display
swap
Most common across fonts
Font loading timeline
TransferFOIT (block)FOUT (swap)
KFO7CnqEu92Fr1ME7kSn66a...woff2swap
Size37 KB
Load time36 ms
Start2.6 s
RiskFOUT — text flashes from fallback to web font
QGYsz_wNahGAdqQ43Rh_fKD...woff2swap
Size49 KB
Load time21 ms
Start2.7 s
RiskFOUT — text flashes from fallback to web font
fa-solid-900.woff2woff2swap
Size147 KB
Load time281 ms
Start2.7 s
RiskFOUT — text flashes from fallback to web font
Subset this font — over 100 KB suggests Latin Extended or full glyph coverage that most pages don't need
Optimization checklist
Preload critical fonts (priority=high)
Use woff2 format for all fonts
Set font-display to swap, optional, or fallback
Subset large fonts (≤100 KB each)
Fixing the unchecked items could save ~73 KB and ~146 ms
A+
Resource Caching
All resources properly cached
PASS
All resources properly cached
Info::
✓
No caching issues found
All static resources have appropriate caching headers.
A+
Critical Rendering Path
No render-blocking resources
PASS
No render-blocking resources
Info::
✓
No render-blocking resources detected
A+
Resource Hints
7 hints, 0 missing preconnects
PASS
7 hints, 0 missing preconnects
Info::
i
3 dns-prefetch redundant with preconnect on same origin
preconnect already does the DNS lookup; adding dns-prefetch to the same origin is at best a no-op. Sample: https://fonts.googleapis.com, https://dpm.demdex.net, https://smetrics.winc.com.au. Remove the redundant dns-prefetch entries.
Info::
✓
Page uses 7 resource hint(s)
Current Resource Hints
preconnect
3
preload—
dns-prefetch
4
prefetch—
7 resource hints configured
preconnect already does the DNS lookup; adding dns-prefetch to the same origin is at best a no-op. Sample: https://fonts.googleapis.com, https://dpm.demdex.net, https://smetrics.winc.com.au. Remove the redundant dns-prefetch entries.
Why this matters
Performance issues directly impact user engagement and conversion rates.
A
Asset Compression
1 of 2 asset hosts still on gzip
PASS
1 of 2 asset hosts still on gzip
Info::
✓
static.winc.com.au serves assets with brotli (assets: 33)
Got: static.winc.com.au (application/javascript)
Info::
i
staplesanz.my.site.com serves assets with gzip; brotli would be ~20% smaller (assets: 4)
Every current browser accepts brotli. On a CDN this is a per-pull-zone toggle (Cloudflare, Fastly, CloudFront, CDN77, Bunny all expose it); on an origin it needs the brotli module (nginx-brotli, Apache mod_brotli). The saving lands on the assets this host serves, not on the HTML document -- the document's own encoding is reported separately.
Got: staplesanz.my.site.com (text/css)
A+
LCP Image Preload
LCP preload audit not available
PASS
LCP preload audit not available
Info::
✓
LCP image preload audit not available for this scan
A+
Main HTML Cache-Control
Main HTML uses no-cache -- safe revalidate-on-request policy
PASS
Main HTML uses no-cache -- safe revalidate-on-request policy
Info::
✓
Main HTML uses no-cache -- safe revalidate-on-request policy
Got: no-cache
A+
Server Response Intelligence
2 server-response signal(s) detected
PASS
2 server-response signal(s) detected
Info::
✓
`Vary` header declared: Accept-Encoding
The page declares a `Vary` header, telling downstream caches which request headers the response varies on. Critical for content-negotiated responses (compression, language, cookies, device class).
Info::
i
No `ETag` or `Last-Modified` -- conditional GET not supported
Without either header, browsers can't issue conditional GETs and refresh always re-downloads the full response body even when nothing changed. Add `ETag: "<hash>"` (or `Last-Modified: <date>`) on cacheable responses; the server returns 304 Not Modified when the client's cached copy is still valid, saving bandwidth.
A+
Render-Blocking Resources
No render-blocking resources detected
PASS
No render-blocking resources detected
Info::
✓
No render-blocking resources detected in <head>
A+
Third-Party Resources
No third-party resources detected
PASS
No third-party resources detected
A+
CSS Performance Depth
No CSS performance depth issues detected
PASS
No CSS performance depth issues detected
Info::
✓
No CSS performance depth issues detected
Network Waterfall
113 requests over 5288ms
INFO
HTML JavaScript CSS Images Fonts XHR/Fetch Other
Third-Party Script Cost
Per-script blocking time, transfer cost, and cache headers
INFO
35%of JavaScript execution is third-party
First-party Third-party1555ms · 445KB · A$41/mo
Script
Category
Execution
Transfer
Unused
Monthly Cost
Verdict
Google Tag Manager
www.googletagmanager.com
Tag Manager
745ms
187 KB
30%
A$20/mo
Costly
Google Tag Manager
www.googletagmanager.com
Tag Manager
311ms
133 KB
50%
A$8/mo
Costly
cdn.mouseflow.com
cdn.mouseflow.com
Other
169ms
53 KB
82%
A$4/mo
Optional
LinkedIn Insight
snap.licdn.com
Advertising
109ms
21 KB
—
A$3/mo
Optional
Google Analytics
www.google-analytics.com
Analytics
85ms
21 KB
—
A$2/mo
Optional
static.winc.com.au
static.winc.com.au
Other
80ms
4 KB
—
A$2/mo
Optional
staplesanz.my.site.com
staplesanz.my.site.com
Other
56ms
26 KB
—
A$1/mo
Optional
Google Tag Manager
Tag Manager
Costly
Execution745ms
Transfer187 KB
Unused30%
Monthly CostA$20/mo
Google Tag Manager
Tag Manager
Costly
Execution311ms
Transfer133 KB
Unused50%
Monthly CostA$8/mo
cdn.mouseflow.com
Other
Optional
Execution169ms
Transfer53 KB
Unused82%
Monthly CostA$4/mo
LinkedIn Insight
Advertising
Optional
Execution109ms
Transfer21 KB
Monthly CostA$3/mo
Google Analytics
Analytics
Optional
Execution85ms
Transfer21 KB
Monthly CostA$2/mo
static.winc.com.au
Other
Optional
Execution80ms
Transfer4 KB
Monthly CostA$2/mo
staplesanz.my.site.com
Other
Optional
Execution56ms
Transfer26 KB
Monthly CostA$1/mo
These scripts may cost more than they're worth
Google Tag Manager adds 745ms and costs ~A$20/month
Google Tag Manager adds 311ms and costs ~A$8/month
Google Tag Manager takes 745ms of CPU time. Consider loading it asynchronously or replacing it with a lighter alternative.
Why this matters
This script has high main-thread execution time — optimize hot paths or defer.
Source: web.dev
Google Tag Manager takes 311ms of CPU time. Consider loading it asynchronously or replacing it with a lighter alternative.
Why this matters
This script has high main-thread execution time — optimize hot paths or defer.
Source: web.dev
82% of cdn.mouseflow.com's code is unused. The script may be loading features you don't use.
Why this matters
Bundle has high unused-code ratio — tree-shaking and route-splitting recover the wasted bytes.