Changes
| Category | Previous | Current | Change |
|---|---|---|---|
| Composite | A (93) | A (93) | — |
| Performance | A (94) | A (93) | -1.000 |
| Security | A (96) | A+ (97) | +1.000 |
| Accessibility | A (90) | A (90) | — |
| SEO | A (91) | A (91) | — |
| Infrastructure | A (92) | A (92) | — |
| Compliance | B (88) | B (88) | — |
| Content | A (96) | A (96) | — |
| Sustainability | A+ (98) | A+ (98) | — |
| Metric | Previous | Current | Change |
|---|---|---|---|
| Performance | 8800 | 9400 | +600 |
| Accessibility | 10000 | 10000 | — |
| Best Practices | 7300 | 8800 | +1500 |
| SEO | 10000 | 10000 | — |
| PWA | 0 | 0 | — |
| Desktop Performance | 10000 | 9900 | -100 |
| Desktop Accessibility | 10000 | 10000 | — |
| Desktop Best Practices | 7300 | 8800 | +1500 |
| Desktop SEO | 10000 | 10000 | — |
| FCP | 1.44 s | 1.61 s | +172 ms |
| LCP | 3.01 s | 2.89 s | -128 ms |
| TBT | 31 ms | 0 ms | -31 ms |
| CLS | 0.142 | 0.000 | -0.142 |
| Desktop FCP | 467 ms | 444 ms | -23 ms |
| Desktop LCP | 594 ms | 821 ms | +226 ms |
| Desktop TBT | 0 ms | 0 ms | — |
| Desktop CLS | 0.051 | 0.053 | +0.002 |
| TTFB | 695 ms | 700 ms | — |
| DNS † | 46 ms | 39 ms | -7 ms |
| TLS † | 23 ms | 24 ms | +1 ms |
| Connect † | 17 ms | 17 ms | -0 ms |
| Total | 696 ms | 701 ms | — |
† Timing metrics may vary by worker location and do not necessarily indicate site changes.
content-security-policy-report-only require-trusted-types-for 'script'; trusted-types defaultcontent-security-policy default-src 'self'; script-src 'self' 'unsafe-inline' https://images.dmca.com... → default-src 'self'; script-src 'self' 'sha256-LwlyZ40NRTXa//NUj9jB46qFF2SwkOD...set-cookie sl-session=WKddP/FqGmpkFbNztlF1Jw==; SameSite=None; Secure; Path=/; Max-Age=8... → sl-session=4YrzJwmjGmocF0MFr8Xo2w==; SameSite=None; Secure; Path=/; Max-Age=8...18 headers unchanged
Technology stack unchanged
5 technologies unchanged
Looking ahead
+6 ptsEstimate — actual results may vary (15 issues to fix)
Website improvement report — Nu11cyber
May 29, 2026 → May 29, 2026
6
Resolved
6
New issues
9
Still remaining
Financial summary
Investment delivered
¥4,929 in development time
Investment remaining
¥10,208 to complete the remaining items
Ongoing risk
¥0/month in ongoing exposure
Figures are estimates based on local developer hourly rate, industry CPC, and regulatory fine ranges.
Performance by category
| Metric | Before | After | Change |
|---|---|---|---|
| Overall score | 93 (A) | 93 (A) | 0 |
| Performance | 94 (A) | 93 (A) | -1 |
| Security | 96 (A) | 97 (A+) | +1 |
| Accessibility | 90 (A) | 90 (A) | 0 |
| SEO | 91 (A) | 91 (A) | 0 |
| Infrastructure | 92 (A) | 92 (A) | 0 |
| Compliance | 88 (B) | 88 (B) | 0 |
| Content | 96 (A) | 96 (A) | 0 |
| Sustainability | 98 (A+) | 98 (A+) | 0 |
Resolved (6)
https://nu11cyber.com/assets/index-C-6R4z5q.js: 20 KB unused (70%) (Performance)
→ Page loads faster for users
https://nu11cyber.com/: 566ms CPU time (Performance)
→ Page loads faster for users
'unsafe-inline' found in script source (Security)
→ Reduced attack surface for visitors
<iframe> missing title attribute (src="") (Accessibility)
→ Improved usability for assistive technology users
https://nu11cyber.com/assets/index-C-6R4z5q.js: 3312ms CPU time (Performance)
→ Page loads faster for users
Unattributable: 427ms CPU time (Performance)
→ Page loads faster for users
Recommended next steps (15)
- Sprint 3
Page has only 41 words — nearly empty (SEO)
- Sprint 2
1 non-essential cookie(s) set without consent banner (Compliance)
- Sprint 1
Soft 404: server returns HTTP 200 for non-existent pages (Accessibility)
- Sprint 1
https://nu11cyber.com/assets/index-CCYJbel1.js: 3407ms CPU time (Performance)
- Sprint 2
1 render-blocking <script src> tag(s) without async/defer (Performance)
- Sprint 1
https://nu11cyber.com/: 498ms CPU time (Performance)
- Sprint 1
Unattributable: 400ms CPU time (Performance)
- Sprint 1
https://nu11cyber.com/assets/vendor-BdZgHC1P.js: 255ms CPU time (Performance)
- Sprint 2
Total JS execution time is 4.6 s -- over the 3.5s budget (Performance)
- Sprint 1
Skip navigation link is missing (WCAG 2.4.1) (Accessibility)
- Sprint 2
1 font preload(s) missing `crossorigin` -- font will be downloaded twice (Performance)
- Sprint 1
Registrar lock is NOT enabled (Infrastructure)
- Sprint 2
All 3 images use legacy formats (JPEG/PNG/GIF) (Content)
- Sprint 1
HSTS max-age is too short (0s, should be ≥ 31536000s) (Security)
- Sprint 3
Thin content — only 41 words (SEO)