Skip to content

Changes

https://costdown.org
Compared to previous audit · 7 minutes ago View previous audit
3
New issues
1
Resolved
13
score changes
CategoryPreviousCurrentChange
CompositeA (93)A (92) -1.000
PerformanceA+ (97)A (96) -1.000
SecurityA (93)A (93)
AccessibilityA (90)A (90)
SEOA+ (97)A (94) -3.000
InfrastructureA (90)A (90)
ComplianceB (85)B (85)
ContentB (85)B (85)
SustainabilityA+ (98)A+ (98)
MetricPreviousCurrentChange
Performance 95009200 -300
Accessibility 96009600
Best Practices 1000010000
SEO 91009100
PWA 00
Desktop Performance 98009900 +100
Desktop Accessibility 96009600
Desktop Best Practices 1000010000
Desktop SEO 92009200
FCP 1.24 s1.24 s
LCP 2.89 s3.33 s +435 ms
TBT 87 ms42 ms -44 ms
CLS 0.0000.000
Desktop FCP 546 ms532 ms -13 ms
Desktop LCP 1.05 s875 ms -174 ms
Desktop TBT 0 ms0 ms
Desktop CLS 0.0000.000
TTFB 381 ms421 ms +40 ms
DNS 36 ms30 ms -6 ms
TLS 23 ms22 ms -1 ms
Connect 17 ms17 ms
Total 464 ms470 ms +5 ms

† Timing metrics may vary by worker location and do not necessarily indicate site changes.

WARNING 1 render-blocking <script src> tag(s) without async/defer performance
WARNING https://costdown.org/: 437ms CPU time performance
WARNING https://costdown.org/_next/static/chunks/1255-fc6c...: 421ms CPU time performance
WARNING https://costdown.org/: 319ms CPU time performance
CRITICAL Both www and non-www versions serve content infrastructure
WARNING 1 images significantly larger than display size content
WARNING No DMARC record found security
WARNING No SPF record found security
WARNING Skip navigation link is missing (WCAG 2.4.1) accessibility
WARNING Registrar lock is NOT enabled infrastructure
WARNING No accessibility statement detected compliance
WARNING All 1 images use legacy formats (JPEG/PNG/GIF) content
WARNING Cross-Origin-Embedder-Policy header is missing security
WARNING X-Powered-By header reveals technology stack security
content-security-policy
default-src 'self'; script-src 'self' 'nonce-rkElveg+Vklz1XoDq9CjEg==' https:... default-src 'self'; script-src 'self' 'nonce-/PMN6VsihtLgT9v05HuB3Q==' https:...
link
</_next/static/media/62c97acc3aa63787-s.p.woff2>; rel=preload; as="font"; cro... </_next/static/media/62c97acc3aa63787-s.p.woff2>; rel=preload; as="font"; cro...

15 headers unchanged

Technology stack unchanged

11 technologies unchanged

Looking ahead

+5 pts
A (92) Could reach A+ (97)
Infrastructure +10Content +8Security +7Accessibility +4Compliance +4Performance +4

Estimate — actual results may vary (13 issues to fix)

Website improvement report — Costdown

August 27, 2026 → August 27, 2026

A A 93 → 92 -1 pts

1

Resolved

3

New issues

10

Still remaining

Financial summary

Investment remaining

₫6,150,000 to complete the remaining items

Ongoing risk

₫2,515/month in ongoing exposure

Figures are estimates based on local developer hourly rate, industry CPC, and regulatory fine ranges.

Performance by category

MetricBeforeAfterChange
Overall score93 (A)92 (A)-1
Performance97 (A+)96 (A)-1
Security93 (A)93 (A)0
Accessibility90 (A)90 (A)0
SEO97 (A+)94 (A)-3
Infrastructure90 (A)90 (A)0
Compliance85 (B)85 (B)0
Content85 (B)85 (B)0
Sustainability98 (A+)98 (A+)0

Resolved (1)

  • https://costdown.org/: 319ms CPU time (Performance)

    → Page loads faster for users

Recommended next steps (13)

  • Sprint 1

    Both www and non-www versions serve content (Infrastructure)

  • Sprint 2

    1 render-blocking <script src> tag(s) without async/defer (Performance)

  • Sprint 1

    https://costdown.org/: 437ms CPU time (Performance)

  • Sprint 1

    https://costdown.org/_next/static/chunks/1255-fc6c...: 421ms CPU time (Performance)

  • Sprint 2

    1 images significantly larger than display size (Content)

  • Sprint 2

    No DMARC record found (Security)

  • Sprint 1

    No SPF record found (Security)

  • Sprint 1

    Skip navigation link is missing (WCAG 2.4.1) (Accessibility)

  • Sprint 1

    Registrar lock is NOT enabled (Infrastructure)

  • Sprint 1

    No accessibility statement detected (Compliance)

  • Sprint 2

    All 1 images use legacy formats (JPEG/PNG/GIF) (Content)

  • Sprint 2

    Cross-Origin-Embedder-Policy header is missing (Security)

  • Sprint 1

    X-Powered-By header reveals technology stack (Security)

Send Feedback