Skip to content

Changes

https://nextjs.org
Compared to previous audit · 32 minutes ago View previous audit

Santa Clara, United States Madrid, Spain

These audits ran from different locations. Timing metrics (TTFB, DNS, TLS) may reflect network path differences rather than site changes.

7
New issues
6
Resolved
11
score changes
CategoryPreviousCurrentChange
CompositeB (82)B (81) -1.000
PerformanceB (89)B (88) -1.000
SecurityB (85)B (85)
AccessibilityC (75)C (75)
SEOC (76)C (76)
InfrastructureB (88)B (88)
ComplianceD (63)D (63)
ContentC (73)C (73)
SustainabilityA (93)A (92) -1.000
MetricPreviousCurrentChange
Performance 59004800 -1100
Accessibility 96009600
Best Practices 92009200
SEO 1000010000
PWA 00
FCP 3.08 s3.08 s
LCP 5.82 s5.73 s -89 ms
TBT 422 ms1.05 s +629 ms
CLS 0.0000.000
TTFB 173 ms169 ms -4 ms
DNS 33 ms6 ms -26 ms
TLS 37 ms9 ms -28 ms
Connect 1 ms3 ms +3 ms
Total 179 ms185 ms +7 ms

† Timing metrics may vary by worker location and do not necessarily indicate site changes.

WARNING JavaScript is 515 KB — consider code splitting or lazy loading performance
WARNING Unattributable: 519ms CPU time performance
WARNING Trackers detected but no privacy policy found compliance
WARNING HTTP→HTTPS redirect uses 302 instead of 301 infrastructure
WARNING https://nextjs.org/_next/static/chunks/0a1x1u7w7w_...: 2460ms CPU time performance
WARNING https://nextjs.org/: 1782ms CPU time performance
WARNING Trackers detected but no cookie policy found compliance
WARNING https://nextjs.org/: 976ms CPU time performance
WARNING No SPF record found security
WARNING HTTP→HTTPS redirect is not permanent infrastructure
WARNING JavaScript is 570 KB — consider code splitting or lazy loading performance
WARNING https://nextjs.org/_next/static/chunks/0a1x1u7w7w_...: 1589ms CPU time performance
WARNING Unattributable: 338ms CPU time performance
CRITICAL 'unsafe-inline' found in script source security
CRITICAL 'unsafe-eval' found in script source security
CRITICAL Page has only 18 words — nearly empty seo
WARNING base-uri directive is missing security
WARNING Referrer-Policy has a weak value security
WARNING Permissions-Policy header is missing security
WARNING Skip navigation link is missing (WCAG 2.4.1) accessibility
WARNING Cross-Origin-Embedder-Policy header is missing security
WARNING 1 link(s) open in new tab without warning accessibility
WARNING https://nextjs.org/_next/static/chunks/0a1x1u7w7w_...: 23 KB unused (32%) performance
WARNING No meta description tag found seo
WARNING No Open Graph meta tags found content
WARNING No <nav> landmark found accessibility
WARNING https://nextjs.org/_next/static/chunks/3u6nxjif50j...: 35 KB unused (99%) performance
WARNING Title is only 26 characters — consider expanding seo
WARNING No internal links found seo
WARNING Dead-end page — no outgoing internal links seo
WARNING No privacy policy link detected compliance
WARNING Cross-Origin-Opener-Policy header is missing security
WARNING frame-ancestors directive is missing security
WARNING Thin content — only 18 words seo
WARNING Registrar lock is NOT enabled infrastructure
WARNING No accessibility statement detected compliance
WARNING GDPR Article 13 disclosure coverage: 0 / 8 categories compliance
WARNING Privacy Policy not detected compliance
WARNING Terms of Service not detected compliance
WARNING X-Powered-By header reveals technology stack security
WARNING No headings found accessibility
WARNING form-action directive is missing security
WARNING No canonical tag found seo
WARNING https://nextjs.org/_next/static/chunks/0la2krl14st...: 28 KB unused (58%) performance
x-vercel-id
cdg1::pdx1::cwlwp-1778262865696-bcc646f673a5 sfo1::pdx1::vwrww-1778264796947-f35b9ba70570

19 headers unchanged

Technology stack unchanged

8 technologies unchanged

Looking ahead

+13 pts
B (81) Could reach A (94)
SEO +20Compliance +17Security +15Accessibility +13Performance +12Infrastructure +8Content +4

Estimate — actual results may vary (38 issues to fix)

Website improvement report — Nextjs

May 8, 2026 → May 8, 2026

B B 82 → 81 -1 pts

6

Resolved

7

New issues

31

Still remaining

Financial summary

Investment delivered

$858 in development time

Investment remaining

$8,192 to complete the remaining items

Ongoing risk

$0/month in ongoing exposure

Figures are estimates based on local developer hourly rate, industry CPC, and regulatory fine ranges.

Performance by category

MetricBeforeAfterChange
Overall score82 (B)81 (B)-1
Performance89 (B)88 (B)-1
Security85 (B)85 (B)0
Accessibility75 (C)75 (C)0
SEO76 (C)76 (C)0
Infrastructure88 (B)88 (B)0
Compliance63 (D)63 (D)0
Content73 (C)73 (C)0
Sustainability93 (A)92 (A)-1

Resolved (6)

  • https://nextjs.org/: 976ms CPU time (Performance)

    → Page loads faster for users

  • No SPF record found (Security)

    → Reduced attack surface for visitors

  • HTTP→HTTPS redirect is not permanent (Infrastructure)

    → More reliable delivery

  • JavaScript is 570 KB — consider code splitting or lazy loading (Performance)

    → Page loads faster for users

  • https://nextjs.org/_next/static/chunks/0a1x1u7w7w_...: 1589ms CPU time (Performance)

    → Page loads faster for users

  • Unattributable: 338ms CPU time (Performance)

    → Page loads faster for users

Recommended next steps (38)

  • Sprint 3

    'unsafe-inline' found in script source (Security)

  • Sprint 3

    'unsafe-eval' found in script source (Security)

  • Sprint 3

    Page has only 18 words — nearly empty (SEO)

  • Sprint 3

    JavaScript is 515 KB — consider code splitting or lazy loading (Performance)

  • Sprint 1

    Unattributable: 519ms CPU time (Performance)

  • Sprint 2

    Trackers detected but no privacy policy found (Compliance)

  • Sprint 3

    HTTP→HTTPS redirect uses 302 instead of 301 (Infrastructure)

  • Sprint 1

    https://nextjs.org/_next/static/chunks/0a1x1u7w7w_...: 2460ms CPU time (Performance)

  • Sprint 1

    https://nextjs.org/: 1782ms CPU time (Performance)

  • Sprint 2

    Trackers detected but no cookie policy found (Compliance)

  • Sprint 1

    base-uri directive is missing (Security)

  • Sprint 1

    Referrer-Policy has a weak value (Security)

  • Sprint 1

    Permissions-Policy header is missing (Security)

  • Sprint 1

    Skip navigation link is missing (WCAG 2.4.1) (Accessibility)

  • Sprint 2

    Cross-Origin-Embedder-Policy header is missing (Security)

…and 23 more recommended item(s)

Send Feedback