Skip to content

Changes

https://xpenv.com
Compared to previous audit · 19 hours ago View previous audit

New York, United Stated Sao Paulo, Brazil

These audits ran from different locations. Timing metrics (TTFB, DNS, TLS) may reflect network path differences rather than site changes.

6
New issues
8
Resolved
13
score changes
CategoryPreviousCurrentChange
CompositeB (88)B (88)
PerformanceA (94)A (95) +1.000
SecurityB (86)B (85) -1.000
AccessibilityB (81)B (81)
SEOA+ (97)A+ (97)
InfrastructureB (86)A (92) +6.000
ComplianceD (69)D (69)
ContentA+ (98)A+ (98)
SustainabilityB (88)B (88)
MetricPreviousCurrentChange
Performance 64006400
Accessibility 91009100
Best Practices 73007300
SEO 1000010000
PWA 00
Desktop Performance 99009900
Desktop Accessibility 1000010000
Desktop Best Practices 73007300
Desktop SEO 1000010000
FCP 3.33 s3.01 s -317 ms
LCP 4.56 s4.29 s -277 ms
TBT 487 ms508 ms +21 ms
CLS 0.0560.056
Desktop FCP 685 ms569 ms -117 ms
Desktop LCP 765 ms944 ms +179 ms
Desktop TBT 65 ms43 ms -22 ms
Desktop CLS 0.0020.002
TTFB 56 ms425 ms +369 ms
DNS 16 ms71 ms +55 ms
TLS 11 ms11 ms
Connect 2 ms2 ms -0 ms
Total 56 ms425 ms +369 ms

† Timing metrics may vary by worker location and do not necessarily indicate site changes.

CRITICAL Broken link: https://xpenv.com/cdn-cgi/content?id=r4byGY5pr3i99gcdfsBk... content
WARNING https://xpenv.com/assets/index-BK0LHtJ6.js: 621ms CPU time performance
WARNING No DMARC record found security
WARNING https://xpenv.com/assets/index-BK0LHtJ6.js: 254 KB unused (64%) performance
WARNING Unattributable: 338ms CPU time performance
WARNING https://xpenv.com/cdn-cgi/challenge-platform/scrip...: 330ms CPU time performance
CRITICAL Broken link: https://xpenv.com/cdn-cgi/content?id=H8NlDPw3OBxy0w4kab2z... content
WARNING Unattributable: 370ms CPU time performance
WARNING https://xpenv.com/assets/index-Bv8_JCRD.js: 749ms CPU time performance
WARNING https://xpenv.com/cdn-cgi/challenge-platform/scrip...: 404ms CPU time performance
WARNING Main HTML cached for 1440 minutes -- risks stale auth / SPA state performance
WARNING https://xpenv.com/: 339ms CPU time performance
WARNING https://xpenv.com/assets/index-Bv8_JCRD.js: 259 KB unused (64%) performance
WARNING IPv6 DNS records exist but server is not reachable infrastructure
CRITICAL 1 link(s) with no accessible text accessibility
CRITICAL No H1 heading found accessibility
CRITICAL No Content-Security-Policy header found security
CRITICAL Transfer efficiency: 41% sustainability
CRITICAL Content-Security-Policy header is missing security
WARNING GDPR Article 13 disclosure coverage: 0 / 8 categories compliance
WARNING Referrer-Policy header is missing security
WARNING Cross-Origin-Opener-Policy header is missing security
WARNING 3 field(s) missing recommended autocomplete attribute accessibility
WARNING Registrar lock is NOT enabled infrastructure
WARNING Cross-Origin-Embedder-Policy header is missing security
WARNING No Permissions-Policy header security
WARNING 1 internal links have no anchor text seo
WARNING No accessibility statement detected compliance
WARNING <iframe> missing title attribute (src="") accessibility
WARNING 10 of 11 links are healthy content
WARNING X-Frame-Options header is missing security
WARNING Login form does not contain a recognizable CSRF token security
WARNING 3 field(s) would benefit from inputmode attribute accessibility
WARNING Bare server default 404 page accessibility
WARNING Permissions-Policy header is missing security
WARNING No privacy policy link detected compliance
WARNING No favicon.ico at site root accessibility
WARNING HSTS max-age is too short (15552000s, should be ≥ 31536000s) security
WARNING Permissions-Policy header not set -- features default to allow-on-same-origin security
last-modified
Tue, 26 May 2026 15:52:18 GMT Wed, 27 May 2026 19:46:39 GMT
cache-control
max-age=86400 no-store
x-ipfs-roots
bafybeicaxpnqp5f6vy5yiln6xxf2vlgg4567cooygtw37ceot6glpw4cuu QmdHsq1s3zm4QqttXqUgyVwHzbqhcrsrbUJ4rSVfiaDYmc
x-cf-ipfs-cache-status
hit miss
cf-cache-status
HIT EXPIRED

13 headers unchanged

PWA Miscellaneous

8 technologies unchanged

Looking ahead

+10 pts
B (88) Could reach A+ (98)
Accessibility +19Security +15Compliance +10Sustainability +10Performance +5Infrastructure +4SEO +3Content +2

Estimate — actual results may vary (31 issues to fix)

Website improvement report — Xpenv

May 27, 2026 → May 27, 2026

B B 88 → 88 0 pts

8

Resolved

6

New issues

25

Still remaining

Financial summary

Investment delivered

€850 in development time

Investment remaining

€2,387 to complete the remaining items

Ongoing risk

€0/month in ongoing exposure

Figures are estimates based on local developer hourly rate, industry CPC, and regulatory fine ranges.

Performance by category

MetricBeforeAfterChange
Overall score88 (B)88 (B)0
Performance94 (A)95 (A)+1
Security86 (B)85 (B)-1
Accessibility81 (B)81 (B)0
SEO97 (A+)97 (A+)0
Infrastructure86 (B)92 (A)+6
Compliance69 (D)69 (D)0
Content98 (A+)98 (A+)0
Sustainability88 (B)88 (B)0

Resolved (8)

  • Unattributable: 370ms CPU time (Performance)

    → Page loads faster for users

  • https://xpenv.com/assets/index-Bv8_JCRD.js: 749ms CPU time (Performance)

    → Page loads faster for users

  • https://xpenv.com/cdn-cgi/challenge-platform/scrip...: 404ms CPU time (Performance)

    → Page loads faster for users

  • Main HTML cached for 1440 minutes -- risks stale auth / SPA state (Performance)

    → Page loads faster for users

  • https://xpenv.com/: 339ms CPU time (Performance)

    → Page loads faster for users

  • Broken link: https://xpenv.com/cdn-cgi/content?id=H8NlDPw3OBxy0w4kab2z... (Content)

    → Stronger social sharing and on-page quality

  • https://xpenv.com/assets/index-Bv8_JCRD.js: 259 KB unused (64%) (Performance)

    → Page loads faster for users

  • IPv6 DNS records exist but server is not reachable (Infrastructure)

    → More reliable delivery

Recommended next steps (31)

  • Sprint 1

    Broken link: https://xpenv.com/cdn-cgi/content?id=r4byGY5pr3i99gcdfsBk... (Content)

  • Sprint 1

    1 link(s) with no accessible text (Accessibility)

  • Sprint 1

    No H1 heading found (Accessibility)

  • Sprint 2

    No Content-Security-Policy header found (Security)

  • Sprint 1

    Transfer efficiency: 41% (Sustainability)

  • Sprint 2

    Content-Security-Policy header is missing (Security)

  • Sprint 1

    https://xpenv.com/assets/index-BK0LHtJ6.js: 621ms CPU time (Performance)

  • Sprint 2

    No DMARC record found (Security)

  • Sprint 3

    https://xpenv.com/assets/index-BK0LHtJ6.js: 254 KB unused (64%) (Performance)

  • Sprint 1

    Unattributable: 338ms CPU time (Performance)

  • Sprint 1

    https://xpenv.com/cdn-cgi/challenge-platform/scrip...: 330ms CPU time (Performance)

  • Sprint 2

    GDPR Article 13 disclosure coverage: 0 / 8 categories (Compliance)

  • Sprint 1

    Referrer-Policy header is missing (Security)

  • Sprint 1

    Cross-Origin-Opener-Policy header is missing (Security)

  • Sprint 1

    3 field(s) missing recommended autocomplete attribute (Accessibility)

…and 16 more recommended item(s)

Send Feedback