Skip to content

Changes

https://x.com
Compared to previous audit · 16 weeks ago View previous audit

New York, United Stated Madrid, Spain

These audits ran from different locations. Timing metrics (TTFB, DNS, TLS) may reflect network path differences rather than site changes.

40
New issues
33
Resolved
25
score changes
CategoryPreviousCurrentChange
CompositeC (76)B (84) +8.000
PerformanceC (75)B (82) +7.000
SecurityC (75)B (87) +12.000
AccessibilityD (69)B (84) +15.000
SEOB (81)B (83) +2.000
InfrastructureB (80)B (82) +2.000
ComplianceB (86)B (80) -6.000
ContentC (77)B (82) +5.000
SustainabilityB (86)A (90) +4.000
MetricPreviousCurrentChange
Performance 45006700 +2200
Accessibility 89009100 +200
Best Practices 96009600
SEO 1000010000
PWA 00
Desktop Performance 55008700 +3200
Desktop Accessibility 89009000 +100
Desktop Best Practices 96009600
Desktop SEO 1000010000
FCP 8.19 s2.05 s -6.14 s
LCP 12.72 s2.58 s -10.14 s
TBT 482 ms1.62 s +1.14 s
CLS 0.0000.000
Desktop FCP 811 ms768 ms -43 ms
Desktop LCP 2.73 s937 ms -1.79 s
Desktop TBT 275 ms258 ms -16 ms
Desktop CLS 0.3000.000 -0.300
TTFB 199 ms113 ms -86 ms
DNS 17 ms4 ms -14 ms
TLS 20 ms8 ms -12 ms
Connect 17 ms2 ms -15 ms
Total 402 ms114 ms -288 ms

† Timing metrics may vary by worker location and do not necessarily indicate site changes.

Projected vs. Actual

Previous
C 76
Projected
A+ 97
Actual
B 84
Fell short of projection
33 issues resolved since last audit
59 issues remaining
Resolving remaining issues could reach A+

Estimate — actual results may vary

CRITICAL 6 tracking cookie(s) set before consent interaction compliance
CRITICAL 6 non-essential cookie(s) set without consent banner compliance
CRITICAL 72 of 79 links are healthy content
CRITICAL No <main> landmark found accessibility
WARNING Page has 85 words — thin content seo
WARNING 1 hreflang value(s) are not valid BCP 47 tags compliance
WARNING Cookie 'guest_id_marketing' is missing the HttpOnly flag security
WARNING JavaScript is 1.6 MB — consider code splitting or lazy loading performance
WARNING Permissions-Policy header not set -- features default to allow-on-same-origin security
WARNING Cookie 'personalization_id' is missing the HttpOnly flag security
WARNING https://x.com/: 1020ms CPU time performance
WARNING https://abs.twimg.com/x-web/x-web/assets/castle.um...: 130 KB unused (60%) performance
WARNING Total JS execution time is 6.0 s -- over the 3.5s budget performance
WARNING Twitter card is `summary_large_image` but OG image is 1024×1024 (ratio 1.00:1) -- closer to square content
WARNING https://abs.twimg.com/x-web/x-web/assets/relay-run...: 38 KB unused (79%) performance
WARNING security.txt has expired security
WARNING Cookie 'guest_id_ads' is missing the HttpOnly flag security
WARNING Broken link: https://cdn.syndication.twimg.com content
WARNING Cookie 'gt' is missing the HttpOnly flag security
WARNING https://abs.twimg.com/x-web/x-web/assets/chunk-BO2...: 85 KB unused (74%) performance
WARNING Multiple H1 headings (2 found) accessibility
WARNING 382 third-party resources (99% of weight) performance
WARNING External link from abs.twimg.com lacks integrity attribute security
WARNING Thin content — only 85 words seo
WARNING 5 tracking-shaped cross-site cookie(s): __cf_bm, guest_id, guest_id_ads, guest_id_marketing, personalization_id compliance
WARNING SRI adoption: 0/2 third-party resources protected (0%) security
WARNING Cross-Origin-Embedder-Policy header is missing security
WARNING Certificate expires soon (15 days remaining) security
WARNING 17 link(s) open in new tab without warning accessibility
WARNING https://abs.twimg.com/x-web/x-web/assets/xhr-DJsfp...: 351ms CPU time performance
WARNING https://abs.twimg.com/x-web/x-web/assets/tweet-res...: 30 KB unused (60%) performance
WARNING 14 text node(s) render below 12 CSS pixels on mobile accessibility
WARNING Unattributable: 2497ms CPU time performance
WARNING https://abs.twimg.com/x-web/x-web/assets/castle.um...: 1162ms CPU time performance
WARNING Broken link: https://ton.twimg.com content
WARNING 385 HTTP requests — consider bundling or reducing performance
WARNING Third-party code accounts for 99% of page weight (1.7 MiB of 1.7 MiB) performance
WARNING https://abs.twimg.com/x-web/x-web/assets/sentry-fi...: 53 KB unused (40%) performance
WARNING https://abs.twimg.com/x-web/x-web/assets/sentry-fi...: 786ms CPU time performance
WARNING Page weight 1.7 MB exceeds 1 MB target by 743 KB performance
CRITICAL 2 non-essential cookie(s) set without consent banner compliance
CRITICAL 38 of 46 links are healthy content
WARNING base-uri directive is missing security
WARNING 21 link(s) open in new tab without warning accessibility
WARNING Third-party scripts: 4246ms (88% of total) performance
WARNING 67 third-party resources (96% of weight) performance
WARNING Page has 153 words — thin content seo
WARNING Third-party code accounts for 96% of page weight (1.6 MiB of 1.7 MiB) performance
WARNING Referrer-Policy header is missing security
WARNING X-Powered-By header reveals technology stack security
WARNING Cookie '__cf_bm' has no SameSite attribute security
WARNING JavaScript is 1.4 MB — consider code splitting or lazy loading performance
WARNING frame-ancestors directive is missing security
WARNING https://abs.twimg.com/responsive-web/client-web/ma...: 2556ms CPU time performance
WARNING https://abs.twimg.com/responsive-web/client-web/ve...: 1319ms CPU time performance
WARNING https://abs.twimg.com/responsive-web/client-web/ma...: 148 KB unused (52%) performance
WARNING https://abs.twimg.com/responsive-web/client-web/i1...: 42 KB unused (23%) performance
WARNING Missing og:image content
WARNING External script from accounts.google.com lacks integrity attribute security
WARNING No headings found accessibility
WARNING Unattributable: 462ms CPU time performance
WARNING Broken link: https://api.twitter.com content
WARNING Page weight 1.7 MB exceeds 1 MB target by 687 KB performance
WARNING No meta description tag found seo
WARNING External script from appleid.cdn-apple.com lacks integrity attribute security
WARNING External link from accounts.google.com lacks integrity attribute security
WARNING https://abs.twimg.com/responsive-web/client-web/ve...: 103 KB unused (30%) performance
WARNING https://accounts.google.com/gsi/client: 72 KB unused (75%) performance
WARNING GDPR Article 13 disclosure coverage: 0 / 8 categories compliance
WARNING No canonical tag found seo
WARNING Thin content — only 153 words seo
WARNING Transfer efficiency: 70% sustainability
WARNING https://abs.twimg.com/responsive-web/client-web/mo...: 75 KB unused (99%) performance
CRITICAL robots.txt blocks all crawlers infrastructure
CRITICAL 'unsafe-inline' found in script source security
CRITICAL Viewport prevents user zooming compliance
CRITICAL robots.txt has 'Disallow: /' but sitemap.xml is published -- contradictory signals seo
CRITICAL Soft 404: server returns HTTP 200 for non-existent pages accessibility
WARNING Cookie 'ct0' is missing the HttpOnly flag security
WARNING Broken link: https://api.x.com content
WARNING No Permissions-Policy header security
WARNING Cookie 'guest_id' is missing the HttpOnly flag security
WARNING Broken link: https://pbs.twimg.com content
WARNING Permissions-Policy header is missing security
WARNING sitemap.xml contains invalid XML infrastructure
WARNING Sitemap is empty -- 0 URLs listed seo
WARNING sitemap.xml is empty — no URLs found infrastructure
WARNING Registrar lock is NOT enabled infrastructure
WARNING Broken link: https://video.twimg.com content
WARNING Skip navigation link is missing (WCAG 2.4.1) accessibility
WARNING Broken link: https://abs.twimg.com content
WARNING External script from abs.twimg.com lacks integrity attribute security
+ content-encoding gzip
+ x-dns-prefetch-control off
+ cross-origin-resource-policy same-origin
+ x-permitted-cross-domain-policies none
+ origin-agent-cluster ?1
+ referrer-policy strict-origin-when-cross-origin
+ x-download-options noopen
x-powered-by Express
last-modified Thu, 16 Apr 2026 16:58:10 GMT
cross-origin-embedder-policy unsafe-none
pragma no-cache
expiry Tue, 31 Mar 1981 05:00:00 GMT
reporting-endpoints coep-report="https://x.com/i/coep-report", coop-report="https://x.com/i/coop-...
x-transaction-id
13d2d39d4f863ae1 12fcc583b2021de4
x-response-time
25 66
set-cookie
guest_id=v1%3A177635869015356344; Max-Age=34214400; Expires=Mon, 17 May 2027 ... guest_id_marketing=v1%3A178638208964864466; Max-Age=63072000; Expires=Wed, 09...
cache-control
no-cache, no-store, must-revalidate, pre-check=0, post-check=0 no-cache, no-store, max-age=0
content-security-policy
connect-src 'self' blob: https://fonts.googleapis.com/css https://mapsresourc... default-src 'self';script-src 'self' 'nonce-wrNXSayFhqd1ymAwLKR95g==' 'unsafe...
content-type
text/html; charset=utf-8 text/html; charset=UTF-8
x-frame-options
DENY SAMEORIGIN
cross-origin-opener-policy
unsafe-none same-origin-allow-popups
origin-cf-ray
9ed4bbb50abfbe96-CDG a290a39c29571b53-ATL

7 headers unchanged

+ Priority Hints Performance
+ shadcn/ui UI frameworks
+ Sentry Issue trackers
+ Tailwind CSS UI frameworks
Express Web frameworks
Node.js Programming languages
React JavaScript frameworks
Amazon S3 CDN
core-js JavaScript libraries
Apple Sign-in Authentication
React Native for Web JavaScript libraries
Webpack Build Tool
Amazon Web Services PaaS

12 technologies unchanged

Looking ahead

+16 pts
B (84) Could reach A+ (100)
Compliance +20Content +18Infrastructure +18Performance +18SEO +17Accessibility +16Security +13

Estimate — actual results may vary (59 issues to fix)

Website improvement report — X

April 16, 2026 → August 10, 2026

C B 76 → 84 +8 pts

33

Resolved

40

New issues

19

Still remaining

Financial summary

Investment delivered

€7,948 in development time

Investment remaining

€9,704 to complete the remaining items

Ongoing risk

€0/month in ongoing exposure

Figures are estimates based on local developer hourly rate, industry CPC, and regulatory fine ranges.

Performance by category

MetricBeforeAfterChange
Overall score76 (C)84 (B)+8
Performance75 (C)82 (B)+7
Security75 (C)87 (B)+12
Accessibility69 (D)84 (B)+15
SEO81 (B)83 (B)+2
Infrastructure80 (B)82 (B)+2
Compliance86 (B)80 (B)-6
Content77 (C)82 (B)+5
Sustainability86 (B)90 (A)+4

Resolved (33)

  • base-uri directive is missing (Security)

    → Reduced attack surface for visitors

  • 21 link(s) open in new tab without warning (Accessibility)

    → Improved usability for assistive technology users

  • Third-party scripts: 4246ms (88% of total) (Performance)

    → Page loads faster for users

  • 67 third-party resources (96% of weight) (Performance)

    → Page loads faster for users

  • Page has 153 words — thin content (SEO)

    → Better search engine visibility

  • 2 non-essential cookie(s) set without consent banner (Compliance)

    → Reduced regulatory exposure

  • Third-party code accounts for 96% of page weight (1.6 MiB of 1.7 MiB) (Performance)

    → Page loads faster for users

  • 38 of 46 links are healthy (Content)

    → Stronger social sharing and on-page quality

  • Referrer-Policy header is missing (Security)

    → Reduced attack surface for visitors

  • X-Powered-By header reveals technology stack (Security)

    → Reduced attack surface for visitors

  • Cookie '__cf_bm' has no SameSite attribute (Security)

    → Reduced attack surface for visitors

  • JavaScript is 1.4 MB — consider code splitting or lazy loading (Performance)

    → Page loads faster for users

  • frame-ancestors directive is missing (Security)

    → Reduced attack surface for visitors

  • https://abs.twimg.com/responsive-web/client-web/ma...: 2556ms CPU time (Performance)

    → Page loads faster for users

  • https://abs.twimg.com/responsive-web/client-web/ve...: 1319ms CPU time (Performance)

    → Page loads faster for users

…and 18 more resolved issue(s)

Recommended next steps (59)

  • Sprint 2

    6 tracking cookie(s) set before consent interaction (Compliance)

  • Sprint 2

    6 non-essential cookie(s) set without consent banner (Compliance)

  • Sprint 1

    72 of 79 links are healthy (Content)

  • Sprint 1

    No <main> landmark found (Accessibility)

  • Sprint 1

    robots.txt blocks all crawlers (Infrastructure)

  • Sprint 3

    'unsafe-inline' found in script source (Security)

  • Sprint 1

    Viewport prevents user zooming (Compliance)

  • Sprint 1

    robots.txt has 'Disallow: /' but sitemap.xml is published -- contradictory signals (SEO)

  • Sprint 1

    Soft 404: server returns HTTP 200 for non-existent pages (Accessibility)

  • Sprint 3

    Page has 85 words — thin content (SEO)

  • Sprint 2

    1 hreflang value(s) are not valid BCP 47 tags (Compliance)

  • Sprint 1

    Cookie 'guest_id_marketing' is missing the HttpOnly flag (Security)

  • Sprint 3

    JavaScript is 1.6 MB — consider code splitting or lazy loading (Performance)

  • Sprint 1

    Permissions-Policy header not set -- features default to allow-on-same-origin (Security)

  • Sprint 1

    Cookie 'personalization_id' is missing the HttpOnly flag (Security)

…and 44 more recommended item(s)

Send Feedback