Skip to content

Changes

https://x.com
Compared to previous audit · 16 weeks ago View previous audit

New York, United Stated → Madrid, Spain

These audits ran from different locations. Timing metrics (TTFB, DNS, TLS) may reflect network path differences rather than site changes.

37
New issues
32
Resolved
25
score changes
CategoryPreviousCurrentChange
CompositeC (76)B (84) +8.000
PerformanceC (75)B (82) +7.000
SecurityC (75)B (87) +12.000
AccessibilityD (69)B (84) +15.000
SEOB (81)B (83) +2.000
InfrastructureB (80)B (82) +2.000
ComplianceB (86)B (80) -6.000
ContentC (77)B (82) +5.000
SustainabilityB (86)A (90) +4.000
MetricPreviousCurrentChange
Performance 45006700 +2200
Accessibility 89009100 +200
Best Practices 96009600—
SEO 1000010000—
PWA 00—
Desktop Performance 55008700 +3200
Desktop Accessibility 89009000 +100
Desktop Best Practices 96009600—
Desktop SEO 1000010000—
FCP 8.19 s2.05 s -6.14 s
LCP 12.72 s2.58 s -10.14 s
TBT 482 ms1.62 s +1.14 s
CLS 0.0000.000—
Desktop FCP 811 ms768 ms -43 ms
Desktop LCP 2.73 s937 ms -1.79 s
Desktop TBT 275 ms258 ms -16 ms
Desktop CLS 0.3000.000 -0.300
TTFB †199 ms113 ms -86 ms
DNS †17 ms4 ms -14 ms
TLS †20 ms8 ms -12 ms
Connect †17 ms2 ms -15 ms
Total †402 ms114 ms -288 ms

† Timing metrics may vary by worker location and do not necessarily indicate site changes.

Projected vs. Actual

Previous
C 76
Projected
A+ 97
Actual
B 84
Fell short of projection
32 issues resolved since last audit
57 issues remaining
Resolving remaining issues could reach A+

Estimate — actual results may vary

CRITICAL No <main> landmark found accessibility
CRITICAL 72 of 79 links are healthy content
WARNING JavaScript is 1.6 MB — consider code splitting or lazy loading performance
WARNING 14 text node(s) render below 12 CSS pixels on mobile accessibility
WARNING https://abs.twimg.com/x-web/x-web/assets/castle.um...: 130 KB unused (60%) performance
WARNING 382 third-party resources (99% of weight) performance
WARNING Cross-Origin-Embedder-Policy header is missing security
WARNING Broken link: https://cdn.syndication.twimg.com content
WARNING 17 link(s) open in new tab without warning accessibility
WARNING https://abs.twimg.com/x-web/x-web/assets/castle.um...: 1162ms CPU time performance
WARNING https://abs.twimg.com/x-web/x-web/assets/sentry-fi...: 786ms CPU time performance
WARNING Cookie 'guest_id_ads' is missing the HttpOnly flag security
WARNING Certificate expires soon (15 days remaining) security
WARNING Page weight 1.7 MB exceeds 1 MB target by 743 KB performance
WARNING Twitter card is `summary_large_image` but OG image is 1024×1024 (ratio 1.00:1) -- closer to square content
WARNING security.txt has expired security
WARNING Page has 85 words — thin content seo
WARNING https://abs.twimg.com/x-web/x-web/assets/chunk-BO2...: 85 KB unused (74%) performance
WARNING Cookie 'gt' is missing the HttpOnly flag security
WARNING Multiple H1 headings (2 found) accessibility
WARNING https://x.com/: 1020ms CPU time performance
WARNING https://abs.twimg.com/x-web/x-web/assets/xhr-DJsfp...: 351ms CPU time performance
WARNING Thin content — only 85 words seo
WARNING Cookie 'personalization_id' is missing the HttpOnly flag security
WARNING https://abs.twimg.com/x-web/x-web/assets/relay-run...: 38 KB unused (79%) performance
WARNING 385 HTTP requests — consider bundling or reducing performance
WARNING Cookie 'guest_id_marketing' is missing the HttpOnly flag security
WARNING SRI adoption: 0/2 third-party resources protected (0%) security
WARNING Unattributable: 2497ms CPU time performance
WARNING https://abs.twimg.com/x-web/x-web/assets/tweet-res...: 30 KB unused (60%) performance
WARNING External link from abs.twimg.com lacks integrity attribute security
WARNING Third-party code accounts for 99% of page weight (1.7 MiB of 1.7 MiB) performance
WARNING https://abs.twimg.com/x-web/x-web/assets/sentry-fi...: 53 KB unused (40%) performance
WARNING Total JS execution time is 6.0 s -- over the 3.5s budget performance
WARNING 1 hreflang value(s) are not valid BCP 47 tags compliance
WARNING 5 tracking-shaped cross-site cookie(s): __cf_bm, guest_id, guest_id_ads, guest_id_marketing, personalization_id compliance
WARNING Broken link: https://ton.twimg.com content
CRITICAL 38 of 46 links are healthy content
WARNING Unattributable: 462ms CPU time performance
WARNING https://abs.twimg.com/responsive-web/client-web/i1...: 42 KB unused (23%) performance
WARNING 67 third-party resources (96% of weight) performance
WARNING No canonical tag found seo
WARNING No headings found accessibility
WARNING https://abs.twimg.com/responsive-web/client-web/ve...: 103 KB unused (30%) performance
WARNING Thin content — only 153 words seo
WARNING Third-party scripts: 4246ms (88% of total) performance
WARNING GDPR Article 13 disclosure coverage: 0 / 8 categories compliance
WARNING https://accounts.google.com/gsi/client: 72 KB unused (75%) performance
WARNING base-uri directive is missing security
WARNING frame-ancestors directive is missing security
WARNING https://abs.twimg.com/responsive-web/client-web/ve...: 1319ms CPU time performance
WARNING https://abs.twimg.com/responsive-web/client-web/ma...: 148 KB unused (52%) performance
WARNING No meta description tag found seo
WARNING Missing og:image content
WARNING Transfer efficiency: 70% sustainability
WARNING X-Powered-By header reveals technology stack security
WARNING https://abs.twimg.com/responsive-web/client-web/ma...: 2556ms CPU time performance
WARNING Broken link: https://api.twitter.com content
WARNING Referrer-Policy header is missing security
WARNING Cookie '__cf_bm' has no SameSite attribute security
WARNING External link from accounts.google.com lacks integrity attribute security
WARNING 21 link(s) open in new tab without warning accessibility
WARNING JavaScript is 1.4 MB — consider code splitting or lazy loading performance
WARNING External script from appleid.cdn-apple.com lacks integrity attribute security
WARNING https://abs.twimg.com/responsive-web/client-web/mo...: 75 KB unused (99%) performance
WARNING Page weight 1.7 MB exceeds 1 MB target by 687 KB performance
WARNING Page has 153 words — thin content seo
WARNING External script from accounts.google.com lacks integrity attribute security
WARNING Third-party code accounts for 96% of page weight (1.6 MiB of 1.7 MiB) performance
CRITICAL robots.txt has 'Disallow: /' but sitemap.xml is published -- contradictory signals seo
CRITICAL 6 non-essential cookie(s) set without consent banner compliance
CRITICAL 'unsafe-inline' found in script source security
CRITICAL Soft 404: server returns HTTP 200 for non-existent pages accessibility
CRITICAL Viewport prevents user zooming compliance
CRITICAL robots.txt blocks all crawlers infrastructure
WARNING Broken link: https://api.x.com content
WARNING Cookie 'guest_id' is missing the HttpOnly flag security
WARNING Cookie 'ct0' is missing the HttpOnly flag security
WARNING External script from abs.twimg.com lacks integrity attribute security
WARNING Broken link: https://pbs.twimg.com content
WARNING Permissions-Policy header is missing security
WARNING sitemap.xml contains invalid XML infrastructure
WARNING Broken link: https://video.twimg.com content
WARNING No Permissions-Policy header security
WARNING Sitemap is empty -- 0 URLs listed seo
WARNING Skip navigation link is missing (WCAG 2.4.1) accessibility
WARNING sitemap.xml is empty — no URLs found infrastructure
WARNING Registrar lock is NOT enabled infrastructure
WARNING Broken link: https://abs.twimg.com content
+ content-encoding gzip
+ referrer-policy strict-origin-when-cross-origin
+ x-dns-prefetch-control off
+ cross-origin-resource-policy same-origin
+ x-download-options noopen
+ x-permitted-cross-domain-policies none
+ origin-agent-cluster ?1
− expiry Tue, 31 Mar 1981 05:00:00 GMT
− x-powered-by Express
− reporting-endpoints coep-report="https://x.com/i/coep-report", coop-report="https://x.com/i/coop-...
− pragma no-cache
− last-modified Thu, 16 Apr 2026 16:58:10 GMT
− cross-origin-embedder-policy unsafe-none
cache-control
no-cache, no-store, must-revalidate, pre-check=0, post-check=0 → no-cache, no-store, max-age=0
set-cookie
guest_id=v1%3A177635869015356344; Max-Age=34214400; Expires=Mon, 17 May 2027 ... → guest_id_marketing=v1%3A178638208964864466; Max-Age=63072000; Expires=Wed, 09...
x-transaction-id
13d2d39d4f863ae1 → 12fcc583b2021de4
content-type
text/html; charset=utf-8 → text/html; charset=UTF-8
cross-origin-opener-policy
unsafe-none → same-origin-allow-popups
x-frame-options
DENY → SAMEORIGIN
content-security-policy
connect-src 'self' blob: https://fonts.googleapis.com/css https://mapsresourc... → default-src 'self';script-src 'self' 'nonce-wrNXSayFhqd1ymAwLKR95g==' 'unsafe...
x-response-time
25 → 66
origin-cf-ray
9ed4bbb50abfbe96-CDG → a290a39c29571b53-ATL

7 headers unchanged

+ shadcn/ui UI frameworks
+ Sentry Issue trackers
+ Tailwind CSS UI frameworks
+ Priority Hints Performance
− Apple Sign-in Authentication
− Amazon S3 CDN
− Webpack Build Tool
− Amazon Web Services PaaS
− React Native for Web JavaScript libraries
− Node.js Programming languages
− React JavaScript frameworks
− core-js JavaScript libraries
− Express Web frameworks

12 technologies unchanged

Looking ahead

+16 pts
B (84) Could reach A+ (100)
Compliance +20Content +18Infrastructure +18Performance +18SEO +17Accessibility +16Security +13

Estimate — actual results may vary (57 issues to fix)

Website improvement report — X

April 16, 2026 → August 10, 2026

C B 76 → 84 +8 pts

32

Resolved

37

New issues

20

Still remaining

Financial summary

Investment delivered

€7,608 in development time

Investment remaining

€9,407 to complete the remaining items

Ongoing risk

€0/month in ongoing exposure

Figures are estimates based on local developer hourly rate, industry CPC, and regulatory fine ranges.

Performance by category

MetricBeforeAfterChange
Overall score76 (C)84 (B)+8
Performance75 (C)82 (B)+7
Security75 (C)87 (B)+12
Accessibility69 (D)84 (B)+15
SEO81 (B)83 (B)+2
Infrastructure80 (B)82 (B)+2
Compliance86 (B)80 (B)-6
Content77 (C)82 (B)+5
Sustainability86 (B)90 (A)+4

Resolved (32)

  • Unattributable: 462ms CPU time (Performance)

    → Page loads faster for users

  • https://abs.twimg.com/responsive-web/client-web/i1...: 42 KB unused (23%) (Performance)

    → Page loads faster for users

  • 67 third-party resources (96% of weight) (Performance)

    → Page loads faster for users

  • No canonical tag found (SEO)

    → Better search engine visibility

  • No headings found (Accessibility)

    → Improved usability for assistive technology users

  • https://abs.twimg.com/responsive-web/client-web/ve...: 103 KB unused (30%) (Performance)

    → Page loads faster for users

  • Thin content — only 153 words (SEO)

    → Better search engine visibility

  • Third-party scripts: 4246ms (88% of total) (Performance)

    → Page loads faster for users

  • GDPR Article 13 disclosure coverage: 0 / 8 categories (Compliance)

    → Reduced regulatory exposure

  • https://accounts.google.com/gsi/client: 72 KB unused (75%) (Performance)

    → Page loads faster for users

  • base-uri directive is missing (Security)

    → Reduced attack surface for visitors

  • frame-ancestors directive is missing (Security)

    → Reduced attack surface for visitors

  • https://abs.twimg.com/responsive-web/client-web/ve...: 1319ms CPU time (Performance)

    → Page loads faster for users

  • https://abs.twimg.com/responsive-web/client-web/ma...: 148 KB unused (52%) (Performance)

    → Page loads faster for users

  • No meta description tag found (SEO)

    → Better search engine visibility

…and 17 more resolved issue(s)

Recommended next steps (57)

  • Sprint 1

    No <main> landmark found (Accessibility)

  • Sprint 1

    72 of 79 links are healthy (Content)

  • Sprint 1

    robots.txt has 'Disallow: /' but sitemap.xml is published -- contradictory signals (SEO)

  • Sprint 2

    6 non-essential cookie(s) set without consent banner (Compliance)

  • Sprint 3

    'unsafe-inline' found in script source (Security)

  • Sprint 1

    Soft 404: server returns HTTP 200 for non-existent pages (Accessibility)

  • Sprint 1

    Viewport prevents user zooming (Compliance)

  • Sprint 1

    robots.txt blocks all crawlers (Infrastructure)

  • Sprint 3

    JavaScript is 1.6 MB — consider code splitting or lazy loading (Performance)

  • Sprint 1

    14 text node(s) render below 12 CSS pixels on mobile (Accessibility)

  • Sprint 3

    https://abs.twimg.com/x-web/x-web/assets/castle.um...: 130 KB unused (60%) (Performance)

  • Sprint 1

    382 third-party resources (99% of weight) (Performance)

  • Sprint 2

    Cross-Origin-Embedder-Policy header is missing (Security)

  • Sprint 1

    Broken link: https://cdn.syndication.twimg.com (Content)

  • Sprint 1

    17 link(s) open in new tab without warning (Accessibility)

…and 42 more recommended item(s)

Send Feedback