Changes
New York, United Stated → Madrid, Spain
These audits ran from different locations. Timing metrics (TTFB, DNS, TLS) may reflect network path differences rather than site changes.
| Category | Previous | Current | Change |
|---|---|---|---|
| Composite | C (76) | B (84) | +8.000 |
| Performance | C (75) | B (82) | +7.000 |
| Security | C (75) | B (87) | +12.000 |
| Accessibility | D (69) | B (84) | +15.000 |
| SEO | B (81) | B (83) | +2.000 |
| Infrastructure | B (80) | B (82) | +2.000 |
| Compliance | B (86) | B (80) | -6.000 |
| Content | C (77) | B (82) | +5.000 |
| Sustainability | B (86) | A (90) | +4.000 |
| Metric | Previous | Current | Change |
|---|---|---|---|
| Performance | 4500 | 6700 | +2200 |
| Accessibility | 8900 | 9100 | +200 |
| Best Practices | 9600 | 9600 | — |
| SEO | 10000 | 10000 | — |
| PWA | 0 | 0 | — |
| Desktop Performance | 5500 | 8700 | +3200 |
| Desktop Accessibility | 8900 | 9000 | +100 |
| Desktop Best Practices | 9600 | 9600 | — |
| Desktop SEO | 10000 | 10000 | — |
| FCP | 8.19 s | 2.05 s | -6.14 s |
| LCP | 12.72 s | 2.58 s | -10.14 s |
| TBT | 482 ms | 1.62 s | +1.14 s |
| CLS | 0.000 | 0.000 | — |
| Desktop FCP | 811 ms | 768 ms | -43 ms |
| Desktop LCP | 2.73 s | 937 ms | -1.79 s |
| Desktop TBT | 275 ms | 258 ms | -16 ms |
| Desktop CLS | 0.300 | 0.000 | -0.300 |
| TTFB † | 199 ms | 113 ms | -86 ms |
| DNS † | 17 ms | 4 ms | -14 ms |
| TLS † | 20 ms | 8 ms | -12 ms |
| Connect † | 17 ms | 2 ms | -15 ms |
| Total † | 402 ms | 114 ms | -288 ms |
† Timing metrics may vary by worker location and do not necessarily indicate site changes.
Projected vs. Actual
Estimate — actual results may vary
content-encoding gzipx-dns-prefetch-control offcross-origin-resource-policy same-originx-permitted-cross-domain-policies noneorigin-agent-cluster ?1referrer-policy strict-origin-when-cross-originx-download-options noopenx-powered-by Expresslast-modified Thu, 16 Apr 2026 16:58:10 GMTcross-origin-embedder-policy unsafe-nonepragma no-cacheexpiry Tue, 31 Mar 1981 05:00:00 GMTreporting-endpoints coep-report="https://x.com/i/coep-report", coop-report="https://x.com/i/coop-...x-transaction-id 13d2d39d4f863ae1 → 12fcc583b2021de4x-response-time 25 → 66set-cookie guest_id=v1%3A177635869015356344; Max-Age=34214400; Expires=Mon, 17 May 2027 ... → guest_id_marketing=v1%3A178638208964864466; Max-Age=63072000; Expires=Wed, 09...cache-control no-cache, no-store, must-revalidate, pre-check=0, post-check=0 → no-cache, no-store, max-age=0content-security-policy connect-src 'self' blob: https://fonts.googleapis.com/css https://mapsresourc... → default-src 'self';script-src 'self' 'nonce-wrNXSayFhqd1ymAwLKR95g==' 'unsafe...content-type text/html; charset=utf-8 → text/html; charset=UTF-8x-frame-options DENY → SAMEORIGINcross-origin-opener-policy unsafe-none → same-origin-allow-popupsorigin-cf-ray 9ed4bbb50abfbe96-CDG → a290a39c29571b53-ATL7 headers unchanged
12 technologies unchanged
Looking ahead
+16 ptsEstimate — actual results may vary (59 issues to fix)
Website improvement report — X
April 16, 2026 → August 10, 2026
33
Resolved
40
New issues
19
Still remaining
Financial summary
Investment delivered
€7,948 in development time
Investment remaining
€9,704 to complete the remaining items
Ongoing risk
€0/month in ongoing exposure
Figures are estimates based on local developer hourly rate, industry CPC, and regulatory fine ranges.
Performance by category
| Metric | Before | After | Change |
|---|---|---|---|
| Overall score | 76 (C) | 84 (B) | +8 |
| Performance | 75 (C) | 82 (B) | +7 |
| Security | 75 (C) | 87 (B) | +12 |
| Accessibility | 69 (D) | 84 (B) | +15 |
| SEO | 81 (B) | 83 (B) | +2 |
| Infrastructure | 80 (B) | 82 (B) | +2 |
| Compliance | 86 (B) | 80 (B) | -6 |
| Content | 77 (C) | 82 (B) | +5 |
| Sustainability | 86 (B) | 90 (A) | +4 |
Resolved (33)
base-uri directive is missing (Security)
→ Reduced attack surface for visitors
21 link(s) open in new tab without warning (Accessibility)
→ Improved usability for assistive technology users
Third-party scripts: 4246ms (88% of total) (Performance)
→ Page loads faster for users
67 third-party resources (96% of weight) (Performance)
→ Page loads faster for users
Page has 153 words — thin content (SEO)
→ Better search engine visibility
2 non-essential cookie(s) set without consent banner (Compliance)
→ Reduced regulatory exposure
Third-party code accounts for 96% of page weight (1.6 MiB of 1.7 MiB) (Performance)
→ Page loads faster for users
38 of 46 links are healthy (Content)
→ Stronger social sharing and on-page quality
Referrer-Policy header is missing (Security)
→ Reduced attack surface for visitors
X-Powered-By header reveals technology stack (Security)
→ Reduced attack surface for visitors
Cookie '__cf_bm' has no SameSite attribute (Security)
→ Reduced attack surface for visitors
JavaScript is 1.4 MB — consider code splitting or lazy loading (Performance)
→ Page loads faster for users
frame-ancestors directive is missing (Security)
→ Reduced attack surface for visitors
https://abs.twimg.com/responsive-web/client-web/ma...: 2556ms CPU time (Performance)
→ Page loads faster for users
https://abs.twimg.com/responsive-web/client-web/ve...: 1319ms CPU time (Performance)
→ Page loads faster for users
…and 18 more resolved issue(s)
Recommended next steps (59)
- Sprint 2
6 tracking cookie(s) set before consent interaction (Compliance)
- Sprint 2
6 non-essential cookie(s) set without consent banner (Compliance)
- Sprint 1
72 of 79 links are healthy (Content)
- Sprint 1
No <main> landmark found (Accessibility)
- Sprint 1
robots.txt blocks all crawlers (Infrastructure)
- Sprint 3
'unsafe-inline' found in script source (Security)
- Sprint 1
Viewport prevents user zooming (Compliance)
- Sprint 1
robots.txt has 'Disallow: /' but sitemap.xml is published -- contradictory signals (SEO)
- Sprint 1
Soft 404: server returns HTTP 200 for non-existent pages (Accessibility)
- Sprint 3
Page has 85 words — thin content (SEO)
- Sprint 2
1 hreflang value(s) are not valid BCP 47 tags (Compliance)
- Sprint 1
Cookie 'guest_id_marketing' is missing the HttpOnly flag (Security)
- Sprint 3
JavaScript is 1.6 MB — consider code splitting or lazy loading (Performance)
- Sprint 1
Permissions-Policy header not set -- features default to allow-on-same-origin (Security)
- Sprint 1
Cookie 'personalization_id' is missing the HttpOnly flag (Security)
…and 44 more recommended item(s)