Your site declined by 17 points (A → C)
Compared to scan from 4 hours ago
Score: 75 / 100 17
Based on 4 categories, 27 sections
The overall score is a weighted average of individual category scores. Categories with more impact on user experience and security carry more weight.
Weights reflect general web best practices. Individual needs may differ.
No viewport meta tag found
DNS resolution is slow (305 ms)
<html lang> attribute is missing
No privacy policy link detected
[](https://beavercheck.com/results/a8822048-45c3-4a12-aa35-48037f0b5d35)<a href="https://beavercheck.com/results/a8822048-45c3-4a12-aa35-48037f0b5d35"><img src="https://beavercheck.com/badge?url=https%3A%2F%2Fbeavercheck.com%2F" alt="BeaverCheck Score"></a>https://beavercheck.com/badge?url=https%3A%2F%2Fbeavercheck.com%2FThis badge auto-updates with your latest scan result.
Thanks for your feedback!
Industry-standard audits powered by Google Lighthouse.
Key metrics that affect user experience.
Desktop audit not available for this result.
Connection-level performance breakdown.
HTTP/2 provides multiplexing and header compression for better performance.
| Name | Secure | HttpOnly | SameSite | Size | Issues |
|---|---|---|---|---|---|
| bc_csrf | ✓ | ✓ | Lax | 39 B | — |
| bc_csrf | ✓ | ✓ | Lax | 39 B | — |
Extended security checks beyond standard header analysis
No known JavaScript library vulnerabilities detected.
No sensitive files exposed — all paths returned 404.
| Path | Status | Category | Risk |
|---|---|---|---|
| /.git/HEAD | ✓ Not found | Version Control | — |
| /.git/config | ✓ Not found | Version Control | — |
| /.svn/entries | ✓ Not found | Version Control | — |
| /.env | ✓ Not found | Configuration | — |
| /.env.local | ✓ Not found | Configuration | — |
| /.env.production | ✓ Not found | Configuration | — |
| /wp-config.php | ✓ Not found | Configuration | — |
| /.htaccess | ✓ Not found | Configuration | — |
| /phpinfo.php | ✓ Not found | Debug | — |
| /server-status | ✓ Not found | Debug | — |
| /server-info | ✓ Not found | Debug | — |
| /.well-known/security.txt | ✓ Not found | Security Policy | — |
No CORS headers detected.
Cross-origin requests are blocked by browser same-origin policy.
Origin reflection test
Some servers mirror the request Origin header, which can be exploited. Test manually:
curl -sI -H "Origin: https://evil.com" <url> | grep -i access-control
No security.txt found at /.well-known/security.txt
Content quality analysis not available for this result.
Performance analysis not available for this result.
Desktop audit not available for this result.
| A | 51.210.209.19 |
| AAAA | — |
| CNAME | — |
| NS | ns14.ovh.net, dns14.ovh.net |
| MX | 0 mail.appscyborg.com |
| TXT | SPF v=spf1 mx -all |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Slow DNS adds latency to every page load. Consider a faster DNS provider.
https://beavercheck.com/
913 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://beavercheck.com/ | 200 | 913 ms | HTTP/1.1 | nginx |
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
User-agent: *
Allow: /
Disallow: /rate-limited
Disallow: /results/*/pdf
Disallow: /submit
Sitemap: https://beavercheck.com/sitemap.xml
# AI model context
# See https://beavercheck.com/llms.txt for a summary
# See https://beavercheck.com/llms-full.txt for detailed context
www / non-www
Preferred variant: non-www
HTTP → HTTPS
Consistent
Newly registered domains may face SEO trust challenges. Search engines generally give more authority to older domains. This is informational — not a problem to fix.
This is an automated check, not legal advice. Consult a privacy professional for GDPR/CCPA compliance.
A privacy policy page is recommended for transparency and may be legally required.
BeaverCheck detects technical indicators of consent management. This does not constitute a legal compliance assessment. Consult a privacy professional for GDPR/CCPA compliance.
The lang attribute on <html> is required for screen readers and WCAG 3.1.1 compliance.
The <html lang> attribute and Content-Language header should agree.
No viewport meta tag found. Mobile devices will render at desktop width.
<meta name="viewport" content="width=device-width, initial-scale=1">Without a viewport meta tag, the page will not render correctly on mobile devices.
Consider using a CDN to improve global delivery speed and reduce origin load.
A CDN can significantly improve load times for users around the world by caching content at edge nodes closer to them.
No Cache-Control header
Adding a Cache-Control header can significantly improve repeat-visit performance.
Browsers will use heuristic caching, which can be unpredictable. Set explicit cache headers.
| Location | Status | TTFB | DNS | Connect | TLS | Total |
|---|---|---|---|---|---|---|
NL Amsterdam | 200 ✓ | 39ms | 8ms | 6ms | 11ms | 40ms |
UN New York (Full audit) | 200 ✓ | 464ms | 160ms | 75ms | 78ms | 464ms |
UN Santa Clara | 200 ✓ | 906ms | 304ms | 150ms | 153ms | 907ms |
SG Singapore | 200 ✓ | 939ms | 294ms | 160ms | 164ms | 939ms |
BR Sao Paulo | 200 ✓ | 954ms | 191ms | 190ms | 193ms | 954ms |
| Average | 660ms | 191ms | 116ms | 120ms | 661ms |
Accessibility analysis not available for this result.
SEO analysis not available for this result.
HSTS, with Nginx CDN
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
No build tool detected
A framework (HSTS) was detected but no bundler was identified. The build tool may not be detectable from output patterns, or the site may use the framework's built-in bundler.
Minimal technology footprint
Only 2 technologies detected. This suggests a simple setup with minimal dependencies — excellent for performance and security.
| Metric | Previous | Current | Change |
|---|---|---|---|
| TTFB † | 779 ms | 906 ms | +127 ms |
| DNS † | 163 ms | 304 ms | +142 ms |
| TLS † | 157 ms | 153 ms | -4 ms |
| Connect † | 153 ms | 150 ms | -4 ms |
| Total † | 780 ms | 907 ms | +127 ms |
† Timing metrics may vary by worker location and do not necessarily indicate site changes.
content-security-policy default-src 'self'; script-src 'self' 'nonce-9kQa0+HRymAVLOU5uEVwbg==' 'sha25... → default-src 'self'; script-src 'self' 'nonce-OST7CuLzhytPaGkcIQXtOQ==' 'sha25...set-cookie bc_csrf=aa15f0f2a4c3ba9ba415088228641b88; Path=/; Max-Age=3600; HttpOnly; Sec... → bc_csrf=fa6bc255dcde1e4e53e639b0a2962683; Path=/; Max-Age=3600; HttpOnly; Sec...12 headers unchanged
2 technologies unchanged
Send Feedback