Skip to content
Audit Complete

Results for https://Vipoftalmologia.com.br

Visit site
BR · BRL (R$) · Estimated Applicable regulations: LGPD Dev cost: R$ 180/hr How jurisdiction is detected
Spain Spain · Madrid Completed: May 3, 2026 01:28 UTC
Download Markdown Report

Three-week fix plan

2 sprints · 4h total → projected C (74)

Sprint 1: Quick Wins

+9

Highest ROI — low effort, high impact

4 findings 2h → C (71)
  • · Content-Security-Policy header is missing
  • · No Content-Security-Policy header found
  • · Cross-Origin-Embedder-Policy header is missing

+1 more in plan export

Sprint 2: Core Fixes

+3

Medium effort, high structural impact

1 findings 2h → C (74)
  • · Soft 404: server returns HTTP 200 for non-existent pages
AI remediation plan Ask AI about this audit
Focus mode
D62
Fix top 3 → C (73, +11)

Site Health

Score: 62 / 100

Based on 4 categories, 27 sections

Good foundation, but a few gaps could be exploited.

Major barriers for users with disabilities — up to 15% of your audience.

Solid infrastructure — fast server responses across the board.

Several regulatory requirements are not yet met.

How is this calculated?

The overall score is a weighted average of individual category scores. Categories with more impact on user experience and security carry more weight.

Security 25%Accessibility 15%Infrastructure 10%Compliance 8%

Weights reflect general web best practices. Individual needs may differ.

How the composite score is calculated

How you compare

Google Search Console · 3610 peers
You 62
·
Avg 73
-11 below average
0 50 100
Accessibility P1Compliance P1Infrastructure P93Security P73

Top 10% of Google Search Console sites score 69+ on Accessibility; you're at 24 — closing this gap is the highest-leverage improvement.

HSTS · 2231 peers
You 62
·
Avg 74
-12 below average
0 50 100
Accessibility P1Compliance P1Infrastructure P93Security P63

Top 10% of HSTS sites score 70+ on Accessibility; you're at 24 — closing this gap is the highest-leverage improvement.

Top Priorities (5)

Critical: 1

Content-Security-Policy header is missing

Security gaps expose your site and users to attacks, eroding trust.

Security › Security Headers· 30m · BRL 90· +4 pts
Critical: 2

No Content-Security-Policy header found

Security gaps expose your site and users to attacks, eroding trust.

Security › Content Security Policy· 30m · BRL 90· +4 pts
Critical: 3

Soft 404: server returns HTTP 200 for non-existent pages

Accessibility issues exclude users with disabilities — up to 15% of your potential audience.

Accessibility › 404 Error Page· 1h 30m · BRL 270· +3 pts
Warning: 4

Cross-Origin-Embedder-Policy header is missing

Security gaps expose your site and users to attacks, eroding trust.

Security › Security Headers· 30m · BRL 90· +2 pts
Warning: 5

Cross-Origin-Opener-Policy header is missing

Security gaps expose your site and users to attacks, eroding trust.

Security › Security Headers· 30m · BRL 90· +2 pts
View fix priority matrix

Fix Priority Matrix

5 findings

Quick Wins

4

High impact, low effort — start here.

Strategic

1

High impact, requires investment.

Easy Improvements

0

Small gains, minimal effort.

Nothing in this quadrant — good news.

Deprioritize

0

Low impact, high effort — do last.

Nothing in this quadrant — good news.

← Low effort High effort →
BeaverCheck badge
Embed this badge
[![BeaverCheck](https://beavercheck.com/badge?url=https%3A%2F%2FVipoftalmologia.com.br)](https://beavercheck.com/results/ac246c48-4ee9-49c3-9077-82210984fb53)
<a href="https://beavercheck.com/results/ac246c48-4ee9-49c3-9077-82210984fb53"><img src="https://beavercheck.com/badge?url=https%3A%2F%2FVipoftalmologia.com.br" alt="BeaverCheck Score"></a>
https://beavercheck.com/badge?url=https%3A%2F%2FVipoftalmologia.com.br

This badge auto-updates with your latest scan result.

match(es)
·

What fixing these means

Your site has several issues that may be affecting user experience and business outcomes. Accessibility issues exclude users who rely on assistive technology — an estimated 15% of your potential audience. Addressing the critical issues below would have the most immediate impact on your user trust.

4 security gaps detected — browsers may warn visitors about your site.
1 accessibility issue excludes users who rely on assistive technology.

Return on Investment

BRL 630 investment → BRL 5,407/month returns + BRL 50,000,000 risk avoided

Payback period: < 1 month First-year ROI: +10200%
Investment

BRL 630

4h · 5 findings

Monthly returns

BRL 5,407 /mo

~BRL 64,888 / year

Regulatory risk avoided

BRL 50,000,000

if kept compliant

Payback period

0 12mo 24mo

Or — fix only the top 3 findings

BRL 450< 1 month payback · +14320% first-year ROI

Optimistic scenario assuming the top 3 capture most of the upside. Real-world recovery typically falls between this projection and the full-fix ROI above.

BRL 360 — in quick wins — start here for the fastest payback

Figures combine localized regulatory fine ceilings, search/conversion value priced against local CPC, and bandwidth waste estimates. Results depend on implementation quality and audience composition. Not legal or financial advice.

Full methodology & sourcesCompare with peers ↓

Conversion Barriers

1 critical 2 warning

3 barrier(s) likely increasing bounce by ~22%.

Trust (2)

No HSTS header

+1% bounce

Returning visitors are briefly exposed to downgrade attacks on first request

Fix: Set Strict-Transport-Security: max-age=31536000; includeSubDomains

No Content-Security-Policy header

+1% bounce

Higher XSS blast radius — one compromised script can exfiltrate the checkout form

Fix: Ship a reporting-only CSP first, then enforce once violations are clean

Usability (1)

No viewport meta tag

+15% bounce

Mobile browsers render at desktop width and shrink — text unreadable, tap targets miniature

Fix: Add <meta name="viewport" content="width=device-width, initial-scale=1">

Preliminary CRO audit — each barrier links to the tab with detailed analysis.

Estimated Remediation Cost

R$630

3.5 developer hours at R$180/hr

Based on Brazil rates (R$180/hr)

Quick wins
R$360 4 fixes in ~120 minutes

Start here for the best return on investment

Cost by category

Cost by effort level

Adjust assumptions

Team composition

Multiplier applied to dev hours to reflect QA, design, and PM overhead. Use Dev only for solo work; Full team for projects with formal review processes.

R$ /hr

Rates reflect fully-loaded developer cost including overhead

How developer rates are sourced

What Inaction Is Costing You

BRL 4,172,074 / month at risk

~BRL 50,064,888 / year if left unfixed

Default is 10,000. Use your own number for accurate $-figures.

Compliance Risk

BRL 50,000,000

LGPD
  • No privacy policy link detected
    LGPD: BRL 10,000 – BRL 50,000,000

Bounce-Rate Cost

BRL 5,407 /mo

+21.6pp bounce · ~2,163 lost visitors/mo

CPC: BRL 2.50

Compliance figures represent the statutory maximum fine for the most severe triggered category, capped per regulation — not the sum of per-finding penalties. Based on published regulatory fine ranges. This is not legal advice.

Compliance methodology · SEO assumptions · Bandwidth model

Was this report useful?

Thanks for your feedback!

Global Performance 7/7 locations
ES Madrid
Full audit
661ms
DNS 54ms · TLS 22ms
UN New York
605ms
DNS 135ms · TLS 9ms
ES Madrid
659ms
DNS 46ms · TLS 21ms
NL Amsterdam
645ms
DNS 26ms · TLS 9ms
BR Sao Paulo
448ms
DNS 8ms · TLS 9ms
US Santa Clara
650ms
DNS 14ms · TLS 8ms
SG Singapore
1126ms
DNS 10ms · TLS 9ms
CDN: Cloudflare (DYNAMIC) · Avg TTFB: 685ms · Cache: No cache headers

Compare with a competitor

Stack yourself against any competitor — score, Core Web Vitals, and the financial gap.

We'll use a cached audit if available, or offer to scan.

Checking for existing audit...

Lighthouse Scores

Industry-standard audits powered by Google Lighthouse.

Core Web Vitals

Key metrics that affect user experience.

Desktop audit not available for this result.

Send Feedback