Skip to content
Audit Complete

Results for https://stelgano.com

Visit site
Spain Spain · Madrid Completed: Apr 30, 2026 11:41 UTC
Download JSON Download Markdown Report

Three-week fix plan

2 sprints · 6h total → projected B (85)

Sprint 1: Quick Wins

+2

Highest ROI — low effort, high impact

2 findings 1h → B (80)
  • · Cross-Origin-Embedder-Policy header is missing
  • · External script from challenges.cloudflare.com lacks integrity attribute

Sprint 2: Core Fixes

+5

Medium effort, high structural impact

3 findings 6h → B (85)
  • · No favicon or icon links detected
  • · Page weighs 5.1 MB (5.0 MB transferred)
  • · Images are 4.8 MB — compress or use modern formats
AI remediation plan Ask AI about this audit

Your site declined by 5 points (B → C)

Compared to scan from 9 days ago

View previous audit

Mobile 375 × 812

Screenshot of the audited page (Mobile 375×812)

Desktop 1440 × 900

Screenshot of the audited page (Desktop 1440×900)
Focus mode
-5 score · 9 days ago B → C
View Changes →
Largest regressions: SEO -27Content -19Compliance -11
C78
Fix top 3 → B (83, +5)

Site Health

Score: 78 / 100 5

Based on 8 categories, 0 sections

Performance trend: stable →

Decent speed, but optimizing further could improve engagement.

Good foundation, but a few gaps could be exploited.

Several issues make your site difficult for assistive technology users.

Missing signals may be hurting your search visibility.

Solid infrastructure — fast server responses across the board.

Mostly compliant — a few items need attention.

Missing metadata means poor previews on social media and search.

Reasonable footprint with room for optimization.

How is this calculated?

The overall score is a weighted average of individual category scores. Categories with more impact on user experience and security carry more weight.

Performance 25%Security 25%Accessibility 15%SEO 10%Infrastructure 10%Compliance 8%Content 5%Sustainability 2%

Weights reflect general web best practices. Individual needs may differ.

How the composite score is calculated

How you compare

AngularJS · 401 peers
You 78
·
Avg 73
At average
0 50 100
SEO P1Content P5Security P95Accessibility P11Compliance P17Infrastructure P78Sustainability P34Performance P62

Top 10% of AngularJS sites score 74+ on SEO; you're at 69 — closing this gap is the highest-leverage improvement.

Better than 84% of AngularJS sites See full AngularJS benchmark →
Cloudflare Turnstile · 413 peers
You 78
·
Avg 73
At average
0 50 100
SEO P1Content P4Security P95Accessibility P12Compliance P17Infrastructure P76Sustainability P35Performance P63

Top 10% of Cloudflare Turnstile sites score 76+ on SEO; you're at 69 — closing this gap is the highest-leverage improvement.

Better than 84% of Cloudflare Turnstile sites See full Cloudflare Turnstile benchmark →

Top Priorities (5)

Critical: 1

Page weighs 5.1 MB (5.0 MB transferred)

Performance issues directly impact user engagement and conversion rates.

Performance › Page Weight Budget· 2h · $200· +3 pts
Critical: 2

No favicon or icon links detected

Accessibility issues exclude users with disabilities — up to 15% of your potential audience.

Accessibility › Favicon & Branding· 1h 30m · $150· +2 pts
Warning: 3

Cross-Origin-Embedder-Policy header is missing

Security gaps expose your site and users to attacks, eroding trust.

Security › Security Headers· 30m · $50· +1 pts
Warning: 4

External script from challenges.cloudflare.com lacks integrity attribute

Security gaps expose your site and users to attacks, eroding trust.

Security › Subresource Integrity· 30m · $50· +1 pts
Warning: 5

Images are 4.8 MB — compress or use modern formats

Performance issues directly impact user engagement and conversion rates.

Performance › Page Weight Budget· 2h · $200· +1 pts
View fix priority matrix

Fix Priority Matrix

5 findings

Quick Wins

2

High impact, low effort — start here.

Strategic

3

High impact, requires investment.

Easy Improvements

0

Small gains, minimal effort.

Nothing in this quadrant — good news.

Deprioritize

0

Low impact, high effort — do last.

Nothing in this quadrant — good news.

← Low effort High effort →
BeaverCheck badge
Embed this badge
[![BeaverCheck](https://beavercheck.com/badge?url=https%3A%2F%2Fstelgano.com)](https://beavercheck.com/results/b759b007-a703-423d-9735-c30d0f0983ac)
<a href="https://beavercheck.com/results/b759b007-a703-423d-9735-c30d0f0983ac"><img src="https://beavercheck.com/badge?url=https%3A%2F%2Fstelgano.com" alt="BeaverCheck Score"></a>
https://beavercheck.com/badge?url=https%3A%2F%2Fstelgano.com

This badge auto-updates with your latest scan result.

match(es)
·

What fixing these means

Your site performs reasonably well, but a few targeted fixes could meaningfully improve results. Your LCP of 7.8s exceeds Google's 2.5s 'Good' threshold and the 2 performance issues below directly contribute to it. Accessibility issues exclude users who rely on assistive technology — an estimated 15% of your potential audience. Addressing the critical issues below would have the most immediate impact on your conversion rate.

Your LCP is 7.8s — fixing the 2 performance criticals could bring it under Google's 2.5s 'Good' threshold.
1 accessibility issue excludes users who rely on assistive technology.
2 security gaps detected — browsers may warn visitors about your site.
B
Could reach Estimate based on resolving critical issues

Return on Investment

$650 investment → $11,242/month returns + USD 150,000 risk avoided

Payback period: < 1 month First-year ROI: +20654%
Investment

$650

6h · 5 findings

Monthly returns

$11,242 /mo

~$134,904 / year

Regulatory risk avoided

USD 150,000

if kept compliant

Payback period

0 12mo 24mo

Or — fix only the top 3 findings

$400< 1 month payback · +33626% first-year ROI

Optimistic scenario assuming the top 3 capture most of the upside. Real-world recovery typically falls between this projection and the full-fix ROI above.

$100 — in quick wins — start here for the fastest payback

Figures combine localized regulatory fine ceilings, search/conversion value priced against local CPC, and bandwidth waste estimates. Results depend on implementation quality and audience composition. Not legal or financial advice.

Full methodology & sourcesCompare with peers ↓

Conversion Barriers

1 critical 4 warning

5 barrier(s) likely increasing bounce by ~24%.

Speed (1)

Page takes 7.8s to load

+12% bounce

Users abandon at ~3s — you're 5.3s over the 2.5s threshold

Fix: Optimize render-blocking resources, preload the hero image, and compress images

Content (3)

No Open Graph tags

+2% bounce

Links shared on LinkedIn / Slack / Facebook show bare URLs — referral clicks drop

Fix: Add og:title, og:description, og:image, og:url to the page head

No structured data

+2% bounce

No rich-result eligibility in Google — lower SERP CTR vs competitors with stars and prices

Fix: Add JSON-LD for your page type (Product, Article, FAQPage, LocalBusiness, …)

Thin content

+3% bounce

Under 300 words — visitors bounce looking for substance, search engines rank competitors first

Fix: Add a substantive FAQ, product detail, or case-study section

Navigation (1)

No skip-to-content link

+1% bounce

Keyboard and screen-reader users must tab through the entire header on every page

Fix: Add a visible-on-focus <a href="#main">Skip to content</a> as the first focusable element

Preliminary CRO audit — each barrier links to the tab with detailed analysis.

Estimated Remediation Cost

$650

6.5 developer hours at $100/hr

Based on United States rates ($100/hr)

Quick wins
$100 2 fixes in ~60 minutes

Start here for the best return on investment

Cost by category

Cost by effort level

Adjust assumptions

Team composition

Multiplier applied to dev hours to reflect QA, design, and PM overhead. Use Dev only for solo work; Full team for projects with formal review processes.

$ /hr

Rates reflect fully-loaded developer cost including overhead

How developer rates are sourced

What Inaction Is Costing You

$19,046 / month at risk

~$228,550 / year if left unfixed

Default is 10,000. Use your own number for accurate $-figures.

Compliance Risk

$150,000

ADA Title III
  • No <nav> landmark found
    ADA Title III: USD 25,000 – USD 150,000
  • Skip navigation link is missing (WCAG 2.4.1)
    ADA Title III: USD 25,000 – USD 150,000

Bounce-Rate Cost

$6,545 /mo

+24.3pp bounce · ~2,433 lost visitors/mo

CPC: USD 2.69

Bandwidth Waste

$1.26 /mo

15713.1 MB/mo × 0.080 USD/GB

  • Optimize transfer: save ~1.6 MB per page load
    Saves $1.26/mo

Compliance figures represent the statutory maximum fine for the most severe triggered category, capped per regulation — not the sum of per-finding penalties. Based on published regulatory fine ranges. This is not legal advice.

Compliance methodology · SEO assumptions · Bandwidth model

Your performance is already good — improvements may show diminishing returns

Unique monthly visitors from your analytics

Purchases, signups, or key actions

Optional — for revenue estimation

additional conversions/month

more engaged visitors from reduced bounce

potential monthly revenue
Current bounce (est.)
After fixes (est.)
Estimated bounce reduction

Fix 2 critical issues to capture this value

How this is calculated

Based on Google/Deloitte research ("Milliseconds Make Millions") showing a ~7% bounce rate increase per additional second of LCP above the 2.5s "Good" threshold.

Your site's LCP: → estimated after fixes.

These are estimates based on industry research — actual results vary

Bounce-rate model & assumptions

Your data stays in your browser — nothing is sent to our servers

Was this report useful?

Thanks for your feedback!

Global Performance 7/7 locations
ES Madrid
Full audit
133ms
DNS 40ms · TLS 22ms
US Santa Clara
78ms
DNS 13ms · TLS 10ms
UN New York
57ms
DNS 9ms · TLS 8ms
ES Madrid
120ms
DNS 42ms · TLS 22ms
NL Amsterdam
90ms
DNS 13ms · TLS 13ms
SG Singapore
67ms
DNS 11ms · TLS 7ms
BR Sao Paulo
74ms
DNS 12ms · TLS 10ms
CDN: Cloudflare (HIT) · Avg TTFB: 88ms · Cache: public, max-age=0, must-revalidate
Recent Trends
Performance stable →
74
TTFB stable →
133ms
FCP stable →
2.0s
LCP stable →
7.8s

Compare with a competitor

Stack yourself against any competitor — score, Core Web Vitals, and the financial gap.

We'll use a cached audit if available, or offer to scan.

Checking for existing audit...

Lighthouse Scores

Industry-standard audits powered by Google Lighthouse.

74 -5
Performance Overall performance score (0–100) based on Core Web Vitals and other metrics. 90+ is good.
96 +7
Accessibility Measures how accessible the page is for users with disabilities. Checks color contrast, ARIA labels, and semantic HTML.
92 -8
Best Practices Checks for modern web development best practices including HTTPS, no console errors, and secure JavaScript.
92
SEO Measures basic SEO optimizations: meta tags, crawlability, link text, and mobile friendliness.

Core Web Vitals

Key metrics that affect user experience.

First Contentful Paint First Contentful Paint — how long until the browser renders the first piece of content. Under 1.8s is good.

2.02 s

Largest Contentful Paint Largest Contentful Paint — how long until the largest visible element loads. Under 2.5s is good.

7.79 s

Total Blocking Time Total Blocking Time — total time the main thread was blocked, preventing user input. Under 200ms is good.

0 ms

Cumulative Layout Shift Cumulative Layout Shift — measures visual stability. How much the page layout shifts during loading. Under 0.1 is good.

0.008

Speed Index Speed Index — how quickly content is visually displayed during load. Under 3.4s is good.

2.02 s

Time to Interactive Time to Interactive — how long until the page is fully interactive and responds to user input. Under 3.8s is good.

7.80 s

Detailed Report

Audit breakdown by category with detailed findings.

74

Performance

Insights

Remove large, duplicate JavaScript modules from bundles to reduce unnecessary bytes consumed by network activity.

Why this matters

Performance issues directly impact user engagement and conversion rates.

Polyfills and transforms enable older browsers to use new JavaScript features. However, many aren't necessary for modern browsers. Consider modifying your JavaScript build process to not transpile Baseline features, unless you know you must support older browsers. Learn why most sites can deploy ES6+ code without transpiling

Why this matters

Shipping ES5 transpiled code to modern browsers wastes bytes — every user with an evergreen browser pays for compatibility you don't need.

Learn more

Most users today run browsers that natively support ES6+, async/await, optional chaining, and the rest of modern JavaScript. Transpiling to ES5 'just in case' adds 20-40% to your bundle for no benefit. Configure your build to target a modern browserslist, or ship a differential bundle pair (modern + legacy) with the module/nomodule pattern.

Source: Google web.dev / Lighthouse

3rd party code can significantly impact load performance. Reduce and defer loading of 3rd party code to prioritize your page's content.

Why this matters

Performance issues directly impact user engagement and conversion rates.

Reducing the download time of images can improve the perceived load time of the page and LCP. Learn more about optimizing image size

Why this matters

Performance issues directly impact user engagement and conversion rates.

URLResource SizeEst Savings
Zero-Knowledge Architecture div.space-y-32 > div.grid > div.relative > img.relative
stelgano.com/images/zero_knowledge_server.png904.6 KiB885.1 KiB
N=1 Messaging - Shattering the previous message section.px-4 > div.grid > div.relative > img.relative
stelgano.com/images/n_equals_1.png749.8 KiB730.1 KiB
Ephemeral Identity Concept div.space-y-32 > div.grid > div.order-1 > img.relative
stelgano.com/images/ephemeral_identity.png730.8 KiB711.3 KiB
Client-Side Encryption div.space-y-32 > div.grid > div.relative > img.relative
stelgano.com/images/client_side_crypto.png720.9 KiB701.4 KiB
Contact-Layer Steganography Concept div.max-w-6xl > div.grid > div.order-2 > img.relative
stelgano.com/images/contact_steg.png407.2 KiB387.8 KiB

Avoid chaining critical requests by reducing the length of chains, reducing the download size of resources, or deferring the download of unnecessary resources to improve page load.

Why this matters

Performance issues directly impact user engagement and conversion rates.

description: [preconnect](https://developer.chrome.com/docs/lighthouse/performance/uses-rel-preconnect/) hints help the browser establish a connection earlier in the page load, saving time when the first request for that origin is made. The following are the origins that the page preconnected to.
title: Preconnected origins
value: no origins were preconnected
description: Add [preconnect](https://developer.chrome.com/docs/lighthouse/performance/uses-rel-preconnect/) hints to your most important origins, but try to use no more than 4.
title: Preconnect candidates
value: No additional origins are good candidates for preconnecting

Requests are blocking the page's initial render, which may delay LCP. Deferring or inlining can move these network requests out of the critical path.

Why this matters

Performance issues directly impact user engagement and conversion rates.

URLTransfer SizeDuration
stelgano.com/assets/app.css13.7 KiB150 ms

These insights are also available in the Chrome DevTools Performance Panel - record a trace to view more detailed information.

Time to Interactive is the amount of time it takes for the page to become fully interactive. Learn more about the Time to Interactive metric.

Why this matters

Performance issues directly impact user engagement and conversion rates.

TTI

Diagnostics

Set an explicit width and height on image elements to reduce layout shifts and improve CLS. Learn how to set image dimensions

Why this matters

Performance issues directly impact user engagement and conversion rates.

URL
Zero-Knowledge Architecture div.space-y-32 > div.grid > div.relative > img.relative
stelgano.com/images/zero_knowledge_server.png
Ephemeral Identity Concept div.space-y-32 > div.grid > div.order-1 > img.relative
stelgano.com/images/ephemeral_identity.png
Client-Side Encryption div.space-y-32 > div.grid > div.relative > img.relative
stelgano.com/images/client_side_crypto.png
Contact-Layer Steganography Concept div.max-w-6xl > div.grid > div.order-2 > img.relative
stelgano.com/images/contact_steg.png
N=1 Messaging - Shattering the previous message section.px-4 > div.grid > div.relative > img.relative
stelgano.com/images/n_equals_1.png

More information about the performance of your application. These numbers don't directly affect the Performance score.

Use efficient cache lifetimes
Layout shift culprits
Document request latency
Optimize DOM size
Font display
Forced reflow
LCP breakdown
Modern HTTP
Optimize viewport for mobile
Max Potential First Input Delay 20 ms
Minify CSS
Minify JavaScript
Reduce unused CSS
Reduce unused JavaScript
JavaScript execution time 0.0 s
Minimizes main-thread work 1.4 s
Avoid long main-thread tasks 6 long tasks found
Page didn't prevent back/forward cache restoration
Network Requests
Network Round Trip Times 0 ms
Server Backend Latencies 70 ms
Tasks
Diagnostics
Metrics
Screenshot Thumbnails
Final Screenshot
Script Treemap Data
Resources Summary
Avoid multiple page redirects
Initial server response time was short Root document took 40 ms
Avoid large layout shifts 2 layout shifts found
INP breakdown
LCP request discovery
User Timing marks and measures
Avoid non-composited animations
96

Accessibility

These checks highlight opportunities to improve the accessibility of your web app. Automatic detection can only detect a subset of issues and does not guarantee the accessibility of your web app, so manual testing is also encouraged.

Contrast

Low-contrast text is difficult or impossible for many users to read. Learn how to provide sufficient color contrast.

Why this matters

Performance issues directly impact user engagement and conversion rates.

Failing Elements
No plaintext ever touches the backend. Even a full database breach reveals noth… ul.space-y-4 > li.flex > div > p.text-slate-500
The protocol is designed so you don't even have to trust us. The cryptography g… ul.space-y-4 > li.flex > div > p.text-slate-500
We don't want to know who you are. The system is designed to prevent us from ev… ul.space-y-4 > li.flex > div > p.text-slate-500
Session keys are kept strictly in volatile memory. Close the browser, and the e… ul.space-y-4 > li.flex > div > p.text-slate-500
Your encryption keys are derived from your PIN and the Steg Number using 600,00… ul.space-y-4 > li.flex > div > p.text-slate-500
Because the payload is encrypted with AES-256-GCM before it ever hits the netwo… ul.space-y-4 > li.flex > div > p.text-slate-500
The moment a reply is sent, the previous message is atomically wiped from the d… ul.space-y-6 > li.flex > div > p.text-slate-500
Because old messages are actively destroyed to make room for new ones, there is… ul.space-y-6 > li.flex > div > p.text-slate-500
Even if a server is physically seized or fully compromised, there is nothing to… ul.space-y-6 > li.flex > div > p.text-slate-500
Pro Tip: Use Incognito/Private Mode to ensure no local traces remain. div.w-full > section.px-6 > div.relative > p.text-xs
The messaging app hidden in your contacts. footer.px-6 > div.max-w-6xl > div.flex > p.text-slate-500
STEL·GAH·NO — STEGANOGRAPHY + TEL footer.px-6 > div.max-w-6xl > div.flex > p.text-slate-600
AGPL-3.0 div.max-w-6xl > div.flex > div.flex > div.px-2
BUILD 2026.04 div.max-w-6xl > div.flex > div.flex > div.px-2
© 2026 sTELgano Contributors footer.px-6 > div.max-w-6xl > div.flex > p.text-[9px]

These are opportunities to improve the legibility of your content.

Interactive controls are keyboard focusable
Interactive elements indicate their purpose and state
The page has a logical tab order
Visual order on the page follows DOM order
User focus is not accidentally trapped in a region
The user's focus is directed to new content added to the page
HTML5 landmark elements are used to improve navigation
Offscreen content is hidden from assistive technology
Custom controls have associated labels
Custom controls have ARIA roles
`[aria-*]` attributes match their roles
`[aria-hidden="true"]` is not present on the document `<body>`
`[aria-*]` attributes have valid values
`[aria-*]` attributes are valid and not misspelled
Buttons have an accessible name
Image elements have `[alt]` attributes
`[user-scalable="no"]` is not used in the `<meta name="viewport">` element and the `[maximum-scale]` attribute is not less than 5.
ARIA attributes are used as specified for the element's role
`[aria-hidden="true"]` elements do not contain focusable descendents
Elements use only permitted ARIA attributes
Document has a `<title>` element
`<html>` element has a `[lang]` attribute
`<html>` element has a valid value for its `[lang]` attribute
Links have a discernible name
Lists contain only `<li>` elements and script supporting elements (`<script>` and `<template>`).
List items (`<li>`) are contained within `<ul>`, `<ol>` or `<menu>` parent elements
Touch targets have sufficient size and spacing.
Cells in a `<table>` element that use the `[headers]` attribute refer to table cells within the same table.
Heading elements appear in a sequentially-descending order
Document has a main landmark.
Tables use `<caption>` instead of cells with the `[colspan]` attribute to indicate a caption.
`<td>` elements in a large `<table>` have one or more table headers.
`[accesskey]` values are unique
`button`, `link`, and `menuitem` elements have accessible names
Deprecated ARIA roles were not used
Elements with `role="dialog"` or `role="alertdialog"` have accessible names.
ARIA input fields have accessible names
ARIA `meter` elements have accessible names
ARIA `progressbar` elements have accessible names
`[role]`s have all required `[aria-*]` attributes
Elements with an ARIA `[role]` that require children to contain a specific `[role]` have all required children.
`[role]`s are contained by their required parent element
`[role]` values are valid
Elements with the `role=text` attribute do not have focusable descendents.
ARIA toggle fields have accessible names
ARIA `tooltip` elements have accessible names
ARIA `treeitem` elements have accessible names
The page contains a heading, skip link, or landmark region
`<dl>`'s contain only properly-ordered `<dt>` and `<dd>` groups, `<script>`, `<template>` or `<div>` elements.
Definition list items are wrapped in `<dl>` elements
ARIA IDs are unique
No form fields have multiple labels
`<frame>` or `<iframe>` elements have a title
`<html>` element has an `[xml:lang]` attribute with the same base language as the `[lang]` attribute.
Input buttons have discernible text.
`<input type="image">` elements have `[alt]` text
Form elements have associated labels
Links are distinguishable without relying on color.
The document does not use `<meta http-equiv="refresh">`
`<object>` elements have alternate text
Select elements have associated label elements.
Skip links are focusable.
No element has a `[tabindex]` value greater than 0
`<th>` elements and elements with `[role="columnheader"/"rowheader"]` have data cells they describe.
`[lang]` attributes have a valid value
`<video>` elements contain a `<track>` element with `[kind="captions"]`
Tables have different content in the summary attribute and `<caption>`.
All heading elements contain content.
Uses ARIA roles only on compatible elements
Image elements do not have `[alt]` attributes that are redundant text.
Identical links have the same purpose.
Elements with visible text labels have matching accessible names.
92

Best Practices

General

Errors logged to the console indicate unresolved problems. They can come from network request failures and other browser concerns. Learn more about this errors in console diagnostic audit

Why this matters

Performance issues directly impact user engagement and conversion rates.

SourceDescription
stelgano.com/ line 748, col 0
Executing inline script violates the following Content Security Policy directive 'script-src 'self' 'sha256-TcKTNdXTdoY7CPkISQBGRdZrB9mW+WPwtBzUlVAeDUI=' 'sha256-j6d3USvTAe86wO1FSGzg2wwLRKlwfPtAEpatzxcoswQ=' 'sha256-xJ+O11qzfGNdhPsakz+MANZJPuAEzgSwqFfTO6evqaU=''. Either the 'unsafe-inline' keyword, a hash ('sha256-GM7H7+I+W2J4GLYn4ntYabY+1Ggo6/SzmPg9yoZUp6k='), or a nonce ('nonce-...') is required to enable inline execution. The action has been blocked.

Issues logged to the `Issues` panel in Chrome Devtools indicate unresolved problems. They can come from network request failures, insufficient security controls, and other browser concerns. Open up the Issues panel in Chrome DevTools for more details on each issue.

Why this matters

Performance issues directly impact user engagement and conversion rates.

Issue type
Content security policy
Uses HTTPS
Avoids deprecated APIs
Avoids third-party cookies
Allows users to paste into input fields
Avoids requesting the geolocation permission on page load
Avoids requesting the notification permission on page load
Displays images with correct aspect ratio
Serves images with appropriate resolution
Page has the HTML doctype
Properly defines charset
Ensure CSP is effective against XSS attacks
Mitigate DOM-based XSS with Trusted Types
Page has valid source maps
Redirects HTTP traffic to HTTPS
Use a strong HSTS policy
Ensure proper origin isolation with COOP
Mitigate clickjacking with XFO or CSP
Detected JavaScript libraries
92

SEO

These checks ensure that your page is following basic search engine optimization advice. There are many additional factors Lighthouse does not score here that may affect your search ranking, including performance on Core Web Vitals. Learn more about Google Search Essentials.

Content Best Practices

Meta descriptions may be included in search results to concisely summarize page content. Learn more about the meta description.

Why this matters

Performance issues directly impact user engagement and conversion rates.

Format your HTML in a way that enables crawlers to better understand your app’s content.

Structured data is valid
Page isn’t blocked from indexing
Document has a `<title>` element
Page has successful HTTP status code
Links have descriptive text
Links are crawlable
robots.txt is valid
Image elements have `[alt]` attributes
Document has a valid `hreflang`
Document has a valid `rel=canonical`

Lighthouse Scores

Industry-standard audits powered by Google Lighthouse. — Desktop

78
Performance Overall performance score (0–100) based on Core Web Vitals and other metrics. 90+ is good.
93
Accessibility Measures how accessible the page is for users with disabilities. Checks color contrast, ARIA labels, and semantic HTML.
92
Best Practices Checks for modern web development best practices including HTTPS, no console errors, and secure JavaScript.
92
SEO Measures basic SEO optimizations: meta tags, crawlability, link text, and mobile friendliness.

Core Web Vitals

Key metrics that affect user experience. — Desktop

First Contentful Paint First Contentful Paint — how long until the browser renders the first piece of content. Under 1.8s is good.

715 ms

Largest Contentful Paint Largest Contentful Paint — how long until the largest visible element loads. Under 2.5s is good.

4.14 s

Total Blocking Time Total Blocking Time — total time the main thread was blocked, preventing user input. Under 200ms is good.

0 ms

Cumulative Layout Shift Cumulative Layout Shift — measures visual stability. How much the page layout shifts during loading. Under 0.1 is good.

0.024

Speed Index Speed Index — how quickly content is visually displayed during load. Under 3.4s is good.

726 ms

Time to Interactive Time to Interactive — how long until the page is fully interactive and responds to user input. Under 3.8s is good.

4.22 s

Detailed Report

Audit breakdown by category with detailed findings.

78

Performance

Insights

Remove large, duplicate JavaScript modules from bundles to reduce unnecessary bytes consumed by network activity.

Why this matters

Performance issues directly impact user engagement and conversion rates.

Polyfills and transforms enable older browsers to use new JavaScript features. However, many aren't necessary for modern browsers. Consider modifying your JavaScript build process to not transpile Baseline features, unless you know you must support older browsers. Learn why most sites can deploy ES6+ code without transpiling

Why this matters

Shipping ES5 transpiled code to modern browsers wastes bytes — every user with an evergreen browser pays for compatibility you don't need.

Learn more

Most users today run browsers that natively support ES6+, async/await, optional chaining, and the rest of modern JavaScript. Transpiling to ES5 'just in case' adds 20-40% to your bundle for no benefit. Configure your build to target a modern browserslist, or ship a differential bundle pair (modern + legacy) with the module/nomodule pattern.

Source: Google web.dev / Lighthouse

3rd party code can significantly impact load performance. Reduce and defer loading of 3rd party code to prioritize your page's content.

Why this matters

Performance issues directly impact user engagement and conversion rates.

Reducing the download time of images can improve the perceived load time of the page and LCP. Learn more about optimizing image size

Why this matters

Performance issues directly impact user engagement and conversion rates.

URLResource SizeEst Savings
Zero-Knowledge Architecture div.space-y-32 > div.grid > div.relative > img.relative
stelgano.com/images/zero_knowledge_server.png904.6 KiB874.5 KiB
Ephemeral Identity Concept div.space-y-32 > div.grid > div.order-1 > img.relative
stelgano.com/images/ephemeral_identity.png730.8 KiB700.7 KiB
Client-Side Encryption div.space-y-32 > div.grid > div.relative > img.relative
stelgano.com/images/client_side_crypto.png720.9 KiB690.8 KiB
Contact-Layer Steganography Concept div.max-w-6xl > div.grid > div.order-2 > img.relative
stelgano.com/images/contact_steg.png407.2 KiB377.2 KiB
sTELgano vs Traditional Messaging Apps div.max-w-7xl > div.grid > div.relative > img.relative
stelgano.com/images/comparison_visual.jpg295.5 KiB279.1 KiB
sTELgano Secure Messaging section.relative > div.grid > div.relative > img.relative
stelgano.com/images/hero_visual.jpg235.3 KiB202.6 KiB

Optimize LCP by making the LCP image discoverable from the HTML immediately, and avoiding lazy-loading

Why this matters

Performance issues directly impact user engagement and conversion rates.

lhId: page-5-IMG
nodeLabel: sTELgano Secure Messaging
path: 2,HTML,1,BODY,3,MAIN,0,DIV,1,SECTION,0,DIV,1,DIV,1,IMG
selector: section.relative > div.grid > div.relative > img.relative
snippet: <img src="/images/hero_visual.jpg" alt="sTELgano Secure Messaging" class="relative z-10 w-full h-auto drop-shadow-[0_0_50px_rgba(16,185,129,0.3)] fl…">

Avoid chaining critical requests by reducing the length of chains, reducing the download size of resources, or deferring the download of unnecessary resources to improve page load.

Why this matters

Performance issues directly impact user engagement and conversion rates.

description: [preconnect](https://developer.chrome.com/docs/lighthouse/performance/uses-rel-preconnect/) hints help the browser establish a connection earlier in the page load, saving time when the first request for that origin is made. The following are the origins that the page preconnected to.
title: Preconnected origins
value: no origins were preconnected
description: Add [preconnect](https://developer.chrome.com/docs/lighthouse/performance/uses-rel-preconnect/) hints to your most important origins, but try to use no more than 4.
title: Preconnect candidates
value: No additional origins are good candidates for preconnecting

Requests are blocking the page's initial render, which may delay LCP. Deferring or inlining can move these network requests out of the critical path.

Why this matters

Performance issues directly impact user engagement and conversion rates.

URLTransfer SizeDuration
stelgano.com/assets/app.css14.4 KiB109 ms

These insights are also available in the Chrome DevTools Performance Panel - record a trace to view more detailed information.

Time to Interactive is the amount of time it takes for the page to become fully interactive. Learn more about the Time to Interactive metric.

Why this matters

Performance issues directly impact user engagement and conversion rates.

TTI

Diagnostics

Set an explicit width and height on image elements to reduce layout shifts and improve CLS. Learn how to set image dimensions

Why this matters

Performance issues directly impact user engagement and conversion rates.

URL
sTELgano Secure Messaging section.relative > div.grid > div.relative > img.relative
stelgano.com/images/hero_visual.jpg
Zero-Knowledge Architecture div.space-y-32 > div.grid > div.relative > img.relative
stelgano.com/images/zero_knowledge_server.png
Ephemeral Identity Concept div.space-y-32 > div.grid > div.order-1 > img.relative
stelgano.com/images/ephemeral_identity.png
Client-Side Encryption div.space-y-32 > div.grid > div.relative > img.relative
stelgano.com/images/client_side_crypto.png
Contact-Layer Steganography Concept div.max-w-6xl > div.grid > div.order-2 > img.relative
stelgano.com/images/contact_steg.png
N=1 Messaging - Shattering the previous message section.px-4 > div.grid > div.relative > img.relative
stelgano.com/images/n_equals_1.png
sTELgano Security Architecture div.max-w-6xl > div.grid > div.relative > img.relative
stelgano.com/images/hero_illustration.png
sTELgano vs Traditional Messaging Apps div.max-w-7xl > div.grid > div.relative > img.relative
stelgano.com/images/comparison_visual.jpg

More information about the performance of your application. These numbers don't directly affect the Performance score.

Use efficient cache lifetimes
Layout shift culprits
Document request latency
Optimize DOM size
Font display
Forced reflow
LCP breakdown
Modern HTTP
Optimize viewport for mobile
Max Potential First Input Delay 20 ms
Minify CSS
Minify JavaScript
Reduce unused CSS
Reduce unused JavaScript
JavaScript execution time 0.0 s
Minimizes main-thread work 0.6 s
Avoid long main-thread tasks 2 long tasks found
Page didn't prevent back/forward cache restoration
Network Requests
Network Round Trip Times 20 ms
Server Backend Latencies 30 ms
Tasks
Diagnostics
Metrics
Screenshot Thumbnails
Final Screenshot
Script Treemap Data
Resources Summary
Avoid multiple page redirects
Initial server response time was short Root document took 40 ms
Avoid large layout shifts 1 layout shift found
INP breakdown
User Timing marks and measures
Avoid non-composited animations
93

Accessibility

These checks highlight opportunities to improve the accessibility of your web app. Automatic detection can only detect a subset of issues and does not guarantee the accessibility of your web app, so manual testing is also encouraged.

Contrast

Low-contrast text is difficult or impossible for many users to read. Learn how to provide sufficient color contrast.

Why this matters

Performance issues directly impact user engagement and conversion rates.

Failing Elements
No plaintext ever touches the backend. Even a full database breach reveals noth… ul.space-y-4 > li.flex > div > p.text-slate-500
The protocol is designed so you don't even have to trust us. The cryptography g… ul.space-y-4 > li.flex > div > p.text-slate-500
We don't want to know who you are. The system is designed to prevent us from ev… ul.space-y-4 > li.flex > div > p.text-slate-500
Session keys are kept strictly in volatile memory. Close the browser, and the e… ul.space-y-4 > li.flex > div > p.text-slate-500
Your encryption keys are derived from your PIN and the Steg Number using 600,00… ul.space-y-4 > li.flex > div > p.text-slate-500
Because the payload is encrypted with AES-256-GCM before it ever hits the netwo… ul.space-y-4 > li.flex > div > p.text-slate-500
The moment a reply is sent, the previous message is atomically wiped from the d… ul.space-y-6 > li.flex > div > p.text-slate-500
Because old messages are actively destroyed to make room for new ones, there is… ul.space-y-6 > li.flex > div > p.text-slate-500
Even if a server is physically seized or fully compromised, there is nothing to… ul.space-y-6 > li.flex > div > p.text-slate-500
Pro Tip: Use Incognito/Private Mode to ensure no local traces remain. div.w-full > section.px-6 > div.relative > p.text-xs
The messaging app hidden in your contacts. footer.px-6 > div.max-w-6xl > div.flex > p.text-slate-500
STEL·GAH·NO — STEGANOGRAPHY + TEL footer.px-6 > div.max-w-6xl > div.flex > p.text-slate-600
AGPL-3.0 div.max-w-6xl > div.flex > div.flex > div.px-2
BUILD 2026.04 div.max-w-6xl > div.flex > div.flex > div.px-2
© 2026 sTELgano Contributors footer.px-6 > div.max-w-6xl > div.flex > p.text-[9px]

These are opportunities to improve the legibility of your content.

Interactive controls are keyboard focusable
Interactive elements indicate their purpose and state
The page has a logical tab order
Visual order on the page follows DOM order
User focus is not accidentally trapped in a region
The user's focus is directed to new content added to the page
HTML5 landmark elements are used to improve navigation
Offscreen content is hidden from assistive technology
Custom controls have associated labels
Custom controls have ARIA roles
`[aria-hidden="true"]` is not present on the document `<body>`
Image elements have `[alt]` attributes
`[user-scalable="no"]` is not used in the `<meta name="viewport">` element and the `[maximum-scale]` attribute is not less than 5.
`[aria-hidden="true"]` elements do not contain focusable descendents
Document has a `<title>` element
`<html>` element has a `[lang]` attribute
`<html>` element has a valid value for its `[lang]` attribute
Links have a discernible name
Lists contain only `<li>` elements and script supporting elements (`<script>` and `<template>`).
List items (`<li>`) are contained within `<ul>`, `<ol>` or `<menu>` parent elements
Touch targets have sufficient size and spacing.
Cells in a `<table>` element that use the `[headers]` attribute refer to table cells within the same table.
Heading elements appear in a sequentially-descending order
Document has a main landmark.
Tables use `<caption>` instead of cells with the `[colspan]` attribute to indicate a caption.
`<td>` elements in a large `<table>` have one or more table headers.
`[accesskey]` values are unique
`[aria-*]` attributes match their roles
`button`, `link`, and `menuitem` elements have accessible names
ARIA attributes are used as specified for the element's role
Deprecated ARIA roles were not used
Elements with `role="dialog"` or `role="alertdialog"` have accessible names.
ARIA input fields have accessible names
ARIA `meter` elements have accessible names
ARIA `progressbar` elements have accessible names
Elements use only permitted ARIA attributes
`[role]`s have all required `[aria-*]` attributes
Elements with an ARIA `[role]` that require children to contain a specific `[role]` have all required children.
`[role]`s are contained by their required parent element
`[role]` values are valid
Elements with the `role=text` attribute do not have focusable descendents.
ARIA toggle fields have accessible names
ARIA `tooltip` elements have accessible names
ARIA `treeitem` elements have accessible names
`[aria-*]` attributes have valid values
`[aria-*]` attributes are valid and not misspelled
Buttons have an accessible name
The page contains a heading, skip link, or landmark region
`<dl>`'s contain only properly-ordered `<dt>` and `<dd>` groups, `<script>`, `<template>` or `<div>` elements.
Definition list items are wrapped in `<dl>` elements
ARIA IDs are unique
No form fields have multiple labels
`<frame>` or `<iframe>` elements have a title
`<html>` element has an `[xml:lang]` attribute with the same base language as the `[lang]` attribute.
Input buttons have discernible text.
`<input type="image">` elements have `[alt]` text
Form elements have associated labels
Links are distinguishable without relying on color.
The document does not use `<meta http-equiv="refresh">`
`<object>` elements have alternate text
Select elements have associated label elements.
Skip links are focusable.
No element has a `[tabindex]` value greater than 0
`<th>` elements and elements with `[role="columnheader"/"rowheader"]` have data cells they describe.
`[lang]` attributes have a valid value
`<video>` elements contain a `<track>` element with `[kind="captions"]`
Tables have different content in the summary attribute and `<caption>`.
All heading elements contain content.
Uses ARIA roles only on compatible elements
Image elements do not have `[alt]` attributes that are redundant text.
Identical links have the same purpose.
Elements with visible text labels have matching accessible names.
92

Best Practices

General

Errors logged to the console indicate unresolved problems. They can come from network request failures and other browser concerns. Learn more about this errors in console diagnostic audit

Why this matters

Performance issues directly impact user engagement and conversion rates.

SourceDescription
stelgano.com/ line 748, col 0
Executing inline script violates the following Content Security Policy directive 'script-src 'self' 'sha256-TcKTNdXTdoY7CPkISQBGRdZrB9mW+WPwtBzUlVAeDUI=' 'sha256-j6d3USvTAe86wO1FSGzg2wwLRKlwfPtAEpatzxcoswQ=' 'sha256-xJ+O11qzfGNdhPsakz+MANZJPuAEzgSwqFfTO6evqaU=''. Either the 'unsafe-inline' keyword, a hash ('sha256-yLmy3umuxrnd+whntb8tNQpGN2xuoa4UWwxilCgfYh0='), or a nonce ('nonce-...') is required to enable inline execution. The action has been blocked.

Issues logged to the `Issues` panel in Chrome Devtools indicate unresolved problems. They can come from network request failures, insufficient security controls, and other browser concerns. Open up the Issues panel in Chrome DevTools for more details on each issue.

Why this matters

Performance issues directly impact user engagement and conversion rates.

Issue type
Content security policy
Uses HTTPS
Avoids deprecated APIs
Avoids third-party cookies
Allows users to paste into input fields
Avoids requesting the geolocation permission on page load
Avoids requesting the notification permission on page load
Displays images with correct aspect ratio
Serves images with appropriate resolution
Page has the HTML doctype
Properly defines charset
Ensure CSP is effective against XSS attacks
Mitigate DOM-based XSS with Trusted Types
Page has valid source maps
Redirects HTTP traffic to HTTPS
Use a strong HSTS policy
Ensure proper origin isolation with COOP
Mitigate clickjacking with XFO or CSP
Detected JavaScript libraries
92

SEO

These checks ensure that your page is following basic search engine optimization advice. There are many additional factors Lighthouse does not score here that may affect your search ranking, including performance on Core Web Vitals. Learn more about Google Search Essentials.

Content Best Practices

Meta descriptions may be included in search results to concisely summarize page content. Learn more about the meta description.

Why this matters

Performance issues directly impact user engagement and conversion rates.

Format your HTML in a way that enables crawlers to better understand your app’s content.

Structured data is valid
Page isn’t blocked from indexing
Document has a `<title>` element
Page has successful HTTP status code
Links have descriptive text
Links are crawlable
robots.txt is valid
Image elements have `[alt]` attributes
Document has a valid `hreflang`
Document has a valid `rel=canonical`

Send Feedback