Skip to content

Changes

https://costdown.org
Compared to previous audit · 1 hour ago View previous audit
3
New issues
5
Resolved
14
score changes
CategoryPreviousCurrentChange
CompositeA (91)A (93) +2.000
PerformanceA+ (97)A+ (97)
SecurityB (89)A (93) +4.000
AccessibilityA (90)A (90)
SEOA (95)A+ (97) +2.000
InfrastructureB (88)A (90) +2.000
ComplianceB (85)B (85)
ContentB (85)B (85)
SustainabilityA+ (98)A+ (98)
MetricPreviousCurrentChange
Performance 86009500 +900
Accessibility 96009600
Best Practices 1000010000
SEO 91009100
PWA 00
Desktop Performance 98009800
Desktop Accessibility 96009600
Desktop Best Practices 1000010000
Desktop SEO 92009200
FCP 1.49 s1.25 s -247 ms
LCP 3.81 s2.82 s -984 ms
TBT 134 ms58 ms -76 ms
CLS 0.0000.000
Desktop FCP 558 ms548 ms -10 ms
Desktop LCP 1.06 s1.05 s
Desktop TBT 0 ms0 ms
Desktop CLS 0.0000.000
TTFB 341 ms332 ms -9 ms
DNS 37 ms39 ms +3 ms
TLS 28 ms22 ms -6 ms
Connect 16 ms17 ms +0 ms
Total 357 ms458 ms +101 ms

† Timing metrics may vary by worker location and do not necessarily indicate site changes.

WARNING https://costdown.org/: 373ms CPU time performance
WARNING https://costdown.org/_next/static/chunks/1255-fc6c...: 263ms CPU time performance
WARNING 1 render-blocking <script src> tag(s) without async/defer performance
WARNING Cross-Origin-Opener-Policy header is missing security
WARNING No Permissions-Policy header security
WARNING Permissions-Policy header not set -- features default to allow-on-same-origin security
WARNING https://costdown.org/: 254ms CPU time performance
WARNING Permissions-Policy header is missing security
CRITICAL Both www and non-www versions serve content infrastructure
WARNING No SPF record found security
WARNING Registrar lock is NOT enabled infrastructure
WARNING Cross-Origin-Embedder-Policy header is missing security
WARNING Skip navigation link is missing (WCAG 2.4.1) accessibility
WARNING No accessibility statement detected compliance
WARNING 1 images significantly larger than display size content
WARNING All 1 images use legacy formats (JPEG/PNG/GIF) content
WARNING X-Powered-By header reveals technology stack security
WARNING No DMARC record found security
+ cross-origin-opener-policy same-origin
+ permissions-policy accelerometer=(), autoplay=(), browsing-topics=(), camera=(), display-capture...
content-security-policy
default-src 'self'; script-src 'self' 'nonce-qahhE5l5vHRP+Ponwit1aw==' https:... default-src 'self'; script-src 'self' 'nonce-KaLZNAgMuQ5N2C5RGOXh5A==' https:...
link
</_next/static/media/62c97acc3aa63787-s.p.woff2>; rel=preload; as="font"; cro... </_next/static/media/62c97acc3aa63787-s.p.woff2>; rel=preload; as="font"; cro...

13 headers unchanged

Technology stack unchanged

11 technologies unchanged

Looking ahead

+5 pts
A (93) Could reach A+ (98)
Infrastructure +10Content +8Security +7Accessibility +4Compliance +4Performance +3

Estimate — actual results may vary (13 issues to fix)

Website improvement report — Costdown

August 27, 2026 → August 27, 2026

A A 91 → 93 +2 pts

5

Resolved

3

New issues

10

Still remaining

Financial summary

Investment delivered

₫750,000 in development time

Investment remaining

₫6,150,000 to complete the remaining items

Ongoing risk

₫3,361/month in ongoing exposure

Figures are estimates based on local developer hourly rate, industry CPC, and regulatory fine ranges.

Performance by category

MetricBeforeAfterChange
Overall score91 (A)93 (A)+2
Performance97 (A+)97 (A+)0
Security89 (B)93 (A)+4
Accessibility90 (A)90 (A)0
SEO95 (A)97 (A+)+2
Infrastructure88 (B)90 (A)+2
Compliance85 (B)85 (B)0
Content85 (B)85 (B)0
Sustainability98 (A+)98 (A+)0

Resolved (5)

  • Cross-Origin-Opener-Policy header is missing (Security)

    → Reduced attack surface for visitors

  • No Permissions-Policy header (Security)

    → Reduced attack surface for visitors

  • Permissions-Policy header not set -- features default to allow-on-same-origin (Security)

    → Reduced attack surface for visitors

  • https://costdown.org/: 254ms CPU time (Performance)

    → Page loads faster for users

  • Permissions-Policy header is missing (Security)

    → Reduced attack surface for visitors

Recommended next steps (13)

  • Sprint 1

    Both www and non-www versions serve content (Infrastructure)

  • Sprint 1

    https://costdown.org/: 373ms CPU time (Performance)

  • Sprint 1

    https://costdown.org/_next/static/chunks/1255-fc6c...: 263ms CPU time (Performance)

  • Sprint 2

    1 render-blocking <script src> tag(s) without async/defer (Performance)

  • Sprint 1

    No SPF record found (Security)

  • Sprint 1

    Registrar lock is NOT enabled (Infrastructure)

  • Sprint 2

    Cross-Origin-Embedder-Policy header is missing (Security)

  • Sprint 1

    Skip navigation link is missing (WCAG 2.4.1) (Accessibility)

  • Sprint 1

    No accessibility statement detected (Compliance)

  • Sprint 2

    1 images significantly larger than display size (Content)

  • Sprint 2

    All 1 images use legacy formats (JPEG/PNG/GIF) (Content)

  • Sprint 1

    X-Powered-By header reveals technology stack (Security)

  • Sprint 2

    No DMARC record found (Security)

Send Feedback