Skip to content

Changes

https://svennouwen.nl
Compared to previous audit · 50 minutes ago View previous audit
12
New issues
14
Resolved
16
score changes
CategoryPreviousCurrentChange
CompositeB (85)B (86) +1.000
PerformanceB (87)B (87)—
SecurityC (78)B (85) +7.000
AccessibilityB (86)B (86)—
SEOA (94)A (94)—
InfrastructureA (95)A (95)—
ComplianceC (72)C (72)—
ContentB (82)B (82)—
SustainabilityB (88)B (88)—
MetricPreviousCurrentChange
Performance 78007700 -100
Accessibility 98009800—
Best Practices 100009200 -800
SEO 1000010000—
PWA 00—
Desktop Performance 99009700 -200
Desktop Accessibility 98009800—
Desktop Best Practices 100009200 -800
Desktop SEO 1000010000—
FCP 2.86 s2.88 s—
LCP 3.47 s3.46 s—
TBT 328 ms391 ms +64 ms
CLS 0.0490.049 -0.001
Desktop FCP 669 ms749 ms +80 ms
Desktop LCP 788 ms1.07 s +284 ms
Desktop TBT 10 ms79 ms +69 ms
Desktop CLS 0.0010.001—
TTFB †336 ms824 ms +488 ms
DNS †7 ms16 ms +8 ms
TLS †8 ms10 ms +2 ms
Connect †1 ms1 ms +0 ms
Total †337 ms826 ms +489 ms

† Timing metrics may vary by worker location and do not necessarily indicate site changes.

CRITICAL 'unsafe-inline' found in script source security
WARNING Permissions-Policy covers 3/10 high-risk features (30%) security
WARNING 12 render-blocking <script src> tag(s) without async/defer performance
WARNING 22 render-blocking stylesheet(s) -- recommended: <=3 performance
WARNING Registrar lock is NOT enabled infrastructure
WARNING https://svennouwen.nl/: 2170ms CPU time performance
WARNING https://svennouwen.nl/wp-includes/js/jquery/jquery...: 991ms CPU time performance
WARNING Unattributable: 483ms CPU time performance
WARNING https://svennouwen.nl/wp-content/plugins/jupiterx-...: 346ms CPU time performance
WARNING HSTS is enabled but missing includeSubDomains security
WARNING Total JS execution time is 4.3 s -- over the 3.5s budget performance
WARNING 60 of 61 links are healthy content
CRITICAL HSTS header is missing security
CRITICAL Content-Security-Policy header is missing security
WARNING Referrer-Policy header is missing security
WARNING https://svennouwen.nl/wp-content/plugins/jupiterx-...: 289ms CPU time performance
WARNING Cross-Origin-Opener-Policy header is missing security
WARNING Unattributable: 504ms CPU time performance
WARNING X-Content-Type-Options header is missing security
WARNING Permissions-Policy header is missing security
WARNING Cross-Origin-Embedder-Policy header is missing security
WARNING DMARC policy is none — monitoring only security
WARNING No Permissions-Policy header security
WARNING https://svennouwen.nl/: 2131ms CPU time performance
WARNING https://svennouwen.nl/wp-includes/js/jquery/jquery...: 995ms CPU time performance
WARNING 61 of 62 links are healthy content
WARNING Broken link: https://svennouwen.nl/xmlrpc.php?rsd content
WARNING Missing og:image content
WARNING 2 images significantly larger than display size content
WARNING 2 software version(s) disclosed in HTML: Elementor 4.3.2; features: e_font_icon_svg, additional_custom_breakpoints; settings: css_print_method-external, google_font-disabled, font_display-auto, WordPress 7.1.2 security
WARNING https://svennouwen.nl/wp-content/plugins/jupiterx-...: 163 KB unused (86%) performance
WARNING Transfer efficiency: 73% sustainability
WARNING SRI adoption: 0/1 third-party resources protected (0%) security
WARNING External link from fonts.bunny.net lacks integrity attribute security
WARNING Heading level skipped: H1 → H3 (missing H2) accessibility
WARNING No accessibility statement detected compliance
WARNING GDPR Article 13 disclosure coverage: 1 / 8 categories compliance
WARNING All 2 images use legacy formats (JPEG/PNG/GIF) content
WARNING X-Frame-Options header is missing security
WARNING https://svennouwen.nl/wp-content/themes/jupiterx/l...: 32 KB unused (84%) performance
+ strict-transport-security max-age=31536000
+ cross-origin-opener-policy same-origin
+ x-content-type-options nosniff
+ permissions-policy camera=(), microphone=(), geolocation=()
+ referrer-policy strict-origin-when-cross-origin
+ content-security-policy default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsa...
+ cross-origin-embedder-policy credentialless
content-length
18900 → 18898

5 headers unchanged

+ HSTS Security
− Twitter Emoji (Twemoji) Font scripts

20 technologies unchanged

Looking ahead

+10 pts
B (86) Could reach A (96)
Content +16Security +15Performance +13Compliance +8Accessibility +4Infrastructure +4Sustainability +4

Estimate — actual results may vary (26 issues to fix)

Website improvement report — Svennouwen

September 30, 2026 → September 30, 2026

B B 85 → 86 +1 pts

14

Resolved

12

New issues

14

Still remaining

Financial summary

Investment delivered

€489 in development time

Investment remaining

€3,039 to complete the remaining items

Ongoing risk

€0/month in ongoing exposure

Figures are estimates based on local developer hourly rate, industry CPC, and regulatory fine ranges.

Performance by category

MetricBeforeAfterChange
Overall score85 (B)86 (B)+1
Performance87 (B)87 (B)0
Security78 (C)85 (B)+7
Accessibility86 (B)86 (B)0
SEO94 (A)94 (A)0
Infrastructure95 (A)95 (A)0
Compliance72 (C)72 (C)0
Content82 (B)82 (B)0
Sustainability88 (B)88 (B)0

Resolved (14)

  • HSTS header is missing (Security)

    → Reduced attack surface for visitors

  • Referrer-Policy header is missing (Security)

    → Reduced attack surface for visitors

  • Content-Security-Policy header is missing (Security)

    → Reduced attack surface for visitors

  • https://svennouwen.nl/wp-content/plugins/jupiterx-...: 289ms CPU time (Performance)

    → Page loads faster for users

  • Cross-Origin-Opener-Policy header is missing (Security)

    → Reduced attack surface for visitors

  • Unattributable: 504ms CPU time (Performance)

    → Page loads faster for users

  • X-Content-Type-Options header is missing (Security)

    → Reduced attack surface for visitors

  • Permissions-Policy header is missing (Security)

    → Reduced attack surface for visitors

  • Cross-Origin-Embedder-Policy header is missing (Security)

    → Reduced attack surface for visitors

  • DMARC policy is none — monitoring only (Security)

    → Reduced attack surface for visitors

  • No Permissions-Policy header (Security)

    → Reduced attack surface for visitors

  • https://svennouwen.nl/: 2131ms CPU time (Performance)

    → Page loads faster for users

  • https://svennouwen.nl/wp-includes/js/jquery/jquery...: 995ms CPU time (Performance)

    → Page loads faster for users

  • 61 of 62 links are healthy (Content)

    → Stronger social sharing and on-page quality

Recommended next steps (26)

  • Sprint 3

    'unsafe-inline' found in script source (Security)

  • Sprint 1

    Permissions-Policy covers 3/10 high-risk features (30%) (Security)

  • Sprint 2

    12 render-blocking <script src> tag(s) without async/defer (Performance)

  • Sprint 1

    22 render-blocking stylesheet(s) -- recommended: <=3 (Performance)

  • Sprint 1

    Registrar lock is NOT enabled (Infrastructure)

  • Sprint 1

    https://svennouwen.nl/: 2170ms CPU time (Performance)

  • Sprint 1

    https://svennouwen.nl/wp-includes/js/jquery/jquery...: 991ms CPU time (Performance)

  • Sprint 1

    Unattributable: 483ms CPU time (Performance)

  • Sprint 1

    https://svennouwen.nl/wp-content/plugins/jupiterx-...: 346ms CPU time (Performance)

  • Sprint 1

    HSTS is enabled but missing includeSubDomains (Security)

  • Sprint 2

    Total JS execution time is 4.3 s -- over the 3.5s budget (Performance)

  • Sprint 1

    60 of 61 links are healthy (Content)

  • Sprint 1

    Broken link: https://svennouwen.nl/xmlrpc.php?rsd (Content)

  • Sprint 1

    Missing og:image (Content)

  • Sprint 2

    2 images significantly larger than display size (Content)

…and 11 more recommended item(s)

Send Feedback