Changes
| Category | Previous | Current | Change |
|---|---|---|---|
| Composite | B (85) | B (86) | +1.000 |
| Performance | B (87) | B (87) | — |
| Security | C (78) | B (85) | +7.000 |
| Accessibility | B (86) | B (86) | — |
| SEO | A (94) | A (94) | — |
| Infrastructure | A (95) | A (95) | — |
| Compliance | C (72) | C (72) | — |
| Content | B (82) | B (82) | — |
| Sustainability | B (88) | B (88) | — |
| Metric | Previous | Current | Change |
|---|---|---|---|
| Performance | 7800 | 7700 | -100 |
| Accessibility | 9800 | 9800 | — |
| Best Practices | 10000 | 9200 | -800 |
| SEO | 10000 | 10000 | — |
| PWA | 0 | 0 | — |
| Desktop Performance | 9900 | 9700 | -200 |
| Desktop Accessibility | 9800 | 9800 | — |
| Desktop Best Practices | 10000 | 9200 | -800 |
| Desktop SEO | 10000 | 10000 | — |
| FCP | 2.86 s | 2.88 s | — |
| LCP | 3.47 s | 3.46 s | — |
| TBT | 328 ms | 391 ms | +64 ms |
| CLS | 0.049 | 0.049 | -0.001 |
| Desktop FCP | 669 ms | 749 ms | +80 ms |
| Desktop LCP | 788 ms | 1.07 s | +284 ms |
| Desktop TBT | 10 ms | 79 ms | +69 ms |
| Desktop CLS | 0.001 | 0.001 | — |
| TTFB † | 336 ms | 824 ms | +488 ms |
| DNS † | 7 ms | 16 ms | +8 ms |
| TLS † | 8 ms | 10 ms | +2 ms |
| Connect † | 1 ms | 1 ms | +0 ms |
| Total † | 337 ms | 826 ms | +489 ms |
† Timing metrics may vary by worker location and do not necessarily indicate site changes.
strict-transport-security max-age=31536000cross-origin-opener-policy same-originx-content-type-options nosniffpermissions-policy camera=(), microphone=(), geolocation=()referrer-policy strict-origin-when-cross-origincontent-security-policy default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsa...cross-origin-embedder-policy credentiallesscontent-length 18900 → 188985 headers unchanged
20 technologies unchanged
Looking ahead
+10 ptsEstimate — actual results may vary (26 issues to fix)
Website improvement report — Svennouwen
September 30, 2026 → September 30, 2026
14
Resolved
12
New issues
14
Still remaining
Financial summary
Investment delivered
€489 in development time
Investment remaining
€3,039 to complete the remaining items
Ongoing risk
€0/month in ongoing exposure
Figures are estimates based on local developer hourly rate, industry CPC, and regulatory fine ranges.
Performance by category
| Metric | Before | After | Change |
|---|---|---|---|
| Overall score | 85 (B) | 86 (B) | +1 |
| Performance | 87 (B) | 87 (B) | 0 |
| Security | 78 (C) | 85 (B) | +7 |
| Accessibility | 86 (B) | 86 (B) | 0 |
| SEO | 94 (A) | 94 (A) | 0 |
| Infrastructure | 95 (A) | 95 (A) | 0 |
| Compliance | 72 (C) | 72 (C) | 0 |
| Content | 82 (B) | 82 (B) | 0 |
| Sustainability | 88 (B) | 88 (B) | 0 |
Resolved (14)
HSTS header is missing (Security)
→ Reduced attack surface for visitors
Referrer-Policy header is missing (Security)
→ Reduced attack surface for visitors
Content-Security-Policy header is missing (Security)
→ Reduced attack surface for visitors
https://svennouwen.nl/wp-content/plugins/jupiterx-...: 289ms CPU time (Performance)
→ Page loads faster for users
Cross-Origin-Opener-Policy header is missing (Security)
→ Reduced attack surface for visitors
Unattributable: 504ms CPU time (Performance)
→ Page loads faster for users
X-Content-Type-Options header is missing (Security)
→ Reduced attack surface for visitors
Permissions-Policy header is missing (Security)
→ Reduced attack surface for visitors
Cross-Origin-Embedder-Policy header is missing (Security)
→ Reduced attack surface for visitors
DMARC policy is none — monitoring only (Security)
→ Reduced attack surface for visitors
No Permissions-Policy header (Security)
→ Reduced attack surface for visitors
https://svennouwen.nl/: 2131ms CPU time (Performance)
→ Page loads faster for users
https://svennouwen.nl/wp-includes/js/jquery/jquery...: 995ms CPU time (Performance)
→ Page loads faster for users
61 of 62 links are healthy (Content)
→ Stronger social sharing and on-page quality
Recommended next steps (26)
- Sprint 3
'unsafe-inline' found in script source (Security)
- Sprint 1
Permissions-Policy covers 3/10 high-risk features (30%) (Security)
- Sprint 2
12 render-blocking <script src> tag(s) without async/defer (Performance)
- Sprint 1
22 render-blocking stylesheet(s) -- recommended: <=3 (Performance)
- Sprint 1
Registrar lock is NOT enabled (Infrastructure)
- Sprint 1
https://svennouwen.nl/: 2170ms CPU time (Performance)
- Sprint 1
https://svennouwen.nl/wp-includes/js/jquery/jquery...: 991ms CPU time (Performance)
- Sprint 1
Unattributable: 483ms CPU time (Performance)
- Sprint 1
https://svennouwen.nl/wp-content/plugins/jupiterx-...: 346ms CPU time (Performance)
- Sprint 1
HSTS is enabled but missing includeSubDomains (Security)
- Sprint 2
Total JS execution time is 4.3 s -- over the 3.5s budget (Performance)
- Sprint 1
60 of 61 links are healthy (Content)
- Sprint 1
Broken link: https://svennouwen.nl/xmlrpc.php?rsd (Content)
- Sprint 1
Missing og:image (Content)
- Sprint 2
2 images significantly larger than display size (Content)
…and 11 more recommended item(s)