Skip to content

Changes

https://costdown.org
Compared to previous audit · 4 hours ago View previous audit

Madrid, Spain Sao Paulo, Brazil

These audits ran from different locations. Timing metrics (TTFB, DNS, TLS) may reflect network path differences rather than site changes.

2
New issues
4
Resolved
13
score changes
CategoryPreviousCurrentChange
CompositeA (94)A (94)
PerformanceA+ (97)A+ (97)
SecurityA (96)A (96)
AccessibilityA (91)A (91)
SEOA+ (97)A+ (97)
InfrastructureB (87)A (90) +3.000
ComplianceB (85)B (85)
ContentA (95)A (95)
SustainabilityA+ (98)A+ (98)
MetricPreviousCurrentChange
Performance 82009500 +1300
Accessibility 96009600
Best Practices 1000010000
SEO 91009100
PWA 00
Desktop Performance 99009900
Desktop Accessibility 96009600
Desktop Best Practices 1000010000
Desktop SEO 92009200
FCP 2.65 s1.23 s -1.41 s
LCP 3.98 s2.90 s -1.08 s
TBT 116 ms32 ms -84 ms
CLS 0.0000.000
Desktop FCP 646 ms561 ms -85 ms
Desktop LCP 964 ms901 ms -63 ms
Desktop TBT 7 ms0 ms -7 ms
Desktop CLS 0.0000.000
TTFB 926 ms888 ms -38 ms
DNS 117 ms35 ms -82 ms
TLS 12 ms24 ms +12 ms
Connect 1 ms17 ms +15 ms
Total 1.17 s1.04 s -129 ms

† Timing metrics may vary by worker location and do not necessarily indicate site changes.

WARNING 1 render-blocking <script src> tag(s) without async/defer performance
WARNING https://costdown.org/: 340ms CPU time performance
WARNING https://costdown.org/: 700ms CPU time performance
WARNING Unattributable: 308ms CPU time performance
WARNING DNS resolution is slow (223 ms) infrastructure
WARNING https://costdown.org/_next/static/chunks/1255-fc6c...: 539ms CPU time performance
CRITICAL Both www and non-www versions serve content infrastructure
WARNING All 1 images use legacy formats (JPEG/PNG/GIF) content
WARNING Cross-Origin-Embedder-Policy header is missing security
WARNING DMARC policy is none — monitoring only security
WARNING Registrar lock is NOT enabled infrastructure
WARNING No accessibility statement detected compliance
WARNING 1 images significantly larger than display size content
content-security-policy
default-src 'self'; script-src 'self' 'nonce-kU1dY2Lsn1j1wcELSf6O1Q==' https:... default-src 'self'; script-src 'self' 'nonce-iUgfo/0CmqLzwl/+7aRkFg==' https:...
link
</_next/static/media/62c97acc3aa63787-s.p.woff2>; rel=preload; as="font"; cro... </_next/static/media/62c97acc3aa63787-s.p.woff2>; rel=preload; as="font"; cro...

14 headers unchanged

Technology stack unchanged

12 technologies unchanged

Looking ahead

+3 pts
A (94) Could reach A+ (97)
Infrastructure +10Content +5Compliance +4Security +4Performance +3

Estimate — actual results may vary (9 issues to fix)

Website improvement report — Costdown

September 5, 2026 → September 5, 2026

A A 94 → 94 0 pts

4

Resolved

2

New issues

7

Still remaining

Financial summary

Investment delivered

€170 in development time

Investment remaining

€730 to complete the remaining items

Ongoing risk

€0/month in ongoing exposure

Figures are estimates based on local developer hourly rate, industry CPC, and regulatory fine ranges.

Performance by category

MetricBeforeAfterChange
Overall score94 (A)94 (A)0
Performance97 (A+)97 (A+)0
Security96 (A)96 (A)0
Accessibility91 (A)91 (A)0
SEO97 (A+)97 (A+)0
Infrastructure87 (B)90 (A)+3
Compliance85 (B)85 (B)0
Content95 (A)95 (A)0
Sustainability98 (A+)98 (A+)0

Resolved (4)

  • https://costdown.org/: 700ms CPU time (Performance)

    → Page loads faster for users

  • Unattributable: 308ms CPU time (Performance)

    → Page loads faster for users

  • DNS resolution is slow (223 ms) (Infrastructure)

    → More reliable delivery

  • https://costdown.org/_next/static/chunks/1255-fc6c...: 539ms CPU time (Performance)

    → Page loads faster for users

Recommended next steps (9)

  • Sprint 1

    Both www and non-www versions serve content (Infrastructure)

  • Sprint 2

    1 render-blocking <script src> tag(s) without async/defer (Performance)

  • Sprint 1

    https://costdown.org/: 340ms CPU time (Performance)

  • Sprint 2

    All 1 images use legacy formats (JPEG/PNG/GIF) (Content)

  • Sprint 2

    Cross-Origin-Embedder-Policy header is missing (Security)

  • Sprint 1

    DMARC policy is none — monitoring only (Security)

  • Sprint 1

    Registrar lock is NOT enabled (Infrastructure)

  • Sprint 1

    No accessibility statement detected (Compliance)

  • Sprint 2

    1 images significantly larger than display size (Content)

Send Feedback