Skip to content

Changes

https://costdown.org
Compared to previous audit · 20 hours ago View previous audit

Singapore, Singapore Madrid, Spain

These audits ran from different locations. Timing metrics (TTFB, DNS, TLS) may reflect network path differences rather than site changes.

4
New issues
2
Resolved
17
score changes
CategoryPreviousCurrentChange
CompositeA (93)A (94) +1.000
PerformanceA+ (97)A+ (97)
SecurityA (96)A (96)
AccessibilityA (90)A (91) +1.000
SEOA (96)A+ (97) +1.000
InfrastructureA (90)A (90)
ComplianceC (74)B (85) +11.000
ContentA (95)A (95)
SustainabilityA+ (98)A+ (98)
MetricPreviousCurrentChange
Performance 94006500 -2900
Accessibility 96009600
Best Practices 1000010000
SEO 91009100
PWA 00
Desktop Performance 99009800 -100
Desktop Accessibility 96009600
Desktop Best Practices 1000010000
Desktop SEO 92009200
FCP 1.45 s3.12 s +1.67 s
LCP 2.95 s5.38 s +2.43 s
TBT 96 ms213 ms +116 ms
CLS 0.0000.000
Desktop FCP 559 ms655 ms +96 ms
Desktop LCP 905 ms1.04 s +139 ms
Desktop TBT 0 ms0 ms +0 ms
Desktop CLS 0.0000.000
TTFB 583 ms904 ms +321 ms
DNS 35 ms29 ms -6 ms
TLS 22 ms9 ms -14 ms
Connect 17 ms1 ms -16 ms
Total 640 ms1.23 s +591 ms

† Timing metrics may vary by worker location and do not necessarily indicate site changes.

WARNING https://costdown.org/_next/static/chunks/1255-fc6c...: 499ms CPU time performance
WARNING https://costdown.org/: 661ms CPU time performance
WARNING Unattributable: 343ms CPU time performance
WARNING 1 render-blocking <script src> tag(s) without async/defer performance
WARNING Skip navigation link is missing (WCAG 2.4.1) accessibility
WARNING https://costdown.org/: 435ms CPU time performance
CRITICAL Both www and non-www versions serve content infrastructure
WARNING No accessibility statement detected compliance
WARNING 1 images significantly larger than display size content
WARNING All 1 images use legacy formats (JPEG/PNG/GIF) content
WARNING Cross-Origin-Embedder-Policy header is missing security
WARNING X-Powered-By header reveals technology stack security
WARNING Registrar lock is NOT enabled infrastructure
WARNING DMARC policy is none — monitoring only security
content-security-policy
default-src 'self'; script-src 'self' 'nonce-1spJL18jX1n4AsY1iRAFhA==' https:... default-src 'self'; script-src 'self' 'nonce-UtpSYoROwjDrWReL7FS/bQ==' https:...
x-middleware-rewrite
/vi /en
link
</_next/static/media/62c97acc3aa63787-s.p.woff2>; rel=preload; as="font"; cro... </_next/static/media/62c97acc3aa63787-s.p.woff2>; rel=preload; as="font"; cro...

14 headers unchanged

Technology stack unchanged

12 technologies unchanged

Looking ahead

+3 pts
A (94) Could reach A+ (97)
Infrastructure +10Content +5Compliance +4Security +4Performance +3

Estimate — actual results may vary (12 issues to fix)

Website improvement report — Costdown

September 4, 2026 → September 5, 2026

A A 93 → 94 +1 pts

2

Resolved

4

New issues

8

Still remaining

Financial summary

Investment delivered

€43 in development time

Investment remaining

€744 to complete the remaining items

Ongoing risk

€0/month in ongoing exposure

Figures are estimates based on local developer hourly rate, industry CPC, and regulatory fine ranges.

Performance by category

MetricBeforeAfterChange
Overall score93 (A)94 (A)+1
Performance97 (A+)97 (A+)0
Security96 (A)96 (A)0
Accessibility90 (A)91 (A)+1
SEO96 (A)97 (A+)+1
Infrastructure90 (A)90 (A)0
Compliance74 (C)85 (B)+11
Content95 (A)95 (A)0
Sustainability98 (A+)98 (A+)0

Resolved (2)

  • Skip navigation link is missing (WCAG 2.4.1) (Accessibility)

    → Improved usability for assistive technology users

  • https://costdown.org/: 435ms CPU time (Performance)

    → Page loads faster for users

Recommended next steps (12)

  • Sprint 1

    Both www and non-www versions serve content (Infrastructure)

  • Sprint 1

    https://costdown.org/_next/static/chunks/1255-fc6c...: 499ms CPU time (Performance)

  • Sprint 1

    https://costdown.org/: 661ms CPU time (Performance)

  • Sprint 1

    Unattributable: 343ms CPU time (Performance)

  • Sprint 2

    1 render-blocking <script src> tag(s) without async/defer (Performance)

  • Sprint 1

    No accessibility statement detected (Compliance)

  • Sprint 2

    1 images significantly larger than display size (Content)

  • Sprint 2

    All 1 images use legacy formats (JPEG/PNG/GIF) (Content)

  • Sprint 2

    Cross-Origin-Embedder-Policy header is missing (Security)

  • Sprint 1

    X-Powered-By header reveals technology stack (Security)

  • Sprint 1

    Registrar lock is NOT enabled (Infrastructure)

  • Sprint 1

    DMARC policy is none — monitoring only (Security)

Send Feedback