Skip to content

Changes

https://xpenv.com
Compared to previous audit · 14 hours ago View previous audit
3
New issues
3
Resolved
11
score changes
CategoryPreviousCurrentChange
CompositeB (88)B (89) +1.000
PerformanceA (94)A (94)
SecurityB (86)B (86)
AccessibilityB (83)B (83)
SEOA+ (97)A+ (97)
InfrastructureA (91)A (94) +3.000
ComplianceD (69)D (69)
ContentA+ (99)A+ (99)
SustainabilityB (88)B (88)
MetricPreviousCurrentChange
Performance 69007000 +100
Accessibility 96009600
Best Practices 73007300
SEO 1000010000
PWA 00
Desktop Performance 99009900
Desktop Accessibility 1000010000
Desktop Best Practices 73007300
Desktop SEO 1000010000
FCP 3.32 s3.32 s
LCP 3.77 s3.77 s
TBT 504 ms466 ms -38 ms
CLS 0.0410.041
Desktop FCP 684 ms695 ms +11 ms
Desktop LCP 983 ms986 ms
Desktop TBT 50 ms60 ms +10 ms
Desktop CLS 0.0030.003
TTFB 259 ms27 ms -232 ms
DNS 12 ms3 ms -10 ms
TLS 10 ms7 ms -3 ms
Connect 2 ms1 ms -0 ms
Total 260 ms28 ms -232 ms

† Timing metrics may vary by worker location and do not necessarily indicate site changes.

WARNING https://xpenv.com/assets/index-22d4mitO.js: 715ms CPU time performance
WARNING https://xpenv.com/: 253ms CPU time performance
WARNING Unattributable: 442ms CPU time performance
WARNING https://xpenv.com/assets/index-22d4mitO.js: 739ms CPU time performance
WARNING https://xpenv.com/: 284ms CPU time performance
WARNING Unattributable: 420ms CPU time performance
CRITICAL No Content-Security-Policy header found security
CRITICAL No H1 heading found accessibility
CRITICAL Transfer efficiency: 41% sustainability
CRITICAL Content-Security-Policy header is missing security
WARNING Cross-Origin-Opener-Policy header is missing security
WARNING Bare server default 404 page accessibility
WARNING No privacy policy link detected compliance
WARNING No accessibility statement detected compliance
WARNING HSTS max-age is too short (15552000s, should be ≥ 31536000s) security
WARNING X-Frame-Options header is missing security
WARNING Login form does not contain a recognizable CSRF token security
WARNING https://xpenv.com/assets/index-22d4mitO.js: 259 KB unused (64%) performance
WARNING Main HTML cached for 1440 minutes -- risks stale auth / SPA state performance
WARNING Referrer-Policy header is missing security
WARNING Permissions-Policy header is missing security
WARNING 3 field(s) would benefit from inputmode attribute accessibility
WARNING <iframe> missing title attribute (src="") accessibility
WARNING https://xpenv.com/cdn-cgi/challenge-platform/scrip...: 400ms CPU time performance
WARNING GDPR Article 13 disclosure coverage: 0 / 8 categories compliance
WARNING Cross-Origin-Embedder-Policy header is missing security
WARNING Permissions-Policy header not set -- features default to allow-on-same-origin security
WARNING No Permissions-Policy header security
WARNING 3 field(s) missing recommended autocomplete attribute accessibility
WARNING Registrar lock is NOT enabled infrastructure
cf-cache-status
EXPIRED HIT

17 headers unchanged

Technology stack unchanged

8 technologies unchanged

Looking ahead

+9 pts
B (89) Could reach A+ (98)
Accessibility +17Security +14Compliance +10Sustainability +10Performance +6Infrastructure +4

Estimate — actual results may vary (27 issues to fix)

Website improvement report — Xpenv

May 26, 2026 → May 26, 2026

B B 88 → 89 +1 pts

3

Resolved

3

New issues

24

Still remaining

Financial summary

Investment remaining

€2,203 to complete the remaining items

Ongoing risk

€0/month in ongoing exposure

Figures are estimates based on local developer hourly rate, industry CPC, and regulatory fine ranges.

Performance by category

MetricBeforeAfterChange
Overall score88 (B)89 (B)+1
Performance94 (A)94 (A)0
Security86 (B)86 (B)0
Accessibility83 (B)83 (B)0
SEO97 (A+)97 (A+)0
Infrastructure91 (A)94 (A)+3
Compliance69 (D)69 (D)0
Content99 (A+)99 (A+)0
Sustainability88 (B)88 (B)0

Resolved (3)

  • https://xpenv.com/assets/index-22d4mitO.js: 739ms CPU time (Performance)

    → Page loads faster for users

  • https://xpenv.com/: 284ms CPU time (Performance)

    → Page loads faster for users

  • Unattributable: 420ms CPU time (Performance)

    → Page loads faster for users

Recommended next steps (27)

  • Sprint 2

    No Content-Security-Policy header found (Security)

  • Sprint 1

    No H1 heading found (Accessibility)

  • Sprint 1

    Transfer efficiency: 41% (Sustainability)

  • Sprint 2

    Content-Security-Policy header is missing (Security)

  • Sprint 1

    https://xpenv.com/assets/index-22d4mitO.js: 715ms CPU time (Performance)

  • Sprint 1

    https://xpenv.com/: 253ms CPU time (Performance)

  • Sprint 1

    Unattributable: 442ms CPU time (Performance)

  • Sprint 1

    Cross-Origin-Opener-Policy header is missing (Security)

  • Sprint 1

    Bare server default 404 page (Accessibility)

  • Sprint 2

    No privacy policy link detected (Compliance)

  • Sprint 1

    No accessibility statement detected (Compliance)

  • Sprint 1

    HSTS max-age is too short (15552000s, should be ≥ 31536000s) (Security)

  • Sprint 1

    X-Frame-Options header is missing (Security)

  • Sprint 1

    Login form does not contain a recognizable CSRF token (Security)

  • Sprint 3

    https://xpenv.com/assets/index-22d4mitO.js: 259 KB unused (64%) (Performance)

…and 12 more recommended item(s)

Send Feedback