Changes
Sao Paulo, Brazil → Madrid, Spain
These audits ran from different locations. Timing metrics (TTFB, DNS, TLS) may reflect network path differences rather than site changes.
| Category | Previous | Current | Change |
|---|---|---|---|
| Composite | B (82) | B (84) | +2.000 |
| Performance | A (92) | A (93) | +1.000 |
| Security | C (75) | B (88) | +13.000 |
| Accessibility | C (79) | C (75) | -4.000 |
| SEO | B (81) | A (90) | +9.000 |
| Infrastructure | B (87) | C (79) | -8.000 |
| Compliance | C (70) | D (63) | -7.000 |
| Content | C (73) | D (69) | -4.000 |
| Sustainability | A+ (98) | A+ (100) | +2.000 |
| Metric | Previous | Current | Change |
|---|---|---|---|
| Performance | 9000 | 8800 | -200 |
| Accessibility | 9700 | 9700 | — |
| Best Practices | 7700 | 9200 | +1500 |
| SEO | 9200 | 9200 | — |
| PWA | 0 | 0 | — |
| Desktop Performance | 9800 | 9900 | +100 |
| Desktop Accessibility | 9700 | 9700 | — |
| Desktop Best Practices | 7700 | 9200 | +1500 |
| Desktop SEO | 9200 | 9200 | — |
| FCP | 2.86 s | 2.90 s | +40 ms |
| LCP | 2.86 s | 3.05 s | +190 ms |
| TBT | 0 ms | 0 ms | — |
| CLS | 0.006 | 0.005 | -0.000 |
| Desktop FCP | 934 ms | 838 ms | -96 ms |
| Desktop LCP | 934 ms | 838 ms | -96 ms |
| Desktop TBT | 0 ms | 0 ms | — |
| Desktop CLS | 0.035 | 0.027 | -0.008 |
| TTFB † | 121 ms | 74 ms | -47 ms |
| DNS † | 39 ms | 13 ms | -25 ms |
| TLS † | 26 ms | 19 ms | -7 ms |
| Connect † | 17 ms | 2 ms | -15 ms |
| Total † | 121 ms | 74 ms | -47 ms |
† Timing metrics may vary by worker location and do not necessarily indicate site changes.
x-content-type-options nosniffpermissions-policy geolocation=(self), camera=(), microphone=(), payment=()referrer-policy strict-origin-when-cross-originstrict-transport-security max-age=31536000; includeSubDomains; preloadcontent-security-policy default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline' https...x-frame-options DENY6 headers unchanged
2 technologies unchanged
Looking ahead
+13 ptsEstimate — actual results may vary (44 issues to fix)
Website improvement report — Letseat.charlietheturtle
September 3, 2026 → September 3, 2026
26
Resolved
26
New issues
18
Still remaining
Financial summary
Investment delivered
€3,067 in development time
Investment remaining
€2,855 to complete the remaining items
Ongoing risk
€0/month in ongoing exposure
Figures are estimates based on local developer hourly rate, industry CPC, and regulatory fine ranges.
Performance by category
| Metric | Before | After | Change |
|---|---|---|---|
| Overall score | 82 (B) | 84 (B) | +2 |
| Performance | 92 (A) | 93 (A) | +1 |
| Security | 75 (C) | 88 (B) | +13 |
| Accessibility | 79 (C) | 75 (C) | -4 |
| SEO | 81 (B) | 90 (A) | +9 |
| Infrastructure | 87 (B) | 79 (C) | -8 |
| Compliance | 70 (C) | 63 (D) | -7 |
| Content | 73 (C) | 69 (D) | -4 |
| Sustainability | 98 (A+) | 100 (A+) | +2 |
Resolved (26)
3 third-party resources (67% of weight) (Performance)
→ Page loads faster for users
HSTS header is missing (Security)
→ Reduced attack surface for visitors
Scan returned a Cloudflare bot-protection interstitial, not the actual page (Security)
→ Reduced attack surface for visitors
https://letseat.charlietheturtle.com/: 1789ms CPU time (Performance)
→ Page loads faster for users
X-Frame-Options header is missing (Security)
→ Reduced attack surface for visitors
Content-Security-Policy header is missing (Security)
→ Reduced attack surface for visitors
No Content-Security-Policy header found (Security)
→ Reduced attack surface for visitors
SRI adoption: 0/1 third-party resources protected (0%) (Security)
→ Reduced attack surface for visitors
No Permissions-Policy header (Security)
→ Reduced attack surface for visitors
X-Content-Type-Options header is missing (Security)
→ Reduced attack surface for visitors
2 link(s) open in new tab without warning (Accessibility)
→ Improved usability for assistive technology users
Third-party code accounts for 67% of page weight (88.8 KiB of 133.2 KiB) (Performance)
→ Page loads faster for users
Title is only 16 characters — consider expanding (SEO)
→ Better search engine visibility
Page has only 47 words — nearly empty (SEO)
→ Better search engine visibility
Permissions-Policy header not set -- features default to allow-on-same-origin (Security)
→ Reduced attack surface for visitors
…and 11 more resolved issue(s)
Recommended next steps (44)
- Sprint 1
Broken link: https://www.banglawok.com/ (Content)
- Sprint 1
Broken link: http://www.duffswings.com/ (Content)
- Sprint 1
191 of 200 links are healthy (Content)
- Sprint 1
Broken link: https://breadhive.coop (Content)
- Sprint 1
Broken link: https://amysplacebuffalo.com/ (Content)
- Sprint 1
Broken link: https://www.akis-restaurant.com/ (Content)
- Sprint 1
Broken link: https://cinnamonrestaurantsweets.com/ (Content)
- Sprint 1
No favicon or icon links detected (Accessibility)
- Sprint 1
HTTP version does not redirect to HTTPS (Infrastructure)
- Sprint 2
/.git/config is publicly accessible (Security)
- Sprint 1
External link from fonts.googleapis.com lacks integrity attribute (Security)
- Sprint 2
287 link(s) with generic text (Accessibility)
- Sprint 1
4 third-party resources (70% of weight) (Performance)
- Sprint 1
100% of images have non-descriptive filenames (SEO)
- Sprint 1
Privacy Policy not detected (Compliance)
…and 29 more recommended item(s)