Adding a Cache-Control header can significantly improve repeat-visit performance.
B
HTTP/3 (QUIC)
HTTP/3 not advertised
REVIEW
HTTP/3 not advertised
Info::
i
HTTP/3 (QUIC) is not advertised
HTTP/3 isn't advertised via Alt-Svc and the worker didn't negotiate h3. HTTP/3 reduces handshake latency (1-RTT instead of 2-3 RTTs) and is more resilient on lossy connections. Most modern CDNs (Cloudflare, Fastly, AWS CloudFront, Google Cloud CDN) support HTTP/3 with a single config switch -- consider enabling for mobile-heavy workloads.
C
Document Compression
Action
Document response served uncompressed
REVIEW
Document response served uncompressed
Info::
i
Main HTML response has no Content-Encoding (uncompressed)
The main HTML document is served without compression. The Text Compression section above lists the broader picture; for the main response specifically, even gzip would shave ~70-80% off most text payloads.
B
Main HTML Cache-Control
No Cache-Control header on main HTML response
REVIEW
No Cache-Control header on main HTML response
Info::
i
Main HTML response has no Cache-Control header
Without an explicit Cache-Control, browsers fall back to heuristic caching (~10% of Last-Modified age). Set `Cache-Control: no-cache` or `max-age=300` for HTML to control freshness explicitly -- prevents stale auth state and SPA shell drift.
B
Server-Timing Observability
No Server-Timing header found
REVIEW
No Server-Timing header found
Info::
i
No Server-Timing header found
Server-Timing exposes backend timing breakdowns to browser DevTools (e.g., `db: 45ms; render: 120ms; cache: 2ms`). Useful for diagnosing slow pages without backend log access. Most modern frameworks (Next.js, Cloudflare Workers, Fastly) emit it automatically; absence on a managed platform usually means telemetry headers are stripped at the edge.
C
Green Hosting
Action
Whether the site is served from green-energy infrastructure
REVIEW
Green Hosting
No green hosting detected
A
Third-Party Impact
38% third-party, 0 ms blocking
PASS
38% third-party, 0 ms blocking
Info::
i
Third-party code accounts for 38% of page weight (1.1 MiB of 3.0 MiB)
Info::
✓
Third-party blocking time is low (0 ms)
62%
38%
First-party Third-party
A+
Text Compression
All text resources are compressed
PASS
All text resources are compressed
Info::
✓
All text resources are compressed
All text resources are properly compressed.
A+
Image Optimization
4 images, 0 KB saveable
PASS
4 images, 0 KB saveable
Info::
✓
All images are well-optimized
4images30 KB
0oversized-0 KB
0legacy format
0missing dimensionsCLS risk
A+
JS Execution Cost
403ms total JS execution
PASS
403ms total JS execution
Info::
i
Unattributable: 99ms CPU time
Info::
i
https://loremipsum.io/: 64ms CPU time
Info::
i
https://loremipsum.io/_next/static/chunks/4bd1b696...: 62ms CPU time
Info::
i
https://securepubads.g.doubleclick.net/pagead/mana...: 60ms CPU time
Info::
i
https://www.googletagmanager.com/gtag/js?id=G-KXPK...: 59ms CPU time
4 font(s) use font-display: swap (FOUT risk but functional)
Web fonts
4
280 KB total
Render-blocking
0
of 4
Dominant font-display
swap
Most common across fonts
Font loading timeline
TransferFOIT (block)FOUT (swap)
5d39360912ab897b-s.p.woff2woff2swap
Size67 KB
Load time42 ms
Start62 ms
RiskFOUT — text flashes from fallback to web font
acc997c86979663b-s.p.woff2woff2swap
Size70 KB
Load time36 ms
Start62 ms
RiskFOUT — text flashes from fallback to web font
cb8d34571a43f897-s.p.woff2woff2swap
Size70 KB
Load time48 ms
Start63 ms
RiskFOUT — text flashes from fallback to web font
f7a9b128ae841a36-s.p.woff2woff2swap
Size73 KB
Load time55 ms
Start63 ms
RiskFOUT — text flashes from fallback to web font
Optimization checklist
Preload critical fonts (priority=high)
Use woff2 format for all fonts
Set font-display to swap, optional, or fallback
Subset large fonts (≤100 KB each)
A+
Resource Caching
All resources properly cached
PASS
All resources properly cached
Info::
✓
No caching issues found
All static resources have appropriate caching headers.
A+
Critical Rendering Path
No render-blocking resources
PASS
No render-blocking resources
Info::
✓
No render-blocking resources detected
A+
Resource Hints
No optimization needed
PASS
No optimization needed
Info::
✓
No resource hint issues
A+
Asset Compression
All 2 asset hosts use brotli
PASS
All 2 asset hosts use brotli
Info::
✓
a.pub.network serves assets with brotli (assets: 4)
Got: a.pub.network (application/javascript)
Info::
✓
cdn.privacy-mgmt.com serves assets with brotli (assets: 3)
Got: cdn.privacy-mgmt.com (text/javascript)
A+
LCP Image Preload
LCP preload audit not available
PASS
LCP preload audit not available
Info::
✓
LCP image preload audit not available for this scan
A+
Server Response Intelligence
1 server-response signal(s) detected
PASS
1 server-response signal(s) detected
Info::
✓
Both `ETag` and `Last-Modified` present -- efficient revalidation supported
The page returns both `ETag` (content hash) and `Last-Modified` (timestamp) headers. Browsers can issue conditional GETs with `If-None-Match` or `If-Modified-Since`; the server returns 304 Not Modified for unchanged content, saving bandwidth. ETag is the more reliable of the two (timestamps fail in DST transitions and clock skew).
Network Waterfall
68 requests over 2476ms
INFO
HTML JavaScript CSS Images Fonts XHR/Fetch Other
Third-Party Script Cost
Per-script blocking time, transfer cost, and cache headers
INFO
44%of JavaScript execution is third-party
First-party Third-party177ms · 570KB · $2/mo
Script
Category
Execution
Transfer
Unused
Monthly Cost
Verdict
securepubads.g.doubleclick.net
securepubads.g.doubleclick.net
Other
60ms
212 KB
76%
$1/mo
Optional
Google Tag Manager
www.googletagmanager.com
Tag Manager
59ms
164 KB
43%
$1/mo
Optional
a.pub.network
a.pub.network
Other
59ms
194 KB
80%
$1/mo
Optional
securepubads.g.doubleclick.net
Other
Optional
Execution60ms
Transfer212 KB
Unused76%
Monthly Cost$1/mo
Google Tag Manager
Tag Manager
Optional
Execution59ms
Transfer164 KB
Unused43%
Monthly Cost$1/mo
a.pub.network
Other
Optional
Execution59ms
Transfer194 KB
Unused80%
Monthly Cost$1/mo
44% of JavaScript execution time comes from third-party scripts.
Why this matters
Third-party scripts (analytics, ads, social, A/B testing) often dominate execution time — every one is a perf-and-privacy tax.
Learn more ▾▴
Each third-party script is a black box: you don't control when it loads, what it executes, or how much it grows. They often account for a major share of total blocking time on average sites (HTTP Archive's Web Almanac documents the trend). Audit which ones you actually need, defer the rest, and use facade patterns (lite-youtube, lite-vimeo) for embedded media.
Source: web.dev / HTTP Archive Web Almanac
76% of securepubads.g.doubleclick.net's code is unused. The script may be loading features you don't use.
Why this matters
Bundle has high unused-code ratio — tree-shaking and route-splitting recover the wasted bytes.
Source: web.dev
80% of a.pub.network's code is unused. The script may be loading features you don't use.
Why this matters
Bundle has high unused-code ratio — tree-shaking and route-splitting recover the wasted bytes.