Skip to content

Changes

https://tomorrowspayment.com
Compared to previous audit · 15 hours ago View previous audit
4
New issues
6
Resolved
14
score changes
CategoryPreviousCurrentChange
CompositeB (87)B (88) +1.000
PerformanceB (87)B (87)
SecurityB (87)B (89) +2.000
AccessibilityB (86)B (86)
SEOA+ (99)A+ (99)
InfrastructureA (90)A (90)
ComplianceC (75)C (75)
ContentA (90)A (90)
SustainabilityC (75)C (75)
MetricPreviousCurrentChange
Performance 63006500 +200
Accessibility 92009700 +500
Best Practices 1000010000
SEO 1000010000
PWA 00
Desktop Performance 82009100 +900
Desktop Accessibility 92009700 +500
Desktop Best Practices 1000010000
Desktop SEO 1000010000
FCP 4.05 s4.06 s
LCP 11.52 s12.44 s +921 ms
TBT 0 ms87 ms +87 ms
CLS 0.0000.000
Desktop FCP 1.07 s1.22 s +150 ms
Desktop LCP 2.84 s1.41 s -1.43 s
Desktop TBT 0 ms0 ms
Desktop CLS 0.0000.000
TTFB 440 ms471 ms +31 ms
DNS 29 ms39 ms +10 ms
TLS 25 ms25 ms
Connect 17 ms17 ms -0 ms
Total 539 ms572 ms +33 ms

† Timing metrics may vary by worker location and do not necessarily indicate site changes.

WARNING Unattributable: 694ms CPU time performance
WARNING 112 text node(s) render below 12 CSS pixels on mobile accessibility
WARNING https://tomorrowspayment.com/_astro/hoisted.D3uQPd...: 725ms CPU time performance
WARNING https://tomorrowspayment.com/: 942ms CPU time performance
WARNING Cross-Origin-Opener-Policy header is missing security
WARNING Compressed response missing `Vary` header performance
WARNING https://tomorrowspayment.com/: 615ms CPU time performance
WARNING Unattributable: 584ms CPU time performance
WARNING https://tomorrowspayment.com/_astro/hoisted.D3uQPd...: 824ms CPU time performance
WARNING 1 software version(s) disclosed in HTML: Astro v4.16.19 security
CRITICAL HTTP version does not redirect to HTTPS infrastructure
CRITICAL Page weighs 6.1 MB (6.0 MB transferred) performance
WARNING Images are 3.1 MB — compress or use modern formats performance
WARNING https://tomorrowspayment.com/media/production/imag... is missing width/height — may cause layout shift performance
WARNING Page weight 6.0 MB exceeds 1 MB target by 5.0 MB performance
WARNING SRI adoption: 0/1 third-party resources protected (0%) security
WARNING DMARC policy is none — monitoring only security
WARNING 1 control(s) rely on placeholder only accessibility
WARNING GDPR Article 13 disclosure coverage: 1 / 8 categories compliance
WARNING Broken link: https://fonts.googleapis.com content
WARNING Broken link: https://fonts.gstatic.com content
WARNING External link from fonts.googleapis.com lacks integrity attribute security
WARNING 1 link(s) open in new tab without warning accessibility
WARNING 62 of 64 links are healthy content
WARNING Total image weight: 1013 KB (1.0 MB) content
WARNING 18 font weights loaded -- likely 100+ KB of unused payload sustainability
WARNING Registrar lock is NOT enabled infrastructure
WARNING 7 images missing explicit width/height content
WARNING All 4 images use legacy formats (JPEG/PNG/GIF) content
WARNING 1.42g CO2 per page view sustainability
WARNING 1.42g CO2 — above the median website (0.60g) sustainability
WARNING HSTS is enabled but max-age is short (15552000s, should be >= 31536000s) security
WARNING Cross-Origin-Embedder-Policy header is missing security
WARNING 2 field(s) would benefit from inputmode attribute accessibility
+ cross-origin-opener-policy same-origin
+ vary Accept-Encoding
content-security-policy
default-src 'self'; script-src 'self' 'nonce-ffefd6c7-7ce3-4f08-a296-eacca450... default-src 'self'; script-src 'self' 'nonce-f3a38804-4bbf-4c19-a4b2-620edffb...

11 headers unchanged

Astro v4.16.19 v

10 technologies unchanged

Looking ahead

+10 pts
B (88) Could reach A+ (98)
Accessibility +13Performance +13Security +11Content +10Infrastructure +10Sustainability +10Compliance +4

Estimate — actual results may vary (28 issues to fix)

Website improvement report — Tomorrowspayment

September 19, 2026 → September 20, 2026

B B 87 → 88 +1 pts

6

Resolved

4

New issues

24

Still remaining

Financial summary

Investment delivered

€213 in development time

Investment remaining

€1,828 to complete the remaining items

Ongoing risk

€1/month in ongoing exposure

Figures are estimates based on local developer hourly rate, industry CPC, and regulatory fine ranges.

Performance by category

MetricBeforeAfterChange
Overall score87 (B)88 (B)+1
Performance87 (B)87 (B)0
Security87 (B)89 (B)+2
Accessibility86 (B)86 (B)0
SEO99 (A+)99 (A+)0
Infrastructure90 (A)90 (A)0
Compliance75 (C)75 (C)0
Content90 (A)90 (A)0
Sustainability75 (C)75 (C)0

Resolved (6)

  • Cross-Origin-Opener-Policy header is missing (Security)

    → Reduced attack surface for visitors

  • Compressed response missing `Vary` header (Performance)

    → Page loads faster for users

  • https://tomorrowspayment.com/: 615ms CPU time (Performance)

    → Page loads faster for users

  • Unattributable: 584ms CPU time (Performance)

    → Page loads faster for users

  • https://tomorrowspayment.com/_astro/hoisted.D3uQPd...: 824ms CPU time (Performance)

    → Page loads faster for users

  • 1 software version(s) disclosed in HTML: Astro v4.16.19 (Security)

    → Reduced attack surface for visitors

Recommended next steps (28)

  • Sprint 1

    HTTP version does not redirect to HTTPS (Infrastructure)

  • Sprint 1

    Page weighs 6.1 MB (6.0 MB transferred) (Performance)

  • Sprint 1

    Unattributable: 694ms CPU time (Performance)

  • Sprint 1

    112 text node(s) render below 12 CSS pixels on mobile (Accessibility)

  • Sprint 1

    https://tomorrowspayment.com/_astro/hoisted.D3uQPd...: 725ms CPU time (Performance)

  • Sprint 1

    https://tomorrowspayment.com/: 942ms CPU time (Performance)

  • Sprint 2

    Images are 3.1 MB — compress or use modern formats (Performance)

  • Sprint 1

    https://tomorrowspayment.com/media/production/imag... is missing width/height — may cause layout shift (Performance)

  • Sprint 2

    Page weight 6.0 MB exceeds 1 MB target by 5.0 MB (Performance)

  • Sprint 1

    SRI adoption: 0/1 third-party resources protected (0%) (Security)

  • Sprint 1

    DMARC policy is none — monitoring only (Security)

  • Sprint 2

    1 control(s) rely on placeholder only (Accessibility)

  • Sprint 2

    GDPR Article 13 disclosure coverage: 1 / 8 categories (Compliance)

  • Sprint 1

    Broken link: https://fonts.googleapis.com (Content)

  • Sprint 1

    Broken link: https://fonts.gstatic.com (Content)

…and 13 more recommended item(s)

Send Feedback