# Audit Report: foxway.com **Website:** https://foxway.com/ **Date:** 03.09.2026 **Audit Coverage:** 43% โ€” axe-core: page.goto: Timeout 60000ms exceeded. Call log: - navigating to "https://foxway.com/", waiting until "networkidle" ; Browser Runtime: page.goto: Timeout 60000ms exceeded. Call log: - navigating to "https://foxway.com/", waiting until "networkidle" ; HTML Inventory: page.goto: Timeout 60000ms exceeded. Call log: - navigating to "https://foxway.com/", waiting until "networkidle" ; Optimized-Web Checklist: Requires html and securityHeaders to succeed **Confidence:** medium **Pages Audited (1 of 1):** - https://foxway.com/ ## Summary of results **Overall Score:** 38 / 100 **Status:** โš  ๐ŸŸ  **Poor** Site overall 38 is the mean of 1 page. PSI mobile performance 40/100 is catastrophic (LCP 5.5s >4s heavy penalty, TBT 2.13s >600ms heavy penalty, FCP 3.03s >3s heavy penalty). Desktop is better at 69 but Google uses mobile-first indexing. W3C validator found 53 HTML errors including structural issues (h3 inside role=button ร—9, duplicate IDs, heading order violations). Security headers score 47/100 with missing CSP and insecure cookie flags. SEO scores 100/100 and CLS is excellent at 0.000. Confidence is medium because PSI succeeded but axe-core, Browser Runtime, and HTML Inventory all timed out, leaving accessibility and image analysis unverifiable. ### Per-page scores ๐ŸŸ  **Poor** ยท https://foxway.com/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 38 | 40 | 95 | 77 | 100 | 47 | ## PageSpeed Insights โ€” Mobile vs Desktop _Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._ | URL | Performance (M / D) | LCP (M / D) | CLS (M / D) | | --- | --- | --- | --- | | https://foxway.com/ | **40** / 69 | **5.53 s** / 2.63 s | 0.000 / **0.002** | ## Fixes ### Priority 1: Critical *Immediate action โ€” impacts user experience, search rankings, or site safety.* **1A. Reduce third-party script impact (recaptcha, gtag, cookie consent)** `Performance` - **Impact:** TBT 2.13s, LCP 5.5s, FCP 3.03s, Speed Index 6.51s - **Problem:** Multiple long tasks from recaptcha (268ms, 264ms, 186ms, 139ms, 138ms), gtag (329ms, 232ms), and cookie consent modal (1.21s). 169KB+ wasted JS from recaptcha alone. - **Solution:** - Load recaptcha with `defer` or `async` and only when needed (e.g., on form interaction) - Use `requestIdleCallback` or `setTimeout` to delay non-critical scripts - Consider self-hosting recaptcha or using a lighter alternative - Defer Google Tag Manager until after LCP - Lazy-load cookie consent modal (only show after user interaction) **1B. Implement proper caching headers** `Performance` - **Impact:** Cache savings of 606 KiB, repeat visit performance - **Problem:** No cache-control header set; caching behavior is unpredictable. TTFB field data shows 2505ms (slow) despite 4ms lab. - **Solution:** Add cache-control for static assets: ```apache ExpiresActive On ExpiresByType image/webp "access plus 1 year" ExpiresByType image/jpeg "access plus 1 year" ExpiresByType text/css "access plus 1 month" ExpiresByType application/javascript "access plus 1 month" Header set Cache-Control "max-age=31536000, public" for static assets ``` **1C. Fix AWSALB cookie security flags** `Security` - **Impact:** Session hijacking, CSRF risk - **Problem:** AWSALB cookie missing Secure, HttpOnly, and SameSite flags. Cookie sent over HTTP and accessible to JavaScript. - **Solution:** Configure load balancer to set: ``` Set-Cookie: AWSALB=...; Secure; HttpOnly; SameSite=Lax ``` This prevents XSS exfiltration and CSRF attacks. ### Priority 2: Important *Essential for compliance, user reach, and search visibility.* **2A. Fix heading order and role=button violations** `Accessibility` - **Impact:** Screen reader navigation, WCAG 1.3.1, 2.4.6 - **Problem:** 9 instances of h3 inside role=button elements. Heading order skips from h2 to h6 (skipping 3 levels). Multiple duplicate IDs (accordion, text-block, social-links, clip0). - **Solution:** - Remove role=button from elements containing headings; use `