# Audit Report: foxway.com
**Website:** https://foxway.com/
**Date:** 03.09.2026
**Audit Coverage:** 43% โ axe-core: page.goto: Timeout 60000ms exceeded.
Call log:
- navigating to "https://foxway.com/", waiting until "networkidle"
; Browser Runtime: page.goto: Timeout 60000ms exceeded.
Call log:
- navigating to "https://foxway.com/", waiting until "networkidle"
; HTML Inventory: page.goto: Timeout 60000ms exceeded.
Call log:
- navigating to "https://foxway.com/", waiting until "networkidle"
; Optimized-Web Checklist: Requires html and securityHeaders to succeed
**Confidence:** medium
**Pages Audited (1 of 1):**
- https://foxway.com/
## Summary of results
**Overall Score:** 38 / 100
**Status:** โ ๐ **Poor**
Site overall 38 is the mean of 1 page. PSI mobile performance 40/100 is catastrophic (LCP 5.5s >4s heavy penalty, TBT 2.13s >600ms heavy penalty, FCP 3.03s >3s heavy penalty). Desktop is better at 69 but Google uses mobile-first indexing. W3C validator found 53 HTML errors including structural issues (h3 inside role=button ร9, duplicate IDs, heading order violations). Security headers score 47/100 with missing CSP and insecure cookie flags. SEO scores 100/100 and CLS is excellent at 0.000. Confidence is medium because PSI succeeded but axe-core, Browser Runtime, and HTML Inventory all timed out, leaving accessibility and image analysis unverifiable.
### Per-page scores
๐ **Poor** ยท https://foxway.com/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 38 | 40 | 95 | 77 | 100 | 47 |
## PageSpeed Insights โ Mobile vs Desktop
_Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._
| URL | Performance (M / D) | LCP (M / D) | CLS (M / D) |
| --- | --- | --- | --- |
| https://foxway.com/ | **40** / 69 | **5.53 s** / 2.63 s | 0.000 / **0.002** |
## Fixes
### Priority 1: Critical
*Immediate action โ impacts user experience, search rankings, or site safety.*
**1A. Reduce third-party script impact (recaptcha, gtag, cookie consent)** `Performance`
- **Impact:** TBT 2.13s, LCP 5.5s, FCP 3.03s, Speed Index 6.51s
- **Problem:** Multiple long tasks from recaptcha (268ms, 264ms, 186ms, 139ms, 138ms), gtag (329ms, 232ms), and cookie consent modal (1.21s). 169KB+ wasted JS from recaptcha alone.
- **Solution:**
- Load recaptcha with `defer` or `async` and only when needed (e.g., on form interaction)
- Use `requestIdleCallback` or `setTimeout` to delay non-critical scripts
- Consider self-hosting recaptcha or using a lighter alternative
- Defer Google Tag Manager until after LCP
- Lazy-load cookie consent modal (only show after user interaction)
**1B. Implement proper caching headers** `Performance`
- **Impact:** Cache savings of 606 KiB, repeat visit performance
- **Problem:** No cache-control header set; caching behavior is unpredictable. TTFB field data shows 2505ms (slow) despite 4ms lab.
- **Solution:**
Add cache-control for static assets:
```apache
ExpiresActive On
ExpiresByType image/webp "access plus 1 year"
ExpiresByType image/jpeg "access plus 1 year"
ExpiresByType text/css "access plus 1 month"
ExpiresByType application/javascript "access plus 1 month"
Header set Cache-Control "max-age=31536000, public" for static assets
```
**1C. Fix AWSALB cookie security flags** `Security`
- **Impact:** Session hijacking, CSRF risk
- **Problem:** AWSALB cookie missing Secure, HttpOnly, and SameSite flags. Cookie sent over HTTP and accessible to JavaScript.
- **Solution:**
Configure load balancer to set:
```
Set-Cookie: AWSALB=...; Secure; HttpOnly; SameSite=Lax
```
This prevents XSS exfiltration and CSRF attacks.
### Priority 2: Important
*Essential for compliance, user reach, and search visibility.*
**2A. Fix heading order and role=button violations** `Accessibility`
- **Impact:** Screen reader navigation, WCAG 1.3.1, 2.4.6
- **Problem:** 9 instances of h3 inside role=button elements. Heading order skips from h2 to h6 (skipping 3 levels). Multiple duplicate IDs (accordion, text-block, social-links, clip0).
- **Solution:**
- Remove role=button from elements containing headings; use `