{"url":"https://foxway.com/","date":"2026-09-03","siteName":"foxway.com","overall":38,"reasoning":"Site overall 38 is the mean of 1 page. PSI mobile performance 40/100 is catastrophic (LCP 5.5s >4s heavy penalty, TBT 2.13s >600ms heavy penalty, FCP 3.03s >3s heavy penalty). Desktop is better at 69 but Google uses mobile-first indexing. W3C validator found 53 HTML errors including structural issues (h3 inside role=button ×9, duplicate IDs, heading order violations). Security headers score 47/100 with missing CSP and insecure cookie flags. SEO scores 100/100 and CLS is excellent at 0.000. Confidence is medium because PSI succeeded but axe-core, Browser Runtime, and HTML Inventory all timed out, leaving accessibility and image analysis unverifiable.","confidence":"medium","fixes":[{"priority":1,"category":"Performance","title":"Reduce third-party script impact (recaptcha, gtag, cookie consent)","impact":"TBT 2.13s, LCP 5.5s, FCP 3.03s, Speed Index 6.51s","problem":"Multiple long tasks from recaptcha (268ms, 264ms, 186ms, 139ms, 138ms), gtag (329ms, 232ms), and cookie consent modal (1.21s). 169KB+ wasted JS from recaptcha alone.","solution":"- Load recaptcha with `defer` or `async` and only when needed (e.g., on form interaction)\n- Use `requestIdleCallback` or `setTimeout` to delay non-critical scripts\n- Consider self-hosting recaptcha or using a lighter alternative\n- Defer Google Tag Manager until after LCP\n- Lazy-load cookie consent modal (only show after user interaction)"},{"priority":1,"category":"Performance","title":"Implement proper caching headers","impact":"Cache savings of 606 KiB, repeat visit performance","problem":"No cache-control header set; caching behavior is unpredictable. TTFB field data shows 2505ms (slow) despite 4ms lab.","solution":"Add cache-control for static assets:\n```apache\n<IfModule mod_expires.c>\n  ExpiresActive On\n  ExpiresByType image/webp \"access plus 1 year\"\n  ExpiresByType image/jpeg \"access plus 1 year\"\n  ExpiresByType text/css \"access plus 1 month\"\n  ExpiresByType application/javascript \"access plus 1 month\"\n</IfModule>\nHeader set Cache-Control \"max-age=31536000, public\" for static assets\n```"},{"priority":1,"category":"Security","title":"Fix AWSALB cookie security flags","impact":"Session hijacking, CSRF risk","problem":"AWSALB cookie missing Secure, HttpOnly, and SameSite flags. Cookie sent over HTTP and accessible to JavaScript.","solution":"Configure load balancer to set:\n```\nSet-Cookie: AWSALB=...; Secure; HttpOnly; SameSite=Lax\n```\nThis prevents XSS exfiltration and CSRF attacks."},{"priority":2,"category":"Accessibility","title":"Fix heading order and role=button violations","impact":"Screen reader navigation, WCAG 1.3.1, 2.4.6","problem":"9 instances of h3 inside role=button elements. Heading order skips from h2 to h6 (skipping 3 levels). Multiple duplicate IDs (accordion, text-block, social-links, clip0).","solution":"- Remove role=button from elements containing headings; use `<button>` with proper text instead\n- Fix heading hierarchy: h1 → h2 → h3 (no skips)\n- Ensure each ID is unique across the page\n- Add section headings where missing (section #form-2 lacks heading)"},{"priority":2,"category":"Security","title":"Add Content-Security-Policy header","impact":"XSS defense-in-depth","problem":"CSP missing. Site has no auth/payments/UGC signals, but WordPress sites are common XSS targets.","solution":"Start with a restrictive CSP and iterate:\n```\nContent-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' https://www.gstatic.com https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; frame-src https://www.google.com;\n```\nUse nonce/hash approach for production."},{"priority":3,"category":"Best Practices","title":"Fix W3C HTML validation errors","impact":"SEO, cross-browser compatibility, maintainability","problem":"53 HTML errors including meta name not allowed (×7), style in body (×5), bad target attribute (×4), stray end tags, duplicate IDs.","solution":"- Move `<style>` from body to head\n- Fix meta tags: use `property` for Open Graph, remove `name` where not allowed\n- Add proper target values (remove empty strings)\n- Fix video element: remove `disableRemotePlayback` attribute\n- Ensure `<link>` elements have proper `rel` attributes"}],"coverage":{"pct":43,"missing":["axe-core: page.goto: Timeout 60000ms exceeded.\nCall log:\n  - navigating to \"https://foxway.com/\", waiting until \"networkidle\"\n","Browser Runtime: page.goto: Timeout 60000ms exceeded.\nCall log:\n  - navigating to \"https://foxway.com/\", waiting until \"networkidle\"\n","HTML Inventory: page.goto: Timeout 60000ms exceeded.\nCall log:\n  - navigating to \"https://foxway.com/\", waiting until \"networkidle\"\n","Optimized-Web Checklist: Requires html and securityHeaders to succeed"]},"siteSummary":{"pagesAudited":1,"pagesAttempted":1,"urls":["https://foxway.com/"]},"psiSnapshot":{"rows":[{"pageUrl":"https://foxway.com/","perfMobile":40,"perfDesktop":69,"lcpMobileMs":5526.048849764604,"lcpDesktopMs":2634.915660469181,"clsMobile":0,"clsDesktop":0.001518873752440717}]},"perPageOverall":[{"url":"https://foxway.com/","overall":38,"reasoning":"PSI mobile performance 40/100 is catastrophic (LCP 5.5s >4s heavy penalty, TBT 2.13s >600ms heavy penalty, FCP 3.03s >3s heavy penalty). Desktop is better at 69 but Google uses mobile-first indexing. W3C validator found 53 HTML errors including structural issues (h3 inside role=button ×9, duplicate IDs, heading order violations). Security headers score 47/100 with missing CSP and insecure cookie flags. SEO scores 100/100 and CLS is excellent at 0.000. Confidence is medium because PSI succeeded but axe-core, Browser Runtime, and HTML Inventory all timed out, leaving accessibility and image analysis unverifiable.","confidence":"medium","fixes":[{"priority":1,"category":"Performance","title":"Reduce third-party script impact (recaptcha, gtag, cookie consent)","impact":"TBT 2.13s, LCP 5.5s, FCP 3.03s, Speed Index 6.51s","problem":"Multiple long tasks from recaptcha (268ms, 264ms, 186ms, 139ms, 138ms), gtag (329ms, 232ms), and cookie consent modal (1.21s). 169KB+ wasted JS from recaptcha alone.","solution":"- Load recaptcha with `defer` or `async` and only when needed (e.g., on form interaction)\n- Use `requestIdleCallback` or `setTimeout` to delay non-critical scripts\n- Consider self-hosting recaptcha or using a lighter alternative\n- Defer Google Tag Manager until after LCP\n- Lazy-load cookie consent modal (only show after user interaction)"},{"priority":1,"category":"Performance","title":"Implement proper caching headers","impact":"Cache savings of 606 KiB, repeat visit performance","problem":"No cache-control header set; caching behavior is unpredictable. TTFB field data shows 2505ms (slow) despite 4ms lab.","solution":"Add cache-control for static assets:\n```apache\n<IfModule mod_expires.c>\n  ExpiresActive On\n  ExpiresByType image/webp \"access plus 1 year\"\n  ExpiresByType image/jpeg \"access plus 1 year\"\n  ExpiresByType text/css \"access plus 1 month\"\n  ExpiresByType application/javascript \"access plus 1 month\"\n</IfModule>\nHeader set Cache-Control \"max-age=31536000, public\" for static assets\n```"},{"priority":1,"category":"Security","title":"Fix AWSALB cookie security flags","impact":"Session hijacking, CSRF risk","problem":"AWSALB cookie missing Secure, HttpOnly, and SameSite flags. Cookie sent over HTTP and accessible to JavaScript.","solution":"Configure load balancer to set:\n```\nSet-Cookie: AWSALB=...; Secure; HttpOnly; SameSite=Lax\n```\nThis prevents XSS exfiltration and CSRF attacks."},{"priority":2,"category":"Accessibility","title":"Fix heading order and role=button violations","impact":"Screen reader navigation, WCAG 1.3.1, 2.4.6","problem":"9 instances of h3 inside role=button elements. Heading order skips from h2 to h6 (skipping 3 levels). Multiple duplicate IDs (accordion, text-block, social-links, clip0).","solution":"- Remove role=button from elements containing headings; use `<button>` with proper text instead\n- Fix heading hierarchy: h1 → h2 → h3 (no skips)\n- Ensure each ID is unique across the page\n- Add section headings where missing (section #form-2 lacks heading)"},{"priority":2,"category":"Security","title":"Add Content-Security-Policy header","impact":"XSS defense-in-depth","problem":"CSP missing. Site has no auth/payments/UGC signals, but WordPress sites are common XSS targets.","solution":"Start with a restrictive CSP and iterate:\n```\nContent-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' https://www.gstatic.com https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; frame-src https://www.google.com;\n```\nUse nonce/hash approach for production."},{"priority":3,"category":"Best Practices","title":"Fix W3C HTML validation errors","impact":"SEO, cross-browser compatibility, maintainability","problem":"53 HTML errors including meta name not allowed (×7), style in body (×5), bad target attribute (×4), stray end tags, duplicate IDs.","solution":"- Move `<style>` from body to head\n- Fix meta tags: use `property` for Open Graph, remove `name` where not allowed\n- Add proper target values (remove empty strings)\n- Fix video element: remove `disableRemotePlayback` attribute\n- Ensure `<link>` elements have proper `rel` attributes"}],"perfScore":40,"a11yScore":95,"bestPracticesScore":77,"seoScore":100,"securityScore":47}]}