Audit

20260903T133345Z-7cb6

← Back to foxwaycom
Audited URL
https://foxway.com/
Timestamp
2026-09-03T13:35:27.530Z
Kind
site
Pages
1
Audit summary
https://foxway.com/
1 of 1 pages audited
Pagespeed scores
Other checks
LLM Report

Weighted audit summary

38
Overall site quality
Poormedium confidence

Site overall 38 is the mean of 1 page. PSI mobile performance 40/100 is catastrophic (LCP 5.5s >4s heavy penalty, TBT 2.13s >600ms heavy penalty, FCP 3.03s >3s heavy penalty). Desktop is better at 69 but Google uses mobile-first indexing. W3C validator found 53 HTML errors including structural issues (h3 inside role=button ×9, duplicate IDs, heading order violations). Security headers score 47/100 with missing CSP and insecure cookie flags. SEO scores 100/100 and CLS is excellent at 0.000. Confidence is medium because PSI succeeded but axe-core, Browser Runtime, and HTML Inventory all timed out, leaving accessibility and image analysis unverifiable.

Audit Report: foxway.com

Website: https://foxway.com/
Date: 03.09.2026
Audit Coverage: 43% — axe-core: page.goto: Timeout 60000ms exceeded. Call log:

  • navigating to "https://foxway.com/", waiting until "networkidle" ; Browser Runtime: page.goto: Timeout 60000ms exceeded. Call log:
  • navigating to "https://foxway.com/", waiting until "networkidle" ; HTML Inventory: page.goto: Timeout 60000ms exceeded. Call log:
  • navigating to "https://foxway.com/", waiting until "networkidle" ; Optimized-Web Checklist: Requires html and securityHeaders to succeed
    Confidence: medium

Pages Audited (1 of 1):

Summary of results

Overall Score: 38 / 100
Status: ⚠ 🟠 Poor

Site overall 38 is the mean of 1 page. PSI mobile performance 40/100 is catastrophic (LCP 5.5s >4s heavy penalty, TBT 2.13s >600ms heavy penalty, FCP 3.03s >3s heavy penalty). Desktop is better at 69 but Google uses mobile-first indexing. W3C validator found 53 HTML errors including structural issues (h3 inside role=button ×9, duplicate IDs, heading order violations). Security headers score 47/100 with missing CSP and insecure cookie flags. SEO scores 100/100 and CLS is excellent at 0.000. Confidence is medium because PSI succeeded but axe-core, Browser Runtime, and HTML Inventory all timed out, leaving accessibility and image analysis unverifiable.

Per-page scores

🟠 Poor · https://foxway.com/

Score Performance Accessibility Best Practices SEO Security
38 40 95 77 100 47

PageSpeed Insights — Mobile vs Desktop

Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.

URL Performance (M / D) LCP (M / D) CLS (M / D)
https://foxway.com/ 40 / 69 5.53 s / 2.63 s 0.000 / 0.002

Fixes

Priority 1: Critical

Immediate action — impacts user experience, search rankings, or site safety.

1A. Reduce third-party script impact (recaptcha, gtag, cookie consent) Performance

  • Impact: TBT 2.13s, LCP 5.5s, FCP 3.03s, Speed Index 6.51s
  • Problem: Multiple long tasks from recaptcha (268ms, 264ms, 186ms, 139ms, 138ms), gtag (329ms, 232ms), and cookie consent modal (1.21s). 169KB+ wasted JS from recaptcha alone.
  • Solution:
    • Load recaptcha with defer or async and only when needed (e.g., on form interaction)
    • Use requestIdleCallback or setTimeout to delay non-critical scripts
    • Consider self-hosting recaptcha or using a lighter alternative
    • Defer Google Tag Manager until after LCP
    • Lazy-load cookie consent modal (only show after user interaction)

1B. Implement proper caching headers Performance

  • Impact: Cache savings of 606 KiB, repeat visit performance
  • Problem: No cache-control header set; caching behavior is unpredictable. TTFB field data shows 2505ms (slow) despite 4ms lab.
  • Solution: Add cache-control for static assets:
    <IfModule mod_expires.c>
      ExpiresActive On
      ExpiresByType image/webp "access plus 1 year"
      ExpiresByType image/jpeg "access plus 1 year"
      ExpiresByType text/css "access plus 1 month"
      ExpiresByType application/javascript "access plus 1 month"
    </IfModule>
    Header set Cache-Control "max-age=31536000, public" for static assets
    

1C. Fix AWSALB cookie security flags Security

  • Impact: Session hijacking, CSRF risk
  • Problem: AWSALB cookie missing Secure, HttpOnly, and SameSite flags. Cookie sent over HTTP and accessible to JavaScript.
  • Solution: Configure load balancer to set:
    Set-Cookie: AWSALB=...; Secure; HttpOnly; SameSite=Lax
    
    This prevents XSS exfiltration and CSRF attacks.

Priority 2: Important

Essential for compliance, user reach, and search visibility.

2A. Fix heading order and role=button violations Accessibility

  • Impact: Screen reader navigation, WCAG 1.3.1, 2.4.6
  • Problem: 9 instances of h3 inside role=button elements. Heading order skips from h2 to h6 (skipping 3 levels). Multiple duplicate IDs (accordion, text-block, social-links, clip0).
  • Solution:
    • Remove role=button from elements containing headings; use <button> with proper text instead
    • Fix heading hierarchy: h1 → h2 → h3 (no skips)
    • Ensure each ID is unique across the page
    • Add section headings where missing (section #form-2 lacks heading)

2B. Add Content-Security-Policy header Security

  • Impact: XSS defense-in-depth
  • Problem: CSP missing. Site has no auth/payments/UGC signals, but WordPress sites are common XSS targets.
  • Solution: Start with a restrictive CSP and iterate:
    Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' https://www.gstatic.com https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; frame-src https://www.google.com;
    
    Use nonce/hash approach for production.

Priority 3: Best Practice

Recommended for long-term maintainability.

3A. Fix W3C HTML validation errors Best Practices

  • Impact: SEO, cross-browser compatibility, maintainability
  • Problem: 53 HTML errors including meta name not allowed (×7), style in body (×5), bad target attribute (×4), stray end tags, duplicate IDs.
  • Solution:
    • Move <style> from body to head
    • Fix meta tags: use property for Open Graph, remove name where not allowed
    • Add proper target values (remove empty strings)
    • Fix video element: remove disableRemotePlayback attribute
    • Ensure <link> elements have proper rel attributes
▸Raw Markdown sent to the LLM
# Site Audit — https://foxway.com/
Run: 2026-09-03T13:33:45.168Z

Audited **1** of 1 discovered pages.
Average per-page audit coverage: **43%**

Aggregate missing or failed sources (deduped across pages):
- axe-core: page.goto: Timeout 60000ms exceeded.
Call log:
  - navigating to "https://foxway.com/", waiting until "networkidle"

- Browser Runtime: page.goto: Timeout 60000ms exceeded.
Call log:
  - navigating to "https://foxway.com/", waiting until "networkidle"

- HTML Inventory: page.goto: Timeout 60000ms exceeded.
Call log:
  - navigating to "https://foxway.com/", waiting until "networkidle"

- Optimized-Web Checklist: Requires html and securityHeaders to succeed

Pages audited:
- https://foxway.com/

---

# Page 1 of 1 — https://foxway.com/

Run: 2026-09-03T13:33:52.650Z

## Audit Coverage
**43%** of audit sources returned data.

Missing or failed sources:
- axe-core: page.goto: Timeout 60000ms exceeded.
Call log:
  - navigating to "https://foxway.com/", waiting until "networkidle"

- Browser Runtime: page.goto: Timeout 60000ms exceeded.
Call log:
  - navigating to "https://foxway.com/", waiting until "networkidle"

- HTML Inventory: page.goto: Timeout 60000ms exceeded.
Call log:
  - navigating to "https://foxway.com/", waiting until "networkidle"

- Optimized-Web Checklist: Requires html and securityHeaders to succeed

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 31383 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **40** | 69 |
| Accessibility | 95 | **92** |
| Best Practices | 77 | 77 |
| SEO | 100 | 100 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **5.5 s** / 3705 ms p75 (average) | 2.6 s / 3933 ms p75 (average) |
| CLS | 0.000 / 0 p75 (fast) | **0.002** / 0 p75 (fast) |
| TBT | **2.13 s** | 307 ms |
| FCP | **3.03 s** / 2791 ms p75 (average) | 765 ms / 2561 ms p75 (average) |
| Speed Index | **6.51 s** | 1.83 s |
| TTFB | 4 ms / 2505 ms p75 (slow) | **5 ms** / 2240 ms p75 (slow) |
| INP (field only) | 183 ms p75 (fast) | 82 ms p75 (fast) |

### Priority fixes
1. **total-blocking-time** (high) — 2,130 ms
2. **largest-contentful-paint** (high) — 5.5 s
3. **speed-index** (high) — 6.5 s
4. **first-contentful-paint** (high) — 3.0 s
5. **cache-insight** (high) — Est savings of 606 KiB

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/ox8dsmiqR62P1bqhciWOn7Fg/recaptcha__en.js — 169 KB wasted
- https://www.gstatic.com/recaptcha/releases/ox8dsmiqR62P1bqhciWOn7Fg/recaptcha__en.js — 156 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-1VPLWX8V3J&cx=c&gtm=4e6911 — 75 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TRQB56V — 70 KB wasted
- https://www.googletagmanager.com/gtag/js?id=AW-11485841630&cx=c&gtm=4e6911 — 67 KB wasted
- https://cookiechimp.com/assets/consent_modal-8e02413441aec1d4d7364adc7d514fba4b1e1b5bf7e459017e77949d630ba616.js — 27 KB wasted

#### Long tasks
- https://cookiechimp.com/assets/consent_modal-8e02413441aec1d4d7364adc7d514fba4b1e1b5bf7e459017e77949d630ba616.js — 1.21 s
- https://www.googletagmanager.com/gtag/js?id=G-1VPLWX8V3J&cx=c&gtm=4e6911 — 329 ms
- https://www.gstatic.com/recaptcha/releases/ox8dsmiqR62P1bqhciWOn7Fg/recaptcha__en.js — 268 ms
- https://www.gstatic.com/recaptcha/releases/ox8dsmiqR62P1bqhciWOn7Fg/recaptcha__en.js — 264 ms
- https://www.googletagmanager.com/gtag/js?id=AW-11485841630&cx=c&gtm=4e6911 — 232 ms
- https://www.gstatic.com/recaptcha/releases/ox8dsmiqR62P1bqhciWOn7Fg/recaptcha__en.js — 186 ms
- Unattributable — 186 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TRQB56V — 140 ms
- https://www.gstatic.com/recaptcha/releases/ox8dsmiqR62P1bqhciWOn7Fg/recaptcha__en.js — 139 ms
- https://www.gstatic.com/recaptcha/releases/ox8dsmiqR62P1bqhciWOn7Fg/recaptcha__en.js — 138 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`

#### All failing PSI audits (sorted by weight × failure margin)
- `total-blocking-time` (performance, score 0.07, weight 30) — Total Blocking Time — 2,130 ms
- `largest-contentful-paint` (performance, score 0.18, weight 25) — Largest Contentful Paint — 5.5 s
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `speed-index` (performance, score 0.39, weight 10) — Speed Index — 6.5 s
- `first-contentful-paint` (performance, score 0.48, weight 10) — First Contentful Paint — 3.0 s
- `deprecations` (best-practices, score 0.00, weight 5) — Uses deprecated APIs — 1 warning found
- `heading-order` (accessibility, score 0.00, weight 3) — Heading elements are not in a sequentially-descending order
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `max-potential-fid` (performance, score 0.00, weight 0) — Max Potential First Input Delay — 1,210 ms
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `interactive` (performance, score 0.08, weight 0) — Time to Interactive — 14.9 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 2809 ms._

**Transport:**
- Final URL: https://www.foxway.com/en/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: not set
- etag: n/a
- last-modified: n/a
- expires: n/a
- pragma: n/a
- vary: Accept-Encoding
- Issues:
  - no cache-control header — caching behavior is unpredictable

**Compression:**
- content-encoding: gzip
- content-length: 28714
- Decoded body: 132.6 KB
- Compression ratio: 0.211

### Priority fixes
1. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
2. **cookie "AWSALB" missing Secure flag** (high) — Cookie sent over HTTP — exposed on unencrypted connections
3. **cookie "AWSALB" missing HttpOnly flag** (medium) — Cookie accessible to JavaScript — XSS can exfiltrate it
4. **weak caching policy** (medium) — no cache-control header — caching behavior is unpredictable
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **cookie "AWSALB" missing SameSite attribute** (low) — No SameSite attribute — browser defaults vary, CSRF risk

### Findings

#### Tracked headers
- **strict-transport-security** (present, high) `max-age=31536000; includeSubDomains; preload`
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Cookies
- AWSALB — HttpOnly=false, Secure=false, SameSite=none
- AWSALBCORS — HttpOnly=false, Secure=true, SameSite=None

#### Info disclosure
- Server: `Apache`


#### All response headers
```
connection: keep-alive
content-encoding: gzip
content-length: 28714
content-type: text/html; charset=UTF-8
date: Thu, 03 Sep 2026 13:33:55 GMT
server: Apache
set-cookie: AWSALBCORS=MJmA7jmsoWo1nZkVS2D4BQg5z0JzbmkdRLEuVfHWQF6My5GT+BTvBKlnAySCN9OGSdM2TsyzPZJiReqJqX47D8lfvL5HDcY9vp29O379OULojRU4orsumgJrLSu/; Expires=Thu, 10 Sep 2026 13:33:53 GMT; Path=/; SameSite=None; Secure
strict-transport-security: max-age=31536000; includeSubDomains; preload
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 3636 ms._

**Scoring:** 53 errors · 7 warnings · 51 cosmetic (suppressed)

### Priority fixes
1. **The element “h3” must not appear as a descendant of an element with the attribute “role=button”.** (high) — x9, first at line 662
2. **Attribute “name” not allowed on element “meta” at this point.** (high) — x7, first at line 101
3. **Element “meta” is missing one or more of the following attributes: “itemprop”, “property”.** (high) — x7, first at line 101
4. **Element “style” not allowed as child of element “body” in this context. (Suppressing further errors from this subtree.)** (high) — x5, first at line 158
5. **Bad value “” for attribute “target” on element “a”: Browsing context name must be at least one character long.** (medium) — x4, first at line 452

### Issue groups
- (×1) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “src” attribute. — first at line 68 `ager -->

<script
type="text/plain"
data-category="analytics"
data-service="Sale`
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 87 `</script><script type="text/javascript">
(func`
- (×1) [error] Bad start tag in “img” in “noscript” in “head”. — first at line 98 `noscript>
<img height="1" width="1" style="display:none;" alt="" src="https://px`
- (×1) [error] Stray end tag “noscript”. — first at line 99 `t=gif" />
</noscript>

<met`
- (×7) [error] Attribute “name” not allowed on element “meta” at this point. — first at line 101 `oscript>

<meta name="google-site-verification" content="C9OKHxTtU9tcqEh663OMkVG`
- (×7) [error] Element “meta” is missing one or more of the following attributes: “itemprop”, “property”. — first at line 101 `oscript>

<meta name="google-site-verification" content="C9OKHxTtU9tcqEh663OMkVG`
- (×5) [error] Element “style” not allowed as child of element “body” in this context. (Suppressing further errors from this subtree.) — first at line 158 `;</script><style class="wpcode-css-snippet">ul.wp-`
- (×1) [error] CSS: “top”: only “0” can be a “unit”. You must put a unit after your number. — first at line 285 `top: 15;`
- (×3) [error] A “link” element must not appear as a descendant of a “body” element unless the “link” element has an “itemprop” attribute or has a “rel” attribute whose value contains “dns-prefetch”, “modulepreload”, “pingback”, “preconnect”, “prefetch”, “preload”, “prerender”, or “stylesheet”. — first at line 355 `}</style><link rel="icon" href="https://www.foxway.com/wp-content/uploads/2025/0`
- (×1) [error] Stray end tag “head”. — first at line 398 `</head>

	<bo`
- (×1) [error] Start tag “body” seen but an element of the same type was already open. — first at line 400 `</head>

	<body>

		<h`
- (×4) [error] Bad value “” for attribute “target” on element “a”: Browsing context name must be at least one character long. — first at line 452 `<a href="https://www.foxway.com/en/contact/" class="button button-action" target`
- (×2) [error] Element “div” not allowed as child of element “ul” in this context. (Suppressing further errors from this subtree.) — first at line 462 `enu">
				<div class="globe-icon mobile-icon"></div>`
- (×1) [error] Attribute “disableremoteplayback” not allowed on element “video” at this point. — first at line 608 `16/9">
			<video autoplay loop muted playsinline disableRemotePlayback>`
- (×1) [error] Stray end tag “source”. — first at line 609 `ideo/mp4"></source>`
- (×1) [error] Duplicate ID “accordion”. — first at line 649 `/section>
<section id="accordion" class="section accordion-section accordion-no-`
- (×1) [warning] The first occurrence of ID “accordion” was here. — first at line 622 `>

						
<section id="accordion" class="section accordion-section accordion-no-`
- (×9) [error] The element “h3” must not appear as a descendant of an element with the attribute “role=button”. — first at line 662 `e="layer"><h3 id="n2-ss-9item2" class="n2-font-6b17c38ef6f78a069597519e6ce3b609-`
- (×1) [error] Duplicate ID “text-block”. — first at line 732 `/section>
<section id="text-block" class="container--large media--img-backplate"`
- (×1) [warning] The first occurrence of ID “text-block” was here. — first at line 688 `</section><section id="text-block" class="container--large media--img-backplate"`
- (×1) [warning] Section lacks heading. Consider using “h2”-“h6” elements to add identifying headings to all sections, or else use a “div” element instead for any cases where no heading is needed. — first at line 829 `section>

<section id="form-2" class="card--section">

	<di`
- (×1) [error] Duplicate ID “clip0”. — first at line 873 `g>
<defs>
<clipPath id="clip0">
<rect`
- (×1) [warning] The first occurrence of ID “clip0” was here. — first at line 416 `g>
<defs>
<clipPath id="clip0">
<rect`
- (×3) [error] The element “header” must not appear as a descendant of the “footer” element. — first at line 881 `u-7">

			<header>`
- (×1) [error] Duplicate ID “social-links”. — first at line 924 `l>
</nav>
<nav id="social-links">`
- (×1) [warning] The first occurrence of ID “social-links” was here. — first at line 486 `</ul>
				<nav id="social-links">`
- (×1) [warning] Consider using the “h1” element as a top-level heading only — or else use the “headingoffset” attribute (otherwise, all “h1” elements are treated as top-level headings by many screen readers and other tools). — first at line 634 `e="layer"><h1 id="n2-ss-10item1" class="n2-font-d2f72a32ce728f5aa8dc1f753dd624f0`
- (×1) [error] The heading “h6” (with computed level 6) follows the heading “h2” (with computed level 2), skipping 3 heading levels. — first at line 636 `e="layer"><h6 id="n2-ss-10item5" class="n2-font-40eb83a5d9468fd5fdfa718c76215781`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)

_Error after 60039 ms: page.goto: Timeout 60000ms exceeded.
Call log:
  - navigating to "https://foxway.com/", waiting until "networkidle"
_

## Browser Runtime

_Error after 60039 ms: page.goto: Timeout 60000ms exceeded.
Call log:
  - navigating to "https://foxway.com/", waiting until "networkidle"
_

## HTML Inventory

_Error after 60039 ms: page.goto: Timeout 60000ms exceeded.
Call log:
  - navigating to "https://foxway.com/", waiting until "networkidle"
_

## Optimized-Web Checklist

_Error after 0 ms: Requires html and securityHeaders to succeed_