20260903T133345Z-7cb6
- Audited URL
- https://foxway.com/
- Timestamp
- 2026-09-03T13:35:27.530Z
- Kind
- site
- Pages
- 1
Weighted audit summary
Site overall 38 is the mean of 1 page. PSI mobile performance 40/100 is catastrophic (LCP 5.5s >4s heavy penalty, TBT 2.13s >600ms heavy penalty, FCP 3.03s >3s heavy penalty). Desktop is better at 69 but Google uses mobile-first indexing. W3C validator found 53 HTML errors including structural issues (h3 inside role=button ×9, duplicate IDs, heading order violations). Security headers score 47/100 with missing CSP and insecure cookie flags. SEO scores 100/100 and CLS is excellent at 0.000. Confidence is medium because PSI succeeded but axe-core, Browser Runtime, and HTML Inventory all timed out, leaving accessibility and image analysis unverifiable.
Audit Report: foxway.com
Website: https://foxway.com/
Date: 03.09.2026
Audit Coverage: 43% — axe-core: page.goto: Timeout 60000ms exceeded.
Call log:
- navigating to "https://foxway.com/", waiting until "networkidle" ; Browser Runtime: page.goto: Timeout 60000ms exceeded. Call log:
- navigating to "https://foxway.com/", waiting until "networkidle" ; HTML Inventory: page.goto: Timeout 60000ms exceeded. Call log:
- navigating to "https://foxway.com/", waiting until "networkidle"
; Optimized-Web Checklist: Requires html and securityHeaders to succeed
Confidence: medium
Pages Audited (1 of 1):
Summary of results
Overall Score: 38 / 100
Status: ⚠ 🟠 Poor
Site overall 38 is the mean of 1 page. PSI mobile performance 40/100 is catastrophic (LCP 5.5s >4s heavy penalty, TBT 2.13s >600ms heavy penalty, FCP 3.03s >3s heavy penalty). Desktop is better at 69 but Google uses mobile-first indexing. W3C validator found 53 HTML errors including structural issues (h3 inside role=button ×9, duplicate IDs, heading order violations). Security headers score 47/100 with missing CSP and insecure cookie flags. SEO scores 100/100 and CLS is excellent at 0.000. Confidence is medium because PSI succeeded but axe-core, Browser Runtime, and HTML Inventory all timed out, leaving accessibility and image analysis unverifiable.
Per-page scores
🟠 Poor · https://foxway.com/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 38 | 40 | 95 | 77 | 100 | 47 |
PageSpeed Insights — Mobile vs Desktop
Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.
| URL | Performance (M / D) | LCP (M / D) | CLS (M / D) |
|---|---|---|---|
| https://foxway.com/ | 40 / 69 | 5.53 s / 2.63 s | 0.000 / 0.002 |
Fixes
Priority 1: Critical
Immediate action — impacts user experience, search rankings, or site safety.
1A. Reduce third-party script impact (recaptcha, gtag, cookie consent) Performance
- Impact: TBT 2.13s, LCP 5.5s, FCP 3.03s, Speed Index 6.51s
- Problem: Multiple long tasks from recaptcha (268ms, 264ms, 186ms, 139ms, 138ms), gtag (329ms, 232ms), and cookie consent modal (1.21s). 169KB+ wasted JS from recaptcha alone.
- Solution:
- Load recaptcha with
deferorasyncand only when needed (e.g., on form interaction) - Use
requestIdleCallbackorsetTimeoutto delay non-critical scripts - Consider self-hosting recaptcha or using a lighter alternative
- Defer Google Tag Manager until after LCP
- Lazy-load cookie consent modal (only show after user interaction)
- Load recaptcha with
1B. Implement proper caching headers Performance
- Impact: Cache savings of 606 KiB, repeat visit performance
- Problem: No cache-control header set; caching behavior is unpredictable. TTFB field data shows 2505ms (slow) despite 4ms lab.
- Solution:
Add cache-control for static assets:
<IfModule mod_expires.c> ExpiresActive On ExpiresByType image/webp "access plus 1 year" ExpiresByType image/jpeg "access plus 1 year" ExpiresByType text/css "access plus 1 month" ExpiresByType application/javascript "access plus 1 month" </IfModule> Header set Cache-Control "max-age=31536000, public" for static assets
1C. Fix AWSALB cookie security flags Security
- Impact: Session hijacking, CSRF risk
- Problem: AWSALB cookie missing Secure, HttpOnly, and SameSite flags. Cookie sent over HTTP and accessible to JavaScript.
- Solution:
Configure load balancer to set:
This prevents XSS exfiltration and CSRF attacks.Set-Cookie: AWSALB=...; Secure; HttpOnly; SameSite=Lax
Priority 2: Important
Essential for compliance, user reach, and search visibility.
2A. Fix heading order and role=button violations Accessibility
- Impact: Screen reader navigation, WCAG 1.3.1, 2.4.6
- Problem: 9 instances of h3 inside role=button elements. Heading order skips from h2 to h6 (skipping 3 levels). Multiple duplicate IDs (accordion, text-block, social-links, clip0).
- Solution:
- Remove role=button from elements containing headings; use
<button>with proper text instead - Fix heading hierarchy: h1 → h2 → h3 (no skips)
- Ensure each ID is unique across the page
- Add section headings where missing (section #form-2 lacks heading)
- Remove role=button from elements containing headings; use
2B. Add Content-Security-Policy header Security
- Impact: XSS defense-in-depth
- Problem: CSP missing. Site has no auth/payments/UGC signals, but WordPress sites are common XSS targets.
- Solution:
Start with a restrictive CSP and iterate:
Use nonce/hash approach for production.Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' https://www.gstatic.com https://www.googletagmanager.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; frame-src https://www.google.com;
Priority 3: Best Practice
Recommended for long-term maintainability.
3A. Fix W3C HTML validation errors Best Practices
- Impact: SEO, cross-browser compatibility, maintainability
- Problem: 53 HTML errors including meta name not allowed (×7), style in body (×5), bad target attribute (×4), stray end tags, duplicate IDs.
- Solution:
- Move
<style>from body to head - Fix meta tags: use
propertyfor Open Graph, removenamewhere not allowed - Add proper target values (remove empty strings)
- Fix video element: remove
disableRemotePlaybackattribute - Ensure
<link>elements have properrelattributes
- Move
▸Raw Markdown sent to the LLM
# Site Audit — https://foxway.com/ Run: 2026-09-03T13:33:45.168Z Audited **1** of 1 discovered pages. Average per-page audit coverage: **43%** Aggregate missing or failed sources (deduped across pages): - axe-core: page.goto: Timeout 60000ms exceeded. Call log: - navigating to "https://foxway.com/", waiting until "networkidle" - Browser Runtime: page.goto: Timeout 60000ms exceeded. Call log: - navigating to "https://foxway.com/", waiting until "networkidle" - HTML Inventory: page.goto: Timeout 60000ms exceeded. Call log: - navigating to "https://foxway.com/", waiting until "networkidle" - Optimized-Web Checklist: Requires html and securityHeaders to succeed Pages audited: - https://foxway.com/ --- # Page 1 of 1 — https://foxway.com/ Run: 2026-09-03T13:33:52.650Z ## Audit Coverage **43%** of audit sources returned data. Missing or failed sources: - axe-core: page.goto: Timeout 60000ms exceeded. Call log: - navigating to "https://foxway.com/", waiting until "networkidle" - Browser Runtime: page.goto: Timeout 60000ms exceeded. Call log: - navigating to "https://foxway.com/", waiting until "networkidle" - HTML Inventory: page.goto: Timeout 60000ms exceeded. Call log: - navigating to "https://foxway.com/", waiting until "networkidle" - Optimized-Web Checklist: Requires html and securityHeaders to succeed ## Methodology Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula. Severity scale in `priorities[]`: - **high** — blocking issue / vulnerability / fail. - **medium** — significant degradation. - **low** — minor improvement. Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify. ## Site Signals (inferred) Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong. - Auth surface: no - Payments: no - User-generated content: no - E-commerce: no ## PageSpeed Insights _Captured in 31383 ms (mobile + desktop in parallel)._ **Lighthouse scores (mobile vs desktop; worse value bolded):** | Category | Mobile | Desktop | | --- | --- | --- | | Performance | **40** | 69 | | Accessibility | 95 | **92** | | Best Practices | 77 | 77 | | SEO | 100 | 100 | **Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:** | Metric | Mobile | Desktop | | --- | --- | --- | | LCP | **5.5 s** / 3705 ms p75 (average) | 2.6 s / 3933 ms p75 (average) | | CLS | 0.000 / 0 p75 (fast) | **0.002** / 0 p75 (fast) | | TBT | **2.13 s** | 307 ms | | FCP | **3.03 s** / 2791 ms p75 (average) | 765 ms / 2561 ms p75 (average) | | Speed Index | **6.51 s** | 1.83 s | | TTFB | 4 ms / 2505 ms p75 (slow) | **5 ms** / 2240 ms p75 (slow) | | INP (field only) | 183 ms p75 (fast) | 82 ms p75 (fast) | ### Priority fixes 1. **total-blocking-time** (high) — 2,130 ms 2. **largest-contentful-paint** (high) — 5.5 s 3. **speed-index** (high) — 6.5 s 4. **first-contentful-paint** (high) — 3.0 s 5. **cache-insight** (high) — Est savings of 606 KiB ### Findings (mobile) #### Unused JavaScript - https://www.gstatic.com/recaptcha/releases/ox8dsmiqR62P1bqhciWOn7Fg/recaptcha__en.js — 169 KB wasted - https://www.gstatic.com/recaptcha/releases/ox8dsmiqR62P1bqhciWOn7Fg/recaptcha__en.js — 156 KB wasted - https://www.googletagmanager.com/gtag/js?id=G-1VPLWX8V3J&cx=c>m=4e6911 — 75 KB wasted - https://www.googletagmanager.com/gtm.js?id=GTM-TRQB56V — 70 KB wasted - https://www.googletagmanager.com/gtag/js?id=AW-11485841630&cx=c>m=4e6911 — 67 KB wasted - https://cookiechimp.com/assets/consent_modal-8e02413441aec1d4d7364adc7d514fba4b1e1b5bf7e459017e77949d630ba616.js — 27 KB wasted #### Long tasks - https://cookiechimp.com/assets/consent_modal-8e02413441aec1d4d7364adc7d514fba4b1e1b5bf7e459017e77949d630ba616.js — 1.21 s - https://www.googletagmanager.com/gtag/js?id=G-1VPLWX8V3J&cx=c>m=4e6911 — 329 ms - https://www.gstatic.com/recaptcha/releases/ox8dsmiqR62P1bqhciWOn7Fg/recaptcha__en.js — 268 ms - https://www.gstatic.com/recaptcha/releases/ox8dsmiqR62P1bqhciWOn7Fg/recaptcha__en.js — 264 ms - https://www.googletagmanager.com/gtag/js?id=AW-11485841630&cx=c>m=4e6911 — 232 ms - https://www.gstatic.com/recaptcha/releases/ox8dsmiqR62P1bqhciWOn7Fg/recaptcha__en.js — 186 ms - Unattributable — 186 ms - https://www.googletagmanager.com/gtm.js?id=GTM-TRQB56V — 140 ms - https://www.gstatic.com/recaptcha/releases/ox8dsmiqR62P1bqhciWOn7Fg/recaptcha__en.js — 139 ms - https://www.gstatic.com/recaptcha/releases/ox8dsmiqR62P1bqhciWOn7Fg/recaptcha__en.js — 138 ms #### DOM size - Total nodes: 0 #### Failing modeled audits - SEO: `tapTargets` - SEO: `structuredData` - Best Practices: `errorsInConsole` #### All failing PSI audits (sorted by weight × failure margin) - `total-blocking-time` (performance, score 0.07, weight 30) — Total Blocking Time — 2,130 ms - `largest-contentful-paint` (performance, score 0.18, weight 25) — Largest Contentful Paint — 5.5 s - `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name - `speed-index` (performance, score 0.39, weight 10) — Speed Index — 6.5 s - `first-contentful-paint` (performance, score 0.48, weight 10) — First Contentful Paint — 3.0 s - `deprecations` (best-practices, score 0.00, weight 5) — Uses deprecated APIs — 1 warning found - `heading-order` (accessibility, score 0.00, weight 3) — Heading elements are not in a sequentially-descending order - `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow - `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree - `max-potential-fid` (performance, score 0.00, weight 0) — Max Potential First Input Delay — 1,210 ms - `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console - `interactive` (performance, score 0.08, weight 0) — Time to Interactive — 14.9 s ### Manual checks - Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation). - Sustained INP under typical user interaction, not just initial load. - CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing. ## Security Headers & HTTP _Captured in 2809 ms._ **Transport:** - Final URL: https://www.foxway.com/en/ - Status: 200 - Redirected: false - HTTPS redirect: HTTP → HTTPS ✓ **Caching:** - cache-control: not set - etag: n/a - last-modified: n/a - expires: n/a - pragma: n/a - vary: Accept-Encoding - Issues: - no cache-control header — caching behavior is unpredictable **Compression:** - content-encoding: gzip - content-length: 28714 - Decoded body: 132.6 KB - Compression ratio: 0.211 ### Priority fixes 1. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions 2. **cookie "AWSALB" missing Secure flag** (high) — Cookie sent over HTTP — exposed on unencrypted connections 3. **cookie "AWSALB" missing HttpOnly flag** (medium) — Cookie accessible to JavaScript — XSS can exfiltrate it 4. **weak caching policy** (medium) — no cache-control header — caching behavior is unpredictable 5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin 6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features 7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context 8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads 9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests 10. **cookie "AWSALB" missing SameSite attribute** (low) — No SameSite attribute — browser defaults vary, CSRF risk ### Findings #### Tracked headers - **strict-transport-security** (present, high) `max-age=31536000; includeSubDomains; preload` - **content-security-policy** (missing, high) - **x-frame-options** (present, medium) `SAMEORIGIN` - **x-content-type-options** (present, medium) `nosniff` - **referrer-policy** (missing, low) - **permissions-policy** (missing, low) - **cross-origin-opener-policy** (missing, low) - **cross-origin-resource-policy** (missing, low) - **x-permitted-cross-domain-policies** (missing, low) #### Cookies - AWSALB — HttpOnly=false, Secure=false, SameSite=none - AWSALBCORS — HttpOnly=false, Secure=true, SameSite=None #### Info disclosure - Server: `Apache` #### All response headers ``` connection: keep-alive content-encoding: gzip content-length: 28714 content-type: text/html; charset=UTF-8 date: Thu, 03 Sep 2026 13:33:55 GMT server: Apache set-cookie: AWSALBCORS=MJmA7jmsoWo1nZkVS2D4BQg5z0JzbmkdRLEuVfHWQF6My5GT+BTvBKlnAySCN9OGSdM2TsyzPZJiReqJqX47D8lfvL5HDcY9vp29O379OULojRU4orsumgJrLSu/; Expires=Thu, 10 Sep 2026 13:33:53 GMT; Path=/; SameSite=None; Secure strict-transport-security: max-age=31536000; includeSubDomains; preload vary: Accept-Encoding x-content-type-options: nosniff x-frame-options: SAMEORIGIN ``` ### Manual checks - Cookie attributes set via JavaScript (not visible in HTTP response). - CORS preflight behavior under non-GET methods (only GET response headers checked). - HSTS preload list inclusion (check hstspreload.org). - WAF / DDoS posture beyond what static headers reveal. ## W3C HTML Validator _Captured in 3636 ms._ **Scoring:** 53 errors · 7 warnings · 51 cosmetic (suppressed) ### Priority fixes 1. **The element “h3” must not appear as a descendant of an element with the attribute “role=button”.** (high) — x9, first at line 662 2. **Attribute “name” not allowed on element “meta” at this point.** (high) — x7, first at line 101 3. **Element “meta” is missing one or more of the following attributes: “itemprop”, “property”.** (high) — x7, first at line 101 4. **Element “style” not allowed as child of element “body” in this context. (Suppressing further errors from this subtree.)** (high) — x5, first at line 158 5. **Bad value “” for attribute “target” on element “a”: Browsing context name must be at least one character long.** (medium) — x4, first at line 452 ### Issue groups - (×1) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “src” attribute. — first at line 68 `ager --> <script type="text/plain" data-category="analytics" data-service="Sale` - (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 87 `</script><script type="text/javascript"> (func` - (×1) [error] Bad start tag in “img” in “noscript” in “head”. — first at line 98 `noscript> <img height="1" width="1" style="display:none;" alt="" src="https://px` - (×1) [error] Stray end tag “noscript”. — first at line 99 `t=gif" /> </noscript> <met` - (×7) [error] Attribute “name” not allowed on element “meta” at this point. — first at line 101 `oscript> <meta name="google-site-verification" content="C9OKHxTtU9tcqEh663OMkVG` - (×7) [error] Element “meta” is missing one or more of the following attributes: “itemprop”, “property”. — first at line 101 `oscript> <meta name="google-site-verification" content="C9OKHxTtU9tcqEh663OMkVG` - (×5) [error] Element “style” not allowed as child of element “body” in this context. (Suppressing further errors from this subtree.) — first at line 158 `;</script><style class="wpcode-css-snippet">ul.wp-` - (×1) [error] CSS: “top”: only “0” can be a “unit”. You must put a unit after your number. — first at line 285 `top: 15;` - (×3) [error] A “link” element must not appear as a descendant of a “body” element unless the “link” element has an “itemprop” attribute or has a “rel” attribute whose value contains “dns-prefetch”, “modulepreload”, “pingback”, “preconnect”, “prefetch”, “preload”, “prerender”, or “stylesheet”. — first at line 355 `}</style><link rel="icon" href="https://www.foxway.com/wp-content/uploads/2025/0` - (×1) [error] Stray end tag “head”. — first at line 398 `</head> <bo` - (×1) [error] Start tag “body” seen but an element of the same type was already open. — first at line 400 `</head> <body> <h` - (×4) [error] Bad value “” for attribute “target” on element “a”: Browsing context name must be at least one character long. — first at line 452 `<a href="https://www.foxway.com/en/contact/" class="button button-action" target` - (×2) [error] Element “div” not allowed as child of element “ul” in this context. (Suppressing further errors from this subtree.) — first at line 462 `enu"> <div class="globe-icon mobile-icon"></div>` - (×1) [error] Attribute “disableremoteplayback” not allowed on element “video” at this point. — first at line 608 `16/9"> <video autoplay loop muted playsinline disableRemotePlayback>` - (×1) [error] Stray end tag “source”. — first at line 609 `ideo/mp4"></source>` - (×1) [error] Duplicate ID “accordion”. — first at line 649 `/section> <section id="accordion" class="section accordion-section accordion-no-` - (×1) [warning] The first occurrence of ID “accordion” was here. — first at line 622 `> <section id="accordion" class="section accordion-section accordion-no-` - (×9) [error] The element “h3” must not appear as a descendant of an element with the attribute “role=button”. — first at line 662 `e="layer"><h3 id="n2-ss-9item2" class="n2-font-6b17c38ef6f78a069597519e6ce3b609-` - (×1) [error] Duplicate ID “text-block”. — first at line 732 `/section> <section id="text-block" class="container--large media--img-backplate"` - (×1) [warning] The first occurrence of ID “text-block” was here. — first at line 688 `</section><section id="text-block" class="container--large media--img-backplate"` - (×1) [warning] Section lacks heading. Consider using “h2”-“h6” elements to add identifying headings to all sections, or else use a “div” element instead for any cases where no heading is needed. — first at line 829 `section> <section id="form-2" class="card--section"> <di` - (×1) [error] Duplicate ID “clip0”. — first at line 873 `g> <defs> <clipPath id="clip0"> <rect` - (×1) [warning] The first occurrence of ID “clip0” was here. — first at line 416 `g> <defs> <clipPath id="clip0"> <rect` - (×3) [error] The element “header” must not appear as a descendant of the “footer” element. — first at line 881 `u-7"> <header>` - (×1) [error] Duplicate ID “social-links”. — first at line 924 `l> </nav> <nav id="social-links">` - (×1) [warning] The first occurrence of ID “social-links” was here. — first at line 486 `</ul> <nav id="social-links">` - (×1) [warning] Consider using the “h1” element as a top-level heading only — or else use the “headingoffset” attribute (otherwise, all “h1” elements are treated as top-level headings by many screen readers and other tools). — first at line 634 `e="layer"><h1 id="n2-ss-10item1" class="n2-font-d2f72a32ce728f5aa8dc1f753dd624f0` - (×1) [error] The heading “h6” (with computed level 6) follows the heading “h2” (with computed level 2), skipping 3 heading levels. — first at line 636 `e="layer"><h6 id="n2-ss-10item5" class="n2-font-40eb83a5d9468fd5fdfa718c76215781` ### Manual checks - Whether each `<section>` / `<article>` wraps semantically meaningful content. - Language tag accuracy for multi-language pages or quoted content. - Whether structural choices align with the document outline algorithm in screen readers. ## axe-core (Accessibility) _Error after 60039 ms: page.goto: Timeout 60000ms exceeded. Call log: - navigating to "https://foxway.com/", waiting until "networkidle" _ ## Browser Runtime _Error after 60039 ms: page.goto: Timeout 60000ms exceeded. Call log: - navigating to "https://foxway.com/", waiting until "networkidle" _ ## HTML Inventory _Error after 60039 ms: page.goto: Timeout 60000ms exceeded. Call log: - navigating to "https://foxway.com/", waiting until "networkidle" _ ## Optimized-Web Checklist _Error after 0 ms: Requires html and securityHeaders to succeed_