Delivery & Trust
37 checks, ordered by severity.
Mixed active content: scripts or styles over HTTPno_mixed_activeMixed content: HTTP assets on an HTTPS pageno_mixed_contentPage served over HTTP instead of HTTPSpage_not_served_over_httpsSSL certificate is outside its validity windowssl_certificate_expiredNo Strict-Transport-Security headerstrict_transport_securityForm on an HTTPS page submitting over HTTPinsecure_form_actionLargest Contentful Paint in the poor rangepoor_lcpInteraction to Next Paint in the poor rangepoor_inpCumulative Layout Shift in the poor rangepoor_clsNo Content-Security-Policy headercontent_security_policyNo clickjacking protection headerx_frame_optionsSSL certificate expires within 30 daysssl_certificate_expiring_soonHTML served without text compressionhtml_not_compressedLargest Contentful Paint image is lazy-loadedlcp_image_lazy_loadedNo X-Content-Type-Options: nosniff headerx_content_type_optionsNo Permissions-Policy headerpermissions_policyNo Referrer-Policy headerreferrer_policy_headerServer takes too long to send the first byteslow_ttfbFirst Contentful Paint in the poor rangepoor_fcpHSTS max-age shorter than one yearhsts_max_age_too_shortTotal Blocking Time in the poor rangepoor_tbtUnminified CSS or JavaScriptunminified_css_jsUnused JavaScriptunused_javascriptRender-blocking scripts or stylesheets in the headrender_blocking_resourcesStatic files cached for too short a timeshort_static_asset_cacheExcessive DOM sizeexcessive_dom_sizeOffscreen images loaded up frontoffscreen_images_not_deferredServer still accepts TLS 1.0 or 1.1outdated_tls_acceptedImages larger than their displayed sizeoversized_imagesHeavy third-party codeheavy_third_party_codePage weight over budgetpage_weight_over_budgetHSTS does not cover subdomainshsts_missing_include_subdomainsSlow Speed Indexslow_speed_indexHSTS header not eligible for preloadhsts_not_preload_readyUnused CSSunused_cssWeb fonts without font-displayfont_display_missingNo preconnect to required third-party originsmissing_preconnect