Audit Result

UUID: 019d8fb1-4cd0-7104-8f32-09fdce87012f

www.doubao.com

https://www.doubao.com/security/doubao-region-ban?source=1

Scanned 4 months ago

72
Fair Score
39 total checks
Passed
19
Warnings
18
Errors
2

Meta Information

  • Title Tag Warning

    Found 2 characters. Keep title between 30 and 60 characters.

    Fix: Add a unique <title> tag describing the main page intent in 30-60 characters.

  • Found 106 characters. Good snippet length.

  • Canonical URL Warning

    Canonical link not found.

    Fix: Add <link rel="canonical" href="https://example.com/page"> to avoid duplicate URL ambiguity.

  • Favicon Pass

    Favicon found and reachable: https://lf-flow-web-cdn.doubao.com/obj/flow-doubao/favicon/64x64.png (HTTP 200).

    Favicon
  • Viewport configured: width=device-width,initial-scale=1,shrink-to-fit=no,viewport-fit=cover,minimum-scale=1,maximum-scale=1,user-scalable=no

  • HTML Lang Warning

    No lang attribute on the <html> element.

    Fix: Set <html lang="en"> (or the correct locale) for accessibility and search engines.

Content Structure

  • H1 Tag Error

    No H1 heading found.

    Fix: Use a single, descriptive <h1> that states the primary purpose of the page.

  • Valid heading flow across 0 headings.

  • 1 of 1 images are missing alt text.

    Fix: Add meaningful alt attributes to all informative images for accessibility and image SEO.

Technical Optimization

  • HTTPS Pass

    Page is served over HTTPS.

  • 2 HTTPS hardening issues detected.

    • • Missing Strict-Transport-Security header.
    • • Could not probe the HTTP version of this page.

    Fix: Set Strict-Transport-Security with a long max-age, add includeSubDomains, and redirect all HTTP requests to HTTPS.

  • Missing: strict-transport-security, x-frame-options, x-content-type-options, referrer-policy.

    Full HTTP headers (27)
    • • cache-control: no-cache
    • • content-encoding: br
    • • content-security-policy: report-to slardar-endpoint; upgrade-insecure-requests ; report-uri https://mon.zijieapi.com/monitor_browser/collect/batch/security/?bid=flow_web; report-to slardar-endpoint; upgrade-insecure-requests ; report-uri https://mon.zijieapi.com/monitor_browser/collect/batch/security/?bid=flow_web;
    • • content-security-policy-report-only: report-to slardar-endpoint; upgrade-insecure-requests ; frame-ancestors 'self' *.toutiao.com *.douyin.com *.bytedance.com *.bytedance.net tcs.jiyunhudong.com aup.jijixiangshangabc.com chrome-extension://dbjibobgilijgolhjdcbdebjhejelffo chrome-extension://molcibnmfbjmmfbefjfcafdeabfniobi chrome-extension://capohkkfagimodmlpnahjoijgooocdjhd chrome-extension://mijalhmcgaaaggjfhkliffkanfhimhch chrome-extension://obkcimipmjdkghadnfcjojepocldeggd chrome-extension://epjhdbhhoeemcbbbgkimcfndcbjapdaa safari-web-extension:; script-src 'nonce-e66b03726f587236d48f65e2d94b13a6-argus' blob: data: 'self' 'unsafe-eval' 'report-sample' 'strict-dynamic' 'unsafe-inline' https:; base-uri 'self'; object-src 'self'; frame-src 'self' *.toutiao.com *.douyin.com *.bytedance.com *.bytedance.net tcs.jiyunhudong.com aup.jijixiangshangabc.com;report-uri https://mon.zijieapi.com/monitor_browser/collect/batch/security/?bid=flow_web; report-to slardar-endpoint; upgrade-insecure-requests ; frame-ancestors 'self' *.toutiao.com *.douyin.com *.bytedance.com *.bytedance.net tcs.jiyunhudong.com aup.jijixiangshangabc.com chrome-extension://dbjibobgilijgolhjdcbdebjhejelffo chrome-extension://molcibnmfbjmmfbefjfcafdeabfniobi chrome-extension://capohkkfagimodmlpnahjoijgooocdjhd chrome-extension://mijalhmcgaaaggjfhkliffkanfhimhch chrome-extension://obkcimipmjdkghadnfcjojepocldeggd chrome-extension://epjhdbhhoeemcbbbgkimcfndcbjapdaa safari-web-extension:; script-src blob: data: 'self' 'unsafe-eval' 'report-sample' 'strict-dynamic' 'unsafe-inline' 'wasm-unsafe-eval' https: 'nonce-e66b03726f587236d48f65e2d94b13a6-argus'; base-uri 'self'; object-src 'self'; frame-src 'self' *.toutiao.com *.douyin.com *.bytedance.com *.bytedance.net tcs.jiyunhudong.com aup.jijixiangshangabc.com; report-uri https://mon.zijieapi.com/monitor_browser/collect/batch/security/?bid=flow_web;
    • • content-type: text/html; charset=UTF-8
    • • date: Wed, 15 Apr 2026 05:50:47 GMT
    • • document-policy: include-js-call-stacks-in-crash-reports
    • • reporting-endpoints: crash-reporting="https://aha.zijieapi.com/api/reporting/crash?bid=flow_web",slardar-endpoint="https://mon.zijieapi.com/monitor_browser/collect/batch/security/?bid=flow_web" slardar-endpoint="https://mon.zijieapi.com/monitor_browser/collect/batch/security/?bid=flow_web"
    • • server: volc-dcdn
    • • server-timing: inner; dur=465, cdn-cache;desc=MISS, origin;dur=565, edge;dur=159, cdn-cache;desc=MISS, cdn-cache;desc=MISS, bd-edenx-server-loader-chat_layout; dur=302.999973, bd-edenx-server-loader;decs="SSR"; dur=304.000139, bd-edenx-ssr-prerender;decs="SSR"; dur=0.999927, bd-edenx-ssr-render-html;decs="SSR"; dur=0, bd-edenx-server-handle-request; dur=438.999891
    • • vary: Accept-Encoding
    • • via: n172-186-203.gdguangzhou-mp01.Creative,n172-207-072.HK-HKG1.Creative,n107-155-001-248.oversea-US-LAX7.Creative
    • • x-bytefaas-enable-stream: true
    • • x-bytefaas-execution-duration: 442.24
    • • x-bytefaas-request-id: 20260415135047506E67F79D646916B075
    • • x-dsa-origin-status: 200
    • • x-dsa-trace-id: 177623224653d666d05b2386aca4994da87b7af682
    • • x-ggw-config-version: 10760024
    • • x-gw-dst-psm: goofy_ssr.cn.3155598
    • • x-modernjs-render: server
    • • x-powered-by: Goofy Node
    • • x-processed-by: Modern.js
    • • x-request-ip: 5.161.96.221
    • • x-tt-logid: 20260415135047506E67F79D646916B075
    • • x-tt-trace-host: 0126a012bf2ba0dcedd9d10879e3ccf5f971fb09a4eee860b9903c8524fd23cef70150f403cf4e1e2732ed1cb767e5f0b6c320253af064a72aff8fc1a45b403feb1476074859632c1769fc7e9a29bf28004537661f7df892fc85211402cb3f8827c833b2b4fc9b383e14e3f900076a96406af886132bd2c164c25e3863354ff978
    • • x-tt-trace-id: 00-8fb1305b0301008fd69b81ca82e10000-8fb1305b0301008f-01
    • • x-tt-trace-tag: id=5

    Fix: Add the missing security headers at your reverse proxy or application layer.

  • CSP Quality Warning

    3 CSP hardening issues detected.

    • • CSP is missing object-src 'none'.
    • • CSP is missing a base-uri restriction.
    • • CSP is missing frame-ancestors protection.
    • • Content-Security-Policy: report-to slardar-endpoint; upgrade-insecure-requests ; report-uri https://mon.zijieapi.com/monitor_browser/collect/batch/security/?bid=flow_web; report-to slardar-endpoint; upgrade-insecure-requests ; report-uri https://mon.zijieapi.com/monitor_browser/collect/batch/security/?bid=flow_web;

    Fix: Tighten Content-Security-Policy by removing unsafe directives and adding object-src, base-uri, and frame-ancestors restrictions.

  • No first-party cookies were set during the initial page load.

  • Server response headers do not expose version tokens.

  • Domain does not appear to be behind Cloudflare.

  • Loaded in 0.46s (perceived).

  • 3 scripts and 6 styles may block rendering.

    • • script: https://lf3-short.ibytedapm.com/slardar/fe/sdk-web/browser.1.16.6.cn.js?bid=flow_web&globalName=inlineSlardarInstance
    • • script: https://lf-flow-web-cdn.doubao.com/obj/flow-doubao/rc-client-security/web/stable/1.0.1.20-alpha.08/bdms.js
    • • script: https://lf3-short.ibytedapm.com/slardar/fe/sdk-web/plugins/common-monitors.1.16.6.js
    • • style: https://lf-flow-web-cdn.doubao.com/obj/flow-doubao/doubao/web/static/css/22273.cc09168b.css
    • • style: https://lf-flow-web-cdn.doubao.com/obj/flow-doubao/doubao/web/static/css/43532.b6f4fdf0.css
    • • style: https://lf-flow-web-cdn.doubao.com/obj/flow-doubao/doubao/web/static/css/77560.4a372353.css
    • • style: https://lf-flow-web-cdn.doubao.com/obj/flow-doubao/doubao/web/static/css/security.4aa8393b.css
    • • style: https://lf-flow-web-cdn.doubao.com/obj/flow-doubao/doubao/web/static/css/async/30200.582d805d.css
    • • style: https://lf-flow-web-cdn.doubao.com/obj/flow-doubao/doubao/web/static/css/async/security_doubao-region-ban/page.17d5aaa1.css

    Fix: Defer non-critical scripts and inline critical CSS to improve first paint speed.

  • Compression Warning

    8 text resources look uncompressed.

    • • https://www.doubao.com/alice/user/get_web_anon_id?version_code=20800&language=zh&device_platform=web&aid=497858&real_aid=497858&pkg_type=release_version&device_id=&pc_version=3.14.5&region=&sys_region=&samantha_web=1&use-olympus-account=1&web_tab_id=a9bfa539-f92f-49de-b91d-95d628624fcc (application/json; charset=utf-8)
    • • https://www.doubao.com/ttwid/check/ (application/json)
    • • https://www.doubao.com/passport/account/info/v2/?pc_version=3.14.5&version_code=20800&language=zh&device_platform=web&aid=497858&real_aid=497858&pkg_type=release_version&use-olympus-account=1&region=&sys_region=&account_sdk_source=web&sdk_version=2.2.10&doubao_from=inject_html&a_bogus=DfsVk77ymN8bcV%2FSmcaiCeC5WoCArBujvFiORuOR7FPwPXUT9KlmYxcVJoo-4PDUGmszhK370DU%2FbxVcu84s1MHkLmkfS%2F4j-RO99U0L2qwVPMvsLrSTCz0FowsGlbGL-5CXi1fRls0ygDOlVrVsAB5GS5ziRObpbNpjd2T9HjA0pFuzE1pWtcX2JH4t-4V6MzhWHym%3D (application/json; charset=utf-8)
    • • https://mcs.doubao.com/webid (application/json; charset=utf-8)
    • • https://www.doubao.com/samantha/user/setting/get?version_code=20800&language=zh&device_platform=web&aid=497858&real_aid=497858&pkg_type=release_version&device_id=&pc_version=3.14.5&region=&sys_region=&samantha_web=1&use-olympus-account=1&web_tab_id=6bac2139-5dc2-4c8d-b535-2ae536c99148&a_bogus=xyUVhe67OqAned%2FtYcrsCHn5c6AlNTujgUTORrFR9FFsPHeG9%2F1EYYdfaqoB4sjU48skhqVHhDWMYxDPmWV1IZHpompkSq0RaROV9UvL0qNpa0vsLHSwCzsFLwsYMRGLl59tilv5Is076E5lnr5sAQlay5ziROmpRHBRdZY99jA0308zL1pRtcvgcH-tB4ofBSWX7E%3D%3D (application/json; charset=utf-8)
    • • https://mcs.doubao.com/list (application/json; charset=utf-8)
    • • https://mcs.doubao.com/tobid (application/json; charset=utf-8)
    • • https://mssdk.bytedance.com/web/report?msToken=&X-Bogus=DFSzswROQDcO7uTSCoFN6EPPCOFy (text/plain; charset=utf-8)

    Fix: Enable Brotli or Gzip compression for HTML, CSS, JS, and JSON responses.

  • Robots.txt Pass

    Found robots.txt (200).

  • Found sitemap (200) at https://www.doubao.com/sitemap.xml.

  • No robots meta tag defined.

    Fix: Add <meta name="robots" content="index,follow"> (or the intended directive) in <head>.

Accessibility Basics

  • All 0 controls are labeled.

  • Landmarks Warning

    Missing landmarks: header, nav, main, footer.

    Fix: Use semantic regions (<header>, <nav>, <main>, <footer>) for navigation and assistive tech.

  • Tap Target Size Warning

    2 interactive elements appear smaller than 48px.

    • • button.semi-button.semi-button-primary (使用 Dola) - 91x44px
    • • button.semi-button.semi-button-primary (登录) - 91x44px

    Fix: Increase target size to at least 48x48 CSS pixels for touch interactions.

Social & Rich Results

  • Core Open Graph tags are present.

  • og:image is missing.

    Fix: Add <meta property="og:image" content="https://..."> with a high-quality share image.

  • Twitter Card Warning

    twitter:card is missing.

    Fix: Add <meta name="twitter:card" content="summary_large_image"> for better previews on X.

  • Structured Data Warning

    No JSON-LD schema scripts found.

    Fix: Add JSON-LD structured data matching your page type (Organization, Article, Product, etc.).

  • PWA Metadata Warning

    Manifest or Apple touch icon is missing.

    Fix: Link your web app manifest and apple-touch-icon for improved install/share experiences.

  • 3 social preview quality issues detected.

    • • ISSUE: og:title should typically be between 10 and 70 characters.
    • • ISSUE: Use an absolute URL for og:image or twitter:image.
    • • ISSUE: twitter:card is missing.
    • • GUIDELINE: Optimal og:title length: 40-60 characters (acceptable: 10-70).
    • • GUIDELINE: Optimal og:description length: 110-160 characters (acceptable: 50-200).
    • • GUIDELINE: Optimal preview image size: 1200x630 pixels.
    • • GUIDELINE: Optimal preview image aspect ratio: 1.91:1.
    • • GUIDELINE: Optimal preview image file size: under 5 MB.
    • • GUIDELINE: Recommended twitter:card: summary_large_image.

    Fix: Use absolute OG/Twitter URLs, keep metadata lengths in recommended ranges, and provide a preview image near 1200x630 under 5MB.

Links Analysis

Performance & Runtime

  • Largest Contentful Paint: 1.40s.

  • Cumulative Layout Shift: 0.000.

  • Total Blocking Time estimate: 129ms.

  • No failed CSS/JS/image/font/media requests detected.

  • 6 JavaScript runtime issues detected.

    • • Request failed: https://mcs.doubao.com/webid (net::ERR_ABORTED, type: xhr)
    • • Request failed: https://www.doubao.com/check_and_get_text/00d51bf0012811ee97fd5fdb0b0365a9/normal/web?lang=zh,zh (net::ERR_ABORTED, type: xhr)
    • • The Content Security Policy directive 'upgrade-insecure-requests' is ignored when delivered in a report-only policy. [https://www.doubao.com/chat?channel=xiazais:1]
    • • The Content Security Policy directive 'upgrade-insecure-requests' is ignored when delivered in a report-only policy. [https://www.doubao.com/security/doubao-region-ban?source=1:1]
    • • WebSocket connection to 'wss://www.doubao.com/security/Create%20WebSocket' failed: Error during WebSocket handshake: Unexpected response code: 404 [https://lf-flow-web-cdn.doubao.com/obj/flow-doubao/rc-client-security/c-webmssdk/1.0.0.43/webmssdk.es5.js:2]
    • • httpStatus=200, code=671000007, message=undefined, logId=20260415135051732E0B301119A82C71EB

    Fix: Fix JS files returning 404/failed requests and resolve the listed runtime exceptions.