Audit Result

UUID: 019db45f-ff58-7003-8af8-bf01252e7133

nextjs.org

https://nextjs.org/

Scanned 4 months ago

76
Fair Score
39 total checks
Passed
23
Warnings
13
Errors
3

Meta Information

  • Title Tag Pass

    Found 39 characters. Length is optimal.

  • Found 64 characters. Keep description around 70-160 characters.

    Fix: Add <meta name="description" content="..."> in <head> with a clear page summary.

  • Canonical URL Warning

    Canonical link not found.

    Fix: Add <link rel="canonical" href="https://example.com/page"> to avoid duplicate URL ambiguity.

  • Favicon Pass

    Favicon found and reachable: /favicon.ico?favicon.117ezoe8m31dk.ico (HTTP 200).

    Favicon
  • Viewport configured: width=device-width, initial-scale=1

  • HTML Lang Pass

    Language declared as "en".

Content Structure

  • H1 Tag Pass

    Exactly one H1 found: "The React Framework for the Web".

  • Valid heading flow across 14 headings.

  • 13 of 45 images are missing alt text.

    Fix: Add meaningful alt attributes to all informative images for accessibility and image SEO.

Technical Optimization

  • HTTPS Pass

    Page is served over HTTPS.

  • 1 HTTPS hardening issues detected.

    • • Could not probe the HTTP version of this page.
    • • Strict-Transport-Security: max-age=31536000; includeSubDomains; preload

    Fix: Set Strict-Transport-Security with a long max-age, add includeSubDomains, and redirect all HTTP requests to HTTPS.

  • Core security headers were detected.

    Full HTTP headers (23)
    • • age: 455
    • • cache-control: public, max-age=0, must-revalidate
    • • content-encoding: br
    • • content-security-policy: default-src 'self' nextjs.org *.nextjs.org vercel.com *.vercel.com *.vercel.sh vercel.live wss://*.vercel.com wss://*.nextjs.org localhost:*;script-src 'self' 'unsafe-eval' 'unsafe-inline' www.google.com www.google-analytics.com www.googleadservices.com www.gstatic.com *.youtube.com *.youtube-nocookie.com *.ytimg.com *.twimg.com cdn.ampproject.org www.googletagmanager.com *.googleapis.com *.fides-cdn.ethyca.com *.ethyca.com cdn.ethyca.com cdn.vercel-insights.com va.vercel-scripts.com app.cal.com *.cr-relay.com vercel.com *.vercel.com *.vercel.sh vercel.live nextjs.org *.nextjs.org localhost:* chrome-extension://*;child-src *.youtube.com *.youtube-nocookie.com *.stripe.com www.google.com td.doubleclick.net github.com calendly.com vercel.cal.com nextjs.org *.nextjs.org vercel.com *.vercel.com *.vercel.sh vercel.live wss://*.vercel.com wss://*.nextjs.org localhost:*;style-src 'self' 'unsafe-inline' *.googleapis.com nextjs.org *.nextjs.org vercel.com *.vercel.com *.vercel.sh vercel.live wss://*.vercel.com wss://*.nextjs.org localhost:*;img-src * blob: data:;media-src 'self' videos.ctfassets.net user-images.githubusercontent.com replicate.delivery *.public.blob.vercel-storage.com blob: data: nextjs.org *.nextjs.org vercel.com *.vercel.com *.vercel.sh vercel.live wss://*.vercel.com wss://*.nextjs.org localhost:*;connect-src 'self' data: vercel.com *.vercel.com *.vercel.sh vercel.live wss://*.vercel.com wss://*.nextjs.org nextjs.org *.nextjs.org localhost:* cdn.vercel-insights.com va.vercel-scripts.com cdp.vercel.com www.google-analytics.com www.googletagmanager.com *.googleapis.com *.cr-relay.com *.ethyca.com cdn.ethyca.com risk.clearbit.com *.ingest.sentry.io *.ingest.us.sentry.io *.public.blob.vercel-storage.com;font-src 'self' *.nextjs.org *.vercel.com *.gstatic.com vercel.live *.vercel.sh;worker-src 'self' *.nextjs.org *.vercel.com blob:
    • • content-type: text/html; charset=utf-8
    • • date: Wed, 22 Apr 2026 08:40:23 GMT
    • • feature-policy: fullscreen 'self'; camera 'none'
    • • link: </_next/static/immutable/media/797e433ab948586e.p.3f30ggp2vw8zj.woff2>; rel=preload; as="font"; crossorigin=""; type="font/woff2", </_next/static/immutable/media/caa3a2e1cccd8315.p.400zotvijr2rn.woff2>; rel=preload; as="font"; crossorigin=""; type="font/woff2", </_next/static/immutable/media/logo-github-light.0j2vz9_zw2uex.svg>; rel=preload; as="image", </_next/static/immutable/media/logo-github-dark.3cps0n_-l5sia.svg>; rel=preload; as="image", </_next/static/immutable/media/logo-twitter-x-light.3lfl0ys_vh_gz.svg>; rel=preload; as="image", </_next/static/immutable/media/logo-twitter-x-dark.2ms8a02663zmn.svg>; rel=preload; as="image", </_next/static/immutable/media/logo-bluesky-light.0oj6yf53-gzbh.svg>; rel=preload; as="image", </_next/static/immutable/media/logo-bluesky-dark.1vnxp7olsp0zg.svg>; rel=preload; as="image"
    • • referrer-policy: origin-when-cross-origin
    • • server: Vercel
    • • strict-transport-security: max-age=31536000; includeSubDomains; preload
    • • vary: rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch
    • • x-content-type-options: nosniff
    • • x-dns-prefetch-control: on
    • • x-download-options: noopen
    • • x-frame-options: DENY
    • • x-matched-path: /home/none
    • • x-nextjs-prerender: 1
    • • x-nextjs-stale-time: 300
    • • x-powered-by: Next.js
    • • x-vercel-cache: HIT
    • • x-vercel-id: iad1::cle1::jdsnd-1776847679401-b971c8042af4
    • • x-xss-protection: 0
  • CSP Quality Error

    5 CSP hardening issues detected.

    • • script-src/default-src permits 'unsafe-inline'.
    • • script-src/default-src permits 'unsafe-eval'.
    • • CSP is missing object-src 'none'.
    • • CSP is missing a base-uri restriction.
    • • CSP is missing frame-ancestors protection.
    • • Content-Security-Policy: default-src 'self' nextjs.org *.nextjs.org vercel.com *.vercel.com *.vercel.sh vercel.live wss://*.vercel.com wss://*.nextjs.org localhost:*;script-src 'self' 'unsafe-eval' 'unsafe-inline' www.google.com www.google-analytics.com www.googleadservices.com www.gstatic.com *.youtube.com *.youtube-nocookie.com *.ytimg.com *.twimg.com cdn.ampproject.org www.googletagmanager.com *.googleapis.com *.fides-cdn.ethyca.com *.ethyca.com cdn.ethyca.com cdn.vercel-insights.com va.vercel-scripts.com app.cal.com *.cr-relay.com vercel.com *.vercel.com *.vercel.sh vercel.live nextjs.org *.nextjs.org localhost:* chrome-extension://*;child-src *.youtube.com *.youtube-nocookie.com *.stripe.com www.google.com td.doubleclick.net github.com calendly.com vercel.cal.com nextjs.org *.nextjs.org vercel.com *.vercel.com *.vercel.sh vercel.live wss://*.vercel.com wss://*.nextjs.org localhost:*;style-src 'self' 'unsafe-inline' *.googleapis.com nextjs.org *.nextjs.org vercel.com *.vercel.com *.vercel.sh vercel.live wss://*.vercel.com wss://*.nextjs.org localhost:*;img-src * blob: data:;media-src 'self' videos.ctfassets.net user-images.githubusercontent.com replicate.delivery *.public.blob.vercel-storage.com blob: data: nextjs.org *.nextjs.org vercel.com *.vercel.com *.vercel.sh vercel.live wss://*.vercel.com wss://*.nextjs.org localhost:*;connect-src 'self' data: vercel.com *.vercel.com *.vercel.sh vercel.live wss://*.vercel.com wss://*.nextjs.org nextjs.org *.nextjs.org localhost:* cdn.vercel-insights.com va.vercel-scripts.com cdp.vercel.com www.google-analytics.com www.googletagmanager.com *.googleapis.com *.cr-relay.com *.ethyca.com cdn.ethyca.com risk.clearbit.com *.ingest.sentry.io *.ingest.us.sentry.io *.public.blob.vercel-storage.com;font-src 'self' *.nextjs.org *.vercel.com *.gstatic.com vercel.live *.vercel.sh;worker-src 'self' *.nextjs.org *.vercel.com blob:

    Fix: Tighten Content-Security-Policy by removing unsafe directives and adding object-src, base-uri, and frame-ancestors restrictions.

  • No first-party cookies were set during the initial page load.

  • Server response headers do not expose version tokens.

  • Domain does not appear to be behind Cloudflare.

  • Loaded in 0.26s (perceived).

  • 12 scripts and 4 styles may block rendering.

    • • script: https://nextjs.org/_next/static/immutable/chunks/0cz1d0mv5g_q7.js
    • • script: https://nextjs.org/_next/static/immutable/chunks/3naiw9r30l3sq.js
    • • script: https://nextjs.org/_next/static/immutable/chunks/1piwscmnml6dr.js
    • • script: https://nextjs.org/_next/static/immutable/chunks/029yj9jwf9t-3.js
    • • script: https://nextjs.org/_next/static/immutable/chunks/29rykfv-0k-89.js
    • • script: https://nextjs.org/_next/static/immutable/chunks/1sz98mwivpojj.js
    • • script: https://nextjs.org/_next/static/immutable/chunks/1k92giwg4zp7c.js
    • • script: https://nextjs.org/_next/static/immutable/chunks/2aqp278l7u5dk.js
    • • script: https://nextjs.org/_next/static/immutable/chunks/2z3qul9yl_m_9.js
    • • script: https://nextjs.org/_next/static/immutable/chunks/1inqx-h-2ajrc.js
    • • script: https://nextjs.org/_next/static/immutable/chunks/2fcpvdd1be_xb.js
    • • script: https://nextjs.org/_next/static/immutable/chunks/33722xztb-98i.js
    • • style: https://nextjs.org/_next/static/immutable/chunks/1-vhr6_0s4o77.css
    • • style: https://nextjs.org/_next/static/immutable/chunks/3-sarejflg6w8.css
    • • style: https://nextjs.org/_next/static/immutable/chunks/1psgp8jcpvsbd.css
    • • style: https://nextjs.org/_next/static/immutable/chunks/1ulxm8je42reo.css

    Fix: Defer non-critical scripts and inline critical CSS to improve first paint speed.

  • Compression Warning

    13 text resources look uncompressed.

    • • https://nextjs.org/_next/static/immutable/chunks/1ulxm8je42reo.css (text/css; charset=utf-8)
    • • https://nextjs.org/_next/static/immutable/chunks/3od2bp9x4j6of.js (application/javascript; charset=utf-8)
    • • https://nextjs.org/_next/static/immutable/chunks/3naiw9r30l3sq.js (application/javascript; charset=utf-8)
    • • https://nextjs.org/learn?_rsc=11c9m (text/x-component)
    • • https://nextjs.org/showcase?_rsc=11c9m (text/x-component)
    • • https://nextjs.org/blog?_rsc=11c9m (text/x-component)
    • • https://nextjs.org/api/stream/internal (application/json; charset=utf-8)
    • • https://nextjs.org/docs?_rsc=11c9m (text/x-component)
    • • https://nextjs.org/learn?utm_source=next-site&utm_medium=homepage-cta&utm_campaign=home&_rsc=11c9m (text/x-component)
    • • https://nextjs.org/_next/static/immutable/chunks/29rykfv-0k-89.js (application/javascript; charset=utf-8)
    • • https://nextjs.org/docs/app/getting-started/images?_rsc=11c9m (text/x-component)
    • • https://nextjs.org/docs/app/api-reference/file-conventions/loading?_rsc=11c9m (text/x-component)
    • • https://nextjs.org/docs/app/getting-started/server-and-client-components?_rsc=11c9m (text/x-component)

    Fix: Enable Brotli or Gzip compression for HTML, CSS, JS, and JSON responses.

  • Robots.txt Error

    robots.txt missing or inaccessible (404).

    Fix: Create a robots.txt file at https://nextjs.org/robots.txt and allow intended crawlers.

  • Found sitemap (200) at https://nextjs.org/sitemap.xml.

  • No robots meta tag defined.

    Fix: Add <meta name="robots" content="index,follow"> (or the intended directive) in <head>.

Accessibility Basics

  • All 1 controls are labeled.

  • Landmarks Pass

    Header, nav, main, and footer landmarks are present.

  • Tap Target Size Warning

    25 interactive elements appear smaller than 48px.

    • • a (Go to Vercel homepage) - 25x22px
    • • a.navbar-module__cV3TuW__logo (Go to the homepage) - 90x18px
    • • a (Showcase) - 69x23px
    • • a (Documentation) - 35x23px
    • • a (Blog) - 29x23px
    • • a (Templates) - 67x23px
    • • a (Enterprise) - 64x23px
    • • button.navbar-module__cV3TuW__search (Search documentation...CtrlK) - 251x32px
    • • a.outline-none.m-0 (Deploy) - 98x32px
    • • a.outline-none.m-0 (Learn) - 62x32px
    • • button.intro-module__l-DIkW__copy (Copy npx command for creating a new Next.js app) - 264x24px
    • • a.flex.flex-col (Vercel logo) - 101x20px
    • • a (Docs) - 35x20px
    • • a (Support Policy) - 95x20px
    • • a (Learn) - 35x20px
    • • a (Showcase) - 69x20px
    • • a (Blog) - 29x20px
    • • a (Team) - 35x20px
    • • a (Analytics) - 60x20px
    • • a (Next.js Conf) - 80x20px
    • • a (Previews) - 59x20px
    • • a (Evals) - 35x20px
    • • a (Next.js Commerce) - 117x20px
    • • a (Contact Sales) - 92x20px
    • • a (Community) - 72x20px

    Fix: Increase target size to at least 48x48 CSS pixels for touch interactions.

Social & Rich Results

  • Core Open Graph tags are present.

  • og:image is present and absolute.

    Open Graph Image
  • twitter:card set to summary_large_image.

  • Structured Data Warning

    No JSON-LD schema scripts found.

    Fix: Add JSON-LD structured data matching your page type (Organization, Article, Product, etc.).

  • PWA Metadata Warning

    Manifest or Apple touch icon is missing.

    Fix: Link your web app manifest and apple-touch-icon for improved install/share experiences.

  • 1 social preview quality issues detected.

    • • ISSUE: og:url should be an absolute URL.
    • • GUIDELINE: Optimal og:title length: 40-60 characters (acceptable: 10-70).
    • • GUIDELINE: Optimal og:description length: 110-160 characters (acceptable: 50-200).
    • • GUIDELINE: Optimal preview image size: 1200x630 pixels.
    • • GUIDELINE: Optimal preview image aspect ratio: 1.91:1.
    • • GUIDELINE: Optimal preview image file size: under 5 MB.
    • • GUIDELINE: Recommended twitter:card: summary_large_image.
    • • MEASURED: Image size: 0.57 MB
    • • MEASURED: Image dimensions: 2800x1600

    Fix: Use absolute OG/Twitter URLs, keep metadata lengths in recommended ranges, and provide a preview image near 1200x630 under 5MB.

Links Analysis

  • Checked 48 links. No broken internal links found.

  • External Links Warning

    2 external links returned errors or timed out.

    • • https://bsky.app/profile/nextjs.org (HTTP 404)
    • • https://bsky.app/profile/vercel.com (HTTP 404)

    Fix: Replace dead external URLs or point to working alternatives.

  • All 97 links use non-empty href values.

Performance & Runtime

  • Largest Contentful Paint: 0.26s.

  • Cumulative Layout Shift: 0.000.

  • Total Blocking Time estimate: 50ms.

  • No failed CSS/JS/image/font/media requests detected.

  • 3 JavaScript runtime issues detected.

    • • Request failed: https://nextjs.org/api/get-session (HTTP 401, type: fetch)
    • • Failed to load resource: the server responded with a status of 401 () [https://nextjs.org/api/get-session:1]
    • • Failed to load resource: the server responded with a status of 403 () [https://api.cr-relay.com/v1/site/f6dd8ada-7a97-4d9d-8ec4-9c2bff6cd234/batch:1]

    Fix: Fix JS files returning 404/failed requests and resolve the listed runtime exceptions.