Audit Result
UUID: 019e249c-91a8-7016-ae77-7fe6e3ad717f
https://gpx.sh/
Scanned 3 months ago
Meta Information
-
Title Tag Pass
Found 43 characters. Length is optimal.
-
Meta Description Pass
Found 142 characters. Good snippet length.
-
Canonical URL Pass
Canonical found: https://gpx.sh
-
-
Viewport Meta Pass
Viewport configured: width=device-width, initial-scale=1
-
HTML Lang Pass
Language declared as "en".
Content Structure
-
H1 Tag Warning
Found 2 H1 tags.
Fix: Use a single, descriptive <h1> that states the primary purpose of the page.
-
Heading Hierarchy Warning
Detected 1 heading level jumps.
- • Skipped from h2 to h6: "Subscribe to Our Newsletter" -> "Pages".
Fix: Follow semantic order (h1 -> h2 -> h3) and avoid skipping heading levels.
-
Image Alt Text Pass
All 3 images include alt text.
Technical Optimization
-
HTTPS Pass
Page is served over HTTPS.
-
HSTS & HTTPS Redirect Warning
2 HTTPS hardening issues detected.
- • Missing Strict-Transport-Security header.
- • Could not probe the HTTP version of this page.
Fix: Set Strict-Transport-Security with a long max-age, add includeSubDomains, and redirect all HTTP requests to HTTPS.
-
Security Headers Warning
Missing: strict-transport-security, content-security-policy, referrer-policy.
Full HTTP headers (10)
- • cache-control: no-cache, private
- • connection: keep-alive
- • content-encoding: gzip
- • content-type: text/html; charset=utf-8
- • date: Thu, 14 May 2026 03:51:37 GMT
- • server: nginx/1.24.0 (Ubuntu)
- • transfer-encoding: chunked
- • x-content-type-options: nosniff
- • x-frame-options: SAMEORIGIN
- • x-xss-protection: 1; mode=block
Fix: Add the missing security headers at your reverse proxy or application layer.
-
CSP Quality Warning
Content-Security-Policy header is missing.
- • Missing Content-Security-Policy header.
Fix: Define a restrictive Content-Security-Policy and avoid unsafe directives such as unsafe-inline and unsafe-eval.
-
Cookie Security Pass
No first-party cookies were set during the initial page load.
-
Server Version Disclosure Warning
Versioned headers detected: server.
- • server: nginx/1.24.0 (Ubuntu)
Fix: Hide or remove version tokens in Server and X-Powered-By headers.
-
Cloudflare Proxy Warning
Domain does not appear to be behind Cloudflare.
-
Perceived Load Time Pass
Loaded in 0.89s (perceived).
-
Render Blocking Resources Warning
0 scripts and 2 styles may block rendering.
- • style: https://gpx.sh/build/assets/admin-DIFkxn47.css
- • style: https://gpx.sh/build/assets/site-BenvJait.css
Fix: Defer non-critical scripts and inline critical CSS to improve first paint speed.
-
Compression Warning
2 text resources look uncompressed.
- • https://matomo.alexmos.ro/matomo.js (application/javascript)
- • https://matomo.alexmos.ro/matomo.php?action_name=Store%2C%20Edit%20%26%20Share%20Your%20GPX%20Files%20%7C%20GPX.sh&idsite=1&rec=1&r=862969&h=5&m=51&s=38&url=https%3A%2F%2Fgpx.sh%2F&_id=1c8d04b3e9ebe90e&_idn=1&send_image=0&_refts=0&dimension1=website&pv_id=qPrbLz&pf_net=307&pf_srv=129&pf_tfr=3&pf_dm1=412&uadata=%7B%22formFactors%22%3A%5B%22Desktop%22%5D%2C%22fullVersionList%22%3A%5B%7B%22brand%22%3A%22Not%3AA-Brand%22%2C%22version%22%3A%2299.0.0.0%22%7D%2C%7B%22brand%22%3A%22HeadlessChrome%22%2C%22version%22%3A%22145.0.7632.6%22%7D%2C%7B%22brand%22%3A%22Chromium%22%2C%22version%22%3A%22145.0.7632.6%22%7D%5D%2C%22mobile%22%3Afalse%2C%22model%22%3A%22%22%2C%22platform%22%3A%22Linux%22%2C%22platformVersion%22%3A%22%22%7D&cookie=1&res=1280x800 (text/html; charset=UTF-8)
Fix: Enable Brotli or Gzip compression for HTML, CSS, JS, and JSON responses.
-
Robots.txt Pass
Found robots.txt (200).
-
Sitemap File Pass
Found sitemap (200) at https://gpx.sh/sitemap.xml.
-
Crawl Directives Warning
No robots meta tag defined.
Fix: Add <meta name="robots" content="index,follow"> (or the intended directive) in <head>.
Accessibility Basics
-
Form Labels Error
1 of 1 controls are missing labels.
- • input[type="email"].form-control.form-control-lg (email)
Fix: Associate each form control with a visible label, aria-label, or aria-labelledby.
-
Landmarks Warning
Missing landmarks: nav, main.
Fix: Use semantic regions (<header>, <nav>, <main>, <footer>) for navigation and assistive tech.
-
Tap Target Size Warning
14 interactive elements appear smaller than 48px.
- • a.logo-box (<GPX.sh) - 90x41px
- • a.nav-link.active (Home) - 89x40px
- • a.nav-link (Documentation) - 146x40px
- • a.nav-link (Pricing) - 95x40px
- • a.nav-link (Apps) - 84x40px
- • a.nav-link (Log in) - 62x40px
- • a.btn (Sign up) - 81x40px
- • a.logo-box (<GPX.sh) - 90x41px
- • a.link-secondary.text-decoration-none (X (Twitter)) - 20x23px
- • a.link-secondary.text-decoration-none (Facebook) - 20x23px
- • a.link-secondary.text-decoration-none (Reddit) - 20x23px
- • a.link-secondary.text-decoration-none (YouTube) - 20x23px
- • a.link-secondary.text-decoration-none (Enable dark mode) - 20x23px
- • button.btn.btn-primary (Accept) - 356x40px
Fix: Increase target size to at least 48x48 CSS pixels for touch interactions.
Social & Rich Results
-
Open Graph Basics Pass
Core Open Graph tags are present.
-
-
Twitter Card Pass
twitter:card set to summary_large_image.
-
Structured Data Pass
JSON-LD schema detected.
-
PWA Metadata Pass
Manifest and Apple touch icon are configured.
-
Social preview metadata and image quality look good for Open Graph/Twitter.
- • GUIDELINE: Optimal og:title length: 40-60 characters (acceptable: 10-70).
- • GUIDELINE: Optimal og:description length: 110-160 characters (acceptable: 50-200).
- • GUIDELINE: Optimal preview image size: 1200x630 pixels.
- • GUIDELINE: Optimal preview image aspect ratio: 1.91:1.
- • GUIDELINE: Optimal preview image file size: under 5 MB.
- • GUIDELINE: Recommended twitter:card: summary_large_image.
- • MEASURED: Image size: 0.79 MB
- • MEASURED: Image dimensions: 1200x630
Links Analysis
-
Internal Links Pass
Checked 12 links. No broken internal links found.
-
External Links Pass
No broken external links found in checked URLs.
-
Link Format Warning
6 links are empty, invalid, or placeholder-only.
- • href="#"
- • href="#"
- • href="#"
- • href="#"
- • href="#"
- • href="#"
Fix: Replace empty/#/javascript href values with real destinations or use buttons for non-navigation actions.
Performance & Runtime
-
Core Web Vitals: LCP Pass
Largest Contentful Paint: 0.96s.
-
Core Web Vitals: CLS Pass
Cumulative Layout Shift: 0.000.
-
Total Blocking Time estimate: 43ms.
-
Broken Assets Pass
No failed CSS/JS/image/font/media requests detected.
-
No console/page runtime errors detected during audit.