Audit Result
UUID: 019e8bf0-ce12-7137-bd1b-156d1bd77e1f
https://www.figma.com/proto/pdQSbKk5IEQ8sp9WdUDAA8/EF-Figma-Updated?node-id=13035-15791&viewport=-8477%2C-9611%2C0.46&t=oYdbbq39wEDZhPSs-1&scaling=min-zoom&content-scaling=fixed&starting-point-node-id=11508%3A54602&page-id=11193%3A44319&hide-ui=1
Scanned 3 months ago
Meta Information
-
Title Tag Warning
Found 21 characters. Keep title between 30 and 60 characters.
Fix: Add a unique <title> tag describing the main page intent in 30-60 characters.
-
Meta Description Warning
Found 18 characters. Keep description around 70-160 characters.
Fix: Add <meta name="description" content="..."> in <head> with a clear page summary.
-
Canonical URL Warning
Canonical link not found.
Fix: Add <link rel="canonical" href="https://example.com/page"> to avoid duplicate URL ambiguity.
-
Favicon Pass
Favicon found and reachable: https://static.figma.com/uploads/1a667ef53b7c4837049399d0593ffca39e0bec9e (HTTP 200).
-
Viewport Meta Pass
Viewport configured: initial-scale=1.0, minimum-scale=1.0, maximum-scale=1.0, user-scalable=no
-
HTML Lang Pass
Language declared as "en".
Content Structure
-
H1 Tag Pass
Exactly one H1 found: "EF-Figma-Updated".
-
Heading Hierarchy Pass
Valid heading flow across 1 headings.
-
Image Alt Text Pass
All 0 images include alt text.
Technical Optimization
-
HTTPS Pass
Page is served over HTTPS.
-
HSTS & HTTPS Redirect Warning
1 HTTPS hardening issues detected.
- • Could not probe the HTTP version of this page.
- • Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Fix: Set Strict-Transport-Security with a long max-age, add includeSubDomains, and redirect all HTTP requests to HTTPS.
-
Security Headers Pass
Core security headers were detected.
Full HTTP headers (21)
- • alt-svc: h3=":443"; ma=86400
- • cache-control: private, no-store
- • content-encoding: br
- • content-security-policy: script-src 'wasm-unsafe-eval' 'nonce-zkNMYDDd8GrOZYQV7ICAcA==' 'strict-dynamic' 'report-sample' 'unsafe-eval' ; style-src 'self' 'unsafe-inline' https://www.figma.com/webpack-artifacts/ https://fonts.googleapis.com/ https://accounts.google.com/gsi/style https://cdnjs.cloudflare.com/ajax/libs/materialize/1.0.0/css/materialize.min.css ; worker-src 'self' blob: ; object-src 'none' ; base-uri 'self' ; form-action https://www.figma.com/exit ; frame-ancestors 'self' vscode-webview: vscode-file: , script-src 'self' https://www.figma.com/ 'wasm-unsafe-eval' 'unsafe-inline' 'report-sample' 'unsafe-eval' https://admin.figma.com/admin/webpack-artifacts/ https://figma-private-data.s3.us-west-2.amazonaws.com/webpack-artifacts/ blob: https://accounts.google.com/gsi/client https://static.figma.com/fullscreen/ https://static.figma.com/uploads/539fd13ba437049b058e7e83fd54539c86878320 https://static.figma.com/uploads/0706b46bdc09a419282285b791ea1dd3c019ecd6 https://static.figma.com/scripts/ https://static.zdassets.com https://ekr.zdassets.com https://assets.zendesk.com/apps/sdk/2.0/zaf_sdk.js https://js.stripe.com https://statics.teams.cdn.office.net/sdk/v1.6.0/js/MicrosoftTeams.min.js https://res.cdn.office.net/teams-js/2.48.1/js/MicrosoftTeams.min.js https://alcdn.msauth.net/browser/2.21.0/js/msal-browser.min.js https://apis.google.com/ https://adora-cdn.com/adora-start.js ; worker-src 'self' blob:
- • content-security-policy-report-only: form-action https://www.figma.com/exit ; report-uri https://o22594.ingest.us.sentry.io/api/4508218677329920/security/?sentry_key=f2dd23d3c297716fae09358359456334&sentry_environment=prod&sentry_release=form_action
- • content-type: text/html;charset=utf-8
- • date: Wed, 03 Jun 2026 05:24:23 GMT
- • referrer-policy: origin-when-cross-origin
- • report-to: {"group":"default", "max_age":604800, "endpoints":[{"url":"https://www.figma.com/api/web_logger/browser_report?tsid=TTB0JpqW3JWOBIKs"}], "include_subdomains":true}
- • reporting-endpoints: default="https://www.figma.com/api/web_logger/browser_report?tsid=TTB0JpqW3JWOBIKs"
- • server-timing: cdn-upstream-layer;desc="EDGE",cdn-upstream-dns;dur=0,cdn-upstream-connect;dur=0,cdn-upstream-fbl;dur=505,proxyq;dur=4.96,app;dur=430.28;desc="id:s",streamed;desc="1",proxy;dur=439,cdn-cache-miss,cdn-pop;desc="IAD55-P1",cdn-rid;desc="ur-ZniFmkX-25JE2KDe_qYBSIhwBuhnl8Z5L7MSgVRpTE2U2ty6XZA==",cdn-downstream-fbl;dur=507
- • strict-transport-security: max-age=31536000; includeSubDomains; preload
- • vary: Accept-Encoding
- • via: 1.1 8bf94e29f889f8d0076c4502ae008b58.cloudfront.net (CloudFront)
- • x-amz-cf-id: ur-ZniFmkX-25JE2KDe_qYBSIhwBuhnl8Z5L7MSgVRpTE2U2ty6XZA==
- • x-amz-cf-pop: IAD55-P1
- • x-cache: Miss from cloudfront
- • x-content-type-options: nosniff
- • x-frame-options: SAMEORIGIN
- • x-preload-streaming: true
- • x-robots-tag: noindex
-
CSP Quality Error
1 CSP hardening issues detected.
- • script-src/default-src permits 'unsafe-eval'.
- • Content-Security-Policy: script-src 'wasm-unsafe-eval' 'nonce-zkNMYDDd8GrOZYQV7ICAcA==' 'strict-dynamic' 'report-sample' 'unsafe-eval' ; style-src 'self' 'unsafe-inline' https://www.figma.com/webpack-artifacts/ https://fonts.googleapis.com/ https://accounts.google.com/gsi/style https://cdnjs.cloudflare.com/ajax/libs/materialize/1.0.0/css/materialize.min.css ; worker-src 'self' blob: ; object-src 'none' ; base-uri 'self' ; form-action https://www.figma.com/exit ; frame-ancestors 'self' vscode-webview: vscode-file: , script-src 'self' https://www.figma.com/ 'wasm-unsafe-eval' 'unsafe-inline' 'report-sample' 'unsafe-eval' https://admin.figma.com/admin/webpack-artifacts/ https://figma-private-data.s3.us-west-2.amazonaws.com/webpack-artifacts/ blob: https://accounts.google.com/gsi/client https://static.figma.com/fullscreen/ https://static.figma.com/uploads/539fd13ba437049b058e7e83fd54539c86878320 https://static.figma.com/uploads/0706b46bdc09a419282285b791ea1dd3c019ecd6 https://static.figma.com/scripts/ https://static.zdassets.com https://ekr.zdassets.com https://assets.zendesk.com/apps/sdk/2.0/zaf_sdk.js https://js.stripe.com https://statics.teams.cdn.office.net/sdk/v1.6.0/js/MicrosoftTeams.min.js https://res.cdn.office.net/teams-js/2.48.1/js/MicrosoftTeams.min.js https://alcdn.msauth.net/browser/2.21.0/js/msal-browser.min.js https://apis.google.com/ https://adora-cdn.com/adora-start.js ; worker-src 'self' blob:
Fix: Tighten Content-Security-Policy by removing unsafe directives and adding object-src, base-uri, and frame-ancestors restrictions.
-
Cookie Security Pass
No first-party cookies were set during the initial page load.
-
Server response headers do not expose version tokens.
-
Cloudflare Proxy Warning
Domain does not appear to be behind Cloudflare.
-
Perceived Load Time Error
Loaded in 4.14s (perceived).
Fix: Reduce payload size, cache static assets, and remove non-critical JS from initial load.
-
Render Blocking Resources Warning
0 scripts and 1 styles may block rendering.
- • style: https://www.figma.com/webpack-artifacts/assets/prototype_app-aa09c4fe94594d77.min.css.br
Fix: Defer non-critical scripts and inline critical CSS to improve first paint speed.
-
Compression Warning
6 text resources look uncompressed.
- • https://www.figma.com/api/figment-proxy/page (text/plain; charset=utf-8)
- • https://www.figma.com/api/figment-proxy/monitor (text/plain; charset=utf-8)
- • https://s3-figma-force-client-reloads-production.figma.com/periodic_refresh.json (application/json)
- • https://www.figma.com/api/web_logger/metrics/session_start (text/plain; charset=utf-8)
- • https://www.figma.com/api/web_logger/metrics/page_load (text/plain; charset=utf-8)
- • https://api.sprig.com/sdk/1/environments/YWwyCyGyqg/config (application/json; charset=utf-8)
Fix: Enable Brotli or Gzip compression for HTML, CSS, JS, and JSON responses.
-
Robots.txt Pass
Found robots.txt (200).
-
Sitemap File Pass
Found sitemap (200) at https://www.figma.com/sitemap.xml.
-
Crawl Directives Warning
No robots meta tag defined.
Fix: Add <meta name="robots" content="index,follow"> (or the intended directive) in <head>.
Accessibility Basics
-
Form Labels Pass
All 1 controls are labeled.
-
Landmarks Warning
Missing landmarks: header, footer.
Fix: Use semantic regions (<header>, <nav>, <main>, <footer>) for navigation and assistive tech.
-
Tap Target Size Warning
12 interactive elements appear smaller than 48px.
- • button.header--animatedAccessibilityDomButton--xnqJi.basic_form--primaryBtn--abwtN (Skip to content) - 98x24px
- • a._14d74zf0 (File browser) - 12x18px
- • button._19xx72g0.header--flowsButton--CW4x3 (Open flows list) - 48x46px
- • button._19xx72g0.header--commentsButton--WSz6c (Comment) - 48x46px
- • button._19xx72g0.button__button__-U-QJ (Log in or create account) - 157x32px
- • button._19xx72g0.google_sso_button--button--dhMOw (Continue with Google) - 159x32px
- • button#:r5:._19xx72g0.header--optionsMenuButton--S22Rz (Options) - 48x46px
- • button._19xx72g0.header--fullScreenButton--VCrpX (Enter full screen (F)) - 48x46px
- • button._19xx72g0.button__button__-U-QJ (Opt out) - 55x24px
- • button - 32x32px
- • button._19xx72g0.button__button__-U-QJ (Learn more) - 77x24px
- • button._19xx72g0.base-icon-button__baseIconButton__TXKzr (Dismiss) - 24x24px
Fix: Increase target size to at least 48x48 CSS pixels for touch interactions.
Social & Rich Results
-
Open Graph Basics Pass
Core Open Graph tags are present.
-
Open Graph Image Error
og:image URL returned HTTP 404.
Fix: Make sure the og:image URL returns HTTP 200 and points to a publicly accessible image.
-
Twitter Card Pass
twitter:card set to player.
-
Structured Data Warning
No JSON-LD schema scripts found.
Fix: Add JSON-LD structured data matching your page type (Organization, Article, Product, etc.).
-
PWA Metadata Warning
Manifest or Apple touch icon is missing.
Fix: Link your web app manifest and apple-touch-icon for improved install/share experiences.
-
Open Graph/Twitter Quality Warning
5 social preview quality issues detected.
- • ISSUE: og:title should typically be between 10 and 70 characters.
- • ISSUE: og:description should typically be between 50 and 200 characters.
- • ISSUE: Preview image is below recommended size (1200x630).
- • ISSUE: Preview image aspect ratio (2.57) differs from the recommended ~1.91:1.
- • ISSUE: twitter:card should be summary_large_image for richer previews.
- • GUIDELINE: Optimal og:title length: 40-60 characters (acceptable: 10-70).
- • GUIDELINE: Optimal og:description length: 110-160 characters (acceptable: 50-200).
- • GUIDELINE: Optimal preview image size: 1200x630 pixels.
- • GUIDELINE: Optimal preview image aspect ratio: 1.91:1.
- • GUIDELINE: Optimal preview image file size: under 5 MB.
- • GUIDELINE: Recommended twitter:card: summary_large_image.
- • MEASURED: Image size: 0.02 MB
- • MEASURED: Image dimensions: 800x311
Fix: Use absolute OG/Twitter URLs, keep metadata lengths in recommended ranges, and provide a preview image near 1200x630 under 5MB.
Links Analysis
-
Internal Links Pass
Checked 2 links. No broken internal links found.
-
External Links Pass
No broken external links found in checked URLs.
-
Link Format Pass
All 6 links use non-empty href values.
Performance & Runtime
-
Core Web Vitals: LCP Error
Largest Contentful Paint: 4.14s.
Fix: Improve LCP by optimizing above-the-fold media, reducing server latency, and inlining critical CSS.
-
Core Web Vitals: CLS Pass
Cumulative Layout Shift: 0.016.
-
Total Blocking Time estimate: 6704ms.
Fix: Reduce heavy JavaScript work, split long tasks, and defer non-critical scripts.
-
Broken Assets Pass
No failed CSS/JS/image/font/media requests detected.
-
JavaScript Runtime Errors Warning
3 JavaScript runtime issues detected.
- • Request failed: https://www.figma.com/api/statsig/v1_ruleset (HTTP 401, type: xhr)
- • Failed to load resource: the server responded with a status of 401 () [https://www.figma.com/api/statsig/v1_ruleset:1]
- • Failed to fetch v1 ruleset: w: XHR for "/api/statsig/v1_ruleset" failed with status 401 at P (https://www.figma.com/webpack-artifacts/assets/3835-526626f3c5ac9623.min.js.br:1445:11072) at async Object.O [as get] (https://www.figma.com/webpack-artifacts/assets/3835-526626f3c5ac9623.min.js.br:1445:11454) at async https://www.figma.com/webpack-artifacts/assets/8859-71fa23500d99f03f.min.js.br:117:94890 at async g.validate (https://www.figma.com/webpack-artifacts/assets/3835-526626f3c5ac9623.min.js.br:1425:5067) at async b (https://www.figma.com/webpack-artifacts/assets/3835-526626f3c5ac9623.min.js.br:1406:177686) at async A (https://www.figma.com/webpack-artifacts/assets/3835-526626f3c5ac9623.min.js.br:1406:176890) at async Object.write (https://www.figma.com/webpack-artifacts/assets/3835-526626f3c5ac9623.min.js.br:1406:176509) [https://www.figma.com/webpack-artifacts/assets/vendor-core-5a58dfb552452d49.min.js.br:54]
Fix: Fix JS files returning 404/failed requests and resolve the listed runtime exceptions.