Audit Result
UUID: 019f8f43-f407-72ae-a0c2-14f6b878c423
https://github.com/
Scanned 1 month ago
Meta Information
-
Title Tag Warning
Found 61 characters. Keep title between 30 and 60 characters.
Fix: Add a unique <title> tag describing the main page intent in 30-60 characters.
-
Meta Description Warning
Found 186 characters. Keep description around 70-160 characters.
Fix: Add <meta name="description" content="..."> in <head> with a clear page summary.
-
Canonical URL Pass
Canonical found: https://github.com
-
Favicon Pass
Favicon found and reachable: https://github.githubassets.com/favicons/favicon.png (HTTP 200).
-
Viewport Meta Pass
Viewport configured: width=device-width
-
HTML Lang Pass
Language declared as "en".
Content Structure
-
H1 Tag Warning
Found 4 H1 tags.
Fix: Use a single, descriptive <h1> that states the primary purpose of the page.
-
Heading Hierarchy Warning
Detected 1 heading level jumps.
- • Skipped from h1 to h3: "Search code, repositories, users, issues, pull requests..." -> "Explore".
Fix: Follow semantic order (h1 -> h2 -> h3) and avoid skipping heading levels.
-
Image Alt Text Error
17 of 24 images are missing alt text.
Fix: Add meaningful alt attributes to all informative images for accessibility and image SEO.
Technical Optimization
-
HTTPS Pass
Page is served over HTTPS.
-
HSTS & HTTPS Redirect Warning
1 HTTPS hardening issues detected.
- • Could not probe the HTTP version of this page.
- • Strict-Transport-Security: max-age=31536000; includeSubdomains; preload
Fix: Set Strict-Transport-Security with a long max-age, add includeSubDomains, and redirect all HTTP requests to HTTPS.
-
Security Headers Pass
Core security headers were detected.
Full HTTP headers (16)
- • accept-ranges: bytes
- • cache-control: max-age=0, private, must-revalidate
- • content-encoding: gzip
- • content-language: en-US
- • content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com github.githubassets.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net productionresultssa1.blob.core.windows.net productionresultssa2.blob.core.windows.net productionresultssa3.blob.core.windows.net productionresultssa4.blob.core.windows.net productionresultssa5.blob.core.windows.net productionresultssa6.blob.core.windows.net productionresultssa7.blob.core.windows.net productionresultssa8.blob.core.windows.net productionresultssa9.blob.core.windows.net productionresultssa10.blob.core.windows.net productionresultssa11.blob.core.windows.net productionresultssa12.blob.core.windows.net productionresultssa13.blob.core.windows.net productionresultssa14.blob.core.windows.net productionresultssa15.blob.core.windows.net productionresultssa16.blob.core.windows.net productionresultssa17.blob.core.windows.net productionresultssa18.blob.core.windows.net productionresultssa19.blob.core.windows.net github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com wss://alive-staging.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com wss://production-copilot-host.webpubsub.azure.com edge.fullstory.com rs.fullstory.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com www.youtube-nocookie.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com user-images.githubusercontent.com private-user-images.githubusercontent.com opengraph.githubassets.com marketplace-screenshots.githubusercontent.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com explore-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com images.ctfassets.net/8aevphvgewt8/; manifest-src 'self'; media-src github.com user-images.githubusercontent.com secured-user-images.githubusercontent.com private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com github.githubassets.com assets.ctfassets.net/8aevphvgewt8/ videos.ctfassets.net/8aevphvgewt8/; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
- • content-type: text/html; charset=utf-8
- • date: Thu, 23 Jul 2026 13:56:36 GMT
- • etag: W/"e794c4fe6828eea13bea5b5d2156fac3"
- • referrer-policy: origin-when-cross-origin, strict-origin-when-cross-origin
- • server: github.com
- • strict-transport-security: max-age=31536000; includeSubdomains; preload
- • vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With, Accept-Language, Sec-Fetch-Site,Accept-Encoding, Accept, X-Requested-With
- • x-content-type-options: nosniff
- • x-frame-options: deny
- • x-github-request-id: C456:326558:289CD6:3A6F25:6A621D9B
- • x-xss-protection: 0
-
CSP Quality Warning
1 CSP hardening issues detected.
- • CSP is missing object-src 'none'.
- • Content-Security-Policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com github.githubassets.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net productionresultssa1.blob.core.windows.net productionresultssa2.blob.core.windows.net productionresultssa3.blob.core.windows.net productionresultssa4.blob.core.windows.net productionresultssa5.blob.core.windows.net productionresultssa6.blob.core.windows.net productionresultssa7.blob.core.windows.net productionresultssa8.blob.core.windows.net productionresultssa9.blob.core.windows.net productionresultssa10.blob.core.windows.net productionresultssa11.blob.core.windows.net productionresultssa12.blob.core.windows.net productionresultssa13.blob.core.windows.net productionresultssa14.blob.core.windows.net productionresultssa15.blob.core.windows.net productionresultssa16.blob.core.windows.net productionresultssa17.blob.core.windows.net productionresultssa18.blob.core.windows.net productionresultssa19.blob.core.windows.net github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com wss://alive-staging.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com wss://production-copilot-host.webpubsub.azure.com edge.fullstory.com rs.fullstory.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com www.youtube-nocookie.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com user-images.githubusercontent.com private-user-images.githubusercontent.com opengraph.githubassets.com marketplace-screenshots.githubusercontent.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com explore-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com images.ctfassets.net/8aevphvgewt8/; manifest-src 'self'; media-src github.com user-images.githubusercontent.com secured-user-images.githubusercontent.com private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com github.githubassets.com assets.ctfassets.net/8aevphvgewt8/ videos.ctfassets.net/8aevphvgewt8/; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
Fix: Tighten Content-Security-Policy by removing unsafe directives and adding object-src, base-uri, and frame-ancestors restrictions.
-
Cookie Security Pass
No first-party cookies were set during the initial page load.
-
Server response headers do not expose version tokens.
-
Cloudflare Proxy Warning
Domain does not appear to be behind Cloudflare.
-
Perceived Load Time Pass
Loaded in 0.68s (perceived).
-
Render Blocking Resources Warning
0 scripts and 36 styles may block rendering.
- • style: https://github.githubassets.com/assets/light-62b06818b06b09b7.css
- • style: https://github.githubassets.com/assets/light_high_contrast-44cd405df9340c5c.css
- • style: https://github.githubassets.com/assets/dark-f3311053b052c5d4.css
- • style: https://github.githubassets.com/assets/dark_high_contrast-6739a26cef6aaf8e.css
- • style:
- • style:
- • style:
- • style:
- • style:
- • style:
- • style:
- • style:
- • style:
- • style:
- • style:
- • style:
- • style:
- • style:
- • style: https://github.githubassets.com/assets/primer-primitives-ac2f4b33720c6312.css
- • style: https://github.githubassets.com/assets/primer-bb3e7caff8347285.css
- • style: https://github.githubassets.com/assets/global-1832d803adebd2b4.css
- • style: https://github.githubassets.com/assets/github-cf976967feea1e66.css
- • style: https://github.githubassets.com/assets/site-2d78c5de4a31d86e.css
- • style: https://github.githubassets.com/assets/landing-pages-44288f2c24a4c584.css
- • style: https://github.githubassets.com/assets/home-9b7c451c90b8cd38.css
- • style: https://github.githubassets.com/assets/app-runtime.f5d0397a71a59372.module.css
- • style: https://github.githubassets.com/assets/react-core.893b53f4d8f6405e.module.css
- • style: https://github.githubassets.com/assets/primer-react-css.95404c9a99044c2c.module.css
- • style: https://github.githubassets.com/assets/primer-react-brand-css.0cc680e6bbf87b2a.module.css
- • style: https://github.githubassets.com/assets/11446.3bcc560539372da7.module.css
- • style: https://github.githubassets.com/assets/landing-pages.055173c315f196cc.module.css
- • style: https://github.githubassets.com/assets/38963.81abdfe60a846dd2.module.css
- • style: https://github.githubassets.com/assets/7309.9a4bca2d3233306a.module.css
- • style: https://github.githubassets.com/assets/37220.2ba3f34ad1fd6072.module.css
- • style: https://github.githubassets.com/assets/70168.7c9fe30e36b6fd8b.module.css
- • style: https://github.githubassets.com/assets/86851.7d0dfed3614c981f.module.css
Fix: Defer non-critical scripts and inline critical CSS to improve first paint speed.
-
Compression Pass
Text-like assets appear compressed.
-
Robots.txt Pass
Found robots.txt (200).
-
Sitemap File Warning
Sitemap missing or inaccessible at https://github.com/sitemap.xml (406).
Fix: Publish a sitemap.xml and reference it in robots.txt with: Sitemap: https://github.com/sitemap.xml
-
Crawl Directives Warning
No robots meta tag defined.
Fix: Add <meta name="robots" content="index,follow"> (or the intended directive) in <head>.
Accessibility Basics
-
Form Labels Error
1 of 7 controls are missing labels.
- • textarea#feedback.form-control.width-full (feedback)
Fix: Associate each form control with a visible label, aria-label, or aria-labelledby.
-
Landmarks Pass
Header, nav, main, and footer landmarks are present.
-
Tap Target Size Warning
25 interactive elements appear smaller than 48px.
- • a.px-2.tmp-py-4 (Skip to content) - 1x1px
- • a.tmp-mr-lg-3.color-fg-inherit (Homepage) - 32x36px
- • button.NavDropdown-module__button__PEHWX.js-details-target (Platform) - 101x40px
- • button.NavDropdown-module__button__PEHWX.js-details-target (Solutions) - 105x40px
- • button.NavDropdown-module__button__PEHWX.js-details-target (Resources) - 114x40px
- • button.NavDropdown-module__button__PEHWX.js-details-target (Open Source) - 131x40px
- • button.NavDropdown-module__button__PEHWX.js-details-target (Enterprise) - 110x40px
- • a.NavLink-module__link__EG3d4.MarketingNavigation-module__navLink__hUomM (Pricing) - 65x40px
- • button.header-search-button.placeholder (Search or jump to…) - 30x30px
- • a.HeaderMenu-link.HeaderMenu-link--sign-in (Sign in) - 67x32px
- • a.HeaderMenu-link.HeaderMenu-link--sign-up (Sign up) - 73x32px
- • button.PlayButton (Pause) - 44x44px
- • button.Toggle-button.Toggle-button--selected (Code) - 130x40px
- • button.Toggle-button (Plan) - 130x40px
- • button.Toggle-button (Collaborate) - 130x40px
- • button.Toggle-button (Automate) - 130x40px
- • button.Toggle-button (Secure) - 130x40px
- • button.Primer_Brand__LogoSuite-module__LogoSuite__logobar-playPauseButton___KDfie (Pause animation) - 32x32px
- • button.PlayButton (Pause video) - 44x44px
- • a.Primer_Brand__Link-module__Link___lF11y.Primer_Brand__Link-module__Link--accent___eC6rQ (Explore GitHub Copilot) - 212x29px
- • a.Primer_Brand__Link-module__Link___lF11y.Primer_Brand__Link-module__Link--accent___eC6rQ (Read customer story) - 196x29px
- • a.Primer_Brand__Link-module__Link___lF11y.Primer_Brand__Link-module__Link--accent___eC6rQ (Read industry report) - 192x29px
- • button.lp-AccordionDisclosure (Automate your path to production) - 544x31px
- • a.Primer_Brand__Link-module__Link___lF11y.Primer_Brand__Link-module__Link--accent___eC6rQ (Explore GitHub Actions) - 215x29px
- • button.lp-AccordionDisclosure (Code instantly from anywhere) - 544x31px
Fix: Increase target size to at least 48x48 CSS pixels for touch interactions.
Social & Rich Results
-
Open Graph Basics Pass
Core Open Graph tags are present.
-
-
Twitter Card Pass
twitter:card set to summary_large_image.
-
Structured Data Warning
No JSON-LD schema scripts found.
Fix: Add JSON-LD structured data matching your page type (Organization, Article, Product, etc.).
-
PWA Metadata Warning
Manifest or Apple touch icon is missing.
Fix: Link your web app manifest and apple-touch-icon for improved install/share experiences.
-
Social preview metadata and image quality look good for Open Graph/Twitter.
- • GUIDELINE: Optimal og:title length: 40-60 characters (acceptable: 10-70).
- • GUIDELINE: Optimal og:description length: 110-160 characters (acceptable: 50-200).
- • GUIDELINE: Optimal preview image size: 1200x630 pixels.
- • GUIDELINE: Optimal preview image aspect ratio: 1.91:1.
- • GUIDELINE: Optimal preview image file size: under 5 MB.
- • GUIDELINE: Recommended twitter:card: summary_large_image.
- • MEASURED: Image size: 0.59 MB
- • MEASURED: Image dimensions: 1200x630
Links Analysis
-
Internal Links Error
2 internal links returned errors.
- • https://github.com/marketplace (HTTP 400)
- • https://github.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F&source=header-home (HTTP 403)
Fix: Fix or remove the listed internal URLs, and ensure routes/pages return 200 responses.
-
External Links Warning
2 external links returned errors or timed out.
- • https://support.github.com/ (HTTP 403)
- • https://www.gartner.com/reprints/?id=1-2LVTG7RP&ct=250915&st=sb (HTTP 403)
Fix: Replace dead external URLs or point to working alternatives.
-
Link Format Warning
3 links are empty, invalid, or placeholder-only.
- • href="(empty)" text="Reload"
- • href="(empty)" text="Reload"
- • href="(empty)" text="Reload"
Fix: Replace empty/#/javascript href values with real destinations or use buttons for non-navigation actions.
Performance & Runtime
-
Core Web Vitals: LCP Pass
Largest Contentful Paint: 0.68s.
-
Core Web Vitals: CLS Pass
Cumulative Layout Shift: 0.002.
-
Total Blocking Time estimate: 2901ms.
Fix: Reduce heavy JavaScript work, split long tasks, and defer non-critical scripts.
-
Broken Assets Pass
No failed CSS/JS/image/font/media requests detected.
-
JavaScript Runtime Errors Warning
1 JavaScript runtime issues detected.
- • Failed to load resource: the server responded with a status of 503 () [https://collector.github.com/github/collect:1]
Fix: Fix JS files returning 404/failed requests and resolve the listed runtime exceptions.