Audit Result
UUID: 019f8fb2-d1ec-72e6-af5c-f159935f8323
https://stripe.com/
Scanned 1 month ago
Meta Information
-
Title Tag Pass
Found 54 characters. Length is optimal.
-
Meta Description Pass
Found 149 characters. Good snippet length.
-
Canonical URL Pass
Canonical found: https://stripe.com/
-
Favicon Pass
Favicon found and reachable: https://images.stripeassets.com/fzn2n1nzq965/1hgcBNd12BfT9VLgbId7By/01d91920114b124fb4cf6d448f9f06eb/favicon.svg (HTTP 200).
-
Viewport Meta Pass
Viewport configured: width=device-width, initial-scale=1, viewport-fit=cover
-
HTML Lang Pass
Language declared as "en-US".
Content Structure
-
H1 Tag Warning
Found 2 H1 tags.
Fix: Use a single, descriptive <h1> that states the primary purpose of the page.
-
Heading Hierarchy Pass
Valid heading flow across 58 headings.
-
Image Alt Text Error
40 of 44 images are missing alt text.
Fix: Add meaningful alt attributes to all informative images for accessibility and image SEO.
Technical Optimization
-
HTTPS Pass
Page is served over HTTPS.
-
HSTS & HTTPS Redirect Warning
1 HTTPS hardening issues detected.
- • Could not probe the HTTP version of this page.
- • Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
Fix: Set Strict-Transport-Security with a long max-age, add includeSubDomains, and redirect all HTTP requests to HTTPS.
-
Security Headers Pass
Core security headers were detected.
Full HTTP headers (17)
- • content-encoding: gzip
- • content-security-policy: base-uri 'none'; child-src 'none'; connect-src https://c.increment.com https://c.stripe.dev https://c.stripe.global https://c.stripe.partners blob: https://b.stripecdn.com https://errors.stripe.com https://ext.stripe.com https://r.stripe.com https://stripe-images.s3.us-west-1.amazonaws.com https://stripe.com 'self'; default-src 'none'; font-src https://b.stripecdn.com 'self'; form-action https://stripe.com 'self'; frame-ancestors https://app.contentful.com 'self'; frame-src https://b.stripecdn.com https://js.stripe.com https://support-conversations.stripe.com 'self'; img-src data: https://assets.ctfassets.net https://assets.stripeassets.com https://b.stripecdn.com https://images.ctfassets.net https://images.stripeassets.com https://q.stripe.com 'self'; manifest-src 'none'; media-src https://assets.ctfassets.net https://assets.stripeassets.com https://b.stripecdn.com https://videos.ctfassets.net https://videos.stripeassets.com 'self'; object-src 'none'; script-src https://b.stripecdn.com https://js.stripe.com 'self' 'sha256-3aWvb9tRBjmz1OjR3n7mwiTm94+s4iki4mMZF82asmc=' 'sha256-5LtzXhT7UFn+GqP5pKEMGL08UNZsrzANHFEBW/mQHGw=' 'sha256-beLzNcen8LrazzSCRjAapoIMTgJI0osPWGNSX7aK6lc=' 'sha256-cCM0Z4lzGkzQnmbdVw+ouz0JRawyaKcZ4yiqzqYS7ek=' 'sha256-vTifGUJH6hJYTvstw4xJ4xfr/vE0ELkOV4GpCumyqfg=' 'sha256-KxhSaxKB5RFTQsqfRwp+zG7iLjvMrTAySqnSvWlqct0=' 'sha256-tMuJ8c00j54yuxogrdIJeGhNVB350dc56i969XRz/Mc=' 'sha256-aEFSvCaVnb2wNwuO3IzA8J44RdTKt6vms9beA7BcCYg=' 'sha256-0SWEc2BfR2o77i2vUiNNIrFKQkjc2Ujsr2hlfZ6oUek=' 'report-sample'; style-src https://b.stripecdn.com 'self' 'unsafe-inline'; worker-src https://b.stripecdn.com 'self'; upgrade-insecure-requests; report-uri https://q.stripe.com/csp-violation?q=IaunZaZ8t0Q4t0kcJ3uf55nvb4lMPsXtUggQCrl14-3ovf-T426deZ4Cq4NWT2c%3D; report-to csp
- • content-type: text/html; charset=utf-8
- • cross-origin-opener-policy: same-origin-allow-popups; report-to="wsp_coop"
- • cross-origin-opener-policy-report-only: same-origin-allow-popups; report-to="wsp_coop"
- • date: Thu, 23 Jul 2026 15:57:53 GMT
- • referrer-policy: no-referrer-when-downgrade
- • report-to: {"group":"coop","max_age":8640,"endpoints":[{"url":"https://q.stripe.com/coop-report"}],"include_subdomains":true}, {"group":"wsp_coop","max_age":8640,"endpoints":[{"url":"https://q.stripe.com/coop-report?s=IaunZaZ8t0Q4t0kcJ3uf55nvb4lMPsXtUggQCrl14-3ovf-T426deZ4Cq4NWT2c="}],"include_subdomains":true}, {"group":"wsp_coep","max_age":8640,"endpoints":[{"url":"https://q.stripe.com/coep-report?s=IaunZaZ8t0Q4t0kcJ3uf55nvb4lMPsXtUggQCrl14-3ovf-T426deZ4Cq4NWT2c="}],"include_subdomains":true}, {"group":"csp","max_age":8640,"endpoints":[{"url":"https://q.stripe.com/csp-report-v2?q=IaunZaZ8t0Q4t0kcJ3uf55nvb4lMPsXtUggQCrl14-3ovf-T426deZ4Cq4NWT2c%3D&t=1"}],"include_subdomains":true}
- • reporting-endpoints: coop="https://q.stripe.com/coop-report", wsp_coop="https://q.stripe.com/coop-report?s=IaunZaZ8t0Q4t0kcJ3uf55nvb4lMPsXtUggQCrl14-3ovf-T426deZ4Cq4NWT2c=", wsp_coep="https://q.stripe.com/coep-report?s=IaunZaZ8t0Q4t0kcJ3uf55nvb4lMPsXtUggQCrl14-3ovf-T426deZ4Cq4NWT2c=", csp="https://q.stripe.com/csp-report-v2?q=IaunZaZ8t0Q4t0kcJ3uf55nvb4lMPsXtUggQCrl14-3ovf-T426deZ4Cq4NWT2c%3D&t=1"
- • server: nginx
- • strict-transport-security: max-age=63072000; includeSubDomains; preload
- • x-content-type-options: nosniff
- • x-frame-options: SAMEORIGIN
- • x-mkt-cache: HIT
- • x-stripe-proxy-response: upstream
- • x-stripe-server-rpc-duration-micros: 66789
- • x-wc: 3ff
-
CSP Quality Pass
Content Security Policy looks restrictive and avoids common unsafe directives.
- • Content-Security-Policy: base-uri 'none'; child-src 'none'; connect-src https://c.increment.com https://c.stripe.dev https://c.stripe.global https://c.stripe.partners blob: https://b.stripecdn.com https://errors.stripe.com https://ext.stripe.com https://r.stripe.com https://stripe-images.s3.us-west-1.amazonaws.com https://stripe.com 'self'; default-src 'none'; font-src https://b.stripecdn.com 'self'; form-action https://stripe.com 'self'; frame-ancestors https://app.contentful.com 'self'; frame-src https://b.stripecdn.com https://js.stripe.com https://support-conversations.stripe.com 'self'; img-src data: https://assets.ctfassets.net https://assets.stripeassets.com https://b.stripecdn.com https://images.ctfassets.net https://images.stripeassets.com https://q.stripe.com 'self'; manifest-src 'none'; media-src https://assets.ctfassets.net https://assets.stripeassets.com https://b.stripecdn.com https://videos.ctfassets.net https://videos.stripeassets.com 'self'; object-src 'none'; script-src https://b.stripecdn.com https://js.stripe.com 'self' 'sha256-3aWvb9tRBjmz1OjR3n7mwiTm94+s4iki4mMZF82asmc=' 'sha256-5LtzXhT7UFn+GqP5pKEMGL08UNZsrzANHFEBW/mQHGw=' 'sha256-beLzNcen8LrazzSCRjAapoIMTgJI0osPWGNSX7aK6lc=' 'sha256-cCM0Z4lzGkzQnmbdVw+ouz0JRawyaKcZ4yiqzqYS7ek=' 'sha256-vTifGUJH6hJYTvstw4xJ4xfr/vE0ELkOV4GpCumyqfg=' 'sha256-KxhSaxKB5RFTQsqfRwp+zG7iLjvMrTAySqnSvWlqct0=' 'sha256-tMuJ8c00j54yuxogrdIJeGhNVB350dc56i969XRz/Mc=' 'sha256-aEFSvCaVnb2wNwuO3IzA8J44RdTKt6vms9beA7BcCYg=' 'sha256-0SWEc2BfR2o77i2vUiNNIrFKQkjc2Ujsr2hlfZ6oUek=' 'report-sample'; style-src https://b.stripecdn.com 'self' 'unsafe-inline'; worker-src https://b.stripecdn.com 'self'; upgrade-insecure-requests; report-uri https://q.stripe.com/csp-violation?q=IaunZaZ8t0Q4t0kcJ3uf55nvb4lMPsXtUggQCrl14-3ovf-T426deZ4Cq4NWT2c%3D; report-to csp
-
Cookie Security Pass
No first-party cookies were set during the initial page load.
-
Server response headers do not expose version tokens.
-
Cloudflare Proxy Warning
Domain does not appear to be behind Cloudflare.
-
Perceived Load Time Pass
Loaded in 0.40s (perceived).
-
Render Blocking Resources Warning
0 scripts and 7 styles may block rendering.
- • style: https://b.stripecdn.com/mkt-ssr-statics/assets/_next/static/css/9d3a49263f73db6f.css
- • style: https://b.stripecdn.com/mkt-ssr-statics/assets/_next/static/css/35cbae6c6f4a503d.css
- • style: https://b.stripecdn.com/mkt-ssr-statics/assets/_next/static/css/9355fd9277f43790.css
- • style: https://b.stripecdn.com/mkt-ssr-statics/assets/_next/static/css/5ddf5563124857a7.css
- • style: https://b.stripecdn.com/mkt-ssr-statics/assets/_next/static/css/4b78f0f4457ea12a.css
- • style: https://b.stripecdn.com/mkt-ssr-statics/assets/_next/static/css/3046c2816c2ffd6e.css
- • style: https://b.stripecdn.com/mkt-ssr-statics/assets/_next/static/css/b793c34868bb4156.css
Fix: Defer non-critical scripts and inline critical CSS to improve first paint speed.
-
Compression Warning
14 text resources look uncompressed.
- • https://b.stripecdn.com/mkt-ssr-statics/assets/_next/static/chunks/45914.c8d4fd1c9d7fc56a.js (text/javascript; charset=utf-8)
- • https://b.stripecdn.com/mkt-ssr-statics/assets/_next/static/VSs0GMTW9hxE%2BR4Ljdr9qZeo%2ByKACzRfLpqJhczb65A%3D/_ssgManifest.js (text/javascript; charset=utf-8)
- • https://b.stripecdn.com/mkt-ssr-statics/assets/_next/static/chunks/6532.4d32b412aee8ef5a.js (text/javascript; charset=utf-8)
- • https://b.stripecdn.com/mkt-ssr-statics/assets/_next/static/chunks/45348.1b0618e89613a79b.js (text/javascript; charset=utf-8)
- • https://b.stripecdn.com/stripethirdparty-srv/assets/v33.1/PrivacyCompliance.html?id=35ca462f-4dc2-4a3f-85b4-3eb6ea4d5ce3&origin=https%3A%2F%2Fstripe.com (text/html; charset=utf-8)
- • https://stripe.com/cookie-settings/enforcement-mode (application/json; charset=utf-8)
- • https://stripe.com/notifications?as=json (application/json; charset=utf-8)
- • https://ext.stripe.com/universal-chat/agent-availability?qr=qvb&country=US (application/json; charset=utf-8)
- • https://b.stripecdn.com/stripethirdparty-srv/assets/v33.1/GoogleTagManager.html?id=d6a9746f-8438-4668-9450-efd482203611&origin=https%3A%2F%2Fstripe.com (text/html; charset=utf-8)
- • https://r.stripe.com/0 (text/plain)
- • https://ipv4.pdscrb.com/ (application/json)
- • https://api.company-target.com/api/v3/ip.json?referrer=https%3A%2F%2Fstripe.com%2F&page=https%3A%2F%2Fb.stripecdn.com%2Fstripethirdparty-srv%2Fassets%2Fv33.1%2FGoogleTagManager.html%3Fid%3Dd6a9746f-8438-4668-9450-efd482203611%26origin%3Dhttps%253A%252F%252Fstripe.com&page_title= (application/json; charset=utf-8)
- • https://tag-logger.demandbase.com/bg9s?x-amz-cf-id=LBOhLBmPkYGRK10X7pD2eenPgaxYtyjoXoD14l0itmuD95_kvicp-Q==&api-version=v3 (text/html)
- • blob:https://b.stripecdn.com/fd5e8c6c-3101-4e60-aa81-dcbb7da21df8 (text/javascript)
Fix: Enable Brotli or Gzip compression for HTML, CSS, JS, and JSON responses.
-
Robots.txt Pass
Found robots.txt (200).
-
Sitemap File Pass
Found sitemap (200) at https://stripe.com/sitemap/sitemap.xml.
-
Crawl Directives Warning
No robots meta tag defined.
Fix: Add <meta name="robots" content="index,follow"> (or the intended directive) in <head>.
Accessibility Basics
-
Form Labels Pass
All 0 controls are labeled.
-
Landmarks Pass
Header, nav, main, and footer landmarks are present.
-
Tap Target Size Warning
25 interactive elements appear smaller than 48px.
- • a.hds-link.navigation-menu-home-link (Stripe homepage) - 60x25px
- • button.hds-button.hds-navigation-menu__trigger (Products) - 83x40px
- • button.hds-button.hds-navigation-menu__trigger (Solutions) - 85x40px
- • button.hds-button.hds-navigation-menu__trigger (Developers) - 97x40px
- • button.hds-button.hds-navigation-menu__trigger (Resources) - 92x40px
- • a.hds-button.hds-navigation-menu__trigger (Pricing) - 48x38px
- • a.hds-button.hds-navigation-menu__trigger (Guide me) - 85x40px
- • a.hds-button.navigation-cta-button (Sign in) - 87x40px
- • a.hds-button.navigation-cta-button (Contact sales) - 147x40px
- • a.hds-link - 142x34px
- • a.hds-link - 142x34px
- • a.hds-link - 142x34px
- • a.hds-link - 142x34px
- • a.hds-link - 142x34px
- • a.hds-link - 142x34px
- • a.hds-link - 142x34px
- • a.hds-link - 142x34px
- • a.hds-link - 142x34px
- • a.hds-link - 142x34px
- • a.hds-link - 142x34px
- • a.hds-link - 142x34px
- • a.hds-link - 142x34px
- • a.hds-link - 142x34px
- • a.hds-link - 142x34px
- • a.hds-link - 142x34px
Fix: Increase target size to at least 48x48 CSS pixels for touch interactions.
Social & Rich Results
-
Open Graph Basics Pass
Core Open Graph tags are present.
-
-
Twitter Card Pass
twitter:card set to summary_large_image.
-
Structured Data Pass
JSON-LD schema detected.
-
PWA Metadata Warning
Manifest or Apple touch icon is missing.
Fix: Link your web app manifest and apple-touch-icon for improved install/share experiences.
-
Social preview metadata and image quality look good for Open Graph/Twitter.
- • GUIDELINE: Optimal og:title length: 40-60 characters (acceptable: 10-70).
- • GUIDELINE: Optimal og:description length: 110-160 characters (acceptable: 50-200).
- • GUIDELINE: Optimal preview image size: 1200x630 pixels.
- • GUIDELINE: Optimal preview image aspect ratio: 1.91:1.
- • GUIDELINE: Optimal preview image file size: under 5 MB.
- • GUIDELINE: Recommended twitter:card: summary_large_image.
- • MEASURED: Image size: 0.30 MB
- • MEASURED: Image dimensions: 2048x1024
Links Analysis
-
Internal Links Pass
Checked 80 links. No broken internal links found.
-
External Links Pass
No broken external links found in checked URLs.
-
Link Format Pass
All 183 links use non-empty href values.
Performance & Runtime
-
Core Web Vitals: LCP Pass
Largest Contentful Paint: 0.40s.
-
Core Web Vitals: CLS Pass
Cumulative Layout Shift: 0.000.
-
Main Thread Blocking (TBT) Warning
Total Blocking Time estimate: 312ms.
Fix: Reduce heavy JavaScript work, split long tasks, and defer non-critical scripts.
-
Broken Assets Error
2 asset requests failed.
- • https://s.ml-attr.com/getuid?https%3a%2f%2fattr.ml-api.io%2f%3fdomain%3dstripe.com%26pId%3d%24UID (net::ERR_BLOCKED_BY_ORB)
- • https://www.google.de/ads/ga-audiences?v=1&t=sr&slf_rd=1&_r=4&tid=G-SEKFWD1C9J&cid=1450735254.1784822275>m=45je67l1v875200074z8838837448za20gzb838837448zd838837448&rcb=10&aip=1&dma=1&dma_cps=a&gcd=13l3l3l2l1l1&npa=1&frm=2&tag_exp=115938466~115938468~118897920~118897930~119896803&z=865880475 (csp)
Fix: Fix missing files, update asset URLs, and ensure static assets return HTTP 200.
-
JavaScript Runtime Errors Warning
5 JavaScript runtime issues detected.
- • Request failed: https://r.stripe.com/0 (net::ERR_ABORTED, type: fetch)
- • Request failed: https://www.google.com/ccm/collect?rcb=8&frm=2&ae=g&en=page_view&dl=https%3A%2F%2Fb.stripecdn.com%2Fstripethirdparty-srv%2Fassets%2Fv33.1%2FGoogleTagManager.html&dr=stripe.com&top=https%3A%2F%2Fstripe.com%2F&scrsrc=www.googletagmanager.com&rnd=1676619687.1784822275&navt=n&npa=1&ep.ads_data_redaction=0>m=45He67l1v838837448za200zd838837448xea&gcd=13l3l3l2l1l1&dma_cps=a&dma=1&tag_exp=115938466~115938468~118897920~118897930~119527020~119896803&apve=1&apvf=f&apvc=1&tft=1784822274838&tfd=276&fmt=8 (net::ERR_ABORTED, type: fetch)
- • Request failed: https://www.google.com/ccm/collect?rcb=18&frm=2&en=page_view&dl=https%3A%2F%2Fb.stripecdn.com%2Fstripethirdparty-srv%2Fassets%2Fv33.1%2FGoogleTagManager.html&dr=stripe.com&top=https%3A%2F%2Fstripe.com%2F&scrsrc=www.googletagmanager.com&rnd=1676619687.1784822275&navt=n&npa=1>m=45be67l1v889774910z8838837448za20gzb838837448zd838837448xec&gcd=13l3l3l2l1l1&dma_cps=a&dma=1&tag_exp=115938466~115938469~118897920~118897930~119896803&apve=1&apvf=f&apvc=0&tids=AW-848119022&tid=AW-848119022&tft=1784822275169&tfd=607&fmt=8 (net::ERR_ABORTED, type: fetch)
- • Request failed: https://region1.analytics.google.com/g/collect?v=2&tid=G-SEKFWD1C9J>m=45je67l1v875200074z8838837448za20gzb838837448zd838837448&_p=1784822274625&_gaz=1&gcd=13l3l3l2l1l1&npa=1&dma_cps=a&dma=1&ecid=400842941&_eu=AAAAAGA&are=1&cid=1450735254.1784822275&ec_mode=a&frm=2&pscdl=noapi&rcb=10&sr=1280x800&uaa=x86&uab=64&uafvl=Not%253AA-Brand%3B99.0.0.0%7CHeadlessChrome%3B145.0.7632.6%7CChromium%3B145.0.7632.6&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938468~118897920~118897930~119896803&dl=https%3A%2F%2Fstripe.com%2F&dr=&dt=Stripe%20%7C%20Financial%20Infrastructure%20to%20Grow%20Your%20Revenue&dp=%2F&sid=1784822275&sct=1&seg=0&_tu=QA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.url_passthrough=true&ep.gtm_container_id=GTM-WK8882T&ep.gtm_container_version=382&ep.previous_url=https%3A%2F%2Fstripe.com%2F&ep.timestamp=2026-07-23T17%3A57%3A54.827%2B02%3A00&ep.page_url=https%3A%2F%2Fb.stripecdn.com%2Fstripethirdparty-srv%2Fassets%2Fv33.1%2FGoogleTagManager.html%3Fid%3Dd6a9746f-8438-4668-9450-efd482203611%26origin%3Dhttps%253A%252F%252Fstripe.com&ep.dl_url=%2F&ep.hostname=https%3A%2F%2Fstripe.com&ep.db_company_name=(Non-Company%20Visitor)&ep.gtm_tag_name=GA4%20-%20Page%20View&up.user_id_2=&upn.timezone_offset=2&up.logged_in=False&tfd=510 (net::ERR_ABORTED, type: fetch)
- • Loading the image 'https://www.google.de/ads/ga-audiences?v=1&t=sr&slf_rd=1&_r=4&tid=G-SEKFWD1C9J&cid=1450735254.1784822275>m=45je67l1v875200074z8838837448za20gzb838837448zd838837448&rcb=10&aip=1&dma=1&dma_cps=a&gcd=13l3l3l2l1l1&npa=1&frm=2&tag_exp=115938466~115938468~118897920~118897930~119896803&z=865880475' violates the following Content Security Policy directive: "img-src 'self' *.company-target.com *.doubleclick.net *.google.com *.linkedin.com *.yimp.jp *.ml-attr.com *.adsrvr.org *.ml-api.io alb.reddit.com analytics.twitter.com b91.yahoo.co.jp ib.adnxs.com id.rlcdn.com p.adsymptotic.com pixel-config.reddit.com q.quora.com snap.licdn.com ssl.gstatic.com t.co tr.line.me www.facebook.com www.google-analytics.com www.googletagmanager.com www.gstatic.com bat.bing.com *.podscribe.com *.pdscrb.com pixel.tapad.com". The action has been blocked. [https://b.stripecdn.com/stripethirdparty-srv/assets/v33.1/GoogleTagManager.html?id=d6a9746f-8438-4668-9450-efd482203611&origin=https%3A%2F%2Fstripe.com:1]
Fix: Fix JS files returning 404/failed requests and resolve the listed runtime exceptions.