Audit Result
UUID: 019ff77d-f6bf-702c-b83c-b055b0ba9258
https://mghost.pl/
Scanned 3 weeks ago
Meta Information
-
Title Tag Warning
Found 61 characters. Keep title between 30 and 60 characters.
Fix: Add a unique <title> tag describing the main page intent in 30-60 characters.
-
Meta Description Pass
Found 158 characters. Good snippet length.
-
Canonical URL Pass
Canonical found: https://mghost.pl
-
-
Viewport Meta Pass
Viewport configured: width=device-width, initial-scale=1
-
HTML Lang Pass
Language declared as "pl-PL".
Content Structure
-
H1 Tag Pass
Exactly one H1 found: "Superszybki i niezawodny hosting dla Twojej witryny".
-
Heading Hierarchy Pass
Valid heading flow across 26 headings.
-
Image Alt Text Error
1 of 24 images are missing alt text.
Fix: Add meaningful alt attributes to all informative images for accessibility and image SEO.
Technical Optimization
-
HTTPS Pass
Page is served over HTTPS.
-
HSTS & HTTPS Redirect Warning
1 HTTPS hardening issues detected.
- • Could not probe the HTTP version of this page.
- • Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Fix: Set Strict-Transport-Security with a long max-age, add includeSubDomains, and redirect all HTTP requests to HTTPS.
-
Security Headers Pass
Core security headers were detected.
Full HTTP headers (20)
- • content-encoding: gzip
- • content-security-policy: base-uri 'none'; default-src 'self'; connect-src 'self' https://mghost.pl https://api.mghost.pl https://o447951.ingest.sentry.io https://*.ingest.sentry.io https://*.ingest.de.sentry.io https://consent.cookiebot.com https://consentcdn.cookiebot.com https://consent.cookiebot.eu https://consentcdn.cookiebot.eu https://www.googletagmanager.com https://www.google-analytics.com https://region1.google-analytics.com https://region1.analytics.google.com https://analytics.google.com https://www.google.com https://www.googleadservices.com https://*.doubleclick.net https://pagead2.googlesyndication.com https://www.facebook.com https://www.clarity.ms https://*.clarity.ms https://api.iconify.design; font-src 'self'; form-action 'self'; frame-ancestors 'none'; frame-src https://*.doubleclick.net https://www.google.com https://www.googletagmanager.com https://consentcdn.cookiebot.com https://consentcdn.cookiebot.eu; img-src 'self' data: https://mghost.pl https://consent.cookiebot.com https://consentcdn.cookiebot.com https://consent.cookiebot.eu https://consentcdn.cookiebot.eu https://www.facebook.com https://www.google.com https://www.google.pl https://www.googletagmanager.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://www.clarity.ms https://*.clarity.ms https://c.bing.com; manifest-src 'self'; media-src 'self'; object-src 'none'; script-src-attr 'unsafe-hashes' 'sha256-bwK6T5wZVTANitXbrTsel7kl/PyCjCd/Dq5Qoz3imjM='; style-src 'self' 'unsafe-inline'; script-src 'self' 'nonce-mUP3Vavzuqk7ATvna8GIdW64' 'strict-dynamic' 'wasm-unsafe-eval' https://consent.cookiebot.com https://consentcdn.cookiebot.com https://consent.cookiebot.eu https://consentcdn.cookiebot.eu https://www.googletagmanager.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.google.com https://connect.facebook.net https://www.clarity.ms; upgrade-insecure-requests; worker-src 'self' blob:;
- • content-type: text/html;charset=utf-8
- • cross-origin-embedder-policy: unsafe-none
- • cross-origin-opener-policy: same-origin
- • cross-origin-resource-policy: same-origin
- • date: Wed, 12 Aug 2026 19:40:47 GMT
- • origin-agent-cluster: ?1
- • permissions-policy: accelerometer=(), autoplay=(), camera=(), display-capture=(), encrypted-media=(), fullscreen=(self), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(self), usb=(), web-share=(), xr-spatial-tracking=()
- • referrer-policy: strict-origin-when-cross-origin
- • server: nginx
- • strict-transport-security: max-age=31536000; includeSubDomains; preload
- • vary: Accept-Encoding
- • x-content-type-options: nosniff
- • x-dns-prefetch-control: off
- • x-download-options: noopen
- • x-frame-options: DENY
- • x-permitted-cross-domain-policies: none
- • x-robots-tag: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- • x-xss-protection: 0
-
CSP Quality Pass
Content Security Policy looks restrictive and avoids common unsafe directives.
- • Content-Security-Policy: base-uri 'none'; default-src 'self'; connect-src 'self' https://mghost.pl https://api.mghost.pl https://o447951.ingest.sentry.io https://*.ingest.sentry.io https://*.ingest.de.sentry.io https://consent.cookiebot.com https://consentcdn.cookiebot.com https://consent.cookiebot.eu https://consentcdn.cookiebot.eu https://www.googletagmanager.com https://www.google-analytics.com https://region1.google-analytics.com https://region1.analytics.google.com https://analytics.google.com https://www.google.com https://www.googleadservices.com https://*.doubleclick.net https://pagead2.googlesyndication.com https://www.facebook.com https://www.clarity.ms https://*.clarity.ms https://api.iconify.design; font-src 'self'; form-action 'self'; frame-ancestors 'none'; frame-src https://*.doubleclick.net https://www.google.com https://www.googletagmanager.com https://consentcdn.cookiebot.com https://consentcdn.cookiebot.eu; img-src 'self' data: https://mghost.pl https://consent.cookiebot.com https://consentcdn.cookiebot.com https://consent.cookiebot.eu https://consentcdn.cookiebot.eu https://www.facebook.com https://www.google.com https://www.google.pl https://www.googletagmanager.com https://googleads.g.doubleclick.net https://pagead2.googlesyndication.com https://www.clarity.ms https://*.clarity.ms https://c.bing.com; manifest-src 'self'; media-src 'self'; object-src 'none'; script-src-attr 'unsafe-hashes' 'sha256-bwK6T5wZVTANitXbrTsel7kl/PyCjCd/Dq5Qoz3imjM='; style-src 'self' 'unsafe-inline'; script-src 'self' 'nonce-mUP3Vavzuqk7ATvna8GIdW64' 'strict-dynamic' 'wasm-unsafe-eval' https://consent.cookiebot.com https://consentcdn.cookiebot.com https://consent.cookiebot.eu https://consentcdn.cookiebot.eu https://www.googletagmanager.com https://www.googleadservices.com https://googleads.g.doubleclick.net https://www.google.com https://connect.facebook.net https://www.clarity.ms; upgrade-insecure-requests; worker-src 'self' blob:;
-
Cookie Security Pass
No first-party cookies were set during the initial page load.
-
Server response headers do not expose version tokens.
-
Cloudflare Proxy Warning
Domain does not appear to be behind Cloudflare.
-
Perceived Load Time Pass
Loaded in 1.08s (perceived).
-
Render Blocking Resources Warning
0 scripts and 17 styles may block rendering.
- • style: https://mghost.pl/_nuxt/entry.oxEYkKE9.css
- • style: https://mghost.pl/_nuxt/Footer.DbGHap8u.css
- • style: https://mghost.pl/_nuxt/ArrowBtn.95G-xOk7.css
- • style: https://mghost.pl/_nuxt/pages.eSFjpD_g.css
- • style: https://mghost.pl/_nuxt/default.CCKMVruq.css
- • style: https://mghost.pl/_nuxt/cart.BmIg-6cs.css
- • style: https://mghost.pl/_nuxt/BlogGrid.XTl3zJa2.css
- • style: https://mghost.pl/_nuxt/Details.BGOLBkWT.css
- • style: https://mghost.pl/_nuxt/przeniesienie-strony.Y5VW8Lav.css
- • style: https://mghost.pl/_nuxt/BoxIntro.DXQjLA_j.css
- • style: https://mghost.pl/_nuxt/domain-configure.BZjo43TO.css
- • style: https://mghost.pl/_nuxt/domain-pricing.Du5vPWs9.css
- • style: https://mghost.pl/_nuxt/blog.DSibgCuG.css
- • style: https://mghost.pl/_nuxt/kontakt.Dj5qJKJw.css
- • style: https://mghost.pl/_nuxt/reset-password.BPu-gDze.css
- • style: https://mghost.pl/_nuxt/register.YMBjBVh3.css
- • style: https://mghost.pl/_nuxt/login.DAc9lN3x.css
Fix: Defer non-critical scripts and inline critical CSS to improve first paint speed.
-
Compression Pass
Text-like assets appear compressed.
-
Robots.txt Pass
Found robots.txt (200).
-
Sitemap File Pass
Found sitemap (200) at https://mghost.pl/sitemap_index.xml.
-
Crawl Directives Pass
Robots meta found: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
Accessibility Basics
-
Form Labels Pass
All 11 controls are labeled.
-
Landmarks Pass
Header, nav, main, and footer landmarks are present.
-
Tap Target Size Warning
20 interactive elements appear smaller than 48px.
- • a#CybotCookiebotDialogPoweredbyCybot (Cookiebot od Usercentrics - otwiera się w nowym oknie) - 175x30px
- • a.skip-to-content (Przejdź do treści) - 48x24px
- • button.scrollUp (Scroll up site) - 40x40px
- • a (Go to cart) - 34x31px
- • button.lang-switch-btn (Zmień język) - 46x15px
- • a (Blog) - 71x24px
- • button.search-trigger (Znajdź domenę) - 10x10px
- • a (Zobacz wszystkie pakiety hostingu) - 213x15px
- • a.router-link-active.router-link-exact-active - 185x38px
- • a (Go to facebook fanpage) - 36x36px
- • a (Go to mghost linkedin) - 36x36px
- • button.footer__menu--header (Oferta) - 71x47px
- • a (Hosting współdzielony) - 156x36px
- • a (VPS) - 156x36px
- • a (Usługi Sys/DevOps) - 156x36px
- • a (Licencje) - 156x36px
- • button.footer__menu--header (Informacje) - 119x47px
- • a (Blog) - 143x36px
- • a (Regulaminy i warunki) - 143x36px
- • a (Polityka prywatności) - 143x36px
Fix: Increase target size to at least 48x48 CSS pixels for touch interactions.
Social & Rich Results
-
Open Graph Basics Pass
Core Open Graph tags are present.
-
-
Twitter Card Pass
twitter:card set to summary_large_image.
-
Structured Data Pass
JSON-LD schema detected.
-
PWA Metadata Warning
Manifest or Apple touch icon is missing.
Fix: Link your web app manifest and apple-touch-icon for improved install/share experiences.
-
Social preview metadata and image quality look good for Open Graph/Twitter.
- • GUIDELINE: Optimal og:title length: 40-60 characters (acceptable: 10-70).
- • GUIDELINE: Optimal og:description length: 110-160 characters (acceptable: 50-200).
- • GUIDELINE: Optimal preview image size: 1200x630 pixels.
- • GUIDELINE: Optimal preview image aspect ratio: 1.91:1.
- • GUIDELINE: Optimal preview image file size: under 5 MB.
- • GUIDELINE: Recommended twitter:card: summary_large_image.
- • MEASURED: Image size: 0.12 MB
- • MEASURED: Image dimensions: 1200x630
Links Analysis
-
Internal Links Error
1 internal links returned errors.
- • https://mghost.pl/gamevps (HTTP 404)
Fix: Fix or remove the listed internal URLs, and ensure routes/pages return 200 responses.
-
External Links Pass
No broken external links found in checked URLs.
-
Link Format Warning
16 links are empty, invalid, or placeholder-only.
- • href="#" text="Zgoda"
- • href="#" text="Szczegóły"
- • href="#" text="[#IABV2SETTINGS#]"
- • href="#" text="O plikach cookies"
- • href="#" text="Pokaż szczegóły"
- • href="#" text="Cookiebot1"
- • href="#" text="Google1"
- • href="#" text="mghost.pl2"
- • href="#" text="Google2"
- • href="#" text="Microsoft3"
- • href="#" text="Meta Platforms, Inc.2"
- • href="#" text="Google4"
- • href="#" text="Microsoft2"
- • href="#" text="mghost.pl1"
- • href="#" text="mghost.pl2"
- • href="#" text="Zgoda międzydomenowa[#BULK_CONSENT_DOMAINS_COUNT#]"
Fix: Replace empty/#/javascript href values with real destinations or use buttons for non-navigation actions.
Performance & Runtime
-
Core Web Vitals: LCP Pass
Largest Contentful Paint: 1.26s.
-
Core Web Vitals: CLS Pass
Cumulative Layout Shift: 0.080.
-
Total Blocking Time estimate: 131ms.
-
Broken Assets Pass
No failed CSS/JS/image/font/media requests detected.
-
JavaScript Runtime Errors Warning
2 JavaScript runtime issues detected.
- • Request failed: https://api.mghost.pl/api/auth/user (HTTP 401, type: fetch)
- • Failed to load resource: the server responded with a status of 401 () [https://api.mghost.pl/api/auth/user:1]
Fix: Fix JS files returning 404/failed requests and resolve the listed runtime exceptions.