Audit Result

UUID: 01a0372a-cdab-71c9-94f0-bb14b7773ba4

github.com

https://github.com/figma/mcp-server-guide

Scanned 1 week ago

72
Fair Score
39 total checks
Passed
19
Warnings
18
Errors
2

Meta Information

  • Title Tag Warning

    Found 84 characters. Keep title between 30 and 60 characters.

    Fix: Add a unique <title> tag describing the main page intent in 30-60 characters.

  • Found 126 characters. Good snippet length.

  • Canonical URL Warning

    Canonical link not found.

    Fix: Add <link rel="canonical" href="https://example.com/page"> to avoid duplicate URL ambiguity.

  • Favicon Pass

    Favicon found and reachable: https://github.githubassets.com/favicons/favicon.png (HTTP 200).

    Favicon
  • Viewport configured: width=device-width

  • HTML Lang Pass

    Language declared as "en".

Content Structure

  • H1 Tag Warning

    Found 3 H1 tags.

    Fix: Use a single, descriptive <h1> that states the primary purpose of the page.

  • Detected 1 heading level jumps.

    • • Skipped from h2 to h4: "Add custom rules" -> "Ensure consistently good output".

    Fix: Follow semantic order (h1 -> h2 -> h3) and avoid skipping heading levels.

  • 1 of 16 images are missing alt text.

    Fix: Add meaningful alt attributes to all informative images for accessibility and image SEO.

Technical Optimization

  • HTTPS Pass

    Page is served over HTTPS.

  • 1 HTTPS hardening issues detected.

    • • Could not probe the HTTP version of this page.
    • • Strict-Transport-Security: max-age=31536000; includeSubdomains; preload

    Fix: Set Strict-Transport-Security with a long max-age, add includeSubDomains, and redirect all HTTP requests to HTTPS.

  • Core security headers were detected.

    Full HTTP headers (16)
    • • accept-ranges: bytes
    • • cache-control: max-age=0, private, must-revalidate
    • • content-encoding: gzip
    • • content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com github.githubassets.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net productionresultssa1.blob.core.windows.net productionresultssa2.blob.core.windows.net productionresultssa3.blob.core.windows.net productionresultssa4.blob.core.windows.net productionresultssa5.blob.core.windows.net productionresultssa6.blob.core.windows.net productionresultssa7.blob.core.windows.net productionresultssa8.blob.core.windows.net productionresultssa9.blob.core.windows.net productionresultssa10.blob.core.windows.net productionresultssa11.blob.core.windows.net productionresultssa12.blob.core.windows.net productionresultssa13.blob.core.windows.net productionresultssa14.blob.core.windows.net productionresultssa15.blob.core.windows.net productionresultssa16.blob.core.windows.net productionresultssa17.blob.core.windows.net productionresultssa18.blob.core.windows.net productionresultssa19.blob.core.windows.net github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com wss://alive-staging.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com wss://production-copilot-host.webpubsub.azure.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com user-images.githubusercontent.com private-user-images.githubusercontent.com opengraph.githubassets.com repository-images.githubusercontent.com marketplace-screenshots.githubusercontent.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com explore-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com; manifest-src 'self'; media-src github.com user-images.githubusercontent.com secured-user-images.githubusercontent.com private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com github.githubassets.com; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
    • • content-type: text/html; charset=utf-8
    • • date: Tue, 25 Aug 2026 04:25:41 GMT
    • • etag: W/"021b7a4c3a21e9041ba3deb9b4eda89a"
    • • referrer-policy: no-referrer-when-downgrade
    • • server: github.com
    • • strict-transport-security: max-age=31536000; includeSubdomains; preload
    • • vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With, X-GitHub-Client-Version, Sec-Fetch-Site,Accept-Encoding, Accept, X-Requested-With
    • • x-content-type-options: nosniff
    • • x-frame-options: deny
    • • x-github-edge-region: iad
    • • x-github-request-id: AF0A:2D5EB1:1796516:202BE7C:6A8D1945
    • • x-xss-protection: 0
  • CSP Quality Warning

    1 CSP hardening issues detected.

    • • CSP is missing object-src 'none'.
    • • Content-Security-Policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com github.githubassets.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net productionresultssa1.blob.core.windows.net productionresultssa2.blob.core.windows.net productionresultssa3.blob.core.windows.net productionresultssa4.blob.core.windows.net productionresultssa5.blob.core.windows.net productionresultssa6.blob.core.windows.net productionresultssa7.blob.core.windows.net productionresultssa8.blob.core.windows.net productionresultssa9.blob.core.windows.net productionresultssa10.blob.core.windows.net productionresultssa11.blob.core.windows.net productionresultssa12.blob.core.windows.net productionresultssa13.blob.core.windows.net productionresultssa14.blob.core.windows.net productionresultssa15.blob.core.windows.net productionresultssa16.blob.core.windows.net productionresultssa17.blob.core.windows.net productionresultssa18.blob.core.windows.net productionresultssa19.blob.core.windows.net github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com wss://alive-staging.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com wss://production-copilot-host.webpubsub.azure.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com user-images.githubusercontent.com private-user-images.githubusercontent.com opengraph.githubassets.com repository-images.githubusercontent.com marketplace-screenshots.githubusercontent.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com explore-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com; manifest-src 'self'; media-src github.com user-images.githubusercontent.com secured-user-images.githubusercontent.com private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com github.githubassets.com; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/

    Fix: Tighten Content-Security-Policy by removing unsafe directives and adding object-src, base-uri, and frame-ancestors restrictions.

  • No first-party cookies were set during the initial page load.

  • Server response headers do not expose version tokens.

  • Domain does not appear to be behind Cloudflare.

  • Loaded in 0.69s (perceived).

  • 0 scripts and 36 styles may block rendering.

    • • style: https://github.githubassets.com/assets/light-b18a1a7ee7730775.css
    • • style: https://github.githubassets.com/assets/light_high_contrast-9d093cb5adfc6a5b.css
    • • style: https://github.githubassets.com/assets/dark-f6186b2d117410d4.css
    • • style: https://github.githubassets.com/assets/dark_high_contrast-f39e8ef7b7418526.css
    • • style:
    • • style:
    • • style:
    • • style:
    • • style:
    • • style:
    • • style:
    • • style:
    • • style:
    • • style:
    • • style:
    • • style:
    • • style:
    • • style:
    • • style: https://github.githubassets.com/assets/primer-primitives-ae6d9799eadb7678.css
    • • style: https://github.githubassets.com/assets/primer-22bf543a61a1060e.css
    • • style: https://github.githubassets.com/assets/global-32ce322364350937.css
    • • style: https://github.githubassets.com/assets/github-a9a9110285537967.css
    • • style: https://github.githubassets.com/assets/repository-5c86d3f12914e4c9.css
    • • style: https://github.githubassets.com/assets/code-4bc66c6b883d8cfe.css
    • • style: https://github.githubassets.com/assets/app-runtime.40de7bf81511173e.module.css
    • • style: https://github.githubassets.com/assets/react-core.7c8eeae6bb9f6dd0.module.css
    • • style: https://github.githubassets.com/assets/primer-react-css.d27722a40f7d1e30.module.css
    • • style: https://github.githubassets.com/assets/1181.b15da6f57110dcaf.module.css
    • • style: https://github.githubassets.com/assets/13795.2a437a5bf83f35df.module.css
    • • style: https://github.githubassets.com/assets/66140.84aa3d3c848620a6.module.css
    • • style: https://github.githubassets.com/assets/dynamic-github-ui--code-view--route-components.3157cb80e3448a81.module.css
    • • style: https://github.githubassets.com/assets/code-view.c24766fa4c6e5e57.module.css
    • • style: https://github.githubassets.com/assets/primer-react-css.d27722a40f7d1e30.module.css
    • • style: https://github.githubassets.com/assets/notifications-subscriptions-menu.4085908b1acb211e.module.css
    • • style: https://github.githubassets.com/assets/38963.1261d6cc34b06e0a.module.css
    • • style: https://github.githubassets.com/assets/3021.e66e2d46cb1770e7.module.css

    Fix: Defer non-critical scripts and inline critical CSS to improve first paint speed.

  • Text-like assets appear compressed.

  • Robots.txt Pass

    Found robots.txt (200).

  • Sitemap File Warning

    Sitemap missing or inaccessible at https://github.com/sitemap.xml (406).

    Fix: Publish a sitemap.xml and reference it in robots.txt with: Sitemap: https://github.com/sitemap.xml

  • No robots meta tag defined.

    Fix: Add <meta name="robots" content="index,follow"> (or the intended directive) in <head>.

Accessibility Basics

  • All 1 controls are labeled.

  • Landmarks Pass

    Header, nav, main, and footer landmarks are present.

  • Tap Target Size Warning

    25 interactive elements appear smaller than 48px.

    • • a.px-2.tmp-py-4 (Skip to content) - 1x1px
    • • a.HeaderLogo-module__logo__UFyHI (Homepage) - 32x32px
    • • button.NavDropdown-module__button__PEHWX (Platform) - 98x40px
    • • button.NavDropdown-module__button__PEHWX (Solutions) - 104x40px
    • • button.NavDropdown-module__button__PEHWX (Resources) - 115x40px
    • • button.NavDropdown-module__button__PEHWX (Open Source) - 133x40px
    • • button.NavDropdown-module__button__PEHWX (Enterprise) - 111x40px
    • • a.MarketingNavigation-module__navLink__hUomM (Pricing) - 67x40px
    • • button.Primer_Brand__Button-module__Button___scH9Z.Primer_Brand__Button-module__Button--subtle___F7pEE (Search or jump to, type / to search) - 42x32px
    • • a.Primer_Brand__Button-module__Button___scH9Z.Primer_Brand__Button-module__Button--subtle___F7pEE (Sign in) - 70x32px
    • • a.Primer_Brand__Button-module__Button___scH9Z.Primer_Brand__Button-module__Button--secondary___gHnw_ (Sign up) - 75x32px
    • • button.Primer_Brand__Button-module__Button___scH9Z.Primer_Brand__Button-module__Button--subtle___F7pEE - 32x32px
    • • a#repository-details-watch-button.btn-sm.btn (You must be signed in to change notification settings) - 115x28px
    • • a#fork-button.btn-sm.btn (Fork 176) - 113x28px
    • • a.tooltipped.tooltipped-sw (You must be signed in to star a repository) - 117x28px
    • • a#code-tab.UnderlineNav-item.no-wrap (Code) - 75x30px
    • • a#pull-requests-tab.UnderlineNav-item.no-wrap (Pull requests 9) - 157x30px
    • • a#actions-tab.UnderlineNav-item.no-wrap (Actions) - 91x30px
    • • a#security-and-quality-tab.UnderlineNav-item.no-wrap (Security and quality 0) - 173x30px
    • • a#insights-tab.UnderlineNav-item.no-wrap (Insights) - 94x30px
    • • button#ref-picker-repos-header-ref-selector.prc-Button-ButtonBase-9n-Xk.overview-ref-selector (main branch) - 104x32px
    • • a.prc-Button-ButtonBase-9n-Xk.OverviewContent-module__Button___Uotu (33 Branches) - 113x32px
    • • a.prc-Button-ButtonBase-9n-Xk.OverviewContent-module__Button___Uotu (0 Tags) - 75x32px
    • • button#_r_k_.prc-Button-ButtonBase-9n-Xk (Code) - 107x32px
    • • a.prc-Link-Link-9ZwDx - 23x21px

    Fix: Increase target size to at least 48x48 CSS pixels for touch interactions.

Social & Rich Results

  • Core Open Graph tags are present.

  • og:image is present and absolute.

    Open Graph Image
  • twitter:card set to summary_large_image.

  • Structured Data Warning

    No JSON-LD schema scripts found.

    Fix: Add JSON-LD structured data matching your page type (Organization, Article, Product, etc.).

  • PWA Metadata Warning

    Manifest or Apple touch icon is missing.

    Fix: Link your web app manifest and apple-touch-icon for improved install/share experiences.

  • 2 social preview quality issues detected.

    • • ISSUE: og:title should typically be between 10 and 70 characters.
    • • ISSUE: Preview image is below recommended size (1200x630).
    • • GUIDELINE: Optimal og:title length: 40-60 characters (acceptable: 10-70).
    • • GUIDELINE: Optimal og:description length: 110-160 characters (acceptable: 50-200).
    • • GUIDELINE: Optimal preview image size: 1200x630 pixels.
    • • GUIDELINE: Optimal preview image aspect ratio: 1.91:1.
    • • GUIDELINE: Optimal preview image file size: under 5 MB.
    • • GUIDELINE: Recommended twitter:card: summary_large_image.
    • • MEASURED: Image size: 0.05 MB
    • • MEASURED: Image dimensions: 1200x600

    Fix: Use absolute OG/Twitter URLs, keep metadata lengths in recommended ranges, and provide a preview image near 1200x630 under 5MB.

Links Analysis

  • 2 internal links returned errors.

    • • https://github.com/marketplace (HTTP 400)
    • • https://github.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E&source=header-repo&source_repo=figma%2Fmcp-server-guide (HTTP 403)

    Fix: Fix or remove the listed internal URLs, and ensure routes/pages return 200 responses.

  • External Links Warning

    1 external links returned errors or timed out.

    • • https://support.github.com/ (HTTP 403)

    Fix: Replace dead external URLs or point to working alternatives.

  • Link Format Warning

    5 links are empty, invalid, or placeholder-only.

    • • href="(empty)" text="Reload"
    • • href="(empty)" text="Reload"
    • • href="(empty)" text="Reload"
    • • href="(empty)" text="Please reload this page"
    • • href="#" text="README"

    Fix: Replace empty/#/javascript href values with real destinations or use buttons for non-navigation actions.

Performance & Runtime

  • Largest Contentful Paint: 0.82s.

  • Cumulative Layout Shift: 0.000.

  • Total Blocking Time estimate: 215ms.

    Fix: Reduce heavy JavaScript work, split long tasks, and defer non-critical scripts.

  • No failed CSS/JS/image/font/media requests detected.

  • 3 JavaScript runtime issues detected.

    • • Request failed: https://github.com/in-product-messaging/budget-threshold-banner?organization=figma (HTTP 401, type: fetch)
    • • Request failed: https://github.com/in-product-messaging/budget-threshold-banner?organization=figma (net::ERR_ABORTED, type: fetch)
    • • Failed to load resource: the server responded with a status of 401 () [https://github.com/in-product-messaging/budget-threshold-banner?organization=figma:1]

    Fix: Fix JS files returning 404/failed requests and resolve the listed runtime exceptions.