Audit Result
UUID: 01a06ffb-bf93-73c7-a7a8-25f8db563826
https://mahjongroom.hk/
Scanned 1 day ago
Meta Information
-
Title Tag Pass
Found 45 characters. Length is optimal.
-
Meta Description Pass
Found 83 characters. Good snippet length.
-
Canonical URL Pass
Canonical found: https://mahjongroom.hk/
-
Favicon Warning
No favicon link found in <head>.
Fix: Add <link rel="icon" href="/favicon.ico"> to ensure browser tab and bookmark visibility.
-
Viewport Meta Pass
Viewport configured: width=device-width, initial-scale=1
-
HTML Lang Pass
Language declared as "zh-HK".
Content Structure
-
H1 Tag Pass
Exactly one H1 found: "MahjongRoom.hk 新蒲崗24小時私人麻雀房。想打,就先查時段。".
-
Heading Hierarchy Pass
Valid heading flow across 29 headings.
-
Image Alt Text Error
3 of 11 images are missing alt text.
Fix: Add meaningful alt attributes to all informative images for accessibility and image SEO.
Technical Optimization
-
HTTPS Pass
Page is served over HTTPS.
-
HSTS & HTTPS Redirect Warning
2 HTTPS hardening issues detected.
- • HSTS is missing includeSubDomains.
- • Could not probe the HTTP version of this page.
- • Strict-Transport-Security: max-age=31536000
Fix: Set Strict-Transport-Security with a long max-age, add includeSubDomains, and redirect all HTTP requests to HTTPS.
-
Security Headers Pass
Core security headers were detected.
Full HTTP headers (22)
- • age: 1
- • alt-svc: h3=":443"; ma=86400
- • cache-control: public,max-age=0,must-revalidate
- • cache-status: "Netlify Edge"; fwd=miss; fwd-status=200; stored
- • cf-cache-status: DYNAMIC
- • cf-ray: a362bd8b8bd6829e-IAD
- • content-encoding: zstd
- • content-security-policy: default-src 'self'; style-src 'self' 'unsafe-inline'; frame-src https://www.google.com https://www.googletagmanager.com; script-src 'self' 'unsafe-inline' https://*.googletagmanager.com https://*.google-analytics.com https://analytics.ahrefs.com https://*.doubleclick.net https://*.google.com; img-src 'self' data: https://*.googletagmanager.com https://*.google-analytics.com https://*.doubleclick.net https://*.google.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://analytics.ahrefs.com https://*.doubleclick.net https://*.google.com;
- • content-type: text/html; charset=utf-8
- • date: Sat, 05 Sep 2026 05:12:42 GMT
- • nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
- • permissions-policy: camera=(), microphone=(), geolocation=()
- • referrer-policy: strict-origin-when-cross-origin
- • report-to: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=R56aABAEBA7mQ4F4ZXjqefnI1nnEFD%2F6KH6RuChkT9%2BuUPomkrIjIw8jOK5RQnv0zsWLwWshfOQpXhvSNcLhPhpR1c9l5ZjNeF9D%2BXfo86s676Cj9YE6%2BWSZ1ipZ2aCLqx2N6K4NChV4CSnR9Q%3D%3D"}]}
- • server: cloudflare
- • server-timing: cfCacheStatus;desc="DYNAMIC" cfEdge;dur=597,cfOrigin;dur=0
- • strict-transport-security: max-age=31536000
- • vary: Accept-Encoding
- • x-content-type-options: nosniff
- • x-frame-options: DENY
- • x-nf-request-id: 01M1QZQCX059J5ZA35E0AK2WV5
- • x-xss-protection: 1; mode=block
-
CSP Quality Error
4 CSP hardening issues detected.
- • script-src/default-src permits 'unsafe-inline'.
- • CSP is missing object-src 'none'.
- • CSP is missing a base-uri restriction.
- • CSP is missing frame-ancestors protection.
- • Content-Security-Policy: default-src 'self'; style-src 'self' 'unsafe-inline'; frame-src https://www.google.com https://www.googletagmanager.com; script-src 'self' 'unsafe-inline' https://*.googletagmanager.com https://*.google-analytics.com https://analytics.ahrefs.com https://*.doubleclick.net https://*.google.com; img-src 'self' data: https://*.googletagmanager.com https://*.google-analytics.com https://*.doubleclick.net https://*.google.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://analytics.ahrefs.com https://*.doubleclick.net https://*.google.com;
Fix: Tighten Content-Security-Policy by removing unsafe directives and adding object-src, base-uri, and frame-ancestors restrictions.
-
Cookie Security Pass
No first-party cookies were set during the initial page load.
-
Server response headers do not expose version tokens.
-
Cloudflare Proxy Pass
Domain appears to be behind Cloudflare.
- • server: cloudflare
- • cf-cache-status: DYNAMIC
- • cf-ray: a362bd8b8bd6829e-IAD
-
Perceived Load Time Pass
Loaded in 0.88s (perceived).
-
No render-blocking scripts or styles detected.
-
Compression Warning
1 text resources look uncompressed.
- • https://mahjongroom.hk/metrics/ag/g/c?v=2&tid=G-45PKEM09QG>m=45g92e6930h2v9217400015z89217701370za20kzb9217701370zd9217701370&_p=1788585162142&_gaz=1&gcd=13l3l3l3l1l1&npa=0&dma=0&gdid=dYzg1YT&ecid=643600016&_eu=AAAAAGA&_uip=%3A%3A&are=1&cid=758927924.1788585163&fp=1&frm=0&pscdl=noapi&rcb=14&sr=1280x800&uaa=x86&uab=64&uafvl=Not%253AA-Brand%3B99.0.0.0%7CHeadlessChrome%3B145.0.7632.6%7CChromium%3B145.0.7632.6&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&ur=US-VA&_gsid=GcNJRvvr0W8DpuRqbgbOmDrREsoqYGPuqQ&gaf=2&_s=1&tag_exp=115938466~115938468~118897920~118897930~119791748~120213116~120385423~120469145~120469153~120914213&sid=1788585162&sct=1&seg=0&dl=https%3A%2F%2Fmahjongroom.hk%2F&dt=MahjongRoom.hk%20%E6%96%B0%E8%92%B2%E5%B4%9724%E5%B0%8F%E6%99%82%E7%A7%81%E4%BA%BA%E9%BA%BB%E9%9B%80%E6%88%BF%EF%BD%9C%E9%A6%99%E6%B8%AF%E9%BA%BB%E9%9B%80%E6%88%BF%E3%83%BB%E6%89%93%E9%BA%BB%E9%9B%80%20%2440%2F%E5%B0%8F%E6%99%82%E8%B5%B7&en=page_view&_fv=1&_nsi=1&_ss=1&gap.gtb=2&tfd=1163 (text/plain)
Fix: Enable Brotli or Gzip compression for HTML, CSS, JS, and JSON responses.
-
Robots.txt Pass
Found robots.txt (200).
-
Sitemap File Pass
Found sitemap (200) at https://mahjongroom.hk/sitemap.xml.
-
Crawl Directives Pass
Robots meta found: index, follow, max-snippet:-1, max-image-preview:large
Accessibility Basics
-
Form Labels Pass
All 3 controls are labeled.
-
Landmarks Pass
Header, nav, main, and footer landmarks are present.
-
Tap Target Size Warning
25 interactive elements appear smaller than 48px.
- • a (場地) - 28x22px
- • a (收費) - 28x22px
- • a (評價) - 28x22px
- • a (交通) - 28x22px
- • a (常見問題) - 56x22px
- • a.button.tiny (查時段・即時計價) - 132x39px
- • button#month-prev (上一個月) - 22x27px
- • button#month-next (下一個月) - 22x27px
- • button (2026年9月1日) - 66x32px
- • button (2026年9月2日) - 66x32px
- • button (2026年9月3日) - 66x32px
- • button (2026年9月4日) - 66x32px
- • button.is-selected (2026年9月5日) - 66x32px
- • button (2026年9月6日) - 66x32px
- • button (2026年9月7日) - 66x32px
- • button (2026年9月8日) - 66x32px
- • button (2026年9月9日) - 66x32px
- • button (2026年9月10日) - 66x32px
- • button (2026年9月11日) - 66x32px
- • button (2026年9月12日) - 66x32px
- • button (2026年9月13日) - 66x32px
- • button (2026年9月14日) - 66x32px
- • button (2026年9月15日) - 66x32px
- • button (2026年9月16日) - 66x32px
- • button (2026年9月17日) - 66x32px
Fix: Increase target size to at least 48x48 CSS pixels for touch interactions.
Social & Rich Results
-
Open Graph Basics Pass
Core Open Graph tags are present.
-
Open Graph Image Error
og:image URL returned HTTP 404.
Fix: Make sure the og:image URL returns HTTP 200 and points to a publicly accessible image.
-
Twitter Card Pass
twitter:card set to summary_large_image.
-
Structured Data Pass
JSON-LD schema detected.
-
PWA Metadata Warning
Manifest or Apple touch icon is missing.
Fix: Link your web app manifest and apple-touch-icon for improved install/share experiences.
-
Open Graph/Twitter Quality Warning
1 social preview quality issues detected.
- • ISSUE: Preview image URL failed with HTTP 404: https://mahjongroom.hk/img/og-mahjongroom.jpg
- • GUIDELINE: Optimal og:title length: 40-60 characters (acceptable: 10-70).
- • GUIDELINE: Optimal og:description length: 110-160 characters (acceptable: 50-200).
- • GUIDELINE: Optimal preview image size: 1200x630 pixels.
- • GUIDELINE: Optimal preview image aspect ratio: 1.91:1.
- • GUIDELINE: Optimal preview image file size: under 5 MB.
- • GUIDELINE: Recommended twitter:card: summary_large_image.
Fix: Use absolute OG/Twitter URLs, keep metadata lengths in recommended ranges, and provide a preview image near 1200x630 under 5MB.
Links Analysis
-
Internal Links Pass
Checked 7 links. No broken internal links found.
-
External Links Pass
No broken external links found in checked URLs.
-
Link Format Pass
All 23 links use non-empty href values.
Performance & Runtime
-
Core Web Vitals: LCP Pass
Largest Contentful Paint: 0.88s.
-
Core Web Vitals: CLS Pass
Cumulative Layout Shift: 0.028.
-
Total Blocking Time estimate: 163ms.
-
Broken Assets Error
1 asset requests failed.
- • https://static.cloudflareinsights.com/beacon.min.js/v31edd6df95cf4e85bb4c19e7a9bdbcba1788362987495 (csp)
Fix: Fix missing files, update asset URLs, and ensure static assets return HTTP 200.
-
JavaScript Runtime Errors Warning
3 JavaScript runtime issues detected.
- • Request failed: https://static.cloudflareinsights.com/beacon.min.js/v31edd6df95cf4e85bb4c19e7a9bdbcba1788362987495 (csp, type: script)
- • Request failed: https://mahjongroom.hk/metrics/ag/g/c?v=2&tid=G-45PKEM09QG>m=45g92e6930h2v9217400015z89217701370za20kzb9217701370zd9217701370&_p=1788585162142&_gaz=1&gcd=13l3l3l3l1l1&npa=0&dma=0&gdid=dYzg1YT&ecid=643600016&_eu=AAAAAGA&_uip=%3A%3A&are=1&cid=758927924.1788585163&fp=1&frm=0&pscdl=noapi&rcb=14&sr=1280x800&uaa=x86&uab=64&uafvl=Not%253AA-Brand%3B99.0.0.0%7CHeadlessChrome%3B145.0.7632.6%7CChromium%3B145.0.7632.6&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&ur=US-VA&_gsid=GcNJRvvr0W8DpuRqbgbOmDrREsoqYGPuqQ&gaf=2&_s=1&tag_exp=115938466~115938468~118897920~118897930~119791748~120213116~120385423~120469145~120469153~120914213&sid=1788585162&sct=1&seg=0&dl=https%3A%2F%2Fmahjongroom.hk%2F&dt=MahjongRoom.hk%20%E6%96%B0%E8%92%B2%E5%B4%9724%E5%B0%8F%E6%99%82%E7%A7%81%E4%BA%BA%E9%BA%BB%E9%9B%80%E6%88%BF%EF%BD%9C%E9%A6%99%E6%B8%AF%E9%BA%BB%E9%9B%80%E6%88%BF%E3%83%BB%E6%89%93%E9%BA%BB%E9%9B%80%20%2440%2F%E5%B0%8F%E6%99%82%E8%B5%B7&en=page_view&_fv=1&_nsi=1&_ss=1&gap.gtb=2&tfd=1163 (net::ERR_ABORTED, type: fetch)
- • Loading the script 'https://static.cloudflareinsights.com/beacon.min.js/v31edd6df95cf4e85bb4c19e7a9bdbcba1788362987495' violates the following Content Security Policy directive: "script-src 'self' 'unsafe-inline' https://*.googletagmanager.com https://*.google-analytics.com https://analytics.ahrefs.com https://*.doubleclick.net https://*.google.com". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback. The action has been blocked. [https://mahjongroom.hk/:1]
Fix: Fix JS files returning 404/failed requests and resolve the listed runtime exceptions.