Audit Result

UUID: 01a06ffb-bf93-73c7-a7a8-25f8db563826

mahjongroom.hk

https://mahjongroom.hk/

Scanned 1 day ago

81
Fair Score
39 total checks
Passed
28
Warnings
7
Errors
4

Meta Information

  • Title Tag Pass

    Found 45 characters. Length is optimal.

  • Found 83 characters. Good snippet length.

  • Canonical found: https://mahjongroom.hk/

  • Favicon Warning

    No favicon link found in <head>.

    Fix: Add <link rel="icon" href="/favicon.ico"> to ensure browser tab and bookmark visibility.

  • Viewport configured: width=device-width, initial-scale=1

  • HTML Lang Pass

    Language declared as "zh-HK".

Content Structure

  • H1 Tag Pass

    Exactly one H1 found: "MahjongRoom.hk 新蒲崗24小時私人麻雀房。想打,就先查時段。".

  • Valid heading flow across 29 headings.

  • 3 of 11 images are missing alt text.

    Fix: Add meaningful alt attributes to all informative images for accessibility and image SEO.

Technical Optimization

  • HTTPS Pass

    Page is served over HTTPS.

  • 2 HTTPS hardening issues detected.

    • • HSTS is missing includeSubDomains.
    • • Could not probe the HTTP version of this page.
    • • Strict-Transport-Security: max-age=31536000

    Fix: Set Strict-Transport-Security with a long max-age, add includeSubDomains, and redirect all HTTP requests to HTTPS.

  • Core security headers were detected.

    Full HTTP headers (22)
    • • age: 1
    • • alt-svc: h3=":443"; ma=86400
    • • cache-control: public,max-age=0,must-revalidate
    • • cache-status: "Netlify Edge"; fwd=miss; fwd-status=200; stored
    • • cf-cache-status: DYNAMIC
    • • cf-ray: a362bd8b8bd6829e-IAD
    • • content-encoding: zstd
    • • content-security-policy: default-src 'self'; style-src 'self' 'unsafe-inline'; frame-src https://www.google.com https://www.googletagmanager.com; script-src 'self' 'unsafe-inline' https://*.googletagmanager.com https://*.google-analytics.com https://analytics.ahrefs.com https://*.doubleclick.net https://*.google.com; img-src 'self' data: https://*.googletagmanager.com https://*.google-analytics.com https://*.doubleclick.net https://*.google.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://analytics.ahrefs.com https://*.doubleclick.net https://*.google.com;
    • • content-type: text/html; charset=utf-8
    • • date: Sat, 05 Sep 2026 05:12:42 GMT
    • • nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
    • • permissions-policy: camera=(), microphone=(), geolocation=()
    • • referrer-policy: strict-origin-when-cross-origin
    • • report-to: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=R56aABAEBA7mQ4F4ZXjqefnI1nnEFD%2F6KH6RuChkT9%2BuUPomkrIjIw8jOK5RQnv0zsWLwWshfOQpXhvSNcLhPhpR1c9l5ZjNeF9D%2BXfo86s676Cj9YE6%2BWSZ1ipZ2aCLqx2N6K4NChV4CSnR9Q%3D%3D"}]}
    • • server: cloudflare
    • • server-timing: cfCacheStatus;desc="DYNAMIC" cfEdge;dur=597,cfOrigin;dur=0
    • • strict-transport-security: max-age=31536000
    • • vary: Accept-Encoding
    • • x-content-type-options: nosniff
    • • x-frame-options: DENY
    • • x-nf-request-id: 01M1QZQCX059J5ZA35E0AK2WV5
    • • x-xss-protection: 1; mode=block
  • CSP Quality Error

    4 CSP hardening issues detected.

    • • script-src/default-src permits 'unsafe-inline'.
    • • CSP is missing object-src 'none'.
    • • CSP is missing a base-uri restriction.
    • • CSP is missing frame-ancestors protection.
    • • Content-Security-Policy: default-src 'self'; style-src 'self' 'unsafe-inline'; frame-src https://www.google.com https://www.googletagmanager.com; script-src 'self' 'unsafe-inline' https://*.googletagmanager.com https://*.google-analytics.com https://analytics.ahrefs.com https://*.doubleclick.net https://*.google.com; img-src 'self' data: https://*.googletagmanager.com https://*.google-analytics.com https://*.doubleclick.net https://*.google.com; connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com https://*.googletagmanager.com https://analytics.ahrefs.com https://*.doubleclick.net https://*.google.com;

    Fix: Tighten Content-Security-Policy by removing unsafe directives and adding object-src, base-uri, and frame-ancestors restrictions.

  • No first-party cookies were set during the initial page load.

  • Server response headers do not expose version tokens.

  • Domain appears to be behind Cloudflare.

    • • server: cloudflare
    • • cf-cache-status: DYNAMIC
    • • cf-ray: a362bd8b8bd6829e-IAD
  • Loaded in 0.88s (perceived).

  • No render-blocking scripts or styles detected.

  • Compression Warning

    1 text resources look uncompressed.

    • • https://mahjongroom.hk/metrics/ag/g/c?v=2&tid=G-45PKEM09QG&gtm=45g92e6930h2v9217400015z89217701370za20kzb9217701370zd9217701370&_p=1788585162142&_gaz=1&gcd=13l3l3l3l1l1&npa=0&dma=0&gdid=dYzg1YT&ecid=643600016&_eu=AAAAAGA&_uip=%3A%3A&are=1&cid=758927924.1788585163&fp=1&frm=0&pscdl=noapi&rcb=14&sr=1280x800&uaa=x86&uab=64&uafvl=Not%253AA-Brand%3B99.0.0.0%7CHeadlessChrome%3B145.0.7632.6%7CChromium%3B145.0.7632.6&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&ur=US-VA&_gsid=GcNJRvvr0W8DpuRqbgbOmDrREsoqYGPuqQ&gaf=2&_s=1&tag_exp=115938466~115938468~118897920~118897930~119791748~120213116~120385423~120469145~120469153~120914213&sid=1788585162&sct=1&seg=0&dl=https%3A%2F%2Fmahjongroom.hk%2F&dt=MahjongRoom.hk%20%E6%96%B0%E8%92%B2%E5%B4%9724%E5%B0%8F%E6%99%82%E7%A7%81%E4%BA%BA%E9%BA%BB%E9%9B%80%E6%88%BF%EF%BD%9C%E9%A6%99%E6%B8%AF%E9%BA%BB%E9%9B%80%E6%88%BF%E3%83%BB%E6%89%93%E9%BA%BB%E9%9B%80%20%2440%2F%E5%B0%8F%E6%99%82%E8%B5%B7&en=page_view&_fv=1&_nsi=1&_ss=1&gap.gtb=2&tfd=1163 (text/plain)

    Fix: Enable Brotli or Gzip compression for HTML, CSS, JS, and JSON responses.

  • Robots.txt Pass

    Found robots.txt (200).

  • Found sitemap (200) at https://mahjongroom.hk/sitemap.xml.

  • Robots meta found: index, follow, max-snippet:-1, max-image-preview:large

Accessibility Basics

  • All 3 controls are labeled.

  • Landmarks Pass

    Header, nav, main, and footer landmarks are present.

  • Tap Target Size Warning

    25 interactive elements appear smaller than 48px.

    • • a (場地) - 28x22px
    • • a (收費) - 28x22px
    • • a (評價) - 28x22px
    • • a (交通) - 28x22px
    • • a (常見問題) - 56x22px
    • • a.button.tiny (查時段・即時計價) - 132x39px
    • • button#month-prev (上一個月) - 22x27px
    • • button#month-next (下一個月) - 22x27px
    • • button (2026年9月1日) - 66x32px
    • • button (2026年9月2日) - 66x32px
    • • button (2026年9月3日) - 66x32px
    • • button (2026年9月4日) - 66x32px
    • • button.is-selected (2026年9月5日) - 66x32px
    • • button (2026年9月6日) - 66x32px
    • • button (2026年9月7日) - 66x32px
    • • button (2026年9月8日) - 66x32px
    • • button (2026年9月9日) - 66x32px
    • • button (2026年9月10日) - 66x32px
    • • button (2026年9月11日) - 66x32px
    • • button (2026年9月12日) - 66x32px
    • • button (2026年9月13日) - 66x32px
    • • button (2026年9月14日) - 66x32px
    • • button (2026年9月15日) - 66x32px
    • • button (2026年9月16日) - 66x32px
    • • button (2026年9月17日) - 66x32px

    Fix: Increase target size to at least 48x48 CSS pixels for touch interactions.

Social & Rich Results

  • Core Open Graph tags are present.

  • og:image URL returned HTTP 404.

    Fix: Make sure the og:image URL returns HTTP 200 and points to a publicly accessible image.

  • twitter:card set to summary_large_image.

  • JSON-LD schema detected.

  • PWA Metadata Warning

    Manifest or Apple touch icon is missing.

    Fix: Link your web app manifest and apple-touch-icon for improved install/share experiences.

  • 1 social preview quality issues detected.

    • • ISSUE: Preview image URL failed with HTTP 404: https://mahjongroom.hk/img/og-mahjongroom.jpg
    • • GUIDELINE: Optimal og:title length: 40-60 characters (acceptable: 10-70).
    • • GUIDELINE: Optimal og:description length: 110-160 characters (acceptable: 50-200).
    • • GUIDELINE: Optimal preview image size: 1200x630 pixels.
    • • GUIDELINE: Optimal preview image aspect ratio: 1.91:1.
    • • GUIDELINE: Optimal preview image file size: under 5 MB.
    • • GUIDELINE: Recommended twitter:card: summary_large_image.

    Fix: Use absolute OG/Twitter URLs, keep metadata lengths in recommended ranges, and provide a preview image near 1200x630 under 5MB.

Links Analysis

  • Checked 7 links. No broken internal links found.

  • No broken external links found in checked URLs.

  • All 23 links use non-empty href values.

Performance & Runtime

  • Largest Contentful Paint: 0.88s.

  • Cumulative Layout Shift: 0.028.

  • Total Blocking Time estimate: 163ms.

  • 1 asset requests failed.

    • • https://static.cloudflareinsights.com/beacon.min.js/v31edd6df95cf4e85bb4c19e7a9bdbcba1788362987495 (csp)

    Fix: Fix missing files, update asset URLs, and ensure static assets return HTTP 200.

  • 3 JavaScript runtime issues detected.

    • • Request failed: https://static.cloudflareinsights.com/beacon.min.js/v31edd6df95cf4e85bb4c19e7a9bdbcba1788362987495 (csp, type: script)
    • • Request failed: https://mahjongroom.hk/metrics/ag/g/c?v=2&tid=G-45PKEM09QG&gtm=45g92e6930h2v9217400015z89217701370za20kzb9217701370zd9217701370&_p=1788585162142&_gaz=1&gcd=13l3l3l3l1l1&npa=0&dma=0&gdid=dYzg1YT&ecid=643600016&_eu=AAAAAGA&_uip=%3A%3A&are=1&cid=758927924.1788585163&fp=1&frm=0&pscdl=noapi&rcb=14&sr=1280x800&uaa=x86&uab=64&uafvl=Not%253AA-Brand%3B99.0.0.0%7CHeadlessChrome%3B145.0.7632.6%7CChromium%3B145.0.7632.6&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&ur=US-VA&_gsid=GcNJRvvr0W8DpuRqbgbOmDrREsoqYGPuqQ&gaf=2&_s=1&tag_exp=115938466~115938468~118897920~118897930~119791748~120213116~120385423~120469145~120469153~120914213&sid=1788585162&sct=1&seg=0&dl=https%3A%2F%2Fmahjongroom.hk%2F&dt=MahjongRoom.hk%20%E6%96%B0%E8%92%B2%E5%B4%9724%E5%B0%8F%E6%99%82%E7%A7%81%E4%BA%BA%E9%BA%BB%E9%9B%80%E6%88%BF%EF%BD%9C%E9%A6%99%E6%B8%AF%E9%BA%BB%E9%9B%80%E6%88%BF%E3%83%BB%E6%89%93%E9%BA%BB%E9%9B%80%20%2440%2F%E5%B0%8F%E6%99%82%E8%B5%B7&en=page_view&_fv=1&_nsi=1&_ss=1&gap.gtb=2&tfd=1163 (net::ERR_ABORTED, type: fetch)
    • • Loading the script 'https://static.cloudflareinsights.com/beacon.min.js/v31edd6df95cf4e85bb4c19e7a9bdbcba1788362987495' violates the following Content Security Policy directive: "script-src 'self' 'unsafe-inline' https://*.googletagmanager.com https://*.google-analytics.com https://analytics.ahrefs.com https://*.doubleclick.net https://*.google.com". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback. The action has been blocked. [https://mahjongroom.hk/:1]

    Fix: Fix JS files returning 404/failed requests and resolve the listed runtime exceptions.