New Audit
History

Puzzles

Puzzles Consulting

https://puzzlesconsulting.com

Audited 2026-03-24

92

Overall

1 Critical 5 High 6 Medium 3 Low
We have completed a comprehensive audit of your website across 15 performance and security metrics, identifying a mix of foundational and technical areas for improvement. The most urgent priority is the missing security header, which must be addressed immediately to ensure robust visitor protection. We recommend scheduling a brief call to review these specific findings so we can prioritize a roadmap for these technical implementation steps.
72
SEO
100
Performance
100
Accessibility
100
UI / Visual
100
Content
78
Technical

Screenshots

Desktop (1440px)

Desktop screenshot

Mobile (375px)

Mobile screenshot

SEO

4 high 4 medium
high

Title too short

<title> is 18 chars: "Puzzles Consulting". Google may rewrite it.

Expand to 50-60 characters.
high

Missing meta description

No <meta name="description"> found.

Add a meta description of 120-160 chars.
high

Multiple H1 tags (3)

Found 3 H1 tags: "Small pieces build a BIG puzzle."; "Your growth journey starts"; "HERE!". Confuses search engines about the page topic.

Keep only one H1 — the primary page heading. Remove or demote the others to H2.
high

Heading hierarchy skip

Heading jumps from H2 to H5: "Contact Us"

Use H3 instead of H5 here.
medium

Missing og:title

<meta property="og:title"> not found.

Add og:title for better social sharing previews.
medium

Missing og:description

<meta property="og:description"> not found.

Add og:description for better social sharing previews.
medium

Missing og:image

<meta property="og:image"> not found.

Add og:image for better social sharing previews.
medium

Missing twitter:card

No twitter:card meta tag found.

Add <meta name="twitter:card" content="summary_large_image">.

Technical

1 critical 1 high 2 medium 3 low
critical

Missing HSTS header

The HSTS HTTP response header is not set.

Add to your server/CDN/nginx config: Strict-Transport-Security: max-age=31536000; includeSubDomains
high

Missing X-Content-Type-Options header

The X-Content-Type-Options HTTP response header is not set.

Add to your server/CDN/nginx config: X-Content-Type-Options: nosniff
medium

Missing X-Frame-Options header

The X-Frame-Options HTTP response header is not set.

Add to your server/CDN/nginx config: X-Frame-Options: SAMEORIGIN
medium

Missing Content-Security-Policy header

The Content-Security-Policy HTTP response header is not set.

Add to your server/CDN/nginx config: Content-Security-Policy: default-src 'self'; img-src * data:; script-src 'self' (customize per stack)
low

Missing Referrer-Policy header

The Referrer-Policy HTTP response header is not set.

Add to your server/CDN/nginx config: Referrer-Policy: strict-origin-when-cross-origin
low

Missing Permissions-Policy header

The Permissions-Policy HTTP response header is not set.

Add to your server/CDN/nginx config: Permissions-Policy: camera=(), microphone=(), geolocation=()
low

4 cookie(s) missing SameSite attribute

Cookies without SameSite may be sent on cross-site requests: __cf_bm, __cf_bm, __cf_bm

Set SameSite=Lax or Strict on all cookies.
New Audit Puzzles History

Add to Asana