Real measurements

Sample website check report

This sample report shows what a website check looks like. We measured two real websites and removed every identifying detail. For each, you see speed on a phone, search and AI basics, and contact paths, followed by what we would do. Both examples are labelled Website A and Website B.

How to read these examples

Both are real websites. We removed the domain, the brand, logos and anything that could identify them. Values were measured on 5 October 2026 with Lighthouse in a lab setting: mobile means an emulated phone on a simulated slow 4G connection.

Both sites are in good shape. A good check also says what to leave alone. Lab values are not field data from real visitors.

Example report: anonymized real website — Website A

CheckWhat we measured
Speed, mobilePerformance score 100, largest content shown after 1.23 s, layout shift 0.000, blocking time 0 ms, first content after 1.04 s
Speed, desktopPerformance score 100, largest content shown after 0.37 s
Server response190 ms; the page is sent with no-store caching, so every visit reaches the server
Page weightAbout 14 KB of HTML compressed, 3 images (all SVG, all with description and size set)
Title and descriptionTitle 57 characters, description 158 characters, both within the usual display limits
HeadingsOne H1, 14 H2, 23 H3
Structured dataOrganization, WebSite, WebPage and FAQPage with 6 questions
Robots and AI accessSearch and AI crawlers are allowed, sitemap listed, llms.txt present, a missing URL returns a real 404; the AI crawlers we tested get the page (HTTP 200)
Contact pathsContact page, e-mail, phone and WhatsApp links; no form on the home page
Security headersHSTS, nosniff, referrer policy and frame options set; the content security policy allows unsafe inline and eval
Third-party scriptsNone in the page HTML

What we would do for Website A

  1. Leave the speed alone. Mobile score 100 and 1.23 s to largest content is good. Changes here would risk more than they gain.
  2. Add a short enquiry form to the home page. Visitors can only use links. A short form removes a step for someone who arrives from a QR code at a stand.
  3. Tighten the content security policy. It currently allows unsafe inline and eval. We would test a stricter policy first and then enforce it.
  4. Measure before caching the HTML. The 190 ms server response could drop with a page cache, but the gain on a score of 100 is small. We would measure first.

Example report: anonymized real website — Website B

CheckWhat we measured
Speed, mobilePerformance score 99, largest content shown after 1.73 s, layout shift 0.000, blocking time 0 ms, first content after 1.72 s
Speed, desktopPerformance score 100, largest content shown after 0.55 s
Server response176 ms; HTML is marked private, so shared caches do not store it
Page weightAbout 20 KB of HTML compressed (99 KB uncompressed), of which about 41 KB uncompressed is inline CSS; no images on the home page
Title and descriptionTitle 66 characters, description 168 characters, both over the usual display limits
HeadingsOne H1, 8 H2, 6 H3
Structured dataOrganization, Person, WebSite, ProfessionalService and FAQPage with 6 questions
Robots and AI accessSearch and AI crawlers are allowed, sitemap listed, llms.txt present, a missing URL returns a real 404; the AI crawlers we tested get the page (HTTP 200)
Contact pathsContact page, e-mail, 4 phone links, 3 WhatsApp links and 2 forms on the home page
Security headersHSTS (180 days, without subdomains), nosniff, referrer policy and frame options set; the content security policy runs in report-only mode and is not enforced
Third-party scripts1 external host, a CDN analytics beacon, loaded in the page HTML

What we would do for Website B

  1. Shorten the title to 60 characters and the description to 160. Both are over the usual limits, so search results may cut them off.
  2. Look at first paint, not images. Largest content (1.73 s) and first content (1.72 s) arrive almost together, so the wait is before the first paint. The 41 KB of inline CSS is the first thing we would examine.
  3. Move the content security policy from report-only to enforced after reading its reports.
  4. Load the analytics beacon only after consent if the visitor’s region requires it. We would check this against the site’s consent set-up.

What this means for your check

Your own result follows the same logic: what we measured, what it means and what we would fix first. We write it in plain language and send it by e-mail within two working days. Ready? Request your free website check. Questions? Contact us.