Speed Insights
Grade C
75% performance
https://mymoon.dev
From MyMoon.dev
LCP
536ms
Largest paint
TBT
409ms
Blocking time
CLS
0.21
Layout shift
76
out of 100
85
out of 100
88/103 rule points
62
out of 100
47/76 rule points
100
out of 100
94/94 rule points
55
out of 100
61/110 rule points
Category point breakdown
Biggest score-losing checks
A small allowlist probe returned a public success response.
Detected 0 CTA candidate(s).
Detected 2 of 5 common public security controls. Present: x-content-type-options, referrer-policy. Missing: strict-transport-security, content-security-policy, frame protection (x-frame-options or content-security-policy frame-ancestors).
Detected 0 JSON-LD schema block(s).
Remove exposed sensitive files
-16 rule ptsWhat failed
A small public allowlist probe found a sensitive-looking file path.
Evidence
A small allowlist probe returned a public success response.
Priority
Priority 1: fix before sharing the page publicly.
Why it matters
Publicly exposed config or backup files can leak implementation details or secrets.
How to fix it
Remove the exposed file, block public access to that path, and rotate any secrets that may have been exposed.
Agent Prompt
Add common public security headers
-13 rule ptsWhat failed
Several basic browser protection headers were not visible.
Evidence
Detected 2 of 5 common public security controls. Present: x-content-type-options, referrer-policy. Missing: strict-transport-security, content-security-policy, frame protection (x-frame-options or content-security-policy frame-ancestors).
Priority
Priority 5: fix before sharing the page publicly.
Why it matters
These headers reduce avoidable browser-side risk and show a baseline of care before launch.
How to fix it
Add only the missing protections among Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, frame protection, and Referrer-Policy. An existing CSP frame-ancestors directive already provides frame protection and must remain unchanged.
Agent Prompt
Make the primary CTA obvious
-14 rule ptsWhat failed
The page does not have a detectable call to action.
Evidence
Detected 0 CTA candidate(s).
Priority
Priority 4: fix before sharing the page publicly.
Why it matters
Early visitors need a clear next step, such as trying the product, joining a waitlist, or booking a demo.
How to fix it
Add one prominent CTA above the fold with action-oriented text such as Start, Join, Try, Book, or Get started.
Agent Prompt
Add basic structured data
-10 rule ptsWhat failed
No JSON-LD schema was detected on the page.
Evidence
Detected 0 JSON-LD schema block(s).
Priority
Priority 12: fix during launch polish.
Why it matters
Structured data gives search and answer engines explicit facts about your product.
How to fix it
Add JSON-LD for SoftwareApplication, Product, Organization, or WebSite using only accurate public facts.
Agent Prompt
Strengthen visual hierarchy
-9 rule ptsWhat failed
The page does not expose enough hierarchy signals from headings, emphasis, or CTA structure.
Evidence
Detected 2 hierarchy signal(s) from headings, CTA, and emphasized text.
Priority
Priority 12: fix during launch polish.
Why it matters
Hierarchy tells visitors what to read first and what action to take next.
How to fix it
Create a clear H1, supportive section headings, emphasized proof, and one visually prominent primary CTA.
Agent Prompt
SEO / AEO
Severity mix: 1 critical, 6 high, 3 medium, 1 low.
Schema presence
-10 rule ptsDetected 0 JSON-LD schema block(s).
Open Graph basics
-5 rule ptsDetected 0 of 4 Open Graph basics.
Security
Severity mix: 2 critical, 3 high, 0 medium, 0 low.
Sensitive file probes
-16 rule ptsA small allowlist probe returned a public success response.
Common security headers
-13 rule ptsDetected 2 of 5 common public security controls. Present: x-content-type-options, referrer-policy. Missing: strict-transport-security, content-security-policy, frame protection (x-frame-options or content-security-policy frame-ancestors).
Accessibility
Severity mix: 0 critical, 3 high, 5 medium, 0 low.
No failed checks in this category.
Design
Severity mix: 0 critical, 3 high, 6 medium, 2 low.
Visible primary CTA
-14 rule ptsDetected 0 CTA candidate(s).
Trust signals
-10 rule ptsDetected 0 trust-signal keyword occurrence(s).
Visual hierarchy
-9 rule ptsDetected 2 hierarchy signal(s) from headings, CTA, and emphasized text.
Failed checks
These checks need attention.
Schema presence
0/10Detected 0 JSON-LD schema block(s).
Failed: earned 0 of 10 points.
Priority: Priority 12: fix during launch polish.
Why it matters: Structured data gives search and answer engines explicit facts about your product.
Fix: Add JSON-LD for SoftwareApplication, Product, Organization, or WebSite using only accurate public facts.
Agent Prompt
Open Graph basics
0/5Detected 0 of 4 Open Graph basics.
Failed: earned 0 of 5 points.
Priority: Priority 18: lower-risk cleanup after urgent launch blockers.
Why it matters: Launch links on X, LinkedIn, Slack, and communities look less trustworthy without a strong preview.
Fix: Add og:title, og:description, og:image, and og:url that match the landing page content.
Agent Prompt
Common security headers
5/18Detected 2 of 5 common public security controls. Present: x-content-type-options, referrer-policy. Missing: strict-transport-security, content-security-policy, frame protection (x-frame-options or content-security-policy frame-ancestors).
Failed: earned 5 of 18 points from partial coverage.
Priority: Priority 5: fix before sharing the page publicly.
Why it matters: These headers reduce avoidable browser-side risk and show a baseline of care before launch.
Fix: Add only the missing protections among Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, frame protection, and Referrer-Policy. An existing CSP frame-ancestors directive already provides frame protection and must remain unchanged.
Agent Prompt
Sensitive file probes
0/16A small allowlist probe returned a public success response.
Failed: earned 0 of 16 points.
Priority: Priority 1: fix before sharing the page publicly.
Why it matters: Publicly exposed config or backup files can leak implementation details or secrets.
Fix: Remove the exposed file, block public access to that path, and rotate any secrets that may have been exposed.
Agent Prompt
Visible primary CTA
0/14Detected 0 CTA candidate(s).
Failed: earned 0 of 14 points.
Priority: Priority 4: fix before sharing the page publicly.
Why it matters: Early visitors need a clear next step, such as trying the product, joining a waitlist, or booking a demo.
Fix: Add one prominent CTA above the fold with action-oriented text such as Start, Join, Try, Book, or Get started.
Agent Prompt
Trust signals
0/10Detected 0 trust-signal keyword occurrence(s).
Failed: earned 0 of 10 points.
Priority: Priority 16: lower-risk cleanup after urgent launch blockers.
Why it matters: Trust signals reduce hesitation when strangers see the product for the first time.
Fix: Add honest proof such as customer quotes, usage stats, founder credibility, security notes, or relevant logos.
Agent Prompt
Spacing consistency
0/7Detected 0 spacing class/style signal(s).
Failed: earned 0 of 7 points.
Priority: Priority 25: lower-risk cleanup after urgent launch blockers.
Why it matters: Consistent spacing helps the page feel deliberate and easier to scan.
Fix: Use consistent section padding, gaps, and margins across repeated content blocks.
Agent Prompt
Visual hierarchy
0/9Detected 2 hierarchy signal(s) from headings, CTA, and emphasized text.
Failed: earned 0 of 9 points.
Priority: Priority 12: fix during launch polish.
Why it matters: Hierarchy tells visitors what to read first and what action to take next.
Fix: Create a clear H1, supportive section headings, emphasized proof, and one visually prominent primary CTA.
Agent Prompt
Rendered layout ergonomics
0/9Horizontal overflow: 0px. Small tap targets: 9.
Affected elements
INFO
INFO
INFO
Go to slide 1
Failed: earned 0 of 9 points.
Priority: Priority 13: fix during launch polish.
Why it matters: Horizontal overflow and tiny tap targets make the page feel broken on real devices, especially for mobile visitors.
Fix: Remove elements wider than the viewport, add responsive constraints, and make important links, buttons, inputs, and controls at least 40px tall and wide where possible.
Agent Prompt
Page-level AEO readiness
Shared eligibility and content signals that affect every search and answer agent.
Index and citation eligibility
No general noindex directive was detected.
Snippet and answer controls
No general nosnippet or max-snippet:0 control was detected.
Canonical alignment
The canonical resolves to the scanned public URL.
Sitemap coverage and freshness
The exact URL appears in the fetched sitemap with lastmod 2026-08-13.
Structured data
Detected 0 JSON-LD block(s), 0 parse error(s), and types none.
Public or paywalled content
No isAccessibleForFree structured-data value was detected.
Entity clarity
Detected 3 of 3 core identity signals across the title, description, and H1.
Answer-ready visible text
Detected 152 visible words and 1 audience, use-case, pricing, or integration signals.
Authorship and accountability
No author meta value or structured-data author was detected.
Published or updated date
No datePublished or dateModified value was detected in structured data.
Supporting-source links
Detected 1 external source or reference link(s); link quality still requires editorial review.
Rendered content availability
Rendered audit completed with 8 visible text element(s).
Synthetic search-agent reachability
8 of 8 search/discovery User-Agent probes returned reachable content.
Optional LLM-readable summary
https://mymoon.dev/llms.txt returned HTTP 200; this is supplemental and does not determine AI-search eligibility.
OAI-SearchBotAI search
Robots: allowed by * allow: / ยท line 2
Probe: reachable ยท HTTP 200 ยท 100% parity
GPTBotModel training
Robots: allowed by * allow: / ยท line 2
Probe: not tested for this control
ChatGPT-UserUser-requested fetch
Robots: not applicable to user-requested fetches
Probe: not tested for this control
ClaudeBotModel training
Robots: allowed by * allow: / ยท line 2
Probe: not tested for this control
Claude-SearchBotAI search
Robots: allowed by * allow: / ยท line 2
Probe: reachable ยท HTTP 200 ยท 100% parity
Claude-UserUser-requested fetch
Robots: allowed by * allow: / ยท line 2
Probe: reachable ยท HTTP 200 ยท 100% parity
GooglebotSearch and discovery
Robots: allowed by * allow: / ยท line 2
Probe: reachable ยท HTTP 200 ยท 100% parity
Google-ExtendedData-use policy control
Robots: allowed by * allow: / ยท line 2
Probe: not tested for this control
BingbotSearch and discovery
Robots: allowed by * allow: / ยท line 2
Probe: reachable ยท HTTP 200 ยท 100% parity
PerplexityBotAI search
Robots: allowed by * allow: / ยท line 2
Probe: reachable ยท HTTP 200 ยท 100% parity
Perplexity-UserUser-requested fetch
Robots: not applicable to user-requested fetches
Probe: not tested for this control
ApplebotSearch and discovery
Robots: allowed by * allow: / ยท line 2
Probe: reachable ยท HTTP 200 ยท 100% parity
Applebot-ExtendedData-use policy control
Robots: allowed by * allow: / ยท line 2
Probe: not tested for this control
MistralAI-IndexAI search
Robots: allowed by * allow: / ยท line 2
Probe: reachable ยท HTTP 200 ยท 100% parity
MistralAI-UserUser-requested fetch
Robots: allowed by * allow: / ยท line 2
Probe: reachable ยท HTTP 200 ยท 100% parity
meta-externalagentModel training
Robots: allowed by * allow: / ยท line 2
Probe: not tested for this control
meta-externalfetcherUser-requested fetch
Robots: allowed by * allow: / ยท line 2
Probe: reachable ยท HTTP 200 ยท 100% parity
AmazonbotModel training
Robots: allowed by * allow: / ยท line 2
Probe: not tested for this control
Amzn-SearchBotAI search
Robots: allowed by * allow: / ยท line 2
Probe: reachable ยท HTTP 200 ยท 100% parity
Amzn-UserUser-requested fetch
Robots: allowed by * allow: / ยท line 2
Probe: reachable ยท HTTP 200 ยท 100% parity
CCBotModel training
Robots: allowed by * allow: / ยท line 2
Probe: not tested for this control
Ready combines robots policy, a bounded synthetic User-Agent fetch, indexability, and snippet eligibility. Synthetic probes do not prove vendor-origin traffic. Purple preference states are training or data-use choices and do not lower the AEO score.
Share preview
mymoon.dev website audit report
Close to ready: 76/100 overall, with prioritized fixes for SEO, security, accessibility, and design.
Public reports expose the scanned public URL, safe scores, sanitized public evidence, and fix guidance. They do not include credentials, cookies, hidden form values, or sensitive response bodies.
