Speed Insights
Grade D
61% performance
https://www.witchesbrew.co
From witchesbrew.co
LCP
980ms
Largest paint
TBT
1794ms
Blocking time
CLS
0.01
Layout shift
75
out of 100
93
out of 100
103/111 rule points
76
out of 100
58/76 rule points
46
out of 100
43/94 rule points
83
out of 100
91/110 rule points
Category point breakdown
Biggest score-losing checks
axe found 6 violation rule(s), including 2 serious or critical rule(s). Top rules: aria-required-children (1), list (1), landmark-main-is-top-level (1), landmark-no-duplicate-main (1), landmark-unique (1).
Affected elements
Certain ARIA roles must contain particular children
Fix any of the following: Element has children which are not allowed: button[aria-label]
<ul> and <ol> must only directly contain <li>, <script> or <template> elements
Fix all of the following: List element has direct children that are not allowed: [role=presentation]
Main landmark should not be contained in another landmark
Fix any of the following: The main landmark is contained in another landmark.
Document should not have more than one main landmark
Fix any of the following: Document has more than one main landmark
A small allowlist probe returned a public success response.
Detected labels or accessible names for 14 of 18 form control(s).
Heading levels found: 2, 2, 1, 2, 2, 3, 3, 3, 3, 2, 3, 3, 3, 3, 2, 3, 3, 3, 3, 3, 4, 4, 4, 4, 3, 3, 3, 2, 4, 2, 2, 2, 2, 2, 2, 2.
Remove exposed sensitive files
-16 rule ptsWhat failed
A small public allowlist probe found a sensitive-looking file path.
Evidence
A small allowlist probe returned a public success response.
Priority
Priority 1: fix before sharing the page publicly.
Why it matters
Publicly exposed config or backup files can leak implementation details or secrets.
How to fix it
Remove the exposed file, block public access to that path, and rotate any secrets that may have been exposed.
Agent Prompt
Fix rendered axe accessibility violations
-18 rule ptsWhat failed
The rendered page has accessibility rule violations detected by axe-core.
Evidence
axe found 6 violation rule(s), including 2 serious or critical rule(s). Top rules: aria-required-children (1), list (1), landmark-main-is-top-level (1), landmark-no-duplicate-main (1), landmark-unique (1).
Affected elements
Certain ARIA roles must contain particular children
Fix any of the following: Element has children which are not allowed: button[aria-label]
<ul> and <ol> must only directly contain <li>, <script> or <template> elements
Fix all of the following: List element has direct children that are not allowed: [role=presentation]
Main landmark should not be contained in another landmark
Fix any of the following: The main landmark is contained in another landmark.
Document should not have more than one main landmark
Fix any of the following: Document has more than one main landmark
Priority
Priority 5: fix before sharing the page publicly.
Why it matters
axe checks the actual browser-rendered page, so these issues can affect people using keyboards, screen readers, or other assistive technology.
How to fix it
Fix the top axe rule IDs first, especially critical and serious violations around names, roles, labels, headings, contrast, landmarks, and keyboard-accessible controls.
Agent Prompt
Label public form fields
-14 rule ptsWhat failed
Some form controls do not have a detectable label or accessible name.
Evidence
Detected labels or accessible names for 14 of 18 form control(s).
Priority
Priority 7: fix during launch polish.
Why it matters
Unlabeled inputs make email capture, demo requests, and signups harder for assistive technology users.
How to fix it
Connect each input to a visible label or an accurate aria-label/aria-labelledby value.
Agent Prompt
Add common public security headers
-2 rule ptsWhat failed
Several basic browser protection headers were not visible.
Evidence
Detected 4 of 5 common public security controls. Present: strict-transport-security, content-security-policy, x-content-type-options, frame protection (content-security-policy frame-ancestors and x-frame-options). Missing: referrer-policy.
Priority
Priority 5: fix before sharing the page publicly.
Why it matters
These headers reduce avoidable browser-side risk and show a baseline of care before launch.
How to fix it
Add only the missing protections among Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, frame protection, and Referrer-Policy. An existing CSP frame-ancestors directive already provides frame protection and must remain unchanged.
Agent Prompt
Use one clear H1 and ordered headings
-8 rule ptsWhat failed
The page heading structure is either missing a single main heading or skips heading levels.
Evidence
Detected 1 H1 heading(s) and 36 total headings.
Priority
Priority 9: fix during launch polish.
Why it matters
Clear headings help visitors, search engines, and assistive technology understand the page quickly.
How to fix it
Keep one H1 for the main promise, then use H2 and H3 headings in order for sections below it.
Agent Prompt
SEO / AEO
Severity mix: 1 critical, 7 high, 3 medium, 1 low.
Heading structure
-8 rule ptsDetected 1 H1 heading(s) and 36 total headings.
Security
Severity mix: 2 critical, 3 high, 0 medium, 0 low.
Sensitive file probes
-16 rule ptsA small allowlist probe returned a public success response.
Common security headers
-2 rule ptsDetected 4 of 5 common public security controls. Present: strict-transport-security, content-security-policy, x-content-type-options, frame protection (content-security-policy frame-ancestors and x-frame-options). Missing: referrer-policy.
Accessibility
Severity mix: 0 critical, 3 high, 5 medium, 0 low.
Rendered axe accessibility violations
-18 rule ptsaxe found 6 violation rule(s), including 2 serious or critical rule(s). Top rules: aria-required-children (1), list (1), landmark-main-is-top-level (1), landmark-no-duplicate-main (1), landmark-unique (1).
Affected elements
Certain ARIA roles must contain particular children
Fix any of the following: Element has children which are not allowed: button[aria-label]
<ul> and <ol> must only directly contain <li>, <script> or <template> elements
Fix all of the following: List element has direct children that are not allowed: [role=presentation]
Main landmark should not be contained in another landmark
Fix any of the following: The main landmark is contained in another landmark.
Document should not have more than one main landmark
Fix any of the following: Document has more than one main landmark
Form labels
-14 rule ptsDetected labels or accessible names for 14 of 18 form control(s).
Heading order
-11 rule ptsHeading levels found: 2, 2, 1, 2, 2, 3, 3, 3, 3, 2, 3, 3, 3, 3, 2, 3, 3, 3, 3, 3, 4, 4, 4, 4, 3, 3, 3, 2, 4, 2, 2, 2, 2, 2, 2, 2.
Design
Severity mix: 0 critical, 3 high, 6 medium, 2 low.
Rendered speed signals
-10 rule ptsDOMContentLoaded: 3477ms. Load complete: 0ms. First contentful paint: 980ms. Resources: 154. Scripts: 75. Images: 35. Third-party origins: 6. Transfer: not available.
Rendered layout ergonomics
-9 rule ptsHorizontal overflow: 0px. Small tap targets: 26.
Affected elements
Read About Our Sourcing ✦
Browse the Tea Apothecary ✦
Review 1
Review 2
Failed checks
These checks need attention.
Heading structure
0/8Detected 1 H1 heading(s) and 36 total headings.
Failed: earned 0 of 8 points.
Priority: Priority 9: fix during launch polish.
Why it matters: Clear headings help visitors, search engines, and assistive technology understand the page quickly.
Fix: Keep one H1 for the main promise, then use H2 and H3 headings in order for sections below it.
Agent Prompt
Common security headers
16/18Detected 4 of 5 common public security controls. Present: strict-transport-security, content-security-policy, x-content-type-options, frame protection (content-security-policy frame-ancestors and x-frame-options). Missing: referrer-policy.
Failed: earned 16 of 18 points from partial coverage.
Priority: Priority 5: fix before sharing the page publicly.
Why it matters: These headers reduce avoidable browser-side risk and show a baseline of care before launch.
Fix: Add only the missing protections among Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, frame protection, and Referrer-Policy. An existing CSP frame-ancestors directive already provides frame protection and must remain unchanged.
Agent Prompt
Sensitive file probes
0/16A small allowlist probe returned a public success response.
Failed: earned 0 of 16 points.
Priority: Priority 1: fix before sharing the page publicly.
Why it matters: Publicly exposed config or backup files can leak implementation details or secrets.
Fix: Remove the exposed file, block public access to that path, and rotate any secrets that may have been exposed.
Agent Prompt
Form labels
0/14Detected labels or accessible names for 14 of 18 form control(s).
Failed: earned 0 of 14 points.
Priority: Priority 7: fix during launch polish.
Why it matters: Unlabeled inputs make email capture, demo requests, and signups harder for assistive technology users.
Fix: Connect each input to a visible label or an accurate aria-label/aria-labelledby value.
Agent Prompt
Heading order
0/11Heading levels found: 2, 2, 1, 2, 2, 3, 3, 3, 3, 2, 3, 3, 3, 3, 2, 3, 3, 3, 3, 3, 4, 4, 4, 4, 3, 3, 3, 2, 4, 2, 2, 2, 2, 2, 2, 2.
Failed: earned 0 of 11 points.
Priority: Priority 13: fix during launch polish.
Why it matters: A clean heading outline helps visitors scan the page and helps assistive technology navigate it.
Fix: Use headings in order: one H1, then H2 for major sections, then H3 for subsections.
Agent Prompt
Basic contrast
0/84 of 100 rendered text color sample(s) missed WCAG contrast targets. Worst rendered ratio: 1.
Affected elements
II
III
IV
Skip to content
Failed: earned 0 of 8 points.
Priority: Priority 20: lower-risk cleanup after urgent launch blockers.
Why it matters: Low contrast makes a launch page feel less polished and can exclude users with low vision.
Fix: Review key text, buttons, and links against a 4.5:1 contrast target for normal text.
Agent Prompt
Rendered axe accessibility violations
0/18axe found 6 violation rule(s), including 2 serious or critical rule(s). Top rules: aria-required-children (1), list (1), landmark-main-is-top-level (1), landmark-no-duplicate-main (1), landmark-unique (1).
Affected elements
Certain ARIA roles must contain particular children
Fix any of the following: Element has children which are not allowed: button[aria-label]
<ul> and <ol> must only directly contain <li>, <script> or <template> elements
Fix all of the following: List element has direct children that are not allowed: [role=presentation]
Main landmark should not be contained in another landmark
Fix any of the following: The main landmark is contained in another landmark.
Document should not have more than one main landmark
Fix any of the following: Document has more than one main landmark
Failed: earned 0 of 18 points.
Priority: Priority 5: fix before sharing the page publicly.
Why it matters: axe checks the actual browser-rendered page, so these issues can affect people using keyboards, screen readers, or other assistive technology.
Fix: Fix the top axe rule IDs first, especially critical and serious violations around names, roles, labels, headings, contrast, landmarks, and keyboard-accessible controls.
Agent Prompt
Rendered speed signals
0/10DOMContentLoaded: 3477ms. Load complete: 0ms. First contentful paint: 980ms. Resources: 154. Scripts: 75. Images: 35. Third-party origins: 6. Transfer: not available.
Failed: earned 0 of 10 points.
Priority: Priority 14: fix during launch polish.
Why it matters: Slow pages lose impatient visitors and make every SEO, social, and paid-traffic visit work harder.
Fix: Reduce render-blocking scripts/styles, compress and size images, defer non-critical JavaScript, reduce third-party tags, and keep above-the-fold content quick to paint.
Agent Prompt
Rendered layout ergonomics
0/9Horizontal overflow: 0px. Small tap targets: 26.
Affected elements
Read About Our Sourcing ✦
Browse the Tea Apothecary ✦
Review 1
Review 2
Failed: earned 0 of 9 points.
Priority: Priority 13: fix during launch polish.
Why it matters: Horizontal overflow and tiny tap targets make the page feel broken on real devices, especially for mobile visitors.
Fix: Remove elements wider than the viewport, add responsive constraints, and make important links, buttons, inputs, and controls at least 40px tall and wide where possible.
Agent Prompt
Page-level AEO readiness
Shared eligibility and content signals that affect every search and answer agent.
Index and citation eligibility
No general noindex directive was detected.
Snippet and answer controls
No general nosnippet or max-snippet:0 control was detected.
Canonical alignment
The canonical resolves to the scanned public URL.
Sitemap coverage and freshness
A sitemap index was found; this safe scan did not recursively fetch child sitemaps.
Structured data
Detected 1 JSON-LD block(s), 0 parse error(s), and types CafeOrCoffeeShop, City, FoodEstablishment, GeoCoordinates, LocalBusiness, LocationFeatureSpecification, OpeningHoursSpecification, PostalAddress.
Public or paywalled content
No isAccessibleForFree structured-data value was detected.
Entity clarity
Detected 3 of 3 core identity signals across the title, description, and H1.
Answer-ready visible text
Detected 1560 visible words and 19 audience, use-case, pricing, or integration signals.
Authorship and accountability
No author meta value or structured-data author was detected.
Published or updated date
No datePublished or dateModified value was detected in structured data.
Supporting-source links
Detected 9 external source or reference link(s); link quality still requires editorial review.
Rendered content availability
Rendered audit completed with 118 visible text element(s).
Synthetic search-agent reachability
8 of 8 search/discovery User-Agent probes returned reachable content.
Optional LLM-readable summary
https://www.witchesbrew.co/llms.txt returned HTTP 200; this is supplemental and does not determine AI-search eligibility.
OAI-SearchBotAI search
Robots: allowed by * allow: / · line 19
Probe: reachable · HTTP 200 · 100% parity
GPTBotModel training
Robots: allowed by * allow: / · line 19
Probe: not tested for this control
ChatGPT-UserUser-requested fetch
Robots: not applicable to user-requested fetches
Probe: not tested for this control
ClaudeBotModel training
Robots: allowed by * allow: / · line 19
Probe: not tested for this control
Claude-SearchBotAI search
Robots: allowed by * allow: / · line 19
Probe: reachable · HTTP 200 · 100% parity
Claude-UserUser-requested fetch
Robots: allowed by * allow: / · line 19
Probe: reachable · HTTP 200 · 100% parity
GooglebotSearch and discovery
Robots: allowed by * allow: / · line 19
Probe: reachable · HTTP 200 · 100% parity
Google-ExtendedData-use policy control
Robots: allowed by * allow: / · line 19
Probe: not tested for this control
BingbotSearch and discovery
Robots: allowed by * allow: / · line 19
Probe: reachable · HTTP 200 · 100% parity
PerplexityBotAI search
Robots: allowed by * allow: / · line 19
Probe: reachable · HTTP 200 · 100% parity
Perplexity-UserUser-requested fetch
Robots: not applicable to user-requested fetches
Probe: not tested for this control
ApplebotSearch and discovery
Robots: allowed by * allow: / · line 19
Probe: reachable · HTTP 200 · 100% parity
Applebot-ExtendedData-use policy control
Robots: allowed by * allow: / · line 19
Probe: not tested for this control
MistralAI-IndexAI search
Robots: allowed by * allow: / · line 19
Probe: reachable · HTTP 200 · 100% parity
MistralAI-UserUser-requested fetch
Robots: allowed by * allow: / · line 19
Probe: reachable · HTTP 200 · 100% parity
meta-externalagentModel training
Robots: allowed by * allow: / · line 19
Probe: not tested for this control
meta-externalfetcherUser-requested fetch
Robots: allowed by * allow: / · line 19
Probe: reachable · HTTP 200 · 100% parity
AmazonbotModel training
Robots: allowed by * allow: / · line 19
Probe: not tested for this control
Amzn-SearchBotAI search
Robots: allowed by * allow: / · line 19
Probe: reachable · HTTP 200 · 100% parity
Amzn-UserUser-requested fetch
Robots: allowed by * allow: / · line 19
Probe: reachable · HTTP 200 · 100% parity
CCBotModel training
Robots: allowed by * allow: / · line 19
Probe: not tested for this control
Ready combines robots policy, a bounded synthetic User-Agent fetch, indexability, and snippet eligibility. Synthetic probes do not prove vendor-origin traffic. Purple preference states are training or data-use choices and do not lower the AEO score.
Share preview
witchesbrew.co website audit report
Close to ready: 75/100 overall, with prioritized fixes for SEO, security, accessibility, and design.
Public reports expose the scanned public URL, safe scores, sanitized public evidence, and fix guidance. They do not include credentials, cookies, hidden form values, or sensitive response bodies.
