wikipedia.org
Strong, with a few clear wins still on the table.
- 01Performance & Core Web Vitals
Total Blocking Time: 857ms (poor)
Heavy JavaScript blocks the main thread, so taps and scrolls feel laggy right when the page appears.
- 02Accessibility
Form elements must have labels (1 element)
Ensure every form element has a label
- 03Security & Trust
HTTP security-header grade: E (1/6 core headers)
Graded on the six response headers securityheaders.com checks: HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.
- 04Performance & Core Web Vitals
Properly size images — save ~0.1s
Est savings of 34 KiB
- 05Performance & Core Web Vitals
Serve images in next-gen formats — save ~20KB
Est savings of 20 KiB
Total Blocking Time: 857ms (poor)
Heavy JavaScript blocks the main thread, so taps and scrolls feel laggy right when the page appears.
Properly size images — save ~0.1s
Est savings of 34 KiB
Serve images in next-gen formats — save ~20KB
Est savings of 20 KiB
Avoid an excessive DOM size
1,094 elements
Minimize main-thread work
2.5 s
Title is short (9 chars)
Aim for ~50–60 characters with your primary keyword and location.
Only ~82 words of extractable content
After stripping navigation and boilerplate, there's very little substance for an AI to summarize or cite. Add real, informative copy.
No structured data (JSON-LD)
Schema.org markup tells AI engines exactly what your business is, what you offer, and how to reach you — the clearest way to be identified and cited.
Form elements must have labels (1 element)
Ensure every form element has a label
HTTP security-header grade: E (1/6 core headers)
Graded on the six response headers securityheaders.com checks: HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.
No Content-Security-Policy
A CSP is the strongest defense against cross-site scripting and content injection.
No clickjacking protection
Set X-Frame-Options: DENY or a CSP frame-ancestors directive so your site can't be embedded in a malicious frame.
Server header leaks software version: "ATS/9.2.13"
Exposing exact server/version tells attackers which known exploits to try. Strip the version from the Server header.
4 cookie(s) missing Secure/HttpOnly/SameSite
Cookies without these flags can be stolen over HTTP or via scripts, or sent in cross-site requests (CSRF).
- No issues in this category. Nicely done.
“We owe you an explanation. You deserve an explanation, so please don't skip this 1-minute read. Our fundraiser won't last long, and we need some help to reach our goal. Less than 2% of our readers donate, but if everyone who saw this message gave $2.75, we'd hit our goal in a few hours. The rare few who donate do so because Wikipedia provides them with useful knowledge. If that sounds like you, please donate $2.75. Any contribution you make today helps.”
This is the text an AI answer engine actually pulls from your page. If your offer or location isn't in here, ChatGPT and Perplexity can't say it.
No sitewide issues across the pages we crawled. Clean.
Proud of your score? Add this badge to your site. It links to this live report and always reflects your current grade.
<a href="https://luxeplatforms.com/website-grader/r/aa95f6c6f6d8" target="_blank" rel="noopener"> <img src="https://luxeplatforms.com/website-grader/r/aa95f6c6f6d8/badge" alt="Website & AI grade: B" width="264" height="66"> </a>
Audited in 29s with a hand-built engine: real Lighthouse, axe-core, and field data. Weights shown per category. No fabricated numbers.