Public-site preflight report

This is a real audit of the Website Repair Sprint site, presented in the same evidence-first format used for customer reports.

Captured
29 July 2026, 19:51 UTC
Pages reviewed
Homepage, invoice builder, project payment page
Boundaries
Public pages only; no login, submission, or probing
Outcome
2 open findings, 1 resolved finding, 7 passed checks

Prioritized findings

Each finding states what was observed, why it matters, and the smallest practical next action.

  1. Priority: Medium · Open

    Prospects without GitHub cannot request the service

    Evidence
    Every paid request action opens a GitHub issue form. An unauthenticated visit redirects to GitHub sign-in.
    Impact
    A legitimate buyer who does not use GitHub—or cannot describe the problem publicly—has no intake path.
    Next action
    Add one project-controlled private contact route while retaining the issue form for public technical intake.
  2. Priority: Low · Open

    Several defense-in-depth response headers are absent

    Evidence
    HSTS is present. The response did not include CSP, X-Content-Type-Options, frame protection, Referrer-Policy, or Permissions-Policy headers. The HTML does include a restrictive CSP meta policy and a no-referrer directive.
    Impact
    The document has useful browser restrictions, but header-only protections and broader resource coverage are unavailable on the current static host.
    Next action
    Keep the current document policy. Move to a host with configurable response headers only if the threat model justifies the migration cost.
  3. Priority: Low · Resolved

    Search metadata omitted the lower-cost entry offer

    Evidence
    The original title and description described only the 48-hour repair sprint, even though the homepage now leads with the $49 preflight.
    Impact
    Search and link previews could hide the clearest, lowest-commitment way to buy.
    Resolution
    The default and social metadata now name the public-site preflight and the repair sprint.

Passed checks

Passing evidence is included so the report distinguishes verified behavior from assumptions.

  • All three pages returned HTTPS 200 responses with no redirect chain.
  • The homepage returned its first byte in 165 ms and completed in 215 ms during the bounded request.
  • Every page had a unique title, description, canonical URL, language, viewport, and one primary heading.
  • Layouts had no horizontal overflow at 320, 360, 768, or 1280 CSS pixels.
  • Primary actions stayed visible and keyboard focus remained clearly indicated.
  • The invoice builder kept draft data in the browser, created no cookies or persistent storage, and made no third-party requests.
  • The generated Bitcoin URI, clickable payment link, visible text, and independently decoded QR payload matched exactly.

Get this report for your public site.

The $49 BTC preflight covers the homepage and up to two additional agreed public pages, delivered within one working day.

Request a $49 preflight