Public-site preflight report
This is a real audit of the Website Repair Sprint site, presented in the same evidence-first format used for customer reports.
Prioritized findings
Each finding states what was observed, why it matters, and the smallest practical next action.
Priority: Medium · Open
Prospects without GitHub cannot request the service
- Evidence
- Every paid request action opens a GitHub issue form. An unauthenticated visit redirects to GitHub sign-in.
- Impact
- A legitimate buyer who does not use GitHub—or cannot describe the problem publicly—has no intake path.
- Next action
- Add one project-controlled private contact route while retaining the issue form for public technical intake.
Priority: Low · Open
Several defense-in-depth response headers are absent
- Evidence
- HSTS is present. The response did not include CSP, X-Content-Type-Options, frame protection, Referrer-Policy, or Permissions-Policy headers. The HTML does include a restrictive CSP meta policy and a no-referrer directive.
- Impact
- The document has useful browser restrictions, but header-only protections and broader resource coverage are unavailable on the current static host.
- Next action
- Keep the current document policy. Move to a host with configurable response headers only if the threat model justifies the migration cost.
Priority: Low · Resolved
Search metadata omitted the lower-cost entry offer
- Evidence
- The original title and description described only the 48-hour repair sprint, even though the homepage now leads with the $49 preflight.
- Impact
- Search and link previews could hide the clearest, lowest-commitment way to buy.
- Resolution
- The default and social metadata now name the public-site preflight and the repair sprint.
Passed checks
Passing evidence is included so the report distinguishes verified behavior from assumptions.
- All three pages returned HTTPS 200 responses with no redirect chain.
- The homepage returned its first byte in 165 ms and completed in 215 ms during the bounded request.
- Every page had a unique title, description, canonical URL, language, viewport, and one primary heading.
- Layouts had no horizontal overflow at 320, 360, 768, or 1280 CSS pixels.
- Primary actions stayed visible and keyboard focus remained clearly indicated.
- The invoice builder kept draft data in the browser, created no cookies or persistent storage, and made no third-party requests.
- The generated Bitcoin URI, clickable payment link, visible text, and independently decoded QR payload matched exactly.
Get this report for your public site.
The $49 BTC preflight covers the homepage and up to two additional agreed public pages, delivered within one working day.