Serious problems. Fix the critical items this week.
0 critical · 4 high · 3 medium · 3 low | 38 checks, 0 links tested
Server responded in 280 ms · 1 KB of HTML · Apache/2.4.58 (Ubuntu)
What is wrong, worst first
high No meta description
Google writes its own snippet for your search result, often badly.
Fix: Add <meta name="description" content="..."> with a 120-155 character sales sentence.
high No social preview tags (Open Graph)
When someone shares your link on LinkedIn, Slack, WhatsApp or Facebook it appears as a bare grey link with no image. This measurably reduces click-through.
Fix: Add og:title, og:description and og:image (1200x630 px) meta tags to <head>.
high No main heading (H1) on the page
Search engines use the H1 to understand what the page is about; you have none.
Fix: Add exactly one <h1> containing your main proposition.
high No visible way to contact you
The homepage has no email link, phone link or form. Interested visitors leave.
Fix: Put an email link or a short contact form above the fold.
medium No canonical URL
Duplicate versions of the page (with/without slash, tracking parameters) compete against each other in search.
Fix: Add <link rel="canonical" href="https://yourdomain.com/"> to <head>.
medium 4 security headers missing: HSTS, Content-Security-Policy, X-Content-Type-Options, Referrer-Policy
HSTS - Browsers can be tricked into loading your site over plain http. Content-Security-Policy - Any injected script can run freely on your pages. X-Content-Type-Options - Browsers may guess file types and execute an upload as script. Referrer-Policy - Full URLs of your pages leak to every third-party site you link to.
Fix: Send: Strict-Transport-Security: max-age=31536000; includeSubDomains Start with a report-only policy, then enforce it. Send: X-Content-Type-Options: nosniff Send: Referrer-Policy: strict-origin-when-cross-origin
medium 5 render-blocking scripts in the page
The browser stops drawing the page while it fetches these.
Fix: Add defer (or async) to script tags that are not needed immediately.
low Server software version is advertised (Apache/2.4.58 (Ubuntu))
Attackers scan for exact versions with known exploits.
Fix: Hide the banner: server_tokens off (nginx) or expose_php=Off / ServerTokens Prod.
low robots.txt does not reference a sitemap
Crawlers have to guess which pages exist.
Fix: Add a "Sitemap:" line to robots.txt.
low No structured data (schema.org)
You are not eligible for rich search results: star ratings, business hours, FAQ dropdowns.
Fix: Add a JSON-LD block describing your Organization, LocalBusiness or Product.
Already correct
- http traffic is redirected to https
- page title present and well-sized
- mobile viewport tag present
- compression enabled (gzip)
- fast server response (280 ms)
- sitemap.xml found
I will write the fixes for you — $29
This page found the problems. The Fix Pack hands you the solution: the exact meta tags for your pages, the redirect and security-header block written for your actual server (Apache/2.4.58 (Ubuntu)), alt text drafted for your images, the broken links mapped to their replacements, and a short ordered checklist of what to do first. One file, copy and paste, plain-English notes throughout. Back to you within 24 hours, or full refund.
Get the Fix Pack for tofuvegan.com/reservation/brighton
Permanent link to this reportShare it with whoever maintains the site — no login needed, and it re-checks nothing until you ask.
https://tinkeraudit.com/r/tofuvegan.com-95ee092
← Audit another site · Recent audits