Report Summary

  • 38

    Performance

    Renders faster than
    57% of other websites

  • 69

    Accessibility

    Visual factors better than
    that of 34% of websites

  • 67

    Best Practices

    More advanced features
    available than in
    24% of websites

  • 79

    SEO

    Google-friendlier than
    40% of websites

xssed.net

XSSed | Cross Site Scripting (XSS) attacks information and archive

Page Load Speed

4.5 sec in total

First Response

200 ms

Resources Loaded

4.1 sec

Page Rendered

189 ms

About Website

Click here to check amazing XSSed content. Otherwise, check out these important facts you probably never knew about xssed.net

Providing the latest information on XSS (cross-site scripting) vulnerabilities. Advisories, news articles, tutorials and an archive of XSS vulnerable websites.

Visit xssed.net

Key Findings

We analyzed Xssed.net page load time and found that the first response time was 200 ms and then it took 4.3 sec to load all DOM resources and completely render a web page. This is a poor result, as 70% of websites can load faster.

Performance Metrics

xssed.net performance score

38

Measured Metrics

name

value

score

weighting

FCP (First Contentful Paint)

Value2.3 s

73/100

10%

LCP (Largest Contentful Paint)

Value2.7 s

85/100

25%

SI (Speed Index)

Value6.1 s

44/100

10%

TBT (Total Blocking Time)

Value2,000 ms

8/100

30%

CLS (Cumulative Layout Shift)

Value0.546

13/100

15%

TTI (Time to Interactive)

Value14.2 s

9/100

10%

Network Requests Diagram

xssed.net

200 ms

www.xssed.com

282 ms

style.css

1711 ms

jquery-1.7.2.min.js

1257 ms

show_ads.js

39 ms

Our browser made a total of 59 requests to load all elements on the main page. We found that 2% of them (1 request) were addressed to the original Xssed.net, 19% (11 requests) were made to Data.xssed.org and 19% (11 requests) were made to Platform.twitter.com. The less responsive or slowest element that took the longest time to load (1.7 sec) relates to the external source Data.xssed.org.

Page Optimization Overview & Recommendations

Page size can be reduced by 17.7 kB (9%)

Content Size

192.7 kB

After Optimization

175.1 kB

In fact, the total size of Xssed.net main page is 192.7 kB. This result falls beyond the top 1M of websites and identifies a large and not optimized web page that may take ages to load. 45% of websites need less resources to load. Javascripts take 157.1 kB which makes up the majority of the site volume.

HTML Optimization

-72%

Potential reduce by 16.9 kB

  • Original 23.3 kB
  • After minification 22.9 kB
  • After compression 6.4 kB

HTML content can be minified and compressed by a website’s server. The most efficient way is to compress content using GZIP which reduces data amount travelling through the network between server and browser. HTML code on this page is well minified. It is highly recommended that content of this web page should be compressed using GZIP, as it can save up to 16.9 kB or 72% of the original size.

Image Optimization

-0%

Potential reduce by 18 B

  • Original 11.0 kB
  • After minification 11.0 kB

Image size optimization can help to speed up a website loading time. The chart above shows the difference between the size before and after optimization. XSSed images are well optimized though.

JavaScript Optimization

-0%

Potential reduce by 520 B

  • Original 157.1 kB
  • After minification 157.1 kB
  • After compression 156.6 kB

It’s better to minify JavaScript in order to improve website performance. The diagram shows the current total size of all JavaScript files against the prospective JavaScript size after its minification and compression. This website has mostly compressed JavaScripts.

CSS Optimization

-20%

Potential reduce by 248 B

  • Original 1.3 kB
  • After minification 1.3 kB
  • After compression 1.0 kB

CSS files minification is very important to reduce a web page rendering time. The faster CSS files can load, the earlier a page can be rendered. Xssed.net needs all CSS files to be minified and compressed as it can save up to 248 B or 20% of the original size.

Requests Breakdown

Number of requests can be reduced by 36 (65%)

Requests Now

55

After Optimization

19

The browser has sent 55 CSS, Javascripts, AJAX and image requests in order to completely render the main page of XSSed. We recommend that multiple CSS and JavaScript files should be merged into one by each type, as it can help reduce assets requests from 26 to 1 for JavaScripts and as a result speed up the page load time.

Accessibility Review

xssed.net accessibility score

69

Accessibility Issues

ARIA

These are opportunities to improve the usage of ARIA in your application which may enhance the experience for users of assistive technology, like a screen reader.

Impact

Issue

High

[aria-*] attributes do not match their roles

Names and labels

These are opportunities to improve the semantics of the controls in your application. This may enhance the experience for users of assistive technology, like a screen reader.

Impact

Issue

High

<frame> or <iframe> elements do not have a title

High

Form elements do not have associated labels

High

Links do not have a discernible name

Internationalization and localization

These are opportunities to improve the interpretation of your content by users in different locales.

Impact

Issue

High

<html> element does not have a [lang] attribute

Best Practices

xssed.net best practices score

67

Areas of Improvement

Trust and Safety

Impact

Issue

High

Does not use HTTPS

High

Includes front-end JavaScript libraries with known security vulnerabilities

Low

Ensure CSP is effective against XSS attacks

User Experience

Impact

Issue

High

Serves images with low resolution

General

Impact

Issue

Low

Detected JavaScript libraries

High

Page has valid source maps

SEO Factors

xssed.net SEO score

79

Search Engine Optimization Advices

Language and Encoding

  • Language Detected

    EN

  • Language Claimed

    EN

  • Encoding

    ISO-8859-1

Language claimed in HTML meta tag should match the language actually used on the web page. Otherwise Xssed.net can be misinterpreted by Google and other search engines. Our service has detected that English is used on the page, and it matches the claimed language. Our system also found out that Xssed.net main page’s claimed encoding is iso-8859-1. Changing it to UTF-8 can be a good choice, as this format is commonly used for encoding all over the web and thus their visitors won’t have any troubles with symbol transcription or reading.

Social Sharing Optimization

Open Graph description is not detected on the main page of XSSed. Lack of Open Graph description can be counter-productive for their social media presence, as such a description allows converting a website homepage (or other pages) into good-looking, rich and well-structured posts, when it is being shared on Facebook and other social media. For example, adding the following code snippet into HTML <head> tag will help to represent this web page correctly in social networks: