domeinflits.nl
Better than 68% (national)
Better than 55% (national)
Better than 18% (national)
Better than 59% (national)
Machine-readable verification: /api/verify/domeinflits.nl
Certified on 8 August 2026 · 17 pages checked · 7 improvements found
Score over time
Every audit and re-audit counts: this is the average score per scan day.
Scan timeline
Pillar scores across recent scans. Methodology changes (different engine version) are noted on the point.
8 August 2026 · Full audit
Engine unknown
83Speed 98Security 76Mobile 100Accessibility 598 July 2026 · Full audit
90Speed 98Security 63Mobile 100Accessibility 97
Full certification report
Part of the WebYes certification: beyond the four pillars we also audit SEO, structured data, content, links, privacy and AI findability. These extra categories do not count towards the certification score.
Pages examined
Sample of 15 pages (not every URL on the site).
- https://domeinflits.nl/
- https://domeinflits.nl/contact
- https://domeinflits.nl/tools
- https://domeinflits.nl/prijzen
- https://domeinflits.nl/kennisbank
- https://domeinflits.nl/account
- https://domeinflits.nl/vandaag-vrij
- https://domeinflits.nl/binnenkort-vrij
- https://domeinflits.nl/hoogste-dr
- https://domeinflits.nl/categorie
- https://domeinflits.nl/beste-drops
- https://domeinflits.nl/tools/dr-checker
- https://domeinflits.nl/tools/domein-geschiedenis
- https://domeinflits.nl/tools/wayback-preview
- https://domeinflits.nl/api-docs
Diff vs previous audit
8 July 2026 → 8 August 2026
Resolved (2)
- Cookie `Next-Locale` is set on an HTTPS page without the Secure flag.https://domeinflits.nl/
- Likely LCP image is missing `fetchpriority="high"`.https://domeinflits.nl/kennisbank
New (2)
- 1 focusable element(s) have aria-hidden="true", making them invisible to screen readers but still reachable via keyboard.https://domeinflits.nl/
- robots.txt Disallow lines reveal sensitive paths: /admin/.https://domeinflits.nl/robots.txt
Findings
- ErrorAccessibilityAutomatically checked
1 <input> element(s) have no associated label, aria-label, or aria-labelledby.
Associate a <label for="inputId"> or add aria-label="..." to every visible form input.
How to fix it
Link every form field to a label via for/id, or use aria-label. A placeholder alone is not enough: it disappears as soon as someone types.
- ErrorAccessibilityAutomatically checked
1 focusable element(s) have aria-hidden="true", making them invisible to screen readers but still reachable via keyboard.
Remove aria-hidden from focusable elements, or add tabindex="-1" to also remove them from the tab order.
How to fix it
Elements with aria-hidden="true" are still keyboard-focusable. Remove them from the tab order too (tabindex="-1") or hide them properly.
- WarningSpeed
HTML document is 797 KB (budget: 488.28125 KB).
Large HTML payloads delay First Contentful Paint on slow connections. Server-render only above-the-fold content and lazy-load the rest, or paginate long listing pages. In Next.js, use streaming with `loading.tsx` to flush the shell early.
How to fix it
Your HTML document is considerably larger than needed. The usual culprits are inline CSS or JSON data in the page; move those to separate files or load them only when needed.
- WarningSecurity
No Content-Security-Policy header — XSS / clickjacking surface is wide open.
Start with a strict-dynamic CSP using nonces: `Content-Security-Policy: script-src 'nonce-<...>' 'strict-dynamic'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'`. Roll out in `Content-Security-Policy-Report-Only` first to catch violations.
How to fix it
Add a Content-Security-Policy header that defines which sources may load scripts and styles. Start with a report-only policy if needed and tighten it from there.
- WarningSpam signals
Term "inzetten" appears unusually often (21×, 8% of words).
Rewrite for natural language — repeated exact-match phrases can trigger spam classifiers.
- InfoSecurity
No `/.well-known/security.txt` published.
Publish a `security.txt` (RFC 9116) at `/.well-known/security.txt`. Even a one-line `Contact: mailto:[email protected]` plus an `Expires:` date is enough; it gives white-hat researchers somewhere to send reports instead of giving up.
How to fix it
Publish a security.txt at /.well-known/security.txt with a contact address for security reports. Researchers then know where to report a vulnerability.
- InfoSecurity
Missing `Cross-Origin-Embedder-Policy`. Cross-origin isolation lets you use SharedArrayBuffer and high-resolution timers safely.
Send `Cross-Origin-Opener-Policy: same-origin` and `Cross-Origin-Embedder-Policy: require-corp`. Note this requires every embedded resource to send `Cross-Origin-Resource-Policy`.
How to fix it
Add Cross-Origin-Opener-Policy: same-origin (and where possible Cross-Origin-Embedder-Policy). This isolates your site from windows opened by other origins.
- InfoSecurity
robots.txt Disallow lines reveal sensitive paths: /admin/.
Listing a path under `Disallow:` doesn't hide it — it advertises it. Either move the resource behind auth and remove the Disallow line, or stop linking the path entirely so it never gets indexed.
- InfoOn-page SEO
Meta description is slightly over the recommended length (165 chars, max 160).
- InfoOn-page SEO
Page declares noindex; it will not be indexed.
Remove noindex if this page should appear in search results.
- InfoStructured data
Page has no JSON-LD structured data in the initial HTML.
Server-render JSON-LD in the HTML response. If this is currently injected after hydration (for example with next/script afterInteractive), static crawlers and AI bots may not see it.
- InfoContent
Text-to-HTML ratio is 1.6% (target ≥ 2%).
Very low ratios usually mean the hydration payload, inline RSC blob or a vendor script is bigger than the rendered prose. Inspect the largest scripts and externalise or split them.
- InfoTechnical
Crawl stopped at the max-pages limit (15); 289 sitemap URLs were not visited but might still be reachable.
Re-run with `--max-pages 2000` (or higher) before trusting orphan-from-sitemap counts.
- InfoQuality impression
Homepage has no `<link rel="icon">` — browsers will request /favicon.ico which may 404.
Add a custom favicon that reflects your brand. A missing favicon causes extra 404 log noise and looks unprofessional in browser tabs and bookmarks.
- InfoPrivacy
1 phone-shaped string(s) appear in main content. Examples: 866341225.
If the phone numbers are intentional public contact info, ignore this finding. If they're personal numbers (employees, customer testimonials), redact or replace with a routing alias.
More from the register
Other websites holding an active WebYes certification. Every report is public and audited on the same four pillars.