Example Website Audit Report
Loading a real PageLens AI growth report with priority fixes, screenshots, and fix prompts.
Loading a real PageLens AI growth report with priority fixes, screenshots, and fix prompts.
This is a genuine shared PageLens report. It shows the affected page, captured evidence and the exact repair instruction—without hiding the useful part behind a signup.
No signup for the free check · No subscription
Open the complete public example reportReal report snapshot
experi.co.uk
Website score
93
Excellent
Multi-page audit
Example finding
Weak Content-Security-Policy
https://experi.co.uk/
Genuine evidence · experi.co.uk
Captured 2026-06-06 from a completed report the owner made public.
Affected page: https://experi.co.uk/
Captured evidence
Content-Security-Policy: default-src 'self'; script-src 'self' 'nonce-s8XMgYvGPAU0kQFS9j85UA' 'strict-dynamic' 'unsafe-inline' https://js.stripe.com https://www.googletagmanager.com https://vercel.live https://challenges.cloudflare.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https: blob:; font-src 'self' data:; connect-src 'self' https://api.stripe.com https://api.resend.com https://www.google.com https://www.google.co.uk https://www.googleadservices.com https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://www.googletagmanager.com https://*.google-analytics.com https://www.google
Repair instruction
Use nonce-based or hash-based CSP for scripts. Remove 'unsafe-eval' if possible. Replace dangerous wildcard hosts with specific origins.
Finding: Weak Content-Security-Policy Severity: MEDIUM Category: HEADERS Affected URL: https://experi.co.uk/ Technical rule: CASA-003 Evidence: Content-Security-Policy: default-src 'self'; script-src 'self' 'nonce-s8XMgYvGPAU0kQFS9j85UA' 'strict-dynamic' 'unsafe-inline' https://js.stripe.com https://www.googletagmanager.com https://vercel.live https://challenges.cloudflare.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: https: blob:; font-src 'self' data:; connect-src 'self' https://api.stripe.com https://api.resend.com https://www.google.com https://www.google.co.uk https://www.googleadservices.com https://googleads.g.doubleclick.net https://stats.g.doubleclick.net https://www.googletagmanager.com https://*.google-analytics.com https://www.google Fix request: Use nonce-based or hash-based CSP for scripts. Remove 'unsafe-eval' if possible. Replace dangerous wildcard hosts with specific origins. Constraints: - Keep the change scoped to this finding. - Do not redesign unrelated UI or refactor unrelated modules. - Preserve existing analytics, auth, payment, and accessibility behaviour unless this finding requires changing it. Report back with files changed, why the change fixes the evidence, and how to verify it.
Verification is explicit
Deploy the fix, reload the affected page, then re-scan and confirm CASA-003 no longer appears. This sample does not claim the owner has completed that step.
From scan to shipped fix
See the evidence
Know the affected page and the exact signal PageLens observed.
Fix what matters first
Work through a short queue ordered by risk, not a wall of warnings.
Hand off the repair
Copy a scoped instruction into your AI builder or send it to a developer.
Prove it changed
Re-scan after publishing and keep the before-and-after evidence.
Public trust and browser-safety signal
Security Headers · Homepage-level signal
Page weight and loading-experience signal
Performance · Homepage-level signal
Search and preview-readiness signal
SEO · Homepage-level signal
Start with three issue summaries for free. Upgrade only when you want the complete evidence pack and repair plan.
No subscription · Billing and refund policy
PageLens AI is the independent release engineer for AI-built apps.
UKBased in London, United Kingdom