Website Audit + Custom Build
Drop your URL.
We optimize your website.
Live Demo
The exact audit you get, running live on droptimize.org right now. This is the standard every build is held to.
Free preliminary audit
How does your site score?
Portfolio, Verified Scores
Sites we've droptimized.
Click any row to expand scores and notes. A · marks a stage not yet logged, filled in as a project moves from audit to verified.
| 1. Audit | 2. Fixing | 3. Pre-Launch | 4. Verified | |
|---|---|---|---|---|
| SEO | 91% | 100% | 100% | 100% |
| Security headers | 5/6 | 6/6 | 6/6 | 6/6 |
| Performance | 77% | 100% | 100% | 100% |
| Accessibility | 93% | 100% | 100% | 100% |
| Best Practices | 96% | 100% | 100% | 100% |
Verified all green (2026-06-19): 100 across all four Lighthouse categories, with all six security headers in place. The audit traced the low Performance (77%) and Best Practices (81%) to one root cause: Cloudflare's JavaScript Detections feature was edge-injecting a bot-detection script that burned ~2.5s of main-thread time and called deprecated browser APIs. The same edge challenge stripped HSTS and 403'd the sitemap for datacenter IPs, which capped Security. Disabling JavaScript Detections plus Bot Fight Mode on the zone cleared all three: Performance 77 to 100, Best Practices 81 to 100, Security to 100 (6/6 headers, sitemap 200). SEO and Accessibility were already 100. The site's own code needed no changes.
| 1. Audit | 2. Fixing | 3. Pre-Launch | 4. Verified | |
|---|---|---|---|---|
| SEO | 100% | · | · | 100% |
| Security headers | 6/6 | · | · | 6/6 |
| Performance | 100% | · | · | 100% |
| Accessibility | 100% | · | · | 100% |
| Best Practices | 100% | · | · | 100% |
The social companion to the training app: public pet pages, the pack, and community, on its own host and its own Cloudflare zone. Built on the OYE standard and verified 100 across all four Lighthouse categories (best of 5 runs, 2026-06-19), with 6/6 security headers and sitemap and robots both returning 200. Unlike the app zone, JavaScript Detections was already off here, so it was never slowed by the bot-detection script, no fixes were needed.
| 1. Audit | 2. Fixing | 3. Pre-Launch | 4. Verified | |
|---|---|---|---|---|
| SEO | 100% | · | · | 100% |
| Security headers | 6/6 | · | · | 6/6 |
| Performance | 100% | · | · | 100% |
| Accessibility | 100% | · | · | 100% |
| Best Practices | 100% | · | · | 100% |
Partner brand: the fine-art photography and print site for Eric Schoep, built from scratch on the OYE standard. Verified 100 across all four Lighthouse categories (best of 5 runs, 2026-06-19), with 6/6 security headers and sitemap and robots both 200. The one audit fix was allowing Cloudflare's analytics beacon in the CSP, which had been blocked and capped Best Practices at 92. The full-bleed hero photo is the mobile LCP and was deliberately kept over shaving it to chase the score; it still verifies at 100 best-of-5.
| 1. Audit | 2. Fixed | 3. Pre-Launch | 4. Verified | |
|---|---|---|---|---|
| SEO | 91% | 100% | 100% | 100% |
| Security headers | 6/6 | 6/6 | 6/6 | 6/6 |
| Performance | 93% | 95% | 95% | 98% |
| Accessibility | 95% | 100% | 100% | 100% |
| Best Practices | 92% | 100% | 100% | 100% |
New OYE internal property built from scratch. Audit exposed: Accessibility 95% (contrast failures on city marquee text, #8C9EA6 on cream = 2.27:1, and 12 links with aria-labels that didn't contain their visible text, WCAG 2.5.3). Best Practices 92% (feed rendering script inline, blocked by CSP). SEO 91% (no robots.txt). Performance boosted to 98% by converting PNG logos to WebP (78KB+101KB down to 13KB+17KB) and disabling Cloudflare email obfuscation, which was injecting a render-blocking script. Final: 100/100/100/100 across SEO, Security, Accessibility, and Best Practices. Performance 98%.
| 1. Audit | 2. Transfer | 3. Pre-Launch | 4. Final | |
|---|---|---|---|---|
| SEO | 92% | 91% | 100% | 100% |
| Security headers | ~92% | 6/6 | 6/6 | 6/6 |
| Performance | 96% | 99% | 99% | 100% |
| Accessibility | 93% | 93% | 100% | 100% |
| Best Practices | 92% | 92% | 100% | 100% |
Migrated from oyecreations.com/scholar to standalone oyescholar.com. Pre-transfer audit: scholar landing and essay builder both in the 92-96% range across all categories. Performance was stuck at 76% due to Cloudflare's Bot Management JavaScript detections injecting a 2,374ms script on every page load, disabled via API. Best Practices hit 100% after the same fix removed deprecated API calls from that injected script. All five categories verified at 100%.
| 1. Audit | 2. Fixed | 3. Pre-Launch | 4. Verified | |
|---|---|---|---|---|
| SEO | ~75% | 92% | 92% | 100% |
| Security headers | ~67% | 6/6 | 6/6 | 6/6 |
| Accessibility | ~80% | 97% | 97% | 100% |
| Best Practices | ~75% | 92% | 92% | 100% |
| Performance | ~60% | 85% | 85% | 100% |
New OYE internal site audited at launch. Security headers gap: X-XSS-Protection legacy value, HSTS max-age 1yr vs 2yr, missing COOP/CORP headers. Inline scripts blocked a tight CSP, extracted to external files, removed unsafe-inline from script-src. Accessibility contrast failures on #888/#999 text on white, fixed to #767676 (passes 4.5:1). Scores verified live: SEO 92%, A11y 97%, Best Practices 92%, Performance 85% (Google Fonts CDN, font migration pending).
| 1. Audit | 2. Transfer | 3. Pre-Launch | 4. Verified | |
|---|---|---|---|---|
| SEO | ~75% | 92% | 100% | 100% |
| Security headers | ~58% | ~58% | ~92% | 6/6 |
| Performance | ~89% | ~89% | ~89% | 100% |
| Accessibility | ~82% | 94% | 100% | 100% |
| Best Practices | ~85% | 92% | 92% | 100% |
Subdomain migration to standalone domain. Cloudflare's default robots.txt caused 2,064 SEO errors; missing security headers left the site exposed at 58%. Performance reached 100% after migrating from Google Fonts CDN to self-hosted woff2 files, eliminating the external font request entirely. All five categories verified at 100%.
| 1. Audit | 2. Rebuilt | 3. Pre-Launch | 4. Verified | |
|---|---|---|---|---|
| SEO | ~84% | 100% | 100% | 100% |
| Security headers | ~38% | 6/6 | 6/6 | 6/6 |
| Accessibility | ~76% | 100% | ~86% | 100% |
| Best Practices | ~80% | 100% | 91% | 100% |
Worst security headers score in the portfolio at ~38%. The Next.js app had no CSP, no HSTS, and no CORP headers at all. Accessibility issues came from component library defaults that didn't meet WCAG AA contrast. Dynamic routes were missing canonical tags, holding SEO back. All rebuilt and verified at 100%.
| 1. Audit | 2. Rebuilt | 3. Pre-Launch | 4. Verified | |
|---|---|---|---|---|
| SEO | 100% | 100% | 100% | 100% |
| Security headers | 6/6 | 6/6 | 6/6 | 6/6 |
| Performance | 76% | 76% | 91% | 93% |
| Accessibility | ~79% | 100% | 88% | 100% |
| Best Practices | ~85% | 100% | 92% | 100% |
SEO started at 100%. Strong existing domain signals meant no indexing work needed. Accessibility gaps were unlabeled interactive elements on chord cards and contrast failures on secondary label text. Security was one header short at audit and pre-launch. Best Practices hit 100% after disabling Cloudflare Bot Management JS detections, which had been injecting deprecated-API code on every page load. Performance at 93%. LCP is 3.2s because the featured news rotator is JavaScript-rendered: the browser can't fetch cover images until JS executes and injects them into the DOM. All covers are now locally hosted as WebP (converted from Wikimedia JPEG). Remaining LCP improvement requires server-side rendering the first article inline in the HTML.
| 1. Audit | 2. Rebuilt | 3. Transfer | 4. Verified | |
|---|---|---|---|---|
| SEO | ~65% | 100% | ~40% | 100% |
| Security headers | 0/6 | 6/6 | ~20% | 6/6 |
| Performance | ~65% | 100% | ~65% | 100% |
| Accessibility | ~70% | 100% | ~30% | 100% |
| Best Practices | ~75% | 100% | ~25% | 100% |
First external client. Built clean to 100% on our end. Client-side DNS changes during handover tanked all scores: security headers dropped to ~20%, accessibility to ~30%, SEO to ~40%, best practices to ~25%. We stepped back in, identified what changed, and closed everything at 100%. Transferred fully to the client in May 2026. Audits after transfer reflect the client's own hosting and changes, not the site we delivered.
| 1. Audit | 2. Rebuilt | 3. Pre-Launch | 4. Verified | |
|---|---|---|---|---|
| SEO | 91% | 100% | 94% | 100% |
| Security headers | 4/6 | 6/6 | 5/6 | 6/6 |
| Accessibility | ~82% | 100% | 91% | 100% |
| Best Practices | ~76% | 100% | 84% | 100% |
Incomplete security headers at audit. HSTS and CORP were missing, holding security headers at 68%. A late pre-launch config push partially reverted those settings, dropping security back to 80% right before go-live. Rebuilt from scratch with the full OYE header stack. All five categories closed at 100%.
Website Rebuilds
Simple pricing. Built to give back.
Agencies charge $6,000 and up for a custom website rebuild like this: a brand-new site, hand-coded from scratch. Ours is a flat price, and you own every line of it.
- Full scored audit report
- Complete website build (HTML/CSS/JS), hand-coded from scratch
- Cloudflare Pages deployment
- Handover docs & DNS setup
- Turnaround 5 to 7 days
- Every category ends green, including all six security headers, or your money back
- You own everything, no lock-in
- Everything in Single Site
- Full custom website build, up to 2 sites and 10 pages total (HTML/CSS/JS)
- Cloudflare Pages deployment
- Admin panel for content edits
- Handover docs & DNS setup
- Turnaround 5 to 7 days
- 30-day post-launch support
- Every category ends green, including all six security headers, or your money back
- You own everything, no lock-in
- Everything in Standard
- Up to 4 sites and 20 pages total
- Contact form with KV storage
- Weekly automated audit reports (1 month included)
- GitHub Actions CI/CD setup
- Turnaround 5 to 7 days
- 60-day post-launch support
- Everything in Professional
- Sites and pages to scope, quoted per project
- E-commerce or booking integration
- Multi-language support
- API & Worker backend builds
- Ongoing maintenance available
Not sure which tier fits? Tell us about your firm and we will say what we would build. It takes a few minutes and costs nothing.
Audit Watch, Ongoing Monitoring
Keep the scores you paid for. Automatically.
A clean launch is step one. Audit Watch re-runs the full audit every week, four Lighthouse categories plus all six security headers, and tells you the moment something slips. It watches and names what changed. Fixes are a separate quote or roll into a build.
Every plan, the same watch
- Weekly audit, all four Lighthouse categories plus all six security headers
- Push alert the moment a Lighthouse score drops below your line
- If a security header disappears, we tell you which one
- If a sensitive file becomes public, we tell you which file
- 1 site, up to 5 pages watched
- Cancel anytime, no lock-in
Each page is watched separately: you give us the exact URLs, and we audit each one on your cadence. Monitoring only. Audit Watch flags what slipped, it does not fix it. Need the fix? We quote it or fold it into a build.
Switch to annual above and get 1 month free. Cancel anytime, no lock-in.
How we got here
The standard wasn't written. It was earned.
droptimize.org started by auditing every OYE Creations property: the podcast site, the resume service, the AI platform. Most had missing security headers, contrast failures, ARIA issues, and incomplete SEO. We fixed them all and wrote down every rule.
Those rules became the build standard. When OYE Scholar launched, built from scratch using that standard, it audited green across the board before a single fix was applied, 96 to 100 on every Lighthouse category with its security headers already set. That's the difference between patching a site and building from a process.
Read the full story →