Glossary

Web audit glossary

Each entry gives the standard definition and then states exactly how — or whether — Audityxe measures it.

LCP (Largest Contentful Paint)
A Core Web Vital that measures how long the largest visible content element takes to render. Google's "good" threshold is 2.5 seconds or less.In Audityxe:Reported from the Lighthouse (PageSpeed Insights) pass, with good / needs-improvement / poor verdicts.
CLS (Cumulative Layout Shift)
A Core Web Vital that scores unexpected layout movement while a page loads. Google's "good" threshold is 0.1 or less.In Audityxe:Reported from the Lighthouse pass; the Performance module also flags layout-shift risk from embeds.
INP (Interaction to Next Paint)
A Core Web Vital measuring responsiveness to user interactions across a page visit; it replaced FID as a Core Web Vital in 2024.In Audityxe:Audityxe's Lighthouse module reports TBT as its lab proxy for responsiveness. Real-user metrics appear in the CrUX module when Google publishes data.
TTFB (Time to First Byte)
The time between requesting a page and receiving the first byte of the response.In Audityxe:Measured by the dedicated TTFB module, including redirect overhead.
CSP (Content Security Policy)
An HTTP response header that tells browsers which sources of scripts, styles, frames, and other resources are allowed, limiting the impact of injection attacks such as XSS.In Audityxe:Audityxe evaluates CSP directives (script-src, style-src, object-src, base-uri, frame-ancestors) and enforcement mode.
HSTS (HTTP Strict Transport Security)
A header instructing browsers to only connect to a site over HTTPS for a set period.In Audityxe:Checked for presence, max-age, includeSubDomains, and preload-list eligibility.
CORS (Cross-Origin Resource Sharing)
A browser mechanism, controlled by response headers, that lets a server permit specific other origins to read its responses.In Audityxe:The security-header module includes a CORS configuration check.
SPF / DKIM / DMARC
Email-authentication DNS standards that help receiving servers verify that mail from a domain is legitimate.In Audityxe:Checked with live DNS lookups in the Email Authentication module.
DNSSEC / CAA
DNSSEC cryptographically signs DNS records; CAA records restrict which certificate authorities may issue certificates for a domain.In Audityxe:Both are checked in the DNS Security module.
SAST (Static Application Security Testing)
Security analysis of source code without running it.In Audityxe:Not provided. Audityxe never reads source code. See the comparison pages.
DAST (Dynamic Application Security Testing)
Security testing of a running application by sending it requests, often including attack payloads.In Audityxe:Not provided. Audityxe's checks are passive and read-only.
SARIF
Static Analysis Results Interchange Format, a standard JSON format for static-analysis results.In Audityxe:Not supported. Use --json for structured output.
OWASP Top 10
A widely referenced list of the most critical web application security risks, maintained by the OWASP Foundation.In Audityxe:Audityxe does not implement an OWASP Top 10 rule set or test for those vulnerabilities.
GEO / AEO (Generative / Answer Engine Optimization)
Structuring content and crawl access so AI search and answer engines can find, understand, and cite a site.In Audityxe:Checked by the AI Search & Agent Optimization module (AI-crawler access, llms.txt, FAQ/HowTo schema, direct-answer structure).
llms.txt
A proposed plain-markdown file at a site's root that summarizes the site for large language models.In Audityxe:Its presence is checked by the AI Search & Agent Optimization module.
CrUX (Chrome UX Report)
Google's public dataset of real-user performance data collected from Chrome users.In Audityxe:Surfaced by the Real-User Experience module when data exists for the site.
Subresource Integrity (SRI)
An attribute that lets browsers verify that a fetched script or stylesheet has not been tampered with.In Audityxe:Checked for cross-origin scripts and stylesheets.

Last reviewed against the Audityxe source code. Product names mentioned are trademarks of their respective owners; Audityxe is not affiliated with them.