Glossary
Web audit glossary
Each entry gives the standard definition and then states exactly how — or whether — Audityxe measures it.
- LCP (Largest Contentful Paint)
- A Core Web Vital that measures how long the largest visible content element takes to render. Google's "good" threshold is 2.5 seconds or less.In Audityxe:Reported from the Lighthouse (PageSpeed Insights) pass, with good / needs-improvement / poor verdicts.
- CLS (Cumulative Layout Shift)
- A Core Web Vital that scores unexpected layout movement while a page loads. Google's "good" threshold is 0.1 or less.In Audityxe:Reported from the Lighthouse pass; the Performance module also flags layout-shift risk from embeds.
- INP (Interaction to Next Paint)
- A Core Web Vital measuring responsiveness to user interactions across a page visit; it replaced FID as a Core Web Vital in 2024.In Audityxe:Audityxe's Lighthouse module reports TBT as its lab proxy for responsiveness. Real-user metrics appear in the CrUX module when Google publishes data.
- TTFB (Time to First Byte)
- The time between requesting a page and receiving the first byte of the response.In Audityxe:Measured by the dedicated TTFB module, including redirect overhead.
- CSP (Content Security Policy)
- An HTTP response header that tells browsers which sources of scripts, styles, frames, and other resources are allowed, limiting the impact of injection attacks such as XSS.In Audityxe:Audityxe evaluates CSP directives (script-src, style-src, object-src, base-uri, frame-ancestors) and enforcement mode.
- HSTS (HTTP Strict Transport Security)
- A header instructing browsers to only connect to a site over HTTPS for a set period.In Audityxe:Checked for presence, max-age, includeSubDomains, and preload-list eligibility.
- CORS (Cross-Origin Resource Sharing)
- A browser mechanism, controlled by response headers, that lets a server permit specific other origins to read its responses.In Audityxe:The security-header module includes a CORS configuration check.
- SPF / DKIM / DMARC
- Email-authentication DNS standards that help receiving servers verify that mail from a domain is legitimate.In Audityxe:Checked with live DNS lookups in the Email Authentication module.
- DNSSEC / CAA
- DNSSEC cryptographically signs DNS records; CAA records restrict which certificate authorities may issue certificates for a domain.In Audityxe:Both are checked in the DNS Security module.
- SAST (Static Application Security Testing)
- Security analysis of source code without running it.In Audityxe:Not provided. Audityxe never reads source code. See the comparison pages.
- DAST (Dynamic Application Security Testing)
- Security testing of a running application by sending it requests, often including attack payloads.In Audityxe:Not provided. Audityxe's checks are passive and read-only.
- SARIF
- Static Analysis Results Interchange Format, a standard JSON format for static-analysis results.In Audityxe:Not supported. Use --json for structured output.
- OWASP Top 10
- A widely referenced list of the most critical web application security risks, maintained by the OWASP Foundation.In Audityxe:Audityxe does not implement an OWASP Top 10 rule set or test for those vulnerabilities.
- GEO / AEO (Generative / Answer Engine Optimization)
- Structuring content and crawl access so AI search and answer engines can find, understand, and cite a site.In Audityxe:Checked by the AI Search & Agent Optimization module (AI-crawler access, llms.txt, FAQ/HowTo schema, direct-answer structure).
- llms.txt
- A proposed plain-markdown file at a site's root that summarizes the site for large language models.In Audityxe:Its presence is checked by the AI Search & Agent Optimization module.
- CrUX (Chrome UX Report)
- Google's public dataset of real-user performance data collected from Chrome users.In Audityxe:Surfaced by the Real-User Experience module when data exists for the site.
- Subresource Integrity (SRI)
- An attribute that lets browsers verify that a fetched script or stylesheet has not been tampered with.In Audityxe:Checked for cross-origin scripts and stylesheets.
Last reviewed against the Audityxe source code. Product names mentioned are trademarks of their respective owners; Audityxe is not affiliated with them.