Read 25 September 2026 Seven live sites Every figure can be re-run

Seven live sites.
Every figure read,
none of them claimed.

Every site Chan-Piu has built and deployed, tested on the same day with two free public instruments anyone can run: securityheaders.com, which grades the security instructions a site sends to your browser, and Google's PageSpeed Insights, which audits accessibility, best practices and search readiness. The readings are below, with a link beside each one so you can take it again yourself.

A+
Security headers — seven of seven
100
Accessibility — every site
100
Best practices — every site
100
SEO — every site
Mobile audits and header scans, 25 September 2026
01 / Readings

Site by site.

Scores in blue are what the instruments returned. The last column opens the same test against the live site, so the reading can be checked rather than trusted.

SiteHeadersAccess.Best prac.SEORun it yourself
SwiftMedia & TechThis siteA+100100100HeadersPageSpeed
Sports GurusAfrica's home of sportA+100100100HeadersPageSpeed
Serengeti StudiosNairobi · Africa, US, UKA+100100100HeadersPageSpeed
Abidha DinUganda's MDRT pioneerA+100100100HeadersPageSpeed
SolodifiedReal people raps onlyA+100100100HeadersPageSpeed
Coffee SafarisEvery bean has a storyA+100100100HeadersPageSpeed
Gaure MdeeJournalist & travellerA+100100100HeadersPageSpeed

Headers: securityheaders.com grade for the home page. Access., Best prac. and SEO: Google PageSpeed Insights, mobile. Performance is left out on purpose — see section 04.

02 / Before and after

Two days,
five sites moved.

The same two instruments were run on 23 September, before a round of work on the client sites, and again on 25 September, after it. Two sites were already at the top on both instruments. The other five each had something the tests could see.

Site23 September25 SeptemberWhat changed
SwiftMedia & TechA+ / 100 / 100 / 100A+ / 100 / 100 / 100Already at the top on both instruments. Its own inline code was removed, and its security policy tightened, on 16 September.
Sports GurusA+ / 100 / 100 / 100A+ / 100 / 100 / 100Already at the top on both instruments. Separately, its article pages moved from a D to an A+ header grade on 24 September.
Serengeti StudiosA / 100 / 100 / 100A+ / 100 / 100 / 100The policy still allowed inline code, which caps the grade at A. 95 inline styles and 21 inline scripts were moved into files; the icon and animation libraries are now served from the site itself instead of a third-party network; the studio's videos moved to its own domain.
Abidha DinA+ / 100 / 92 / 100A+ / 100 / 100 / 100The policy blocked an image the analytics service loads, and the audit logged the refusal as an error. The policy now names every host the analytics actually uses; the tracking snippets moved into a file; a page that answered every mistyped address with the home page now returns a real not-found.
SolodifiedA+ / 100 / 92 / 100A+ / 100 / 100 / 100Two analytics services were being refused by the policy, logging errors. Their hosts were added, and eight per-script exceptions were retired as those scripts moved into files.
Coffee SafarisA / 100 / 92 / 100A+ / 100 / 100 / 100279 inline styles and 20 inline scripts were moved into files so the policy could drop its exceptions. The host's script-rewriting feature, which the audit tripped over, was instructed to leave the site's scripts alone.
Gaure MdeeA+ / 96 / 96 / 100A+ / 100 / 100 / 100A footer link was distinguished by colour alone, which fails accessibility; it is now underlined. The film clips moved from a development address to the site's own domain, and the second clip now loads only when a visitor engages — see section 04.

Each cell reads headers grade / accessibility / best practices / SEO. Amber marks the figure that moved.

03 / Underneath

What every one of
the seven now ships.

CH 01

A security policy with no exceptions

Each site tells your browser exactly which sources it may load code, styles and media from, and nothing else. None of the seven carries the two exemptions scanners flag — permission to run code written into the page itself, or to evaluate code from text. To hold that line, every style and every script lives in its own file; no page carries inline script or inline style.

  • Content-Security-Policy
  • No unsafe-inline
  • No unsafe-eval
CH 02

One header taken away

The hosting platform adds a header to every response saying any other website may read it. On a public site that exposes nothing that is not already public — it was removed because a header that cannot be justified should not be sent. It is one line in each site's configuration.

  • Access-Control-Allow-Origin removed
  • HSTS
  • Frame and referrer policies
CH 03

An honest front door

A mistyped address returns a real “not found” rather than quietly showing the home page, which search engines read as duplicate content. Every site publishes a security.txt, so anyone who finds a problem knows where to report it. Video is served from each site's own domain, not from a development address the host warns against using in production.

  • Real 404
  • security.txt
  • Media on the client's domain
CH 04

Tested before it ships, read after it lands

Before a release leaves, every page is loaded in a browser under its final security policy and every interactive part is exercised; old and new versions are compared pixel by pixel, and the release is expected to show no difference except the one intended. After it is deployed, the files the live site serves are checked against the files that were shipped, one by one.

  • Zero policy violations
  • Pixel comparison
  • Live file check
04 / Limits

What these numbers
do not say.

Performance is not quoted. Google's performance score is a timing taken on a simulated slow phone, and it moves between runs of an unchanged page — in one test run for this practice, by 32 points between two runs seven minutes apart. A single performance figure says more about the moment of the test than about the site.

A reading is a date, not a promise. Gaure Mdee's site scored 100 for best practices on 24 September and 96 the next day, with nothing on the site changed. Google's test had begun downloading a 35 MB film clip meant for the page's second scene, and the download was cut off when the test ended — which the audit counts as an error. The clip now loads only once a visitor starts to scroll or tap, which also spares anyone on mobile data a film they may never reach. Re-read after the change: 100.

Some of what a site sends is added by its host. The hosting platform inserts a small bot-detection script into three of these sites as they are served. Their security policies refuse to run it, which leaves one line in the browser console. It does not affect the scores above and is disclosed here rather than hidden.

A header grade is not a security audit. The largest real risks to a website are rarely in its headers: a takeover of the hosting or domain account, email sent in the owner's name, a contact form flooded until real enquiries are buried. Those are covered in the security practice, and they are where an engagement starts.

Code is marked, not locked. Each site's scripts ship minified and obfuscated, as a mark of ownership and a deterrent to casual copying. Anything a browser runs can be read by the person running it; this is not protection, and it is not sold as protection.

05 / Contact

Have your own site
read the same way.

Send the address of a site you run or are about to commission. Chan-Piu will run the same instruments against it and tell you what they found and what fixing it involves, before either of you commits to anything.