Run 1 summary

LoginPage

Tested 2026-05-26 05:41:58 using Firefox 150.0.2 (script).(runtime settings)

Test as a logged in user

Login the user with an empty browser cache, then visit Obama and Facebook

SummaryWaterfall MetricsVideoFilmstrip CoachPageXrayCPU Screenshots

Summary

LCP2.305 s
Coach91
Loading & responsiveness
TTFB
1.704 s
First Paint
2.223 s
Fully Loaded
2.592 s
Page weight & requests
Total transfer size
415.2 KB
Requests
17
Visual progress
First Visual Change
2.233 s
Speed Index
2.484 s
Visual Complete 85%
2.233 s
Visual Complete 99%
7.400 s
Last Visual Change
10.900 s
Screenshot
Waterfall | Download HAR | 

Waterfall

First paintFCPLCPDOMContentLoadedDOM interactiveLoadRender-blockingRedirectError

Video

Run 1
Download video

Filmstrip

73 frames

Use --filmstrip.showAll to show all filmstrips.

0 s
2.3 sDOM Content Loaded Time 2.211 sFirst Contentful Paint 2.224 smwStartup 2.228 sFirst Visual Change 2.233 sVisual Complete 85% 2.233 sLargest Image 2.233 sHeading 2.233 s
2.4 sLCP <DIV> mw-createaccount-cta 2.305 s
2.5 s
2.6 sFully Loaded 2.592 s
2.7 sPage Load Time 2.650 sVisual Complete 95% 2.667 s
2.8 s
2.9 s
3 s
3.1 s
3.2 s
3.3 s
3.4 s
3.5 s
3.6 s
4.7 s
4.8 s
4.9 s
5 s
5.1 s
5.2 s
5.3 s
5.4 s
5.5 s
5.6 s
5.7 s
5.8 s
5.9 s
6 s
6.1 s
6.2 s
6.3 s
6.4 s
6.5 s
6.6 s
6.7 s
6.8 s
6.9 s
7.3 s
7.4 sVisual Complete 99% 7.400 s
7.5 s
7.6 s
7.7 s
7.8 s
7.9 s
8 s
8.1 s
8.2 s
8.3 s
8.4 s
8.5 s
8.6 s
8.7 s
8.8 s
8.9 s
9 s
9.1 s
9.2 s
9.3 s
9.4 s
9.7 s
9.8 s
9.9 s
10 s
10.1 s
10.2 s
10.3 s
10.4 s
10.5 s
10.6 s
10.7 s
10.8 s
10.9 sLast Visual Change 10.900 s
Performance advice | Best practice advice | Privacy advice | Page info | Technologies | 

Coach

The coach helps you find performance problems on your web page using web performance best practice rules. And gives you advice on privacy and best practices. Tested using Coach-core version 9.2.1.

Performance advice

91
2 errors6 warnings3 info
infoAdd decoding="async" to non-critical imagesdecodingAsync

The page has 5 images (out of 5) without a decoding hint. Add decoding="async" to non-critical images so the browser can decode them off the main thread.

Setting decoding="async" on an <img> tells the browser it can decode the image off the main thread, which keeps the page responsive to user interactions while images are being processed. The default ("auto") leaves the choice to the browser. https://developer.mozilla.org/en-US/docs/Web/HTML/Element/img#decoding

Offenders
warn(50)Don't scale images in the browseravoidScalingImages

The page has 5 images that are scaled more than 100 pixels. It would be better if those images are sent so the browser don't need to scale them.

It's easy to scale images in the browser and make sure they look good in different devices, however that is bad for performance! Scaling images in the browser takes extra CPU time and will hurt performance on mobile. And the user will download extra kilobytes (sometimes megabytes) of data that could be avoided. Don't do that, make sure you create multiple version of the same image server-side and serve the appropriate one.

Offenders
error(50)Have a fast first contentful paintfirstContentfulPaint

First contentful paint can be improved (2.224 s). It is in the Google Web Vitals needs improvement range, slower than 1.8 seconds.

The First Contentful Paint (FCP) metric measures the time from when the page starts loading to when any part of the page content is rendered on the screen. For this metric, "content" refers to text, images (including background images), <svg> elements, or non-white <canvas> elements.

warn(50)Total JavaScript size shouldn't be too bigjavascriptSize

The total JavaScript transfer size is 299.3 kB. This is quite large.

A lot of JavaScript often means you are downloading more than you need. How complex is the page and what can the user do on the page? Do you use multiple JavaScript frameworks?

Offenders
URLTransferContent
https://en.wikipedia.org/w/load.php...ia.org/w/load.php21.2 KB0 b
https://en.wikipedia.org/w/load.php...ia.org/w/load.php18.1 KB0 b
https://en.wikipedia.org/w/load.php...ia.org/w/load.php253.0 KB0 b
warn(70)Avoid extra requests by setting cache headerscacheHeaders

The page has 3 requests that are missing a cache time. Configure a cache time so the browser doesn't need to download them every time. It will save 17.8 kB the next access.

The easiest way to make your page fast is to avoid doing requests to the server. Setting a cache header on your server response will tell the browser that it doesn't need to download the asset again during the configured cache time! Always try to set a cache time if the content doesn't change for every request.

Offenders
warn(80)Avoid doing redirectsassetsRedirects

The page has 2 redirects. 1 of the redirects are from the base domain, please fix them! 1 request are from other domains, it could be 3rd-party assets doing unnecessary redirects. :(

A redirect is one extra step for the user to download the asset. Avoid that if you want to be fast. Redirects are even more of a showstopper on mobile.

Offenders
error(90)Avoid Frontend single point of failuresspof

The page has 1 request inside of the head that can cause a SPOF (single point of failure). Load them asynchronously or move them outside of the document head.

A page can be stopped from loading in the browser if a single JavaScript, CSS, and in some cases a font, couldn't be fetched or is loading really slowly (the white screen of death). That is a scenario you really want to avoid. Never load 3rd-party components synchronously inside of the head tag.

Offenders
infoMake each CSS response smalloptimalCssSize

https://en.wikipedia.org/w/load.php?lang=en&modules=ext.uls.interlanguage%7Cext.visualEditor.desktopArticleTarget.noscript%7Cmediawiki.codex.messagebox.styles%7Cmediawiki.htmlform.codex.styles%7Cmediawiki.htmlform.styles%7Cmediawiki.special.userlogin.common.styles%7Cmediawiki.special.userlogin.login.styles%7Cskins.vector.icons%2Cstyles%7Cskins.vector.search.codex.styles&only=styles&skin=vector-2022 size is 33.3 kB (33262) and that is bigger than the limit of 25 kB. Try to keep each CSS response under 25 kB.

Render-blocking CSS holds up the first paint until it has fully downloaded, parsed and applied, so smaller CSS files mean a faster start. Split your CSS into a small critical bundle inlined or eagerly loaded, with the rest lazy-loaded.

Offenders
URLTransferContent
https://en.wikipedia.org/w/load.php...ia.org/w/load.php32.5 KB0 b
warn(90)Don't use private headers on static contentprivateAssets

The page has 1 request with private headers. Make sure that the assets really should be private and only used by one user. Otherwise, make it cacheable for everyone.

If you set private headers on content, that means that the content are specific for that user. Static content should be able to be cached and used by everyone. Avoid setting the cache header to private.

Offenders
warn(95)Inline CSS for faster first renderinlineCss

The page has both inline CSS and CSS requests even though it uses a HTTP/2-ish connection. If you have many users on slow connections, it can be better to only inline the CSS. Run your own tests and check the waterfall graph to see what happens.

In the early days of the Internet, inlining CSS was one of the ugliest things you can do. That has changed if you want your page to start rendering fast for your user. Always inline the critical CSS when you use HTTP/1 and HTTP/2 (avoid doing CSS requests that block rendering) and lazy load and cache the rest of the CSS. It is a little more complicated when using HTTP/2. Does your server support HTTP push? Then maybe that can help. Do you have a lot of users on a slow connection and are serving large chunks of HTML? Then it could be better to use the inline technique, becasue some servers always prioritize HTML content over CSS so the user needs to download the HTML first, before the CSS is downloaded.

infoLong cache headers is goodcacheHeadersLong

The page has 5 requests that have a shorter cache time than one year (but still a cache time).

Setting a cache header is good. Setting a long cache header (a year) is even better because the asset will stay in the browser cache across visits. For content-hashed URLs (e.g. app.4af2.css) you can safely use Cache-Control: max-age=31536000, immutable. For unversioned URLs that may change, use a revalidating strategy instead.

Offenders

Best practice advice

65
1 error1 warning4 info
error(0)Cumulative Layout ShiftcumulativeLayoutShift

Layout Shift is not supported in this browser

Cumulative Layout Shift measures the sum total of all individual layout shift scores for unexpected layout shift that occur. The metric is measuring visual stability by quantify how often users experience unexpected layout shifts. It is one of Google Web Vitals.

infoMeta descriptionmetaDescription

The page is missing a meta description.

Use a page description to make the page more relevant to search engines.

infoHave a good URL formaturl

The page is using more than two request parameters. You should really rethink and try to minimize the number of parameters. The URL is 158 characters long. Try to make it less than 100 characters.

A clean URL is good for the user and for SEO. Make them human readable, avoid too long URLs, spaces in the URL, too many request parameters, and never ever have the session id in your URL.

warn(50)Set a sensible viewport meta tagviewport

The viewport meta tag does not contain width=device-width, the browser may use a desktop-width fallback.

The viewport meta tag tells the browser how to lay out the page on small screens. Without it (or without width=device-width) the page is rendered at a desktop fallback width and scaled down, which makes text unreadable on mobile. Disabling zoom (user-scalable=no, maximum-scale<=1) is also an accessibility regression. https://developer.mozilla.org/en-US/docs/Web/HTML/Viewport_meta_tag

infoAvoid unnecessary headersunnecessaryHeaders

There are 14 responses that sets both a max-age and expires header. There are 17 responses that sets a server header.

Do not send headers that you don't need. We look for p3p, cache-control and max-age, pragma, server and x-frame-options headers. Have a look at Andrew Betts - Headers for Hackers talk as a guide https://www.youtube.com/watch?v=k92ZbrY815c or read https://www.fastly.com/blog/headers-we-dont-want.

Offenders
infoDo not send too long headerslongHeaders

https://en.wikipedia...a.org/w/index.php has a header set-cookie that is 616 characters long. https://auth.wikimed...Special:UserLogin has a header content-security-policy that is 4600 characters long. https://en.wikipedia...ia.org/w/load.php has a header sourcemap that is 1099 characters long.

Do not send response headers that are too long.

Offenders

Privacy advice

79
4 warnings2 info
warn(0)Use a strict Content-Security-Policy header to mitigate cross-site scripting (XSS) attacks.contentSecurityPolicyHeader

Set a Content-Security-Policy header to mitigate cross-site scripting attacks. You can start with a Content-Security-Policy-Report-Only header, which only reports violations rather than blocking them.

A Content-Security-Policy response header tells the browser which sources of script, style, and other content are allowed. The most effective form is a strict CSP using nonces or hashes together with strict-dynamic; the worst is a missing header, with unsafe-inline and unsafe-eval close behind. https://web.dev/articles/strict-csp

Offenders
infoSet a Cross-Origin-Embedder-Policy header so cross-origin subresources opt in to being embedded.crossOriginEmbedderPolicyHeader

Set a Cross-Origin-Embedder-Policy header (typically require-corp or credentialless) on the document response to control cross-origin embedding.

Cross-Origin-Embedder-Policy (COEP) makes the page refuse to load cross-origin subresources unless they explicitly opt in via CORP or CORS. Together with Cross-Origin-Opener-Policy it puts the page in a cross-origin isolated context, which mitigates cross-window side-channel attacks (Spectre) and unlocks high-resolution timers and SharedArrayBuffer. https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cross-Origin-Embedder-Policy

Offenders
warn(0)Set a Cross-Origin-Opener-Policy header to isolate the page from cross-origin windows.crossOriginOpenerPolicyHeader

Set a Cross-Origin-Opener-Policy header (typically same-origin) on the document response to isolate the page from cross-origin windows.

Cross-Origin-Opener-Policy (COOP) lets a page sever its window-group ties to cross-origin documents that opened it or that it opens. Together with Cross-Origin-Embedder-Policy it puts the page in a cross-origin isolated context, which mitigates cross-window side-channel attacks (Spectre) and unlocks high-resolution timers and SharedArrayBuffer. https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cross-Origin-Opener-Policy

Offenders
infoSet a Cross-Origin-Resource-Policy header to limit who may embed the page.crossOriginResourcePolicyHeader

Set a Cross-Origin-Resource-Policy header (same-origin, same-site or cross-origin) on the document response to limit who may embed it.

Cross-Origin-Resource-Policy (CORP) is a per-response opt-in that tells the browser which origins are allowed to embed the resource. It blocks cross-origin or cross-site no-cors embedding (img, script, iframe, etc.) and is one of the building blocks of cross-origin isolation. https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cross-Origin-Resource-Policy

Offenders
warn(0)Set a Permissions-Policy header to control which browser features the page can use.permissionsPolicyHeader

Set a Permissions-Policy header to control which browser features the page can use.

The Permissions-Policy response header (the successor to Feature-Policy) lets a site explicitly opt in or out of powerful browser features such as camera, microphone, geolocation, payment and clipboard. Setting a strict policy reduces the attack surface and limits what embedded third parties can do. https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Permissions-Policy

Offenders
warn(0)Set a referrer-policy header to make sure you do not leak user information.referrerPolicyHeader

Set a referrer-policy header to make sure you do not leak user information.

Referrer Policy is a new header that allows a site to control how much information the browser includes with navigations away from a document and should be set by all sites. https://scotthelme.co.uk/a-new-security-header-referrer-policy/.

Offenders

Page info

Page info

TitleLog in - Wikipedia
GeneratorMediaWiki 1.47.0-wmf.3
Width1920
Height995
DOM elements449
Avg DOM depth11
Max DOM depth20
Iframes0
Script tags4
Local storage65 B
Session storage0 b
Network Information APIunknown

Technologies used to build the page

Data collected using Coach-core version 9.2.1. With updated code from Webappanalyzer 2026-05-04. Use --browsertime.firefox.includeResponseBodies html or --browsertime.chrome.includeResponseBodies html to help Wappalyzer find more information about technologies used.

Detected technologies

5 technologies
Visual Metrics | Google Web Vitals | Largest Contentful Paint | Browser metrics | Visual Elements | Metrics from CDP | Server timings | 

Visual Metrics

Visual milestones
Visual progress
Visual progress at 0 s0.0s
Visual progress at 3.2 s3.2s
Visual progress at 5.3 s5.3s
Visual progress at 6.3 s6.3s
Visual progress at 7.6 s7.6s
Visual progress at 8.6 s8.6s
Visual progress at 9.9 s9.9s
Visual progress at 10.9 s10.9s
FCP2.22s
LCP2.31s
VC852.23s
0.0s2.2s4.4s6.5s8.7s10.9s

Google Web Vitals

1.704 sTTFB
Needs improvement
2.224 sFCP
Needs improvement

Largest Contentful Paint

When the page main content is rendered, collected via the Largest Contentful Paint API. Read more about Largest Contentful Paint.

2.305 sLCP render time

Phase breakdown

  • TTFB1.704 s
  • Resource load delay0 ms
  • Resource load duration0 ms
  • Element render delay600 ms

Element

Element type
<div>
Element id
mw-createaccount-cta
Size (w × h)
20114
URL
https://en.wikipedia...-people-large.png
Load time
2.296 s

DOM path

body > div:eq(2) > div > div:eq(2) > main#content > div#bodyContent > div#mw-content-text > div:eq(1) > div#userloginForm > form > div:eq(7) > div > div#mw-createaccount-cta
LCP

The LCP element is highlighted in the screenshot. If nothing is highlighted the element was removed before the screenshot or the LCP API couldn't find it.

The Largest Contentful Paint API matched this image:

LCP element

Browser Metrics

Navigation Timing
Extra timings
User Timing marks
mwStartup2.228 s

Server timings

2 entries
NameDurationDescription
cache0 mspass
host0 mscp3070

Custom metrics collected through JavaScript

There are no custom configured scripts.

Extra metrics collected using scripting

There are no custom extra metrics from scripting.

Visual Elements3
LargestImagewikipedia-wordmark-en-25.svg
Display time2.233 s
Position (x, y)314, 14
Size (w × h)140 × 22
HTML snippet
<img class="mw-logo-wordmark" alt="Wikipedia" src="/static/images/mobile/copyright/wikipedia-wordmark-en-25.svg" style="width: 8.75em; height: 1.375em;">
Heading
Display time2.233 s
Position (x, y)350, 66
Size (w × h)948 × 40
HTML snippet
<h1 id="firstHeading" class="firstHeading mw-first-heading"></h1>
LargestContentfulPaint
Display time2.233 s
Position (x, y)434, 459
Size (w × h)280 × 163
HTML snippet
<div id="mw-createaccount-cta"></div>
Summary | Largest responses | Per content type | Per domain | Expires & last-modified | 

PageXray

How the page is built.

HTTP versionHTTP/2.0
Total requests17
Total domains2
Transfer size415.2 KB
Content size0 b
Missing compression0
Cookies100 third-party

Response codes

200
1482.4%
302
317.6%

Requests and sizes per content type

6 types
ContentHeader SizeTransfer SizeContent SizeRequests
html6.1 KB14.3 KB0 b1
css1.5 KB32.5 KB0 b1
javascript5.4 KB292.3 KB0 b3
image2.1 KB5.0 KB0 b2
favicon1008 B2.0 KB0 b1
svg6.5 KB64.2 KB0 b6
Total22.6 KB410.2 KB0 b14

Data per domain

2 domains
DomainTotal download timeTransfer SizeContent SizeRequests
en.wikipedia.org2.328 s332.8 KB0 b8
auth.wikimedia.org2.153 s82.4 KB0 b9

Expires & last-modified statistics

typeminmedianmax
Expires0 seconds4 weeks1 year
Last modified10 hours9 weeks9 weeks

CPU

afterPageCompleteCheck.jpg | largestContentfulPaint.jpg | 

Screenshots