Site teardown · Nowkickback
nowkickback.com
Site health · September 2, 2026
Prepared by Harvv

What your site is actually doing.

One page: what is working, what is costing you visitors, and what to fix next. A phone-and-desktop teardown of the live site: 4 phone loads + 2 desktop loads. No login, no insider access, no Harvv pixel needed. The full evidence is at the bottom.

September 2, 2026·External scan·4 mobile + 2 desktop loads · no pixel data·Download as PDF

Working

What's already working. These held up across every load.

0.3s

Speed is good.

1.3MB

The page is about 1.3 MB across 132 requests. That keeps it quick on mobile data and cheap to load repeatedly.

0

No JavaScript errors on load.

100/100

Lighthouse scores SEO 100/100. The fundamentals Google looks for are present.

Nothing spilled past the edge at either 390px (phone) or 1366px (desktop), so the structure is responsive.

Costing you

Ranked by what hurts conversion most. Full evidence below.

41%

Add quotations so AI engines cite this page

faint

Some text is low-contrast and hard to read

fix

No XML sitemap found

fix

Security headers are missing or weak

493

Unused JavaScript is being downloaded

40

Unused CSS is being downloaded

Fixing next
AI citability, contrast and missing sitemap.

3 small changes, on the pages people actually land on: Add quotations so AI engines cite this page; Some text is low-contrast and hard to read; No XML sitemap found. We re-measure the same samples after.

6
hours
AI search visibility
How visible is nowkickback.com to AI search?
ChatGPT, Perplexity, and Google AI Overviews are the new front page. The AI checks in this report are a preview. A free account turns them into a live 0 to 100 score, tracked daily and benchmarked against your competitors.
See the full AI report, free

01Findings, ranked by what hurts conversion most

SeverityFindingHow we know
LowUnused JavaScript is being downloadedBothPerformance
Code that never runs on this page still costs download and parse time on every visit. Splitting or removing it speeds up load. Lighthouse measured: Est savings of 493 KiB.
paste into Claude, Cursor, or ChatGPT
LowUnused CSS is being downloadedBothPerformance
Style rules that this page never uses still block rendering while they download. Trimming them frees the paint path. Lighthouse measured: Est savings of 40 KiB.
paste into Claude, Cursor, or ChatGPT
LowNo email capture or newsletter detectedBothConversion
No email input field was found in the page, and no email-marketing tag (Klaviyo, Mailchimp, Substack, ConvertKit, Beehiiv, MailerLite, ActiveCampaign, Omnisend, Brevo, Drip or Buttondown) was detected. A form that loads after JavaScript runs, or one behind a popup or a separate page, will not be visible to this check. If capturing visitors is relevant to this site, an email signup builds an owned audience you keep regardless of ad costs. Not every site needs one.
paste into Claude, Cursor, or ChatGPT
LowNo visible contact details (email or phone)BothConversion
This page exposes no email address, no phone link, no contact form and no link to a contact page. For higher-value or trust-sensitive purchases, a clear way to reach a human reduces hesitation. A contact route that only appears after JavaScript runs, or that lives on a page not checked here, will not be visible to this check. Add an email or phone link in the header or footer.
paste into Claude, Cursor, or ChatGPT
HighAdd quotations so AI engines cite this pageBothAI SearchSEO
Generative engines (ChatGPT, Perplexity, AI Overviews) lift sourced, attributed quotes almost verbatim, and quotations are the single strongest citation lever (studies measure roughly +41%). Add 1-2 attributed expert quotes or blockquotes to the pages below. (Found across a sample of 1 pages from your sitemap, a partial crawl rather than your full site.)
paste into Claude, Cursor, or ChatGPT
LowNo advertising pixel detectedBothTracking
Analytics is present but no Meta/Google/TikTok ad pixel was found. If you run paid ads, conversion tracking should be installed before the next campaign so the platforms can optimize toward buyers, not clicks.
paste into Claude, Cursor, or ChatGPT
MediumNo XML sitemap foundBoth
No sitemap.xml at the standard location and none listed in robots.txt. A sitemap tells search engines every page you want indexed; without it they rely on link discovery and may miss pages.
paste into Claude, Cursor, or ChatGPT
LowNo canonical tag, so duplicate URLs split the page's rankingBoth
When the same content is reachable at multiple URLs (think tracking parameters or session IDs), Google can split your ranking signal across them. A single canonical tag tells Google which version counts.
paste into Claude, Cursor, or ChatGPT
LowLinks to this page will look bare when sharedBoth
The page is missing its Open Graph image, so when someone shares it on Facebook, LinkedIn, iMessage, or Slack the preview has no image. A flat grey link gets far fewer clicks than one with an image and headline.
paste into Claude, Cursor, or ChatGPT
LowNo structured data for rich search resultsBoth
The page has no schema.org markup. Adding the right type (Product, Article, Organization, FAQ) lets Google show rich results like star ratings and prices, which lift click-through for free.
paste into Claude, Cursor, or ChatGPT
Low2 potential dead-click targetsBothConversionAccessibility (WCAG)Tracking
Elements styled like buttons but with no anchor, no <button> wrapper, no role="button", and no click attribute. Real visitors tap these expecting something to happen, then leave. Examples on this page: "DRAFTED IN YOUR VOICE" (div.kb-deck-tag), "DRAFTED IN YOUR VOICE" (div.kb-deck-tag).
paste into Claude, Cursor, or ChatGPT
LowNo llms.txt fileBothSEO
No /llms.txt. Optional: some AI tools read this file (Anthropic, Vercel, Stripe, Cloudflare and Hugging Face publish one, and AI coding assistants use it to find docs), so adding one is a cheap courtesy to them. Google has said in writing that Google Search and its AI features do not use llms.txt, so do not expect a search-ranking or AI Overviews benefit from it.
paste into Claude, Cursor, or ChatGPT
HighSome text is low-contrast and hard to readBothAccessibility (WCAG)
Text that does not stand out enough from its background is hard to read for many visitors, and fails accessibility guidelines Google checks.
paste into Claude, Cursor, or ChatGPT
MediumSecurity headers are missing or weakBothSecurity
The server response is missing browser-hardening headers that protect visitors and are a standard security and agency checklist item. Missing or weak here: Content-Security-Policy (the main defense against injected and cross-site scripts); clickjacking protection (X-Frame-Options or a CSP frame-ancestors rule); HSTS (Strict-Transport-Security, which forces HTTPS on return visits); X-Content-Type-Options: nosniff (stops MIME-type sniffing attacks). These are set at the server, CDN, or host level (most platforms expose them in settings or a config file) and do not change how the site looks or performs.
paste into Claude, Cursor, or ChatGPT
Low3 interactive elements have no stable, accessible identityBothAccessibility (WCAG)Tracking
These elements are clicked like buttons but expose no accessible name, or are a plain div/span used as a control with no role. Assistive tech announces only a role (or nothing), and analytics and heatmaps have no human-readable label or stable selector to bind the click to, so the click is both inaccessible and untrackable, and any redesign silently breaks click aggregation. Give each one a real <button>/<a>, an aria-label, and a stable id or data-attribute.
paste into Claude, Cursor, or ChatGPT
LowSome text is too small to read on phonesMobileAccessibility (WCAG)Conversion
43 chunks of text come in under 12 pixels on this page. Most visitors don't zoom, they just skim past anything that small. Bumping the smallest body text to 14 pixels makes the page read without effort.
paste into Claude, Cursor, or ChatGPT
median across loads

Accessibility findings are automated checks against Web Content Accessibility Guidelines (WCAG) 2.1 and 2.2. They flag potential barriers and legal risk, not a certification or a determination of compliance with the ADA, Section 508, or EN 301 549. Automated testing catches only a subset of issues; a full conformance review needs manual and assistive-technology testing by a qualified reviewer.

From finding to fix
Want the fix, not just the finding?
Install Harvv and we turn each issue above into a ready-to-paste prompt for your AI coding assistant. Drop it into Cursor, Claude, or Copilot and the diagnosis becomes a concrete code change, written against this exact page.
Get the fix prompts

"How we know": unlabeled = a deterministic fact, identical on every load (e.g. element sizes). Most findings are this kind, so we only mark the exceptions: median across loads = a noisy lab metric, reported as a median. real-user field data = Google CrUX, actual Chrome visitors.

Structural and AI-search checks crawl up to 8 pages from your sitemap (a sample, not your full site). "Broken" means a link returned 404, 410, or 5xx, or did not respond; access-controlled pages (401, 403) are not counted.

01bTake the whole report to your AI

Every finding above in one payload, with the reasoning behind each one. The prompt is written to be pasted into Claude, Cursor, or ChatGPT. The JSON is for piping into your own tooling.

Includes the site context, what is already working (so your assistant does not "fix" it), and every finding with its severity, evidence, and why it matters.
Audit of https://nowkickback.com/, run September 2, 2026. 16 issues were found. I want them fixed.

## Context
- Site: https://nowkickback.com/
- Mobile LCP (lab median): 326 ms
- Desktop LCP (lab median): 454 ms
- Page weight (median): 1.3 MB
- Tap targets under 44px: 0% (0 of 33)
- Evidence base: 4 mobile + 2 desktop loads

## Already working, do not change these
- Speed is good: The main content paints in about 0.3s in our test loads, inside Google's 2.5s "good" threshold. Real networks are slower, but the page itself is not heavy.
- Light page weight: The page is about 1.3 MB across 132 requests. That keeps it quick on mobile data and cheap to load repeatedly.
- No JavaScript errors on load: Nothing threw a script error across the test loads, so buttons and tracking are not silently breaking mid-session.
- Search basics are in place: Lighthouse scores SEO 100/100. The fundamentals Google looks for are present.
- Layout holds on phone and desktop: Nothing spilled past the edge at either 390px (phone) or 1366px (desktop), so the structure is responsive.

## Issues, most damaging first

### 1. [HIGH] Add quotations so AI engines cite this page
Category: AI Search, SEO
Why it matters: Generative engines (ChatGPT, Perplexity, AI Overviews) lift sourced, attributed quotes almost verbatim, and quotations are the single strongest citation lever (studies measure roughly +41%). Add 1-2 attributed expert quotes or blockquotes to the pages below. (Found across a sample of 1 pages from your sitemap, a partial crawl rather than your full site.)

### 2. [HIGH] Some text is low-contrast and hard to read
Category: Accessibility (WCAG)
Why it matters: Text that does not stand out enough from its background is hard to read for many visitors, and fails accessibility guidelines Google checks.

### 3. [MEDIUM] No XML sitemap found
Why it matters: No sitemap.xml at the standard location and none listed in robots.txt. A sitemap tells search engines every page you want indexed; without it they rely on link discovery and may miss pages.

### 4. [MEDIUM] Security headers are missing or weak
Category: Security
Why it matters: The server response is missing browser-hardening headers that protect visitors and are a standard security and agency checklist item. Missing or weak here: Content-Security-Policy (the main defense against injected and cross-site scripts); clickjacking protection (X-Frame-Options or a CSP frame-ancestors rule); HSTS (Strict-Transport-Security, which forces HTTPS on return visits); X-Content-Type-Options: nosniff (stops MIME-type sniffing attacks). These are set at the server, CDN, or host level (most platforms expose them in settings or a config file) and do not change how the site looks or performs.

### 5. [LOW] Unused JavaScript is being downloaded
Category: Performance
Why it matters: Code that never runs on this page still costs download and parse time on every visit. Splitting or removing it speeds up load. Lighthouse measured: Est savings of 493 KiB.

### 6. [LOW] Unused CSS is being downloaded
Category: Performance
Why it matters: Style rules that this page never uses still block rendering while they download. Trimming them frees the paint path. Lighthouse measured: Est savings of 40 KiB.

### 7. [LOW] No email capture or newsletter detected
Category: Conversion
Why it matters: No email input field was found in the page, and no email-marketing tag (Klaviyo, Mailchimp, Substack, ConvertKit, Beehiiv, MailerLite, ActiveCampaign, Omnisend, Brevo, Drip or Buttondown) was detected. A form that loads after JavaScript runs, or one behind a popup or a separate page, will not be visible to this check. If capturing visitors is relevant to this site, an email signup builds an owned audience you keep regardless of ad costs. Not every site needs one.

### 8. [LOW] No visible contact details (email or phone)
Category: Conversion
Why it matters: This page exposes no email address, no phone link, no contact form and no link to a contact page. For higher-value or trust-sensitive purchases, a clear way to reach a human reduces hesitation. A contact route that only appears after JavaScript runs, or that lives on a page not checked here, will not be visible to this check. Add an email or phone link in the header or footer.

### 9. [LOW] No advertising pixel detected
Category: Tracking
Why it matters: Analytics is present but no Meta/Google/TikTok ad pixel was found. If you run paid ads, conversion tracking should be installed before the next campaign so the platforms can optimize toward buyers, not clicks.

### 10. [LOW] No canonical tag, so duplicate URLs split the page's ranking
Why it matters: When the same content is reachable at multiple URLs (think tracking parameters or session IDs), Google can split your ranking signal across them. A single canonical tag tells Google which version counts.

### 11. [LOW] Links to this page will look bare when shared
Why it matters: The page is missing its Open Graph image, so when someone shares it on Facebook, LinkedIn, iMessage, or Slack the preview has no image. A flat grey link gets far fewer clicks than one with an image and headline.

### 12. [LOW] No structured data for rich search results
Why it matters: The page has no schema.org markup. Adding the right type (Product, Article, Organization, FAQ) lets Google show rich results like star ratings and prices, which lift click-through for free.

### 13. [LOW] 2 potential dead-click targets
Category: Conversion, Accessibility (WCAG), Tracking
Why it matters: Elements styled like buttons but with no anchor, no <button> wrapper, no role="button", and no click attribute. Real visitors tap these expecting something to happen, then leave. Examples on this page: "DRAFTED IN YOUR VOICE" (div.kb-deck-tag), "DRAFTED IN YOUR VOICE" (div.kb-deck-tag).
Exact elements found: "DRAFTED IN YOUR VOICE" (div.kb-deck-tag), "DRAFTED IN YOUR VOICE" (div.kb-deck-tag)

### 14. [LOW] No llms.txt file
Category: SEO
Why it matters: No /llms.txt. Optional: some AI tools read this file (Anthropic, Vercel, Stripe, Cloudflare and Hugging Face publish one, and AI coding assistants use it to find docs), so adding one is a cheap courtesy to them. Google has said in writing that Google Search and its AI features do not use llms.txt, so do not expect a search-ranking or AI Overviews benefit from it.

### 15. [LOW] 3 interactive elements have no stable, accessible identity
Category: Accessibility (WCAG), Tracking
Why it matters: These elements are clicked like buttons but expose no accessible name, or are a plain div/span used as a control with no role. Assistive tech announces only a role (or nothing), and analytics and heatmaps have no human-readable label or stable selector to bind the click to, so the click is both inaccessible and untrackable, and any redesign silently breaks click aggregation. Give each one a real <button>/<a>, an aria-label, and a stable id or data-attribute.
Exact elements found: (span.kb-h1-chat-pill) (no accessible name), "DRAFTED IN YOUR VOICE" (div.kb-deck-tag) (div/span used as a button, no role), "DRAFTED IN YOUR VOICE" (div.kb-deck-tag) (div/span used as a button, no role)

### 16. [LOW] Some text is too small to read on phones
Affects: mobile only
Category: Accessibility (WCAG), Conversion
Why it matters: 43 chunks of text come in under 12 pixels on this page. Most visitors don't zoom, they just skim past anything that small. Bumping the smallest body text to 14 pixels makes the page read without effort.
How we know: median across loads

## How to respond
Work through the issues in order. For each one give me the specific change that fixes it: real code or real copy, not advice. Keep changes minimal and match the existing style of the site.
Where several issues share one root cause, say so and fix it once rather than patching each symptom.
If an issue cannot be fixed without seeing more of the code, say exactly which file or selector you need instead of guessing.
16 findings, ready to paste

02Performance: phone, desktop, and real visitors

MetricMobileDesktopRead
TTFB (lab median)41 ms46 msLab
FCP (lab median)326 ms454 msLab
LCP (lab median)326 ms454 msGood
Page weight (median)1.3 MB1.3 MBOK

Google Lighthouse (lab): Performance 59 mobile / 99 desktop, SEO 100, Accessibility 96, Best Practices 96.

Lab numbers are from a headless mobile browser on an unthrottled connection: treat them as a floor, not a typical experience. Add a Google API key to light up real-user field data (CrUX) and Lighthouse scores.

03Tiny buttons are hard to tap on mobile

0 of 33 tappable items on this page come in below the platform minimums for reliable tapping on a phone (Apple recommends 44pt, Android 48dp; WCAG 2.5.8 sets 24px as the hard accessibility floor). The same ones came up small on every one of the 4 test loads, so this is the page itself, not a fluke.

When customers can't tap what they expect to, they get frustrated and many of them leave. They don't file a bug. They don't try again. They just leave. A desktop dashboard can't see this because it's the difference between a thumb and a cursor.

The fix is CSS-only on most sites: add padding around the icon (don't just change the icon size) so the actual tap area is at least 44×44 pixels. No redesign, no new assets.

04Technical SEO & structured data

CheckResult
TitleKickback — AI for the back office (33 chars)
Meta description167 chars
H11 on page
CanonicalMissing
Structured data (JSON-LD)None
Open GraphIncomplete

05The fix checklist

Everything to fix, priority first, each tagged with the screen it affects and a rough effort. Work top to bottom.

  1. Unused JavaScript is being downloadedBothVaries
  2. Unused CSS is being downloadedBothVaries
  3. No email capture or newsletter detectedBothVaries
  4. No visible contact details (email or phone)BothVaries
  5. Add quotations so AI engines cite this pageBothVaries
  6. No advertising pixel detectedBothDev afternoon
  7. No XML sitemap foundBothVaries
  8. No canonical tag, so duplicate URLs split the page's rankingBoth1 line
  9. Links to this page will look bare when sharedBothVaries
  10. No structured data for rich search resultsBothVaries
  11. 2 potential dead-click targetsBothCSS only
  12. No llms.txt fileBothVaries
  13. Some text is low-contrast and hard to readBothVaries
  14. Security headers are missing or weakBothVaries
  15. 3 interactive elements have no stable, accessible identityBothDev afternoon
  16. Some text is too small to read on phonesMobileCSS only

Effort is a rough read from the outside: "CSS only" means no new assets or backend work, "1 line" means a single tag, "Dev afternoon" means a developer needs to touch tracking or scripts.

06What this report cannot tell you

Everything above is from the outside, looking at the page on a simulated phone and desktop. The questions that actually decide revenue need real visitors. Install the Harvv pixel (one script tag, 16 KB, zero personal data, no engineering project) and within about 72 hours you'd know which buttons real customers tapped and missed, how often Google Analytics is missing visits, and exactly where mobile shoppers stalled and left. This report shows you where to look. The pixel shows you how often it happens, and to whom.

What to do next
See this same depth on your real visitors, every day.

Drop the Harvv pixel on nowkickback.com and we turn this one-off scan into ongoing measured behavior: which taps miss, where sessions stall, and the real drop rates. Free to start, no card needed.

Add the pixel free

07How we did this, and what it can't prove

  • 4 mobile + 2 desktop loads of one URL from headless Chrome (iPhone viewport at 390px, desktop at 1366px), September 2, 2026. Enough loads to separate real defects from random noise, not a full-site crawl.
  • Lab numbers, not real-user numbers (no field data was available for this run). Real devices on real networks run slower.
  • Friction is inferred, not counted. We can prove a button is small. We can't, from the outside, count how often it causes a missed tap. That requires the pixel on a live page.

About Harvv, the source of this teardown

Harvv is a behavioral UX analytics platform (harvv.com). A lightweight JavaScript pixel captures how real visitors behave on a site (dead clicks, rage clicks, scroll depth, Core Web Vitals, JavaScript errors, and 50+ other signals) and the engine turns them into prioritized, plain-English findings. This teardown is the outside-in version of that: the same detectors run against a public page, with no pixel installed.

How to read it. Every finding here is a reproducible, automated measurement, not an opinion: element sizes, contrast ratios, load metrics, and structured-data checks that anyone can re-run against the same URL. The method is stated in full above. Automated testing catches a subset of issues, so this is a starting point, not a certification.

Full disclosure. Harvv makes the pixel that would measure the friction these findings imply, so we have a commercial interest. That is exactly why the findings are kept to things a reader can verify independently, and why nothing here is inflated: an unreproducible claim would undermine the tool it is meant to demonstrate.

Prepared by Harvv (harvv.com), a behavioral UX analytics platform. Last updated September 2, 2026.

Related teardowns

Eco Host
Behavioral teardown
Vibhinngautam
Behavioral teardown
Forgeyourpathai
Behavioral teardown
Ysdev Ca
Behavioral teardown

See all site teardowns →

harvv://this-page live
Scroll depth how far you read0%
Dead clicks clicks that did nothing0
Rage clicks frustration bursts0
Interactions clicks that worked0
event log · live