What your site is actually doing.
One page: what is working, what is costing you visitors, and what to fix next. A phone-and-desktop teardown of the live site: 4 phone loads + 2 desktop loads. No login, no insider access, no Harvv pixel needed. The full evidence is at the bottom.
Working
What's already working. These held up across every load.
Speed is good.
No JavaScript errors on load.
Lighthouse scores SEO 92/100. The fundamentals Google looks for are present.
Nothing spilled past the edge at either 390px (phone) or 1366px (desktop), so the structure is responsive.
Costing you
Ranked by what hurts conversion most. Full evidence below.
Some links cannot be followed by Google
Add quotations so AI engines cite this page
Tiny buttons are hard to tap on mobile
Page is heavy and slow on mobile data
2 form fields have no label
7 potential dead-click targets
3 small changes, on the pages people actually land on: Tiny buttons are hard to tap on mobile; Page is heavy and slow on mobile data; 7 potential dead-click targets. We re-measure the same samples after.
This is one of several industrial supply sites we tore down the same way. The same friction repeats on Fastenal, and we pulled the cross-site pattern together in the industrial web report.
01Findings, ranked by what hurts conversion most
| Severity | Finding | How we know |
|---|---|---|
| Medium | Tiny buttons are hard to tap on mobileMobileAccessibility (WCAG)Conversion 15 of 38 tappable items on this page (39%) measure under 24 pixels on their shorter side, below the 24px floor WCAG 2.5.8 sets for accessibility and well under the platform minimums (Apple recommends 44pt, Android 48dp) for reliable tapping, and the same ones came up small on every test load. When visitors can't hit what they expect to, they get frustrated and many of them leave instead of trying again. The exact elements we found: paste into Claude, Cursor, or ChatGPT | |
| Medium | Page is heavy and slow on mobile dataBothPerformance Each visit downloads about 2.7 megabytes, roughly 137 KB of images and 2282 KB of JavaScript across 134 separate downloads. On a fast connection that's fine. On a phone with patchy mobile data, that's several seconds of blank screen before the page is readable. paste into Claude, Cursor, or ChatGPT | median across loads |
| Low | Images have no width or height set (layout is stable for now)BothPerformanceSEO 32 of 33 images don't declare width and height. Your layout currently stays stable (measured Cumulative Layout Shift is 0, which is fine), most likely because space is reserved another way (CSS), so this is not causing visible jumps today. It is still worth setting explicit dimensions or a CSS aspect-ratio so a slow connection or a future style change cannot reintroduce shift. The exact images we found: paste into Claude, Cursor, or ChatGPT | |
| Low | Unused JavaScript is being downloadedBothPerformance Code that never runs on this page still costs download and parse time on every visit. Splitting or removing it speeds up load. Lighthouse measured: Est savings of 1,068 KiB. paste into Claude, Cursor, or ChatGPT | |
| Low | Unused CSS is being downloadedBothPerformance Style rules that this page never uses still block rendering while they download. Trimming them frees the paint path. Lighthouse measured: Est savings of 270 KiB. paste into Claude, Cursor, or ChatGPT | |
| Low | The page loads from a lot of third-party servicesBoth Around 26 separate outside domains load on this page (analytics, ads, chat widgets, fonts). Each one is a connection that can be slow, fail, or change behavior outside your control. paste into Claude, Cursor, or ChatGPT | median across loads |
| Medium | 2 form fields have no labelBothAccessibility (WCAG)ConversionTracking Screen readers can't announce these fields, and a sighted user who clears the placeholder can't recover the prompt. Wrap each input in <label>…</label> or add aria-label. The exact elements we found: paste into Claude, Cursor, or ChatGPT | |
| Low | No email capture or newsletter detectedBothConversion No email input field was found in the page, and no email-marketing tag (Klaviyo, Mailchimp, Substack, ConvertKit, Beehiiv, MailerLite, ActiveCampaign, Omnisend, Brevo, Drip or Buttondown) was detected. A form that loads after JavaScript runs, or one behind a popup or a separate page, will not be visible to this check. If capturing visitors is relevant to this site, an email signup builds an owned audience you keep regardless of ad costs. Not every site needs one. paste into Claude, Cursor, or ChatGPT | |
| High | Some links cannot be followed by GoogleBothSEO Links that are not real anchors with an href cannot be crawled, so the pages they point to may never get indexed. paste into Claude, Cursor, or ChatGPT | |
| High | Add quotations so AI engines cite this pageBothAI SearchSEO Generative engines (ChatGPT, Perplexity, AI Overviews) lift sourced, attributed quotes almost verbatim, and quotations are the single strongest citation lever (studies measure roughly +41%). Add 1-2 attributed expert quotes or blockquotes to the pages below. (Found across a sample of 1 pages from your sitemap, a partial crawl rather than your full site.) paste into Claude, Cursor, or ChatGPT | |
| Low | Search-result title will be cut offBothSEO The title is 80 characters; Google truncates around 60. Front-load the important words so nothing useful gets clipped. paste into Claude, Cursor, or ChatGPT | |
| Medium | 7 potential dead-click targetsBothConversionAccessibility (WCAG)Tracking Elements styled like buttons but with no anchor, no <button> wrapper, no role="button", and no click attribute. Real visitors tap these expecting something to happen, then leave. Examples on this page: "Help" (span.hide), "Contact Us" (span.hide), "Shipping Boxes" (span.hide). The exact elements we found: paste into Claude, Cursor, or ChatGPT | |
| Medium | Click activity may be invisible inside the Facebook in-app browserBothTracking Patterns on this page (42 inline onclick handlers) tend to suppress click events inside Android Webview and iOS in-app browsers. Visitors arriving from Meta ads may register as zero-interaction sessions even when they're actively using the page. Add a server-side landing tracker so you don't lose that audience entirely. paste into Claude, Cursor, or ChatGPT | |
| Low | No canonical tag, so duplicate URLs split the page's rankingBoth When the same content is reachable at multiple URLs (think tracking parameters or session IDs), Google can split your ranking signal across them. A single canonical tag tells Google which version counts. paste into Claude, Cursor, or ChatGPT | |
| Low | There is very little text on this pageBoth The page has about 58 words. Thin pages give Google little to rank on and visitors little to act on. If this is a key landing page, it usually needs more substance. paste into Claude, Cursor, or ChatGPT | |
| Low | No llms.txt fileBothSEO No /llms.txt. Optional: some AI tools read this file (Anthropic, Vercel, Stripe, Cloudflare and Hugging Face publish one, and AI coding assistants use it to find docs), so adding one is a cheap courtesy to them. Google has said in writing that Google Search and its AI features do not use llms.txt, so do not expect a search-ranking or AI Overviews benefit from it. paste into Claude, Cursor, or ChatGPT | |
| Medium | 10 interactive elements have no stable, accessible identityBothAccessibility (WCAG)Tracking These elements are clicked like buttons but expose no accessible name, or are a plain div/span used as a control with no role. Assistive tech announces only a role (or nothing), and analytics and heatmaps have no human-readable label or stable selector to bind the click to, so the click is both inaccessible and untrackable, and any redesign silently breaks click aggregation. Give each one a real <button>/<a>, an aria-label, and a stable id or data-attribute. The exact elements we found:
paste into Claude, Cursor, or ChatGPT | |
| Low | Security headers are missing or weakBothSecurity The server response is missing browser-hardening headers that protect visitors and are a standard security and agency checklist item. Missing or weak here: a stronger HSTS policy (max-age at least 180 days plus includeSubDomains); X-Content-Type-Options: nosniff (stops MIME-type sniffing attacks). These are set at the server, CDN, or host level (most platforms expose them in settings or a config file) and do not change how the site looks or performs. paste into Claude, Cursor, or ChatGPT |
Accessibility findings are automated checks against Web Content Accessibility Guidelines (WCAG) 2.1 and 2.2. They flag potential barriers and legal risk, not a certification or a determination of compliance with the ADA, Section 508, or EN 301 549. Automated testing catches only a subset of issues; a full conformance review needs manual and assistive-technology testing by a qualified reviewer.
"How we know": unlabeled = a deterministic fact, identical on every load (e.g. element sizes). Most findings are this kind, so we only mark the exceptions: median across loads = a noisy lab metric, reported as a median. real-user field data = Google CrUX, actual Chrome visitors.
Structural and AI-search checks crawl up to 8 pages from your sitemap (a sample, not your full site). "Broken" means a link returned 404, 410, or 5xx, or did not respond; access-controlled pages (401, 403) are not counted.
02Performance: phone, desktop, and real visitors
| Metric | Mobile | Desktop | Read |
|---|---|---|---|
| TTFB (lab median) | 158 ms | 479 ms | Lab |
| FCP (lab median) | 768 ms | 1.2s | Lab |
| LCP (lab median) | 1.2s | 1.6s | Good |
| Page weight (median) | 2.7 MB | 3.0 MB | Watch |
Google Lighthouse (lab): Performance 31 (mobile), SEO 92, Accessibility 92, Best Practices 38.
Lab numbers are from a headless mobile browser on an unthrottled connection: treat them as a floor, not a typical experience. Add a Google API key to light up real-user field data (CrUX) and Lighthouse scores.
03Tiny buttons are hard to tap on mobile
15 of 38 tappable items on this page come in below the platform minimums for reliable tapping on a phone (Apple recommends 44pt, Android 48dp; WCAG 2.5.8 sets 24px as the hard accessibility floor). The same ones came up small on every one of the 4 test loads, so this is the page itself, not a fluke.
The buttons measuring below the minimum on this scan:
- a 75x22 "Uline homepage"
- a 44x22 "My Account"
- a 44x22 "Call Uline"
- a 44x22 "Cart: 0 Items"
- a 30x19 "Help"
- a 67x19 "Contact Us"
- a 49x19 "Careers"
- a 92x19 "Shipping Boxes"
The fix is CSS-only on most sites: add padding around the icon (don't just change the icon size) so the actual tap area is at least 44×44 pixels. No redesign, no new assets.
04Technical SEO & structured data
| Check | Result |
|---|---|
| Title | ULINE - Shipping Boxes, Shipping Supplies, Packaging Materials, Packing Supplies (80 chars) |
| Meta description | 202 chars |
| H1 | 1 on page |
| Canonical | Missing |
| Structured data (JSON-LD) | Organization |
| Open Graph | Title + image |
05The fix checklist
Everything to fix, priority first, each tagged with the screen it affects and a rough effort. Work top to bottom.
- Tiny buttons are hard to tap on mobileMobileCSS only
- Page is heavy and slow on mobile dataBothSmall
- Images have no width or height set (layout is stable for now)BothCSS only
- Unused JavaScript is being downloadedBothVaries
- Unused CSS is being downloadedBothVaries
- The page loads from a lot of third-party servicesBothDev afternoon
- 2 form fields have no labelBothVaries
- No email capture or newsletter detectedBothVaries
- Some links cannot be followed by GoogleBothVaries
- Add quotations so AI engines cite this pageBothVaries
- Search-result title will be cut offBoth1 line
- 7 potential dead-click targetsBothCSS only
- Click activity may be invisible inside the Facebook in-app browserBothVaries
- No canonical tag, so duplicate URLs split the page's rankingBoth1 line
- There is very little text on this pageBothVaries
- No llms.txt fileBothVaries
- 10 interactive elements have no stable, accessible identityBothDev afternoon
- Security headers are missing or weakBothVaries
Effort is a rough read from the outside: "CSS only" means no new assets or backend work, "1 line" means a single tag, "Dev afternoon" means a developer needs to touch tracking or scripts.
06What this report cannot tell you
Everything above is from the outside, looking at the page on a simulated phone and desktop. The questions that actually decide revenue need real visitors. Install the Harvv pixel (one script tag, 16 KB, zero personal data, no engineering project) and within about 72 hours you'd know which buttons real customers tapped and missed, how often Google Analytics is missing visits, and exactly where mobile shoppers stalled and left. This report shows you where to look. The pixel shows you how often it happens, and to whom.
Drop the Harvv pixel on uline.com and we turn this one-off scan into ongoing measured behavior: which taps miss, where sessions stall, and the real drop rates. Free to start, no card needed.
Add the pixel free07How we did this, and what it can't prove
- 4 mobile + 2 desktop loads of one URL from headless Chrome (iPhone viewport at 390px, desktop at 1366px), September 1, 2026. Enough loads to separate real defects from random noise, not a full-site crawl.
- Lab numbers, not real-user numbers (no field data was available for this run). Real devices on real networks run slower.
- Friction is inferred, not counted. We can prove a button is small. We can't, from the outside, count how often it causes a missed tap. That requires the pixel on a live page.
- This page rotates its content load to load, which is on its own a reason a single-shot scan can't be the last word on it.
About Harvv, the source of this teardown
Harvv is a behavioral UX analytics platform (harvv.com). A lightweight JavaScript pixel captures how real visitors behave on a site (dead clicks, rage clicks, scroll depth, Core Web Vitals, JavaScript errors, and 50+ other signals) and the engine turns them into prioritized, plain-English findings. This teardown is the outside-in version of that: the same detectors run against a public page, with no pixel installed.
How to read it. Every finding here is a reproducible, automated measurement, not an opinion: element sizes, contrast ratios, load metrics, and structured-data checks that anyone can re-run against the same URL. The method is stated in full above. Automated testing catches a subset of issues, so this is a starting point, not a certification.
Full disclosure. Harvv makes the pixel that would measure the friction these findings imply, so we have a commercial interest. That is exactly why the findings are kept to things a reader can verify independently, and why nothing here is inflated: an unreproducible claim would undermine the tool it is meant to demonstrate.
Prepared by Harvv (harvv.com), a behavioral UX analytics platform. Last updated September 1, 2026.