AGAINST LAB. // SITE AUDIT
Confidential · For Shawn · 27 May 2026

Full-Site
Audit.

A multi-pass, multi-agent review of againstlab.com across performance, SEO, accessibility, security, and UX. The store sits on a clean Shopify + Cloudflare foundation — the headline issues are owner-fixable, and most live in the theme, settings, DNS, and one custom rewards integration.

Target
againstlab.com
Platform
Shopify + Cloudflare
Catalog
250+ products
Method
6 AI agents + Codex
0
Findings logged
0
Fix-first (P0)
0
Critical + High
0
Owner-actionable
01

Scorecard

Grades reflect current live state, not potential. The bones are good; execution gaps drag the scores.

C

Overall: solid foundation, urgent fixes needed

Nothing here is a teardown. A well-built theme and a managed platform mean the store is fundamentally sound — but a catastrophic mobile load time, blank legal pages, missing email authentication, an unsafe rewards integration, and zero on-site reviews are actively costing trust, ranking, and conversions today. Clear the eight Fix-First items and this jumps to a B+.

02

Fix First

The eight items with the biggest impact on revenue, trust, and legal exposure — ordered by leverage.

03

All Findings

Filter by area, severity, or who can fix it. Click any row for impact & the fix.

Area
Severity Owner
04

Working Well

What to protect. These are real strengths — keep them through any redesign.

05

How This Was Done

Black-box audit of the live site. Independent agents, cross-checked, then key claims re-verified.

PASS 1

Recon

Headers, DNS, TLS, robots/sitemaps, rendered HTML, catalog dump, tech fingerprint — captured as shared evidence.

PASS 2

Parallel audit

Five specialist agents (perf, SEO, a11y, security, UX) ran concurrently, each writing a full report with evidence.

PASS 2b

Codex review

An independent engine re-read the raw markup to confirm, challenge, and extend the agents' findings.

PASS 3

Verify

The highest-impact claims (LCP, blank policies, /zh, SPF/DMARC, the XSS sink) were re-tested directly before publishing.

Performance · Lighthouse
SEO · structured data & i18n
Accessibility · WCAG 2.2 AA
Security · headers, DNS, supply chain
UX & Content · CRO
◆ Codex · independent code review

Note on honesty: Codex flagged a few claims as "unverifiable" — that's because it only read the static saved HTML, while the live-fetching agents confirmed those same items against the running site and Lighthouse traces (e.g. the blank policy pages and the untranslated /zh were independently re-checked here). "Unverifiable from static files" ≠ false.