We built this site, audited it ourselves, then fixed what we found.
The whole of what SDG does — build it, look after it, keep it honest — in one example we can't spin. We built the Horizon Football Festival site for Manly United FC, ran our own audit against it, fixed every finding, and re-audited to prove the improvement. Here are the receipts.
- ClientManly United FC — Horizon Football Festival
- WhatTournament microsite with team registration
- WhereCromer Park, Northern Beaches NSW
- EngagementBuild + audit + fix + ongoing care
- Livehorizonfootballfestival.com.au
- Year2026
Most agencies show you the polished result and ask you to take the quality on faith. We'd rather show our working. After building the Horizon site we put it through the exact same audit we sell — the same 900-plus dimension check we run on any prospect — and it came back with findings. Of course it did; every site does on the first pass.
The honest move was to fix them and re-run the audit, so the improvement is measured, not asserted. That's the loop a managed-care client gets every quarter: audit, fix, verify, repeat.
Three real audit runs. Same engine, same site.
Finding counts by severity across the three audits — as first built, after the security and accessibility round, then after the performance round. Every count comes from a citation-verified audit, not a self-graded checklist.
| Severity | Original (as built) |
After security + accessibility |
After performance |
|---|---|---|---|
| Critical | 1 | 0 | 0 |
| High | 11 | 7 | 8 |
| Medium | 54 | 30 | 30 |
| Low | 73 | 62 | 56 |
The one critical finding: gone. High severity down by a third, medium nearly halved. The high count ticking from 7 to 8 in the last column is honest noise — the performance round changed how some images load, which surfaced one new lower-confidence high while removing several medium and low items. We show it rather than hide it. That's the point of the page.
Every change deployed, then re-audit-confirmed.
-
Security headers
Six headers added via
closed the critical + several high findings.htaccess— HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy — plus asecurity.txtdisclosure contact. -
Accessibility
A
WCAG landmark + bypass block<main>landmark and a skip-to-content link added to every page, so keyboard and screen-reader users can navigate the site properly. -
SEO & structured data
A schema.org
valid SportsEvent schemaSportsEventJSON-LD block so search engines understand the tournament dates, venue and registration — the markup that earns rich results. -
Performance
Nine photos converted to WebP (2.87 MB → 1.43 MB, 51% lighter) with a JPG fallback, explicit image dimensions to stop layout shift, cache-control headers, and a preload hint for the hero image.
page weight roughly halved
The actual audit deliverable.
This is the original "as built" audit for the Horizon site, exactly the format a client receives — every finding with its evidence, every claim citation-verified. Read it in the browser or take the PDF.
Where we stopped, and why.
A defensible audit has to be honest about the findings left standing. Two remain deliberately.
The audit correctly flags the CSS framework as render-blocking. It's load-bearing for the whole design; removing it cleanly means migrating off the CDN to a compiled stylesheet — a worthwhile change, scheduled rather than rushed. We left it visible in the audit rather than suppressing a true finding.
The first run flagged a missing ABN, privacy policy and public-liability statement — obligations that apply to a commercial business, not a club tournament microsite. Rather than ignore them, we improved the audit engine itself to classify site type and gate those checks. Finding the gap on our own build is exactly how the tool gets sharper.
Want the same honesty on your site?
An audit is where most relationships start. From $497, fully credited against managed care if you go further.
Start a conversation