toolforge.ai ← Back to home

Audit

borednbuzzed.com

The one thing to read first: this site is a client-rendered React SPA

△
The server sends 1,272 bytes and one empty <div id="root">
Every word of visible content, every link, every image loads AFTER the browser downloads and runs /assets/index-CufQhBwR.js. That shapes almost every finding below.
  • The no-JS on-page crawl sees 0 links, 0 images, 0 words, no <h1> — because it never ran the JavaScript that builds the page. This is not a report that the page is empty; it is the known limit of the thin/no-JS plan requested. A real content audit needs a JS-rendering crawl (paid, costs more per page).
  • Lighthouse (PageSpeed Insights) DOES run real Chrome and DOES execute the JavaScript, so its speed numbers below are trustworthy for what a visitor actually sees.

Speed — Lighthouse / PageSpeed Insights

68Moderate
Performance — Mobile
97Good
Performance — Desktop

Largest Contentful Paint — the real problem

8.1sPoor
Mobile
0.7sGood
Desktop

First Contentful Paint

2.7sModerate
Mobile
0.7sGood
Desktop
Accessibility 100 / 100 Best Practices 100 / 100 Total Blocking Time 0 ms / 0 ms Cumulative Layout Shift 0 / 0 Page weight 1,257 KB Server response 0 ms (Vercel edge)

Mobile LCP is the one real speed problem, and it is not a server or bundle-size problem — the server answers in 0 ms and the page is only 1.2 MB total. The 8.1-second wait is the SPA pattern itself: on a throttled mobile connection, the visitor sees a blank page until the JS bundle downloads, parses, and React paints the content. Desktop does not show this because Lighthouse desktop assumes a fast connection.

Fix: prerender or server-render at least the above-the-fold hero (a static HTML shell Google and mobile visitors see immediately, before React hydrates) — this is a build change, not a hosting change, since Vercel itself responds instantly.

On-page scan — what happened, and what tripped

16Pages attempted
16Pages returned 200
0Broken (4xx/5xx)
0Redirects
92.32On-page score (all 16)
16Identical shells

Every one of the 16 known routes was crawled as its own thin, no-JavaScript page — not one homepage scan. All 16 returned HTTP 200 (ok). Zero were broken and zero redirected.

△
The real finding: all 16 pages are byte-identical
/about, /shop, /checkout, /blog/indica-vs-sativa, and every other route return the exact same 1,272-byte SPA shell as the homepage — same title, same meta description, same onpage_score: 92.32, same missing <h1>. The server sends one shell for every route with no per-page HTML; a crawler or link-preview bot that cannot run JavaScript sees 16 indistinguishable pages, not 16 distinct ones. Same root cause as the mobile LCP issue above — the fix is prerendering or SSR per route, not a hosting change.
  • Title (all 16 pages, pre-JS): “Bored ‘N Buzzed Cannabis — Kirkland, WA” (39 chars — fine on its own, but identical everywhere)
  • Meta description (all 16 pages, pre-JS): “Bored N Buzzed Cannabis — Premium cannabis dispensary in Kirkland, WA. Come bored. Get buzzed.” (94 chars)
  • No <meta name="robots"> conflicts, canonical present, HTTPS, valid HTML5 doctype, on every page
  • duplicate_tags check errored (API needs a type param on this account) — harmless; the identical-shell finding above already covers what that check would have flagged

Analytics

△
No analytics at all
No Google Analytics, GTM, Meta/TikTok/Snapchat/Pinterest pixel, Hotjar, Klaviyo, Segment, Mixpanel, Amplitude, Matomo, HubSpot, Intercom, or Cloudflare RUM. Checked three ways: the live request list from a real Chrome page load, the raw HTML source, and the full text of all four JS bundles (index, vendor, motion, state) for every common tracker signature. Two string hits were false positives on inspection — “TikTok” is marketing copy, “gTag” is an internal JS toStringTag string, not Google's gtag.js. No visitor analytics of any kind, first-party or third-party.

Menu, POS & product content

Checked against the client's own Marketing Manager job posting. Every item below is a fact about the current site, confirmed in its own live menu feed — not a guess.

1,158Live products (POSaBIT feed)
9Categories
95.6%Products with no description
99.9%Products with no terpene data
△
POSaBIT is real and working — the content behind it is almost empty
The site's own menu feed (data/api_menu.json) pulls 1,158 live products across 9 categories straight from POSaBIT — every product image points at pbit-production.s3.amazonaws.com, POSaBIT's own image host. The “real-time inventory accuracy” part of the job posting is real. But 1,107 of those 1,158 products (95.6%) have no description text at all, and 1,157 (99.9%) have zero terpene data. This is the exact gap the job posting's Product Content task names: keeping the digital menu and the physical shelf at 100% accuracy. Right now the digital menu is almost entirely blank product names.
  • No Weedmaps or Leafly links found anywhere on the site — checked the full site and the live homepage. The job posting names updating both as a task; both listings already exist and are active (see Reviews below), the site just never points a visitor toward them.
  • 475 of 1,158 products (41%) are marked doh_compliant: false in the feed's own data. What this flag controls is a WSLCB/DOH question for the client — noted here as a fact to ask about, not a claim of a violation.

Reviews & social

  • Strong reviews, invisible on the site. Yelp lists the business at 4.8/5 from 189 reviews; Leafly and other cannabis directories list it separately, one at 4.9/5 from 123+ reviews. None of this appears anywhere on borednbuzzed.com — no review widget, no star rating, no link to either platform.
  • Social links confirmed live: Instagram (instagram.com/bnbkirkland_) and Twitter/X (twitter.com/borednbuzzed), both in the footer on every page.
  • No TikTok link exists. “TikTok” appears only in marketing copy describing what the brand does elsewhere — not a link to an account on this site.
  • No push notifications or SMS. Checked all four JS bundles for a service worker and the Notification API — neither is present. The Rewards page mentions “early drop notifications” as a benefit of joining, but no working notification mechanism exists in the code today.

Age gate

Every page carries the required text disclaimer site-wide, in the footer, not only in a one-time pop-up: “Must be 21+ to purchase. For use only where legal. Keep out of reach of children.” That part is confirmed correct.

✓
Pop-up gate mechanism confirmed
Read directly from the site's own JS, then proved live in a browser: the gate stores one flag, sessionStorage.setItem("bnb_age","1"), set the moment a visitor clicks “YES, I AM 21+”. No cookie, localStorage, or IndexedDB is involved. Clearing this one flag and reloading brings the gate back; a normal same-tab reload after passing it does not. It works exactly as the client's own code intends.

Site health

  • ✗
    No sitemap.xml. Confirmed two ways: DataForSEO's own site-wide check (sitemap: false) and a direct fetch — /sitemap.xml returns HTTP 200 but the body is the React app shell, not a real sitemap.
  • ✗
    No robots.txt either. Same symptom — /robots.txt returns 200 with the SPA shell, not a robots file.
  • ✓
    SSL valid — wildcard cert (*.borednbuzzed.com) from Let's Encrypt, expires 2026-09-18. Auto-renews if Vercel manages it (it almost certainly does).
  • ✓
    Redirects working — http:// → https:// (308) and bare borednbuzzed.com → www. (308) both correct, no duplicate-content risk.
  • ✓
    Hosting: Vercel — healthy — IP 216.198.79.1, HTTP/2, HSTS enabled (max-age=63072000), fast edge response (X-Vercel-Cache: HIT). No CMS detected.

Fonts in use

Six font families load across two paths — the HTML <head> link and a separate @import inside the compiled CSS bundle. Luckiest Guy is the site's primary display font, the default for every <h1>–<h6> and all three button styles.

Bored N Buzzed

Luckiest GuyPrimary display font — default for every h1–h6 and all buttons. Loaded via the CSS @import.

Bored N Buzzed

Bebas NeueThe font-display utility (fallback: Impact)

Bored N Buzzed

AntonThe font-heading utility (fallback: Impact)

Bored N Buzzed

DM SansBody font (font-body), weight 300–600, italic

Bored N Buzzed

JetBrains MonoLoaded via the same @import; used only for code/kbd/pre — not a visible design element here

Bored N Buzzed

ItalianaLoaded via the head link but zero font-family declarations anywhere in the built CSS — genuinely unused

← Back to home