How to use it
- 1
Paste a public HTML page URL.
- 2
WebDiag discovers external script src values and checks a bounded response set through SafeHttpFetcher.
- 3
Review unique scripts, declared bytes, parser-blocking candidates, compression, cache, and failed assets.
What the tool can do
- Script-src deduplication and module/classic separation.
- Checks status, final URL, MIME, Content-Length, Content-Encoding, Cache-Control, and redirects.
- Heuristic findings for a large asset surface and classic parser-blocking candidates without a fake score.
Common use cases
- Review bundle-count growth after a release.
- Find failed, duplicated, or MIME-mismatched script responses.
- Review compression and long-cache signals for external JavaScript assets.
How it works inside
HTML uses a bounded GET, while discovered JavaScript assets use headers-only GET requests through the same SSRF-safe fetcher.
Private/local targets, unsafe redirects, and DNS-rebinding paths are blocked for every nested URL.
Questions and answers
Does this replace a bundler analyzer?
No. WebDiag checks the delivery surface of a published page. Module graphs, tree shaking, and composition require your bundler report.
Why is there no performance score?
Static headers and Content-Length are not enough for an honest runtime-cost score. That requires a browser or PageSpeed layer.
