1The settings outside the plugin
Every visit to www.hermeticnetworks.com passes through six places in order: the visitor's phone, Cloudflare, the hosting server, WordPress, the Beaver Builder theme, and the finished page. Each place has settings that change what Google measures, and an SEO plugin controls none of them. This module names the setting at each stop, says what to look for, and has you run Google's own measuring tool against the homepage and the managed IT page. At the end you have those results recorded, the four versions of the site's address checked, and the permalink setting confirmed.
Search engine optimization (SEO) work on the Hermetic site has so far been about words: which search each page answers, what the title says, which pages are in the sitemap. The Rank Math course handles all of that. This module is about the machinery under the words. Google's documentation on page experience says its ranking systems favor pages that load fast, respond quickly and hold still, and that relevance and quality still decide most of the order. A fast page about the wrong subject stays unranked. Between two pages that answer "managed IT services Richmond" equally well, the one that loads faster on a phone has the edge.
The order in the figure is the order of the module. A slow answer from the host cannot be fixed in the theme, and a heavy theme cannot be fixed at Cloudflare, so each stop is checked on its own.
2Hosting and server response time
Time to first byte (TTFB) is the time from the moment the browser sends its request to the moment the first byte of the answer arrives. It covers the Domain Name System (DNS) lookup that turns www.hermeticnetworks.com into an address, the connection and encryption handshake, and the time the server spends building the page. Everything else in this module, the images, the fonts, the scripts, can only start after that first byte. A page with a two-second TTFB is slow before a single pixel is drawn.
Three things raise it on a WordPress site. The first is shared hosting, where many sites live on one machine and share its processor and memory, so a neighbor's busy afternoon slows the Hermetic page. The second is the work WordPress does per visit: unless a cache is in place, every request runs PHP code and database queries to assemble the page from scratch. The third is the page builder. Beaver Builder stores each page as a layout of modules and renders them on request, which adds to the PHP work, and every additional plugin adds its share. The site's host and plan are not known yet; the Do this now section asks you to find out.
PageSpeed Insights, Google's free measuring tool at pagespeed.web.dev, shows TTFB in two places. In the field data at the top, Time to First Byte appears among the additional metrics when Google has enough visitor data for the page. In the lab section further down, the audit named "Reduce initial server response time" reports how long the server took to send the HTML document in that one test run. The web.dev guidance on TTFB publishes 0.8 seconds as the figure most sites should aim to stay under; it is a published guide, cited in Sources, and a page over it is spending time before it has started.
Two older worries about hosting matter less than they did. A shared IP address, the usual side effect of shared hosting, is the normal case for any site behind Cloudflare, because every Cloudflare site shares Cloudflare's addresses, and Google ranks hostnames. A transfer cap on the plan still matters: a plan that throttles or suspends the site after a set amount of monthly traffic takes it down at the moment it gets attention. Read the plan's terms and write down the cap.
Who hosts the site, which plan it is on, whether the plan includes a page cache, and what the TTFB is. The crawl of 2026-09-29 read the site through Cloudflare and could not see the host behind it. Until the Do this now steps are done, every speed statement about the Hermetic site is a guess.
3HTTPS and one hostname
Hypertext Transfer Protocol Secure (HTTPS) is the encrypted form of the protocol the primer covered: the browser and the server agree on a key and everything between them is scrambled in transit. Google has used HTTPS as a ranking signal since 2014 and Chrome marks plain HTTP pages "Not secure". The certificate that makes it work can be issued at the host or by Cloudflare at its edge, and on this site Cloudflare sits in front, so there are two legs to encrypt: visitor to Cloudflare, and Cloudflare to the host.
The homepage can be reached at four addresses: http://hermeticnetworks.com/, http://www.hermeticnetworks.com/, https://hermeticnetworks.com/ and https://www.hermeticnetworks.com/. To Google those are four URLs that happen to hold the same page. Google's documentation on duplicate URLs says it will pick one as the canonical, the version it treats as the original, and it may pick the one you did not want. Links other sites make to the non-www address and links to the www address are then counted toward different URLs. The fix is one permanent redirect: three of the four answer 301 and send the visitor to the fourth. For Hermetic the fourth is https://www.hermeticnetworks.com/, the address the homepage already declares as its canonical.
The redirect can be made at any of three stops in the figure in section 1: Cloudflare, with its Always Use HTTPS switch under SSL/TLS and a redirect rule for the bare hostname; the host's control panel; or WordPress itself, which redirects a request for a different hostname to the one in its settings for most pages. Whichever layer does it, the result is tested from the outside, in the Do this now section. Inside WordPress, open Settings and then General. Two fields matter: WordPress Address (URL), where the WordPress files live, and Site Address (URL), the address visitors use. Both read https://www.hermeticnetworks.com on a correctly set site. A value starting http:// in either field makes WordPress write plain-HTTP links into its own pages, each of which then redirects.
One trap sits between the two legs of encryption. Cloudflare's SSL/TLS mode called Flexible encrypts visitor to Cloudflare and sends plain HTTP to the host. WordPress sees an HTTP request, compares it with the https address in its settings, redirects to https, Cloudflare sends it back as http, and the browser reports too many redirects. The mode to use is Full (strict), with a certificate installed at the host. If the site loads today without a loop the mode is fine; write down which one it is anyway.
4Permalink structure
A permalink is the permanent address of one post or page, and the permalink structure is the rule WordPress uses to build those addresses. It lives under Settings and then Permalinks. The choices are Plain, which produces /?p=123; Day and name and Month and name, which put the date in front of the slug; Numeric; Post name, which produces /slug/; and Custom. Pages always use their slug regardless of the setting. The setting changes posts, and the Hermetic site has 148 of them in its sitemap.
Post name is the structure to have. A reader and Google both get more from /which-mfa-is-most-secure/ than from /2024/03/14/which-mfa-is-most-secure/, where the date tells a searcher in 2026 that the post is old before they open it, and the plain version says nothing at all. Google's guidance on URL structure asks for simple, readable words in the address, and Post name is how WordPress delivers that.
The catch is changing it on a live site. The structure applies to every post at once, so moving from Day and name to Post name changes 148 addresses in the same second, and every link to the old addresses from other sites, from email signatures and from Google's index now points at an address that no longer exists. WordPress tries to help: when a request arrives for an old-style address it often recognizes the slug and redirects to the new one on its own. You cannot count on that for every post, and you cannot see which ones it missed without checking. A permalink change is therefore a redirect job, done with the redirect inventory from the Rank Math course and tested row by row, which is Rank Math module 09. If the setting already reads Post name, there is nothing to do except record it. If it reads anything else, record that and add the change to the redirect job rather than clicking Save today.
The same screen holds the Category base and Tag base fields, which set the word in front of archive URLs, such as /category/cybersecurity/. Leave them alone. The Rank Math course decides which archives stay in the index at all, and renaming the base is another 102 redirects for the 84 tags and 18 categories the site has today.
5Theme and page-builder weight
A page builder is a WordPress plugin that lets you lay out a page by dragging modules, rows and columns instead of writing the page's code. The site runs Beaver Builder, both the theme and the builder. The convenience has a cost that shows up at the last two stops in the figure: every module adds its own markup, the builder loads a stylesheet and scripts for the page, and modules such as sliders, counters and accordions bring their own scripts along. The browser has to download, parse and run all of it before the page is finished, and on a phone with a mid-range processor that running time is what the visitor waits through.
You can see the weight rather than guess at it. Run the managed IT page through PageSpeed Insights and open the lab diagnostics. Three audits tell the story. "Reduce unused CSS" and "Reduce unused JavaScript" list the stylesheet and script files on the page and how much of each the page never used; builder files appear here by name. "Avoid enormous network payloads" totals what the page downloaded, with the largest files first. "Minimize main-thread work" shows how long the browser's single working thread was busy running scripts and laying out the page. Each audit names files, so you can see which plugin or module put a file there.
Most of what the builder loads is outside your control without a developer. Three things are in your control from the editor.
Fewer modules per page
Every module is markup, style and often a script. A service page with a headline, four paragraphs, one image and one call to action loads faster than the same words in twelve modules with icons, dividers and animated counters. When a module is decoration, remove it.
No sliders
A slider on the homepage loads every slide's image, runs a script to rotate them, and moves content under the visitor's thumb. The visitor reads slide one and scrolls. One image and one headline say the same thing with none of the cost.
System fonts or one family
Each web font family is a download, and text cannot settle until it arrives. System fonts, the ones already on the phone, cost nothing. If the brand needs a web font, one family in two weights, set once in the theme's Customizer typography settings, is the limit.
A heavier change, such as replacing the builder or the theme, is a rebuild of 139 pages and belongs in a project plan. Write the three audits' top entries into the record for each page you test; they are the backlog for that plan.
6Images
Images are usually the largest files on a page, and on a service page the hero image is usually the largest thing on the first screen, which makes it the element Google times in section 8. Five decisions about each image are made in WordPress and the editor, and none of them is a plugin setting.
- Dimensions. Upload an image at the size it is displayed. A camera file 5,000 pixels wide shown in a 1,200-pixel column makes the phone download four times the pixels it can show. WordPress generates several smaller sizes on upload and the browser picks the one that fits, but the original is still what the builder's full-size option serves.
- Compression. A photograph saved at a moderate JPEG quality looks the same on a phone as the same photograph saved at maximum quality and weighs a fraction. Export from the editing tool at a moderate setting, or run the file through a compressor before upload.
- Format. WebP and AVIF are newer image formats that hold the same picture in a smaller file than JPEG or PNG. WordPress has accepted WebP uploads since version 5.8 and AVIF since 6.5, so the Media Library takes them directly. Convert the hero and any large photo; leave logos and icons as SVG or PNG where sharp edges matter.
- Lazy loading. Lazy loading delays the download of an image until the visitor scrolls near it. WordPress has added the
loading="lazy"attribute to images on its own since version 5.5, and in recent versions it skips the images likely to be on the first screen. The trap is the hero: if a builder module marks the first-screen image lazy, the browser waits before fetching the one image that matters most. The PageSpeed Insights audit "Largest Contentful Paint image was lazily loaded" catches it. - Alt text. The alt attribute is the sentence a screen reader speaks and the text Google reads to know what the image shows. Write it for the reader: "Technician replacing a switch in a Richmond office server rack" says what the picture is; "managed IT services Richmond VA" describes a search and gets read as stuffing. A purely decorative image gets an empty alt so screen readers skip it.
The plugin side of images, the automatic alt text fallback and whether attachment pages exist, is set in Rank Math module 04. That fallback fills a gap when someone forgets; the real alt text is written in the Media Library, one image at a time.
7Caching and Cloudflare
A page cache stores the finished HTML of a page the first time WordPress builds it and hands that stored copy to the next visitor, so the PHP and database work from section 2 happens once instead of on every visit. For a site like Hermetic's, where pages change when someone edits them and at no other time, a page cache removes most of the server time from TTFB. The cache can live at the host, where many managed WordPress plans include one, or in a plugin, and WP Rocket and LiteSpeed Cache are two options for the plugin route. Whether the current host provides one is not known yet. A browser cache is the separate copy the visitor's own phone keeps of stylesheets, scripts and images, so a second page on the site loads without fetching them again.
Cloudflare is a content delivery network (CDN), a set of servers around the world that sit in front of the site. The domain's DNS points at Cloudflare; Cloudflare fetches pages from the host, keeps copies of static files such as images, stylesheets and scripts at its edge servers, and serves those copies from whichever server is nearest the visitor. It also terminates HTTPS and blocks a share of hostile traffic, which is why the crawl of 2026-09-29 could read only the homepage. By default it caches static files and passes HTML through to the host each time; a cache rule can make it store HTML too, a second page cache in front of the first.
The one trap is that a cache serves what it stored and does not know you changed something. A redirect served once can be cached at Cloudflare and keep being served after you remove it at the host. A browser that receives a 301 remembers it and never asks the old address again, so your own laptop keeps going to the old destination after the fix. An old version of a page, with the old title or an old noindex instruction, stays in the edge cache for as long as its rule allows. The fix for all three is a purge: in the Cloudflare dashboard, under Caching and then Configuration, Purge Everything clears the whole site's copies and Custom Purge clears named URLs. Development Mode, on the same screen, bypasses the cache for three hours and is the switch to turn on before a launch or a redirect test. A page cache plugin has its own purge button; purge the plugin first, then Cloudflare.
Test every redirect and every changed page in a private browser window or with curl.exe from PowerShell, because a normal window answers from its own memory. A redirect that looks wrong in your browser and right in curl is a browser cache; one that looks wrong in both is still cached at Cloudflare or still wrong at the host.
8Core Web Vitals
Core Web Vitals are the three measurements Google takes of a page as a real visitor experiences it, and the ones its documentation names as used in ranking. Each has a published threshold, and a page passes when the 75th percentile of its visits, meaning three visitors in four, meets all three. The thresholds are LCP of 2.5 seconds or less, INP of 200 milliseconds or less, and CLS of 0.1 or less, from web.dev's Core Web Vitals page cited in Sources. INP replaced an earlier metric, First Input Delay (FID), in March 2024; any guide that lists FID is out of date.
- LCP
- INP
- Layout shifts (CLS)
Largest Contentful Paint (LCP) is the time from the request until the largest image or block of text on the first screen has been drawn. On the managed IT page that is almost certainly the hero image, so LCP is TTFB from section 2 plus the time to find, download and draw that one image from section 6. A slow host, a lazy-loaded hero or a 4 MB photograph each pushes it past 2.5 seconds on their own.
Interaction to Next Paint (INP) is the time from a visitor's tap, click or key press to the moment the screen shows a response, measured for every interaction in the visit and reported as the slowest one. Tapping the menu icon on the Hermetic homepage and waiting for the menu to appear is an interaction; so is tapping into the contact form's first field. The wait is long when the browser's one working thread is still busy running the builder and plugin scripts from section 5, so the tap queues behind them.
Cumulative Layout Shift (CLS) is a score, with no unit, for how much visible content moved unexpectedly while the page loaded, summed over the visit. A cookie bar that pushes the page down, a hero image with no width and height set so text jumps when it arrives, a web font that replaces the fallback with a wider one, and a Popup Maker window that opens and closes all add to it. The visitor's version of CLS is tapping "Schedule a call" and hitting the button that moved into its place.
Field data and lab data
PageSpeed Insights shows two kinds of result for the same URL, and they often disagree. Field data, at the top under "Discover what your real users are experiencing", comes from the Chrome User Experience Report (CrUX): measurements Chrome collected from real visitors to that page over the previous 28 days, reported at the 75th percentile. This is the data Google ranks on. A page with few Chrome visitors shows "no data", which is likely for several Hermetic pages and is itself a finding to write down. Lab data, further down under "Diagnose performance issues", is one simulated visit by Google's Lighthouse tool on a throttled connection and a simulated phone, with the 0 to 100 performance score and the named audits used in sections 2 and 5. Lab data cannot measure INP because nobody taps during a simulation; it reports Total Blocking Time as a stand-in. The performance score is a diagnostic, and Google does not rank on it.
Search Console, once a property exists for the site, carries a Core Web Vitals report under Experience, separately for mobile and desktop, grouping URLs as Good, Needs improvement or Poor from the same CrUX data. It needs enough visitors to show anything, so it may be empty for Hermetic at first. The Rank Math course connects Search Console; this report is the one to open each month after that.
9Mobile layout
Mobile-first indexing means Google crawls and indexes the site with its smartphone crawler, so the version of each page that a phone receives is the version in Google's index. Google's documentation says this now applies to all sites. A heading that appears on the desktop layout and is hidden on the phone layout by a builder setting is still in the HTML and Google still reads it, but a visitor on a phone cannot, and Google's guidance asks that the two versions carry the same content for exactly that reason. A page element that exists only in the desktop markup, such as a separate desktop-only menu holding the links to the service pages, is a link Google may never follow.
Google retired its standalone Mobile-Friendly Test tool, so the check is now two things: the mobile run in PageSpeed Insights, which is the default tab, and a real phone in your hand. Open the homepage and the managed IT page on your phone and look for three things.
Tap targets
Buttons and links sized and spaced so a thumb hits the one intended. Two links one line apart in small text fail; a menu item with padding passes. The Lighthouse accessibility audit "Touch targets have sufficient size and spacing" names the offenders.
Hidden content
Compare the phone to the laptop side by side. Every service in the menu, the phone number, the address and the main text of the page should be reachable on the phone. Content in an accordion the visitor can open is fine; content removed by a "hide on small devices" setting is a gap.
Pop-ups
Google's page experience guidance names intrusive interstitials, pop-ups that cover the page on arrival, as a thing to avoid. The crawl found Popup Maker running on the site. A cookie notice that takes a strip at the bottom is acceptable; a full-screen offer on the first view is the pattern Google describes.
Also check that the text is readable without pinching, that nothing scrolls sideways, and that the layout does not jump when the page loads. Each of those is a line on the phone-check list in Do this now, and anything that fails is a builder setting on that page rather than a plugin setting.
10Staging sites and temporary redirects
A staging site is a copy of the live site at another address, such as a staging. subdomain or a URL the host provides, where changes are built and tested before they go live. The Rank Math course tests the redirect map on one before launch. The risk is that Google finds it: a staging copy is 139 pages of duplicate content at a second hostname, and if it is indexed Google has to choose between the copy and the original. A staging site is hidden in one of two ways. Password protection at the host, so that every request gets a login prompt before any page is served, is the stronger one, because a crawler cannot read a page it cannot open. The other is WordPress's switch under Settings and then Reading, "Discourage search engines from indexing this site", which adds a noindex instruction to every page. Blocking the site in robots.txt alone is the choice that fails: Google's documentation says a robots.txt block stops crawling, a URL linked from somewhere can still be indexed without its content, and a noindex instruction cannot be read on a page Google is forbidden to fetch.
The same logic explains why gated content hurts a live page. A service page whose text sits behind a form or a login is invisible to Google in the way the staging site is meant to be. A lead-capture form for a downloadable checklist is fine as long as the page around it says enough on its own to rank.
The staging switch has a twin trap at launch. When a staging copy is pushed to live, the Discourage setting can travel with it, and the live site then tells Google to drop every page. The pre-launch check has a line for it.
Temporary redirects
The status codes primer covered 301 and 302. A 302 says the move is temporary and the original address is coming back, so Google keeps the old address in its index and leaves the page's standing there. A 301 says the move is permanent, so Google updates its index to the new address and carries the standing over. The failure here is a 302 that was meant to be a 301 and was left in place for months: the old address stays in the index, the new page inherits nothing, and nobody notices because visitors arrive either way. Google's documentation says it may eventually treat a long-lived temporary redirect as permanent, and you do not control when. Two places produce accidental 302s on a small business site: domain forwarding at a registrar, which often defaults to a temporary redirect, and redirect tools that list 302 first in a dropdown. Every redirect the site makes on purpose is a 301, and the four-hostname check in the next section confirms the ones that matter most.
The pre-launch check
Before any staging copy goes live, and again on the live site in the first hour, confirm these in writing.
Pre-launch check
- 1Settings, Reading: "Discourage search engines" is unchecked on the live site.
- 2Settings, General: both address fields read
https://www.hermeticnetworks.com. - 3The four hostnames: three answer 301 straight to the fourth, which answers 200.
- 4Settings, Permalinks: Post name, and unchanged from before the launch.
- 5Every redirect in the inventory answers 301, none 302, tested in a private window or curl.
- 6The page cache plugin and Cloudflare are purged, in that order, after the switch.
- 7PageSpeed Insights run on the homepage and the managed IT page, results written next to the pre-launch figures.
- 8The staging address itself is still password protected or noindexed after launch.
11Do this now
- Open pagespeed.web.dev and run
https://www.hermeticnetworks.com/. On the Mobile tab, record whether field data exists and, if it does, the LCP, INP and CLS values and whether each passes. Record the lab performance score, the "Reduce initial server response time" value, and the top three entries under "Reduce unused CSS" and "Reduce unused JavaScript". Take a screenshot. Switch to the Desktop tab and record the same. Put all of it in a sheet named Speed record with the date in the first column. - Run the managed IT services page the same way, mobile and desktop. Use the URL the page map kept, or
/managed-services/if that decision has not been made. Record the same fields and whether the audit "Largest Contentful Paint image was lazily loaded" appears. - Open PowerShell and run
curl.exe -I http://hermeticnetworks.com/. Write down the first line (the status) and the Location line. Repeat forhttp://www.hermeticnetworks.com/,https://hermeticnetworks.com/andhttps://www.hermeticnetworks.com/. The first three should each show 301 and a Location ofhttps://www.hermeticnetworks.com/; the fourth should show 200. If Cloudflare answers with a challenge page instead, do the same four in a private browser window and record where the address bar ends up. Any 302, any chain of two hops, or any address that lands somewhere else goes into the record as a fault to fix. - In WordPress, open Settings and then General and record the WordPress Address and Site Address fields exactly as written. Then open Settings and then Permalinks and record the selected structure. Do not change either screen today. If the structure is anything other than Post name, add a line to the redirect job in the plugin course and note it in the Speed record.
- On your phone, open the homepage and the managed IT page. Write a list: what appeared over the page on arrival, whether the service links are all reachable from the menu, whether any text needed pinching, whether anything scrolled sideways, and whether the layout jumped while loading. Note which page each item is on.
- Find out, and write into the record, the hosting company and plan, whether the plan includes a page cache or a cache plugin is installed, who holds the Cloudflare login and what the SSL/TLS mode is, and whether a staging site exists and how it is hidden. Write "not known yet" against anything you cannot answer today, with the name of the person who can.
12Review questions
-
Answer
Google ranks on the field data, the CrUX measurements from real visitors at the 75th percentile, and those pass. The 45 is one simulated visit on a throttled connection and is a diagnostic. Record both figures and use the audits under the 45 to find the heaviest files and images for the backlog.
-
Answer
The visitor and Google both arrive at the canonical address, so it works. It is a chain of two hops; each hop is a round trip before the page starts loading, and a chain breaks if either rule changes. Set the rule so each alternate goes to the www https address in one hop, then re-test all four.
-
Answer
Your browser cached the 301 and is answering from memory, or Cloudflare cached the redirect at its edge. Test in a private window or with curl.exe: if that shows the fix, it was the browser. If curl still shows the old redirect, purge the URL at Cloudflare (Caching, Configuration, Custom Purge) and test again. If it persists after the purge, the host has not applied the change.
-
Answer
All 148 post addresses change at once, and every link from other sites, from Google's index and from old emails points at an address that no longer exists. WordPress redirects some of them by recognizing the slug, and nobody can tell which without testing. The change is right; the way to make it is as a redirect job: build the old-to-new list in the redirect inventory, make the change, test the rows, and watch the 404 log, as the Rank Math course's module 09 describes.
-
Answer
All three. LCP, because the largest first-screen element is the first slide and it arrives after the slider script loads, often lazily; INP, because the slider script keeps the browser's working thread busy so a tap on the menu waits; and CLS, because slides moving and resizing under the visitor count as layout shifts. One static image and a headline remove all three costs.
-
Answer
It is exposed. A robots.txt block stops Google from fetching the pages, and a URL linked from anywhere can still be indexed with no content shown. A noindex instruction on the pages cannot be read because Google is forbidden to fetch them. Password-protect the staging site at the host, or allow crawling and use the Discourage setting so the noindex is read, and confirm that setting is off on the live site at launch.
13Glossary
- Time to first byte (TTFB)
- The time from the browser's request to the first byte of the server's answer, including DNS, connection setup and the server's work building the page.
- Canonical hostname
- The one address Google treats as the original for the site. For Hermetic, https://www.hermeticnetworks.com/, with the other three versions redirecting to it with a 301.
- Permalink structure
- The rule under Settings, Permalinks that builds post addresses. Post name produces /slug/. Changing it on a live site changes every post address at once.
- Page builder
- A plugin that lays out pages from modules by dragging. The site uses Beaver Builder. Each module adds markup, styles and often scripts to the page.
- Lazy loading
- Delaying an image's download until the visitor scrolls near it. Built into WordPress since 5.5. Harmful when applied to the first-screen image.
- Page cache
- A stored copy of a page's finished HTML, served to later visitors without rebuilding it. Lives at the host or in a plugin.
- Content delivery network (CDN)
- Servers in front of the site that keep copies of its files near visitors and answer for it. Cloudflare is the site's CDN.
- Cache purge
- Clearing stored copies so the next request fetches the current version. Done in the cache plugin first, then at Cloudflare under Caching, Configuration.
- Largest Contentful Paint (LCP)
- Time from the request until the largest first-screen image or text block is drawn. Good: 2.5 seconds or less.
- Interaction to Next Paint (INP)
- The slowest wait from a visitor's tap or click to the screen responding, over the whole visit. Good: 200 milliseconds or less. Replaced First Input Delay in March 2024.
- Cumulative Layout Shift (CLS)
- A unitless score for how much content moved unexpectedly while loading, summed over the visit. Good: 0.1 or less.
- Field data and lab data
- Field data is measured from real Chrome visitors over 28 days (CrUX) and is what Google ranks on. Lab data is one simulated visit by Lighthouse, used for diagnosis.
- Mobile-first indexing
- Google crawls and indexes with its smartphone crawler, so the phone version of a page is the one in the index.
- Staging site
- A copy of the site at another address for building and testing. Hidden from Google by password protection or a noindex setting, never by robots.txt alone.
14Sources
- Google Search Central, Understanding page experience in Google Search results: page experience signals, Core Web Vitals, HTTPS, interstitials, and the statement that relevance still comes first.
- Google Search Central, Understanding Core Web Vitals and Google search results: the three metrics and how they are used.
- web.dev, Web Vitals: the thresholds LCP 2.5 s, INP 200 ms, CLS 0.1, judged at the 75th percentile; INP replaced FID in March 2024. Read 2026-10-01.
- web.dev, Time to First Byte (TTFB): definition and the published 0.8 second guide. Read 2026-10-01.
- Google, PageSpeed Insights: field data from CrUX and lab data from Lighthouse for a URL.
- Google Search Console Help, Core Web Vitals report: the Good, Needs improvement and Poor groupings by mobile and desktop.
- Google Search Central, Mobile-first indexing best practices: the smartphone crawler, and keeping phone and desktop content the same.
- Google Search Central, How to specify a canonical with rel="canonical" and other methods: why four hostnames are duplicates and how a 301 consolidates them.
- Google Search Central, Redirects and Google Search: permanent and temporary redirects and how Google treats each.
- Google Search Central, Block Search indexing with noindex: noindex requires the page to be crawlable; a robots.txt block alone does not keep a URL out of the index.
- Google Search Central, URL structure best practices: simple, readable words in the address.
- WordPress.org, Customize Permalinks: the structures and the Category and Tag base fields.
- WordPress.org, HTTPS for WordPress: the WordPress Address and Site Address fields and moving a site to HTTPS.
- Cloudflare, Purge cache and Default cache behavior: what is cached by default and how to purge by URL or everything.
- Stephan Spencer, Eric Enge and Jessie Stricchiola, The Art of SEO, 4th edition (O'Reilly, early release 2021), chapters 3 and 5.
- Site facts from a crawl of www.hermeticnetworks.com on 2026-09-29: Cloudflare in front of the site, the Beaver Builder theme and builder, Popup Maker, the canonical address declared on the homepage, 139 pages and 148 posts in the sitemaps, 84 tag and 18 category archives.
Documentation read 2026-10-01. Google changes often; where this page and the documentation disagree, the documentation is current.