
Cursor was tested and 161 issues were detected across the site. The most critical finding was: Unconsented third-party analytics loader request detected. Issues span Security, Performance, A11y, Other categories. Persona feedback rated Visual highest (7/10) and Accessibility lowest (5/10).







⚠️ POTENTIAL ISSUE: Tracking request detectedGET https://0ay7zb.cursor.com/analytics/loader-v1.js?key=6f091e8fd6f3c36209a1e08f140c7a4b334baea548f4702052f0732f8d577990 - Status: N/A[ERROR] Connecting to 'https://stats.g.doubleclick.net/g/collect?v=2&tid=G-5H6JBHFD7Z&cid=767046130.1774469730>m=45je63o0v9238630528z89237776711za20gzb9237776711zd9237776711&aip=1&dma=0&gcd=13l3l3l3l1l1&npa=0&frm=0&tag_exp=103116026~103200004~115938465~115938469~116024733~117266401~117484252' violates the following CSP directive: "connect-src 'self' cursor.com *.cursor.com cursor.sh *.cursor.sh unifyintent.com *.unifyintent.com *.cloudfront.net pro.ip-api.com *.liadm.com *.usbrowserspeed.com alocdn.com 9xgnrndqve.execute-api.us-west-2.amazonaws.com api.ashbyhq.com jobs.ashbyhq.com api.conceptualhq.com ip.conceptualhq.com *.facebook.com facebook.com featureassets.org prodregistryv2.org youtube.com *.youtube.com js.zi-scripts.com ws.zoominfo.com *.zoominfo.com *.chilipiper.com www.googletagmanager.com *.google-analytics.com analytics.google.com *.analytics.google.com *.roadwayai.com *.mux.com stream.mux.com inferred.litix.io". The action has been blocked.https://stats.g.doubleclick.net/g/collect?v=2&tid=G-5H6JBHFD7Z&cid=767046130.1774469730>m=45je63o0v9238630528z89237776711za20gzb9237776711zd9237776711&aip=1&dma=0&gcd=13l3l3l3l1l1&npa=0&frm=0&tag_exp=103116026~103200004~115938465~115938469~116024733~117266401~117484252[ERROR] Loading the image 'https://www.google.com/ccm/collect?frm=0&en=page_view&dl=https%3A%2F%2Fcursor.com%2F&scrsrc=www.googletagmanager.com&rnd=1519986609.1774469740&dt=Cursor%3A%20The%20best%20way%20to%20code%20with%20AI&auid=746754114.1774469730&navt=n&npa=0>m=45be63o0v9231728922za200zd9231728922xec&gcd=13l3l3l3l1l1&dma=0&tag_exp=103116026~103200004~115616985~115938465~115938469~116024733~117384405~117484252&apve=1&apvf=f&apvc=1&tids=AW-17332771332&tid=AW-17332771332&tft=1774469740262&tfd=712' violates the following Content Security Policy directive: "script-src 'self' 'unsafe-inline' 'unsafe-eval' cursor.com *.cursor.com cursor.sh *.cursor.sh *.unifyintent.com *.cloudfront.net pro.ip-api.com *.liadm.com *.usbrowserspeed.com alocdn.com va.vercel-scripts.com vercel.live jobs.ashbyhq.com os.ryo.lu connect.facebook.net js.zi-scripts.com ws-assets.zoominfo.com *.chilipiper.com www.googletagmanager.com *.googletagmanager.com *.roadwayai.com". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback. The action has been blocked.https://www.google.com/ccm/collect?frm=0&en=page_view&dl=https%3A%2F%2Fcursor.com%2F&scrsrc=www.googletagmanager.com&rnd=1519986609.1774469740&dt=Cursor%3A%20The%20best%20way%20to%20code%20with%20AI&auid=746754114.1774469730&navt=n&npa=0>m=45be63o0v9231728922za200zd9231728922xec&gcd=13l3l3l3l1l1&dma=0&tag_exp=103116026~103200004~115616985~115938465~115938469~116024733~117384405~117484252&apve=1&apvf=f&apvc=1&tids=AW-17332771332&tid=AW-17332771332&tft=1774469740262&tfd=712