Tsoden
Public audit for bomly.dev

Fast revenue-leak triage

bomly.dev is 4 fixes away from more trial signups.

The site is usable but probably leaking qualified visitors because important buyer and machine-readable signals are incomplete.

Read from 5 live pages · metadata, crawlability, trust, CTA, schema, sitemap, robots, llms.txt

Questions about this audit? Reply to the email or write to us — a human answers same day.

4 fixable leaks6/8 selling signals live9/13 checks passed

The complete, prioritized plan to fix all 4 leaks above and win more trial signups — written for bomly.dev, delivered instantly.

What buyers and AI/search engines see right now

Pages checked55 read in full
How we read itRead as crawlers doSame view buyers & bots get
Response time3488msSlower than the 2.5s target
Checks verified9/134 need fixing

Diagnostics

Full technical analysis

36 checks across six areas — search visibility, AI & answer engines, performance, security, conversion and trust — each measured against bomly.dev's live site.

23 pass 7 warn 6 fail

Findability

10/10 pass · 81/100
Page title
9 chars
Warning
Meta description
187 chars
Warning
Single H1 heading
present (5/5 pages)
Pass
Heading structure (H1–H3)
H1:1 H2:10 H3:28
Pass
Canonical tag
present
Pass
Indexable by search
indexable
Pass
Mobile viewport
set
Pass
Language declared
en
Pass
Image alt text
0/1 missing alt
Pass
Content depth
1,584 words
Pass
XML sitemap
found
Pass
robots.txt
found
Pass

AI & Answer Engines

4/5 pass · 89/100
Structured data (Schema.org)
website, softwareapplication
Pass
FAQ / Q&A schema
missing
Issue
Open Graph (social preview)
4/4 tags
Pass
Twitter / X card
present
Pass
llms.txt (AI summary)
found
Pass

Performance

2/4 pass · 33/100
Server response time
3,488 ms
Issue
HTML page weight
150.7 KB
Warning
Compression (gzip/brotli)
enabled
Pass
Render-blocking scripts
1 blocking / 43 scripts
Issue
Browser caching
cache-control set
Pass

Security

2/2 pass · 54/100
HTTPS / SSL
enabled
Pass
HSTS
missing
Warning
Content-Security-Policy
missing
Warning
X-Content-Type-Options
missing
Warning
Clickjacking protection
missing
Warning
No mixed content
clean
Pass

Conversion

2/4 pass · 55/100
Clear value proposition
found: “Bomly CLI Analyze Your Software DNA.”
Pass
Primary call-to-action
found: “Get started”
Pass
Easy contact / booking
not found
Issue
Visible pricing signal
not found
Issue

Trust

3/4 pass · 86/100
Social proof
found: “review”
Pass
Risk reversal
found: “guarantee”
Pass
Legal / privacy pages
privacy
Pass
Analytics installed
none detected
Issue

Priorities

Top Leaks To Fix First

Ranked by revenue impact. Each one is something users — or an AI answer engine — need to see and currently can't. Fixing the top few moves your score the most.

01

Pricing or buying signal

Show pricing or a "from…" anchor so users can self-qualify before they reach out.

02

Contact or booking path

Make it easy to start a free trial from the homepage — a visible form, booking link, or tap-to-call number.

03

Clear page title

Put what you do (and where) in the page title so your search result wins the click from users.

04

Fast initial response

Speed up the homepage — most users arrive on a phone, and a slow first load loses them before the page shows.

Conversion evidence

How The Page Sells

6 of 8 of the buying-decision signals we could verify are on your site today. The page already shows 6 of 8 buying-decision elements. The remaining lift is in sharpening the ones that are missing, not rebuilding the page.

Below is the breakdown: what's already working (with the exact text quoted from your page as proof), and the highest-impact additions to win more trial signups — in priority order.

Scope: an automated scan of the 5 pages we could read across your site. Every “found” item quotes the exact text on your page so you can verify it. It doesn't judge copy quality or design.

Selling well (detected, with proof)

  • Clear value proposition (headline) — found: “Bomly CLI Analyze Your Software DNA.”
  • Action-oriented primary CTA — found: “Get started”
  • Social proof (testimonial / customers / rating) — found: “review” (on /faq)
  • Specific, quantified result — found: “11 Star”
  • Risk reversal (trial / guarantee / no card) — found: “guarantee” (on /faq)
  • Objection handling (FAQ) — found: “FAQ”

Highest-impact additions to sell more

  • Visible pricing / 'starting at' anchor — Show pricing or a 'starting at' anchor so buyers can self-qualify without emailing.
  • Easy lead-capture path — Give an easy capture path: short form, booking link, or contact route from the first screen.

Deliverable

Your complete fix pack is ready

We've already done the full work-up for bomly.dev — every fix written out, with copy and code ready to paste. Here's what's inside:

Complete fix plan (every issue, step by step)

1. Pricing or buying signal

Show pricing or a "from…" anchor so users can self-qualify before they reach out.

  1. Show pricing, packages, or a 'from …' anchor so buyers can self-qualify.
  2. If pricing is bespoke, give a starting price or a typical range.
  3. Pair each price with what's included so it reads as value, not cost.

2. Contact or booking path

Make it easy to start a free trial from the homepage — a visible form, booking link, or tap-to-call number.

  1. Add a visible booking link, short form, or tap-to-call number on the first screen.
  2. Keep the form to 3 fields max; every extra field drops completion.
  3. Confirm submissions with a clear success state, not a silent reload.

3. Clear page title

Put what you do (and where) in the page title so your search result wins the click from users.

  1. Write a 50–60 character <title> in the format: Primary outcome for [audience] — [Brand].
  2. Put the most-searched term first; keep the brand at the end.
  3. Make every important page's title unique — never reuse the homepage title.

4. Fast initial response

Speed up the homepage — most users arrive on a phone, and a slow first load loses them before the page shows.

  1. Compress and lazy-load images; serve modern formats (WebP/AVIF).
  2. Put the site behind a CDN and enable caching of static assets.
  3. Defer non-critical JavaScript so the first screen paints fast.

Done-for-you assets — copy & paste

SEO title
Where to paste: Replace the <title> tag inside your page <head>.
Bomly CLI - Analyze Software Dependencies
Meta description
Where to paste: In <head>, set <meta name="description" content="…"> to this (replace the old one).
Bomly CLI scans projects and SBOMs to identify vulnerabilities and dependencies. Start analyzing your software today!
H1 — main page heading
Where to paste: Make this the single <h1> at the top of the homepage (real text, not an image).
Unlock the Secrets of Your Software Dependencies with Bomly CLI

— or one of these —
- Discover Vulnerabilities in Your Software Stack
- Get Complete Visibility into Your Software Bill of Materials
Primary CTA button
Where to paste: Use as the main button above the fold; repeat it after your proof/services section.
Get Started
JSON-LD structured data (Organization)
Where to paste: Paste this entire block right before </head> (or before </body>).
<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "Organization",
  "name": "bomly.dev",
  "url": "https://bomly.dev/",
  "description": "Bomly CLI is an open-source tool that analyzes software dependencies and vulnerabilities across multiple ecosystems.",
  "makesOffer": [
    {
      "@type": "Offer",
      "itemOffered": {
        "@type": "Service",
        "name": "Dependency scanning for projects and SBOMs"
      }
    },
    {
      "@type": "Offer",
      "itemOffered": {
        "@type": "Service",
        "name": "Vulnerability and license data analysis"
      }
    },
    {
      "@type": "Offer",
      "itemOffered": {
        "@type": "Service",
        "name": "Interactive dependency graph navigation"
      }
    },
    {
      "@type": "Offer",
      "itemOffered": {
        "@type": "Service",
        "name": "Integration with CI/CD pipelines"
      }
    },
    {
      "@type": "Offer",
      "itemOffered": {
        "@type": "Service",
        "name": "Support for multiple ecosystems and container images"
      }
    }
  ]
}
</script>

Page-by-page findings

PageWhat to fix
/looks healthy
/docs/detectorslooks healthy
/faqlooks healthy
/clilooks healthy
/guardlooks healthy

Action order

48-Hour Fix Plan

  • Show pricing or a "from…" anchor so users can self-qualify before they reach out.
  • Make it easy to start a free trial from the homepage — a visible form, booking link, or tap-to-call number.
  • Put what you do (and where) in the page title so your search result wins the click from users.
  • Speed up the homepage — most users arrive on a phone, and a slow first load loses them before the page shows.

Why it matters

The fastest users do not read every page. They scan the first screen, trust signals, pricing cues and how easy it is to start a free trial. Missing signals make the offer harder to understand and easier to ignore.

Packages

Turn this into more trial signups

You've seen the leaks. Most owners start with the €49 full report — the same fixes we'd implement for €199, written out so you can do them yourself. Want it hands-off? Step up a tier.

Do it yourselfFree

The complete evidence report and the prioritized, step-by-step plan for bomly.dev — every fix written out with copy & code ready to paste. It is on this page. Nothing to buy, nothing to unlock.

Read the full plan ↑
Done-for-you — 48h€199

We implement the highest-impact fixes for bomly.dev — metadata, schema, CTA, llms.txt, trust signals — in 48 hours. You keep every bit of the lift, no lock-in.

Have us do it — €199
Ongoing monitor€499/mo

Weekly re-checks of bomly.dev + drift alerts so the fixes compound and never silently slip back.

Start monitoring

Not sure which fits? Book a free 30-min call and we'll tell you straight. · 48-hour turnaround · no lock-in · every claim verified.

Verification

Evidence Snapshot

Every signal below was read from your live site — nothing is estimated. We checked 5 pages; “couldn’t verify” means a signal needs JavaScript to read and we won’t guess.

What we read

TitleBomly CLI
Meta description187 chars
H1 heading Found 5/5
Structured data Found

Crawl & AI files

robots.txt Found
sitemap.xml Found
llms.txt (AI) Found
Response time3488ms

Pages we checked

/
Bomly CLI
Read
/docs/detectors
Detectors — Bomly Docs
Read
/faq
FAQ
Read
/cli
Bomly CLI
Read
/guard
Bomly Guard
Read

Vragen over de bevindingen? Reply to the email, or reach us directly — we answer same day.

Who we are

Tsoden — a full-service web studio

We don't just audit — we build and rank websites end-to-end. Web development & design, plus SEO & AEO, so your business shows up in Google and in AI answers like ChatGPT, Perplexity and Gemini. This report is where we start; we can implement every fix below and grow your visibility on a full-service basis.

Web development & redesign — fast, conversion-first sites
SEO — rank in Google for what your buyers actually search
AEO — get found & cited by AI answer engines (ChatGPT, Perplexity, Gemini)
Ongoing monitoring & growth — we keep it improving
Work with Tsoden →or email support@tsoden.ai

Curious how a competitor scores?

Run the same free check on any site — the same buying signals, the same evidence quoted from the page itself. About a minute, no email needed to see the result.

Disclaimer

This service is a marketing and informational tool based on public website signals. It is not legal, financial, tax, investment, security, or professional advice. Scores and recommendations are estimates, not guarantees of revenue, rankings, AI visibility, deliverability, or business outcomes. You remain responsible for reviewing, approving, and implementing any changes and for complying with laws that apply to your business.

Full disclaimer · Terms · Privacy

This audit is from 1 Aug 2026 — we re-run it fresh when you order bomly.dev · Grade C · 65/100