Phil Moore Studio

Prepared by Phil Moore Studio

LongevityX Pre-Launch Site Audit

  • Prepared forWilliam Bosch
  • Sitelongevity-x.com
  • Date8 July 2026

Billy, I spent the past few days going through the new site properly: on the live pages, and against the code behind them.

Here’s the short version. This is a good site. The writing is strong, the palette holds together across eight separately built pages, and it’s a long way ahead of most first solo builds I see, agency or otherwise. I wouldn’t say that if it weren’t true.

But there are a handful of things underneath the surface worth sorting before you send any real traffic at it, paid or otherwise. Two of them I can’t check myself, since I don’t have your Netlify login, so those come first below as a quick five minute check on your end. Everything else is grouped by how urgent it is: what to fix before traffic, what’s worth fixing soon, and what’s just polish once the bigger items are settled.

One thing worth knowing before any of this

Right now, your live site and the code in your repo aren’t a clean match of each other. The live version has been reformatted, and has a Meta Pixel injected into it that exists in no version of the source code. The repo, in turn, has a lead webhook and form settings that aren’t on the live site. So the obvious move, just redeploy from the code, would swap one set of problems for a different set. Whoever touches the deploy next needs to reconcile the two first. I’ve kept that in mind in everything below.

Check now · 5 minutes

What I’d love you to check on Netlify

These two are the highest stakes items in this whole report, and they only take a few minutes to confirm. I’d love you to check both before we do anything else with the site.

1. Confirm your forms are actually capturing leads

Here’s what I found from the outside. When someone submits a form on the live site, it shows a “thanks, we got it” message no matter what actually happened underneath, it never checks whether Netlify accepted the submission. A direct test against the live server, using the real form name the site sends, came back “not found,” which is the classic signature of a Netlify form that was never registered at build time. The code in your repo is set up correctly, but the version that’s actually live looks like Netlify never detected the forms on it.

The check: open Netlify, click into the longevity‑x site, then Forms in the left sidebar. You should see five form names listed: contact, apply, health‑assessment, bloodtest‑waitlist, and vault‑unlock, each with recent submissions landing under it. If any are missing, or the tab is empty, every lead since launch may have gone nowhere, and this becomes the first thing to fix.

While you’re in there, it’s worth turning on a Netlify email notification to your inbox for at least the Apply form, so a lead is never silently dropped again.

2. Confirm whether a Meta Pixel was added in the Netlify dashboard

A Facebook and Meta tracking pixel is firing on every page of the live site right now, including the health assessment quiz and the blood panel page. It loads the moment the page opens, before anyone agrees to anything, and on the quiz it goes further: it sends Meta a custom event carrying the program recommendation the quiz produced. There’s no cookie or consent banner anywhere on the site.

The check: in Netlify, go to Site configuration → Build & deploy → Post processing → Snippet injection. This pixel isn’t anywhere in your source code, which means it was added directly through that dashboard setting, not through the codebase. It won’t show up if anyone, including me, reviews the code, so it’s worth confirming it’s there and whether you added it on purpose.

If you did add it and want to keep it, it needs a consent banner in front of it, and it should come off the health pages, or at least stop sending health related data. If you didn’t knowingly add it, that’s worth knowing too, and it should probably come out.

Before you drive any traffic

These three are the ones I’d genuinely hold traffic for. None of them are big rebuilds, but each one either loses you leads, exposes you to risk, or blocks a business system you’re relying on.

Before traffic

Your lead forms may not be capturing anything

This is the item from the Netlify check above, and it’s first on this list for a reason: the evidence points to submissions landing nowhere, while visitors see a success message regardless. Affected forms: Apply, the one minute assessment, the blood test waitlist, the Vault email gate, and the homepage contact form. That’s the entire lead capture surface of the business, so it’s worth confirming before anything else moves forward.

Before traffic

The Meta Pixel needs a decision, then a consent gate

On a health site, sending a quiz’s health related recommendation to an ad platform is exactly the pattern behind a recent wave of US healthcare pixel lawsuits and regulator action. I’m flagging this because it’s worth a quick check with your side before launch, not because I’m offering legal advice, I’m not a lawyer. There’s also no mention of Meta, Facebook, or its cookies anywhere in your privacy policy right now, so the site is tracking people with a tool it doesn’t disclose.

Once you’ve confirmed whether it’s there on purpose (see the Netlify check above), the fix itself is straightforward: gate it behind consent, keep it off the health pages, and add it to the privacy policy.

Before traffic

The SMS opt-in is missing on your forms, which will get your text campaign rejected

Good news first, since this was the specific thing I went in to check: the required A2P privacy policy clause survived the rebuild, word for word. The “Required Disclosure, Mobile Information Sharing” language is intact on your live privacy policy. Don’t touch it.

The gap is on the forms themselves, and carriers check the actual form when they approve a text campaign. The Apply form asks for a phone number but has no SMS consent checkbox, no opt in language, no message frequency or rates text, and no STOP or HELP near the submit button. The Blood Test page has partial language but is still missing the checkbox and STOP or HELP. And no form links to your Privacy Policy or Terms next to its submit button, those links currently only live in the homepage footer.

Without an unchecked consent checkbox, explicit opt in wording, “Msg and data rates may apply,” a stated message frequency, STOP and HELP, and Privacy plus Terms links beside each submit button, the SMS campaign will get rejected and your texts won’t send. That was the whole point of the original A2P work, so it’s worth closing this loop.

Worth fixing soon

None of these need to happen before you turn traffic on, but each one is either quietly costing you rankings or leads right now, or it’s worth a conversation before it becomes a bigger problem.

Worth fixing soon

The move off Framer left some SEO loose ends

Four old URLs from the Framer site now return “not found” with no redirect, and each was live and indexed as recently as mid March. Worth a redirect to the nearest new page for each, before the ranking they built up gets forfeited. It’s free to fix, and most valuable while it’s still fresh.

See the fuller SEO list
  • The four missing redirects: /lx90, /retreat, /contact, and /alcoholfree.
  • Your Netlify preview URL is a byte identical copy of the whole site and it’s fully indexable right now, which is a duplicate content risk. It should redirect to the real domain or be set to no index.
  • Every canonical and SEO signal on the site points at the www version of your domain, but that address redirects straight back to the non‑www version. Worth pointing everything at the address that actually serves the page.
  • Only the homepage currently has a canonical tag, the other seven pages don’t, and a few pages are reachable at two URLs at once (/apply and /apply.html both load). One canonical URL per page closes that gap.
  • There’s no structured data anywhere on the site. Adding Organization, Person, Service, and FAQ markup would help both Google’s rich results and how AI assistants like ChatGPT and Perplexity describe your business when someone asks about it.
Worth fixing soon

The blood test and Vault promises don’t quite match what happens next

The $299 blood test is shown as a buyable price five separate times on the site, but the button underneath it lands on a waitlist, and that’s never labelled before the click. It’s worth either making it purchasable, or relabelling every “Start With a Blood Test” button so it says what actually happens next. Right now it’s the entry point of your whole offer ladder, and it ends in a wall at the exact moment someone is most interested.

The Vault lead magnet has a couple of small leaks too: three of the guides are already free and ungated on the homepage, so they bypass your email capture entirely. The page promises “we’ll email you a copy too” but there’s no delivery email actually built for that. And the follow up email sequence’s only call to action points at a subdomain that doesn’t resolve.

Worth fixing soon

A few things worth a quick check with your side before launch

A single PSA marker on the site sits under a heading that reads “Cancer Screening,” which implies a screening service that isn’t really what’s being offered. There are also a couple of phrases worth a second look: “a complete picture of your health” (no single blood panel really is), and the “MD‑Reviewed” claim, which is stated plainly on one page and hedged to “medical review where applicable” on another. A couple of the lead magnet titles read more like medical claims than marketing too, things like “burn more fat while you sleep.”

The Terms page is worth a closer look as well. Right now it’s essentially a no refund policy rather than a full terms of service, and it includes a clause stating that disputing a charge is itself a breach of contract. A clause that tries to waive someone’s right to dispute a charge with their card issuer generally doesn’t hold up, and it’s the kind of thing card networks flag. I’d genuinely get this one in front of your counsel before you start charging cards through it. It also means your privacy policy’s line pointing to “our Terms for full SMS terms” currently points at a page with no SMS terms on it.

Worth fixing soon

The site currently fails a WCAG 2.2 AA accessibility check

One thing here is more than cosmetic: when someone submits a form, the button disappears and a confirmation panel appears, but nothing announces that to a screen reader. A blind visitor genuinely can’t tell whether their application went through. That’s the one I’d prioritise.

See the fuller accessibility list
  • No “skip to content” link on any page.
  • The homepage FAQ, including pricing, sits inside the footer landmark, where screen readers usually skip past it.
  • The FAQ accordion and the mobile menu button don’t announce whether they’re open or closed.
  • No autocomplete attribute on any form field. Cheap fix, one attribute each.
  • The Apply form’s message box has no label.
  • A handful of contrast misses: the error text, the footer legal line, form input borders (hard to see the field edge if you have low vision), and the gold gradient on the results stats.

The good news: the whole list is about three hours of additive fixes on a genuinely solid base, not a rebuild.

Worth fixing soon

Two small security items worth closing before a full redeploy

Your repo, not the live site, has a live GoHighLevel webhook URL hardcoded into the page’s JavaScript. It’s unauthenticated, so anyone who views the page source could push fake leads into your CRM. It isn’t on the live site today, but if the repo gets deployed as is, it becomes public. Worth treating that webhook as compromised, regenerating it, and moving the lead flow server side.

There’s also no Content Security Policy on the site. The basic security headers are there, and Netlify adds HSTS automatically, but a CSP is worth adding once the Meta Pixel decision above is settled, since a CSP is part of what would have stopped that pixel loading unchallenged in the first place.

Polish, once the above is done

None of this is urgent. It’s the kind of polish worth doing once the list above is handled, mostly design consistency and performance.

Polish

Responsive text sizing has a real bug on phones

Every one of the 22 fluid text sizes on the site has already hit its minimum size on phone width screens, so none of them are actually scaling anymore, and one homepage heading actually gets bigger as the screen gets smaller, which is a genuine bug, visible right around 640px width. The logo can also run past the edge of the screen at 320px width. Worth a dedicated pass.

Polish

The design has drifted a little page to page

Because each page was styled in its own session, small inconsistencies have crept in: buttons change weight and height between pages, the nav bar changes height by close to 30px page to page so the page visibly jumps as you navigate, and the same text sizes get redefined up to four times across the file. The colour palette, though, is impressively consistent across all eight pages, genuinely well done there. This is really a “consolidate into one shared stylesheet” job, worth scoping separately.

Polish

Images are unoptimised

There’s about 1.3MB of raw JPEGs on the site with no WebP versions, and several without lazy loading. Worth compressing and converting given your audience skews 40 to 70 and is often on older devices and slower connections, page speed matters more for them than average.

Polish

A small brand nuance worth a conversation

Your logo wordmark is set in a high contrast Didone serif, the page headings are in a softer Fraunces serif, and the favicon is plain Georgia, so there are three different serif voices in play. The wordmark is genuinely the most premium asset on the site, and the current heading font undercuts it a little. Also worth knowing: the favicon is an SVG, and iOS ignores SVGs for home screen icons, so it needs a PNG version alongside it.

Genuinely working well

What’s already working well

This isn’t a bad build, not even close. For a first site, built solo with Claude Code, it’s well above most agency output I see, and that’s worth saying plainly.

  • The A2P privacy clause, the exact thing I went in to check first, survived the rebuild intact, word for word.
  • The writing carries the whole site. You’ve internalised a real narrative structure, and it shows.
  • The colour palette held perfectly consistent across eight separately built pages. That’s genuinely hard to do without a shared system, and you did it anyway.
  • The semantic HTML underneath is solid: real buttons, properly labelled form fields, one heading per page, honest image descriptions, correct zoom settings, and the right logo colour on light versus dark backgrounds. Most of the accessibility gaps above are additive fixes on top of a good foundation, not a rebuild.
  • The old desktop versus mobile link mismatch that used to trip up the Framer site is gone. The nav is a single shared block now, so that whole class of bug can’t happen anymore.

A few things only you can answer

A handful of these only you can answer, and they’ll shape what happens next.

  1. Is there a named, licensed physician under contract? The “MD‑Reviewed” claim depends entirely on this.
  2. Is the blood test actually launching, or is the waitlist meant to be the permanent state?
  3. Did you found Iconic Protein, or work with it? The founder stat block and the body copy currently say different things.
  4. Is Glyzen still engaged? Every automation spec in the build currently assigns the work to them.
  5. Has your counsel seen the Terms page yet, specifically the anti chargeback clause?
  6. Did you knowingly add the Meta Pixel, and is it something you actually want on the site?

That’s everything. None of this needs to happen at once, and a good chunk of it is genuinely quick. Let me know which of these you’d like the studio to take on first, whether that’s the Netlify check today, the forms and pixel work this week, or a scoped pass through the rest. I’m glad to help however makes sense for you.

Phil