Public audit / not a customer

Discover What the Audit Engine Found on canva.com

Nebula ran its evidence-backed audit on canva.com on August 5, 2026. Canva is not a Nebula customer. This page shows the raw output of the same engine every free scan uses - 5 findings, evidence included.

Score

5.7/10

Grade

C

Findings

5

Audited

August 5, 2026

Same engine, public URL

Disclosure: Canva did not request this audit and is not affiliated with Nebula Components. This teardown is published to demonstrate what the audit engine produces on a real, well-known page - not to imply any commercial relationship. All findings are evidence-backed; source, selector, and confidence are included per finding. Canva may update their page at any time; this reflects a snapshot taken August 5, 2026.

Page snapshot · August 5, 2026

canva.com
Canva landing page snapshot - August 5, 2026

Five Findings

Ranked by observable priority. Each finding includes the evidence Nebula used - no opinion, no estimation. Priority scores are rule-based heuristics for fix order, not predicted conversion loss.

Finding 1

Fallback Document Masks the Real Page

Priority 3/10Major Project

The served document is the "unsupported browser" fallback: title "Unsupported client – Canva" (26 chars, below the 120-char meta minimum applies to the 26-char description too), H1 "Please update your browser". Any non-JS client - crawlers, link unfurlers, assistive fetchers - receives an error page instead of the product story.

Evidence

title: "Unsupported client – Canva" (26 chars) | meta desc: 26 chars | h1: "Please update your browser" | h1 count: 1. Snapshot timestamp: 2026-08-05T00:56:29Z.

Recommended Fix

Serve a real, content-complete HTML document to all clients - H1, value proposition, and CTA in the initial HTML - and layer the interactive app on top. Progressive enhancement, not UA gating.

Finding 2

No Trust Signals

Priority 3.5/10Quick Win

No testimonials, reviews, or social proof anywhere in the served document - for a product whose entire growth story is user volume.

Evidence

Fetched source trust terms: none; recognized proof markers: none. Snapshot timestamp: 2026-08-05T00:56:29Z.

Recommended Fix

Add proof near the first CTA: user counts, customer quotes, or output samples in the static HTML.

Finding 3

No Structured Data

Priority 2/10Major Project

No JSON-LD structured data, no canonical URL, and only 3/5 OpenGraph tags populated. AI engines and unfurlers get almost nothing to cite.

Evidence

valid JSON-LD: 0/0 block(s) | OpenGraph: 3/5 non-empty tags | Canonical: absent. Snapshot timestamp: 2026-08-05T00:56:29Z.

Recommended Fix

Add Organization JSON-LD, complete the OpenGraph set, and set a canonical URL.

Finding 4

No Tracking Artifacts in Static Source

Priority 4/10Major Project

No recognized ad-tracking artifact observed in the fetched source at all - no GA4, no pixel, no UTM links, no conversion call.

Evidence

Static artifacts present: none. Not observed: Facebook Pixel initializer, GA4 initializer or measurement ID, UTM-bearing link, explicit conversion call. Snapshot timestamp: 2026-08-05T00:56:29Z.

Recommended Fix

Confirm the real page's tracking path via consent-aware network validation; the fallback document carries nothing measurable.

Finding 5

Above-Fold Source Proxy

Priority 4/10Quick Win

Early source proxy lacks a headline, clickable control, or offer term in its first 3,000 characters - the fallback document has no above-fold content to evaluate.

Evidence

Early HTML proxy missing: H1 headline, primary CTA, price/offer signal in first 3,000 source chars. Snapshot timestamp: 2026-08-05T00:56:29Z.

Recommended Fix

Resolved by fixing the fallback document: real H1 + CTA + offer signal in the initial HTML.

What This Demonstrates

Canva user-agent-sniffs its homepage: browsers it recognizes get the design tool's landing page; everything else - including this audit's fetcher and any crawler without a whitelisted UA - gets a document titled "Unsupported client – Canva" (26 chars) with a single H1: "Please update your browser". That fallback document is what the engine scored: 5.7/C, the lowest in this batch. No social proof, no JSON-LD, no canonical, no ad-tracking artifacts. Googlebot executes JS and likely sees the real page - but any client that doesn't run Canva's JS gets an error page as the front door.

Work at Canva? Verify ownership to manage this teardown in your workspace.

Claim this teardown

See what it finds on your page

Same engine, your URL. Free, no signup. Results in under two minutes.

Find the Leak →

Already know your page has issues? Skip the audit.

Fix one leak now, $97 →

One finding. 48h delivery. No call, no retainer.