Research · 9 min read

We audited 11 Singapore business websites in one morning

Not a survey, not a roundup of best practice. Eleven live Singapore business websites, measured on the same morning with the same tools, and the five problems that kept recurring.

Eleven columns of light rising from a dark plain — ten short and even, and one blazing far higher than all the rest.

In short

We measured eleven live Singapore SME websites on 25 August 2026. The spread in server response time was extraordinary — the fastest replied in 0.33 seconds, the slowest took between 21 and 36 seconds across three attempts. Five of the eleven had a broken or missing H1 heading, two published obvious placeholder email addresses left over from their template, three listed a contact address on a different domain from the website itself, and one was running a page builder last updated in April 2022. None of these are design problems. All of them are cheap to fix.

Key points

  • The slowest site measured took 21 to 36 seconds to send its first byte across three separate attempts; the fastest took 0.33 seconds.
  • Five of eleven Singapore business websites had a missing, duplicated or meaningless H1 heading.
  • Two of eleven published template placeholder email addresses — johndoe@company.com and user@domain.com — on live pages.
  • Three of eleven published a contact email on a different domain from their website.
  • One site was running Elementor 3.6.3, build-dated 12 April 2022, with the version number visible in its public page source.
  • Site speed had no relationship to how expensive or modern the site looked.

Why we did this

We are a studio in Nagercoil, Tamil Nadu, and six of our clients are Singapore businesses. We wanted a clearer picture of what Singapore SME websites actually look like under the bonnet, rather than what the industry says they look like.

So we picked eleven live websites across three sectors we know well — physiotherapy and healthcare, professional training, and manpower and logistics — and measured them all on the same morning with the same tools. No opinions about the design. Just what the server sends and what is in the HTML.

The results were more lopsided than we expected. The problems were not spread evenly across eleven mediocre sites. Most were fine. A few had faults severe enough to be costing real money every day, and in every case the owner almost certainly does not know.

How we measured

Everything here is reproducible. We used curl to request each homepage, recording time to first byte and total transfer time, then parsed the served HTML for structure. Anything that looked slow was sampled three times rather than once, because a single slow response can be a fluke and a claim built on one sample is not a finding.

We did not use a synthetic scoring tool, and we are not reporting a score out of a hundred. Scores compress unrelated problems into one number and then hide which of them matters.

If you want the same numbers for your own site, our free audit runs the same class of checks and explains what to fix first.

Finding one: the speed spread was enormous

Time to first byte is the gap between a browser asking for your page and your server beginning to answer. It happens before a single image, font or script loads. It is almost entirely a hosting characteristic, which means it is one of the few web performance problems you can fix without touching the site.

Across eleven sites the range was not a spectrum. It was a cluster and an outlier.

BandSitesTime to first byte
Fast6 of 11under 1.2 seconds
Slow4 of 112.1 to 5.1 seconds
Broken1 of 1121 to 36 seconds

The outlier deserves its own paragraph

One manpower agency's site took 21.4, 36.4 and 29.2 seconds to begin responding across three consecutive attempts. Total load reached 40.3 seconds. For context, Google considers 2.5 seconds a reasonable target for the main content to appear.

Nobody waits forty seconds. On a phone, on mobile data, that visitor is gone long before anything renders — and because they never reached the site, they never appear in its analytics. The owner sees a quiet month, not a broken server. This is the most expensive kind of fault precisely because it is invisible from the inside.

Notably, that site is not badly designed. Its HTML is 49KB, which is lean. The problem is entirely the server it sits on, and moving hosts would likely fix it in an afternoon.

Finding two: five of eleven had a broken heading structure

The H1 is a page's main heading. Search engines and, increasingly, AI assistants use it as the strongest single signal of what a page is about. It is one line of HTML and it is free.

Five of the eleven sites got it wrong, in four different ways:

  • Two had no H1 at all — nothing on the homepage identified the subject of the page.
  • One used the word "Home" as its H1. The business is a freight forwarder; "Home" says nothing a competitor could not also say.
  • One used "About Us" as the H1 on its homepage — a training academy, whose accreditations are the first thing a buyer checks.
  • One had three H1s on a single page. When everything is the main heading, nothing is.

One of these sites also had a malformed closing tag — </h1 > with a space before the bracket — which changes how parsers read everything after it.

Finding three: two sites still show their template's placeholder text

One published johndoe@company.com on a live page. Another published user@domain.com as its only contact address.

Both are leftovers from a theme demo that nobody removed. Both appear on pages where a customer is deciding whether to get in touch. It is a small thing that does a specific kind of damage: it tells a visitor that nobody has looked at this page recently, which invites the question of whether anybody is minding the business either.

It is also the single cheapest fix on this list. It takes under a minute, and the reason it survives is that the owner has read their own contact page so many times they no longer see it.

Finding four: three sites publish an email on a different domain

One site at a .com published its contact address at a .sg. Another, whose website is one brand name, published an address at a different brand name entirely. A third did the same across two variants of its own name.

There are usually good historical reasons for this — an older company, an acquisition, a domain bought later. But it costs twice. A customer comparing suppliers sees a mismatch and reads it as slightly off, and mail filters increasingly score outbound messages lower when the sending domain does not align with the website it references.

If you cannot consolidate, at least make sure both domains have matching SPF, DKIM and DMARC records so your mail authenticates properly from either.

Finding five: one site advertises a four-year-old page builder

One site is running Elementor 3.6.3, build-dated 12 April 2022. That is over four years of releases and security patches skipped.

The specific risk is not that old software is inherently broken. It is that the version number is printed in the page's public source code, where it is trivially discoverable. Automated scanners look for exactly this: a known plugin, a known old version, and therefore a known list of published vulnerabilities to try.

If you run WordPress, check what your page builder announces about itself. You can see it by viewing source and searching for your builder's name.

What none of this was about

Not one of these problems is a design problem. Nobody needs a rebuild because of anything on this list. Every single finding is either a hosting decision, one line of HTML, a forgotten placeholder, a DNS record, or an update that has been waiting four years.

That is the part worth sitting with. The industry sells redesigns, because a redesign is a big visible project with a big invoice attached. Meanwhile the site that takes 36 seconds to load does not need to look different at all. It needs a better server.

Five checks you can run on your own site today

  • Load your homepage on mobile data, not office wifi, and count the seconds before anything appears.
  • View source and search for "<h1". Confirm there is exactly one, and that it describes what you sell and where.
  • Search your own site for the words "lorem", "example.com", "johndoe" and "yourname".
  • Check that the email address on your contact page is on the same domain as your website.
  • If you run WordPress, check your page builder's version against its current release.

All five take about ten minutes together, and any one of them could be the reason a month felt quiet.

Questions

Frequently asked

How were these eleven websites chosen?

They were selected from public directories and search results across three sectors — physiotherapy and healthcare, professional training, and manpower and logistics — because those are sectors we already work in. They are all real, live Singapore businesses. We have not named them, because they did not ask to be written about and the findings hold without the names.

What is a good time to first byte for a small business website?

Under 0.8 seconds is comfortable and achievable on ordinary shared hosting. Between 1 and 2 seconds is workable but worth improving. Anything consistently over 2.5 seconds usually points at the hosting rather than the design, and above 5 seconds you are losing visitors who will never appear in your analytics because they left before the page existed.

Why does a missing H1 matter if the page looks fine to visitors?

Because visitors are not the only readers. Search engines and AI assistants parse structure to work out what a page is about, and the H1 is the strongest single signal available. A page that looks perfect to a human can be almost meaningless to a parser, which is how a well-designed site ends up invisible for the terms it should own.

Is an outdated WordPress plugin actually dangerous?

The age itself is not the danger. The danger is that the version number is published in your page source, so an automated scanner can identify exactly which known vulnerabilities to attempt. A plugin four years behind has four years of published security advisories attached to it, and finding sites running it requires no skill at all.

Can you audit our website?

Yes. MW Digital Solutions runs a free website audit that performs the same class of checks described here — performance, crawlability, metadata, structured data and mobile behaviour — and explains what to fix first. It needs no signup, and if the fixes are ones your existing developer can handle, that is a perfectly good outcome.

Want this run on your own site?

Our audit performs the same checks described here and tells you what to fix first. No signup, and no obligation to fix it with us.

Run a free audit