# Audit Report: Tere tulemast Paws N' Play veebilehele! — gotoAndPlay Demo WordPress Base
**Website:** https://demo.playandnope.com/
**Date:** 2026-07-13
**Overall Score:** 82 / 100
**Status:** 🟡 **Needs Improvement**
**Confidence:** high
**Audit Coverage:** 100% — all sources returned data
## Summary
PSI mobile 99 and desktop 99 indicate excellent performance with LCP 1.8 s and CLS 0.014. Accessibility is strong with 0 axe violations, though W3C reports 10 errors including invalid ARIA attributes and semantic issues. Security is the primary weakness: HTTP does not redirect to HTTPS and the Security Headers grade is 20/100 due to missing HSTS and weak CSP. Console errors indicate a broken third-party script (CookieYes). The overall score reflects high technical quality in rendering and a11y, penalized significantly for transport security configuration.
## PageSpeed Insights — Mobile vs Desktop
_Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._
| Strategy | Performance (M / D) | LCP (M / D) | CLS (M / D) |
| --- | --- | --- | --- |
| Mobile vs Desktop | 99 / 99 | **1.82 s** / 795 ms | **0.014** / 0.003 |
## Optimization Checklist
**4 of 6 passing** — 4 pass · 1 warn · 1 fail · 1 n/a
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | **Pass** | All non-hero raster images use loading="lazy". |
| Hero image eagerly loaded | **Fail** | Hero image has loading="lazy", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading="eager" (or omit loading) and add fetchpriority="high". |
| Hero is a real
(not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / ) | **Pass** | 20/20 raster images use srcset or (100%). |
| Reasonable number of image sizes | **Pass** | 48 distinct srcset widths. |
| JS scripts not blocking in | **Warn** | 1 render-blocking script in . Move to footer or add defer/async. |
## Fixes
### Priority 1: Critical
*Immediate action — impacts user experience, search rankings, or site safety.*
**1A. Force HTTPS Redirect**
- **Impact:** Transport security, MITM protection
- **Problem:** http://demo.playandnope.com/ does not redirect to HTTPS, leaving users vulnerable to interception on the initial request.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS:
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1B. Add HSTS Header**
- **Impact:** Security Headers grade, browser enforcement
- **Problem:** strict-transport-security is missing; grade is 20/100. HSTS prevents protocol downgrade attacks.
- **Solution:**
Add the following header with max-age >= 1 year:
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
```
### Priority 2: Important
*Essential for compliance, user reach, and search visibility.*
**2A. Fix W3C Validation Errors**
- **Impact:** Accessibility, SEO, Standards compliance
- **Problem:** 10 errors found including invalid `aria-expanded` (empty value), `target` on ``, and `script` defer misuse.
- **Solution:**
- Set `aria-expanded="true"` or `"false"` (not empty) on buttons.
- Remove `target` from ``; move to `` if needed.
- Remove `defer` from `