# Audit Report: Tere tulemast Paws N' Play veebilehele! — gotoAndPlay Demo WordPress Base **Website:** https://demo.playandnope.com/ **Date:** 2026-07-13 **Overall Score:** 82 / 100 **Status:** 🟡 **Needs Improvement** **Confidence:** high **Audit Coverage:** 100% — all sources returned data ## Summary PSI mobile 99 and desktop 99 indicate excellent performance with LCP 1.8 s and CLS 0.014. Accessibility is strong with 0 axe violations, though W3C reports 10 errors including invalid ARIA attributes and semantic issues. Security is the primary weakness: HTTP does not redirect to HTTPS and the Security Headers grade is 20/100 due to missing HSTS and weak CSP. Console errors indicate a broken third-party script (CookieYes). The overall score reflects high technical quality in rendering and a11y, penalized significantly for transport security configuration. ## PageSpeed Insights — Mobile vs Desktop _Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._ | Strategy | Performance (M / D) | LCP (M / D) | CLS (M / D) | | --- | --- | --- | --- | | Mobile vs Desktop | 99 / 99 | **1.82 s** / 795 ms | **0.014** / 0.003 | ## Optimization Checklist **4 of 6 passing** — 4 pass · 1 warn · 1 fail · 1 n/a | Item | Status | Detail | | --- | --- | --- | | Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) | | Images lazy-loaded | **Pass** | All non-hero raster images use loading="lazy". | | Hero image eagerly loaded | **Fail** | Hero image has loading="lazy", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading="eager" (or omit loading) and add fetchpriority="high". | | Hero is a real (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. | | Responsive images (srcset / ) | **Pass** | 20/20 raster images use srcset or (100%). | | Reasonable number of image sizes | **Pass** | 48 distinct srcset widths. | | JS scripts not blocking in | **Warn** | 1 render-blocking script in . Move to footer or add defer/async. | ## Fixes ### Priority 1: Critical *Immediate action — impacts user experience, search rankings, or site safety.* **1A. Force HTTPS Redirect** - **Impact:** Transport security, MITM protection - **Problem:** http://demo.playandnope.com/ does not redirect to HTTPS, leaving users vulnerable to interception on the initial request. - **Solution:** Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS: ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1B. Add HSTS Header** - **Impact:** Security Headers grade, browser enforcement - **Problem:** strict-transport-security is missing; grade is 20/100. HSTS prevents protocol downgrade attacks. - **Solution:** Add the following header with max-age >= 1 year: ```apache Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" ``` ### Priority 2: Important *Essential for compliance, user reach, and search visibility.* **2A. Fix W3C Validation Errors** - **Impact:** Accessibility, SEO, Standards compliance - **Problem:** 10 errors found including invalid `aria-expanded` (empty value), `target` on ``, and `script` defer misuse. - **Solution:** - Set `aria-expanded="true"` or `"false"` (not empty) on buttons. - Remove `target` from ``; move to `` if needed. - Remove `defer` from `