# Audit Report: Viga 401 - Error 401 | Veebimajutus.ee
**Website:** https://gigaehitus.gotoand.support/
**Date:** 2026-06-29
**Overall Score:** 55 / 100
**Status:** ๐ **Poor**
**Confidence:** high
**Audit Coverage:** 100% โ all sources returned data
**Pages Audited (1 of 1):**
- https://gigaehitus.gotoand.support/
## Summary
Site overall 55 is the mean of 1 page. PSI mobile 95 indicates strong rendering performance (LCP 2.4 s, TTFB 2 ms), but the HTTP 401 Unauthorized status renders the site inaccessible to public users, creating a critical functional failure. Security headers are entirely missing (0/100 grade), though site signals suggest low authentication risk. Accessibility has a serious color-contrast violation and missing semantic landmarks. SEO metadata is absent, and the page contains three H1 tags. The overall score reflects high technical performance undermined by configuration errors and missing standards.
## Per-Page Scores
| Page | Score | Status | Confidence |
| --- | --- | --- | --- |
| https://gigaehitus.gotoand.support/ | 55 | ๐ **Poor** | high |
## PageSpeed Insights โ Mobile vs Desktop
_Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._
| URL | Performance (M / D) | LCP (M / D) | CLS (M / D) |
| --- | --- | --- | --- |
| https://gigaehitus.gotoand.support/ | **95** / 100 | **2.41 s** / 648 ms | **0.002** / 0.000 |
## Optimization Checklist
**1 of 3 passing** โ 1 pass ยท 1 warn ยท 1 fail ยท 4 n/a
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | **Fail** | No WordPress cache plugin marker or CDN edge cache detected on the document response. |
| Images lazy-loaded | **Pass** | All raster images use loading="lazy". |
| Hero image eagerly loaded | **Warn** | Hero image has no explicit loading or fetchpriority (inferred from DOM order/size โ Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP. |
| Hero is a real (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / ) | N/A | Only 1 raster image on the page โ responsive-image rule does not apply. |
| Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in | N/A | No external scripts on the page. |
## Fixes
### Priority 1: Critical
*Immediate action โ impacts user experience, search rankings, or site safety.*
**1A. Resolve HTTP 401 Unauthorized Status**
- **Impact:** Site Accessibility, SEO Indexing
- **Problem:** Server returns 401 Unauthorized (WWW-Authenticate: Basic), blocking public access despite 'Auth surface: no' signals.
- **Solution:**
Remove Basic Auth requirements from the web server configuration (Apache/Nginx) for this public URL, or ensure the intended audience has credentials. Verify the `WWW-Authenticate` header is removed from the response.
### Priority 2: Important
*Essential for compliance, user reach, and search visibility.*
**2A. Implement Baseline Security Headers**
- **Impact:** Transport Security, Clickjacking Protection
- **Problem:** HSTS, X-Frame-Options, and X-Content-Type-Options are missing (Security Headers grade 0/100).
- **Solution:**
Add the following headers to the server configuration:
```
Strict-Transport-Security: max-age=63072000; includeSubDomains
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
```
**2B. Fix Accessibility Contrast and Landmarks**
- **Impact:** WCAG 1.4.3, 1.3.1, 2.4.1
- **Problem:** Serious color-contrast violations on navbar/links; missing `` and `