# Audit Report: Giga Investeeringud
**Website:** https://gigainvesteeringud.giga.ee/
**Date:** 31.08.2026
**Audit Coverage:** 100% β all sources returned data
**Confidence:** high
**Pages Audited (5 of 5):**
- https://gigainvesteeringud.giga.ee/
- https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil
- https://gigainvesteeringud.giga.ee/test
- https://gigainvesteeringud.giga.ee/meist
- https://gigainvesteeringud.giga.ee/kinnitus
## Summary of results
**Overall Score:** 73 / 100
**Status:** π‘ **Needs Improvement**
Site overall 73 is the mean of 5 pages. Scores range 68 (https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil) β 87 (https://gigainvesteeringud.giga.ee/). Weakest page: Mobile performance is the primary constraint with an LCP of 4.1 s and FCP of 3.04 s, both exceeding recommended thresholds. Security posture is critically weak with a 0/100 header score, missing HSTS and CSP despite user-generated content signals. Accessibility has two serious axe violations regarding color contrast and link names that require immediate remediation. HTML validation errors in `srcset` and script attributes further degrade code quality. SEO is hindered by missing meta descriptions and structured data.
### Per-page scores
π‘ **Needs Improvement** Β· https://gigainvesteeringud.giga.ee/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 87 | 97 | 89 | 100 | 92 | 0 |
π‘ **Needs Improvement** Β· https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 68 | 81 | 85 | 100 | 92 | 0 |
π‘ **Needs Improvement** Β· https://gigainvesteeringud.giga.ee/test
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 68 | 87 | 94 | 96 | 83 | 0 |
π‘ **Needs Improvement** Β· https://gigainvesteeringud.giga.ee/meist
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 68 | 73 | 89 | 100 | 92 | 0 |
π‘ **Needs Improvement** Β· https://gigainvesteeringud.giga.ee/kinnitus
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 76 | 97 | 94 | 100 | 92 | 0 |
## PageSpeed Insights β Mobile vs Desktop
_Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._
| URL | Performance (M / D) | LCP (M / D) | CLS (M / D) |
| --- | --- | --- | --- |
| https://gigainvesteeringud.giga.ee/ | **97** / 98 | **1.95 s** / 446 ms | **0.090** / 0.090 |
| https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil | **81** / 99 | **4.10 s** / 995 ms | 0.000 / **0.000** |
| https://gigainvesteeringud.giga.ee/test | **87** / 100 | **3.16 s** / 432 ms | **0.000** / 0.000 |
| https://gigainvesteeringud.giga.ee/meist | **73** / 99 | **5.80 s** / 732 ms | 0.034 / **0.064** |
| https://gigainvesteeringud.giga.ee/kinnitus | **97** / 98 | **1.86 s** / 564 ms | 0.090 / **0.090** |
## Optimization Checklist
**2 of 2 passing** β 2 pass Β· 0 warn Β· 0 fail Β· 5 n/a
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | N/A | No raster
elements found (15 SVGs excluded). |
| Hero image eagerly loaded | N/A | No raster
elements found (15 SVGs excluded). |
| Hero is a real
(not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / ) | N/A | Only 0 raster images on the page (15 SVGs excluded) β responsive-image rule does not apply. |
| Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in | **Pass** | No render-blocking scripts in . |
## Fixes
### Priority 1: Critical
*Immediate action β impacts user experience, search rankings, or site safety.*
**1A. Add HSTS and X-Content-Type-Options headers** `Security`
- **Impact:** Transport security, MIME sniffing protection
- **Problem:** Security Headers grade is 0/100; HSTS and X-Content-Type-Options are missing despite HTTPS being enabled.
- **Solution:**
Add the following headers to your server configuration (Apache example):
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
Header always set X-Content-Type-Options "nosniff"
```
**1B. Fix color contrast on navigation links** `Accessibility`
- **Impact:** WCAG 1.4.3 Compliance, Screen Reader usability
- **Problem:** axe-core reports 1 serious violation: color-contrast on multiple menu items (e.g., .menu-item-543).
- **Solution:**
Increase the contrast ratio between text and background to at least 4.5:1. Adjust CSS for `.menu-item-543 > a` and similar selectors to use darker text or lighter backgrounds.
**1C. Implement Critical Security Headers (HSTS, CSP)** `Security`
- **Impact:** Transport security, XSS defense
- **Problem:** Security Headers grade is 0/100; HSTS and CSP are missing. Site signals indicate user-generated content (upload anchor), elevating XSS risk.
- **Solution:**
Add HSTS with preload and a strict CSP:
```http
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
Content-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';
```
**1D. Optimize Largest Contentful Paint (LCP)** `Performance`
- **Impact:** LCP 4.1 s, FCP 3.04 s
- **Problem:** Mobile LCP is 4.1 s (heavy penalty zone >4 s) and FCP is 3.04 s. Unused JS (23 KB) and image delivery (227 KiB savings) identified.
- **Solution:**
- Preload LCP image resource.
- Defer unused JavaScript (`jquery.7e52f38a196e6397.js`).
- Optimize image delivery (227 KiB savings potential).
**1E. Resolve 404 Status Code** `SEO`
- **Impact:** SEO, User Experience
- **Problem:** W3C, PSI, and Browser Runtime all confirm the URL returns HTTP 404 (Page Not Found).
- **Solution:**
Ensure the target URL returns a 200 OK status if content is intended to be live. If this is a test page, do not index it (add `noindex` meta tag) or move it to a staging environment.
### Priority 2: Important
*Essential for compliance, user reach, and search visibility.*
**2A. Add a meta description** `SEO`
- **Impact:** Search result click-through rate, SEO audit score
- **Problem:** Lighthouse SEO audit fails `metaDescription`; HTML Inventory confirms Description meta tag is not set.
- **Solution:**
Add a concise description (150β160 characters) in the ``:
```html
```
**2B. Fix srcset width descriptors on SVGs** `Best Practices`
- **Impact:** HTML Validation, Image rendering consistency
- **Problem:** W3C Validator reports 9 errors where `srcset` lacks width specifications (e.g., `giga-invest.svg`) while `sizes` is present.
- **Solution:**
Update `
` tags to include width descriptors in `srcset` (e.g., `srcset="image.svg 100w"`) or remove `sizes` if not needed for SVGs.
**2C. Fix Color Contrast and Link Names** `Accessibility`
- **Impact:** WCAG 1.4.3, 2.4.4 compliance
- **Problem:** axe-core reports 2 serious violations: color-contrast on menu links and link-name on gallery images.
- **Solution:**
- Increase contrast ratio on `.menu-item-543` links to β₯4.5:1.
- Add `aria-label` or visible text to gallery links (e.g., `data-fancybox` elements).
**2D. Resolve W3C HTML Validation Errors** `Best Practices`
- **Impact:** Code quality, rendering consistency
- **Problem:** 4 errors found: `srcset` missing width (x2), `sizes` 'auto' without `loading='lazy'`, and invalid `script` type/defer combination.
- **Solution:**
- Add width descriptors to `srcset` (e.g., `100w`).
- Add `loading="lazy"` to images with `sizes="auto"`.
- Remove `defer` from non-JS script types or correct MIME type.
**2E. Add Baseline Security Headers** `Security`
- **Impact:** Transport security, clickjacking, MIME sniffing
- **Problem:** Security Headers grade is 0/100. HSTS, X-Frame-Options, and X-Content-Type-Options are missing.
- **Solution:**
Send the following headers from the server (Apache example):
```
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
Header always set X-Content-Type-Options "nosniff"
Header always set X-Frame-Options "SAMEORIGIN"
```
**2F. Enable Browser Caching** `Performance`
- **Impact:** Repeat visit load time, TTFB
- **Problem:** Cache-Control header is set to `no-store, no-cache, max-age=0`, preventing the browser from caching the document despite WP Rocket being active.
- **Solution:**
Update server configuration to allow caching for static assets and the document itself (e.g., `Cache-Control: public, max-age=31536000` for assets, `max-age=600` for HTML).
**2G. Fix Color Contrast on Navigation** `Accessibility`
- **Impact:** WCAG 1.4.3 Contrast
- **Problem:** axe-core reports a serious color-contrast violation on 23+ nodes, including menu links like `.menu-item-543`.
- **Solution:**
Increase the contrast ratio of text against its background to at least 4.5:1. Adjust CSS for `.menu-item-543 > a` and similar classes.
**2H. Implement Baseline Security Headers** `Security`
- **Impact:** Transport security, clickjacking protection, MIME sniffing
- **Problem:** Security Headers grade is 0/100; HSTS, X-Frame-Options, and X-Content-Type-Options are missing despite HTTPS being active.
- **Solution:**
Add the following headers to the server configuration (Apache example):
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
Header always set X-Frame-Options "SAMEORIGIN"
Header always set X-Content-Type-Options "nosniff"
```
**2I. Fix Color Contrast on Navigation Links** `Accessibility`
- **Impact:** WCAG 1.4.3 (Contrast), Accessibility Score
- **Problem:** axe-core reports 1 serious violation: multiple menu links (e.g., `.menu-item-543 > a`) fail minimum contrast ratios.
- **Solution:**
- Increase text color luminance or darken background for affected links.
- Target a contrast ratio of at least 4.5:1 for normal text.
- Verify changes with a contrast checker tool before deployment.
**2J. Add baseline security headers (HSTS, X-Content-Type-Options, X-Frame-Options)** `Security`
- **Impact:** Transport security, clickjacking protection, MIME sniffing
- **Problem:** Security Headers grade is 0/100; HSTS, X-Content-Type-Options, and X-Frame-Options are missing.
- **Solution:**
Configure server to send:
```
Strict-Transport-Security: max-age=63072000; includeSubDomains
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
```
**2K. Provide accessible names for buttons** `Accessibility`
- **Impact:** WCAG 4.1.2 Name, Role, Value
- **Problem:** PSI failing audit `button-name` (score 0.00) indicates buttons lack accessible names.
- **Solution:**
Ensure all `