{"url":"https://gigainvesteeringud.giga.ee/","date":"2026-08-31","siteName":"Giga Investeeringud","overall":73,"reasoning":"Site overall 73 is the mean of 5 pages. Scores range 68 (https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil) → 87 (https://gigainvesteeringud.giga.ee/). Weakest page: Mobile performance is the primary constraint with an LCP of 4.1 s and FCP of 3.04 s, both exceeding recommended thresholds. Security posture is critically weak with a 0/100 header score, missing HSTS and CSP despite user-generated content signals. Accessibility has two serious axe violations regarding color contrast and link names that require immediate remediation. HTML validation errors in `srcset` and script attributes further degrade code quality. SEO is hindered by missing meta descriptions and structured data.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Add HSTS and X-Content-Type-Options headers","impact":"Transport security, MIME sniffing protection","problem":"Security Headers grade is 0/100; HSTS and X-Content-Type-Options are missing despite HTTPS being enabled.","solution":"Add the following headers to your server configuration (Apache example):\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":1,"category":"Accessibility","title":"Fix color contrast on navigation links","impact":"WCAG 1.4.3 Compliance, Screen Reader usability","problem":"axe-core reports 1 serious violation: color-contrast on multiple menu items (e.g., .menu-item-543).","solution":"Increase the contrast ratio between text and background to at least 4.5:1. Adjust CSS for `.menu-item-543 > a` and similar selectors to use darker text or lighter backgrounds."},{"priority":1,"category":"Security","title":"Implement Critical Security Headers (HSTS, CSP)","impact":"Transport security, XSS defense","problem":"Security Headers grade is 0/100; HSTS and CSP are missing. Site signals indicate user-generated content (upload anchor), elevating XSS risk.","solution":"Add HSTS with preload and a strict CSP:\n```http\nStrict-Transport-Security: max-age=63072000; includeSubDomains; preload\nContent-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\n```"},{"priority":1,"category":"Performance","title":"Optimize Largest Contentful Paint (LCP)","impact":"LCP 4.1 s, FCP 3.04 s","problem":"Mobile LCP is 4.1 s (heavy penalty zone >4 s) and FCP is 3.04 s. Unused JS (23 KB) and image delivery (227 KiB savings) identified.","solution":"- Preload LCP image resource.\n- Defer unused JavaScript (`jquery.7e52f38a196e6397.js`).\n- Optimize image delivery (227 KiB savings potential)."},{"priority":1,"category":"SEO","title":"Resolve 404 Status Code","impact":"SEO, User Experience","problem":"W3C, PSI, and Browser Runtime all confirm the URL returns HTTP 404 (Page Not Found).","solution":"Ensure the target URL returns a 200 OK status if content is intended to be live. If this is a test page, do not index it (add `noindex` meta tag) or move it to a staging environment."},{"priority":2,"category":"SEO","title":"Add a meta description","impact":"Search result click-through rate, SEO audit score","problem":"Lighthouse SEO audit fails `metaDescription`; HTML Inventory confirms Description meta tag is not set.","solution":"Add a concise description (150–160 characters) in the `<head>`:\n```html\n<meta name=\"description\" content=\"Giga Investeeringud – Äri- ja elamukinnisvara spetsialist. Uurige meie pakkumisi ja arendusi.\">\n```"},{"priority":2,"category":"Best Practices","title":"Fix srcset width descriptors on SVGs","impact":"HTML Validation, Image rendering consistency","problem":"W3C Validator reports 9 errors where `srcset` lacks width specifications (e.g., `giga-invest.svg`) while `sizes` is present.","solution":"Update `<img>` tags to include width descriptors in `srcset` (e.g., `srcset=\"image.svg 100w\"`) or remove `sizes` if not needed for SVGs."},{"priority":2,"category":"Accessibility","title":"Fix Color Contrast and Link Names","impact":"WCAG 1.4.3, 2.4.4 compliance","problem":"axe-core reports 2 serious violations: color-contrast on menu links and link-name on gallery images.","solution":"- Increase contrast ratio on `.menu-item-543` links to ≥4.5:1.\n- Add `aria-label` or visible text to gallery links (e.g., `data-fancybox` elements)."},{"priority":2,"category":"Best Practices","title":"Resolve W3C HTML Validation Errors","impact":"Code quality, rendering consistency","problem":"4 errors found: `srcset` missing width (x2), `sizes` 'auto' without `loading='lazy'`, and invalid `script` type/defer combination.","solution":"- Add width descriptors to `srcset` (e.g., `100w`).\n- Add `loading=\"lazy\"` to images with `sizes=\"auto\"`.\n- Remove `defer` from non-JS script types or correct MIME type."},{"priority":2,"category":"Security","title":"Add Baseline Security Headers","impact":"Transport security, clickjacking, MIME sniffing","problem":"Security Headers grade is 0/100. HSTS, X-Frame-Options, and X-Content-Type-Options are missing.","solution":"Send the following headers from the server (Apache example):\n```\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\n```"},{"priority":2,"category":"Performance","title":"Enable Browser Caching","impact":"Repeat visit load time, TTFB","problem":"Cache-Control header is set to `no-store, no-cache, max-age=0`, preventing the browser from caching the document despite WP Rocket being active.","solution":"Update server configuration to allow caching for static assets and the document itself (e.g., `Cache-Control: public, max-age=31536000` for assets, `max-age=600` for HTML)."},{"priority":2,"category":"Accessibility","title":"Fix Color Contrast on Navigation","impact":"WCAG 1.4.3 Contrast","problem":"axe-core reports a serious color-contrast violation on 23+ nodes, including menu links like `.menu-item-543`.","solution":"Increase the contrast ratio of text against its background to at least 4.5:1. Adjust CSS for `.menu-item-543 > a` and similar classes."},{"priority":2,"category":"Security","title":"Implement Baseline Security Headers","impact":"Transport security, clickjacking protection, MIME sniffing","problem":"Security Headers grade is 0/100; HSTS, X-Frame-Options, and X-Content-Type-Options are missing despite HTTPS being active.","solution":"Add the following headers to the server configuration (Apache example):\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Accessibility","title":"Fix Color Contrast on Navigation Links","impact":"WCAG 1.4.3 (Contrast), Accessibility Score","problem":"axe-core reports 1 serious violation: multiple menu links (e.g., `.menu-item-543 > a`) fail minimum contrast ratios.","solution":"- Increase text color luminance or darken background for affected links.\n- Target a contrast ratio of at least 4.5:1 for normal text.\n- Verify changes with a contrast checker tool before deployment."},{"priority":2,"category":"Security","title":"Add baseline security headers (HSTS, X-Content-Type-Options, X-Frame-Options)","impact":"Transport security, clickjacking protection, MIME sniffing","problem":"Security Headers grade is 0/100; HSTS, X-Content-Type-Options, and X-Frame-Options are missing.","solution":"Configure server to send:\n```\nStrict-Transport-Security: max-age=63072000; includeSubDomains\nX-Content-Type-Options: nosniff\nX-Frame-Options: SAMEORIGIN\n```"},{"priority":2,"category":"Accessibility","title":"Provide accessible names for buttons","impact":"WCAG 4.1.2 Name, Role, Value","problem":"PSI failing audit `button-name` (score 0.00) indicates buttons lack accessible names.","solution":"Ensure all `<button>` elements have visible text or `aria-label` attributes describing their action."},{"priority":2,"category":"SEO","title":"Add meta description and structured data","impact":"Search snippet quality, rich results eligibility","problem":"PSI SEO audit fails `metaDescription` and `structuredData`; HTML Inventory confirms no meta description or JSON-LD.","solution":"Add `<meta name=\"description\" content=\"...\">` and implement relevant JSON-LD (e.g., Organization or WebPage)."},{"priority":3,"category":"Security","title":"Implement Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing. Site signals show no auth/payments, so risk is lower, but CSP is still a best practice.","solution":"Deploy a restrictive CSP with nonces for scripts:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"},{"priority":3,"category":"SEO","title":"Add Meta Description and Structured Data","impact":"Search snippet quality, rich results","problem":"SEO audit fails `metaDescription` and `structuredData`; HTML inventory confirms no JSON-LD or meta description.","solution":"- Add `<meta name=\"description\" content=\"...\">` summarizing the Raadi homes article.\n- Implement `Article` or `NewsArticle` JSON-LD schema."},{"priority":3,"category":"Security","title":"Implement Content Security Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing. Site signals indicate no auth, payments, or user content, lowering immediate risk but CSP remains best practice.","solution":"Deploy a strict CSP with nonces for scripts. Example:\n```\nContent-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\n```"},{"priority":3,"category":"SEO","title":"Add Meta Description and Open Graph Tags","impact":"Search snippet quality, Social sharing","problem":"HTML Inventory shows no meta description, no Open Graph tags, and no Twitter tags; PSI SEO audit flags `metaDescription` as failing.","solution":"Add to `<head>`:\n```html\n<meta name=\"description\" content=\"Giga Investeeringud on ambitsioonikas äri- ja elamukinnisvara arendaja.\">\n<meta property=\"og:title\" content=\"Meist - Giga Investeeringud\">\n<meta property=\"og:description\" content=\"...\">\n<meta property=\"og:image\" content=\"/path/to/og-image.jpg\">\n```"},{"priority":3,"category":"Best Practices","title":"Fix W3C srcset Width Errors","impact":"HTML Validity, Image Rendering","problem":"W3C Validator reports 7 errors where `srcset` attributes lack width descriptors (e.g., `100w`) while `sizes` is present.","solution":"Update `<img>` tags to include width descriptors in `srcset`:\n```html\n<!-- Incorrect -->\n<img srcset=\"/img.svg\" sizes=\"100vw\">\n\n<!-- Correct -->\n<img srcset=\"/img.svg 100w\" sizes=\"100vw\">\n```"},{"priority":3,"category":"Security","title":"Consider Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing. Site signals indicate no auth, payments, or user content, lowering immediate risk but CSP remains a best practice.","solution":"If user content or login is added later, deploy a nonce-based CSP:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'\"\n```\nFor now, prioritize P1/P2 fixes."}],"coverage":{"pct":100,"missing":[]},"siteSummary":{"pagesAudited":5,"pagesAttempted":5,"urls":["https://gigainvesteeringud.giga.ee/","https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil","https://gigainvesteeringud.giga.ee/test","https://gigainvesteeringud.giga.ee/meist","https://gigainvesteeringud.giga.ee/kinnitus"]},"psiSnapshot":{"rows":[{"pageUrl":"https://gigainvesteeringud.giga.ee/","perfMobile":97,"perfDesktop":98,"lcpMobileMs":1951,"lcpDesktopMs":445.6679268855653,"clsMobile":0.08997394034695415,"clsDesktop":0.08988814439158797},{"pageUrl":"https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil","perfMobile":81,"perfDesktop":99,"lcpMobileMs":4100.1955,"lcpDesktopMs":994.6025800000003,"clsMobile":0,"clsDesktop":0.0003212253472007708},{"pageUrl":"https://gigainvesteeringud.giga.ee/test","perfMobile":87,"perfDesktop":100,"lcpMobileMs":3157.4581775,"lcpDesktopMs":431.77744249999995,"clsMobile":0.0004095375908800655,"clsDesktop":0.0003698642706358864},{"pageUrl":"https://gigainvesteeringud.giga.ee/meist","perfMobile":73,"perfDesktop":99,"lcpMobileMs":5799.027285,"lcpDesktopMs":731.96416,"clsMobile":0.034377103852042366,"clsDesktop":0.06388093864933357},{"pageUrl":"https://gigainvesteeringud.giga.ee/kinnitus","perfMobile":97,"perfDesktop":98,"lcpMobileMs":1860.5067000000004,"lcpDesktopMs":564,"clsMobile":0.08983959603668534,"clsDesktop":0.09004225727283881}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket)","evidence":["HTML markers: WP Rocket","generator: WP Rocket 3.23.3.3"]},{"id":"lazyload","title":"Images lazy-loaded","status":"n/a","detail":"No raster <img> elements found (15 SVGs excluded).","evidence":[]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"n/a","detail":"No raster <img> elements found (15 SVGs excluded).","evidence":[]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"n/a","detail":"No CSS background-images detected on raster-image-eligible elements.","evidence":[]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"n/a","detail":"Only 0 raster images on the page (15 SVGs excluded) — responsive-image rule does not apply.","evidence":[]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"n/a","detail":"Too few raster images to evaluate srcset width variety.","evidence":[]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"pass","detail":"No render-blocking scripts in <head>.","evidence":[]}],"summary":{"passed":2,"warned":0,"failed":0,"notApplicable":5},"priorities":[]},"perPageOverall":[{"url":"https://gigainvesteeringud.giga.ee/","overall":87,"reasoning":"PSI mobile 97 indicates excellent performance (LCP 2.0 s, TBT 0 ms), but security headers score 0/100 drags the SEO/Security budget significantly. Accessibility is strong (89) but hindered by a serious color-contrast violation on menu links. W3C validation reports 9 errors, primarily regarding srcset width descriptors on SVGs. Despite the low-risk site signals (no auth/payments), missing HSTS and X-Content-Type-Options remain priority hardening steps. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Add HSTS and X-Content-Type-Options headers","impact":"Transport security, MIME sniffing protection","problem":"Security Headers grade is 0/100; HSTS and X-Content-Type-Options are missing despite HTTPS being enabled.","solution":"Add the following headers to your server configuration (Apache example):\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":1,"category":"Accessibility","title":"Fix color contrast on navigation links","impact":"WCAG 1.4.3 Compliance, Screen Reader usability","problem":"axe-core reports 1 serious violation: color-contrast on multiple menu items (e.g., .menu-item-543).","solution":"Increase the contrast ratio between text and background to at least 4.5:1. Adjust CSS for `.menu-item-543 > a` and similar selectors to use darker text or lighter backgrounds."},{"priority":2,"category":"SEO","title":"Add a meta description","impact":"Search result click-through rate, SEO audit score","problem":"Lighthouse SEO audit fails `metaDescription`; HTML Inventory confirms Description meta tag is not set.","solution":"Add a concise description (150–160 characters) in the `<head>`:\n```html\n<meta name=\"description\" content=\"Giga Investeeringud – Äri- ja elamukinnisvara spetsialist. Uurige meie pakkumisi ja arendusi.\">\n```"},{"priority":2,"category":"Best Practices","title":"Fix srcset width descriptors on SVGs","impact":"HTML Validation, Image rendering consistency","problem":"W3C Validator reports 9 errors where `srcset` lacks width specifications (e.g., `giga-invest.svg`) while `sizes` is present.","solution":"Update `<img>` tags to include width descriptors in `srcset` (e.g., `srcset=\"image.svg 100w\"`) or remove `sizes` if not needed for SVGs."},{"priority":3,"category":"Security","title":"Implement Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing. Site signals show no auth/payments, so risk is lower, but CSP is still a best practice.","solution":"Deploy a restrictive CSP with nonces for scripts:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"}],"perfScore":97,"a11yScore":89,"bestPracticesScore":100,"seoScore":92,"securityScore":0},{"url":"https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil","overall":68,"reasoning":"Mobile performance is the primary constraint with an LCP of 4.1 s and FCP of 3.04 s, both exceeding recommended thresholds. Security posture is critically weak with a 0/100 header score, missing HSTS and CSP despite user-generated content signals. Accessibility has two serious axe violations regarding color contrast and link names that require immediate remediation. HTML validation errors in `srcset` and script attributes further degrade code quality. SEO is hindered by missing meta descriptions and structured data.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Implement Critical Security Headers (HSTS, CSP)","impact":"Transport security, XSS defense","problem":"Security Headers grade is 0/100; HSTS and CSP are missing. Site signals indicate user-generated content (upload anchor), elevating XSS risk.","solution":"Add HSTS with preload and a strict CSP:\n```http\nStrict-Transport-Security: max-age=63072000; includeSubDomains; preload\nContent-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\n```"},{"priority":1,"category":"Performance","title":"Optimize Largest Contentful Paint (LCP)","impact":"LCP 4.1 s, FCP 3.04 s","problem":"Mobile LCP is 4.1 s (heavy penalty zone >4 s) and FCP is 3.04 s. Unused JS (23 KB) and image delivery (227 KiB savings) identified.","solution":"- Preload LCP image resource.\n- Defer unused JavaScript (`jquery.7e52f38a196e6397.js`).\n- Optimize image delivery (227 KiB savings potential)."},{"priority":2,"category":"Accessibility","title":"Fix Color Contrast and Link Names","impact":"WCAG 1.4.3, 2.4.4 compliance","problem":"axe-core reports 2 serious violations: color-contrast on menu links and link-name on gallery images.","solution":"- Increase contrast ratio on `.menu-item-543` links to ≥4.5:1.\n- Add `aria-label` or visible text to gallery links (e.g., `data-fancybox` elements)."},{"priority":2,"category":"Best Practices","title":"Resolve W3C HTML Validation Errors","impact":"Code quality, rendering consistency","problem":"4 errors found: `srcset` missing width (x2), `sizes` 'auto' without `loading='lazy'`, and invalid `script` type/defer combination.","solution":"- Add width descriptors to `srcset` (e.g., `100w`).\n- Add `loading=\"lazy\"` to images with `sizes=\"auto\"`.\n- Remove `defer` from non-JS script types or correct MIME type."},{"priority":3,"category":"SEO","title":"Add Meta Description and Structured Data","impact":"Search snippet quality, rich results","problem":"SEO audit fails `metaDescription` and `structuredData`; HTML inventory confirms no JSON-LD or meta description.","solution":"- Add `<meta name=\"description\" content=\"...\">` summarizing the Raadi homes article.\n- Implement `Article` or `NewsArticle` JSON-LD schema."}],"perfScore":81,"a11yScore":85,"bestPracticesScore":100,"seoScore":92,"securityScore":0},{"url":"https://gigainvesteeringud.giga.ee/test","overall":68,"reasoning":"Mobile PSI 87 is strong, but LCP 3.2s exceeds the 2.5s threshold. Security headers are completely missing (0/100), and the page returns a 404 status code, which is a critical SEO and availability failure. Accessibility has a serious color-contrast violation affecting 23+ navigation nodes. The `no-store` cache directive negates the benefit of the WP Rocket plugin detected in the HTML.","confidence":"high","fixes":[{"priority":1,"category":"SEO","title":"Resolve 404 Status Code","impact":"SEO, User Experience","problem":"W3C, PSI, and Browser Runtime all confirm the URL returns HTTP 404 (Page Not Found).","solution":"Ensure the target URL returns a 200 OK status if content is intended to be live. If this is a test page, do not index it (add `noindex` meta tag) or move it to a staging environment."},{"priority":2,"category":"Security","title":"Add Baseline Security Headers","impact":"Transport security, clickjacking, MIME sniffing","problem":"Security Headers grade is 0/100. HSTS, X-Frame-Options, and X-Content-Type-Options are missing.","solution":"Send the following headers from the server (Apache example):\n```\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\n```"},{"priority":2,"category":"Performance","title":"Enable Browser Caching","impact":"Repeat visit load time, TTFB","problem":"Cache-Control header is set to `no-store, no-cache, max-age=0`, preventing the browser from caching the document despite WP Rocket being active.","solution":"Update server configuration to allow caching for static assets and the document itself (e.g., `Cache-Control: public, max-age=31536000` for assets, `max-age=600` for HTML)."},{"priority":2,"category":"Accessibility","title":"Fix Color Contrast on Navigation","impact":"WCAG 1.4.3 Contrast","problem":"axe-core reports a serious color-contrast violation on 23+ nodes, including menu links like `.menu-item-543`.","solution":"Increase the contrast ratio of text against its background to at least 4.5:1. Adjust CSS for `.menu-item-543 > a` and similar classes."},{"priority":3,"category":"Security","title":"Implement Content Security Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing. Site signals indicate no auth, payments, or user content, lowering immediate risk but CSP remains best practice.","solution":"Deploy a strict CSP with nonces for scripts. Example:\n```\nContent-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\n```"}],"perfScore":87,"a11yScore":94,"bestPracticesScore":96,"seoScore":83,"securityScore":0},{"url":"https://gigainvesteeringud.giga.ee/meist","overall":68,"reasoning":"Mobile performance (73) is dragged down significantly by an LCP of 5.8 s, which exceeds the 4 s heavy penalty threshold despite an excellent TTFB of 3 ms. Security headers are critically absent (0/100 grade), missing baseline protections like HSTS and X-Frame-Options. Accessibility is mostly sound but includes one serious color-contrast violation on navigation links. HTML validation shows 9 errors primarily related to invalid srcset attributes, and SEO metadata (description, OG tags) is missing. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Optimize Largest Contentful Paint (LCP)","impact":"LCP, FCP, Mobile Performance Score","problem":"Mobile LCP is 5.8 s (heavy penalty), while TTFB is excellent at 3 ms, indicating render-blocking or resource delivery issues after the server responds.","solution":"- Identify the LCP element (likely the hero SVG or text) and preload it.\n- Ensure the LCP image is not lazy-loaded.\n- Minimize main-thread work; check if the 23 KB unused JS can be deferred further.\n- Use `<link rel=\"preload\">` for the LCP resource if it is an image or font."},{"priority":2,"category":"Security","title":"Implement Baseline Security Headers","impact":"Transport security, clickjacking protection, MIME sniffing","problem":"Security Headers grade is 0/100; HSTS, X-Frame-Options, and X-Content-Type-Options are missing despite HTTPS being active.","solution":"Add the following headers to the server configuration (Apache example):\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Accessibility","title":"Fix Color Contrast on Navigation Links","impact":"WCAG 1.4.3 (Contrast), Accessibility Score","problem":"axe-core reports 1 serious violation: multiple menu links (e.g., `.menu-item-543 > a`) fail minimum contrast ratios.","solution":"- Increase text color luminance or darken background for affected links.\n- Target a contrast ratio of at least 4.5:1 for normal text.\n- Verify changes with a contrast checker tool before deployment."},{"priority":3,"category":"SEO","title":"Add Meta Description and Open Graph Tags","impact":"Search snippet quality, Social sharing","problem":"HTML Inventory shows no meta description, no Open Graph tags, and no Twitter tags; PSI SEO audit flags `metaDescription` as failing.","solution":"Add to `<head>`:\n```html\n<meta name=\"description\" content=\"Giga Investeeringud on ambitsioonikas äri- ja elamukinnisvara arendaja.\">\n<meta property=\"og:title\" content=\"Meist - Giga Investeeringud\">\n<meta property=\"og:description\" content=\"...\">\n<meta property=\"og:image\" content=\"/path/to/og-image.jpg\">\n```"},{"priority":3,"category":"Best Practices","title":"Fix W3C srcset Width Errors","impact":"HTML Validity, Image Rendering","problem":"W3C Validator reports 7 errors where `srcset` attributes lack width descriptors (e.g., `100w`) while `sizes` is present.","solution":"Update `<img>` tags to include width descriptors in `srcset`:\n```html\n<!-- Incorrect -->\n<img srcset=\"/img.svg\" sizes=\"100vw\">\n\n<!-- Correct -->\n<img srcset=\"/img.svg 100w\" sizes=\"100vw\">\n```"},{"priority":3,"category":"Security","title":"Consider Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing. Site signals indicate no auth, payments, or user content, lowering immediate risk but CSP remains a best practice.","solution":"If user content or login is added later, deploy a nonce-based CSP:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'\"\n```\nFor now, prioritize P1/P2 fixes."}],"perfScore":73,"a11yScore":89,"bestPracticesScore":100,"seoScore":92,"securityScore":0},{"url":"https://gigainvesteeringud.giga.ee/kinnitus","overall":76,"reasoning":"PSI mobile performance is excellent (97, LCP 1.9s), but the Security Headers grade is 0/100 (missing HSTS, X-Content-Type-Options, etc.), which heavily impacts the security budget. Accessibility has a serious color-contrast violation on menu links and failing button-name audits. SEO is weakened by missing meta descriptions and structured data. Confidence is high as all tools returned data, though PSI reported 0 DOM nodes which contradicts the 50KB HTML inventory.","confidence":"high","fixes":[{"priority":1,"category":"Accessibility","title":"Fix color contrast on navigation links","impact":"WCAG 1.4.3 compliance, screen reader usability","problem":"axe-core flagged 1 serious violation for color-contrast on menu items (e.g., .menu-item-543).","solution":"Increase contrast ratio to at least 4.5:1 for normal text. Adjust link colors or background to meet WCAG AA standards."},{"priority":2,"category":"Security","title":"Add baseline security headers (HSTS, X-Content-Type-Options, X-Frame-Options)","impact":"Transport security, clickjacking protection, MIME sniffing","problem":"Security Headers grade is 0/100; HSTS, X-Content-Type-Options, and X-Frame-Options are missing.","solution":"Configure server to send:\n```\nStrict-Transport-Security: max-age=63072000; includeSubDomains\nX-Content-Type-Options: nosniff\nX-Frame-Options: SAMEORIGIN\n```"},{"priority":2,"category":"Accessibility","title":"Provide accessible names for buttons","impact":"WCAG 4.1.2 Name, Role, Value","problem":"PSI failing audit `button-name` (score 0.00) indicates buttons lack accessible names.","solution":"Ensure all `<button>` elements have visible text or `aria-label` attributes describing their action."},{"priority":2,"category":"SEO","title":"Add meta description and structured data","impact":"Search snippet quality, rich results eligibility","problem":"PSI SEO audit fails `metaDescription` and `structuredData`; HTML Inventory confirms no meta description or JSON-LD.","solution":"Add `<meta name=\"description\" content=\"...\">` and implement relevant JSON-LD (e.g., Organization or WebPage)."},{"priority":3,"category":"Security","title":"Implement Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing. Site signals indicate no auth/payments, so risk is lower, but CSP is still best practice.","solution":"Deploy a restrictive CSP with nonces for scripts:\n```\nContent-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\n```"}],"perfScore":97,"a11yScore":94,"bestPracticesScore":100,"seoScore":92,"securityScore":0}]}