# Audit Report: Viga 401 - Error 401 | Veebimajutus.ee
**Website:** https://gotoand.dev/larsen
**Date:** 2026-06-30
**Overall Score:** 55 / 100
**Status:** ๐ **Poor**
**Confidence:** high
**Audit Coverage:** 100% โ all sources returned data
## Summary
PSI mobile 95 indicates fast delivery of the error page, but the 401 Unauthorized status makes the content inaccessible to the public. Security headers are completely absent (0/100), including HSTS and X-Frame-Options, which are critical baseline protections. Accessibility has one serious color-contrast violation and missing landmarks. SEO is weak with missing meta descriptions, canonical tags, and three
elements. The 401 status is the primary drag on the score despite high performance metrics.
## PageSpeed Insights โ Mobile vs Desktop
_Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._
| Strategy | Performance (M / D) | LCP (M / D) | CLS (M / D) |
| --- | --- | --- | --- |
| Mobile vs Desktop | **95** / 100 | **2.41 s** / 682 ms | **0.002** / 0.000 |
## Optimization Checklist
**1 of 3 passing** โ 1 pass ยท 1 warn ยท 1 fail ยท 4 n/a
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | **Fail** | No WordPress cache plugin marker or CDN edge cache detected on the document response. |
| Images lazy-loaded | **Pass** | All raster images use loading="lazy". |
| Hero image eagerly loaded | **Warn** | Hero image has no explicit loading or fetchpriority (inferred from DOM order/size โ Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP. |
| Hero is a real (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / ) | N/A | Only 1 raster image on the page โ responsive-image rule does not apply. |
| Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in | N/A | No external scripts on the page. |
## Fixes
### Priority 1: Critical
*Immediate action โ impacts user experience, search rankings, or site safety.*
**1A. Resolve 401 Unauthorized Status**
- **Impact:** Site accessibility, SEO indexing
- **Problem:** The page returns HTTP 401 Unauthorized (W3C error, PSI failing audit), preventing public access to content.
- **Solution:**
Check server configuration (Apache .htaccess or auth settings) to ensure the path `/larsen` is publicly accessible or redirect to a valid landing page. If authentication is required, implement a proper login flow rather than a raw 401 response.
**1B. Add Baseline Security Headers (HSTS, X-Frame-Options, X-Content-Type-Options)**
- **Impact:** Transport security, clickjacking, MIME sniffing
- **Problem:** Security Headers grade is 0/100; HSTS, X-Frame-Options, and X-Content-Type-Options are missing.
- **Solution:**
Configure server to send:
```
Strict-Transport-Security: max-age=63072000; includeSubDomains
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
```
**1C. Enforce HTTPS Redirect**
- **Impact:** Data encryption, security
- **Problem:** HTTP traffic does not redirect to HTTPS (http://gotoand.dev/larsen does not redirect).
- **Solution:**
Configure the web server (Apache/Nginx) to redirect all HTTP requests to HTTPS with a 301 status code.
### Priority 2: Important
*Essential for compliance, user reach, and search visibility.*
**2A. Fix Color Contrast and Landmarks**
- **Impact:** WCAG 1.4.3 contrast, 1.3.1 info/relationships
- **Problem:** axe-core reports 1 serious color-contrast violation and missing main/nav landmarks.
- **Solution:**
- Increase contrast ratio for `.navbar-nav` links to โฅ4.5:1.
- Wrap main content in ``, navigation in `