# Audit Report: Viga 401 - Error 401 | Veebimajutus.ee **Website:** https://gotoand.dev/larsen **Date:** 2026-07-09 **Overall Score:** 25 / 100 **Status:** 🔴 **Critical** **Confidence:** high **Audit Coverage:** 100% — all sources returned data ## Summary The site returns a 401 Unauthorized status, making content inaccessible to the public, which is a core functional failure. Security headers are completely missing (0/100) and HTTP does not redirect to HTTPS, creating significant security exposure. Accessibility has 1 serious color-contrast violation and missing landmarks. Performance is strong (PSI 94) but irrelevant if the site is locked. SEO basics are missing. ## PageSpeed Insights — Mobile vs Desktop _Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._ | Strategy | Performance (M / D) | LCP (M / D) | CLS (M / D) | | --- | --- | --- | --- | | Mobile vs Desktop | **94** / 100 | **2.47 s** / 687 ms | **0.002** / 0.000 | ## Optimization Checklist **1 of 3 passing** — 1 pass · 1 warn · 1 fail · 4 n/a | Item | Status | Detail | | --- | --- | --- | | Page caching plugin / CDN active | **Fail** | No WordPress cache plugin marker or CDN edge cache detected on the document response. | | Images lazy-loaded | **Pass** | All raster images use loading="lazy". | | Hero image eagerly loaded | **Warn** | Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP. | | Hero is a real (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. | | Responsive images (srcset / ) | N/A | Only 1 raster image on the page — responsive-image rule does not apply. | | Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. | | JS scripts not blocking in | N/A | No external scripts on the page. | ## Fixes ### Priority 1: Critical *Immediate action — impacts user experience, search rankings, or site safety.* **1A. Resolve 401 Unauthorized Status** - **Impact:** Core functionality, Public Access - **Problem:** W3C and Security Headers report HTTP status 401; page is blocked from public access. - **Solution:** Remove authentication requirements for this URL or configure the server to return 200 OK for public visitors. If this is a private resource, ensure it is not indexed or linked publicly. **1B. Enforce HTTPS Redirect** - **Impact:** Transport Security - **Problem:** Security Headers report 'http://gotoand.dev/larsen does not redirect to HTTPS'. - **Solution:** Configure the web server (Apache/Nginx) to redirect all HTTP traffic to HTTPS: ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` ### Priority 2: Important *Essential for compliance, user reach, and search visibility.* **2A. Add Security Headers (HSTS, X-Frame-Options, CSP)** - **Impact:** Security Headers Grade (0/100) - **Problem:** Missing HSTS, X-Content-Type-Options, X-Frame-Options, and CSP. Grade is 0/100. - **Solution:** Add headers to server config: ```apache Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" Header always set X-Frame-Options "SAMEORIGIN" Header always set X-Content-Type-Options "nosniff" ``` **2B. Fix Color Contrast and Landmarks** - **Impact:** Accessibility (axe-core 3 violations) - **Problem:** Serious color-contrast violation on navigation links; missing main landmark and skip link. - **Solution:** - Increase contrast ratio to ≥4.5:1 for `.navbar-nav > a` links. - Wrap main content in `
` and navigation in `