# Audit Report: Viga 401 - Error 401 | Veebimajutus.ee
**Website:** https://gotoand.dev/larsen
**Date:** 2026-07-09
**Overall Score:** 25 / 100
**Status:** 🔴 **Critical**
**Confidence:** high
**Audit Coverage:** 100% — all sources returned data
## Summary
The site returns a 401 Unauthorized status, making content inaccessible to the public, which is a core functional failure. Security headers are completely missing (0/100) and HTTP does not redirect to HTTPS, creating significant security exposure. Accessibility has 1 serious color-contrast violation and missing landmarks. Performance is strong (PSI 94) but irrelevant if the site is locked. SEO basics are missing.
## PageSpeed Insights — Mobile vs Desktop
_Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._
| Strategy | Performance (M / D) | LCP (M / D) | CLS (M / D) |
| --- | --- | --- | --- |
| Mobile vs Desktop | **94** / 100 | **2.47 s** / 687 ms | **0.002** / 0.000 |
## Optimization Checklist
**1 of 3 passing** — 1 pass · 1 warn · 1 fail · 4 n/a
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | **Fail** | No WordPress cache plugin marker or CDN edge cache detected on the document response. |
| Images lazy-loaded | **Pass** | All raster images use loading="lazy". |
| Hero image eagerly loaded | **Warn** | Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP. |
| Hero is a real (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / ) | N/A | Only 1 raster image on the page — responsive-image rule does not apply. |
| Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in | N/A | No external scripts on the page. |
## Fixes
### Priority 1: Critical
*Immediate action — impacts user experience, search rankings, or site safety.*
**1A. Resolve 401 Unauthorized Status**
- **Impact:** Core functionality, Public Access
- **Problem:** W3C and Security Headers report HTTP status 401; page is blocked from public access.
- **Solution:**
Remove authentication requirements for this URL or configure the server to return 200 OK for public visitors. If this is a private resource, ensure it is not indexed or linked publicly.
**1B. Enforce HTTPS Redirect**
- **Impact:** Transport Security
- **Problem:** Security Headers report 'http://gotoand.dev/larsen does not redirect to HTTPS'.
- **Solution:**
Configure the web server (Apache/Nginx) to redirect all HTTP traffic to HTTPS:
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
### Priority 2: Important
*Essential for compliance, user reach, and search visibility.*
**2A. Add Security Headers (HSTS, X-Frame-Options, CSP)**
- **Impact:** Security Headers Grade (0/100)
- **Problem:** Missing HSTS, X-Content-Type-Options, X-Frame-Options, and CSP. Grade is 0/100.
- **Solution:**
Add headers to server config:
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
Header always set X-Frame-Options "SAMEORIGIN"
Header always set X-Content-Type-Options "nosniff"
```
**2B. Fix Color Contrast and Landmarks**
- **Impact:** Accessibility (axe-core 3 violations)
- **Problem:** Serious color-contrast violation on navigation links; missing main landmark and skip link.
- **Solution:**
- Increase contrast ratio to ≥4.5:1 for `.navbar-nav > a` links.
- Wrap main content in `` and navigation in `