# Audit Report: Kawiare - Experience of Taste
**Website:** https://kawiare.ee/
**Date:** 2026-07-07
**Overall Score:** 61 / 100
**Status:** π‘ **Needs Improvement**
**Confidence:** high
**Audit Coverage:** 100% β all sources returned data
**Pages Audited (10 of 10):**
- https://kawiare.ee/
- https://kawiare.ee/artiklid
- https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja
- https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta
- https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga
- https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari
- https://kawiare.ee/kammkarp
- https://kawiare.ee/ahven-ja-koha
- https://kawiare.ee/lumekrabi
- https://kawiare.ee/kaaviar-tanapaeval
## Summary
Site overall 61 is the mean of 10 pages. Scores range 42 (https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta) β 72 (https://kawiare.ee/lumekrabi). Weakest page: Mobile performance is critically low (61) with LCP 8.5s and FCP 4.6s, driven by 11 render-blocking scripts. Security configuration is weak (40/100) with HTTP not redirecting to HTTPS, creating a downgrade risk. Accessibility has 1 serious contrast violation and missing skip-link despite high PSI score. SEO lacks a meta description and has W3C errors. Confidence is high due to complete data coverage.
## Per-Page Scores
| Page | Score | Status | Confidence |
| --- | --- | --- | --- |
| https://kawiare.ee/ | 55 | π **Poor** | high |
| https://kawiare.ee/artiklid | 63 | π‘ **Needs Improvement** | high |
| https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja | 72 | π‘ **Needs Improvement** | high |
| https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta | 42 | π **Poor** | high |
| https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga | 65 | π‘ **Needs Improvement** | high |
| https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari | 55 | π **Poor** | high |
| https://kawiare.ee/kammkarp | 68 | π‘ **Needs Improvement** | high |
| https://kawiare.ee/ahven-ja-koha | 58 | π **Poor** | high |
| https://kawiare.ee/lumekrabi | 72 | π‘ **Needs Improvement** | high |
| https://kawiare.ee/kaaviar-tanapaeval | 58 | π **Poor** | high |
## PageSpeed Insights β Mobile vs Desktop
_Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._
| URL | Performance (M / D) | LCP (M / D) | CLS (M / D) |
| --- | --- | --- | --- |
| https://kawiare.ee/ | **44** / 72 | **9.77 s** / 1.52 s | **1.000** / 0.637 |
| https://kawiare.ee/artiklid | **67** / 93 | **10.28 s** / 1.73 s | 0.001 / **0.001** |
| https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja | **71** / 92 | **6.56 s** / 1.72 s | 0.000 / **0.000** |
| https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta | **61** / 93 | **8.49 s** / 1.69 s | 0.000 / **0.000** |
| https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga | **60** / 93 | **8.89 s** / 1.62 s | 0.000 / **0.000** |
| https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari | **68** / 93 | **8.71 s** / 1.65 s | 0.000 / **0.000** |
| https://kawiare.ee/kammkarp | **71** / 95 | **7.22 s** / 1.49 s | 0.000 / **0.000** |
| https://kawiare.ee/ahven-ja-koha | **67** / 93 | **9.44 s** / 1.62 s | 0.000 / **0.000** |
| https://kawiare.ee/lumekrabi | **70** / 94 | **7.23 s** / 1.58 s | 0.000 / **0.000** |
| https://kawiare.ee/kaaviar-tanapaeval | **61** / 99 | **8.36 s** / 926 ms | 0.000 / **0.000** |
## Optimization Checklist
**4 of 7 passing** β 4 pass Β· 2 warn Β· 1 fail
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | **Pass** | All raster images use loading="lazy". |
| Hero image eagerly loaded | **Pass** | Hero image is eagerly loaded (inferred from DOM order/size β Lighthouse LCP element unavailable). |
| Hero is a real (not a CSS background-image) | **Warn** | Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport β there is no srcset equivalent. Move the hero to a real with srcset/sizes (or ) so smaller viewports can fetch a smaller file. |
| Responsive images (srcset / ) | **Warn** | Only 15/22 raster images use srcset or (68%). |
| Reasonable number of image sizes | **Pass** | 17 distinct srcset widths. |
| JS scripts not blocking in | **Fail** | 5 render-blocking scripts in . Move to footer or add defer/async. |
## Fixes
### Priority 1: Critical
*Immediate action β impacts user experience, search rankings, or site safety.*
**1A. Fix Mobile LCP and CLS**
- **Impact:** LCP, CLS, Performance Score
- **Problem:** Mobile LCP is 9.8s (threshold 2.5s) and CLS is 1.0 (threshold 0.1), causing a Performance score of 44.
- **Solution:**
1. Preload the LCP image (hero) with ``.
2. Reserve space for dynamic content to prevent CLS (add width/height or aspect-ratio CSS).
3. Convert hero PNG to WebP/AVIF to reduce 1.46 MB image weight.
**1B. Defer Render-Blocking JavaScript**
- **Impact:** FCP, TBT, Performance Score
- **Problem:** 11 render-blocking scripts (including jQuery and WooCommerce) delay FCP to 1.99s and contribute to LCP delay.
- **Solution:**
Add `defer` or `async` to non-critical scripts in ``:
```html
```
Move WooCommerce frontend scripts to footer if not needed for initial paint.
**1C. Force HTTPS Redirect**
- **Impact:** Security, Transport Layer
- **Problem:** Security Headers audit reports 'http://kawiare.ee/artiklid does not redirect to HTTPS', leaving users vulnerable to downgrade attacks.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1D. Optimize Largest Contentful Paint (LCP)**
- **Impact:** Performance, Mobile UX
- **Problem:** Mobile LCP is 10.3 s (target β€2.5 s), caused by 16 render-blocking scripts and a hero image loaded via CSS background.
- **Solution:**
- Move non-critical scripts to `defer` or `async` (16 currently blocking).
- Replace CSS background hero with a real `` or `` element with `fetchpriority="high"`.
- Inline critical CSS and defer the rest.
**1E. Enforce HTTPS Redirect**
- **Impact:** Security, Transport Layer
- **Problem:** Security Headers audit shows http://kawiare.ee/... does not redirect to HTTPS, leaving users vulnerable to MITM attacks on unencrypted connections.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS.
**Apache (.htaccess):**
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1F. Eliminate Render-Blocking JavaScript**
- **Impact:** LCP, FCP, Performance
- **Problem:** 11 render-blocking scripts identified in HTML Inventory; LCP is 8.5s and FCP is 4.6s on mobile.
- **Solution:**
Add `defer` or `async` to non-critical scripts in ``. Move critical CSS inline and defer JS execution.
```html
```
**1G. Force HTTPS redirect on HTTP requests**
- **Impact:** Security, Transport Layer
- **Problem:** Security Headers audit reports 'http://kawiare.ee/... does not redirect to HTTPS', leaving users on unencrypted connections if they type http.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests.
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1H. Reduce render-blocking JavaScript to improve LCP**
- **Impact:** LCP, FCP, Mobile Performance
- **Problem:** Mobile LCP is 8.9 s; HTML Inventory identifies 11 render-blocking scripts (5 in ), including main.js and jQuery.
- **Solution:**
Add `defer` or `async` to non-critical scripts. Move critical CSS inline and defer JS execution.
```html
```
### Priority 2: Important
*Essential for compliance, user reach, and search visibility.*
**2A. Strengthen Security Headers**
- **Impact:** Security Score, XSS Protection
- **Problem:** Security Headers grade is 40/100; CSP is missing despite WooCommerce assets indicating potential cart data exposure.
- **Solution:**
Add Content-Security-Policy (nonce-based) and HSTS preload:
```
Content-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
```
**2B. Fix Accessibility Structure and Contrast**
- **Impact:** WCAG Compliance, Screen Reader Usability
- **Problem:** HTML Inventory shows 3 `
` elements and missing skip-link; axe-core found 1 serious contrast violation on `#cookiescript_accept`.
- **Solution:**
1. Ensure only one `
` per page.
2. Add `Skip to content`.
3. Increase contrast on cookie accept button to 4.5:1 ratio.
**2C. Fix Accessibility Violations**
- **Impact:** WCAG Compliance, SEO
- **Problem:** axe-core reports 1 serious color-contrast violation (#cookiescript_accept) and 1 moderate heading-order violation (h1βh3 skip).
- **Solution:**
- Increase contrast on `.cookiescript_accept` to β₯4.5:1 ratio.
- Insert an `
` between the `
` and `
` elements to maintain sequential heading levels.
**2D. Eliminate Render-Blocking JavaScript**
- **Impact:** FCP, TBT, Performance
- **Problem:** 11 render-blocking scripts found in HTML Inventory; 5 specifically in `` per Optimization Checklist.
- **Solution:**
Add `defer` or `async` to script tags that do not need to execute before DOM parsing.
**Example:**
```html
```
**2E. Strengthen HSTS Configuration**
- **Impact:** Security, Transport Layer
- **Problem:** HSTS is present but missing the `preload` directive, preventing inclusion in browser preload lists.
- **Solution:**
Update the `Strict-Transport-Security` header to include `preload`.
**Header:**
`Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`
**2F. Fix color contrast on cookie consent button**
- **Impact:** Accessibility (WCAG 1.4.3)
- **Problem:** axe-core reports 1 serious violation on `#cookiescript_accept` for insufficient color contrast.
- **Solution:**
Increase contrast ratio to at least 4.5:1 for text on the button. Test with a contrast checker tool and adjust CSS colors.
**2G. Fix Render-Blocking Scripts**
- **Impact:** FCP, TBT, Performance
- **Problem:** 11 render-blocking scripts detected in , including jQuery and WooCommerce assets, delaying first paint.
- **Solution:**
Move scripts to the footer or add `defer`/`async` attributes:
```html
```
**2H. Defer Render-Blocking Scripts**
- **Impact:** FCP, LCP, TBT
- **Problem:** 11 render-blocking external scripts detected in , delaying first paint and increasing TBT.
- **Solution:**
Add `defer` or `async` to non-critical scripts in the ``:
```html
```
Move non-essential scripts to the footer or use a plugin to optimize script loading order.
**2I. Fix Color Contrast Violation**
- **Impact:** Accessibility (WCAG 1.4.3)
- **Problem:** Serious axe violation on `#cookiescript_accept` element fails minimum contrast ratio thresholds.
- **Solution:**
Adjust the text color or background color of the cookie consent button to achieve a contrast ratio of at least 4.5:1. Use a tool like WebAIM Contrast Checker to verify.
**2J. Implement Content Security Policy (CSP)**
- **Impact:** Security, XSS Defense
- **Problem:** CSP is missing. WooCommerce scripts detected in HTML inventory suggest e-commerce capability, raising XSS risk despite inferred signals.
- **Solution:**
Deploy a strict CSP with nonce/hash for scripts:
```apache
Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';"
```
**2K. Fix Color Contrast on Cookie Button**
- **Impact:** Accessibility (WCAG 1.4.3)
- **Problem:** Axe reports serious contrast violation on `#cookiescript_accept`.
- **Solution:**
Increase contrast ratio to β₯4.5:1. Adjust background or text color in CSS:
```css
#cookiescript_accept { color: #333; background: #f0f0f0; }
```
**2L. Add Meta Description**
- **Impact:** SEO, Click-Through Rate
- **Problem:** PSI SEO audit fails `metaDescription`; document lacks summary.
- **Solution:**
Add a unique description tag (150-160 chars) in ``:
```html
```
**2M. Fix Color Contrast on Cookie Banner**
- **Impact:** Accessibility (WCAG 1.4.3)
- **Problem:** Serious axe-core violation: `#cookiescript_accept` fails minimum contrast ratio thresholds.
- **Solution:**
Increase contrast between text and background on the cookie accept button.
**CSS:**
```css
#cookiescript_accept {
color: #333333; /* Darker text */
background-color: #ffffff;
}
```
### Priority 3: Best Practice
*Recommended for long-term maintainability.*
**3A. Add Meta Description and Lazy Load Remaining Images**
- **Impact:** SEO, Page Weight
- **Problem:** SEO audit fails `metaDescription`; 6 images below the fold lack `loading="lazy"`.
- **Solution:**
1. Add ``.
2. Add `loading="lazy"` to all images not in the viewport:
```html
```
**3B. Add Content Security Policy (CSP)**
- **Impact:** XSS Defense-in-Depth
- **Problem:** CSP is missing. Site signals indicate no auth/payments, so risk is lower, but CSP remains a best practice for content integrity.
- **Solution:**
Implement a strict CSP with nonce-based script execution:
```apache
Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';"
```
**3C. Fix Accessibility Contrast & SEO Meta**
- **Impact:** Accessibility, SEO
- **Problem:** axe-core reports 1 serious color-contrast violation on `#cookiescript_accept`. Meta description is missing (SEO score 92).
- **Solution:**
1. **Contrast:** Increase text color contrast on `#cookiescript_accept` to meet WCAG AA (4.5:1).
2. **Meta:** Add a `` tag summarizing the article content.
**3D. Add Meta Description**
- **Impact:** SEO, Click-Through Rate
- **Problem:** HTML Inventory shows meta description is not set; W3C validator reports SEO failing audit.
- **Solution:**
Add a unique meta description tag (150-160 characters) summarizing the article content.
```html
```
**3E. Add meta description for SEO**
- **Impact:** Search Visibility, CTR
- **Problem:** PSI and HTML Inventory confirm 'metaDescription' is missing; document has no meta description tag.
- **Solution:**
Add a concise meta description (150β160 characters) summarizing the article content.
```html
```
**3F. Implement Content Security Policy (CSP)**
- **Impact:** XSS Defense-in-Depth
- **Problem:** CSP is missing. Site signals indicate no auth, payments, or user content, lowering immediate risk but CSP remains a best practice.
- **Solution:**
Deploy a strict CSP with nonces for scripts. Since the site is brochure/blog focused, a strict allowlist is less critical than on an app, but recommended for defense-in-depth.
```apache
Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';"
```
**3G. Add Meta Description and Fix Landmarks**
- **Impact:** SEO, Accessibility
- **Problem:** SEO audit flags missing meta description; axe-core reports duplicate main landmarks and missing skip-to-content link.
- **Solution:**
- Add ``.
- Add `Skip to content`.
- Ensure only one `` element exists in the DOM.
**3H. Implement Content Security Policy**
- **Impact:** XSS Defense-in-Depth
- **Problem:** CSP is missing. Site signals show no auth/payments, so risk is lower, but defense is recommended.
- **Solution:**
Deploy a strict CSP with nonce/hash for scripts:
```apache
Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';"
```