# Audit Report: Kawiare - Experience of Taste **Website:** https://kawiare.ee/ **Date:** 2026-07-07 **Overall Score:** 61 / 100 **Status:** 🟑 **Needs Improvement** **Confidence:** high **Audit Coverage:** 100% β€” all sources returned data **Pages Audited (10 of 10):** - https://kawiare.ee/ - https://kawiare.ee/artiklid - https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja - https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta - https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga - https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari - https://kawiare.ee/kammkarp - https://kawiare.ee/ahven-ja-koha - https://kawiare.ee/lumekrabi - https://kawiare.ee/kaaviar-tanapaeval ## Summary Site overall 61 is the mean of 10 pages. Scores range 42 (https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta) β†’ 72 (https://kawiare.ee/lumekrabi). Weakest page: Mobile performance is critically low (61) with LCP 8.5s and FCP 4.6s, driven by 11 render-blocking scripts. Security configuration is weak (40/100) with HTTP not redirecting to HTTPS, creating a downgrade risk. Accessibility has 1 serious contrast violation and missing skip-link despite high PSI score. SEO lacks a meta description and has W3C errors. Confidence is high due to complete data coverage. ## Per-Page Scores | Page | Score | Status | Confidence | | --- | --- | --- | --- | | https://kawiare.ee/ | 55 | 🟠 **Poor** | high | | https://kawiare.ee/artiklid | 63 | 🟑 **Needs Improvement** | high | | https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja | 72 | 🟑 **Needs Improvement** | high | | https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta | 42 | 🟠 **Poor** | high | | https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga | 65 | 🟑 **Needs Improvement** | high | | https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari | 55 | 🟠 **Poor** | high | | https://kawiare.ee/kammkarp | 68 | 🟑 **Needs Improvement** | high | | https://kawiare.ee/ahven-ja-koha | 58 | 🟠 **Poor** | high | | https://kawiare.ee/lumekrabi | 72 | 🟑 **Needs Improvement** | high | | https://kawiare.ee/kaaviar-tanapaeval | 58 | 🟠 **Poor** | high | ## PageSpeed Insights β€” Mobile vs Desktop _Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._ | URL | Performance (M / D) | LCP (M / D) | CLS (M / D) | | --- | --- | --- | --- | | https://kawiare.ee/ | **44** / 72 | **9.77 s** / 1.52 s | **1.000** / 0.637 | | https://kawiare.ee/artiklid | **67** / 93 | **10.28 s** / 1.73 s | 0.001 / **0.001** | | https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja | **71** / 92 | **6.56 s** / 1.72 s | 0.000 / **0.000** | | https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta | **61** / 93 | **8.49 s** / 1.69 s | 0.000 / **0.000** | | https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga | **60** / 93 | **8.89 s** / 1.62 s | 0.000 / **0.000** | | https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari | **68** / 93 | **8.71 s** / 1.65 s | 0.000 / **0.000** | | https://kawiare.ee/kammkarp | **71** / 95 | **7.22 s** / 1.49 s | 0.000 / **0.000** | | https://kawiare.ee/ahven-ja-koha | **67** / 93 | **9.44 s** / 1.62 s | 0.000 / **0.000** | | https://kawiare.ee/lumekrabi | **70** / 94 | **7.23 s** / 1.58 s | 0.000 / **0.000** | | https://kawiare.ee/kaaviar-tanapaeval | **61** / 99 | **8.36 s** / 926 ms | 0.000 / **0.000** | ## Optimization Checklist **4 of 7 passing** β€” 4 pass Β· 2 warn Β· 1 fail | Item | Status | Detail | | --- | --- | --- | | Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) | | Images lazy-loaded | **Pass** | All raster images use loading="lazy". | | Hero image eagerly loaded | **Pass** | Hero image is eagerly loaded (inferred from DOM order/size β€” Lighthouse LCP element unavailable). | | Hero is a real (not a CSS background-image) | **Warn** | Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport β€” there is no srcset equivalent. Move the hero to a real with srcset/sizes (or ) so smaller viewports can fetch a smaller file. | | Responsive images (srcset / ) | **Warn** | Only 15/22 raster images use srcset or (68%). | | Reasonable number of image sizes | **Pass** | 17 distinct srcset widths. | | JS scripts not blocking in | **Fail** | 5 render-blocking scripts in . Move to footer or add defer/async. | ## Fixes ### Priority 1: Critical *Immediate action β€” impacts user experience, search rankings, or site safety.* **1A. Fix Mobile LCP and CLS** - **Impact:** LCP, CLS, Performance Score - **Problem:** Mobile LCP is 9.8s (threshold 2.5s) and CLS is 1.0 (threshold 0.1), causing a Performance score of 44. - **Solution:** 1. Preload the LCP image (hero) with ``. 2. Reserve space for dynamic content to prevent CLS (add width/height or aspect-ratio CSS). 3. Convert hero PNG to WebP/AVIF to reduce 1.46 MB image weight. **1B. Defer Render-Blocking JavaScript** - **Impact:** FCP, TBT, Performance Score - **Problem:** 11 render-blocking scripts (including jQuery and WooCommerce) delay FCP to 1.99s and contribute to LCP delay. - **Solution:** Add `defer` or `async` to non-critical scripts in ``: ```html ``` Move WooCommerce frontend scripts to footer if not needed for initial paint. **1C. Force HTTPS Redirect** - **Impact:** Security, Transport Layer - **Problem:** Security Headers audit reports 'http://kawiare.ee/artiklid does not redirect to HTTPS', leaving users vulnerable to downgrade attacks. - **Solution:** Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS: ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1D. Optimize Largest Contentful Paint (LCP)** - **Impact:** Performance, Mobile UX - **Problem:** Mobile LCP is 10.3 s (target ≀2.5 s), caused by 16 render-blocking scripts and a hero image loaded via CSS background. - **Solution:** - Move non-critical scripts to `defer` or `async` (16 currently blocking). - Replace CSS background hero with a real `` or `` element with `fetchpriority="high"`. - Inline critical CSS and defer the rest. **1E. Enforce HTTPS Redirect** - **Impact:** Security, Transport Layer - **Problem:** Security Headers audit shows http://kawiare.ee/... does not redirect to HTTPS, leaving users vulnerable to MITM attacks on unencrypted connections. - **Solution:** Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS. **Apache (.htaccess):** ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1F. Eliminate Render-Blocking JavaScript** - **Impact:** LCP, FCP, Performance - **Problem:** 11 render-blocking scripts identified in HTML Inventory; LCP is 8.5s and FCP is 4.6s on mobile. - **Solution:** Add `defer` or `async` to non-critical scripts in ``. Move critical CSS inline and defer JS execution. ```html ``` **1G. Force HTTPS redirect on HTTP requests** - **Impact:** Security, Transport Layer - **Problem:** Security Headers audit reports 'http://kawiare.ee/... does not redirect to HTTPS', leaving users on unencrypted connections if they type http. - **Solution:** Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests. ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1H. Reduce render-blocking JavaScript to improve LCP** - **Impact:** LCP, FCP, Mobile Performance - **Problem:** Mobile LCP is 8.9 s; HTML Inventory identifies 11 render-blocking scripts (5 in ), including main.js and jQuery. - **Solution:** Add `defer` or `async` to non-critical scripts. Move critical CSS inline and defer JS execution. ```html ``` ### Priority 2: Important *Essential for compliance, user reach, and search visibility.* **2A. Strengthen Security Headers** - **Impact:** Security Score, XSS Protection - **Problem:** Security Headers grade is 40/100; CSP is missing despite WooCommerce assets indicating potential cart data exposure. - **Solution:** Add Content-Security-Policy (nonce-based) and HSTS preload: ``` Content-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; Strict-Transport-Security: max-age=63072000; includeSubDomains; preload ``` **2B. Fix Accessibility Structure and Contrast** - **Impact:** WCAG Compliance, Screen Reader Usability - **Problem:** HTML Inventory shows 3 `

` elements and missing skip-link; axe-core found 1 serious contrast violation on `#cookiescript_accept`. - **Solution:** 1. Ensure only one `

` per page. 2. Add ``. 3. Increase contrast on cookie accept button to 4.5:1 ratio. **2C. Fix Accessibility Violations** - **Impact:** WCAG Compliance, SEO - **Problem:** axe-core reports 1 serious color-contrast violation (#cookiescript_accept) and 1 moderate heading-order violation (h1β†’h3 skip). - **Solution:** - Increase contrast on `.cookiescript_accept` to β‰₯4.5:1 ratio. - Insert an `

` between the `

` and `

` elements to maintain sequential heading levels. **2D. Eliminate Render-Blocking JavaScript** - **Impact:** FCP, TBT, Performance - **Problem:** 11 render-blocking scripts found in HTML Inventory; 5 specifically in `` per Optimization Checklist. - **Solution:** Add `defer` or `async` to script tags that do not need to execute before DOM parsing. **Example:** ```html ``` **2E. Strengthen HSTS Configuration** - **Impact:** Security, Transport Layer - **Problem:** HSTS is present but missing the `preload` directive, preventing inclusion in browser preload lists. - **Solution:** Update the `Strict-Transport-Security` header to include `preload`. **Header:** `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload` **2F. Fix color contrast on cookie consent button** - **Impact:** Accessibility (WCAG 1.4.3) - **Problem:** axe-core reports 1 serious violation on `#cookiescript_accept` for insufficient color contrast. - **Solution:** Increase contrast ratio to at least 4.5:1 for text on the button. Test with a contrast checker tool and adjust CSS colors. **2G. Fix Render-Blocking Scripts** - **Impact:** FCP, TBT, Performance - **Problem:** 11 render-blocking scripts detected in , including jQuery and WooCommerce assets, delaying first paint. - **Solution:** Move scripts to the footer or add `defer`/`async` attributes: ```html ``` **2H. Defer Render-Blocking Scripts** - **Impact:** FCP, LCP, TBT - **Problem:** 11 render-blocking external scripts detected in , delaying first paint and increasing TBT. - **Solution:** Add `defer` or `async` to non-critical scripts in the ``: ```html ``` Move non-essential scripts to the footer or use a plugin to optimize script loading order. **2I. Fix Color Contrast Violation** - **Impact:** Accessibility (WCAG 1.4.3) - **Problem:** Serious axe violation on `#cookiescript_accept` element fails minimum contrast ratio thresholds. - **Solution:** Adjust the text color or background color of the cookie consent button to achieve a contrast ratio of at least 4.5:1. Use a tool like WebAIM Contrast Checker to verify. **2J. Implement Content Security Policy (CSP)** - **Impact:** Security, XSS Defense - **Problem:** CSP is missing. WooCommerce scripts detected in HTML inventory suggest e-commerce capability, raising XSS risk despite inferred signals. - **Solution:** Deploy a strict CSP with nonce/hash for scripts: ```apache Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';" ``` **2K. Fix Color Contrast on Cookie Button** - **Impact:** Accessibility (WCAG 1.4.3) - **Problem:** Axe reports serious contrast violation on `#cookiescript_accept`. - **Solution:** Increase contrast ratio to β‰₯4.5:1. Adjust background or text color in CSS: ```css #cookiescript_accept { color: #333; background: #f0f0f0; } ``` **2L. Add Meta Description** - **Impact:** SEO, Click-Through Rate - **Problem:** PSI SEO audit fails `metaDescription`; document lacks summary. - **Solution:** Add a unique description tag (150-160 chars) in ``: ```html ``` **2M. Fix Color Contrast on Cookie Banner** - **Impact:** Accessibility (WCAG 1.4.3) - **Problem:** Serious axe-core violation: `#cookiescript_accept` fails minimum contrast ratio thresholds. - **Solution:** Increase contrast between text and background on the cookie accept button. **CSS:** ```css #cookiescript_accept { color: #333333; /* Darker text */ background-color: #ffffff; } ``` ### Priority 3: Best Practice *Recommended for long-term maintainability.* **3A. Add Meta Description and Lazy Load Remaining Images** - **Impact:** SEO, Page Weight - **Problem:** SEO audit fails `metaDescription`; 6 images below the fold lack `loading="lazy"`. - **Solution:** 1. Add ``. 2. Add `loading="lazy"` to all images not in the viewport: ```html ... ``` **3B. Add Content Security Policy (CSP)** - **Impact:** XSS Defense-in-Depth - **Problem:** CSP is missing. Site signals indicate no auth/payments, so risk is lower, but CSP remains a best practice for content integrity. - **Solution:** Implement a strict CSP with nonce-based script execution: ```apache Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';" ``` **3C. Fix Accessibility Contrast & SEO Meta** - **Impact:** Accessibility, SEO - **Problem:** axe-core reports 1 serious color-contrast violation on `#cookiescript_accept`. Meta description is missing (SEO score 92). - **Solution:** 1. **Contrast:** Increase text color contrast on `#cookiescript_accept` to meet WCAG AA (4.5:1). 2. **Meta:** Add a `` tag summarizing the article content. **3D. Add Meta Description** - **Impact:** SEO, Click-Through Rate - **Problem:** HTML Inventory shows meta description is not set; W3C validator reports SEO failing audit. - **Solution:** Add a unique meta description tag (150-160 characters) summarizing the article content. ```html ``` **3E. Add meta description for SEO** - **Impact:** Search Visibility, CTR - **Problem:** PSI and HTML Inventory confirm 'metaDescription' is missing; document has no meta description tag. - **Solution:** Add a concise meta description (150–160 characters) summarizing the article content. ```html ``` **3F. Implement Content Security Policy (CSP)** - **Impact:** XSS Defense-in-Depth - **Problem:** CSP is missing. Site signals indicate no auth, payments, or user content, lowering immediate risk but CSP remains a best practice. - **Solution:** Deploy a strict CSP with nonces for scripts. Since the site is brochure/blog focused, a strict allowlist is less critical than on an app, but recommended for defense-in-depth. ```apache Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';" ``` **3G. Add Meta Description and Fix Landmarks** - **Impact:** SEO, Accessibility - **Problem:** SEO audit flags missing meta description; axe-core reports duplicate main landmarks and missing skip-to-content link. - **Solution:** - Add ``. - Add ``. - Ensure only one `
` element exists in the DOM. **3H. Implement Content Security Policy** - **Impact:** XSS Defense-in-Depth - **Problem:** CSP is missing. Site signals show no auth/payments, so risk is lower, but defense is recommended. - **Solution:** Deploy a strict CSP with nonce/hash for scripts: ```apache Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';" ```