{"url":"https://kawiare.ee/","date":"2026-07-07","siteName":"Kawiare - Experience of Taste","overall":61,"reasoning":"Site overall 61 is the mean of 10 pages. Scores range 42 (https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta) → 72 (https://kawiare.ee/lumekrabi). Weakest page: Mobile performance is critically low (61) with LCP 8.5s and FCP 4.6s, driven by 11 render-blocking scripts. Security configuration is weak (40/100) with HTTP not redirecting to HTTPS, creating a downgrade risk. Accessibility has 1 serious contrast violation and missing skip-link despite high PSI score. SEO lacks a meta description and has W3C errors. Confidence is high due to complete data coverage.","confidence":"high","fixes":[{"priority":1,"title":"Fix Mobile LCP and CLS","impact":"LCP, CLS, Performance Score","problem":"Mobile LCP is 9.8s (threshold 2.5s) and CLS is 1.0 (threshold 0.1), causing a Performance score of 44.","solution":"1. Preload the LCP image (hero) with `<link rel=\"preload\" as=\"image\">`.\n2. Reserve space for dynamic content to prevent CLS (add width/height or aspect-ratio CSS).\n3. Convert hero PNG to WebP/AVIF to reduce 1.46 MB image weight."},{"priority":1,"title":"Defer Render-Blocking JavaScript","impact":"FCP, TBT, Performance Score","problem":"11 render-blocking scripts (including jQuery and WooCommerce) delay FCP to 1.99s and contribute to LCP delay.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`:\n```html\n<script src=\"...\" defer></script>\n```\nMove WooCommerce frontend scripts to footer if not needed for initial paint."},{"priority":1,"title":"Force HTTPS Redirect","impact":"Security, Transport Layer","problem":"Security Headers audit reports 'http://kawiare.ee/artiklid does not redirect to HTTPS', leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Performance, Mobile UX","problem":"Mobile LCP is 10.3 s (target ≤2.5 s), caused by 16 render-blocking scripts and a hero image loaded via CSS background.","solution":"- Move non-critical scripts to `defer` or `async` (16 currently blocking).\n- Replace CSS background hero with a real `<img>` or `<picture>` element with `fetchpriority=\"high\"`.\n- Inline critical CSS and defer the rest."},{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Transport Layer","problem":"Security Headers audit shows http://kawiare.ee/... does not redirect to HTTPS, leaving users vulnerable to MITM attacks on unencrypted connections.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS.\n\n**Apache (.htaccess):**\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Eliminate Render-Blocking JavaScript","impact":"LCP, FCP, Performance","problem":"11 render-blocking scripts identified in HTML Inventory; LCP is 8.5s and FCP is 4.6s on mobile.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Move critical CSS inline and defer JS execution.\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":1,"title":"Force HTTPS redirect on HTTP requests","impact":"Security, Transport Layer","problem":"Security Headers audit reports 'http://kawiare.ee/... does not redirect to HTTPS', leaving users on unencrypted connections if they type http.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests.\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Reduce render-blocking JavaScript to improve LCP","impact":"LCP, FCP, Mobile Performance","problem":"Mobile LCP is 8.9 s; HTML Inventory identifies 11 render-blocking scripts (5 in <head>), including main.js and jQuery.","solution":"Add `defer` or `async` to non-critical scripts. Move critical CSS inline and defer JS execution.\n```html\n<script src=\"main.js\" defer></script>\n```"},{"priority":2,"title":"Strengthen Security Headers","impact":"Security Score, XSS Protection","problem":"Security Headers grade is 40/100; CSP is missing despite WooCommerce assets indicating potential cart data exposure.","solution":"Add Content-Security-Policy (nonce-based) and HSTS preload:\n```\nContent-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\nStrict-Transport-Security: max-age=63072000; includeSubDomains; preload\n```"},{"priority":2,"title":"Fix Accessibility Structure and Contrast","impact":"WCAG Compliance, Screen Reader Usability","problem":"HTML Inventory shows 3 `<h1>` elements and missing skip-link; axe-core found 1 serious contrast violation on `#cookiescript_accept`.","solution":"1. Ensure only one `<h1>` per page.\n2. Add `<a href=\"#main\" class=\"skip-link\">Skip to content</a>`.\n3. Increase contrast on cookie accept button to 4.5:1 ratio."},{"priority":2,"title":"Fix Accessibility Violations","impact":"WCAG Compliance, SEO","problem":"axe-core reports 1 serious color-contrast violation (#cookiescript_accept) and 1 moderate heading-order violation (h1→h3 skip).","solution":"- Increase contrast on `.cookiescript_accept` to ≥4.5:1 ratio.\n- Insert an `<h2>` between the `<h1>` and `<h3>` elements to maintain sequential heading levels."},{"priority":2,"title":"Eliminate Render-Blocking JavaScript","impact":"FCP, TBT, Performance","problem":"11 render-blocking scripts found in HTML Inventory; 5 specifically in `<head>` per Optimization Checklist.","solution":"Add `defer` or `async` to script tags that do not need to execute before DOM parsing.\n\n**Example:**\n```html\n<script src=\"main.js\" defer></script>\n```"},{"priority":2,"title":"Strengthen HSTS Configuration","impact":"Security, Transport Layer","problem":"HSTS is present but missing the `preload` directive, preventing inclusion in browser preload lists.","solution":"Update the `Strict-Transport-Security` header to include `preload`.\n\n**Header:**\n`Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`"},{"priority":2,"title":"Fix color contrast on cookie consent button","impact":"Accessibility (WCAG 1.4.3)","problem":"axe-core reports 1 serious violation on `#cookiescript_accept` for insufficient color contrast.","solution":"Increase contrast ratio to at least 4.5:1 for text on the button. Test with a contrast checker tool and adjust CSS colors."},{"priority":2,"title":"Fix Render-Blocking Scripts","impact":"FCP, TBT, Performance","problem":"11 render-blocking scripts detected in <head>, including jQuery and WooCommerce assets, delaying first paint.","solution":"Move scripts to the footer or add `defer`/`async` attributes:\n```html\n<script src=\"...\" defer></script>\n<script src=\"...\" async></script>\n```"},{"priority":2,"title":"Defer Render-Blocking Scripts","impact":"FCP, LCP, TBT","problem":"11 render-blocking external scripts detected in <head>, delaying first paint and increasing TBT.","solution":"Add `defer` or `async` to non-critical scripts in the `<head>`:\n```html\n<script src=\"...\" defer></script>\n```\nMove non-essential scripts to the footer or use a plugin to optimize script loading order."},{"priority":2,"title":"Fix Color Contrast Violation","impact":"Accessibility (WCAG 1.4.3)","problem":"Serious axe violation on `#cookiescript_accept` element fails minimum contrast ratio thresholds.","solution":"Adjust the text color or background color of the cookie consent button to achieve a contrast ratio of at least 4.5:1. Use a tool like WebAIM Contrast Checker to verify."},{"priority":2,"title":"Implement Content Security Policy (CSP)","impact":"Security, XSS Defense","problem":"CSP is missing. WooCommerce scripts detected in HTML inventory suggest e-commerce capability, raising XSS risk despite inferred signals.","solution":"Deploy a strict CSP with nonce/hash for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\"\n```"},{"priority":2,"title":"Fix Color Contrast on Cookie Button","impact":"Accessibility (WCAG 1.4.3)","problem":"Axe reports serious contrast violation on `#cookiescript_accept`.","solution":"Increase contrast ratio to ≥4.5:1. Adjust background or text color in CSS:\n```css\n#cookiescript_accept { color: #333; background: #f0f0f0; }\n```"},{"priority":2,"title":"Add Meta Description","impact":"SEO, Click-Through Rate","problem":"PSI SEO audit fails `metaDescription`; document lacks summary.","solution":"Add a unique description tag (150-160 chars) in `<head>`:\n```html\n<meta name=\"description\" content=\"Lumekrabi on tervislik, jätkusuutlik ja peene maitsega delikatess. Tutvuge meie valikuga.\">\n```"},{"priority":2,"title":"Fix Color Contrast on Cookie Banner","impact":"Accessibility (WCAG 1.4.3)","problem":"Serious axe-core violation: `#cookiescript_accept` fails minimum contrast ratio thresholds.","solution":"Increase contrast between text and background on the cookie accept button.\n\n**CSS:**\n```css\n#cookiescript_accept {\n  color: #333333; /* Darker text */\n  background-color: #ffffff;\n}\n```"},{"priority":3,"title":"Add Meta Description and Lazy Load Remaining Images","impact":"SEO, Page Weight","problem":"SEO audit fails `metaDescription`; 6 images below the fold lack `loading=\"lazy\"`.","solution":"1. Add `<meta name=\"description\" content=\"...\">`.\n2. Add `loading=\"lazy\"` to all images not in the viewport:\n```html\n<img src=\"...\" loading=\"lazy\" alt=\"...\">\n```"},{"priority":3,"title":"Add Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals indicate no auth/payments, so risk is lower, but CSP remains a best practice for content integrity.","solution":"Implement a strict CSP with nonce-based script execution:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\"\n```"},{"priority":3,"title":"Fix Accessibility Contrast & SEO Meta","impact":"Accessibility, SEO","problem":"axe-core reports 1 serious color-contrast violation on `#cookiescript_accept`. Meta description is missing (SEO score 92).","solution":"1. **Contrast:** Increase text color contrast on `#cookiescript_accept` to meet WCAG AA (4.5:1).\n2. **Meta:** Add a `<meta name=\"description\" content=\"...\">` tag summarizing the article content."},{"priority":3,"title":"Add Meta Description","impact":"SEO, Click-Through Rate","problem":"HTML Inventory shows meta description is not set; W3C validator reports SEO failing audit.","solution":"Add a unique meta description tag (150-160 characters) summarizing the article content.\n```html\n<meta name=\"description\" content=\"...\">\n```"},{"priority":3,"title":"Add meta description for SEO","impact":"Search Visibility, CTR","problem":"PSI and HTML Inventory confirm 'metaDescription' is missing; document has no meta description tag.","solution":"Add a concise meta description (150–160 characters) summarizing the article content.\n```html\n<meta name=\"description\" content=\"Learn how to identify high-quality octopus and caviar with these expert tips.\">\n```"},{"priority":3,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals indicate no auth, payments, or user content, lowering immediate risk but CSP remains a best practice.","solution":"Deploy a strict CSP with nonces for scripts. Since the site is brochure/blog focused, a strict allowlist is less critical than on an app, but recommended for defense-in-depth.\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"},{"priority":3,"title":"Add Meta Description and Fix Landmarks","impact":"SEO, Accessibility","problem":"SEO audit flags missing meta description; axe-core reports duplicate main landmarks and missing skip-to-content link.","solution":"- Add `<meta name=\"description\" content=\"...\">`.\n- Add `<a href=\"#main\" class=\"skip-link\">Skip to content</a>`.\n- Ensure only one `<main>` element exists in the DOM."},{"priority":3,"title":"Implement Content Security Policy","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals show no auth/payments, so risk is lower, but defense is recommended.","solution":"Deploy a strict CSP with nonce/hash for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"}],"coverage":{"pct":100,"missing":[]},"siteSummary":{"pagesAudited":10,"pagesAttempted":10,"urls":["https://kawiare.ee/","https://kawiare.ee/artiklid","https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja","https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta","https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga","https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari","https://kawiare.ee/kammkarp","https://kawiare.ee/ahven-ja-koha","https://kawiare.ee/lumekrabi","https://kawiare.ee/kaaviar-tanapaeval"]},"psiSnapshot":{"rows":[{"pageUrl":"https://kawiare.ee/","perfMobile":44,"perfDesktop":72,"lcpMobileMs":9770.061987408142,"lcpDesktopMs":1518.0484979249802,"clsMobile":1,"clsDesktop":0.637178},{"pageUrl":"https://kawiare.ee/artiklid","perfMobile":67,"perfDesktop":93,"lcpMobileMs":10281.48326457966,"lcpDesktopMs":1725.8028002314636,"clsMobile":0.000677,"clsDesktop":0.001308},{"pageUrl":"https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja","perfMobile":71,"perfDesktop":92,"lcpMobileMs":6564.32093644506,"lcpDesktopMs":1718.3621279029717,"clsMobile":0,"clsDesktop":0.000173},{"pageUrl":"https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta","perfMobile":61,"perfDesktop":93,"lcpMobileMs":8490.88682047076,"lcpDesktopMs":1694.4105743132432,"clsMobile":0,"clsDesktop":0.0001},{"pageUrl":"https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga","perfMobile":60,"perfDesktop":93,"lcpMobileMs":8893.157507344984,"lcpDesktopMs":1621.4673460781542,"clsMobile":0,"clsDesktop":0.000173},{"pageUrl":"https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari","perfMobile":68,"perfDesktop":93,"lcpMobileMs":8709.706911222962,"lcpDesktopMs":1649.7213993451544,"clsMobile":0,"clsDesktop":0.000173},{"pageUrl":"https://kawiare.ee/kammkarp","perfMobile":71,"perfDesktop":95,"lcpMobileMs":7218.712040500011,"lcpDesktopMs":1488.7500574552805,"clsMobile":0,"clsDesktop":0.0001},{"pageUrl":"https://kawiare.ee/ahven-ja-koha","perfMobile":67,"perfDesktop":93,"lcpMobileMs":9435.424039461468,"lcpDesktopMs":1621.5292254099213,"clsMobile":0,"clsDesktop":0.0001},{"pageUrl":"https://kawiare.ee/lumekrabi","perfMobile":70,"perfDesktop":94,"lcpMobileMs":7227.286616565358,"lcpDesktopMs":1584.588328706102,"clsMobile":0,"clsDesktop":0.0001},{"pageUrl":"https://kawiare.ee/kaaviar-tanapaeval","perfMobile":61,"perfDesktop":99,"lcpMobileMs":8356.814613567078,"lcpDesktopMs":926.2286125226647,"clsMobile":0,"clsDesktop":0.0001}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket)","evidence":["HTML markers: WP Rocket","generator: WordPress 7.0"]},{"id":"lazyload","title":"Images lazy-loaded","status":"pass","detail":"All raster images use loading=\"lazy\".","evidence":[]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"pass","detail":"Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable).","evidence":["hero: https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-1.png","loading: eager","fetchpriority: (not set)"]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"warn","detail":"Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.","evidence":["selector: div.pt-24.pb-16","url: …e.ee/wp-content/uploads/2026/01/823960696-teadmuskeskus_2592x726_b-scaled.jpg","box: 1280×464px"]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"warn","detail":"Only 15/22 raster images use srcset or <picture> (68%).","evidence":["https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-1.png","https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-e1782658950478.png","…kawiare.ee/wp-content/uploads/2026/02/Kawiare_paisepildid_mob_2_1900x2560.jpg","https://kawiare.ee/wp-content/uploads/2026/02/pais2_uus_2595x1467-scaled.jpg","…kawiare.ee/wp-content/uploads/2026/02/Kawiare_paisepildid_mob_3_1900x2560.jpg"]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"pass","detail":"17 distinct srcset widths.","evidence":["widths: 100, 150, 200, 225, 300, 600, 683, 768, 800, 1024, 1080, 1152, 1365, 1536, 1707, 1920, 2000"]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"fail","detail":"5 render-blocking scripts in <head>. Move to footer or add defer/async.","evidence":["…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638","https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1","https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1","…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0","…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0"]}],"summary":{"passed":4,"warned":2,"failed":1,"notApplicable":0},"priorities":[{"title":"JS scripts not blocking in <head>","severity":"high","detail":"5 render-blocking scripts in <head>. Move to footer or add defer/async."},{"title":"Responsive images (srcset / <picture>)","severity":"medium","detail":"Only 15/22 raster images use srcset or <picture> (68%)."},{"title":"Hero is a real <img> (not a CSS background-image)","severity":"medium","detail":"Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file."}]},"perPageOverall":[{"url":"https://kawiare.ee/","overall":55,"reasoning":"Mobile performance is critically low at 44 due to LCP 9.8s and CLS 1.0, despite excellent TTFB (3ms). Desktop is healthy (72), but mobile-first indexing penalizes the site heavily. Security headers score 40/100 with missing CSP, though WooCommerce assets suggest e-commerce capability requiring stricter headers. Accessibility has structural flaws (3 h1s) and one serious contrast violation. Image weight (1.46 MB) dominates page size.","confidence":"high","fixes":[{"priority":1,"title":"Fix Mobile LCP and CLS","impact":"LCP, CLS, Performance Score","problem":"Mobile LCP is 9.8s (threshold 2.5s) and CLS is 1.0 (threshold 0.1), causing a Performance score of 44.","solution":"1. Preload the LCP image (hero) with `<link rel=\"preload\" as=\"image\">`.\n2. Reserve space for dynamic content to prevent CLS (add width/height or aspect-ratio CSS).\n3. Convert hero PNG to WebP/AVIF to reduce 1.46 MB image weight."},{"priority":1,"title":"Defer Render-Blocking JavaScript","impact":"FCP, TBT, Performance Score","problem":"11 render-blocking scripts (including jQuery and WooCommerce) delay FCP to 1.99s and contribute to LCP delay.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`:\n```html\n<script src=\"...\" defer></script>\n```\nMove WooCommerce frontend scripts to footer if not needed for initial paint."},{"priority":2,"title":"Strengthen Security Headers","impact":"Security Score, XSS Protection","problem":"Security Headers grade is 40/100; CSP is missing despite WooCommerce assets indicating potential cart data exposure.","solution":"Add Content-Security-Policy (nonce-based) and HSTS preload:\n```\nContent-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\nStrict-Transport-Security: max-age=63072000; includeSubDomains; preload\n```"},{"priority":2,"title":"Fix Accessibility Structure and Contrast","impact":"WCAG Compliance, Screen Reader Usability","problem":"HTML Inventory shows 3 `<h1>` elements and missing skip-link; axe-core found 1 serious contrast violation on `#cookiescript_accept`.","solution":"1. Ensure only one `<h1>` per page.\n2. Add `<a href=\"#main\" class=\"skip-link\">Skip to content</a>`.\n3. Increase contrast on cookie accept button to 4.5:1 ratio."},{"priority":3,"title":"Add Meta Description and Lazy Load Remaining Images","impact":"SEO, Page Weight","problem":"SEO audit fails `metaDescription`; 6 images below the fold lack `loading=\"lazy\"`.","solution":"1. Add `<meta name=\"description\" content=\"...\">`.\n2. Add `loading=\"lazy\"` to all images not in the viewport:\n```html\n<img src=\"...\" loading=\"lazy\" alt=\"...\">\n```"}]},{"url":"https://kawiare.ee/artiklid","overall":63,"reasoning":"Mobile performance is the primary drag with a 67 score and a critical LCP of 10.3 s, driven by 16 render-blocking scripts and a CSS background hero image. Security configuration is weak (40/100) due to missing HTTPS redirects and HSTS preload, though the site lacks auth/payment surfaces. Accessibility is strong (96) but marred by one serious contrast violation and heading order issues. Desktop performance is excellent (93), highlighting a significant mobile/desktop delta. Overall quality is moderate due to these specific mobile and security failures.","confidence":"high","fixes":[{"priority":1,"title":"Force HTTPS Redirect","impact":"Security, Transport Layer","problem":"Security Headers audit reports 'http://kawiare.ee/artiklid does not redirect to HTTPS', leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Performance, Mobile UX","problem":"Mobile LCP is 10.3 s (target ≤2.5 s), caused by 16 render-blocking scripts and a hero image loaded via CSS background.","solution":"- Move non-critical scripts to `defer` or `async` (16 currently blocking).\n- Replace CSS background hero with a real `<img>` or `<picture>` element with `fetchpriority=\"high\"`.\n- Inline critical CSS and defer the rest."},{"priority":2,"title":"Fix Accessibility Violations","impact":"WCAG Compliance, SEO","problem":"axe-core reports 1 serious color-contrast violation (#cookiescript_accept) and 1 moderate heading-order violation (h1→h3 skip).","solution":"- Increase contrast on `.cookiescript_accept` to ≥4.5:1 ratio.\n- Insert an `<h2>` between the `<h1>` and `<h3>` elements to maintain sequential heading levels."},{"priority":3,"title":"Add Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals indicate no auth/payments, so risk is lower, but CSP remains a best practice for content integrity.","solution":"Implement a strict CSP with nonce-based script execution:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\"\n```"}]},{"url":"https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja","overall":72,"reasoning":"Mobile performance 71 is dragged down significantly by LCP 6.6s (>4s heavy penalty) and 11 render-blocking scripts. Security headers score 40/100 due to a critical missing HTTP-to-HTTPS redirect and missing CSP. Accessibility is strong (97) with only one serious contrast violation, and SEO is solid (92) despite a missing meta description. TTFB is excellent (4ms), indicating server speed is not the bottleneck.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Transport Layer","problem":"Security Headers audit shows http://kawiare.ee/... does not redirect to HTTPS, leaving users vulnerable to MITM attacks on unencrypted connections.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS.\n\n**Apache (.htaccess):**\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Performance, LCP, FCP","problem":"LCP is 6.6s on mobile (heavy penalty). 11 render-blocking scripts and unoptimized images contribute to this delay.","solution":"1. **Defer non-critical JS:** Move scripts to footer or add `defer`/`async` attributes.\n2. **Optimize Hero Image:** Ensure the LCP image (likely the header) is preloaded or uses `fetchpriority=\"high\"`.\n3. **Compress Images:** Convert to WebP/AVIF to reduce the 220 KiB image delivery savings potential."},{"priority":2,"title":"Eliminate Render-Blocking JavaScript","impact":"FCP, TBT, Performance","problem":"11 render-blocking scripts found in HTML Inventory; 5 specifically in `<head>` per Optimization Checklist.","solution":"Add `defer` or `async` to script tags that do not need to execute before DOM parsing.\n\n**Example:**\n```html\n<script src=\"main.js\" defer></script>\n```"},{"priority":2,"title":"Strengthen HSTS Configuration","impact":"Security, Transport Layer","problem":"HSTS is present but missing the `preload` directive, preventing inclusion in browser preload lists.","solution":"Update the `Strict-Transport-Security` header to include `preload`.\n\n**Header:**\n`Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`"},{"priority":3,"title":"Fix Accessibility Contrast & SEO Meta","impact":"Accessibility, SEO","problem":"axe-core reports 1 serious color-contrast violation on `#cookiescript_accept`. Meta description is missing (SEO score 92).","solution":"1. **Contrast:** Increase text color contrast on `#cookiescript_accept` to meet WCAG AA (4.5:1).\n2. **Meta:** Add a `<meta name=\"description\" content=\"...\">` tag summarizing the article content."}]},{"url":"https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta","overall":42,"reasoning":"Mobile performance is critically low (61) with LCP 8.5s and FCP 4.6s, driven by 11 render-blocking scripts. Security configuration is weak (40/100) with HTTP not redirecting to HTTPS, creating a downgrade risk. Accessibility has 1 serious contrast violation and missing skip-link despite high PSI score. SEO lacks a meta description and has W3C errors. Confidence is high due to complete data coverage.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Transport","problem":"Security Headers audit shows http://kawiare.ee/... does not redirect to HTTPS, leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests.\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Eliminate Render-Blocking JavaScript","impact":"LCP, FCP, Performance","problem":"11 render-blocking scripts identified in HTML Inventory; LCP is 8.5s and FCP is 4.6s on mobile.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Move critical CSS inline and defer JS execution.\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":2,"title":"Fix Accessibility Violations","impact":"WCAG Compliance, Usability","problem":"axe-core found 1 serious color-contrast violation (#cookiescript_accept) and 3 moderate landmark issues; skip-to-content link is missing.","solution":"- Increase contrast ratio for `#cookiescript_accept` to ≥4.5:1.\n- Add `<a href=\"#main\" class=\"skip-link\">Skip to content</a>` before the header.\n- Ensure `<main>` is not nested inside another landmark."},{"priority":3,"title":"Add Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP header is missing. Site signals indicate no auth/payments/UGC, so risk is lower but hardening is recommended.","solution":"Implement a nonce-based CSP rather than a flat allowlist.\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"},{"priority":3,"title":"Add Meta Description","impact":"SEO, Click-Through Rate","problem":"HTML Inventory shows meta description is not set; W3C validator reports SEO failing audit.","solution":"Add a unique meta description tag (150-160 characters) summarizing the article content.\n```html\n<meta name=\"description\" content=\"...\">\n```"}]},{"url":"https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga","overall":65,"reasoning":"Mobile performance (60) is the primary drag due to LCP 8.9 s and FCP 4.6 s, despite Desktop scoring 93. Security headers score 40/100, critically missing an HTTP-to-HTTPS redirect. Accessibility is strong (97) but contains 1 serious color-contrast violation. W3C validation shows 2 errors, and SEO lacks a meta description. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Force HTTPS redirect on HTTP requests","impact":"Security, Transport Layer","problem":"Security Headers audit reports 'http://kawiare.ee/... does not redirect to HTTPS', leaving users on unencrypted connections if they type http.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests.\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Reduce render-blocking JavaScript to improve LCP","impact":"LCP, FCP, Mobile Performance","problem":"Mobile LCP is 8.9 s; HTML Inventory identifies 11 render-blocking scripts (5 in <head>), including main.js and jQuery.","solution":"Add `defer` or `async` to non-critical scripts. Move critical CSS inline and defer JS execution.\n```html\n<script src=\"main.js\" defer></script>\n```"},{"priority":2,"title":"Fix color contrast on cookie consent button","impact":"Accessibility (WCAG 1.4.3)","problem":"axe-core reports 1 serious violation on `#cookiescript_accept` for insufficient color contrast.","solution":"Increase contrast ratio to at least 4.5:1 for text on the button. Test with a contrast checker tool and adjust CSS colors."},{"priority":3,"title":"Add meta description for SEO","impact":"Search Visibility, CTR","problem":"PSI and HTML Inventory confirm 'metaDescription' is missing; document has no meta description tag.","solution":"Add a concise meta description (150–160 characters) summarizing the article content.\n```html\n<meta name=\"description\" content=\"Learn how to identify high-quality octopus and caviar with these expert tips.\">\n```"},{"priority":3,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals indicate no auth, payments, or user content, lowering immediate risk but CSP remains a best practice.","solution":"Deploy a strict CSP with nonces for scripts. Since the site is brochure/blog focused, a strict allowlist is less critical than on an app, but recommended for defense-in-depth.\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"}]},{"url":"https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari","overall":55,"reasoning":"Mobile performance is critically low (68) primarily due to an LCP of 8.7 s, despite an excellent TTFB of 4 ms. Security is a major concern with a grade of 40/100 and a critical failure where HTTP does not redirect to HTTPS. Accessibility is generally strong (97) but includes one serious color-contrast violation. SEO is hindered by a missing meta description. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Transport Layer","problem":"Security Headers audit reports that http://kawiare.ee does not redirect to HTTPS, leaving users vulnerable to interception.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Performance, LCP, FCP","problem":"Mobile LCP is 8.7 s (heavy penalty), driven by 11 render-blocking scripts and unused JavaScript (224 KB wasted).","solution":"- Defer non-critical JavaScript (e.g., WooCommerce, Analytics) using `defer` or `async`.\n- Preload the LCP image resource.\n- Inline critical CSS and remove unused CSS rules.\n- Optimize image delivery (WebP/AVIF) for the hero image."},{"priority":2,"title":"Fix Render-Blocking Scripts","impact":"FCP, TBT, Performance","problem":"11 render-blocking scripts detected in <head>, including jQuery and WooCommerce assets, delaying first paint.","solution":"Move scripts to the footer or add `defer`/`async` attributes:\n```html\n<script src=\"...\" defer></script>\n<script src=\"...\" async></script>\n```"},{"priority":2,"title":"Strengthen Security Headers","impact":"Security Headers Grade, XSS/Clickjacking Defense","problem":"Security Headers grade is 40/100; HSTS lacks preload directive, and CSP is missing.","solution":"- Add `Content-Security-Policy` (start with report-only).\n- Update HSTS to include `preload`.\n- Add `Permissions-Policy` to restrict unused features.\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":3,"title":"Add Meta Description and Fix Landmarks","impact":"SEO, Accessibility","problem":"SEO audit flags missing meta description; axe-core reports duplicate main landmarks and missing skip-to-content link.","solution":"- Add `<meta name=\"description\" content=\"...\">`.\n- Add `<a href=\"#main\" class=\"skip-link\">Skip to content</a>`.\n- Ensure only one `<main>` element exists in the DOM."}]},{"url":"https://kawiare.ee/kammkarp","overall":68,"reasoning":"Mobile performance 71 is dragged down by LCP 7.2 s, exceeding the 4 s heavy penalty threshold. Security headers score 40/100, critically missing an HTTP-to-HTTPS redirect. Accessibility is strong (97) but contains 1 serious contrast violation and landmark issues. SEO is solid (92) but lacks a meta description. Confidence is high as all tools returned data.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Transport","problem":"HTTP does not redirect to HTTPS (http://kawiare.ee/kammkarp does not redirect), leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Performance, LCP","problem":"LCP is 7.2 s on mobile, far exceeding the 2.5 s good threshold, primarily due to the hero image load time.","solution":"- Preload the hero image using `<link rel=\"preload\" as=\"image\" href=\"/path/to/hero.jpg\">`.\n- Convert the hero image to WebP/AVIF.\n- Ensure the hero image is not lazy-loaded (it is currently eager, which is correct, but compression is needed)."},{"priority":2,"title":"Defer Render-Blocking Scripts","impact":"FCP, LCP, TBT","problem":"11 render-blocking external scripts detected in <head>, delaying first paint and increasing TBT.","solution":"Add `defer` or `async` to non-critical scripts in the `<head>`:\n```html\n<script src=\"...\" defer></script>\n```\nMove non-essential scripts to the footer or use a plugin to optimize script loading order."},{"priority":2,"title":"Fix Color Contrast Violation","impact":"Accessibility (WCAG 1.4.3)","problem":"Serious axe violation on `#cookiescript_accept` element fails minimum contrast ratio thresholds.","solution":"Adjust the text color or background color of the cookie consent button to achieve a contrast ratio of at least 4.5:1. Use a tool like WebAIM Contrast Checker to verify."},{"priority":2,"title":"Implement Content Security Policy (CSP)","impact":"Security, XSS Defense","problem":"CSP is missing. WooCommerce scripts detected in HTML inventory suggest e-commerce capability, raising XSS risk despite inferred signals.","solution":"Deploy a strict CSP with nonce/hash for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\"\n```"},{"priority":3,"title":"Add Meta Description","impact":"SEO, Click-Through Rate","problem":"SEO audit failed `metaDescription`; document does not have a meta description tag.","solution":"Add a unique, descriptive meta description (150–160 characters) in the `<head>`:\n```html\n<meta name=\"description\" content=\"Kammkarp retseptid ja kasu. Lihtne fast food, mis ei vaja keerulisi tehnikaid.\">\n```"}]},{"url":"https://kawiare.ee/ahven-ja-koha","overall":58,"reasoning":"PSI mobile performance is 67 with a critical LCP of 9.4 s, dragging the score despite a strong desktop score of 93. Security configuration is weak (40/100) with HTTP traffic not redirecting to HTTPS, creating a man-in-the-middle risk. Accessibility is mostly solid (97) but has one serious contrast violation and missing skip links. W3C validation shows 2 errors and 5 warnings indicating markup hygiene issues. The combination of mobile performance failure and security misconfiguration places this in the 'Poor' band.","confidence":"high","fixes":[{"priority":1,"title":"Force HTTPS Redirect","impact":"Security, Transport","problem":"HTTP traffic does not redirect to HTTPS (http://kawiare.ee/ahven-ja-koha does not redirect), leaving users vulnerable to interception.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS.\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Performance, Mobile UX","problem":"Mobile LCP is 9.4 s (threshold is 2.5 s), driven by 11 render-blocking scripts and unoptimized image delivery.","solution":"- Preload the LCP image (`fetchpriority=\"high\"`).\n- Defer non-critical JavaScript (11 render-blocking scripts found).\n- Convert hero image to WebP/AVIF and ensure correct dimensions."},{"priority":2,"title":"Defer Render-Blocking Scripts","impact":"FCP, TBT","problem":"11 render-blocking external scripts delay first paint; 5 scripts found in `<head>` without `defer` or `async`.","solution":"Add `defer` or `async` attributes to non-critical scripts in `<head>`:\n```html\n<script src=\"...\" defer></script>\n```\nMove WooCommerce and analytics scripts to the footer if possible."},{"priority":2,"title":"Fix Color Contrast Violation","impact":"Accessibility (WCAG 1.4.3)","problem":"axe-core reports 1 serious violation on `#cookiescript_accept` element where foreground/background contrast is insufficient.","solution":"Adjust the CSS for `.cookiescript_accept` to ensure a contrast ratio of at least 4.5:1 against its background color."},{"priority":3,"title":"Add Content Security Policy (CSP)","impact":"Security (XSS Defense)","problem":"CSP is missing. While site signals indicate no auth/payments/UGC, a CSP provides defense-in-depth against injected scripts.","solution":"Implement a strict CSP with nonce/hash for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```\nEnsure all inline scripts use the nonce."}]},{"url":"https://kawiare.ee/lumekrabi","overall":72,"reasoning":"Mobile performance 70 with LCP 7.2s is the primary drag, despite excellent desktop metrics (94) and low TTFB (3ms). Security headers grade 40 and missing HTTP-to-HTTPS redirect introduce critical vulnerabilities. Accessibility is strong (97 Lighthouse) but marred by one serious contrast violation. SEO is functional but missing a meta description. Confidence is high as all tools returned data.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Transport Layer","problem":"http://kawiare.ee/lumekrabi does not redirect to HTTPS, leaving users on insecure connections.","solution":"Configure server (Apache/Nginx) to redirect all HTTP traffic to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Eliminate Render-Blocking JavaScript","impact":"LCP, FCP, Performance","problem":"11 render-blocking scripts delay paint; LCP is 7.2s despite 3ms TTFB.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Critical CSS should be inlined. Example:\n```html\n<script src=\"main.js\" defer></script>\n```"},{"priority":2,"title":"Fix Color Contrast on Cookie Button","impact":"Accessibility (WCAG 1.4.3)","problem":"Axe reports serious contrast violation on `#cookiescript_accept`.","solution":"Increase contrast ratio to ≥4.5:1. Adjust background or text color in CSS:\n```css\n#cookiescript_accept { color: #333; background: #f0f0f0; }\n```"},{"priority":2,"title":"Add Meta Description","impact":"SEO, Click-Through Rate","problem":"PSI SEO audit fails `metaDescription`; document lacks summary.","solution":"Add a unique description tag (150-160 chars) in `<head>`:\n```html\n<meta name=\"description\" content=\"Lumekrabi on tervislik, jätkusuutlik ja peene maitsega delikatess. Tutvuge meie valikuga.\">\n```"},{"priority":3,"title":"Implement Content Security Policy","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals show no auth/payments, so risk is lower, but defense is recommended.","solution":"Deploy a strict CSP with nonce/hash for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"}]},{"url":"https://kawiare.ee/kaaviar-tanapaeval","overall":58,"reasoning":"Mobile performance is critically degraded (LCP 8.4s, FCP 4.6s) due to render-blocking JavaScript, despite excellent desktop scores (99). A critical security gap exists where HTTP traffic does not redirect to HTTPS, exposing users to interception. Accessibility is generally good but contains one serious contrast violation and missing skip links. SEO is hindered by a missing meta description and incomplete structured data.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Data Integrity","problem":"HTTP traffic does not redirect to HTTPS (http://kawiare.ee/kaaviar-tanapaeval does not redirect), leaving users vulnerable to interception.","solution":"Configure the web server to redirect all HTTP requests to HTTPS.\n\n**Apache (.htaccess):**\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```\n\n**Nginx:**\n```nginx\nserver {\n    listen 80;\n    server_name kawiare.ee;\n    return 301 https://$server_name$request_uri;\n}\n```"},{"priority":1,"title":"Eliminate Render-Blocking JavaScript","impact":"LCP, FCP, Mobile Performance","problem":"11 render-blocking scripts delay FCP to 4.6s and LCP to 8.4s on mobile; 224 KB of unused JS identified.","solution":"Move non-critical scripts to the footer or add `defer`/`async` attributes.\n\n**Example:**\n```html\n<!-- Change from -->\n<script src=\"main.js\"></script>\n\n<!-- To -->\n<script src=\"main.js\" defer></script>\n```"},{"priority":2,"title":"Fix Color Contrast on Cookie Banner","impact":"Accessibility (WCAG 1.4.3)","problem":"Serious axe-core violation: `#cookiescript_accept` fails minimum contrast ratio thresholds.","solution":"Increase contrast between text and background on the cookie accept button.\n\n**CSS:**\n```css\n#cookiescript_accept {\n  color: #333333; /* Darker text */\n  background-color: #ffffff;\n}\n```"},{"priority":2,"title":"Add Meta Description","impact":"SEO, Click-Through Rate","problem":"SEO audit flags missing meta description; document does not have one set.","solution":"Add a concise description (150–160 characters) in the `<head>`.\n\n**HTML:**\n```html\n<meta name=\"description\" content=\"Kaaviar tänapäeval: kuidas kasvukeskkond määrab kvaliteedi ja miks valik on oluline.\">\n```"},{"priority":3,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower, but CSP adds defense-in-depth.","solution":"Deploy a strict CSP with nonce/hash approach if user content or login is added later.\n\n**Header:**\n```http\nContent-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\n```"}]}]}