# Audit Report: Kawiare - Experience of Taste
**Website:** https://kawiare.ee/
**Date:** 2026-07-07
**Overall Score:** 60 / 100
**Status:** 🟡 **Needs Improvement**
**Confidence:** high
**Audit Coverage:** 100% — all sources returned data
**Pages Audited (10 of 10):**
- https://kawiare.ee/
- https://kawiare.ee/artiklid
- https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja
- https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta
- https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga
- https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari
- https://kawiare.ee/kammkarp
- https://kawiare.ee/ahven-ja-koha
- https://kawiare.ee/lumekrabi
- https://kawiare.ee/kaaviar-tanapaeval
## Summary
Site overall 60 is the mean of 10 pages. Scores range 52 (https://kawiare.ee/) → 68 (https://kawiare.ee/lumekrabi). Weakest page: Mobile PSI score of 49 with catastrophic Core Web Vitals (LCP 9.2s, CLS 1.0) places this site in the Poor band despite excellent TTFB (5ms). Accessibility is mostly functional but contains 1 serious contrast violation and structural heading issues (3 h1s). Security headers are weak (40/100) with missing CSP and HSTS preload, though basic protections like X-Frame-Options exist. WooCommerce scripts indicate e-commerce capability despite signals, justifying stricter security recommendations.
## Per-Page Scores
| Page | Score | Status | Confidence |
| --- | --- | --- | --- |
| https://kawiare.ee/ | 52 | 🟠**Poor** | high |
| https://kawiare.ee/artiklid | 55 | 🟠**Poor** | high |
| https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja | 58 | 🟠**Poor** | high |
| https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta | 62 | 🟡 **Needs Improvement** | high |
| https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga | 65 | 🟡 **Needs Improvement** | high |
| https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari | 55 | 🟠**Poor** | high |
| https://kawiare.ee/kammkarp | 62 | 🟡 **Needs Improvement** | high |
| https://kawiare.ee/ahven-ja-koha | 58 | 🟠**Poor** | high |
| https://kawiare.ee/lumekrabi | 68 | 🟡 **Needs Improvement** | high |
| https://kawiare.ee/kaaviar-tanapaeval | 60 | 🟡 **Needs Improvement** | high |
## PageSpeed Insights — Mobile vs Desktop
_Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._
| URL | Performance (M / D) | LCP (M / D) | CLS (M / D) |
| --- | --- | --- | --- |
| https://kawiare.ee/ | **49** / 70 | **9.24 s** / 1.81 s | **1.000** / 0.637 |
| https://kawiare.ee/artiklid | **68** / 93 | **9.58 s** / 1.66 s | 0.001 / **0.001** |
| https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja | **61** / 93 | **8.64 s** / 1.50 s | 0.000 / **0.000** |
| https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta | **71** / 94 | **6.05 s** / 1.51 s | 0.000 / **0.000** |
| https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga | **69** / 94 | **8.91 s** / 1.53 s | 0.000 / **0.000** |
| https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari | **60** / 95 | **8.57 s** / 1.44 s | 0.000 / **0.000** |
| https://kawiare.ee/kammkarp | **61** / 96 | **8.50 s** / 1.26 s | 0.000 / **0.000** |
| https://kawiare.ee/ahven-ja-koha | **59** / 97 | **9.32 s** / 1.13 s | 0.000 / **0.000** |
| https://kawiare.ee/lumekrabi | **69** / 98 | **8.50 s** / 993 ms | 0.000 / **0.000** |
| https://kawiare.ee/kaaviar-tanapaeval | **69** / 95 | **7.23 s** / 1.44 s | 0.000 / **0.000** |
## Optimization Checklist
**4 of 7 passing** — 4 pass · 2 warn · 1 fail
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | **Pass** | All raster images use loading="lazy". |
| Hero image eagerly loaded | **Pass** | Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real (not a CSS background-image) | **Warn** | Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real with srcset/sizes (or ) so smaller viewports can fetch a smaller file. |
| Responsive images (srcset / ) | **Warn** | Only 15/22 raster images use srcset or (68%). |
| Reasonable number of image sizes | **Pass** | 17 distinct srcset widths. |
| JS scripts not blocking in | **Fail** | 5 render-blocking scripts in . Move to footer or add defer/async. |
## Fixes
### Priority 1: Critical
*Immediate action — impacts user experience, search rankings, or site safety.*
**1A. Fix Largest Contentful Paint (LCP) and Layout Shift (CLS)**
- **Impact:** Performance, Core Web Vitals
- **Problem:** LCP is 9.2s (target <2.5s) and CLS is 1.0 (target <0.1), driven by render-blocking scripts and unoptimized hero images.
- **Solution:**
- Preload the hero image: ``.
- Convert hero image to WebP/AVIF and ensure explicit width/height attributes.
- Defer non-critical JavaScript to reduce render-blocking time.
**1B. Eliminate Render-Blocking JavaScript**
- **Impact:** FCP, LCP, TBT
- **Problem:** 11 render-blocking scripts detected (5 in head), including jQuery and WooCommerce assets, delaying page rendering.
- **Solution:**
- Add `defer` or `async` to all non-critical scripts.
- Move script loading to the footer where possible.
- Inline critical CSS and defer non-critical stylesheets.
**1C. Enforce HTTPS Redirect**
- **Impact:** Security, Data Integrity
- **Problem:** HTTP traffic (http://kawiare.ee/artiklid) does not redirect to HTTPS, leaving initial requests vulnerable to interception.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1D. Optimize Largest Contentful Paint (LCP)**
- **Impact:** LCP, FCP, Mobile Performance
- **Problem:** LCP is 9.6s on mobile due to 16 render-blocking scripts and a hero image implemented as a CSS background (no srcset optimization).
- **Solution:**
- Move non-critical scripts to `defer` or `async`.
- Replace the CSS background hero with a real `` or `` element with `fetchpriority="high"` and `srcset`.
- Inline critical CSS and defer the rest.
**1E. Force HTTPS redirect for all HTTP requests**
- **Impact:** Security, Transport Layer
- **Problem:** Security Headers audit shows http://kawiare.ee/... does not redirect to HTTPS, allowing downgrade attacks.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS.
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1F. Defer or async render-blocking JavaScript**
- **Impact:** LCP, FCP, Performance
- **Problem:** 11 render-blocking scripts (including main.js 224KB) delay FCP to 2.57s and LCP to 6.1s on mobile.
- **Solution:**
Add `defer` or `async` attributes to non-critical scripts in ``. Critical CSS should be inlined.
```html
```
**1G. Force HTTPS redirect**
- **Impact:** Security, Transport Layer
- **Problem:** HTTP does not redirect to HTTPS (http://kawiare.ee... does not redirect), leaving traffic vulnerable to interception.
- **Solution:**
Configure server to redirect all HTTP traffic to HTTPS:
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1H. Enforce HTTPS redirect for HTTP requests**
- **Impact:** Security, Transport Layer
- **Problem:** http://kawiare.ee/kammkarp does not redirect to HTTPS, leaving the site vulnerable to downgrade attacks despite the final URL being HTTPS.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic:
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1I. Defer or async non-critical JavaScript**
- **Impact:** LCP, FCP, Performance Score
- **Problem:** 11 render-blocking scripts in contribute to LCP 8.5s and FCP 4.6s on mobile.
- **Solution:**
Add `defer` or `async` attributes to scripts that do not need to execute before DOM parsing. Move non-critical scripts to the footer.
```html
```
**1J. Defer render-blocking JavaScript**
- **Impact:** LCP, FCP, Mobile Performance
- **Problem:** 11 render-blocking scripts in contribute to LCP 9.3 s and FCP 4.6 s on mobile, despite TTFB being 4 ms.
- **Solution:**
Add `defer` or `async` to non-critical scripts in the ``. Critical CSS should be inlined, and JS moved to the footer or deferred:
```html
```
### Priority 2: Important
*Essential for compliance, user reach, and search visibility.*
**2A. Strengthen Security Headers (CSP & HSTS)**
- **Impact:** Security, XSS protection
- **Problem:** CSP is missing and HSTS lacks preload directive. WooCommerce scripts suggest potential cart functionality, increasing XSS risk.
- **Solution:**
- Add Content-Security-Policy with nonce/hash strategy: `Content-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic';`.
- Update HSTS: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`.
**2B. Fix SEO and Document Structure**
- **Impact:** SEO, Accessibility
- **Problem:** Missing meta description, 3 h1 elements (should be 1), and missing skip-to-content link.
- **Solution:**
- Add ``.
- Consolidate to a single `
` per page.
- Add `Skip to content` before the header.
**2C. Fix Accessibility Violations**
- **Impact:** WCAG Compliance, Usability
- **Problem:** 1 serious color-contrast violation (#cookiescript_accept) and 1 moderate heading-order skip (h1→h3). Form inputs lack labels.
- **Solution:**
- Increase contrast ratio for `.lead-text` and cookie button to ≥4.5:1.
- Insert an `