{"url":"https://kawiare.ee/","date":"2026-07-07","siteName":"Kawiare - Experience of Taste","overall":60,"reasoning":"Site overall 60 is the mean of 10 pages. Scores range 52 (https://kawiare.ee/) → 68 (https://kawiare.ee/lumekrabi). Weakest page: Mobile PSI score of 49 with catastrophic Core Web Vitals (LCP 9.2s, CLS 1.0) places this site in the Poor band despite excellent TTFB (5ms). Accessibility is mostly functional but contains 1 serious contrast violation and structural heading issues (3 h1s). Security headers are weak (40/100) with missing CSP and HSTS preload, though basic protections like X-Frame-Options exist. WooCommerce scripts indicate e-commerce capability despite signals, justifying stricter security recommendations.","confidence":"high","fixes":[{"priority":1,"title":"Fix Largest Contentful Paint (LCP) and Layout Shift (CLS)","impact":"Performance, Core Web Vitals","problem":"LCP is 9.2s (target <2.5s) and CLS is 1.0 (target <0.1), driven by render-blocking scripts and unoptimized hero images.","solution":"- Preload the hero image: `<link rel=\"preload\" as=\"image\" href=\"/hero.webp\">`.\n- Convert hero image to WebP/AVIF and ensure explicit width/height attributes.\n- Defer non-critical JavaScript to reduce render-blocking time."},{"priority":1,"title":"Eliminate Render-Blocking JavaScript","impact":"FCP, LCP, TBT","problem":"11 render-blocking scripts detected (5 in head), including jQuery and WooCommerce assets, delaying page rendering.","solution":"- Add `defer` or `async` to all non-critical scripts.\n- Move script loading to the footer where possible.\n- Inline critical CSS and defer non-critical stylesheets."},{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Data Integrity","problem":"HTTP traffic (http://kawiare.ee/artiklid) does not redirect to HTTPS, leaving initial requests vulnerable to interception.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"LCP, FCP, Mobile Performance","problem":"LCP is 9.6s on mobile due to 16 render-blocking scripts and a hero image implemented as a CSS background (no srcset optimization).","solution":"- Move non-critical scripts to `defer` or `async`.\n- Replace the CSS background hero with a real `<img>` or `<picture>` element with `fetchpriority=\"high\"` and `srcset`.\n- Inline critical CSS and defer the rest."},{"priority":1,"title":"Force HTTPS redirect for all HTTP requests","impact":"Security, Transport Layer","problem":"Security Headers audit shows http://kawiare.ee/... does not redirect to HTTPS, allowing downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS.\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Defer or async render-blocking JavaScript","impact":"LCP, FCP, Performance","problem":"11 render-blocking scripts (including main.js 224KB) delay FCP to 2.57s and LCP to 6.1s on mobile.","solution":"Add `defer` or `async` attributes to non-critical scripts in `<head>`. Critical CSS should be inlined.\n```html\n<script src=\"/js/main.js\" defer></script>\n```"},{"priority":1,"title":"Force HTTPS redirect","impact":"Security, Transport Layer","problem":"HTTP does not redirect to HTTPS (http://kawiare.ee... does not redirect), leaving traffic vulnerable to interception.","solution":"Configure server to redirect all HTTP traffic to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Enforce HTTPS redirect for HTTP requests","impact":"Security, Transport Layer","problem":"http://kawiare.ee/kammkarp does not redirect to HTTPS, leaving the site vulnerable to downgrade attacks despite the final URL being HTTPS.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Defer or async non-critical JavaScript","impact":"LCP, FCP, Performance Score","problem":"11 render-blocking scripts in <head> contribute to LCP 8.5s and FCP 4.6s on mobile.","solution":"Add `defer` or `async` attributes to scripts that do not need to execute before DOM parsing. Move non-critical scripts to the footer.\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":1,"title":"Defer render-blocking JavaScript","impact":"LCP, FCP, Mobile Performance","problem":"11 render-blocking scripts in <head> contribute to LCP 9.3 s and FCP 4.6 s on mobile, despite TTFB being 4 ms.","solution":"Add `defer` or `async` to non-critical scripts in the `<head>`. Critical CSS should be inlined, and JS moved to the footer or deferred:\n```html\n<script src=\"/js/main.js\" defer></script>\n```"},{"priority":2,"title":"Strengthen Security Headers (CSP & HSTS)","impact":"Security, XSS protection","problem":"CSP is missing and HSTS lacks preload directive. WooCommerce scripts suggest potential cart functionality, increasing XSS risk.","solution":"- Add Content-Security-Policy with nonce/hash strategy: `Content-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic';`.\n- Update HSTS: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`."},{"priority":2,"title":"Fix SEO and Document Structure","impact":"SEO, Accessibility","problem":"Missing meta description, 3 h1 elements (should be 1), and missing skip-to-content link.","solution":"- Add `<meta name=\"description\" content=\"...\">`.\n- Consolidate to a single `<h1>` per page.\n- Add `<a href=\"#main\" class=\"skip-link\">Skip to content</a>` before the header."},{"priority":2,"title":"Fix Accessibility Violations","impact":"WCAG Compliance, Usability","problem":"1 serious color-contrast violation (#cookiescript_accept) and 1 moderate heading-order skip (h1→h3). Form inputs lack labels.","solution":"- Increase contrast ratio for `.lead-text` and cookie button to ≥4.5:1.\n- Insert an `<h2>` between the existing `<h1>` and `<h3>` elements.\n- Add `<label>` elements or `aria-label` attributes to all form inputs."},{"priority":2,"title":"Defer Render-Blocking JavaScript","impact":"FCP, TBT, Mobile Performance","problem":"11 render-blocking scripts identified (e.g., main.js, jQuery), contributing to 3.6s FCP.","solution":"Add `defer` or `async` attributes to non-critical scripts in `<head>`:\n```html\n<script src=\"main.js\" defer></script>\n```\nMove critical scripts to the footer or inline critical CSS."},{"priority":2,"title":"Fix color contrast and landmark structure","impact":"Accessibility (WCAG 1.4.3, 1.3.1)","problem":"axe-core reports 1 serious contrast violation on #cookiescript_accept and 3 moderate landmark violations (duplicate main).","solution":"- Increase contrast on cookie accept button to ≥4.5:1.\n- Ensure only one `<main>` element exists and it is not nested inside another landmark.\n- Add a skip-to-content link at the top of the page."},{"priority":2,"title":"Fix color contrast on cookie consent","impact":"Accessibility (WCAG 1.4.3)","problem":"axe-core reports 1 serious violation: `#cookiescript_accept` fails minimum contrast ratio.","solution":"Increase contrast between text and background on the cookie accept button to at least 4.5:1 (e.g., darker text or lighter background)."},{"priority":2,"title":"Add Content Security Policy (CSP)","impact":"XSS Defense, Security Headers","problem":"CSP is missing. WooCommerce plugins are detected, suggesting potential cart/checkout interactions elsewhere on the site.","solution":"Implement a strict CSP with nonce/hash for scripts. Start with a report-only policy to avoid breaking functionality.\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"},{"priority":2,"title":"Fix color contrast on cookie consent button","impact":"Accessibility (WCAG 1.4.3)","problem":"axe-core reports a serious violation on `#cookiescript_accept` where foreground/background contrast is insufficient.","solution":"Increase contrast ratio to at least 4.5:1 for normal text. Adjust the button background or text color in CSS:\n```css\n#cookiescript_accept { color: #333; background: #fff; }\n```"},{"priority":2,"title":"Add meta description for SEO","impact":"Search Visibility, CTR","problem":"SEO audit fails `metaDescription` check; document does not have a meta description.","solution":"Add a unique, descriptive meta tag in the `<head>`:\n```html\n<meta name=\"description\" content=\"Kammkarp retsept ja kasu: lihtne fast food, mis ei vaja keerulisi tehnikaid.\">\n```"},{"priority":2,"title":"Add meta description","impact":"SEO, Click-through rate","problem":"SEO audit fails `metaDescription`; HTML Inventory confirms description meta tag is not set.","solution":"Add a unique, descriptive meta description (150–160 characters) in the `<head>`:\n```html\n<meta name=\"description\" content=\"Lugege, kuidas ahven ja koha on väärtuslikud Balti järvede kalad ning kuidas neid valmistada.\">"},{"priority":2,"title":"Fix Color Contrast on Cookie Button","impact":"Accessibility (WCAG 1.4.3)","problem":"axe-core reports a serious contrast violation on `#cookiescript_accept`, making text hard to read for users with visual impairments.","solution":"Increase contrast ratio to at least 4.5:1. Adjust button background or text color:\n```css\n#cookiescript_accept { color: #333; background: #f0f0f0; }\n```"},{"priority":2,"title":"Strengthen Security Headers","impact":"Transport Security, XSS Defense","problem":"HSTS is missing the preload directive; CSP is absent (though site signals indicate low XSS risk).","solution":"Add HSTS preload and a basic CSP:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com;\"\n```"},{"priority":3,"title":"Fix HTML Validation Errors","impact":"Maintainability, Compatibility","problem":"1 W3C error (style not allowed in div) and 6 warnings (obsolete charset, missing headings).","solution":"- Move inline `<style>` blocks to external CSS or `<head>`.\n- Remove obsolete `charset` attributes from script tags.\n- Ensure all `<section>` elements have appropriate heading levels."},{"priority":3,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals indicate no auth/payments/UGC, so this is calibrated to Priority 3 per the security rubric.","solution":"Deploy a strict CSP with nonce/hash for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\"\n```"},{"priority":3,"title":"Add Meta Description and Fix W3C Errors","impact":"SEO, Code Quality","problem":"SEO audit flags missing meta description. W3C validator reports 2 errors (style in div, heading skip).","solution":"- Add `<meta name=\"description\" content=\"...\">` summarizing the article content.\n- Move inline `<style>` blocks to the `<head>` or external CSS file.\n- Ensure heading levels increment sequentially without skipping."},{"priority":3,"title":"Add Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP header is missing. Site signals indicate no auth/payments, lowering priority to P3 per rubric.","solution":"Implement a strict CSP with nonce/hash for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"},{"priority":3,"title":"Resolve W3C Validation Errors","impact":"Code Quality, SEO","problem":"2 errors found: `<style>` not allowed in `div` context, and unescaped `<` character.","solution":"- Move `<style>` blocks to `<head>` or use `<style>` inside allowed containers.\n- Escape special characters in text content (e.g., `&lt;` instead of `<`)."},{"priority":3,"title":"Fix W3C validation errors and add meta description","impact":"SEO, Code Quality","problem":"W3C reports 2 errors (invalid `<style>` in `<div>`, unescaped `<`) and SEO audit notes missing meta description.","solution":"- Move `<style>` blocks to `<head>` or use `<div>`-safe CSS.\n- Escape unescaped `<` characters as `&lt;`.\n- Add `<meta name=\"description\" content=\"...\">` summarizing the article content."},{"priority":3,"title":"Add meta description","impact":"SEO, Click-through rate","problem":"PSI SEO audit fails `metaDescription`; document does not have a meta description.","solution":"Add a concise summary in the `<head>`:\n```html\n<meta name=\"description\" content=\"Learn how to identify high-quality octopus with our guide on texture, origin, and preparation.\">\n```"},{"priority":3,"title":"Add meta description and skip link","impact":"SEO, Accessibility","problem":"SEO audit flags missing meta description; HTML inventory confirms no skip-to-content link.","solution":"- Add `<meta name=\"description\" content=\"...\">` summarizing the article.\n- Add a skip link at the top of the `<body>`:\n```html\n<a href=\"#main\" class=\"skip-link\">Skip to content</a>\n```"},{"priority":3,"title":"Add Meta Description and Image Lazy Loading","impact":"SEO, Page Weight","problem":"Meta description is missing for SEO; 2 images below the fold lack `loading=\"lazy\"`.","solution":"Add meta description in `<head>` and lazy load non-critical images:\n```html\n<meta name=\"description\" content=\"...\">\n<img src=\"...\" loading=\"lazy\" alt=\"...\">\n```"},{"priority":3,"title":"Resolve W3C HTML Validation Errors","impact":"Maintainability, SEO","problem":"2 errors found: `<style>` not allowed as child of `div`, and unescaped `<` character.","solution":"- Move `<style>` blocks to `<head>` or use `<div>`-safe containers.\n- Escape special characters in text content (e.g., use `&lt;` instead of `<`)."}],"coverage":{"pct":100,"missing":[]},"siteSummary":{"pagesAudited":10,"pagesAttempted":10,"urls":["https://kawiare.ee/","https://kawiare.ee/artiklid","https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja","https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta","https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga","https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari","https://kawiare.ee/kammkarp","https://kawiare.ee/ahven-ja-koha","https://kawiare.ee/lumekrabi","https://kawiare.ee/kaaviar-tanapaeval"]},"psiSnapshot":{"rows":[{"pageUrl":"https://kawiare.ee/","perfMobile":49,"perfDesktop":70,"lcpMobileMs":9236.076554146666,"lcpDesktopMs":1805.0444071845686,"clsMobile":1.000187,"clsDesktop":0.637178},{"pageUrl":"https://kawiare.ee/artiklid","perfMobile":68,"perfDesktop":93,"lcpMobileMs":9580.0111903947,"lcpDesktopMs":1655.1035445276773,"clsMobile":0.000677,"clsDesktop":0.001308},{"pageUrl":"https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja","perfMobile":61,"perfDesktop":93,"lcpMobileMs":8641.362938992113,"lcpDesktopMs":1501.4185903886305,"clsMobile":0,"clsDesktop":0.000135},{"pageUrl":"https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta","perfMobile":71,"perfDesktop":94,"lcpMobileMs":6054.8074778339615,"lcpDesktopMs":1513.886758818142,"clsMobile":0,"clsDesktop":0.0001},{"pageUrl":"https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga","perfMobile":69,"perfDesktop":94,"lcpMobileMs":8907.275541628032,"lcpDesktopMs":1526.3310767968417,"clsMobile":0,"clsDesktop":0.000173},{"pageUrl":"https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari","perfMobile":60,"perfDesktop":95,"lcpMobileMs":8573.976904189696,"lcpDesktopMs":1444.0449115356719,"clsMobile":0,"clsDesktop":0.000173},{"pageUrl":"https://kawiare.ee/kammkarp","perfMobile":61,"perfDesktop":96,"lcpMobileMs":8495.896998328875,"lcpDesktopMs":1257.9552119721957,"clsMobile":0,"clsDesktop":0.00009099999999999999},{"pageUrl":"https://kawiare.ee/ahven-ja-koha","perfMobile":59,"perfDesktop":97,"lcpMobileMs":9324.881187693321,"lcpDesktopMs":1126.4082251735067,"clsMobile":0,"clsDesktop":0.0001},{"pageUrl":"https://kawiare.ee/lumekrabi","perfMobile":69,"perfDesktop":98,"lcpMobileMs":8503.168276599548,"lcpDesktopMs":992.6621754001548,"clsMobile":0,"clsDesktop":0.0001},{"pageUrl":"https://kawiare.ee/kaaviar-tanapaeval","perfMobile":69,"perfDesktop":95,"lcpMobileMs":7229.253404938133,"lcpDesktopMs":1436.9700451458145,"clsMobile":0,"clsDesktop":0.00009099999999999999}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket)","evidence":["HTML markers: WP Rocket","generator: WordPress 7.0"]},{"id":"lazyload","title":"Images lazy-loaded","status":"pass","detail":"All raster images use loading=\"lazy\".","evidence":[]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"pass","detail":"Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable).","evidence":["hero: https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-1.png","loading: eager","fetchpriority: (not set)"]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"warn","detail":"Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.","evidence":["selector: div.pt-24.pb-16","url: …e.ee/wp-content/uploads/2026/01/823960696-teadmuskeskus_2592x726_b-scaled.jpg","box: 1280×464px"]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"warn","detail":"Only 15/22 raster images use srcset or <picture> (68%).","evidence":["https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-1.png","https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-e1782658950478.png","…kawiare.ee/wp-content/uploads/2026/02/Kawiare_paisepildid_mob_2_1900x2560.jpg","https://kawiare.ee/wp-content/uploads/2026/02/pais2_uus_2595x1467-scaled.jpg","…kawiare.ee/wp-content/uploads/2026/02/Kawiare_paisepildid_mob_3_1900x2560.jpg"]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"pass","detail":"17 distinct srcset widths.","evidence":["widths: 100, 150, 200, 225, 300, 600, 683, 768, 800, 1024, 1080, 1152, 1365, 1536, 1707, 1920, 2000"]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"fail","detail":"5 render-blocking scripts in <head>. Move to footer or add defer/async.","evidence":["…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638","https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1","https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1","…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0","…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0"]}],"summary":{"passed":4,"warned":2,"failed":1,"notApplicable":0},"priorities":[{"title":"JS scripts not blocking in <head>","severity":"high","detail":"5 render-blocking scripts in <head>. Move to footer or add defer/async."},{"title":"Responsive images (srcset / <picture>)","severity":"medium","detail":"Only 15/22 raster images use srcset or <picture> (68%)."},{"title":"Hero is a real <img> (not a CSS background-image)","severity":"medium","detail":"Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file."}]},"perPageOverall":[{"url":"https://kawiare.ee/","overall":52,"reasoning":"Mobile PSI score of 49 with catastrophic Core Web Vitals (LCP 9.2s, CLS 1.0) places this site in the Poor band despite excellent TTFB (5ms). Accessibility is mostly functional but contains 1 serious contrast violation and structural heading issues (3 h1s). Security headers are weak (40/100) with missing CSP and HSTS preload, though basic protections like X-Frame-Options exist. WooCommerce scripts indicate e-commerce capability despite signals, justifying stricter security recommendations.","confidence":"high","fixes":[{"priority":1,"title":"Fix Largest Contentful Paint (LCP) and Layout Shift (CLS)","impact":"Performance, Core Web Vitals","problem":"LCP is 9.2s (target <2.5s) and CLS is 1.0 (target <0.1), driven by render-blocking scripts and unoptimized hero images.","solution":"- Preload the hero image: `<link rel=\"preload\" as=\"image\" href=\"/hero.webp\">`.\n- Convert hero image to WebP/AVIF and ensure explicit width/height attributes.\n- Defer non-critical JavaScript to reduce render-blocking time."},{"priority":1,"title":"Eliminate Render-Blocking JavaScript","impact":"FCP, LCP, TBT","problem":"11 render-blocking scripts detected (5 in head), including jQuery and WooCommerce assets, delaying page rendering.","solution":"- Add `defer` or `async` to all non-critical scripts.\n- Move script loading to the footer where possible.\n- Inline critical CSS and defer non-critical stylesheets."},{"priority":2,"title":"Strengthen Security Headers (CSP & HSTS)","impact":"Security, XSS protection","problem":"CSP is missing and HSTS lacks preload directive. WooCommerce scripts suggest potential cart functionality, increasing XSS risk.","solution":"- Add Content-Security-Policy with nonce/hash strategy: `Content-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic';`.\n- Update HSTS: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`."},{"priority":2,"title":"Fix SEO and Document Structure","impact":"SEO, Accessibility","problem":"Missing meta description, 3 h1 elements (should be 1), and missing skip-to-content link.","solution":"- Add `<meta name=\"description\" content=\"...\">`.\n- Consolidate to a single `<h1>` per page.\n- Add `<a href=\"#main\" class=\"skip-link\">Skip to content</a>` before the header."},{"priority":3,"title":"Fix HTML Validation Errors","impact":"Maintainability, Compatibility","problem":"1 W3C error (style not allowed in div) and 6 warnings (obsolete charset, missing headings).","solution":"- Move inline `<style>` blocks to external CSS or `<head>`.\n- Remove obsolete `charset` attributes from script tags.\n- Ensure all `<section>` elements have appropriate heading levels."}]},{"url":"https://kawiare.ee/artiklid","overall":55,"reasoning":"Mobile performance is critically low with an LCP of 9.6s, far exceeding the 4s threshold for heavy penalties, driven by 16 render-blocking scripts and a CSS background hero image. A critical security vulnerability exists where HTTP traffic does not redirect to HTTPS, exposing users to interception. Desktop performance is strong (93), but mobile-first indexing penalizes the site based on the mobile metrics. Accessibility has one serious color-contrast violation and heading hierarchy errors. Security headers score 40/100 with missing CSP and weak HSTS configuration.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Data Integrity","problem":"HTTP traffic (http://kawiare.ee/artiklid) does not redirect to HTTPS, leaving initial requests vulnerable to interception.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"LCP, FCP, Mobile Performance","problem":"LCP is 9.6s on mobile due to 16 render-blocking scripts and a hero image implemented as a CSS background (no srcset optimization).","solution":"- Move non-critical scripts to `defer` or `async`.\n- Replace the CSS background hero with a real `<img>` or `<picture>` element with `fetchpriority=\"high\"` and `srcset`.\n- Inline critical CSS and defer the rest."},{"priority":2,"title":"Fix Accessibility Violations","impact":"WCAG Compliance, Usability","problem":"1 serious color-contrast violation (#cookiescript_accept) and 1 moderate heading-order skip (h1→h3). Form inputs lack labels.","solution":"- Increase contrast ratio for `.lead-text` and cookie button to ≥4.5:1.\n- Insert an `<h2>` between the existing `<h1>` and `<h3>` elements.\n- Add `<label>` elements or `aria-label` attributes to all form inputs."},{"priority":3,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals indicate no auth/payments/UGC, so this is calibrated to Priority 3 per the security rubric.","solution":"Deploy a strict CSP with nonce/hash for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\"\n```"},{"priority":3,"title":"Add Meta Description and Fix W3C Errors","impact":"SEO, Code Quality","problem":"SEO audit flags missing meta description. W3C validator reports 2 errors (style in div, heading skip).","solution":"- Add `<meta name=\"description\" content=\"...\">` summarizing the article content.\n- Move inline `<style>` blocks to the `<head>` or external CSS file.\n- Ensure heading levels increment sequentially without skipping."}]},{"url":"https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja","overall":58,"reasoning":"Mobile performance is critically low (61) with an LCP of 8.6s and FCP of 3.6s, dragging the score despite excellent desktop metrics (93). Security configuration has a critical gap: HTTP traffic does not redirect to HTTPS, and the header grade is only 40/100. Accessibility is generally strong (97 PSI) but contains 1 serious contrast violation and landmark structure issues. W3C validation reports 2 errors, and 11 render-blocking scripts contribute to the performance debt. The score reflects these mobile performance and security configuration failures.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Data Integrity","problem":"HTTP traffic (http://kawiare.ee/...) does not redirect to HTTPS, exposing users to downgrade attacks.","solution":"Configure the web server (Apache) to force HTTPS on all HTTP requests:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"LCP, FCP, Mobile Performance","problem":"Mobile LCP is 8.6s (target <2.5s), driven by render-blocking resources and large images.","solution":"- Preload the LCP image (hero) with `<link rel=\"preload\" as=\"image\">`.\n- Defer non-critical CSS/JS.\n- Compress images to WebP/AVIF (currently 5 images, some missing srcset)."},{"priority":2,"title":"Defer Render-Blocking JavaScript","impact":"FCP, TBT, Mobile Performance","problem":"11 render-blocking scripts identified (e.g., main.js, jQuery), contributing to 3.6s FCP.","solution":"Add `defer` or `async` attributes to non-critical scripts in `<head>`:\n```html\n<script src=\"main.js\" defer></script>\n```\nMove critical scripts to the footer or inline critical CSS."},{"priority":2,"title":"Fix Accessibility Violations","impact":"WCAG 1.4.3, 1.3.1","problem":"1 serious color-contrast violation (#cookiescript_accept) and 3 moderate landmark violations (duplicate main).","solution":"- Increase contrast ratio for `.lead-text` or cookie button to ≥4.5:1.\n- Ensure only one `<main>` element exists; remove duplicate `role=\"main\"` attributes.\n- Add a skip-to-content link for keyboard navigation."},{"priority":3,"title":"Add Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP header is missing. Site signals indicate no auth/payments, lowering priority to P3 per rubric.","solution":"Implement a strict CSP with nonce/hash for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"},{"priority":3,"title":"Resolve W3C Validation Errors","impact":"Code Quality, SEO","problem":"2 errors found: `<style>` not allowed in `div` context, and unescaped `<` character.","solution":"- Move `<style>` blocks to `<head>` or use `<style>` inside allowed containers.\n- Escape special characters in text content (e.g., `&lt;` instead of `<`)."}]},{"url":"https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta","overall":62,"reasoning":"Mobile performance (71) is significantly dragged down by LCP 6.1s and 11 render-blocking scripts, despite excellent TTFB (4ms). Security configuration is weak (Grade 40) with a critical missing HTTP-to-HTTPS redirect, though the tested page loads over HTTPS. Accessibility is mostly strong (PSI 97) but has one serious contrast violation and landmark issues. W3C validation shows 2 errors indicating HTML structure problems. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Force HTTPS redirect for all HTTP requests","impact":"Security, Transport Layer","problem":"Security Headers audit shows http://kawiare.ee/... does not redirect to HTTPS, allowing downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS.\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Defer or async render-blocking JavaScript","impact":"LCP, FCP, Performance","problem":"11 render-blocking scripts (including main.js 224KB) delay FCP to 2.57s and LCP to 6.1s on mobile.","solution":"Add `defer` or `async` attributes to non-critical scripts in `<head>`. Critical CSS should be inlined.\n```html\n<script src=\"/js/main.js\" defer></script>\n```"},{"priority":2,"title":"Fix color contrast and landmark structure","impact":"Accessibility (WCAG 1.4.3, 1.3.1)","problem":"axe-core reports 1 serious contrast violation on #cookiescript_accept and 3 moderate landmark violations (duplicate main).","solution":"- Increase contrast on cookie accept button to ≥4.5:1.\n- Ensure only one `<main>` element exists and it is not nested inside another landmark.\n- Add a skip-to-content link at the top of the page."},{"priority":3,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. While site signals show no auth/payments, WordPress sites are high-value targets for plugin-based XSS.","solution":"Deploy a nonce-based CSP rather than a flat allowlist.\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"},{"priority":3,"title":"Fix W3C validation errors and add meta description","impact":"SEO, Code Quality","problem":"W3C reports 2 errors (invalid `<style>` in `<div>`, unescaped `<`) and SEO audit notes missing meta description.","solution":"- Move `<style>` blocks to `<head>` or use `<div>`-safe CSS.\n- Escape unescaped `<` characters as `&lt;`.\n- Add `<meta name=\"description\" content=\"...\">` summarizing the article content."}]},{"url":"https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga","overall":65,"reasoning":"PSI mobile performance is 69 with a critical LCP of 8.9 s, which heavily penalizes the score despite a strong desktop score of 94. Security headers score 40/100 due to a missing HTTP-to-HTTPS redirect and absent CSP, though signals indicate no auth/payments to escalate CSP to P1. Accessibility is mostly solid (PSI 97) but contains 1 serious axe violation on color contrast. SEO suffers from a missing meta description. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Force HTTPS redirect","impact":"Security, Transport Layer","problem":"HTTP does not redirect to HTTPS (http://kawiare.ee... does not redirect), leaving traffic vulnerable to interception.","solution":"Configure server to redirect all HTTP traffic to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Performance, LCP (8.9 s)","problem":"Mobile LCP is 8.9 s (target ≤2.5 s), driven by render-blocking scripts and unoptimized hero image delivery.","solution":"- Preload the hero image resource.\n- Defer non-critical JavaScript (11 render-blocking scripts detected).\n- Ensure hero image is served in next-gen format (WebP/AVIF) with correct dimensions."},{"priority":2,"title":"Defer render-blocking JavaScript","impact":"FCP, TBT, Performance","problem":"11 render-blocking scripts detected in <head> (e.g., jQuery, WooCommerce assets), delaying first paint.","solution":"Add `defer` or `async` attributes to non-critical scripts:\n```html\n<script src=\"...\" defer></script>\n```\nMove critical CSS inline and defer the rest."},{"priority":2,"title":"Fix color contrast on cookie consent","impact":"Accessibility (WCAG 1.4.3)","problem":"axe-core reports 1 serious violation: `#cookiescript_accept` fails minimum contrast ratio.","solution":"Increase contrast between text and background on the cookie accept button to at least 4.5:1 (e.g., darker text or lighter background)."},{"priority":3,"title":"Add meta description","impact":"SEO, Click-through rate","problem":"PSI SEO audit fails `metaDescription`; document does not have a meta description.","solution":"Add a concise summary in the `<head>`:\n```html\n<meta name=\"description\" content=\"Learn how to identify high-quality octopus with our guide on texture, origin, and preparation.\">\n```"},{"priority":3,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense-in-depth","problem":"CSP is missing. Site signals show no auth/payments, so this is P3, but recommended for defense-in-depth.","solution":"Deploy a nonce-based CSP rather than a flat allowlist:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"}]},{"url":"https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari","overall":55,"reasoning":"Mobile performance is poor (60) with LCP 8.6s and FCP 4.6s, heavily penalizing the score despite excellent desktop metrics (95). Security configuration is weak (40/100 headers) with a critical HTTP-to-HTTPS redirect failure that exposes users to downgrade attacks. Accessibility has one serious contrast violation and missing skip link, while HTML validation errors indicate code quality issues. The combination of critical mobile performance bottlenecks and security misconfiguration places the site in the 'Poor' band.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS redirect","impact":"Security, Transport Layer","problem":"HTTP does not redirect to HTTPS (http://kawiare.ee... does not redirect), leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests.\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Eliminate render-blocking JavaScript","impact":"LCP, FCP, Mobile Performance","problem":"11 render-blocking scripts delay FCP to 4.6s and LCP to 8.6s on mobile; 224 KB unused JS identified.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Defer jQuery and theme scripts unless they are required for initial paint.\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":2,"title":"Add Content Security Policy (CSP)","impact":"XSS Defense, Security Headers","problem":"CSP is missing. WooCommerce plugins are detected, suggesting potential cart/checkout interactions elsewhere on the site.","solution":"Implement a strict CSP with nonce/hash for scripts. Start with a report-only policy to avoid breaking functionality.\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"},{"priority":2,"title":"Fix color contrast and landmark structure","impact":"Accessibility (WCAG 1.4.3, 1.3.1)","problem":"1 serious contrast violation on `#cookiescript_accept`; 3 moderate landmark violations (duplicate main, not top-level).","solution":"- Increase contrast on `#cookiescript_accept` to ≥4.5:1.\n- Ensure `<main>` is not nested inside another landmark.\n- Remove duplicate `role=\"main\"` attributes."},{"priority":3,"title":"Add meta description and skip link","impact":"SEO, Accessibility","problem":"SEO audit flags missing meta description; HTML inventory confirms no skip-to-content link.","solution":"- Add `<meta name=\"description\" content=\"...\">` summarizing the article.\n- Add a skip link at the top of the `<body>`:\n```html\n<a href=\"#main\" class=\"skip-link\">Skip to content</a>\n```"}]},{"url":"https://kawiare.ee/kammkarp","overall":62,"reasoning":"Mobile performance (61/100) is the primary drag, driven by a critical LCP of 8.5s and FCP of 4.6s caused by 11 render-blocking scripts. Security posture is weak due to the HTTP version not redirecting to HTTPS, despite the final URL being secure. Accessibility is generally strong (97/100) but contains one serious color-contrast violation. SEO is functional but lacks a meta description. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS redirect for HTTP requests","impact":"Security, Transport Layer","problem":"http://kawiare.ee/kammkarp does not redirect to HTTPS, leaving the site vulnerable to downgrade attacks despite the final URL being HTTPS.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Defer or async non-critical JavaScript","impact":"LCP, FCP, Performance Score","problem":"11 render-blocking scripts in <head> contribute to LCP 8.5s and FCP 4.6s on mobile.","solution":"Add `defer` or `async` attributes to scripts that do not need to execute before DOM parsing. Move non-critical scripts to the footer.\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":2,"title":"Fix color contrast on cookie consent button","impact":"Accessibility (WCAG 1.4.3)","problem":"axe-core reports a serious violation on `#cookiescript_accept` where foreground/background contrast is insufficient.","solution":"Increase contrast ratio to at least 4.5:1 for normal text. Adjust the button background or text color in CSS:\n```css\n#cookiescript_accept { color: #333; background: #fff; }\n```"},{"priority":2,"title":"Add meta description for SEO","impact":"Search Visibility, CTR","problem":"SEO audit fails `metaDescription` check; document does not have a meta description.","solution":"Add a unique, descriptive meta tag in the `<head>`:\n```html\n<meta name=\"description\" content=\"Kammkarp retsept ja kasu: lihtne fast food, mis ei vaja keerulisi tehnikaid.\">\n```"},{"priority":3,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals indicate no auth, payments, or user content, lowering immediate risk but CSP remains a best practice.","solution":"Deploy a strict CSP using nonces for scripts rather than a permissive allowlist:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"}]},{"url":"https://kawiare.ee/ahven-ja-koha","overall":58,"reasoning":"Mobile performance is critically low (LCP 9.3 s, PSI 59) despite excellent server TTFB (4 ms), primarily due to 11 render-blocking scripts and unused JavaScript. Security posture is weakened by the lack of an HTTP-to-HTTPS redirect, creating a man-in-the-middle risk. Accessibility is mostly strong (97 score) but contains one serious color-contrast violation. Desktop performance is excellent (97), highlighting a significant mobile/desktop disparity. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS redirect","impact":"Security, Transport Layer","problem":"Security Headers audit reports that http://kawiare.ee/ahven-ja-koha does not redirect to HTTPS, leaving users on unencrypted connections if they type http://.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Defer render-blocking JavaScript","impact":"LCP, FCP, Mobile Performance","problem":"11 render-blocking scripts in <head> contribute to LCP 9.3 s and FCP 4.6 s on mobile, despite TTFB being 4 ms.","solution":"Add `defer` or `async` to non-critical scripts in the `<head>`. Critical CSS should be inlined, and JS moved to the footer or deferred:\n```html\n<script src=\"/js/main.js\" defer></script>\n```"},{"priority":2,"title":"Fix color contrast on cookie consent","impact":"Accessibility (WCAG 1.4.3)","problem":"axe-core reports 1 serious violation: color-contrast on `#cookiescript_accept` element.","solution":"Increase contrast ratio to at least 4.5:1 for text against background. Adjust CSS:\n```css\n#cookiescript_accept { color: #333333; background: #ffffff; }\n```"},{"priority":2,"title":"Add meta description","impact":"SEO, Click-through rate","problem":"SEO audit fails `metaDescription`; HTML Inventory confirms description meta tag is not set.","solution":"Add a unique, descriptive meta description (150–160 characters) in the `<head>`:\n```html\n<meta name=\"description\" content=\"Lugege, kuidas ahven ja koha on väärtuslikud Balti järvede kalad ning kuidas neid valmistada.\">"},{"priority":3,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals indicate no auth, payments, or user content, so risk is lower than P1, but still recommended for defense.","solution":"Deploy a strict CSP with nonce/hash for scripts. Since this is a content site, a restrictive default-src is safe:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"}]},{"url":"https://kawiare.ee/lumekrabi","overall":68,"reasoning":"Mobile performance (69) is critically impacted by an 8.5s LCP and 11 render-blocking scripts, despite excellent desktop scores (98). Security posture is weak due to missing HTTP-to-HTTPS redirection and incomplete HSTS, though basic headers like X-Frame-Options are present. Accessibility is strong (97) but marred by one serious contrast violation on the cookie button. SEO is solid but lacks a meta description. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Data Integrity","problem":"HTTP requests do not redirect to HTTPS, leaving users vulnerable to man-in-the-middle attacks on the initial connection.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Defer Render-Blocking JavaScript","impact":"LCP, FCP, Performance Score","problem":"11 render-blocking scripts delay first paint; LCP is 8.5s on mobile due to script execution blocking rendering.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Critical CSS should be inlined, and JS moved to footer or deferred:\n```html\n<script src=\"/js/main.js\" defer></script>\n```"},{"priority":2,"title":"Fix Color Contrast on Cookie Button","impact":"Accessibility (WCAG 1.4.3)","problem":"axe-core reports a serious contrast violation on `#cookiescript_accept`, making text hard to read for users with visual impairments.","solution":"Increase contrast ratio to at least 4.5:1. Adjust button background or text color:\n```css\n#cookiescript_accept { color: #333; background: #f0f0f0; }\n```"},{"priority":2,"title":"Strengthen Security Headers","impact":"Transport Security, XSS Defense","problem":"HSTS is missing the preload directive; CSP is absent (though site signals indicate low XSS risk).","solution":"Add HSTS preload and a basic CSP:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com;\"\n```"},{"priority":3,"title":"Add Meta Description and Image Lazy Loading","impact":"SEO, Page Weight","problem":"Meta description is missing for SEO; 2 images below the fold lack `loading=\"lazy\"`.","solution":"Add meta description in `<head>` and lazy load non-critical images:\n```html\n<meta name=\"description\" content=\"...\">\n<img src=\"...\" loading=\"lazy\" alt=\"...\">\n```"}]},{"url":"https://kawiare.ee/kaaviar-tanapaeval","overall":60,"reasoning":"Mobile performance is critically low (LCP 7.2 s, PSI 69) due to 11 render-blocking scripts and unused JavaScript, dragging the score into the 'Needs Improvement' band despite excellent desktop metrics. Security configuration is weak (40/100) with a critical failure where HTTP does not redirect to HTTPS, creating a vulnerability regardless of the final URL being HTTPS. Accessibility is generally good (Lighthouse 97) but has a serious color-contrast violation and missing skip-link. W3C validation shows 2 errors affecting HTML integrity. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS redirect","impact":"Security, Data Integrity","problem":"Security audit found that http://kawiare.ee/kaaviar-tanapaeval does not redirect to HTTPS, leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Eliminate render-blocking JavaScript","impact":"LCP, FCP, Performance Score","problem":"11 render-blocking scripts (including main.js and jQuery) delay FCP to 2.7 s and LCP to 7.2 s on mobile.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Move critical CSS inline and defer JS execution:\n```html\n<script src=\"/js/main.js\" defer></script>\n```"},{"priority":2,"title":"Strengthen Security Headers","impact":"Transport Security, XSS Defense","problem":"HSTS is missing preload directive; CSP is missing (though site signals indicate low XSS risk).","solution":"Update HSTS header to include preload and add a baseline CSP:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com;\"\n```"},{"priority":2,"title":"Fix Accessibility Violations","impact":"WCAG Compliance, Usability","problem":"1 serious color-contrast violation (#cookiescript_accept), 3 moderate landmark issues, and missing skip-to-content link.","solution":"- Increase contrast on `.cookiescript_accept` to ≥4.5:1.\n- Add `<a href=\"#main\" class=\"skip-link\">Skip to content</a>` before the header.\n- Ensure `<main>` is not nested inside another landmark."},{"priority":3,"title":"Resolve W3C HTML Validation Errors","impact":"Maintainability, SEO","problem":"2 errors found: `<style>` not allowed as child of `div`, and unescaped `<` character.","solution":"- Move `<style>` blocks to `<head>` or use `<div>`-safe containers.\n- Escape special characters in text content (e.g., use `&lt;` instead of `<`)."}]}]}