# Audit Report: Kawiare - Experience of Taste
**Website:** https://kawiare.ee/
**Date:** 2026-07-07
**Overall Score:** 57 / 100
**Status:** ๐ **Poor**
**Confidence:** high
**Audit Coverage:** 100% โ all sources returned data
**Pages Audited (10 of 10):**
- https://kawiare.ee/
- https://kawiare.ee/artiklid
- https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja
- https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta
- https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga
- https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari
- https://kawiare.ee/kammkarp
- https://kawiare.ee/ahven-ja-koha
- https://kawiare.ee/lumekrabi
- https://kawiare.ee/kaaviar-tanapaeval
## Summary
Site overall 57 is the mean of 10 pages. Scores range 46 (https://kawiare.ee/ahven-ja-koha) โ 62 (https://kawiare.ee/kammkarp). Weakest page: Mobile LCP of 9.6 s is a critical failure (>4 s threshold), dragging performance to 68 despite a 90 desktop score. Security is compromised by a missing HTTP-to-HTTPS redirect and a 40/100 header grade. Accessibility is strong (97 PSI) but has 1 serious contrast violation. W3C validation shows 2 errors. Confidence is high as all tools returned data.
## Per-Page Scores
| Page | Score | Status | Confidence |
| --- | --- | --- | --- |
| https://kawiare.ee/ | 56 | ๐ **Poor** | high |
| https://kawiare.ee/artiklid | 55 | ๐ **Poor** | high |
| https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja | 62 | ๐ก **Needs Improvement** | high |
| https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta | 62 | ๐ก **Needs Improvement** | high |
| https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga | 48 | ๐ **Poor** | high |
| https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari | 62 | ๐ก **Needs Improvement** | high |
| https://kawiare.ee/kammkarp | 62 | ๐ก **Needs Improvement** | high |
| https://kawiare.ee/ahven-ja-koha | 46 | ๐ **Poor** | high |
| https://kawiare.ee/lumekrabi | 58 | ๐ **Poor** | high |
| https://kawiare.ee/kaaviar-tanapaeval | 56 | ๐ **Poor** | high |
## PageSpeed Insights โ Mobile vs Desktop
_Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._
| URL | Performance (M / D) | LCP (M / D) | CLS (M / D) |
| --- | --- | --- | --- |
| https://kawiare.ee/ | **49** / 69 | **9.19 s** / 1.56 s | **1.000** / 0.637 |
| https://kawiare.ee/artiklid | **67** / 91 | **9.46 s** / 1.75 s | 0.001 / **0.001** |
| https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja | **78** / 94 | **4.62 s** / 1.50 s | 0.000 / **0.000** |
| https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta | **69** / 92 | **8.51 s** / 1.70 s | 0.000 / **0.000** |
| https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga | **60** / 81 | **8.92 s** / 1.89 s | 0.000 / **0.000** |
| https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari | **69** / 95 | **8.76 s** / 1.43 s | 0.000 / **0.000** |
| https://kawiare.ee/kammkarp | **61** / 93 | **8.49 s** / 1.67 s | 0.000 / **0.000** |
| https://kawiare.ee/ahven-ja-koha | **68** / 90 | **9.58 s** / 1.91 s | 0.000 / **0.000** |
| https://kawiare.ee/lumekrabi | **62** / 94 | **8.49 s** / 1.59 s | 0.000 / **0.000** |
| https://kawiare.ee/kaaviar-tanapaeval | **61** / 95 | **8.18 s** / 1.46 s | 0.000 / **0.000** |
## Optimization Checklist
**4 of 7 passing** โ 4 pass ยท 2 warn ยท 1 fail
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | **Pass** | All raster images use loading="lazy". |
| Hero image eagerly loaded | **Pass** | Hero image is eagerly loaded (inferred from DOM order/size โ Lighthouse LCP element unavailable). |
| Hero is a real (not a CSS background-image) | **Warn** | Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport โ there is no srcset equivalent. Move the hero to a real with srcset/sizes (or ) so smaller viewports can fetch a smaller file. |
| Responsive images (srcset / ) | **Warn** | Only 15/22 raster images use srcset or (68%). |
| Reasonable number of image sizes | **Pass** | 17 distinct srcset widths. |
| JS scripts not blocking in | **Fail** | 5 render-blocking scripts in . Move to footer or add defer/async. |
## Fixes
### Priority 1: Critical
*Immediate action โ impacts user experience, search rankings, or site safety.*
**1A. Optimize Largest Contentful Paint (LCP) Image**
- **Impact:** LCP, Performance Score
- **Problem:** LCP is 9.2s on mobile (threshold โค2.5s), caused by the hero image loading without priority.
- **Solution:**
Preload the LCP image and serve it in WebP/AVIF format:
```html
```
**1B. Fix Cumulative Layout Shift (CLS)**
- **Impact:** CLS, User Experience
- **Problem:** CLS is 1.000 (threshold โค0.1), caused by images and content shifting during load.
- **Solution:**
Reserve space for all images and dynamic content using explicit `width` and `height` attributes or aspect-ratio CSS:
```css
img { aspect-ratio: attr(width) / attr(height); }
```
**1C. Force HTTPS redirect on HTTP requests**
- **Impact:** Security, Transport Layer
- **Problem:** HTTP does not redirect to HTTPS (http://kawiare.ee/artiklid does not redirect), leaving users vulnerable to downgrade attacks.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic:
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1D. Fix Mobile LCP (9.5 s) by deferring JS and optimizing hero**
- **Impact:** Performance, Core Web Vitals
- **Problem:** LCP is 9.5 s on mobile due to 16 render-blocking scripts and a hero image implemented as a CSS background (no srcset).
- **Solution:**
- Move non-critical scripts to footer or add `defer`/`async`.
- Replace CSS background hero with a real `` or `` element with `fetchpriority="high"`.
- Defer unused JavaScript (224 KB wasted).
**1E. Enforce HTTPS Redirect**
- **Impact:** Security, Trust
- **Problem:** HTTP requests to http://kawiare.ee do not redirect to HTTPS, exposing users to potential MITM attacks if they type the URL manually.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS:
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1F. Eliminate Render-Blocking JavaScript**
- **Impact:** LCP, FCP, Performance
- **Problem:** 11 render-blocking scripts delay FCP (2.65 s) and contribute to LCP (4.6 s); unused JS totals ~290 KB.
- **Solution:**
Add `defer` or `async` to non-critical scripts in ``. Move critical CSS inline and defer remaining JS:
```html
```
Consider code-splitting the 224 KB `main.js` bundle.
**1G. Force HTTPS redirect for all HTTP traffic**
- **Impact:** Security, Data Integrity
- **Problem:** Security audit shows 'http://kawiare.ee/... does not redirect to HTTPS', leaving users on unencrypted connections.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests.
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1H. Optimize Largest Contentful Paint (LCP)**
- **Impact:** Performance, Mobile UX
- **Problem:** Mobile LCP is 8.5 s (heavy penalty), driven by 11 render-blocking scripts and a large hero image (2560px).
- **Solution:**
- Defer non-critical JavaScript (11 render-blocking scripts found).
- Preload the LCP image resource.
- Compress the hero image to WebP/AVIF and reduce dimensions to viewport size.
```html
```
**1I. Defer render-blocking JavaScript**
- **Impact:** LCP, FCP, Performance Score
- **Problem:** 11 render-blocking scripts delay FCP to 4.6s and LCP to 8.9s on mobile.
- **Solution:**
Add `defer` or `async` to non-critical scripts in ``. Move critical CSS inline and load JS at the bottom or via `defer`:
```html
```
**1J. Eliminate render-blocking JavaScript to fix LCP**
- **Impact:** LCP (8.8s), FCP (2.6s), Mobile Performance (69)
- **Problem:** 5 render-blocking scripts in delay rendering; LCP is 8.8s on mobile, far above the 2.5s target.
- **Solution:**
Move non-critical scripts to the footer or add `defer`/`async` attributes. Prioritize deferring WooCommerce and Google Tag Manager scripts:
```html
```
### Priority 2: Important
*Essential for compliance, user reach, and search visibility.*
**2A. Defer Render-Blocking JavaScript**
- **Impact:** FCP, LCP, TBT
- **Problem:** 11 render-blocking scripts (including jQuery and WooCommerce) delay first paint.
- **Solution:**
Add `defer` or `async` to non-critical scripts in ``:
```html
```
**2B. Strengthen Security Headers**
- **Impact:** Transport Security, Clickjacking
- **Problem:** HSTS is missing the preload directive; CSP is absent (signals show no auth/payments, so P2/P3).
- **Solution:**
Update HSTS header and add CSP:
```
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com;
```
**2C. Fix accessibility violations (Contrast & Headings)**
- **Impact:** WCAG Compliance, Usability
- **Problem:** 1 serious color-contrast violation (#cookiescript_accept) and heading order skips (H1 โ H3).
- **Solution:**
- Increase contrast ratio for `.cookiescript_accept` to โฅ4.5:1.
- Insert an H2 between the H1 and H3s, or change the H3s to H2s to maintain sequential order.
**2D. Strengthen Security Headers (HSTS, COOP, CORP)**
- **Impact:** Transport Security, Context Isolation
- **Problem:** HSTS missing preload directive; COOP and CORP missing (grade 40/100).
- **Solution:**
Add the following headers:
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
Header always set Cross-Origin-Opener-Policy "same-origin"
Header always set Cross-Origin-Resource-Policy "same-origin"
```
**2E. Fix Accessibility Violations**
- **Impact:** WCAG 2.1 AA Compliance
- **Problem:** One serious color-contrast violation on `#cookiescript_accept` and moderate landmark issues (duplicate main, main not top-level).
- **Solution:**
- Increase contrast ratio on `#cookiescript_accept` to โฅ4.5:1.
- Ensure `` is a direct child of `` and remove duplicate `role="main"` attributes.
- Add a skip-to-content link at the top of the DOM.
**2F. Add Content-Security-Policy (CSP) and HSTS Preload**
- **Impact:** XSS Defense, Transport Security
- **Problem:** CSP is missing and HSTS lacks the preload directive; Security Headers grade is 40/100.
- **Solution:**
- Add CSP with nonce/hash strategy (even for brochure sites, it mitigates injection risks).
- Add `preload` to HSTS header.
```apache
Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'"
Header set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
```
**2G. Fix Accessibility Violations (Contrast & Landmarks)**
- **Impact:** WCAG Compliance, Screen Reader Support
- **Problem:** axe-core reports 1 serious color-contrast violation (#cookiescript_accept) and missing skip-to-content link.
- **Solution:**
- Increase contrast ratio for `.lead-text` and cookie banner to โฅ4.5:1.
- Add a skip link at the top of the DOM:
```html
Otse sisule
```
**2H. Fix color contrast on cookie consent buttons**
- **Impact:** Accessibility (WCAG 1.4.3)
- **Problem:** axe-core reports 1 serious violation: `#cookiescript_accept` and `#cookiescript_reject` fail contrast thresholds.
- **Solution:**
Increase text color contrast to at least 4.5:1 against the background. Use browser dev tools to test contrast ratios before deploying:
```css
#cookiescript_accept, #cookiescript_reject {
color: #333333; /* Adjust to meet ratio */
background: #ffffff;
}
```
**2I. Harden security headers**
- **Impact:** Transport security, Context isolation
- **Problem:** HSTS missing preload directive; COOP, CORP, and Permissions-Policy are missing.
- **Solution:**
Update server headers to include preload and context isolation:
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
Header always set Cross-Origin-Opener-Policy "same-origin"
Header always set Cross-Origin-Resource-Policy "same-origin"
```
**2J. Defer Render-Blocking Scripts**
- **Impact:** FCP, TBT, Performance
- **Problem:** HTML Inventory reports 11 render-blocking external scripts, including WooCommerce and jQuery, delaying page interactivity.
- **Solution:**
Add `defer` or `async` attributes to non-critical scripts in ``:
```html
```
- Move critical CSS inline and defer the rest.
- Remove unused JavaScript identified in PSI (224 KB wasted).
**2K. Fix Color Contrast Violation**
- **Impact:** Accessibility, WCAG 1.4.3
- **Problem:** axe-core reports 1 serious violation on `#cookiescript_accept` where foreground/background contrast is insufficient.
- **Solution:**
Increase text color contrast to at least 4.5:1 ratio for the cookie consent button text. Use a darker text color or lighter background in CSS.
### Priority 3: Best Practice
*Recommended for long-term maintainability.*
**3A. Correct HTML Structure and Accessibility**
- **Impact:** SEO, Screen Readers
- **Problem:** Page has 3 `
` elements and missing skip-to-content link; serious contrast violation on cookie button.
- **Solution:**
Ensure only one `
` per page, add `Skip to content`, and fix contrast on `#cookiescript_accept`.
**3B. Implement Content Security Policy (CSP)**
- **Impact:** XSS Defense-in-Depth
- **Problem:** CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower, but WP sites benefit from CSP.
- **Solution:**
Deploy a nonce-based CSP rather than a flat allowlist:
```apache
Header always set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';"
```
**3C. Improve SEO & HTML Validity**
- **Impact:** Search Visibility, Code Quality
- **Problem:** Missing meta description affects SEO snippet; W3C reports 2 errors (invalid `