# Audit Report: Kawiare - Experience of Taste **Website:** https://kawiare.ee/ **Date:** 2026-07-07 **Overall Score:** 57 / 100 **Status:** ๐ŸŸ  **Poor** **Confidence:** high **Audit Coverage:** 100% โ€” all sources returned data **Pages Audited (10 of 10):** - https://kawiare.ee/ - https://kawiare.ee/artiklid - https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja - https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta - https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga - https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari - https://kawiare.ee/kammkarp - https://kawiare.ee/ahven-ja-koha - https://kawiare.ee/lumekrabi - https://kawiare.ee/kaaviar-tanapaeval ## Summary Site overall 57 is the mean of 10 pages. Scores range 46 (https://kawiare.ee/ahven-ja-koha) โ†’ 62 (https://kawiare.ee/kammkarp). Weakest page: Mobile LCP of 9.6 s is a critical failure (>4 s threshold), dragging performance to 68 despite a 90 desktop score. Security is compromised by a missing HTTP-to-HTTPS redirect and a 40/100 header grade. Accessibility is strong (97 PSI) but has 1 serious contrast violation. W3C validation shows 2 errors. Confidence is high as all tools returned data. ## Per-Page Scores | Page | Score | Status | Confidence | | --- | --- | --- | --- | | https://kawiare.ee/ | 56 | ๐ŸŸ  **Poor** | high | | https://kawiare.ee/artiklid | 55 | ๐ŸŸ  **Poor** | high | | https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja | 62 | ๐ŸŸก **Needs Improvement** | high | | https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta | 62 | ๐ŸŸก **Needs Improvement** | high | | https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga | 48 | ๐ŸŸ  **Poor** | high | | https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari | 62 | ๐ŸŸก **Needs Improvement** | high | | https://kawiare.ee/kammkarp | 62 | ๐ŸŸก **Needs Improvement** | high | | https://kawiare.ee/ahven-ja-koha | 46 | ๐ŸŸ  **Poor** | high | | https://kawiare.ee/lumekrabi | 58 | ๐ŸŸ  **Poor** | high | | https://kawiare.ee/kaaviar-tanapaeval | 56 | ๐ŸŸ  **Poor** | high | ## PageSpeed Insights โ€” Mobile vs Desktop _Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._ | URL | Performance (M / D) | LCP (M / D) | CLS (M / D) | | --- | --- | --- | --- | | https://kawiare.ee/ | **49** / 69 | **9.19 s** / 1.56 s | **1.000** / 0.637 | | https://kawiare.ee/artiklid | **67** / 91 | **9.46 s** / 1.75 s | 0.001 / **0.001** | | https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja | **78** / 94 | **4.62 s** / 1.50 s | 0.000 / **0.000** | | https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta | **69** / 92 | **8.51 s** / 1.70 s | 0.000 / **0.000** | | https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga | **60** / 81 | **8.92 s** / 1.89 s | 0.000 / **0.000** | | https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari | **69** / 95 | **8.76 s** / 1.43 s | 0.000 / **0.000** | | https://kawiare.ee/kammkarp | **61** / 93 | **8.49 s** / 1.67 s | 0.000 / **0.000** | | https://kawiare.ee/ahven-ja-koha | **68** / 90 | **9.58 s** / 1.91 s | 0.000 / **0.000** | | https://kawiare.ee/lumekrabi | **62** / 94 | **8.49 s** / 1.59 s | 0.000 / **0.000** | | https://kawiare.ee/kaaviar-tanapaeval | **61** / 95 | **8.18 s** / 1.46 s | 0.000 / **0.000** | ## Optimization Checklist **4 of 7 passing** โ€” 4 pass ยท 2 warn ยท 1 fail | Item | Status | Detail | | --- | --- | --- | | Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) | | Images lazy-loaded | **Pass** | All raster images use loading="lazy". | | Hero image eagerly loaded | **Pass** | Hero image is eagerly loaded (inferred from DOM order/size โ€” Lighthouse LCP element unavailable). | | Hero is a real (not a CSS background-image) | **Warn** | Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport โ€” there is no srcset equivalent. Move the hero to a real with srcset/sizes (or ) so smaller viewports can fetch a smaller file. | | Responsive images (srcset / ) | **Warn** | Only 15/22 raster images use srcset or (68%). | | Reasonable number of image sizes | **Pass** | 17 distinct srcset widths. | | JS scripts not blocking in | **Fail** | 5 render-blocking scripts in . Move to footer or add defer/async. | ## Fixes ### Priority 1: Critical *Immediate action โ€” impacts user experience, search rankings, or site safety.* **1A. Optimize Largest Contentful Paint (LCP) Image** - **Impact:** LCP, Performance Score - **Problem:** LCP is 9.2s on mobile (threshold โ‰ค2.5s), caused by the hero image loading without priority. - **Solution:** Preload the LCP image and serve it in WebP/AVIF format: ```html ... ``` **1B. Fix Cumulative Layout Shift (CLS)** - **Impact:** CLS, User Experience - **Problem:** CLS is 1.000 (threshold โ‰ค0.1), caused by images and content shifting during load. - **Solution:** Reserve space for all images and dynamic content using explicit `width` and `height` attributes or aspect-ratio CSS: ```css img { aspect-ratio: attr(width) / attr(height); } ``` **1C. Force HTTPS redirect on HTTP requests** - **Impact:** Security, Transport Layer - **Problem:** HTTP does not redirect to HTTPS (http://kawiare.ee/artiklid does not redirect), leaving users vulnerable to downgrade attacks. - **Solution:** Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic: ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1D. Fix Mobile LCP (9.5 s) by deferring JS and optimizing hero** - **Impact:** Performance, Core Web Vitals - **Problem:** LCP is 9.5 s on mobile due to 16 render-blocking scripts and a hero image implemented as a CSS background (no srcset). - **Solution:** - Move non-critical scripts to footer or add `defer`/`async`. - Replace CSS background hero with a real `` or `` element with `fetchpriority="high"`. - Defer unused JavaScript (224 KB wasted). **1E. Enforce HTTPS Redirect** - **Impact:** Security, Trust - **Problem:** HTTP requests to http://kawiare.ee do not redirect to HTTPS, exposing users to potential MITM attacks if they type the URL manually. - **Solution:** Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS: ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1F. Eliminate Render-Blocking JavaScript** - **Impact:** LCP, FCP, Performance - **Problem:** 11 render-blocking scripts delay FCP (2.65 s) and contribute to LCP (4.6 s); unused JS totals ~290 KB. - **Solution:** Add `defer` or `async` to non-critical scripts in ``. Move critical CSS inline and defer remaining JS: ```html ``` Consider code-splitting the 224 KB `main.js` bundle. **1G. Force HTTPS redirect for all HTTP traffic** - **Impact:** Security, Data Integrity - **Problem:** Security audit shows 'http://kawiare.ee/... does not redirect to HTTPS', leaving users on unencrypted connections. - **Solution:** Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests. ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1H. Optimize Largest Contentful Paint (LCP)** - **Impact:** Performance, Mobile UX - **Problem:** Mobile LCP is 8.5 s (heavy penalty), driven by 11 render-blocking scripts and a large hero image (2560px). - **Solution:** - Defer non-critical JavaScript (11 render-blocking scripts found). - Preload the LCP image resource. - Compress the hero image to WebP/AVIF and reduce dimensions to viewport size. ```html ``` **1I. Defer render-blocking JavaScript** - **Impact:** LCP, FCP, Performance Score - **Problem:** 11 render-blocking scripts delay FCP to 4.6s and LCP to 8.9s on mobile. - **Solution:** Add `defer` or `async` to non-critical scripts in ``. Move critical CSS inline and load JS at the bottom or via `defer`: ```html ``` **1J. Eliminate render-blocking JavaScript to fix LCP** - **Impact:** LCP (8.8s), FCP (2.6s), Mobile Performance (69) - **Problem:** 5 render-blocking scripts in delay rendering; LCP is 8.8s on mobile, far above the 2.5s target. - **Solution:** Move non-critical scripts to the footer or add `defer`/`async` attributes. Prioritize deferring WooCommerce and Google Tag Manager scripts: ```html ``` ### Priority 2: Important *Essential for compliance, user reach, and search visibility.* **2A. Defer Render-Blocking JavaScript** - **Impact:** FCP, LCP, TBT - **Problem:** 11 render-blocking scripts (including jQuery and WooCommerce) delay first paint. - **Solution:** Add `defer` or `async` to non-critical scripts in ``: ```html ``` **2B. Strengthen Security Headers** - **Impact:** Transport Security, Clickjacking - **Problem:** HSTS is missing the preload directive; CSP is absent (signals show no auth/payments, so P2/P3). - **Solution:** Update HSTS header and add CSP: ``` Strict-Transport-Security: max-age=63072000; includeSubDomains; preload Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com; ``` **2C. Fix accessibility violations (Contrast & Headings)** - **Impact:** WCAG Compliance, Usability - **Problem:** 1 serious color-contrast violation (#cookiescript_accept) and heading order skips (H1 โ†’ H3). - **Solution:** - Increase contrast ratio for `.cookiescript_accept` to โ‰ฅ4.5:1. - Insert an H2 between the H1 and H3s, or change the H3s to H2s to maintain sequential order. **2D. Strengthen Security Headers (HSTS, COOP, CORP)** - **Impact:** Transport Security, Context Isolation - **Problem:** HSTS missing preload directive; COOP and CORP missing (grade 40/100). - **Solution:** Add the following headers: ```apache Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" Header always set Cross-Origin-Opener-Policy "same-origin" Header always set Cross-Origin-Resource-Policy "same-origin" ``` **2E. Fix Accessibility Violations** - **Impact:** WCAG 2.1 AA Compliance - **Problem:** One serious color-contrast violation on `#cookiescript_accept` and moderate landmark issues (duplicate main, main not top-level). - **Solution:** - Increase contrast ratio on `#cookiescript_accept` to โ‰ฅ4.5:1. - Ensure `
` is a direct child of `` and remove duplicate `role="main"` attributes. - Add a skip-to-content link at the top of the DOM. **2F. Add Content-Security-Policy (CSP) and HSTS Preload** - **Impact:** XSS Defense, Transport Security - **Problem:** CSP is missing and HSTS lacks the preload directive; Security Headers grade is 40/100. - **Solution:** - Add CSP with nonce/hash strategy (even for brochure sites, it mitigates injection risks). - Add `preload` to HSTS header. ```apache Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'" Header set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" ``` **2G. Fix Accessibility Violations (Contrast & Landmarks)** - **Impact:** WCAG Compliance, Screen Reader Support - **Problem:** axe-core reports 1 serious color-contrast violation (#cookiescript_accept) and missing skip-to-content link. - **Solution:** - Increase contrast ratio for `.lead-text` and cookie banner to โ‰ฅ4.5:1. - Add a skip link at the top of the DOM: ```html ``` **2H. Fix color contrast on cookie consent buttons** - **Impact:** Accessibility (WCAG 1.4.3) - **Problem:** axe-core reports 1 serious violation: `#cookiescript_accept` and `#cookiescript_reject` fail contrast thresholds. - **Solution:** Increase text color contrast to at least 4.5:1 against the background. Use browser dev tools to test contrast ratios before deploying: ```css #cookiescript_accept, #cookiescript_reject { color: #333333; /* Adjust to meet ratio */ background: #ffffff; } ``` **2I. Harden security headers** - **Impact:** Transport security, Context isolation - **Problem:** HSTS missing preload directive; COOP, CORP, and Permissions-Policy are missing. - **Solution:** Update server headers to include preload and context isolation: ```apache Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" Header always set Cross-Origin-Opener-Policy "same-origin" Header always set Cross-Origin-Resource-Policy "same-origin" ``` **2J. Defer Render-Blocking Scripts** - **Impact:** FCP, TBT, Performance - **Problem:** HTML Inventory reports 11 render-blocking external scripts, including WooCommerce and jQuery, delaying page interactivity. - **Solution:** Add `defer` or `async` attributes to non-critical scripts in ``: ```html ``` - Move critical CSS inline and defer the rest. - Remove unused JavaScript identified in PSI (224 KB wasted). **2K. Fix Color Contrast Violation** - **Impact:** Accessibility, WCAG 1.4.3 - **Problem:** axe-core reports 1 serious violation on `#cookiescript_accept` where foreground/background contrast is insufficient. - **Solution:** Increase text color contrast to at least 4.5:1 ratio for the cookie consent button text. Use a darker text color or lighter background in CSS. ### Priority 3: Best Practice *Recommended for long-term maintainability.* **3A. Correct HTML Structure and Accessibility** - **Impact:** SEO, Screen Readers - **Problem:** Page has 3 `

` elements and missing skip-to-content link; serious contrast violation on cookie button. - **Solution:** Ensure only one `

` per page, add ``, and fix contrast on `#cookiescript_accept`. **3B. Implement Content Security Policy (CSP)** - **Impact:** XSS Defense-in-Depth - **Problem:** CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower, but WP sites benefit from CSP. - **Solution:** Deploy a nonce-based CSP rather than a flat allowlist: ```apache Header always set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';" ``` **3C. Improve SEO & HTML Validity** - **Impact:** Search Visibility, Code Quality - **Problem:** Missing meta description affects SEO snippet; W3C reports 2 errors (invalid `