{"url":"https://kawiare.ee/","date":"2026-07-07","siteName":"Kawiare - Experience of Taste","overall":57,"reasoning":"Site overall 57 is the mean of 10 pages. Scores range 46 (https://kawiare.ee/ahven-ja-koha) → 62 (https://kawiare.ee/kammkarp). Weakest page: Mobile LCP of 9.6 s is a critical failure (>4 s threshold), dragging performance to 68 despite a 90 desktop score. Security is compromised by a missing HTTP-to-HTTPS redirect and a 40/100 header grade. Accessibility is strong (97 PSI) but has 1 serious contrast violation. W3C validation shows 2 errors. Confidence is high as all tools returned data.","confidence":"high","fixes":[{"priority":1,"title":"Optimize Largest Contentful Paint (LCP) Image","impact":"LCP, Performance Score","problem":"LCP is 9.2s on mobile (threshold ≤2.5s), caused by the hero image loading without priority.","solution":"Preload the LCP image and serve it in WebP/AVIF format:\n```html\n<link rel=\"preload\" as=\"image\" href=\"/img/hero.webp\">\n<img src=\"/img/hero.webp\" alt=\"...\" fetchpriority=\"high\">\n```"},{"priority":1,"title":"Fix Cumulative Layout Shift (CLS)","impact":"CLS, User Experience","problem":"CLS is 1.000 (threshold ≤0.1), caused by images and content shifting during load.","solution":"Reserve space for all images and dynamic content using explicit `width` and `height` attributes or aspect-ratio CSS:\n```css\nimg { aspect-ratio: attr(width) / attr(height); }\n```"},{"priority":1,"title":"Force HTTPS redirect on HTTP requests","impact":"Security, Transport Layer","problem":"HTTP does not redirect to HTTPS (http://kawiare.ee/artiklid does not redirect), leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Fix Mobile LCP (9.5 s) by deferring JS and optimizing hero","impact":"Performance, Core Web Vitals","problem":"LCP is 9.5 s on mobile due to 16 render-blocking scripts and a hero image implemented as a CSS background (no srcset).","solution":"- Move non-critical scripts to footer or add `defer`/`async`.\n- Replace CSS background hero with a real `<img>` or `<picture>` element with `fetchpriority=\"high\"`.\n- Defer unused JavaScript (224 KB wasted)."},{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Trust","problem":"HTTP requests to http://kawiare.ee do not redirect to HTTPS, exposing users to potential MITM attacks if they type the URL manually.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Eliminate Render-Blocking JavaScript","impact":"LCP, FCP, Performance","problem":"11 render-blocking scripts delay FCP (2.65 s) and contribute to LCP (4.6 s); unused JS totals ~290 KB.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Move critical CSS inline and defer remaining JS:\n```html\n<script src=\"main.js\" defer></script>\n```\nConsider code-splitting the 224 KB `main.js` bundle."},{"priority":1,"title":"Force HTTPS redirect for all HTTP traffic","impact":"Security, Data Integrity","problem":"Security audit shows 'http://kawiare.ee/... does not redirect to HTTPS', leaving users on unencrypted connections.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests.\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Performance, Mobile UX","problem":"Mobile LCP is 8.5 s (heavy penalty), driven by 11 render-blocking scripts and a large hero image (2560px).","solution":"- Defer non-critical JavaScript (11 render-blocking scripts found).\n- Preload the LCP image resource.\n- Compress the hero image to WebP/AVIF and reduce dimensions to viewport size.\n```html\n<link rel=\"preload\" as=\"image\" href=\"/path/to/hero.webp\">\n```"},{"priority":1,"title":"Defer render-blocking JavaScript","impact":"LCP, FCP, Performance Score","problem":"11 render-blocking scripts delay FCP to 4.6s and LCP to 8.9s on mobile.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Move critical CSS inline and load JS at the bottom or via `defer`:\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":1,"title":"Eliminate render-blocking JavaScript to fix LCP","impact":"LCP (8.8s), FCP (2.6s), Mobile Performance (69)","problem":"5 render-blocking scripts in <head> delay rendering; LCP is 8.8s on mobile, far above the 2.5s target.","solution":"Move non-critical scripts to the footer or add `defer`/`async` attributes. Prioritize deferring WooCommerce and Google Tag Manager scripts:\n```html\n<script src=\"...\" defer></script>\n<script src=\"...\" async></script>\n```"},{"priority":2,"title":"Defer Render-Blocking JavaScript","impact":"FCP, LCP, TBT","problem":"11 render-blocking scripts (including jQuery and WooCommerce) delay first paint.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`:\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":2,"title":"Strengthen Security Headers","impact":"Transport Security, Clickjacking","problem":"HSTS is missing the preload directive; CSP is absent (signals show no auth/payments, so P2/P3).","solution":"Update HSTS header and add CSP:\n```\nStrict-Transport-Security: max-age=63072000; includeSubDomains; preload\nContent-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com;\n```"},{"priority":2,"title":"Fix accessibility violations (Contrast & Headings)","impact":"WCAG Compliance, Usability","problem":"1 serious color-contrast violation (#cookiescript_accept) and heading order skips (H1 → H3).","solution":"- Increase contrast ratio for `.cookiescript_accept` to ≥4.5:1.\n- Insert an H2 between the H1 and H3s, or change the H3s to H2s to maintain sequential order."},{"priority":2,"title":"Strengthen Security Headers (HSTS, COOP, CORP)","impact":"Transport Security, Context Isolation","problem":"HSTS missing preload directive; COOP and CORP missing (grade 40/100).","solution":"Add the following headers:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set Cross-Origin-Opener-Policy \"same-origin\"\nHeader always set Cross-Origin-Resource-Policy \"same-origin\"\n```"},{"priority":2,"title":"Fix Accessibility Violations","impact":"WCAG 2.1 AA Compliance","problem":"One serious color-contrast violation on `#cookiescript_accept` and moderate landmark issues (duplicate main, main not top-level).","solution":"- Increase contrast ratio on `#cookiescript_accept` to ≥4.5:1.\n- Ensure `<main>` is a direct child of `<body>` and remove duplicate `role=\"main\"` attributes.\n- Add a skip-to-content link at the top of the DOM."},{"priority":2,"title":"Add Content-Security-Policy (CSP) and HSTS Preload","impact":"XSS Defense, Transport Security","problem":"CSP is missing and HSTS lacks the preload directive; Security Headers grade is 40/100.","solution":"- Add CSP with nonce/hash strategy (even for brochure sites, it mitigates injection risks).\n- Add `preload` to HSTS header.\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'\"\nHeader set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":2,"title":"Fix Accessibility Violations (Contrast & Landmarks)","impact":"WCAG Compliance, Screen Reader Support","problem":"axe-core reports 1 serious color-contrast violation (#cookiescript_accept) and missing skip-to-content link.","solution":"- Increase contrast ratio for `.lead-text` and cookie banner to ≥4.5:1.\n- Add a skip link at the top of the DOM:\n```html\n<a href=\"#main\" class=\"skip-link\">Otse sisule</a>\n```"},{"priority":2,"title":"Fix color contrast on cookie consent buttons","impact":"Accessibility (WCAG 1.4.3)","problem":"axe-core reports 1 serious violation: `#cookiescript_accept` and `#cookiescript_reject` fail contrast thresholds.","solution":"Increase text color contrast to at least 4.5:1 against the background. Use browser dev tools to test contrast ratios before deploying:\n```css\n#cookiescript_accept, #cookiescript_reject {\n  color: #333333; /* Adjust to meet ratio */\n  background: #ffffff;\n}\n```"},{"priority":2,"title":"Harden security headers","impact":"Transport security, Context isolation","problem":"HSTS missing preload directive; COOP, CORP, and Permissions-Policy are missing.","solution":"Update server headers to include preload and context isolation:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set Cross-Origin-Opener-Policy \"same-origin\"\nHeader always set Cross-Origin-Resource-Policy \"same-origin\"\n```"},{"priority":2,"title":"Defer Render-Blocking Scripts","impact":"FCP, TBT, Performance","problem":"HTML Inventory reports 11 render-blocking external scripts, including WooCommerce and jQuery, delaying page interactivity.","solution":"Add `defer` or `async` attributes to non-critical scripts in `<head>`:\n```html\n<script src=\"/wp-content/plugins/woocommerce/...\" defer></script>\n```\n- Move critical CSS inline and defer the rest.\n- Remove unused JavaScript identified in PSI (224 KB wasted)."},{"priority":2,"title":"Fix Color Contrast Violation","impact":"Accessibility, WCAG 1.4.3","problem":"axe-core reports 1 serious violation on `#cookiescript_accept` where foreground/background contrast is insufficient.","solution":"Increase text color contrast to at least 4.5:1 ratio for the cookie consent button text. Use a darker text color or lighter background in CSS."},{"priority":3,"title":"Correct HTML Structure and Accessibility","impact":"SEO, Screen Readers","problem":"Page has 3 `<h1>` elements and missing skip-to-content link; serious contrast violation on cookie button.","solution":"Ensure only one `<h1>` per page, add `<a href=\"#main\" class=\"skip-link\">Skip to content</a>`, and fix contrast on `#cookiescript_accept`."},{"priority":3,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower, but WP sites benefit from CSP.","solution":"Deploy a nonce-based CSP rather than a flat allowlist:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"},{"priority":3,"title":"Improve SEO & HTML Validity","impact":"Search Visibility, Code Quality","problem":"Missing meta description affects SEO snippet; W3C reports 2 errors (invalid `<style>` in `<div>`, unescaped `<`).","solution":"- Add a `<meta name=\"description\" content=\"...\">` tag.\n- Move inline `<style>` blocks to the `<head>` or external CSS.\n- Escape special characters in text content (e.g., `&lt;` instead of `<`)."},{"priority":3,"title":"Add Meta Description and Fix W3C Errors","impact":"SEO, Code Quality","problem":"SEO audit flags missing meta description; W3C validator reports 2 errors (invalid style tag placement, unescaped character).","solution":"- Add `<meta name=\"description\" content=\"...\">` summarizing the article.\n- Move `<style>` blocks to `<head>` or use inline styles correctly.\n- Escape `<` characters in text content as `&lt;`."},{"priority":3,"title":"Optimize image delivery","impact":"Page weight, LCP","problem":"2 images missing `loading=\"lazy\"`, 2 missing `srcset`, and LCP image is a large PNG.","solution":"- Add `loading=\"lazy\"` to below-fold images.\n- Generate WebP/AVIF versions and use `<picture>` or `srcset`.\n- Ensure LCP image has `fetchpriority=\"high\"` and explicit dimensions."},{"priority":3,"title":"Implement Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower, but CSP remains a best practice.","solution":"Deploy a strict CSP with nonce/hash for scripts rather than a flat allowlist:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\"\n```"},{"priority":3,"title":"Resolve HTML Validation & SEO Gaps","impact":"Maintainability, Search Visibility","problem":"W3C reported 2 errors (style in div, bad char) and SEO audit notes missing meta description.","solution":"- Move `<style>` blocks out of `<div>` containers.\n- Escape special characters (e.g., `<` to `&lt;`).\n- Add a meta description tag:\n```html\n<meta name=\"description\" content=\"...\">\n```"}],"coverage":{"pct":100,"missing":[]},"siteSummary":{"pagesAudited":10,"pagesAttempted":10,"urls":["https://kawiare.ee/","https://kawiare.ee/artiklid","https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja","https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta","https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga","https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari","https://kawiare.ee/kammkarp","https://kawiare.ee/ahven-ja-koha","https://kawiare.ee/lumekrabi","https://kawiare.ee/kaaviar-tanapaeval"]},"psiSnapshot":{"rows":[{"pageUrl":"https://kawiare.ee/","perfMobile":49,"perfDesktop":69,"lcpMobileMs":9193.588002399943,"lcpDesktopMs":1558.5396150308127,"clsMobile":1.000187,"clsDesktop":0.637178},{"pageUrl":"https://kawiare.ee/artiklid","perfMobile":67,"perfDesktop":91,"lcpMobileMs":9457.764322344632,"lcpDesktopMs":1749.8249400387276,"clsMobile":0.000677,"clsDesktop":0.001308},{"pageUrl":"https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja","perfMobile":78,"perfDesktop":94,"lcpMobileMs":4624.554067199797,"lcpDesktopMs":1500.6652241820568,"clsMobile":0,"clsDesktop":0.000173},{"pageUrl":"https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta","perfMobile":69,"perfDesktop":92,"lcpMobileMs":8510.193497411967,"lcpDesktopMs":1704.0322353260135,"clsMobile":0,"clsDesktop":0.0001},{"pageUrl":"https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga","perfMobile":60,"perfDesktop":81,"lcpMobileMs":8922.522379954029,"lcpDesktopMs":1889.2727630989962,"clsMobile":0,"clsDesktop":0.000173},{"pageUrl":"https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari","perfMobile":69,"perfDesktop":95,"lcpMobileMs":8756.380773962504,"lcpDesktopMs":1426.5373405418445,"clsMobile":0,"clsDesktop":0.000173},{"pageUrl":"https://kawiare.ee/kammkarp","perfMobile":61,"perfDesktop":93,"lcpMobileMs":8491.408922844654,"lcpDesktopMs":1666.4849812430944,"clsMobile":0,"clsDesktop":0.0001},{"pageUrl":"https://kawiare.ee/ahven-ja-koha","perfMobile":68,"perfDesktop":90,"lcpMobileMs":9577.121654881916,"lcpDesktopMs":1907.8996578566723,"clsMobile":0,"clsDesktop":0.0001},{"pageUrl":"https://kawiare.ee/lumekrabi","perfMobile":62,"perfDesktop":94,"lcpMobileMs":8485.502392018929,"lcpDesktopMs":1590.5824925847012,"clsMobile":0,"clsDesktop":0.0001},{"pageUrl":"https://kawiare.ee/kaaviar-tanapaeval","perfMobile":61,"perfDesktop":95,"lcpMobileMs":8182.115601496344,"lcpDesktopMs":1458.7089497244096,"clsMobile":0,"clsDesktop":0.0001}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket)","evidence":["HTML markers: WP Rocket","generator: WordPress 7.0"]},{"id":"lazyload","title":"Images lazy-loaded","status":"pass","detail":"All raster images use loading=\"lazy\".","evidence":[]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"pass","detail":"Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable).","evidence":["hero: https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-1.png","loading: eager","fetchpriority: (not set)"]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"warn","detail":"Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.","evidence":["selector: div.pt-24.pb-16","url: …e.ee/wp-content/uploads/2026/01/823960696-teadmuskeskus_2592x726_b-scaled.jpg","box: 1280×464px"]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"warn","detail":"Only 15/22 raster images use srcset or <picture> (68%).","evidence":["https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-1.png","https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-e1782658950478.png","…kawiare.ee/wp-content/uploads/2026/02/Kawiare_paisepildid_mob_2_1900x2560.jpg","https://kawiare.ee/wp-content/uploads/2026/02/pais2_uus_2595x1467-scaled.jpg","…kawiare.ee/wp-content/uploads/2026/02/Kawiare_paisepildid_mob_3_1900x2560.jpg"]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"pass","detail":"17 distinct srcset widths.","evidence":["widths: 100, 150, 200, 225, 300, 600, 683, 768, 800, 1024, 1080, 1152, 1365, 1536, 1707, 1920, 2000"]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"fail","detail":"5 render-blocking scripts in <head>. Move to footer or add defer/async.","evidence":["…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638","https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1","https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1","…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0","…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0"]}],"summary":{"passed":4,"warned":2,"failed":1,"notApplicable":0},"priorities":[{"title":"JS scripts not blocking in <head>","severity":"high","detail":"5 render-blocking scripts in <head>. Move to footer or add defer/async."},{"title":"Responsive images (srcset / <picture>)","severity":"medium","detail":"Only 15/22 raster images use srcset or <picture> (68%)."},{"title":"Hero is a real <img> (not a CSS background-image)","severity":"medium","detail":"Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file."}]},"perPageOverall":[{"url":"https://kawiare.ee/","overall":56,"reasoning":"Mobile performance is critically low (49) driven by LCP 9.2s and CLS 1.0, which heavily penalize the score. Images consume 1.46 MB of the 1.84 MB total weight without modern formats like WebP. Security headers score 40/100, missing HSTS preload and CSP, though site signals indicate no active auth/payments. Accessibility is strong (97) but marred by structural HTML errors like three `<h1>` tags.","confidence":"high","fixes":[{"priority":1,"title":"Optimize Largest Contentful Paint (LCP) Image","impact":"LCP, Performance Score","problem":"LCP is 9.2s on mobile (threshold ≤2.5s), caused by the hero image loading without priority.","solution":"Preload the LCP image and serve it in WebP/AVIF format:\n```html\n<link rel=\"preload\" as=\"image\" href=\"/img/hero.webp\">\n<img src=\"/img/hero.webp\" alt=\"...\" fetchpriority=\"high\">\n```"},{"priority":1,"title":"Fix Cumulative Layout Shift (CLS)","impact":"CLS, User Experience","problem":"CLS is 1.000 (threshold ≤0.1), caused by images and content shifting during load.","solution":"Reserve space for all images and dynamic content using explicit `width` and `height` attributes or aspect-ratio CSS:\n```css\nimg { aspect-ratio: attr(width) / attr(height); }\n```"},{"priority":2,"title":"Defer Render-Blocking JavaScript","impact":"FCP, LCP, TBT","problem":"11 render-blocking scripts (including jQuery and WooCommerce) delay first paint.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`:\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":2,"title":"Strengthen Security Headers","impact":"Transport Security, Clickjacking","problem":"HSTS is missing the preload directive; CSP is absent (signals show no auth/payments, so P2/P3).","solution":"Update HSTS header and add CSP:\n```\nStrict-Transport-Security: max-age=63072000; includeSubDomains; preload\nContent-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com;\n```"},{"priority":3,"title":"Correct HTML Structure and Accessibility","impact":"SEO, Screen Readers","problem":"Page has 3 `<h1>` elements and missing skip-to-content link; serious contrast violation on cookie button.","solution":"Ensure only one `<h1>` per page, add `<a href=\"#main\" class=\"skip-link\">Skip to content</a>`, and fix contrast on `#cookiescript_accept`."}]},{"url":"https://kawiare.ee/artiklid","overall":55,"reasoning":"Mobile performance (67) is critically impacted by an LCP of 9.5 s, despite excellent desktop scores (91). Security configuration is weak (grade 40) with HTTP not redirecting to HTTPS, a high-priority vulnerability. Accessibility is strong (96) but marred by one serious contrast violation and heading hierarchy errors. The site appears to be a content hub for a seafood brand, where mobile speed is crucial for SEO. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Force HTTPS redirect on HTTP requests","impact":"Security, Transport Layer","problem":"HTTP does not redirect to HTTPS (http://kawiare.ee/artiklid does not redirect), leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Fix Mobile LCP (9.5 s) by deferring JS and optimizing hero","impact":"Performance, Core Web Vitals","problem":"LCP is 9.5 s on mobile due to 16 render-blocking scripts and a hero image implemented as a CSS background (no srcset).","solution":"- Move non-critical scripts to footer or add `defer`/`async`.\n- Replace CSS background hero with a real `<img>` or `<picture>` element with `fetchpriority=\"high\"`.\n- Defer unused JavaScript (224 KB wasted)."},{"priority":2,"title":"Fix accessibility violations (Contrast & Headings)","impact":"WCAG Compliance, Usability","problem":"1 serious color-contrast violation (#cookiescript_accept) and heading order skips (H1 → H3).","solution":"- Increase contrast ratio for `.cookiescript_accept` to ≥4.5:1.\n- Insert an H2 between the H1 and H3s, or change the H3s to H2s to maintain sequential order."},{"priority":2,"title":"Strengthen Security Headers (HSTS, COOP, CORP)","impact":"Transport Security, Context Isolation","problem":"HSTS missing preload directive; COOP and CORP missing (grade 40/100).","solution":"Add the following headers:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set Cross-Origin-Opener-Policy \"same-origin\"\nHeader always set Cross-Origin-Resource-Policy \"same-origin\"\n```"},{"priority":3,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower, but WP sites benefit from CSP.","solution":"Deploy a nonce-based CSP rather than a flat allowlist:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"}]},{"url":"https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja","overall":62,"reasoning":"Mobile performance (78) is significantly dragged down by a 4.6 s LCP and 11 render-blocking scripts, violating Core Web Vitals thresholds. Security configuration is flawed because HTTP requests do not redirect to HTTPS, creating a potential MITM risk despite the HTTPS grade of 40/100. Accessibility is strong (97) but contains one serious color-contrast violation and landmark structure issues. SEO is mostly solid but lacks a meta description, and W3C validation shows 2 errors. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Trust","problem":"HTTP requests to http://kawiare.ee do not redirect to HTTPS, exposing users to potential MITM attacks if they type the URL manually.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Eliminate Render-Blocking JavaScript","impact":"LCP, FCP, Performance","problem":"11 render-blocking scripts delay FCP (2.65 s) and contribute to LCP (4.6 s); unused JS totals ~290 KB.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Move critical CSS inline and defer remaining JS:\n```html\n<script src=\"main.js\" defer></script>\n```\nConsider code-splitting the 224 KB `main.js` bundle."},{"priority":2,"title":"Strengthen Security Headers","impact":"Security Headers Grade (40/100)","problem":"Missing Content-Security-Policy and weak HSTS (no preload) lower the security grade; X-Frame-Options is present but CSP is preferred.","solution":"Add CSP with nonce/hash strategy and enable HSTS preload:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":2,"title":"Fix Accessibility Violations","impact":"WCAG 2.1 AA Compliance","problem":"One serious color-contrast violation on `#cookiescript_accept` and moderate landmark issues (duplicate main, main not top-level).","solution":"- Increase contrast ratio on `#cookiescript_accept` to ≥4.5:1.\n- Ensure `<main>` is a direct child of `<body>` and remove duplicate `role=\"main\"` attributes.\n- Add a skip-to-content link at the top of the DOM."},{"priority":3,"title":"Improve SEO & HTML Validity","impact":"Search Visibility, Code Quality","problem":"Missing meta description affects SEO snippet; W3C reports 2 errors (invalid `<style>` in `<div>`, unescaped `<`).","solution":"- Add a `<meta name=\"description\" content=\"...\">` tag.\n- Move inline `<style>` blocks to the `<head>` or external CSS.\n- Escape special characters in text content (e.g., `&lt;` instead of `<`)."}]},{"url":"https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta","overall":62,"reasoning":"Mobile performance is the primary drag with an LCP of 8.5 s and a PSI score of 69, despite a strong Desktop score of 92. Security posture is weak (Grade 40/100) with a critical failure where HTTP does not redirect to HTTPS. Accessibility is strong (PSI 97) but marred by one serious contrast violation and missing skip-to-content links. The combination of critical mobile performance latency and security configuration errors prevents a higher score despite good accessibility and SEO fundamentals.","confidence":"high","fixes":[{"priority":1,"title":"Force HTTPS redirect for all HTTP traffic","impact":"Security, Data Integrity","problem":"Security audit shows 'http://kawiare.ee/... does not redirect to HTTPS', leaving users on unencrypted connections.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests.\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Performance, Mobile UX","problem":"Mobile LCP is 8.5 s (heavy penalty), driven by 11 render-blocking scripts and a large hero image (2560px).","solution":"- Defer non-critical JavaScript (11 render-blocking scripts found).\n- Preload the LCP image resource.\n- Compress the hero image to WebP/AVIF and reduce dimensions to viewport size.\n```html\n<link rel=\"preload\" as=\"image\" href=\"/path/to/hero.webp\">\n```"},{"priority":2,"title":"Add Content-Security-Policy (CSP) and HSTS Preload","impact":"XSS Defense, Transport Security","problem":"CSP is missing and HSTS lacks the preload directive; Security Headers grade is 40/100.","solution":"- Add CSP with nonce/hash strategy (even for brochure sites, it mitigates injection risks).\n- Add `preload` to HSTS header.\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'\"\nHeader set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":2,"title":"Fix Accessibility Violations (Contrast & Landmarks)","impact":"WCAG Compliance, Screen Reader Support","problem":"axe-core reports 1 serious color-contrast violation (#cookiescript_accept) and missing skip-to-content link.","solution":"- Increase contrast ratio for `.lead-text` and cookie banner to ≥4.5:1.\n- Add a skip link at the top of the DOM:\n```html\n<a href=\"#main\" class=\"skip-link\">Otse sisule</a>\n```"},{"priority":3,"title":"Add Meta Description and Fix W3C Errors","impact":"SEO, Code Quality","problem":"SEO audit flags missing meta description; W3C validator reports 2 errors (invalid style tag placement, unescaped character).","solution":"- Add `<meta name=\"description\" content=\"...\">` summarizing the article.\n- Move `<style>` blocks to `<head>` or use inline styles correctly.\n- Escape `<` characters in text content as `&lt;`."}]},{"url":"https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga","overall":48,"reasoning":"Mobile performance is critically low (60/100) with an LCP of 8.9s and FCP of 4.6s, primarily due to 11 render-blocking scripts and heavy image delivery. Security posture is weak with a critical HTTP-to-HTTPS redirect failure and missing CSP, despite basic headers like X-Frame-Options being present. Accessibility has one serious contrast violation and structural landmark issues that affect screen reader navigation. The combination of catastrophic mobile load times and transport security gaps places this site in the 'Poor' band.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS redirect","impact":"Transport security, data integrity","problem":"HTTP requests do not redirect to HTTPS, exposing traffic to interception.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Defer render-blocking JavaScript","impact":"LCP, FCP, Performance Score","problem":"11 render-blocking scripts delay FCP to 4.6s and LCP to 8.9s on mobile.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Move critical CSS inline and load JS at the bottom or via `defer`:\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":2,"title":"Fix accessibility violations","impact":"WCAG 2.1 AA compliance, Screen readers","problem":"1 serious color-contrast violation on `#cookiescript_accept` and 3 moderate landmark issues (duplicate main, not top-level).","solution":"- Increase contrast on `#cookiescript_accept` to ≥4.5:1.\n- Ensure `<main>` is not nested inside another landmark.\n- Add a skip-to-content link: `<a href=\"#main\" class=\"skip-link\">Skip to content</a>`."},{"priority":2,"title":"Strengthen security headers","impact":"XSS defense, HSTS preload eligibility","problem":"Security Headers grade is 40/100; CSP is missing and HSTS lacks preload directive.","solution":"Add Content-Security-Policy (nonce-based) and update HSTS:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'\"\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":3,"title":"Optimize image delivery","impact":"Page weight, LCP","problem":"2 images missing `loading=\"lazy\"`, 2 missing `srcset`, and LCP image is a large PNG.","solution":"- Add `loading=\"lazy\"` to below-fold images.\n- Generate WebP/AVIF versions and use `<picture>` or `srcset`.\n- Ensure LCP image has `fetchpriority=\"high\"` and explicit dimensions."}]},{"url":"https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari","overall":62,"reasoning":"Mobile LCP 8.8s is the primary drag, exceeding the 4s heavy penalty threshold and indicating poor mobile UX. Security configuration is weak with HTTP not redirecting to HTTPS and a 40/100 header grade, creating potential downgrade risks. Accessibility is strong (97 PSI) but has 1 serious axe violation on cookie buttons. Desktop performance is excellent (95), but mobile-first indexing prioritizes the 69 mobile score. W3C validation shows 2 errors that need cleanup.","confidence":"high","fixes":[{"priority":1,"title":"Force HTTPS redirect for all HTTP traffic","impact":"Security, Transport integrity","problem":"HTTP does not redirect to HTTPS (http://kawiare.ee/... returns 200 instead of 301/302), leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to the HTTPS equivalent:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Eliminate render-blocking JavaScript to fix LCP","impact":"LCP (8.8s), FCP (2.6s), Mobile Performance (69)","problem":"5 render-blocking scripts in <head> delay rendering; LCP is 8.8s on mobile, far above the 2.5s target.","solution":"Move non-critical scripts to the footer or add `defer`/`async` attributes. Prioritize deferring WooCommerce and Google Tag Manager scripts:\n```html\n<script src=\"...\" defer></script>\n<script src=\"...\" async></script>\n```"},{"priority":2,"title":"Fix color contrast on cookie consent buttons","impact":"Accessibility (WCAG 1.4.3)","problem":"axe-core reports 1 serious violation: `#cookiescript_accept` and `#cookiescript_reject` fail contrast thresholds.","solution":"Increase text color contrast to at least 4.5:1 against the background. Use browser dev tools to test contrast ratios before deploying:\n```css\n#cookiescript_accept, #cookiescript_reject {\n  color: #333333; /* Adjust to meet ratio */\n  background: #ffffff;\n}\n```"},{"priority":3,"title":"Implement Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower, but CSP remains a best practice.","solution":"Deploy a strict CSP with nonce/hash for scripts rather than a flat allowlist:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\"\n```"}]},{"url":"https://kawiare.ee/kammkarp","overall":62,"reasoning":"Mobile performance (61) is dragged down by an 8.5 s LCP and 4.6 s FCP, primarily due to 11 render-blocking scripts and unused JavaScript. Security configuration is weak with a missing HTTP-to-HTTPS redirect and a 40/100 header grade, though the site loads securely via HTTPS. Accessibility has one serious contrast violation and missing skip links, while W3C validation shows 2 errors. Desktop performance is strong (93), but mobile-first indexing penalizes the mobile experience heavily.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS redirect","impact":"Security, Transport integrity","problem":"Security Headers audit confirms http://kawiare.ee/kammkarp does not redirect to HTTPS, allowing downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to the HTTPS equivalent:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Eliminate render-blocking JavaScript","impact":"LCP, FCP, Mobile Performance","problem":"11 render-blocking scripts and 224 KB unused JS delay First Contentful Paint to 4.6 s and LCP to 8.5 s on mobile.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Defer jQuery and theme scripts unless required for initial paint:\n```html\n<script src=\"main.js\" defer></script>\n```\nRemove unused JS via tree-shaking or plugin configuration."},{"priority":2,"title":"Fix accessibility violations","impact":"WCAG 1.4.3, 2.4.1","problem":"1 serious color-contrast violation on `#cookiescript_accept` and missing skip-to-content link.","solution":"- Increase contrast on `.cookiescript_accept` to ≥4.5:1.\n- Add a skip link at the top of `<body>`:\n```html\n<a href=\"#main\" class=\"skip-link\">Otse sisu juurde</a>\n```"},{"priority":2,"title":"Harden security headers","impact":"Transport security, Context isolation","problem":"HSTS missing preload directive; COOP, CORP, and Permissions-Policy are missing.","solution":"Update server headers to include preload and context isolation:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set Cross-Origin-Opener-Policy \"same-origin\"\nHeader always set Cross-Origin-Resource-Policy \"same-origin\"\n```"},{"priority":3,"title":"Implement Content Security Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing. Site signals indicate no auth, payments, or user content, lowering immediate risk but CSP remains best practice.","solution":"Deploy a strict CSP with nonce/hash for scripts:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```\nEnsure all inline scripts use the nonce."}]},{"url":"https://kawiare.ee/ahven-ja-koha","overall":46,"reasoning":"Mobile LCP of 9.6 s is a critical failure (>4 s threshold), dragging performance to 68 despite a 90 desktop score. Security is compromised by a missing HTTP-to-HTTPS redirect and a 40/100 header grade. Accessibility is strong (97 PSI) but has 1 serious contrast violation. W3C validation shows 2 errors. Confidence is high as all tools returned data.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Data Integrity","problem":"Security Headers audit found 'http://kawiare.ee/ahven-ja-koha does not redirect to HTTPS', leaving initial requests vulnerable.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS.\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Performance, Mobile UX","problem":"Mobile LCP is 9.6 s (threshold >4 s), caused by 11 render-blocking scripts and a 2560×717 hero image.","solution":"- Convert hero image to WebP/AVIF and compress.\n- Defer non-critical JavaScript (11 render-blocking scripts found).\n- Preload the LCP image resource.\n```html\n<link rel=\"preload\" as=\"image\" href=\"/path/to/hero.webp\">\n```"},{"priority":2,"title":"Strengthen Security Headers","impact":"XSS/Clickjacking Protection","problem":"Security Headers grade is 40/100; HSTS missing preload, CSP missing, and COOP/CORP absent.","solution":"Add missing headers to server config. HSTS should include preload.\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"title":"Fix Accessibility Violations","impact":"WCAG Compliance, Usability","problem":"axe-core found 1 serious color-contrast violation (#cookiescript_accept) and 3 moderate landmark issues; skip-to-content link missing.","solution":"- Increase contrast ratio for `.cookiescript_accept` to ≥4.5:1.\n- Ensure `<main>` is not nested inside another landmark.\n- Add a skip link at the top of the `<body>`:\n```html\n<a href=\"#main\" class=\"skip-link\">Otse sisule</a>\n```"},{"priority":3,"title":"Resolve HTML Validation & SEO Gaps","impact":"Maintainability, Search Visibility","problem":"W3C reported 2 errors (style in div, bad char) and SEO audit notes missing meta description.","solution":"- Move `<style>` blocks out of `<div>` containers.\n- Escape special characters (e.g., `<` to `&lt;`).\n- Add a meta description tag:\n```html\n<meta name=\"description\" content=\"...\">\n```"}]},{"url":"https://kawiare.ee/lumekrabi","overall":58,"reasoning":"Mobile performance is critically low (62) with an LCP of 8.5s, driven by render-blocking scripts and an unoptimized hero image. A critical security flaw exists where HTTP traffic does not redirect to HTTPS, exposing users to downgrade attacks. Accessibility is mostly sound but contains one serious contrast violation and missing skip links. Security headers are weak (40/100) with missing CSP and HSTS preload. The score reflects the severe mobile performance degradation and the critical security configuration gap.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Transport Layer","problem":"HTTP traffic does not redirect to HTTPS (http://kawiare.ee/lumekrabi does not redirect), leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Performance, Mobile UX","problem":"LCP is 8.5s on mobile (target ≤2.5s), caused by a 2560px hero image and render-blocking JavaScript.","solution":"1. Convert hero image to WebP/AVIF and compress.\n2. Add `fetchpriority=\"high\"` to the hero image.\n3. Defer non-critical JS (see P2 fix) to reduce main thread blocking."},{"priority":2,"title":"Defer Render-Blocking JavaScript","impact":"FCP, TBT, LCP","problem":"11 render-blocking scripts (including jQuery and WooCommerce assets) delay FCP to 3.6s and contribute to 8.5s LCP.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Move WooCommerce JS to footer if not needed for initial paint:\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":2,"title":"Strengthen Security Headers","impact":"XSS, Clickjacking, Transport Security","problem":"Security Headers grade is 40/100; HSTS lacks preload directive, and CSP is missing.","solution":"1. Add `preload` to HSTS: `max-age=31536000; includeSubDomains; preload`.\n2. Implement a strict CSP (nonce-based) to mitigate XSS, especially given WooCommerce assets are present."},{"priority":2,"title":"Fix Accessibility Violations","impact":"WCAG Compliance, Usability","problem":"1 serious color-contrast violation (#cookiescript_accept) and missing skip-to-content link.","solution":"1. Increase contrast ratio for `.lead-text` and cookie button to ≥4.5:1.\n2. Add a skip link at the top of the `<body>`:\n```html\n<a href=\"#main\" class=\"skip-link\">Skip to content</a>\n```"}]},{"url":"https://kawiare.ee/kaaviar-tanapaeval","overall":56,"reasoning":"Mobile performance is critically low (61) with an LCP of 8.2 s, far exceeding the 4 s penalty threshold. A critical security configuration error exists where HTTP traffic does not redirect to HTTPS, exposing users to interception. While accessibility is generally good (97 PSI), one serious contrast violation and 11 render-blocking scripts degrade the user experience. Security headers score 40/100 with missing CSP and weak HSTS. The combination of severe performance delays and transport security misconfiguration places the site in the 'Poor' band.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Transport Integrity","problem":"Security Headers audit shows 'http://kawiare.ee/kaaviar-tanapaeval does not redirect to HTTPS', leaving non-HTTPS traffic unencrypted.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Performance, Core Web Vitals","problem":"Mobile LCP is 8.2 s (threshold is ≤2.5 s), driven by render-blocking resources and unoptimized hero image loading.","solution":"- Preload the LCP hero image: `<link rel=\"preload\" as=\"image\" href=\"/path/to/hero.jpg\">`.\n- Defer non-critical CSS/JS.\n- Ensure the hero image uses `fetchpriority=\"high\"` and is served in WebP/AVIF format."},{"priority":2,"title":"Defer Render-Blocking Scripts","impact":"FCP, TBT, Performance","problem":"HTML Inventory reports 11 render-blocking external scripts, including WooCommerce and jQuery, delaying page interactivity.","solution":"Add `defer` or `async` attributes to non-critical scripts in `<head>`:\n```html\n<script src=\"/wp-content/plugins/woocommerce/...\" defer></script>\n```\n- Move critical CSS inline and defer the rest.\n- Remove unused JavaScript identified in PSI (224 KB wasted)."},{"priority":2,"title":"Fix Color Contrast Violation","impact":"Accessibility, WCAG 1.4.3","problem":"axe-core reports 1 serious violation on `#cookiescript_accept` where foreground/background contrast is insufficient.","solution":"Increase text color contrast to at least 4.5:1 ratio for the cookie consent button text. Use a darker text color or lighter background in CSS."},{"priority":3,"title":"Implement Content Security Policy (CSP)","impact":"Security, XSS Defense","problem":"CSP is missing. While site signals indicate no auth/payments (P3 per rubric), a CSP provides defense-in-depth against injected scripts.","solution":"Deploy a strict CSP header with nonce-based script execution:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```\n- Ensure all inline scripts use the nonce."}]}]}