# Audit Report: Kawiare - Experience of Taste **Website:** https://kawiare.ee/ **Date:** 2026-07-13 **Overall Score:** 56 / 100 **Status:** 🟠 **Poor** **Confidence:** high **Audit Coverage:** 100% — all sources returned data **Pages Audited (10 of 10):** - https://kawiare.ee/ - https://kawiare.ee/artiklid - https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja - https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta - https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga - https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari - https://kawiare.ee/kammkarp - https://kawiare.ee/ahven-ja-koha - https://kawiare.ee/lumekrabi - https://kawiare.ee/kaaviar-tanapaeval ## Summary Site overall 56 is the mean of 10 pages. Scores range 45 (https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja) → 62 (https://kawiare.ee/kaaviar-tanapaeval). Weakest page: Mobile performance is critically low (63/100) with an LCP of 8.6 s, far exceeding the 2.5 s threshold and dragging the overall score. A critical security configuration error exists where HTTP traffic does not redirect to HTTPS, exposing users to downgrade attacks. Accessibility has a serious contrast violation and missing skip-link, though desktop performance is strong (95/100). Security headers are weak (40/100) with missing CSP and preload, but the HTTP redirect failure is the most urgent security fix. The site functions but requires significant optimization for mobile users and security hardening. ## Per-Page Scores | Page | Score | Status | Confidence | | --- | --- | --- | --- | | https://kawiare.ee/ | 55 | 🟠 **Poor** | high | | https://kawiare.ee/artiklid | 48 | 🟠 **Poor** | high | | https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja | 45 | 🟠 **Poor** | high | | https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta | 58 | 🟠 **Poor** | high | | https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga | 55 | 🟠 **Poor** | high | | https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari | 62 | 🟡 **Needs Improvement** | high | | https://kawiare.ee/kammkarp | 62 | 🟡 **Needs Improvement** | high | | https://kawiare.ee/ahven-ja-koha | 55 | 🟠 **Poor** | high | | https://kawiare.ee/lumekrabi | 62 | 🟡 **Needs Improvement** | high | | https://kawiare.ee/kaaviar-tanapaeval | 62 | 🟡 **Needs Improvement** | high | ## PageSpeed Insights — Mobile vs Desktop _Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._ | URL | Performance (M / D) | LCP (M / D) | CLS (M / D) | | --- | --- | --- | --- | | https://kawiare.ee/ | **49** / 71 | **9.27 s** / 1.67 s | **1.000** / 0.637 | | https://kawiare.ee/artiklid | **61** / 89 | **7.82 s** / 1.79 s | 0.001 / **0.001** | | https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja | **63** / 95 | **8.65 s** / 1.51 s | 0.000 / **0.000** | | https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta | **60** / 72 | **8.49 s** / 1.77 s | 0.000 / **0.000** | | https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga | **60** / 91 | **8.95 s** / 1.61 s | 0.000 / **0.000** | | https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari | **60** / 94 | **8.56 s** / 1.60 s | 0.000 / **0.000** | | https://kawiare.ee/kammkarp | **60** / 98 | **8.48 s** / 1.01 s | 0.000 / **0.000** | | https://kawiare.ee/ahven-ja-koha | **68** / 94 | **8.39 s** / 1.58 s | 0.000 / **0.000** | | https://kawiare.ee/lumekrabi | **65** / 94 | **7.28 s** / 1.53 s | 0.000 / **0.000** | | https://kawiare.ee/kaaviar-tanapaeval | **56** / 95 | **8.34 s** / 1.48 s | 0.000 / **0.000** | ## Optimization Checklist **4 of 7 passing** — 4 pass · 2 warn · 1 fail | Item | Status | Detail | | --- | --- | --- | | Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) | | Images lazy-loaded | **Pass** | All raster images use loading="lazy". | | Hero image eagerly loaded | **Pass** | Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable). | | Hero is a real (not a CSS background-image) | **Warn** | Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real with srcset/sizes (or ) so smaller viewports can fetch a smaller file. | | Responsive images (srcset / ) | **Warn** | Only 15/22 raster images use srcset or (68%). | | Reasonable number of image sizes | **Pass** | 17 distinct srcset widths. | | JS scripts not blocking in | **Fail** | 5 render-blocking scripts in . Move to footer or add defer/async. | ## Fixes ### Priority 1: Critical *Immediate action — impacts user experience, search rankings, or site safety.* **1A. Optimize images for WebP and lazy loading** - **Impact:** LCP, Page Weight, CLS - **Problem:** Images total 1.45 MB with no WebP format; 6 images missing loading='lazy' contribute to LCP 9.3 s. - **Solution:** Convert all PNG/JPEG to WebP/AVIF. Add `loading="lazy"` to non-hero images. Ensure hero image has `fetchpriority="high"`. ```html ... ``` **1B. Defer non-critical JavaScript** - **Impact:** LCP, TBT, FCP - **Problem:** 11 render-blocking scripts identified; main.js (163 KB) and GTM (64 KB) cause long tasks and delay rendering. - **Solution:** Add `defer` or `async` to all non-critical scripts in ``. Move WooCommerce/Contact Form scripts to footer if not needed for initial paint. ```html ``` **1C. Enforce HTTPS redirect for all HTTP traffic** - **Impact:** Security, Data Integrity - **Problem:** Audit shows http://kawiare.ee/artiklid does not redirect to HTTPS, leaving users vulnerable to interception on unencrypted connections. - **Solution:** Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to the HTTPS equivalent: ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1D. Defer or async non-critical JavaScript to fix LCP** - **Impact:** LCP, FCP, TBT - **Problem:** 16 render-blocking scripts and 224 KB unused JS delay first paint; LCP is 7.8 s on mobile. - **Solution:** Add `defer` or `async` to all non-critical scripts in ``. For WordPress, use a plugin like 'WP Rocket' or 'Autoptimize' to defer JS, or manually update theme files: ```html ``` **1E. Force HTTPS Redirect** - **Impact:** Security, Transport Layer - **Problem:** HTTP traffic (http://kawiare.ee/...) does not redirect to HTTPS, leaving users vulnerable to downgrade attacks and mixed content warnings. - **Solution:** Configure the web server (Apache/Nginx) to redirect all HTTP requests to HTTPS: ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1F. Optimize Largest Contentful Paint (LCP)** - **Impact:** Mobile Performance, LCP (8.6 s) - **Problem:** Mobile LCP is 8.6 s (threshold 2.5 s), driven by render-blocking scripts and heavy resource loading. - **Solution:** - Defer non-critical JavaScript (11 render-blocking scripts found). - Preload the LCP image (hero) with ``. - Optimize server response time (TTFB is 4 ms, so focus on resource delivery). **1G. Force HTTP to HTTPS Redirect** - **Impact:** Security, Data Integrity - **Problem:** Security Headers audit confirms http://kawiare.ee/... does not redirect to HTTPS, allowing unencrypted traffic. - **Solution:** Configure the web server (Apache/Nginx) to return a 301/302 redirect for all HTTP requests to the HTTPS equivalent. **Apache Example:** ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1H. Defer Render-Blocking JavaScript** - **Impact:** LCP, FCP, Performance - **Problem:** 11 render-blocking scripts in cause LCP to reach 8.5s and FCP 4.6s on mobile. - **Solution:** Add `defer` or `async` attributes to non-critical scripts in the ``. Move critical CSS inline and defer the rest. **Example:** ```html ``` **1I. Enforce HTTPS Redirect** - **Impact:** Security, Transport Layer - **Problem:** Security Headers audit reports 'HTTPS redirect: ✗ http://kawiare.ee... does not redirect to HTTPS'. - **Solution:** Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS. **Apache (.htaccess):** ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1J. Optimize Mobile Largest Contentful Paint (LCP)** - **Impact:** Performance, Mobile UX - **Problem:** Mobile LCP is 9.0s (threshold is 2.5s), driven by render-blocking scripts and heavy assets. - **Solution:** - Defer non-critical JavaScript (11 render-blocking scripts found). - Preload the LCP image (hero) with `fetchpriority="high"`. - Compress images to WebP/AVIF. - Remove unused JavaScript (224KB wasted in `main.js`). **1K. Enforce HTTP to HTTPS redirect** - **Impact:** Security, Transport Layer - **Problem:** Security Headers audit shows http://kawiare.ee... does not redirect to HTTPS, leaving users vulnerable on unencrypted connections. - **Solution:** Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS: ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1L. Eliminate render-blocking JavaScript** - **Impact:** LCP, FCP, Performance Score - **Problem:** PSI mobile LCP is 8.6 s; HTML Inventory shows 11 render-blocking scripts including main.js and jQuery. - **Solution:** Add `defer` or `async` to non-critical scripts in ``. Critical CSS should be inlined, and JS moved to footer or deferred: ```html ``` ### Priority 2: Important *Essential for compliance, user reach, and search visibility.* **2A. Strengthen security headers** - **Impact:** Security Grade, XSS/Clickjacking Defense - **Problem:** Security Headers grade 40/100; missing CSP, COOP, CORP. HSTS lacks preload directive. - **Solution:** Add missing headers via server config (Apache example): ```apache Header set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com" Header set Cross-Origin-Opener-Policy "same-origin" Header set Cross-Origin-Resource-Policy "same-origin" ``` **2B. Fix HTML structure and navigation** - **Impact:** SEO, Accessibility - **Problem:** Page contains 3 `

` elements; missing skip-to-content link; W3C error on ` ``` **2I. Fix Color Contrast Violation** - **Impact:** Accessibility (WCAG 1.4.3) - **Problem:** axe-core reports 1 serious violation on `#cookiescript_accept` element. - **Solution:** Increase text contrast ratio to at least 4.5:1 for the cookie consent button text. Adjust CSS color values or background opacity. **2J. Fix accessibility contrast and landmarks** - **Impact:** WCAG 1.4.3, 2.4.1 - **Problem:** axe-core reports 1 serious color-contrast violation (#cookiescript_accept) and missing skip-to-content link. - **Solution:** - Increase contrast on `.lead-text` and cookie button to ≥4.5:1. - Add a skip link at the top of the DOM: ```html ``` **2K. Strengthen HSTS configuration** - **Impact:** Security Headers Grade - **Problem:** HSTS is present but missing the `preload` directive, preventing inclusion in browser preload lists. - **Solution:** Update the `Strict-Transport-Security` header to include preload: ```apache Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" ``` **2L. Implement Content Security Policy (CSP)** - **Impact:** XSS Defense, Security Headers - **Problem:** CSP is missing (Security Headers grade 40/100). While site signals show no auth/payments, CSP mitigates XSS risks from third-party scripts (e.g., GTM). - **Solution:** Deploy a strict CSP with nonce/hash for scripts: ```apache Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; style-src 'self' 'unsafe-inline';" ``` **2M. Fix Color Contrast and Landmarks** - **Impact:** Accessibility (WCAG 1.4.3, 1.3.1) - **Problem:** axe-core found 1 serious color-contrast violation (#cookiescript_accept) and 3 moderate landmark issues (duplicate main). - **Solution:** - Increase contrast on `#cookiescript_accept` to ≥4.5:1. - Ensure only one `
` element exists; remove duplicate `role="main"`. - Add `aria-label` to landmarks if roles are duplicated. ### Priority 3: Best Practice *Recommended for long-term maintainability.* **3A. Fix color contrast on cookie banner** - **Impact:** WCAG 1.4.3 - **Problem:** axe-core reports serious contrast violation on `#cookiescript_accept`. - **Solution:** Increase text color contrast ratio to ≥4.5:1 against the background. Verify with a contrast checker tool. **3B. Replace CSS Background Hero with Real Image** - **Impact:** LCP, Image Optimization - **Problem:** Hero uses CSS background-image, preventing srcset usage and browser optimization; LCP element is heavy. - **Solution:** Move the hero image into an `` tag with `fetchpriority="high"` and `srcset`: ```html ... ``` **3C. Add Content Security Policy (CSP)** - **Impact:** XSS Defense-in-Depth - **Problem:** CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower than P1, but still recommended for defense. - **Solution:** Implement a strict CSP with nonce/hash for scripts: ```apache Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';" ``` Ensure all inline scripts use the nonce. **3D. Implement Content Security Policy (CSP)** - **Impact:** XSS Defense-in-Depth - **Problem:** CSP is missing. Site signals indicate no auth/payments, so this is a best practice rather than critical, but recommended for hardening. - **Solution:** Deploy a strict CSP with nonces for scripts. Since this is a brochure/blog page, a strict allowlist is feasible. **Header:** ```http Content-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; ``` **3E. Resolve W3C Validation Errors** - **Impact:** SEO, Rendering Consistency - **Problem:** 2 errors found: `