# Audit Report: Kawiare - Experience of Taste
**Website:** https://kawiare.ee/
**Date:** 2026-07-13
**Overall Score:** 56 / 100
**Status:** 🟠**Poor**
**Confidence:** high
**Audit Coverage:** 100% — all sources returned data
**Pages Audited (10 of 10):**
- https://kawiare.ee/
- https://kawiare.ee/artiklid
- https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja
- https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta
- https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga
- https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari
- https://kawiare.ee/kammkarp
- https://kawiare.ee/ahven-ja-koha
- https://kawiare.ee/lumekrabi
- https://kawiare.ee/kaaviar-tanapaeval
## Summary
Site overall 56 is the mean of 10 pages. Scores range 45 (https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja) → 62 (https://kawiare.ee/kaaviar-tanapaeval). Weakest page: Mobile performance is critically low (63/100) with an LCP of 8.6 s, far exceeding the 2.5 s threshold and dragging the overall score. A critical security configuration error exists where HTTP traffic does not redirect to HTTPS, exposing users to downgrade attacks. Accessibility has a serious contrast violation and missing skip-link, though desktop performance is strong (95/100). Security headers are weak (40/100) with missing CSP and preload, but the HTTP redirect failure is the most urgent security fix. The site functions but requires significant optimization for mobile users and security hardening.
## Per-Page Scores
| Page | Score | Status | Confidence |
| --- | --- | --- | --- |
| https://kawiare.ee/ | 55 | 🟠**Poor** | high |
| https://kawiare.ee/artiklid | 48 | 🟠**Poor** | high |
| https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja | 45 | 🟠**Poor** | high |
| https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta | 58 | 🟠**Poor** | high |
| https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga | 55 | 🟠**Poor** | high |
| https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari | 62 | 🟡 **Needs Improvement** | high |
| https://kawiare.ee/kammkarp | 62 | 🟡 **Needs Improvement** | high |
| https://kawiare.ee/ahven-ja-koha | 55 | 🟠**Poor** | high |
| https://kawiare.ee/lumekrabi | 62 | 🟡 **Needs Improvement** | high |
| https://kawiare.ee/kaaviar-tanapaeval | 62 | 🟡 **Needs Improvement** | high |
## PageSpeed Insights — Mobile vs Desktop
_Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._
| URL | Performance (M / D) | LCP (M / D) | CLS (M / D) |
| --- | --- | --- | --- |
| https://kawiare.ee/ | **49** / 71 | **9.27 s** / 1.67 s | **1.000** / 0.637 |
| https://kawiare.ee/artiklid | **61** / 89 | **7.82 s** / 1.79 s | 0.001 / **0.001** |
| https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja | **63** / 95 | **8.65 s** / 1.51 s | 0.000 / **0.000** |
| https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta | **60** / 72 | **8.49 s** / 1.77 s | 0.000 / **0.000** |
| https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga | **60** / 91 | **8.95 s** / 1.61 s | 0.000 / **0.000** |
| https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari | **60** / 94 | **8.56 s** / 1.60 s | 0.000 / **0.000** |
| https://kawiare.ee/kammkarp | **60** / 98 | **8.48 s** / 1.01 s | 0.000 / **0.000** |
| https://kawiare.ee/ahven-ja-koha | **68** / 94 | **8.39 s** / 1.58 s | 0.000 / **0.000** |
| https://kawiare.ee/lumekrabi | **65** / 94 | **7.28 s** / 1.53 s | 0.000 / **0.000** |
| https://kawiare.ee/kaaviar-tanapaeval | **56** / 95 | **8.34 s** / 1.48 s | 0.000 / **0.000** |
## Optimization Checklist
**4 of 7 passing** — 4 pass · 2 warn · 1 fail
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | **Pass** | All raster images use loading="lazy". |
| Hero image eagerly loaded | **Pass** | Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real (not a CSS background-image) | **Warn** | Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real with srcset/sizes (or ) so smaller viewports can fetch a smaller file. |
| Responsive images (srcset / ) | **Warn** | Only 15/22 raster images use srcset or (68%). |
| Reasonable number of image sizes | **Pass** | 17 distinct srcset widths. |
| JS scripts not blocking in | **Fail** | 5 render-blocking scripts in . Move to footer or add defer/async. |
## Fixes
### Priority 1: Critical
*Immediate action — impacts user experience, search rankings, or site safety.*
**1A. Optimize images for WebP and lazy loading**
- **Impact:** LCP, Page Weight, CLS
- **Problem:** Images total 1.45 MB with no WebP format; 6 images missing loading='lazy' contribute to LCP 9.3 s.
- **Solution:**
Convert all PNG/JPEG to WebP/AVIF. Add `loading="lazy"` to non-hero images. Ensure hero image has `fetchpriority="high"`.
```html
```
**1B. Defer non-critical JavaScript**
- **Impact:** LCP, TBT, FCP
- **Problem:** 11 render-blocking scripts identified; main.js (163 KB) and GTM (64 KB) cause long tasks and delay rendering.
- **Solution:**
Add `defer` or `async` to all non-critical scripts in ``. Move WooCommerce/Contact Form scripts to footer if not needed for initial paint.
```html
```
**1C. Enforce HTTPS redirect for all HTTP traffic**
- **Impact:** Security, Data Integrity
- **Problem:** Audit shows http://kawiare.ee/artiklid does not redirect to HTTPS, leaving users vulnerable to interception on unencrypted connections.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to the HTTPS equivalent:
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1D. Defer or async non-critical JavaScript to fix LCP**
- **Impact:** LCP, FCP, TBT
- **Problem:** 16 render-blocking scripts and 224 KB unused JS delay first paint; LCP is 7.8 s on mobile.
- **Solution:**
Add `defer` or `async` to all non-critical scripts in ``. For WordPress, use a plugin like 'WP Rocket' or 'Autoptimize' to defer JS, or manually update theme files:
```html
```
**1E. Force HTTPS Redirect**
- **Impact:** Security, Transport Layer
- **Problem:** HTTP traffic (http://kawiare.ee/...) does not redirect to HTTPS, leaving users vulnerable to downgrade attacks and mixed content warnings.
- **Solution:**
Configure the web server (Apache/Nginx) to redirect all HTTP requests to HTTPS:
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1F. Optimize Largest Contentful Paint (LCP)**
- **Impact:** Mobile Performance, LCP (8.6 s)
- **Problem:** Mobile LCP is 8.6 s (threshold 2.5 s), driven by render-blocking scripts and heavy resource loading.
- **Solution:**
- Defer non-critical JavaScript (11 render-blocking scripts found).
- Preload the LCP image (hero) with ``.
- Optimize server response time (TTFB is 4 ms, so focus on resource delivery).
**1G. Force HTTP to HTTPS Redirect**
- **Impact:** Security, Data Integrity
- **Problem:** Security Headers audit confirms http://kawiare.ee/... does not redirect to HTTPS, allowing unencrypted traffic.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301/302 redirect for all HTTP requests to the HTTPS equivalent.
**Apache Example:**
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1H. Defer Render-Blocking JavaScript**
- **Impact:** LCP, FCP, Performance
- **Problem:** 11 render-blocking scripts in cause LCP to reach 8.5s and FCP 4.6s on mobile.
- **Solution:**
Add `defer` or `async` attributes to non-critical scripts in the ``. Move critical CSS inline and defer the rest.
**Example:**
```html
```
**1I. Enforce HTTPS Redirect**
- **Impact:** Security, Transport Layer
- **Problem:** Security Headers audit reports 'HTTPS redirect: ✗ http://kawiare.ee... does not redirect to HTTPS'.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS.
**Apache (.htaccess):**
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1J. Optimize Mobile Largest Contentful Paint (LCP)**
- **Impact:** Performance, Mobile UX
- **Problem:** Mobile LCP is 9.0s (threshold is 2.5s), driven by render-blocking scripts and heavy assets.
- **Solution:**
- Defer non-critical JavaScript (11 render-blocking scripts found).
- Preload the LCP image (hero) with `fetchpriority="high"`.
- Compress images to WebP/AVIF.
- Remove unused JavaScript (224KB wasted in `main.js`).
**1K. Enforce HTTP to HTTPS redirect**
- **Impact:** Security, Transport Layer
- **Problem:** Security Headers audit shows http://kawiare.ee... does not redirect to HTTPS, leaving users vulnerable on unencrypted connections.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1L. Eliminate render-blocking JavaScript**
- **Impact:** LCP, FCP, Performance Score
- **Problem:** PSI mobile LCP is 8.6 s; HTML Inventory shows 11 render-blocking scripts including main.js and jQuery.
- **Solution:**
Add `defer` or `async` to non-critical scripts in ``. Critical CSS should be inlined, and JS moved to footer or deferred:
```html
```
### Priority 2: Important
*Essential for compliance, user reach, and search visibility.*
**2A. Strengthen security headers**
- **Impact:** Security Grade, XSS/Clickjacking Defense
- **Problem:** Security Headers grade 40/100; missing CSP, COOP, CORP. HSTS lacks preload directive.
- **Solution:**
Add missing headers via server config (Apache example):
```apache
Header set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com"
Header set Cross-Origin-Opener-Policy "same-origin"
Header set Cross-Origin-Resource-Policy "same-origin"
```
**2B. Fix HTML structure and navigation**
- **Impact:** SEO, Accessibility
- **Problem:** Page contains 3 `
` elements; missing skip-to-content link; W3C error on `
```
**2I. Fix Color Contrast Violation**
- **Impact:** Accessibility (WCAG 1.4.3)
- **Problem:** axe-core reports 1 serious violation on `#cookiescript_accept` element.
- **Solution:**
Increase text contrast ratio to at least 4.5:1 for the cookie consent button text. Adjust CSS color values or background opacity.
**2J. Fix accessibility contrast and landmarks**
- **Impact:** WCAG 1.4.3, 2.4.1
- **Problem:** axe-core reports 1 serious color-contrast violation (#cookiescript_accept) and missing skip-to-content link.
- **Solution:**
- Increase contrast on `.lead-text` and cookie button to ≥4.5:1.
- Add a skip link at the top of the DOM:
```html
Otse sisule
```
**2K. Strengthen HSTS configuration**
- **Impact:** Security Headers Grade
- **Problem:** HSTS is present but missing the `preload` directive, preventing inclusion in browser preload lists.
- **Solution:**
Update the `Strict-Transport-Security` header to include preload:
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
```
**2L. Implement Content Security Policy (CSP)**
- **Impact:** XSS Defense, Security Headers
- **Problem:** CSP is missing (Security Headers grade 40/100). While site signals show no auth/payments, CSP mitigates XSS risks from third-party scripts (e.g., GTM).
- **Solution:**
Deploy a strict CSP with nonce/hash for scripts:
```apache
Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; style-src 'self' 'unsafe-inline';"
```
**2M. Fix Color Contrast and Landmarks**
- **Impact:** Accessibility (WCAG 1.4.3, 1.3.1)
- **Problem:** axe-core found 1 serious color-contrast violation (#cookiescript_accept) and 3 moderate landmark issues (duplicate main).
- **Solution:**
- Increase contrast on `#cookiescript_accept` to ≥4.5:1.
- Ensure only one `` element exists; remove duplicate `role="main"`.
- Add `aria-label` to landmarks if roles are duplicated.
### Priority 3: Best Practice
*Recommended for long-term maintainability.*
**3A. Fix color contrast on cookie banner**
- **Impact:** WCAG 1.4.3
- **Problem:** axe-core reports serious contrast violation on `#cookiescript_accept`.
- **Solution:**
Increase text color contrast ratio to ≥4.5:1 against the background. Verify with a contrast checker tool.
**3B. Replace CSS Background Hero with Real Image**
- **Impact:** LCP, Image Optimization
- **Problem:** Hero uses CSS background-image, preventing srcset usage and browser optimization; LCP element is heavy.
- **Solution:**
Move the hero image into an `` tag with `fetchpriority="high"` and `srcset`:
```html
```
**3C. Add Content Security Policy (CSP)**
- **Impact:** XSS Defense-in-Depth
- **Problem:** CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower than P1, but still recommended for defense.
- **Solution:**
Implement a strict CSP with nonce/hash for scripts:
```apache
Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';"
```
Ensure all inline scripts use the nonce.
**3D. Implement Content Security Policy (CSP)**
- **Impact:** XSS Defense-in-Depth
- **Problem:** CSP is missing. Site signals indicate no auth/payments, so this is a best practice rather than critical, but recommended for hardening.
- **Solution:**
Deploy a strict CSP with nonces for scripts. Since this is a brochure/blog page, a strict allowlist is feasible.
**Header:**
```http
Content-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';
```
**3E. Resolve W3C Validation Errors**
- **Impact:** SEO, Rendering Consistency
- **Problem:** 2 errors found: `