{"url":"https://kawiare.ee/","date":"2026-07-13","siteName":"Kawiare - Experience of Taste","overall":56,"reasoning":"Site overall 56 is the mean of 10 pages. Scores range 45 (https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja) → 62 (https://kawiare.ee/kaaviar-tanapaeval). Weakest page: Mobile performance is critically low (63/100) with an LCP of 8.6 s, far exceeding the 2.5 s threshold and dragging the overall score. A critical security configuration error exists where HTTP traffic does not redirect to HTTPS, exposing users to downgrade attacks. Accessibility has a serious contrast violation and missing skip-link, though desktop performance is strong (95/100). Security headers are weak (40/100) with missing CSP and preload, but the HTTP redirect failure is the most urgent security fix. The site functions but requires significant optimization for mobile users and security hardening.","confidence":"high","fixes":[{"priority":1,"title":"Optimize images for WebP and lazy loading","impact":"LCP, Page Weight, CLS","problem":"Images total 1.45 MB with no WebP format; 6 images missing loading='lazy' contribute to LCP 9.3 s.","solution":"Convert all PNG/JPEG to WebP/AVIF. Add `loading=\"lazy\"` to non-hero images. Ensure hero image has `fetchpriority=\"high\"`.\n```html\n<img src=\"image.webp\" alt=\"...\" loading=\"lazy\" width=\"1200\" height=\"800\">\n```"},{"priority":1,"title":"Defer non-critical JavaScript","impact":"LCP, TBT, FCP","problem":"11 render-blocking scripts identified; main.js (163 KB) and GTM (64 KB) cause long tasks and delay rendering.","solution":"Add `defer` or `async` to all non-critical scripts in `<head>`. Move WooCommerce/Contact Form scripts to footer if not needed for initial paint.\n```html\n<script src=\"main.js\" defer></script>\n```"},{"priority":1,"title":"Enforce HTTPS redirect for all HTTP traffic","impact":"Security, Data Integrity","problem":"Audit shows http://kawiare.ee/artiklid does not redirect to HTTPS, leaving users vulnerable to interception on unencrypted connections.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to the HTTPS equivalent:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Defer or async non-critical JavaScript to fix LCP","impact":"LCP, FCP, TBT","problem":"16 render-blocking scripts and 224 KB unused JS delay first paint; LCP is 7.8 s on mobile.","solution":"Add `defer` or `async` to all non-critical scripts in `<head>`. For WordPress, use a plugin like 'WP Rocket' or 'Autoptimize' to defer JS, or manually update theme files:\n```html\n<script src=\"main.js\" defer></script>\n```"},{"priority":1,"title":"Force HTTPS Redirect","impact":"Security, Transport Layer","problem":"HTTP traffic (http://kawiare.ee/...) does not redirect to HTTPS, leaving users vulnerable to downgrade attacks and mixed content warnings.","solution":"Configure the web server (Apache/Nginx) to redirect all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Mobile Performance, LCP (8.6 s)","problem":"Mobile LCP is 8.6 s (threshold 2.5 s), driven by render-blocking scripts and heavy resource loading.","solution":"- Defer non-critical JavaScript (11 render-blocking scripts found).\n- Preload the LCP image (hero) with `<link rel=\"preload\" as=\"image\">`.\n- Optimize server response time (TTFB is 4 ms, so focus on resource delivery)."},{"priority":1,"title":"Force HTTP to HTTPS Redirect","impact":"Security, Data Integrity","problem":"Security Headers audit confirms http://kawiare.ee/... does not redirect to HTTPS, allowing unencrypted traffic.","solution":"Configure the web server (Apache/Nginx) to return a 301/302 redirect for all HTTP requests to the HTTPS equivalent.\n\n**Apache Example:**\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Defer Render-Blocking JavaScript","impact":"LCP, FCP, Performance","problem":"11 render-blocking scripts in <head> cause LCP to reach 8.5s and FCP 4.6s on mobile.","solution":"Add `defer` or `async` attributes to non-critical scripts in the `<head>`. Move critical CSS inline and defer the rest.\n\n**Example:**\n```html\n<script src=\"/js/main.js\" defer></script>\n```"},{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Transport Layer","problem":"Security Headers audit reports 'HTTPS redirect: ✗ http://kawiare.ee... does not redirect to HTTPS'.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS.\n\n**Apache (.htaccess):**\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Mobile Largest Contentful Paint (LCP)","impact":"Performance, Mobile UX","problem":"Mobile LCP is 9.0s (threshold is 2.5s), driven by render-blocking scripts and heavy assets.","solution":"- Defer non-critical JavaScript (11 render-blocking scripts found).\n- Preload the LCP image (hero) with `fetchpriority=\"high\"`.\n- Compress images to WebP/AVIF.\n- Remove unused JavaScript (224KB wasted in `main.js`)."},{"priority":1,"title":"Enforce HTTP to HTTPS redirect","impact":"Security, Transport Layer","problem":"Security Headers audit shows http://kawiare.ee... does not redirect to HTTPS, leaving users vulnerable on unencrypted connections.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Eliminate render-blocking JavaScript","impact":"LCP, FCP, Performance Score","problem":"PSI mobile LCP is 8.6 s; HTML Inventory shows 11 render-blocking scripts including main.js and jQuery.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Critical CSS should be inlined, and JS moved to footer or deferred:\n```html\n<script src=\"main.js\" defer></script>\n```"},{"priority":2,"title":"Strengthen security headers","impact":"Security Grade, XSS/Clickjacking Defense","problem":"Security Headers grade 40/100; missing CSP, COOP, CORP. HSTS lacks preload directive.","solution":"Add missing headers via server config (Apache example):\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com\"\nHeader set Cross-Origin-Opener-Policy \"same-origin\"\nHeader set Cross-Origin-Resource-Policy \"same-origin\"\n```"},{"priority":2,"title":"Fix HTML structure and navigation","impact":"SEO, Accessibility","problem":"Page contains 3 `<h1>` elements; missing skip-to-content link; W3C error on `<style>` inside `<div>`.","solution":"Ensure exactly one `<h1>` per page. Add skip link before main content. Move inline styles to external CSS or `<style>` block in `<head>`.\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n```"},{"priority":2,"title":"Complete Security Header Hardening","impact":"XSS, Clickjacking, Transport Security","problem":"Security Headers grade is 40/100; HSTS lacks preload directive, and CSP is missing entirely.","solution":"Add HSTS preload and a strict CSP. Since signals indicate no auth/payments, a restrictive default-src is safe:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com;\"\n```"},{"priority":2,"title":"Fix Heading Hierarchy and Color Contrast","impact":"WCAG 1.3.1, 1.4.3, SEO","problem":"W3C and axe report h1→h3 skip and serious contrast failure on #cookiescript_accept.","solution":"- Insert an h2 between h1 and h3, or change h3 to h2.\n- Increase contrast on `.lead-text` or `#cookiescript_accept` to meet 4.5:1 ratio (e.g., darken text or lighten background)."},{"priority":2,"title":"Defer Render-Blocking Scripts","impact":"FCP, TBT, Mobile Performance","problem":"11 render-blocking scripts in <head> delay First Contentful Paint (3.62 s) and contribute to long tasks.","solution":"Add `defer` or `async` attributes to non-critical scripts in `<head>`:\n```html\n<script src=\"...\" defer></script>\n```\nMove critical CSS inline and defer the rest."},{"priority":2,"title":"Fix Accessibility Violations","impact":"WCAG Compliance, Usability","problem":"1 serious color-contrast violation (#cookiescript_accept) and 3 moderate landmark violations (duplicate main, missing skip-link).","solution":"- Increase contrast ratio for `.cookiescript_accept` to ≥4.5:1.\n- Add `<a href=\"#main\" class=\"skip-link\">Skip to content</a>`.\n- Ensure only one `<main>` or `role=\"main\"` element exists."},{"priority":2,"title":"Fix Color Contrast on Cookie Buttons","impact":"Accessibility (WCAG 1.4.3)","problem":"axe-core reports 1 serious violation: background and foreground colors on #cookiescript_accept/reject do not meet contrast thresholds.","solution":"Increase contrast ratio to at least 4.5:1 for normal text. Adjust button text color or background color in CSS.\n\n**CSS Example:**\n```css\n#cookiescript_accept { color: #333333; background: #ffffff; }\n```"},{"priority":2,"title":"Correct Invalid HTML Structure","impact":"SEO, Rendering Consistency","problem":"W3C Validator reports 2 errors: `<style>` not allowed as child of `<div>` and unescaped `<` character.","solution":"Move `<style>` blocks to the `<head>` or use `<template>` if dynamic. Escape special characters like `<` as `&lt;` in text content.\n\n**Fix:**\n```html\n<!-- Move style to head -->\n<head>\n  <style>...</style>\n</head>\n```"},{"priority":2,"title":"Fix Color Contrast Violation","impact":"Accessibility (WCAG 1.4.3)","problem":"axe-core reports 1 serious violation on `#cookiescript_accept` element.","solution":"Increase text contrast ratio to at least 4.5:1 for the cookie consent button text. Adjust CSS color values or background opacity."},{"priority":2,"title":"Fix accessibility contrast and landmarks","impact":"WCAG 1.4.3, 2.4.1","problem":"axe-core reports 1 serious color-contrast violation (#cookiescript_accept) and missing skip-to-content link.","solution":"- Increase contrast on `.lead-text` and cookie button to ≥4.5:1.\n- Add a skip link at the top of the DOM:\n```html\n<a href=\"#main\" class=\"skip-link\">Otse sisule</a>\n```"},{"priority":2,"title":"Strengthen HSTS configuration","impact":"Security Headers Grade","problem":"HSTS is present but missing the `preload` directive, preventing inclusion in browser preload lists.","solution":"Update the `Strict-Transport-Security` header to include preload:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":2,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense, Security Headers","problem":"CSP is missing (Security Headers grade 40/100). While site signals show no auth/payments, CSP mitigates XSS risks from third-party scripts (e.g., GTM).","solution":"Deploy a strict CSP with nonce/hash for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; style-src 'self' 'unsafe-inline';\"\n```"},{"priority":2,"title":"Fix Color Contrast and Landmarks","impact":"Accessibility (WCAG 1.4.3, 1.3.1)","problem":"axe-core found 1 serious color-contrast violation (#cookiescript_accept) and 3 moderate landmark issues (duplicate main).","solution":"- Increase contrast on `#cookiescript_accept` to ≥4.5:1.\n- Ensure only one `<main>` element exists; remove duplicate `role=\"main\"`.\n- Add `aria-label` to landmarks if roles are duplicated."},{"priority":3,"title":"Fix color contrast on cookie banner","impact":"WCAG 1.4.3","problem":"axe-core reports serious contrast violation on `#cookiescript_accept`.","solution":"Increase text color contrast ratio to ≥4.5:1 against the background. Verify with a contrast checker tool."},{"priority":3,"title":"Replace CSS Background Hero with Real Image","impact":"LCP, Image Optimization","problem":"Hero uses CSS background-image, preventing srcset usage and browser optimization; LCP element is heavy.","solution":"Move the hero image into an `<img>` tag with `fetchpriority=\"high\"` and `srcset`:\n```html\n<img src=\"hero-800.jpg\" srcset=\"hero-400.jpg 400w, hero-800.jpg 800w\" fetchpriority=\"high\" alt=\"...\">\n```"},{"priority":3,"title":"Add Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower than P1, but still recommended for defense.","solution":"Implement a strict CSP with nonce/hash for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```\nEnsure all inline scripts use the nonce."},{"priority":3,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals indicate no auth/payments, so this is a best practice rather than critical, but recommended for hardening.","solution":"Deploy a strict CSP with nonces for scripts. Since this is a brochure/blog page, a strict allowlist is feasible.\n\n**Header:**\n```http\nContent-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\n```"},{"priority":3,"title":"Resolve W3C Validation Errors","impact":"SEO, Rendering Consistency","problem":"2 errors found: `<style>` not allowed in `div` context and unescaped `<` character in text content.","solution":"- Move inline `<style>` blocks to the `<head>` or external CSS file.\n- Escape special characters in text content (e.g., use `&lt;` instead of `<`)."},{"priority":3,"title":"Add Meta Description","impact":"SEO, Click-Through Rate","problem":"W3C and SEO audits confirm the document lacks a meta description.","solution":"Add a concise description (150–160 chars) in the `<head>`:\n```html\n<meta name=\"description\" content=\"Ahven ja koha – kaks Balti järvede kala, mille väärtus vajab uuesti mõtestamist.\">```"},{"priority":3,"title":"Add Security Headers (CSP, HSTS Preload)","impact":"Defense-in-depth, Security Score","problem":"CSP is missing; HSTS lacks preload directive. Site signals indicate low auth/payment risk, so this is P3.","solution":"Add CSP with nonce/hash strategy. Add `preload` to HSTS.\n\n**Apache:**\n```apache\nHeader set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'\"\n```"},{"priority":3,"title":"Improve SEO and Validation","impact":"Search Visibility, Code Quality","problem":"Missing meta description; W3C validator reports 2 errors (invalid `<style>` in `<div>`, unescaped `<`).","solution":"- Add `<meta name=\"description\" content=\"...\">`.\n- Fix W3C errors: Move `<style>` blocks to `<head>` or use `<div>` correctly; escape `<` as `&lt;`."},{"priority":3,"title":"Improve SEO and HTML Validity","impact":"Search Visibility, Code Quality","problem":"PSI SEO audit fails `metaDescription`; W3C reports 2 errors (invalid `<style>` in `div`, unescaped `<` character).","solution":"- Add `<meta name=\"description\" content=\"...\">`.\n- Fix W3C errors: move `<style>` to `<head>` or use `<div>` correctly; escape `<` as `&lt;` in text content."}],"coverage":{"pct":100,"missing":[]},"siteSummary":{"pagesAudited":10,"pagesAttempted":10,"urls":["https://kawiare.ee/","https://kawiare.ee/artiklid","https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja","https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta","https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga","https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari","https://kawiare.ee/kammkarp","https://kawiare.ee/ahven-ja-koha","https://kawiare.ee/lumekrabi","https://kawiare.ee/kaaviar-tanapaeval"]},"psiSnapshot":{"rows":[{"pageUrl":"https://kawiare.ee/","perfMobile":49,"perfDesktop":71,"lcpMobileMs":9269.61484149964,"lcpDesktopMs":1665.1987440990026,"clsMobile":1.0001866402722046,"clsDesktop":0.6371777108733764},{"pageUrl":"https://kawiare.ee/artiklid","perfMobile":61,"perfDesktop":89,"lcpMobileMs":7824.938534314547,"lcpDesktopMs":1788.0572769724915,"clsMobile":0.0006772344876011911,"clsDesktop":0.001307555645912965},{"pageUrl":"https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja","perfMobile":63,"perfDesktop":95,"lcpMobileMs":8648.836953056101,"lcpDesktopMs":1505.3057695587001,"clsMobile":0,"clsDesktop":0.0001730970214735764},{"pageUrl":"https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta","perfMobile":60,"perfDesktop":72,"lcpMobileMs":8489.471419510828,"lcpDesktopMs":1771.5092300493632,"clsMobile":0,"clsDesktop":0.00006940881631644403},{"pageUrl":"https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga","perfMobile":60,"perfDesktop":91,"lcpMobileMs":8952.990892233629,"lcpDesktopMs":1610.8728435851872,"clsMobile":0,"clsDesktop":0.0001730970214735764},{"pageUrl":"https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari","perfMobile":60,"perfDesktop":94,"lcpMobileMs":8562.357390860512,"lcpDesktopMs":1601.1356121178594,"clsMobile":0,"clsDesktop":0.0001569569198852857},{"pageUrl":"https://kawiare.ee/kammkarp","perfMobile":60,"perfDesktop":98,"lcpMobileMs":8483.22046951184,"lcpDesktopMs":1013.1160229856441,"clsMobile":0,"clsDesktop":0.00009163097511686772},{"pageUrl":"https://kawiare.ee/ahven-ja-koha","perfMobile":68,"perfDesktop":94,"lcpMobileMs":8394.574065497596,"lcpDesktopMs":1576.8024147307412,"clsMobile":0,"clsDesktop":0.00009994557290477509},{"pageUrl":"https://kawiare.ee/lumekrabi","perfMobile":65,"perfDesktop":94,"lcpMobileMs":7278.075460329479,"lcpDesktopMs":1527.3744712790362,"clsMobile":0,"clsDesktop":0.00009994557290477509},{"pageUrl":"https://kawiare.ee/kaaviar-tanapaeval","perfMobile":56,"perfDesktop":95,"lcpMobileMs":8344.136307725488,"lcpDesktopMs":1477.4132664072577,"clsMobile":0,"clsDesktop":0.00009994557290477509}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket)","evidence":["HTML markers: WP Rocket","generator: WordPress 7.0.1"]},{"id":"lazyload","title":"Images lazy-loaded","status":"pass","detail":"All raster images use loading=\"lazy\".","evidence":[]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"pass","detail":"Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable).","evidence":["hero: https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-1.png","loading: eager","fetchpriority: (not set)"]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"warn","detail":"Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.","evidence":["selector: div.pt-24.pb-16","url: …e.ee/wp-content/uploads/2026/01/823960696-teadmuskeskus_2592x726_b-scaled.jpg","box: 1280×464px"]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"warn","detail":"Only 15/22 raster images use srcset or <picture> (68%).","evidence":["https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-1.png","https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-e1782658950478.png","…kawiare.ee/wp-content/uploads/2026/02/Kawiare_paisepildid_mob_2_1900x2560.jpg","https://kawiare.ee/wp-content/uploads/2026/02/pais2_uus_2595x1467-scaled.jpg","…kawiare.ee/wp-content/uploads/2026/02/Kawiare_paisepildid_mob_3_1900x2560.jpg"]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"pass","detail":"17 distinct srcset widths.","evidence":["widths: 100, 150, 200, 225, 300, 600, 683, 768, 800, 1024, 1080, 1152, 1365, 1536, 1707, 1920, 2000"]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"fail","detail":"5 render-blocking scripts in <head>. Move to footer or add defer/async.","evidence":["…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638","https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1","https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1","…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0","…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0"]}],"summary":{"passed":4,"warned":2,"failed":1,"notApplicable":0},"priorities":[{"title":"JS scripts not blocking in <head>","severity":"high","detail":"5 render-blocking scripts in <head>. Move to footer or add defer/async."},{"title":"Responsive images (srcset / <picture>)","severity":"medium","detail":"Only 15/22 raster images use srcset or <picture> (68%)."},{"title":"Hero is a real <img> (not a CSS background-image)","severity":"medium","detail":"Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file."}]},"perPageOverall":[{"url":"https://kawiare.ee/","overall":55,"reasoning":"Mobile PSI score of 49 is critically low, driven by a catastrophic LCP of 9.3 s and CLS of 1.000, despite an excellent TTFB of 5 ms. The 1.45 MB image payload and 11 render-blocking scripts are the primary performance bottlenecks. Security headers score 40/100 due to missing CSP and COOP, though signals indicate no auth/payment risk. Accessibility is strong (97) with only one serious contrast violation. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Optimize images for WebP and lazy loading","impact":"LCP, Page Weight, CLS","problem":"Images total 1.45 MB with no WebP format; 6 images missing loading='lazy' contribute to LCP 9.3 s.","solution":"Convert all PNG/JPEG to WebP/AVIF. Add `loading=\"lazy\"` to non-hero images. Ensure hero image has `fetchpriority=\"high\"`.\n```html\n<img src=\"image.webp\" alt=\"...\" loading=\"lazy\" width=\"1200\" height=\"800\">\n```"},{"priority":1,"title":"Defer non-critical JavaScript","impact":"LCP, TBT, FCP","problem":"11 render-blocking scripts identified; main.js (163 KB) and GTM (64 KB) cause long tasks and delay rendering.","solution":"Add `defer` or `async` to all non-critical scripts in `<head>`. Move WooCommerce/Contact Form scripts to footer if not needed for initial paint.\n```html\n<script src=\"main.js\" defer></script>\n```"},{"priority":2,"title":"Strengthen security headers","impact":"Security Grade, XSS/Clickjacking Defense","problem":"Security Headers grade 40/100; missing CSP, COOP, CORP. HSTS lacks preload directive.","solution":"Add missing headers via server config (Apache example):\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com\"\nHeader set Cross-Origin-Opener-Policy \"same-origin\"\nHeader set Cross-Origin-Resource-Policy \"same-origin\"\n```"},{"priority":2,"title":"Fix HTML structure and navigation","impact":"SEO, Accessibility","problem":"Page contains 3 `<h1>` elements; missing skip-to-content link; W3C error on `<style>` inside `<div>`.","solution":"Ensure exactly one `<h1>` per page. Add skip link before main content. Move inline styles to external CSS or `<style>` block in `<head>`.\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n```"},{"priority":3,"title":"Fix color contrast on cookie banner","impact":"WCAG 1.4.3","problem":"axe-core reports serious contrast violation on `#cookiescript_accept`.","solution":"Increase text color contrast ratio to ≥4.5:1 against the background. Verify with a contrast checker tool."}]},{"url":"https://kawiare.ee/artiklid","overall":48,"reasoning":"Mobile performance is critically low (LCP 7.8 s, Speed Index 12.6 s) due to 16 render-blocking scripts and unused JavaScript, dragging the score into the 'Poor' band. A critical security configuration failure exists where HTTP traffic does not redirect to HTTPS, exposing users to man-in-the-middle risks. Accessibility is mostly functional but contains a serious color-contrast violation and heading hierarchy skips (h1→h3). Security headers are weak (grade 40/100) with missing CSP and HSTS preload. The combination of severe performance degradation and fundamental security misconfiguration justifies the low score despite good desktop performance.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS redirect for all HTTP traffic","impact":"Security, Data Integrity","problem":"Audit shows http://kawiare.ee/artiklid does not redirect to HTTPS, leaving users vulnerable to interception on unencrypted connections.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to the HTTPS equivalent:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Defer or async non-critical JavaScript to fix LCP","impact":"LCP, FCP, TBT","problem":"16 render-blocking scripts and 224 KB unused JS delay first paint; LCP is 7.8 s on mobile.","solution":"Add `defer` or `async` to all non-critical scripts in `<head>`. For WordPress, use a plugin like 'WP Rocket' or 'Autoptimize' to defer JS, or manually update theme files:\n```html\n<script src=\"main.js\" defer></script>\n```"},{"priority":2,"title":"Complete Security Header Hardening","impact":"XSS, Clickjacking, Transport Security","problem":"Security Headers grade is 40/100; HSTS lacks preload directive, and CSP is missing entirely.","solution":"Add HSTS preload and a strict CSP. Since signals indicate no auth/payments, a restrictive default-src is safe:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com;\"\n```"},{"priority":2,"title":"Fix Heading Hierarchy and Color Contrast","impact":"WCAG 1.3.1, 1.4.3, SEO","problem":"W3C and axe report h1→h3 skip and serious contrast failure on #cookiescript_accept.","solution":"- Insert an h2 between h1 and h3, or change h3 to h2.\n- Increase contrast on `.lead-text` or `#cookiescript_accept` to meet 4.5:1 ratio (e.g., darken text or lighten background)."},{"priority":3,"title":"Replace CSS Background Hero with Real Image","impact":"LCP, Image Optimization","problem":"Hero uses CSS background-image, preventing srcset usage and browser optimization; LCP element is heavy.","solution":"Move the hero image into an `<img>` tag with `fetchpriority=\"high\"` and `srcset`:\n```html\n<img src=\"hero-800.jpg\" srcset=\"hero-400.jpg 400w, hero-800.jpg 800w\" fetchpriority=\"high\" alt=\"...\">\n```"}]},{"url":"https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja","overall":45,"reasoning":"Mobile performance is critically low (63/100) with an LCP of 8.6 s, far exceeding the 2.5 s threshold and dragging the overall score. A critical security configuration error exists where HTTP traffic does not redirect to HTTPS, exposing users to downgrade attacks. Accessibility has a serious contrast violation and missing skip-link, though desktop performance is strong (95/100). Security headers are weak (40/100) with missing CSP and preload, but the HTTP redirect failure is the most urgent security fix. The site functions but requires significant optimization for mobile users and security hardening.","confidence":"high","fixes":[{"priority":1,"title":"Force HTTPS Redirect","impact":"Security, Transport Layer","problem":"HTTP traffic (http://kawiare.ee/...) does not redirect to HTTPS, leaving users vulnerable to downgrade attacks and mixed content warnings.","solution":"Configure the web server (Apache/Nginx) to redirect all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Mobile Performance, LCP (8.6 s)","problem":"Mobile LCP is 8.6 s (threshold 2.5 s), driven by render-blocking scripts and heavy resource loading.","solution":"- Defer non-critical JavaScript (11 render-blocking scripts found).\n- Preload the LCP image (hero) with `<link rel=\"preload\" as=\"image\">`.\n- Optimize server response time (TTFB is 4 ms, so focus on resource delivery)."},{"priority":2,"title":"Defer Render-Blocking Scripts","impact":"FCP, TBT, Mobile Performance","problem":"11 render-blocking scripts in <head> delay First Contentful Paint (3.62 s) and contribute to long tasks.","solution":"Add `defer` or `async` attributes to non-critical scripts in `<head>`:\n```html\n<script src=\"...\" defer></script>\n```\nMove critical CSS inline and defer the rest."},{"priority":2,"title":"Fix Accessibility Violations","impact":"WCAG Compliance, Usability","problem":"1 serious color-contrast violation (#cookiescript_accept) and 3 moderate landmark violations (duplicate main, missing skip-link).","solution":"- Increase contrast ratio for `.cookiescript_accept` to ≥4.5:1.\n- Add `<a href=\"#main\" class=\"skip-link\">Skip to content</a>`.\n- Ensure only one `<main>` or `role=\"main\"` element exists."},{"priority":3,"title":"Add Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower than P1, but still recommended for defense.","solution":"Implement a strict CSP with nonce/hash for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```\nEnsure all inline scripts use the nonce."}]},{"url":"https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta","overall":58,"reasoning":"Mobile performance is critically low (LCP 8.5s, FCP 4.6s) due to 11 render-blocking scripts and unused JavaScript, dragging the score significantly below the 60 threshold. Security configuration is flawed as HTTP traffic does not redirect to HTTPS, exposing users to potential interception despite HTTPS being available. Accessibility has one serious violation regarding color contrast on cookie consent buttons, alongside landmark structure issues. W3C validation reports 2 HTML errors, including invalid nesting of style elements within divs. Desktop performance is acceptable (72) but mobile-first indexing penalizes the overall score heavily.","confidence":"high","fixes":[{"priority":1,"title":"Force HTTP to HTTPS Redirect","impact":"Security, Data Integrity","problem":"Security Headers audit confirms http://kawiare.ee/... does not redirect to HTTPS, allowing unencrypted traffic.","solution":"Configure the web server (Apache/Nginx) to return a 301/302 redirect for all HTTP requests to the HTTPS equivalent.\n\n**Apache Example:**\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Defer Render-Blocking JavaScript","impact":"LCP, FCP, Performance","problem":"11 render-blocking scripts in <head> cause LCP to reach 8.5s and FCP 4.6s on mobile.","solution":"Add `defer` or `async` attributes to non-critical scripts in the `<head>`. Move critical CSS inline and defer the rest.\n\n**Example:**\n```html\n<script src=\"/js/main.js\" defer></script>\n```"},{"priority":2,"title":"Fix Color Contrast on Cookie Buttons","impact":"Accessibility (WCAG 1.4.3)","problem":"axe-core reports 1 serious violation: background and foreground colors on #cookiescript_accept/reject do not meet contrast thresholds.","solution":"Increase contrast ratio to at least 4.5:1 for normal text. Adjust button text color or background color in CSS.\n\n**CSS Example:**\n```css\n#cookiescript_accept { color: #333333; background: #ffffff; }\n```"},{"priority":2,"title":"Correct Invalid HTML Structure","impact":"SEO, Rendering Consistency","problem":"W3C Validator reports 2 errors: `<style>` not allowed as child of `<div>` and unescaped `<` character.","solution":"Move `<style>` blocks to the `<head>` or use `<template>` if dynamic. Escape special characters like `<` as `&lt;` in text content.\n\n**Fix:**\n```html\n<!-- Move style to head -->\n<head>\n  <style>...</style>\n</head>\n```"},{"priority":3,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals indicate no auth/payments, so this is a best practice rather than critical, but recommended for hardening.","solution":"Deploy a strict CSP with nonces for scripts. Since this is a brochure/blog page, a strict allowlist is feasible.\n\n**Header:**\n```http\nContent-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\n```"}]},{"url":"https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga","overall":55,"reasoning":"Mobile performance (60) severely drags the score due to LCP 9.0s, despite desktop scoring 91. A critical security configuration failure exists where HTTP does not redirect to HTTPS, lowering the security budget. Accessibility is strong (97) but contains one serious color-contrast violation. W3C validation shows minor errors, and SEO is missing a meta description. The site is functional on desktop but fails mobile core web vitals and basic security hardening.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Transport Layer","problem":"Security Headers audit reports 'HTTPS redirect: ✗ http://kawiare.ee... does not redirect to HTTPS'.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS.\n\n**Apache (.htaccess):**\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Mobile Largest Contentful Paint (LCP)","impact":"Performance, Mobile UX","problem":"Mobile LCP is 9.0s (threshold is 2.5s), driven by render-blocking scripts and heavy assets.","solution":"- Defer non-critical JavaScript (11 render-blocking scripts found).\n- Preload the LCP image (hero) with `fetchpriority=\"high\"`.\n- Compress images to WebP/AVIF.\n- Remove unused JavaScript (224KB wasted in `main.js`)."},{"priority":2,"title":"Defer Render-Blocking Scripts","impact":"FCP, TBT, Performance","problem":"11 render-blocking scripts in <head> delay First Contentful Paint (4.58s).","solution":"Add `defer` or `async` attributes to non-critical scripts in `<head>`.\n\n**Example:**\n```html\n<script src=\"/wp-content/plugins/woocommerce/...\" defer></script>\n```"},{"priority":2,"title":"Fix Color Contrast Violation","impact":"Accessibility (WCAG 1.4.3)","problem":"axe-core reports 1 serious violation on `#cookiescript_accept` element.","solution":"Increase text contrast ratio to at least 4.5:1 for the cookie consent button text. Adjust CSS color values or background opacity."},{"priority":3,"title":"Add Content Security Policy (CSP)","impact":"Security (XSS Defense)","problem":"CSP is missing. Site signals indicate no auth/payments, but WooCommerce scripts are present.","solution":"Implement a strict CSP with nonce/hash for scripts.\n\n**Header:**\n`Content-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';`\n\n**HTML:**\n`<script nonce=\"{random}\">...</script>`"}]},{"url":"https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari","overall":62,"reasoning":"Mobile performance is 60 with a critical LCP of 8.6 s, driven by 11 render-blocking scripts and unused JavaScript. Security headers grade is 40/100, notably missing an HTTP-to-HTTPS redirect which is a critical vulnerability. Accessibility has one serious color-contrast violation and a missing skip-to-content link. Desktop performance is excellent (94) but mobile-first indexing penalizes the site heavily. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTP to HTTPS redirect","impact":"Security, Transport Layer","problem":"Security Headers audit shows http://kawiare.ee... does not redirect to HTTPS, leaving users vulnerable on unencrypted connections.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Eliminate render-blocking JavaScript","impact":"LCP, FCP, Performance Score","problem":"PSI mobile LCP is 8.6 s; HTML Inventory shows 11 render-blocking scripts including main.js and jQuery.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Critical CSS should be inlined, and JS moved to footer or deferred:\n```html\n<script src=\"main.js\" defer></script>\n```"},{"priority":2,"title":"Fix accessibility contrast and landmarks","impact":"WCAG 1.4.3, 2.4.1","problem":"axe-core reports 1 serious color-contrast violation (#cookiescript_accept) and missing skip-to-content link.","solution":"- Increase contrast on `.lead-text` and cookie button to ≥4.5:1.\n- Add a skip link at the top of the DOM:\n```html\n<a href=\"#main\" class=\"skip-link\">Otse sisule</a>\n```"},{"priority":2,"title":"Strengthen HSTS configuration","impact":"Security Headers Grade","problem":"HSTS is present but missing the `preload` directive, preventing inclusion in browser preload lists.","solution":"Update the `Strict-Transport-Security` header to include preload:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":3,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower but still recommended for hardening.","solution":"Deploy a strict CSP with nonce/hash for scripts:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"}]},{"url":"https://kawiare.ee/kammkarp","overall":62,"reasoning":"Mobile performance is the primary drag with an LCP of 8.5 s and FCP of 4.58 s, driven by 11 render-blocking scripts and unused JavaScript. Security posture is critically weakened because HTTP requests do not redirect to HTTPS, exposing users to potential MITM attacks despite the HTTPS grade of 40/100. Accessibility is mostly solid (PSI 97) but contains one serious contrast violation and missing skip-link. Desktop performance is excellent (98), highlighting a severe mobile/desktop disparity. W3C validation errors and missing meta descriptions further reduce SEO confidence.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Data Integrity","problem":"HTTP requests do not redirect to HTTPS (http://kawiare.ee/kammkarp does not redirect), leaving traffic vulnerable to interception.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Eliminate Render-Blocking JavaScript","impact":"LCP, FCP, Mobile Performance","problem":"11 render-blocking scripts delay FCP to 4.58 s and LCP to 8.5 s on mobile; 224 KB of unused JS identified.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Inline critical CSS and move non-critical JS to the footer. Use `preload` for the LCP image resource."},{"priority":2,"title":"Fix Accessibility Violations","impact":"WCAG Compliance, Usability","problem":"1 serious color-contrast violation (#cookiescript_accept) and 3 moderate landmark issues; skip-to-content link is missing.","solution":"- Increase contrast ratio for `.cookiescript_accept` to ≥4.5:1.\n- Add `<a href=\"#main\" class=\"skip-link\">Skip to content</a>` before the header.\n- Ensure only one `<main>` element exists and it is not nested inside another landmark."},{"priority":2,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense, Security Headers","problem":"CSP is missing (Security Headers grade 40/100). While site signals show no auth/payments, CSP mitigates XSS risks from third-party scripts (e.g., GTM).","solution":"Deploy a strict CSP with nonce/hash for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; style-src 'self' 'unsafe-inline';\"\n```"},{"priority":3,"title":"Resolve W3C Validation Errors","impact":"SEO, Rendering Consistency","problem":"2 errors found: `<style>` not allowed in `div` context and unescaped `<` character in text content.","solution":"- Move inline `<style>` blocks to the `<head>` or external CSS file.\n- Escape special characters in text content (e.g., use `&lt;` instead of `<`)."}]},{"url":"https://kawiare.ee/ahven-ja-koha","overall":55,"reasoning":"Mobile performance (68) is dragged down by an 8.4s LCP despite excellent TTFB (3ms). Security configuration is critical: HTTP requests do not redirect to HTTPS, exposing users to interception. Accessibility is mostly strong (97 Lighthouse) but has one serious contrast violation on cookie buttons. SEO is missing a meta description. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Force HTTPS Redirect","impact":"Security, Transport Encryption","problem":"Security Headers audit found http://kawiare.ee/ahven-ja-koha does not redirect to HTTPS, leaving users vulnerable to interception.","solution":"Configure the web server (Apache/Nginx) to redirect all HTTP traffic to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Performance, Mobile UX","problem":"Mobile LCP is 8.4s (target <2.5s), driven by 11 render-blocking scripts and a 2560px hero image.","solution":"- Defer non-critical JavaScript (move 11 render-blocking scripts to footer or add `defer`).\n- Serve hero image in WebP/AVIF with responsive `srcset` (current 2560px is too large for mobile).\n- Preload the LCP image resource."},{"priority":2,"title":"Fix Accessibility Violations","impact":"WCAG Compliance, Inclusion","problem":"axe-core found 1 serious color-contrast violation on cookie buttons and 3 moderate landmark issues.","solution":"- Increase contrast on `#cookiescript_accept` / `#cookiescript_reject` to ≥4.5:1.\n- Ensure `<main>` is not nested inside another landmark and remove duplicate `role=\"main\"`."},{"priority":3,"title":"Add Meta Description","impact":"SEO, Click-Through Rate","problem":"W3C and SEO audits confirm the document lacks a meta description.","solution":"Add a concise description (150–160 chars) in the `<head>`:\n```html\n<meta name=\"description\" content=\"Ahven ja koha – kaks Balti järvede kala, mille väärtus vajab uuesti mõtestamist.\">```"},{"priority":3,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. While site signals show no auth/payments, a CSP prevents future XSS risks if features are added.","solution":"Deploy a strict CSP with nonce/hash for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\"```"}]},{"url":"https://kawiare.ee/lumekrabi","overall":62,"reasoning":"Mobile performance 65 is severely impacted by LCP 7.3s and 11 render-blocking scripts, despite excellent TTFB (4ms). Security is weak (40/100) primarily due to the lack of an HTTP-to-HTTPS redirect, a critical vulnerability. Accessibility has one serious color-contrast violation despite a 97 Lighthouse score. Desktop performance (94) is excellent, highlighting mobile-specific optimization gaps.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Data Integrity","problem":"http://kawiare.ee/lumekrabi does not redirect to HTTPS (Status 200 on HTTP), exposing users to MITM attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS.\n\n**Apache (.htaccess):**\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Defer Render-Blocking JavaScript","impact":"LCP, FCP, Performance Score","problem":"11 render-blocking scripts (including jQuery, WooCommerce, main.js) delay FCP (2.65s) and LCP (7.3s) on mobile.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Critical CSS should be inlined; remaining JS should load after paint.\n\n**Example:**\n```html\n<script src=\"/wp-content/.../main.js\" defer></script>\n```"},{"priority":2,"title":"Fix Color Contrast and Landmarks","impact":"Accessibility (WCAG 1.4.3, 1.3.1)","problem":"axe-core found 1 serious color-contrast violation (#cookiescript_accept) and 3 moderate landmark issues (duplicate main).","solution":"- Increase contrast on `#cookiescript_accept` to ≥4.5:1.\n- Ensure only one `<main>` element exists; remove duplicate `role=\"main\"`.\n- Add `aria-label` to landmarks if roles are duplicated."},{"priority":3,"title":"Add Security Headers (CSP, HSTS Preload)","impact":"Defense-in-depth, Security Score","problem":"CSP is missing; HSTS lacks preload directive. Site signals indicate low auth/payment risk, so this is P3.","solution":"Add CSP with nonce/hash strategy. Add `preload` to HSTS.\n\n**Apache:**\n```apache\nHeader set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'\"\n```"},{"priority":3,"title":"Improve SEO and Validation","impact":"Search Visibility, Code Quality","problem":"Missing meta description; W3C validator reports 2 errors (invalid `<style>` in `<div>`, unescaped `<`).","solution":"- Add `<meta name=\"description\" content=\"...\">`.\n- Fix W3C errors: Move `<style>` blocks to `<head>` or use `<div>` correctly; escape `<` as `&lt;`."}]},{"url":"https://kawiare.ee/kaaviar-tanapaeval","overall":62,"reasoning":"Mobile performance (56) is the primary drag, with LCP 8.3 s and FCP 4.6 s failing Core Web Vitals thresholds, despite desktop scoring 95. A critical security misconfiguration exists where HTTP does not redirect to HTTPS, alongside a low Security Headers grade (40/100). Accessibility is mostly sound but has one serious color-contrast violation and missing skip links. W3C validation shows 2 errors and SEO lacks a meta description. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Data Integrity","problem":"Security Headers audit confirms http://kawiare.ee/kaaviar-tanapaeval does not redirect to HTTPS, exposing traffic to interception.","solution":"Configure server (Apache/Nginx) to return 301/302 for all HTTP requests:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Mobile Performance, LCP, FCP","problem":"Mobile LCP is 8.3 s (target <2.5 s) and FCP is 4.6 s; 11 render-blocking scripts and 224 KB unused JS delay rendering.","solution":"- Defer non-critical scripts (WooCommerce, GTM) using `defer` or `async`.\n- Inline critical CSS for above-the-fold content.\n- Preload LCP image resource: `<link rel=\"preload\" as=\"image\" href=\"/path/to/hero.jpg\">`."},{"priority":2,"title":"Fix Accessibility Violations","impact":"WCAG 2.1 Compliance, UX","problem":"axe-core reports 1 serious color-contrast violation (#cookiescript_accept) and 3 moderate landmark issues (duplicate main, missing skip link).","solution":"- Increase contrast ratio for `#cookiescript_accept` to ≥4.5:1.\n- Add `<a href=\"#main\" class=\"skip-link\">Skip to content</a>`.\n- Ensure only one `<main>` element exists and remove nested landmarks."},{"priority":2,"title":"Strengthen Security Headers","impact":"XSS Protection, Transport Security","problem":"Security Headers grade is 40/100; HSTS missing preload directive, CSP missing, and Server header discloses Apache.","solution":"- Add HSTS preload: `max-age=63072000; includeSubDomains; preload`.\n- Implement CSP (nonce-based) if user content/auth is added later.\n- Hide server version: `ServerTokens Prod` (Apache)."},{"priority":3,"title":"Improve SEO and HTML Validity","impact":"Search Visibility, Code Quality","problem":"PSI SEO audit fails `metaDescription`; W3C reports 2 errors (invalid `<style>` in `div`, unescaped `<` character).","solution":"- Add `<meta name=\"description\" content=\"...\">`.\n- Fix W3C errors: move `<style>` to `<head>` or use `<div>` correctly; escape `<` as `&lt;` in text content."}]}]}