# Audit Report: Kawiare - Experience of Taste **Website:** https://kawiare.ee/ **Date:** 2026-07-14 **Overall Score:** 61 / 100 **Status:** 🟑 **Needs Improvement** **Confidence:** high **Audit Coverage:** 100% β€” all sources returned data **Pages Audited (10 of 10):** - https://kawiare.ee/ - https://kawiare.ee/artiklid - https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja - https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta - https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga - https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari - https://kawiare.ee/kammkarp - https://kawiare.ee/ahven-ja-koha - https://kawiare.ee/lumekrabi - https://kawiare.ee/kaaviar-tanapaeval ## Summary Site overall 61 is the mean of 10 pages. Scores range 52 (https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta) β†’ 71 (https://kawiare.ee/lumekrabi). Weakest page: Mobile performance is critically low (58) with an LCP of 8.5 s, driven by 11 render-blocking scripts and unused JavaScript. Security posture is weak due to missing HTTP-to-HTTPS redirects and absent CSP, despite the primary URL using HTTPS. Accessibility has a serious contrast violation and missing skip link, though core structure is mostly intact. Desktop performance is excellent (96), highlighting a severe mobile-specific bottleneck. Confidence is high as all audit tools returned complete data. ## Per-Page Scores | Page | Score | Status | Confidence | | --- | --- | --- | --- | | https://kawiare.ee/ | 62 | 🟑 **Needs Improvement** | high | | https://kawiare.ee/artiklid | 58 | 🟠 **Poor** | high | | https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja | 66 | 🟑 **Needs Improvement** | high | | https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta | 52 | 🟠 **Poor** | high | | https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga | 55 | 🟠 **Poor** | high | | https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari | 65 | 🟑 **Needs Improvement** | high | | https://kawiare.ee/kammkarp | 65 | 🟑 **Needs Improvement** | high | | https://kawiare.ee/ahven-ja-koha | 55 | 🟠 **Poor** | high | | https://kawiare.ee/lumekrabi | 71 | 🟑 **Needs Improvement** | high | | https://kawiare.ee/kaaviar-tanapaeval | 62 | 🟑 **Needs Improvement** | high | ## PageSpeed Insights β€” Mobile vs Desktop _Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._ | URL | Performance (M / D) | LCP (M / D) | CLS (M / D) | | --- | --- | --- | --- | | https://kawiare.ee/ | **56** / 69 | **10.08 s** / 1.83 s | 0.000 / **0.637** | | https://kawiare.ee/artiklid | **68** / 89 | **9.35 s** / 1.87 s | 0.001 / **0.001** | | https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja | **58** / 92 | **8.53 s** / 1.79 s | 0.000 / **0.000** | | https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta | **58** / 96 | **8.52 s** / 1.41 s | 0.000 / **0.000** | | https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga | **69** / 87 | **8.91 s** / 1.86 s | 0.000 / **0.000** | | https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari | **74** / 96 | **5.39 s** / 1.18 s | 0.000 / **0.000** | | https://kawiare.ee/kammkarp | **61** / 95 | **8.50 s** / 1.48 s | 0.000 / **0.000** | | https://kawiare.ee/ahven-ja-koha | **41** / 96 | **9.18 s** / 1.33 s | 0.000 / **0.000** | | https://kawiare.ee/lumekrabi | **74** / 97 | **5.28 s** / 1.19 s | 0.000 / **0.000** | | https://kawiare.ee/kaaviar-tanapaeval | **67** / 93 | **8.36 s** / 1.53 s | 0.000 / **0.000** | ## Optimization Checklist **4 of 7 passing** β€” 4 pass Β· 2 warn Β· 1 fail | Item | Status | Detail | | --- | --- | --- | | Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) | | Images lazy-loaded | **Pass** | All raster images use loading="lazy". | | Hero image eagerly loaded | **Pass** | Hero image is eagerly loaded (inferred from DOM order/size β€” Lighthouse LCP element unavailable). | | Hero is a real (not a CSS background-image) | **Warn** | Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport β€” there is no srcset equivalent. Move the hero to a real with srcset/sizes (or ) so smaller viewports can fetch a smaller file. | | Responsive images (srcset / ) | **Warn** | Only 15/22 raster images use srcset or (68%). | | Reasonable number of image sizes | **Pass** | 17 distinct srcset widths. | | JS scripts not blocking in | **Fail** | 5 render-blocking scripts in . Move to footer or add defer/async. | ## Fixes ### Priority 1: Critical *Immediate action β€” impacts user experience, search rankings, or site safety.* **1A. Eliminate render-blocking JavaScript** - **Impact:** LCP, FCP, Performance Score - **Problem:** 11 render-blocking scripts (including jQuery and WooCommerce) delay first paint; LCP is 10.1s on mobile. - **Solution:** Add `defer` or `async` to non-critical scripts in ``. Move WooCommerce and theme JS to footer or use `type="module"`. ```html ``` **1B. Optimize hero and above-fold images** - **Impact:** LCP, Page Weight - **Problem:** Images total 1.45 MB; 6 images lack `loading="lazy"`; hero image is eagerly loaded but heavy. - **Solution:** Convert PNG/JPEG to WebP/AVIF. Add `fetchpriority="high"` to LCP image. Ensure `loading="lazy"` on below-fold images. ```html ... ``` **1C. Force HTTPS redirect** - **Impact:** Security, Transport encryption - **Problem:** http://kawiare.ee/artiklid does not redirect to HTTPS, leaving users on unencrypted connections. - **Solution:** Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS: ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1D. Fix LCP by optimizing hero image and scripts** - **Impact:** LCP, FCP, Performance Score - **Problem:** LCP is 9.4 s on mobile; hero uses CSS background-image (no srcset) and 16 scripts are render-blocking. - **Solution:** 1. Replace CSS background hero with a real `` or `` element with `fetchpriority="high"`. 2. Add `defer` or `async` to non-critical scripts in ``. 3. Inline critical CSS and remove unused JS (224 KB wasted). **1E. Enforce HTTPS redirect for all HTTP traffic** - **Impact:** Security, Transport encryption - **Problem:** Security Headers audit reports: 'http://kawiare.ee... does not redirect to HTTPS'. This exposes users to MITM attacks on initial connection. - **Solution:** Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests. ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1F. Eliminate render-blocking JavaScript to fix LCP** - **Impact:** LCP (8.5 s), FCP (4.7 s), Mobile Performance (58) - **Problem:** 11 render-blocking scripts found in HTML Inventory; PSI identifies 224 KB unused JS and long tasks delaying main thread. - **Solution:** Add `defer` or `async` to non-critical scripts in ``. Inline critical CSS and move non-critical JS to the footer. ```html ``` **1G. Force HTTPS redirect for all HTTP traffic** - **Impact:** Security, Data Integrity - **Problem:** Security Headers audit found 'http://kawiare.ee... does not redirect to HTTPS', leaving users vulnerable to downgrade attacks. - **Solution:** Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests. ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1H. Enforce HTTPS Redirect** - **Impact:** Security, Trust - **Problem:** http://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari does not redirect to HTTPS, leaving HTTP traffic unencrypted. - **Solution:** Configure server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests. ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1I. Defer Render-Blocking JavaScript** - **Impact:** LCP, FCP, Performance - **Problem:** 11 render-blocking scripts contribute to a 5.4s LCP on mobile; 224 KB of unused JS identified. - **Solution:** Add `defer` or `async` to non-critical scripts in ``. ```html ``` Move critical CSS inline and defer non-critical CSS. **1J. Optimize Largest Contentful Paint (LCP)** - **Impact:** Performance, Mobile UX - **Problem:** Mobile LCP is 8.5 s (target ≀2.5 s) caused by render-blocking scripts and unoptimized hero image. - **Solution:** - Defer non-critical JavaScript (11 render-blocking scripts found). - Preload the hero image (``). - Convert hero image to WebP/AVIF and serve responsive sizes. ### Priority 2: Important *Essential for compliance, user reach, and search visibility.* **2A. Strengthen security headers** - **Impact:** Security Headers Score, XSS/Clickjacking Defense - **Problem:** Security Headers grade 40/100; CSP missing, HSTS lacks preload directive. - **Solution:** Add CSP with nonce/hash (not just allowlist). Update HSTS to include `preload`. ```apache Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'" Header set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" ``` **2B. Fix color contrast on cookie banner** - **Impact:** Accessibility (WCAG 1.4.3) - **Problem:** axe-core reports 1 serious violation on `#cookiescript_accept` button. - **Solution:** Increase contrast ratio to β‰₯4.5:1 for text on the cookie accept button. Test with a contrast checker tool. **2C. Fix accessibility violations and landmarks** - **Impact:** WCAG 1.4.3, 2.4.1, 2.4.6 - **Problem:** Serious color-contrast on `#cookiescript_accept`; heading order skips H2; missing skip-to-content link; form inputs lack labels. - **Solution:** - Increase contrast on `#cookiescript_accept` to β‰₯4.5:1. - Insert `

` between `h1` and `h3` or change `h3` to `h2`. - Add ``. - Add `