{"url":"https://kawiare.ee/","date":"2026-07-14","siteName":"Kawiare - Experience of Taste","overall":61,"reasoning":"Site overall 61 is the mean of 10 pages. Scores range 52 (https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta) → 71 (https://kawiare.ee/lumekrabi). Weakest page: Mobile performance is critically low (58) with an LCP of 8.5 s, driven by 11 render-blocking scripts and unused JavaScript. Security posture is weak due to missing HTTP-to-HTTPS redirects and absent CSP, despite the primary URL using HTTPS. Accessibility has a serious contrast violation and missing skip link, though core structure is mostly intact. Desktop performance is excellent (96), highlighting a severe mobile-specific bottleneck. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Eliminate render-blocking JavaScript","impact":"LCP, FCP, Performance Score","problem":"11 render-blocking scripts (including jQuery and WooCommerce) delay first paint; LCP is 10.1s on mobile.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Move WooCommerce and theme JS to footer or use `type=\"module\"`.\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":1,"title":"Optimize hero and above-fold images","impact":"LCP, Page Weight","problem":"Images total 1.45 MB; 6 images lack `loading=\"lazy\"`; hero image is eagerly loaded but heavy.","solution":"Convert PNG/JPEG to WebP/AVIF. Add `fetchpriority=\"high\"` to LCP image. Ensure `loading=\"lazy\"` on below-fold images.\n```html\n<img src=\"hero.webp\" fetchpriority=\"high\" alt=\"...\">\n```"},{"priority":1,"title":"Force HTTPS redirect","impact":"Security, Transport encryption","problem":"http://kawiare.ee/artiklid does not redirect to HTTPS, leaving users on unencrypted connections.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Fix LCP by optimizing hero image and scripts","impact":"LCP, FCP, Performance Score","problem":"LCP is 9.4 s on mobile; hero uses CSS background-image (no srcset) and 16 scripts are render-blocking.","solution":"1. Replace CSS background hero with a real `<img>` or `<picture>` element with `fetchpriority=\"high\"`.\n2. Add `defer` or `async` to non-critical scripts in `<head>`.\n3. Inline critical CSS and remove unused JS (224 KB wasted)."},{"priority":1,"title":"Enforce HTTPS redirect for all HTTP traffic","impact":"Security, Transport encryption","problem":"Security Headers audit reports: 'http://kawiare.ee... does not redirect to HTTPS'. This exposes users to MITM attacks on initial connection.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests.\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Eliminate render-blocking JavaScript to fix LCP","impact":"LCP (8.5 s), FCP (4.7 s), Mobile Performance (58)","problem":"11 render-blocking scripts found in HTML Inventory; PSI identifies 224 KB unused JS and long tasks delaying main thread.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Inline critical CSS and move non-critical JS to the footer.\n```html\n<!-- Change this -->\n<script src=\"main.js\"></script>\n<!-- To this -->\n<script src=\"main.js\" defer></script>\n```"},{"priority":1,"title":"Force HTTPS redirect for all HTTP traffic","impact":"Security, Data Integrity","problem":"Security Headers audit found 'http://kawiare.ee... does not redirect to HTTPS', leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests.\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Trust","problem":"http://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari does not redirect to HTTPS, leaving HTTP traffic unencrypted.","solution":"Configure server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests.\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Defer Render-Blocking JavaScript","impact":"LCP, FCP, Performance","problem":"11 render-blocking scripts contribute to a 5.4s LCP on mobile; 224 KB of unused JS identified.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`.\n```html\n<script src=\"main.js\" defer></script>\n```\nMove critical CSS inline and defer non-critical CSS."},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Performance, Mobile UX","problem":"Mobile LCP is 8.5 s (target ≤2.5 s) caused by render-blocking scripts and unoptimized hero image.","solution":"- Defer non-critical JavaScript (11 render-blocking scripts found).\n- Preload the hero image (`<link rel=\"preload\" as=\"image\" href=\"...\">`).\n- Convert hero image to WebP/AVIF and serve responsive sizes."},{"priority":2,"title":"Strengthen security headers","impact":"Security Headers Score, XSS/Clickjacking Defense","problem":"Security Headers grade 40/100; CSP missing, HSTS lacks preload directive.","solution":"Add CSP with nonce/hash (not just allowlist). Update HSTS to include `preload`.\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'\"\nHeader set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":2,"title":"Fix color contrast on cookie banner","impact":"Accessibility (WCAG 1.4.3)","problem":"axe-core reports 1 serious violation on `#cookiescript_accept` button.","solution":"Increase contrast ratio to ≥4.5:1 for text on the cookie accept button. Test with a contrast checker tool."},{"priority":2,"title":"Fix accessibility violations and landmarks","impact":"WCAG 1.4.3, 2.4.1, 2.4.6","problem":"Serious color-contrast on `#cookiescript_accept`; heading order skips H2; missing skip-to-content link; form inputs lack labels.","solution":"- Increase contrast on `#cookiescript_accept` to ≥4.5:1.\n- Insert `<h2>` between `h1` and `h3` or change `h3` to `h2`.\n- Add `<a href=\"#main\" class=\"skip-link\">Skip to content</a>`.\n- Add `<label>` or `aria-label` to all form inputs."},{"priority":2,"title":"Fix accessibility violations (contrast and landmarks)","impact":"WCAG 1.4.3, 1.3.1, Screen Reader usability","problem":"axe-core reports 1 serious color-contrast violation (#cookiescript_accept) and 3 moderate landmark issues (duplicate main, missing skip link).","solution":"- Increase contrast on `.cookiescript_accept` to ≥4.5:1.\n- Add `<a href=\"#main\" class=\"skip-link\">Skip to content</a>` before the header.\n- Ensure only one `<main>` element exists and it is not nested inside another landmark."},{"priority":2,"title":"Fix serious accessibility violations and landmarks","impact":"WCAG Compliance, Usability","problem":"axe-core found 1 serious color-contrast violation (#cookiescript_accept) and 3 moderate landmark issues (duplicate main, missing skip link).","solution":"- Increase contrast on `#cookiescript_accept` to ≥4.5:1.\n- Add a skip link: `<a href=\"#main\" class=\"skip-link\">Skip to content</a>`.\n- Ensure only one `<main>` element exists and it is not nested inside another landmark."},{"priority":2,"title":"Fix color contrast and add skip-to-content link","impact":"Accessibility (WCAG 1.4.3, 2.4.1)","problem":"axe-core found 1 serious contrast violation on `#cookiescript_accept` and HTML Inventory notes missing skip-to-content link.","solution":"- Increase contrast on the cookie accept button to ≥4.5:1.\n- Add a visible skip link at the top of the DOM:\n```html\n<a href=\"#main\" class=\"skip-link\">Otse sisule</a>\n```"},{"priority":2,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense, Security Headers Grade","problem":"CSP is missing. WooCommerce scripts are present, indicating potential cart functionality despite 'no ecommerce' signals.","solution":"Deploy a strict CSP with nonces for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"},{"priority":2,"title":"Fix Cookie Banner Contrast","impact":"WCAG 1.4.3 (Contrast)","problem":"axe-core reports a serious color-contrast violation on `#cookiescript_accept`.","solution":"Increase contrast ratio to at least 4.5:1 for text on the cookie banner.\n```css\n#cookiescript_accept { color: #333333; background: #ffffff; }\n```"},{"priority":2,"title":"Add Meta Description","impact":"SEO","problem":"HTML Inventory and PSI SEO audit show `Description: not set`.","solution":"Add a unique meta description tag in the `<head>`.\n```html\n<meta name=\"description\" content=\"20 punkti, kuidas eristada kvaliteetset kaaviari...\">\n```"},{"priority":2,"title":"Fix Accessibility Violations","impact":"WCAG Compliance, Usability","problem":"1 serious color-contrast violation (#cookiescript_accept) and 3 moderate landmark issues (duplicate main, missing skip link).","solution":"- Increase contrast on `#cookiescript_accept` to ≥4.5:1.\n- Add `<a class=\"skip-link\" href=\"#main\">Skip to content</a>`.\n- Ensure only one `<main>` element exists and remove duplicate `role=\"main\"`."},{"priority":2,"title":"Fix Color Contrast Violation","impact":"Accessibility (WCAG 1.4.3)","problem":"axe-core reports 1 serious violation on `#cookiescript_accept` where foreground/background contrast is insufficient.","solution":"Increase contrast ratio to at least 4.5:1 for normal text. Adjust CSS for the cookie accept button:\n```css\n#cookiescript_accept { color: #333; background: #fff; }\n```"},{"priority":2,"title":"Resolve Landmark Duplication","impact":"Accessibility (WCAG 1.3.1)","problem":"axe-core reports duplicate `main` landmarks (`#main` and `#primary`) and `main` nested inside another landmark.","solution":"Ensure only one `<main>` element exists per page. Remove `role=\"main\"` from `<div id=\"primary\">` if it wraps the main content, or change it to `<section>`."},{"priority":2,"title":"Fix accessibility contrast and landmarks","impact":"WCAG 1.4.3, 1.3.1, Screen Reader Navigation","problem":"1 serious color-contrast violation on #cookiescript_accept and 3 moderate landmark issues (duplicate main, nested main).","solution":"- Increase contrast on the cookie accept button to ≥4.5:1.\n- Remove duplicate `role=\"main\"` attributes; ensure only one `<main>` element exists.\n- Add a skip-to-content link at the top of the page for keyboard users."},{"priority":2,"title":"Add Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. While signals indicate no auth/payments on this page, WooCommerce plugins are present, increasing potential attack surface.","solution":"Implement a strict CSP with nonce/hash for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\"\n```\nEnsure all inline scripts use the nonce."},{"priority":3,"title":"Correct HTML structure and H1 usage","impact":"SEO, Accessibility","problem":"W3C reports 1 error (style in div); HTML Inventory shows 3 `<h1>` elements.","solution":"Ensure only one `<h1>` per page. Move inline `<style>` blocks to external CSS or `<head>`. Add a skip-to-content link."},{"priority":3,"title":"Add Content Security Policy and Meta Description","impact":"XSS defense, SEO snippet","problem":"CSP is missing (low risk per signals); SEO meta description not set.","solution":"1. Add a nonce-based CSP: `Content-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic';`\n2. Add `<meta name=\"description\" content=\"...\">` summarizing the article content."},{"priority":3,"title":"Add Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower than P1, but still recommended for defense-in-depth.","solution":"Implement a strict CSP with nonce/hash for scripts.\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"},{"priority":3,"title":"Add meta description for SEO","impact":"Search snippet quality, CTR","problem":"W3C/SEO audit notes: 'Document does not have a meta description'.","solution":"Add a unique description tag (150-160 chars) in `<head>`.\n```html\n<meta name=\"description\" content=\"Learn how to identify quality red fish roe with our expert guide on taste, smell, and texture.\">\n```"},{"priority":3,"title":"Implement Content-Security-Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower than P1, but still recommended for defense-in-depth.","solution":"Start with a report-only policy to identify violations, then enforce:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com;\"\n```"},{"priority":3,"title":"Add meta description and fix W3C errors","impact":"SEO, Code Quality","problem":"SEO audit flagged missing meta description; W3C validator reported 2 errors (invalid style in div, unescaped character).","solution":"- Add `<meta name=\"description\" content=\"...\">` summarizing the article.\n- Move inline `<style>` blocks out of `<div>` tags and escape `<` characters in text content."},{"priority":3,"title":"Add meta description and optimize hero image","impact":"SEO, LCP","problem":"HTML Inventory shows 'Description: not set' and hero image is a 2000×560 PNG without srcset.","solution":"- Add `<meta name=\"description\" content=\"...\">`.\n- Convert hero PNG to WebP/AVIF and add `srcset` for responsive loading."},{"priority":3,"title":"Implement Content Security Policy","impact":"XSS Defense-in-Depth","problem":"CSP is missing; site signals indicate no auth/payments on this page, lowering priority to P3.","solution":"Deploy a nonce-based CSP to mitigate XSS risks.\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'\"\n```"},{"priority":3,"title":"Implement Content Security Policy (CSP)","impact":"XSS Protection","problem":"CSP is missing. Site signals show no auth/payments/UGC, so risk is lower but still recommended for defense-in-depth.","solution":"Deploy a strict CSP with nonces for scripts:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{RANDOM}' 'strict-dynamic';\"\n```\nEnsure all inline scripts use the nonce."},{"priority":3,"title":"Add Content Security Policy","impact":"Security (XSS Defense)","problem":"CSP is missing. While site signals indicate no auth/payments, a CSP provides defense-in-depth against injected scripts.","solution":"Implement a strict CSP with nonce/hash for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"},{"priority":3,"title":"Add Meta Description","impact":"SEO","problem":"W3C and PSI report missing meta description, reducing click-through potential in search results.","solution":"Add a unique description tag in `<head>`:\n```html\n<meta name=\"description\" content=\"Lumekrabi on tervislik ja jätkusuutlik delikatess. Loe, kuidas eristada kvaliteetset kaaviari.\">\n```"},{"priority":3,"title":"Add meta description and lazy load below-fold images","impact":"SEO, Page Weight","problem":"Meta description is missing (SEO audit fail); 2 images below the fold lack loading=\"lazy\".","solution":"- Add a unique meta description tag in `<head>`.\n- Ensure all images below the fold have `loading=\"lazy\"` attribute:\n```html\n<img src=\"...\" alt=\"...\" loading=\"lazy\" width=\"...\" height=\"...\">\n```"}],"coverage":{"pct":100,"missing":[]},"siteSummary":{"pagesAudited":10,"pagesAttempted":10,"urls":["https://kawiare.ee/","https://kawiare.ee/artiklid","https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja","https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta","https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga","https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari","https://kawiare.ee/kammkarp","https://kawiare.ee/ahven-ja-koha","https://kawiare.ee/lumekrabi","https://kawiare.ee/kaaviar-tanapaeval"]},"psiSnapshot":{"rows":[{"pageUrl":"https://kawiare.ee/","perfMobile":56,"perfDesktop":69,"lcpMobileMs":10077.066513172631,"lcpDesktopMs":1832.5555886405978,"clsMobile":0,"clsDesktop":0.6371777108733764},{"pageUrl":"https://kawiare.ee/artiklid","perfMobile":68,"perfDesktop":89,"lcpMobileMs":9350.288631071786,"lcpDesktopMs":1871.6201004817021,"clsMobile":0.0006772344876011911,"clsDesktop":0.001307555645912965},{"pageUrl":"https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja","perfMobile":58,"perfDesktop":92,"lcpMobileMs":8525.994472137376,"lcpDesktopMs":1788.7862177673735,"clsMobile":0,"clsDesktop":0.0001730970214735764},{"pageUrl":"https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta","perfMobile":58,"perfDesktop":96,"lcpMobileMs":8517.07786317392,"lcpDesktopMs":1405.5372725573384,"clsMobile":0,"clsDesktop":0.00009994557290477509},{"pageUrl":"https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga","perfMobile":69,"perfDesktop":87,"lcpMobileMs":8907.275407591975,"lcpDesktopMs":1859.0254975178723,"clsMobile":0,"clsDesktop":0.0001730970214735764},{"pageUrl":"https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari","perfMobile":74,"perfDesktop":96,"lcpMobileMs":5387.376410586454,"lcpDesktopMs":1180.843459241049,"clsMobile":0,"clsDesktop":0.0001569569198852857},{"pageUrl":"https://kawiare.ee/kammkarp","perfMobile":61,"perfDesktop":95,"lcpMobileMs":8500.15500104284,"lcpDesktopMs":1481.7405525103363,"clsMobile":0,"clsDesktop":0.00009994557290477509},{"pageUrl":"https://kawiare.ee/ahven-ja-koha","perfMobile":41,"perfDesktop":96,"lcpMobileMs":9175.20115632718,"lcpDesktopMs":1331.747875037407,"clsMobile":0,"clsDesktop":0.00009163097511686772},{"pageUrl":"https://kawiare.ee/lumekrabi","perfMobile":74,"perfDesktop":97,"lcpMobileMs":5276.266354799742,"lcpDesktopMs":1193.5968499907467,"clsMobile":0,"clsDesktop":0.00009994557290477509},{"pageUrl":"https://kawiare.ee/kaaviar-tanapaeval","perfMobile":67,"perfDesktop":93,"lcpMobileMs":8358.436406677107,"lcpDesktopMs":1528.4338987217418,"clsMobile":0,"clsDesktop":0.00009163097511686772}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket)","evidence":["HTML markers: WP Rocket","generator: WordPress 7.0.1"]},{"id":"lazyload","title":"Images lazy-loaded","status":"pass","detail":"All raster images use loading=\"lazy\".","evidence":[]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"pass","detail":"Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable).","evidence":["hero: https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-1.png","loading: eager","fetchpriority: (not set)"]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"warn","detail":"Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.","evidence":["selector: div.pt-24.pb-16","url: …e.ee/wp-content/uploads/2026/01/823960696-teadmuskeskus_2592x726_b-scaled.jpg","box: 1280×464px"]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"warn","detail":"Only 15/22 raster images use srcset or <picture> (68%).","evidence":["https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-1.png","https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-e1782658950478.png","…kawiare.ee/wp-content/uploads/2026/02/Kawiare_paisepildid_mob_2_1900x2560.jpg","https://kawiare.ee/wp-content/uploads/2026/02/pais2_uus_2595x1467-scaled.jpg","…kawiare.ee/wp-content/uploads/2026/02/Kawiare_paisepildid_mob_3_1900x2560.jpg"]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"pass","detail":"17 distinct srcset widths.","evidence":["widths: 100, 150, 200, 225, 300, 600, 683, 768, 800, 1024, 1080, 1152, 1365, 1536, 1707, 1920, 2000"]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"fail","detail":"5 render-blocking scripts in <head>. Move to footer or add defer/async.","evidence":["…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638","https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1","https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1","…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0","…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0"]}],"summary":{"passed":4,"warned":2,"failed":1,"notApplicable":0},"priorities":[{"title":"JS scripts not blocking in <head>","severity":"high","detail":"5 render-blocking scripts in <head>. Move to footer or add defer/async."},{"title":"Responsive images (srcset / <picture>)","severity":"medium","detail":"Only 15/22 raster images use srcset or <picture> (68%)."},{"title":"Hero is a real <img> (not a CSS background-image)","severity":"medium","detail":"Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file."}]},"perPageOverall":[{"url":"https://kawiare.ee/","overall":62,"reasoning":"Mobile performance is critically low (56/100) driven by a 10.1s LCP and 3.8s FCP, despite a decent desktop score (69). Accessibility is strong (97/100) but marred by one serious color-contrast violation on the cookie banner. Security headers score 40/100 with missing CSP and weak HSTS configuration. HTML structure issues include three H1 tags and 11 render-blocking scripts that block the main thread. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Eliminate render-blocking JavaScript","impact":"LCP, FCP, Performance Score","problem":"11 render-blocking scripts (including jQuery and WooCommerce) delay first paint; LCP is 10.1s on mobile.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Move WooCommerce and theme JS to footer or use `type=\"module\"`.\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":1,"title":"Optimize hero and above-fold images","impact":"LCP, Page Weight","problem":"Images total 1.45 MB; 6 images lack `loading=\"lazy\"`; hero image is eagerly loaded but heavy.","solution":"Convert PNG/JPEG to WebP/AVIF. Add `fetchpriority=\"high\"` to LCP image. Ensure `loading=\"lazy\"` on below-fold images.\n```html\n<img src=\"hero.webp\" fetchpriority=\"high\" alt=\"...\">\n```"},{"priority":2,"title":"Strengthen security headers","impact":"Security Headers Score, XSS/Clickjacking Defense","problem":"Security Headers grade 40/100; CSP missing, HSTS lacks preload directive.","solution":"Add CSP with nonce/hash (not just allowlist). Update HSTS to include `preload`.\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'\"\nHeader set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":2,"title":"Fix color contrast on cookie banner","impact":"Accessibility (WCAG 1.4.3)","problem":"axe-core reports 1 serious violation on `#cookiescript_accept` button.","solution":"Increase contrast ratio to ≥4.5:1 for text on the cookie accept button. Test with a contrast checker tool."},{"priority":3,"title":"Correct HTML structure and H1 usage","impact":"SEO, Accessibility","problem":"W3C reports 1 error (style in div); HTML Inventory shows 3 `<h1>` elements.","solution":"Ensure only one `<h1>` per page. Move inline `<style>` blocks to external CSS or `<head>`. Add a skip-to-content link."}]},{"url":"https://kawiare.ee/artiklid","overall":58,"reasoning":"Mobile performance is critically low (68) driven by an LCP of 9.4 s, which exceeds the 4 s heavy penalty threshold. A critical security configuration error allows HTTP access without redirecting to HTTPS, exposing users to interception. While TTFB is excellent (6 ms) and desktop scores well (89), render-blocking scripts and a CSS background hero image prevent mobile users from seeing content quickly. Accessibility is mostly solid but has one serious contrast violation and missing skip links. SEO suffers from a missing meta description.","confidence":"high","fixes":[{"priority":1,"title":"Force HTTPS redirect","impact":"Security, Transport encryption","problem":"http://kawiare.ee/artiklid does not redirect to HTTPS, leaving users on unencrypted connections.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Fix LCP by optimizing hero image and scripts","impact":"LCP, FCP, Performance Score","problem":"LCP is 9.4 s on mobile; hero uses CSS background-image (no srcset) and 16 scripts are render-blocking.","solution":"1. Replace CSS background hero with a real `<img>` or `<picture>` element with `fetchpriority=\"high\"`.\n2. Add `defer` or `async` to non-critical scripts in `<head>`.\n3. Inline critical CSS and remove unused JS (224 KB wasted)."},{"priority":2,"title":"Fix accessibility violations and landmarks","impact":"WCAG 1.4.3, 2.4.1, 2.4.6","problem":"Serious color-contrast on `#cookiescript_accept`; heading order skips H2; missing skip-to-content link; form inputs lack labels.","solution":"- Increase contrast on `#cookiescript_accept` to ≥4.5:1.\n- Insert `<h2>` between `h1` and `h3` or change `h3` to `h2`.\n- Add `<a href=\"#main\" class=\"skip-link\">Skip to content</a>`.\n- Add `<label>` or `aria-label` to all form inputs."},{"priority":2,"title":"Strengthen security headers","impact":"HSTS, COOP, CORP","problem":"HSTS missing preload directive; COOP, CORP, Permissions-Policy missing.","solution":"Add the following headers:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set Cross-Origin-Opener-Policy \"same-origin\"\nHeader always set Cross-Origin-Resource-Policy \"same-origin\"\n```"},{"priority":3,"title":"Add Content Security Policy and Meta Description","impact":"XSS defense, SEO snippet","problem":"CSP is missing (low risk per signals); SEO meta description not set.","solution":"1. Add a nonce-based CSP: `Content-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic';`\n2. Add `<meta name=\"description\" content=\"...\">` summarizing the article content."}]},{"url":"https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja","overall":66,"reasoning":"Mobile performance is the primary drag (PSI 58, LCP 8.5 s), driven by 11 render-blocking scripts and unused JavaScript. Security configuration has a critical gap where HTTP traffic does not redirect to HTTPS, despite the site supporting HTTPS. Accessibility is mostly strong (PSI 97) but contains one serious color-contrast violation and missing landmarks. Image optimization is adequate with only 5 images, though some lack srcset. Confidence is high due to complete tool coverage.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS redirect for all HTTP traffic","impact":"Security, Transport encryption","problem":"Security Headers audit reports: 'http://kawiare.ee... does not redirect to HTTPS'. This exposes users to MITM attacks on initial connection.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests.\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Eliminate render-blocking JavaScript to fix LCP","impact":"LCP (8.5 s), FCP (4.7 s), Mobile Performance (58)","problem":"11 render-blocking scripts found in HTML Inventory; PSI identifies 224 KB unused JS and long tasks delaying main thread.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Inline critical CSS and move non-critical JS to the footer.\n```html\n<!-- Change this -->\n<script src=\"main.js\"></script>\n<!-- To this -->\n<script src=\"main.js\" defer></script>\n```"},{"priority":2,"title":"Fix accessibility violations (contrast and landmarks)","impact":"WCAG 1.4.3, 1.3.1, Screen Reader usability","problem":"axe-core reports 1 serious color-contrast violation (#cookiescript_accept) and 3 moderate landmark issues (duplicate main, missing skip link).","solution":"- Increase contrast on `.cookiescript_accept` to ≥4.5:1.\n- Add `<a href=\"#main\" class=\"skip-link\">Skip to content</a>` before the header.\n- Ensure only one `<main>` element exists and it is not nested inside another landmark."},{"priority":3,"title":"Add Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower than P1, but still recommended for defense-in-depth.","solution":"Implement a strict CSP with nonce/hash for scripts.\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"},{"priority":3,"title":"Add meta description for SEO","impact":"Search snippet quality, CTR","problem":"W3C/SEO audit notes: 'Document does not have a meta description'.","solution":"Add a unique description tag (150-160 chars) in `<head>`.\n```html\n<meta name=\"description\" content=\"Learn how to identify quality red fish roe with our expert guide on taste, smell, and texture.\">\n```"}]},{"url":"https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta","overall":52,"reasoning":"Mobile performance is critically low (58) with an LCP of 8.5 s, driven by 11 render-blocking scripts and unused JavaScript. Security posture is weak due to missing HTTP-to-HTTPS redirects and absent CSP, despite the primary URL using HTTPS. Accessibility has a serious contrast violation and missing skip link, though core structure is mostly intact. Desktop performance is excellent (96), highlighting a severe mobile-specific bottleneck. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS redirect for all HTTP traffic","impact":"Security, Data Integrity","problem":"Security Headers audit found 'http://kawiare.ee/... does not redirect to HTTPS', allowing downgrade attacks despite the main URL using HTTPS.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to the HTTPS version:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Eliminate render-blocking JavaScript to fix LCP","impact":"LCP, FCP, Performance Score","problem":"Mobile LCP is 8.5 s (threshold 2.5 s); 11 render-blocking scripts identified in HTML Inventory and Optimization Checklist.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`, or move them to the footer. Prioritize deferring WooCommerce and analytics scripts:\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":2,"title":"Fix serious accessibility violations and landmarks","impact":"WCAG Compliance, Usability","problem":"axe-core found 1 serious color-contrast violation (#cookiescript_accept) and 3 moderate landmark issues (duplicate main, missing skip link).","solution":"- Increase contrast on `#cookiescript_accept` to ≥4.5:1.\n- Add a skip link: `<a href=\"#main\" class=\"skip-link\">Skip to content</a>`.\n- Ensure only one `<main>` element exists and it is not nested inside another landmark."},{"priority":3,"title":"Implement Content-Security-Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower than P1, but still recommended for defense-in-depth.","solution":"Start with a report-only policy to identify violations, then enforce:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com;\"\n```"},{"priority":3,"title":"Add meta description and fix W3C errors","impact":"SEO, Code Quality","problem":"SEO audit flagged missing meta description; W3C validator reported 2 errors (invalid style in div, unescaped character).","solution":"- Add `<meta name=\"description\" content=\"...\">` summarizing the article.\n- Move inline `<style>` blocks out of `<div>` tags and escape `<` characters in text content."}]},{"url":"https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga","overall":55,"reasoning":"Mobile performance is critically hampered by an 8.9 s LCP and 11 render-blocking scripts, despite a PSI score of 69. Security posture is weak due to missing HTTPS redirects and a 40/100 header grade. Accessibility has one serious contrast violation and missing skip links. SEO suffers from a missing meta description. The discrepancy between the 69 performance score and 8.9 s LCP suggests heavy blocking resources.","confidence":"high","fixes":[{"priority":1,"title":"Force HTTPS redirect for all HTTP traffic","impact":"Security, Data Integrity","problem":"Security Headers audit found 'http://kawiare.ee... does not redirect to HTTPS', leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests.\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Eliminate render-blocking JavaScript to fix LCP","impact":"LCP, FCP, Performance Score","problem":"LCP is 8.9 s on mobile with 11 render-blocking scripts identified in HTML Inventory and PSI.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Inline critical CSS and move non-critical JS to the footer.\n```html\n<!-- Change this -->\n<script src=\"main.js\"></script>\n<!-- To this -->\n<script src=\"main.js\" defer></script>\n```"},{"priority":2,"title":"Fix color contrast and add skip-to-content link","impact":"Accessibility (WCAG 1.4.3, 2.4.1)","problem":"axe-core found 1 serious contrast violation on `#cookiescript_accept` and HTML Inventory notes missing skip-to-content link.","solution":"- Increase contrast on the cookie accept button to ≥4.5:1.\n- Add a visible skip link at the top of the DOM:\n```html\n<a href=\"#main\" class=\"skip-link\">Otse sisule</a>\n```"},{"priority":2,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense, Security Headers Grade","problem":"CSP is missing. WooCommerce scripts are present, indicating potential cart functionality despite 'no ecommerce' signals.","solution":"Deploy a strict CSP with nonces for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"},{"priority":3,"title":"Add meta description and optimize hero image","impact":"SEO, LCP","problem":"HTML Inventory shows 'Description: not set' and hero image is a 2000×560 PNG without srcset.","solution":"- Add `<meta name=\"description\" content=\"...\">`.\n- Convert hero PNG to WebP/AVIF and add `srcset` for responsive loading."}]},{"url":"https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari","overall":65,"reasoning":"Mobile performance (74) is significantly impacted by a 5.4s LCP and 11 render-blocking scripts, despite a strong desktop score. Security posture is weakened by the lack of an HTTP-to-HTTPS redirect and missing CSP, though HSTS is present. Accessibility has one serious contrast violation on the cookie banner, and SEO lacks a meta description. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Trust","problem":"http://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari does not redirect to HTTPS, leaving HTTP traffic unencrypted.","solution":"Configure server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests.\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Defer Render-Blocking JavaScript","impact":"LCP, FCP, Performance","problem":"11 render-blocking scripts contribute to a 5.4s LCP on mobile; 224 KB of unused JS identified.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`.\n```html\n<script src=\"main.js\" defer></script>\n```\nMove critical CSS inline and defer non-critical CSS."},{"priority":2,"title":"Fix Cookie Banner Contrast","impact":"WCAG 1.4.3 (Contrast)","problem":"axe-core reports a serious color-contrast violation on `#cookiescript_accept`.","solution":"Increase contrast ratio to at least 4.5:1 for text on the cookie banner.\n```css\n#cookiescript_accept { color: #333333; background: #ffffff; }\n```"},{"priority":2,"title":"Add Meta Description","impact":"SEO","problem":"HTML Inventory and PSI SEO audit show `Description: not set`.","solution":"Add a unique meta description tag in the `<head>`.\n```html\n<meta name=\"description\" content=\"20 punkti, kuidas eristada kvaliteetset kaaviari...\">\n```"},{"priority":3,"title":"Implement Content Security Policy","impact":"XSS Defense-in-Depth","problem":"CSP is missing; site signals indicate no auth/payments on this page, lowering priority to P3.","solution":"Deploy a nonce-based CSP to mitigate XSS risks.\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'\"\n```"}]},{"url":"https://kawiare.ee/kammkarp","overall":65,"reasoning":"Mobile performance (61) is the primary drag due to an 8.5 s LCP and 11 render-blocking scripts, despite a strong desktop score (95). Security configuration is weak (40/100) with a critical missing HTTP-to-HTTPS redirect, though signals indicate no auth/payment exposure. Accessibility is high (97) but contains one serious color-contrast violation and missing landmarks. The site is a food blog/recipe page, so performance on mobile devices is critical for user retention.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS redirect","impact":"Security, Data Integrity","problem":"http://kawiare.ee/kammkarp does not redirect to HTTPS, leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Performance, Mobile UX","problem":"Mobile LCP is 8.5 s (target ≤2.5 s) caused by render-blocking scripts and unoptimized hero image.","solution":"- Defer non-critical JavaScript (11 render-blocking scripts found).\n- Preload the hero image (`<link rel=\"preload\" as=\"image\" href=\"...\">`).\n- Convert hero image to WebP/AVIF and serve responsive sizes."},{"priority":2,"title":"Fix Accessibility Violations","impact":"WCAG Compliance, Usability","problem":"1 serious color-contrast violation (#cookiescript_accept) and 3 moderate landmark issues (duplicate main, missing skip link).","solution":"- Increase contrast on `#cookiescript_accept` to ≥4.5:1.\n- Add `<a class=\"skip-link\" href=\"#main\">Skip to content</a>`.\n- Ensure only one `<main>` element exists and remove duplicate `role=\"main\"`."},{"priority":2,"title":"Strengthen Security Headers","impact":"Defense-in-depth","problem":"Security Headers grade is 40/100; HSTS missing preload directive, missing CSP, COOP, CORP.","solution":"Add HSTS preload and other headers (Apache example):\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":3,"title":"Implement Content Security Policy (CSP)","impact":"XSS Protection","problem":"CSP is missing. Site signals show no auth/payments/UGC, so risk is lower but still recommended for defense-in-depth.","solution":"Deploy a strict CSP with nonces for scripts:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{RANDOM}' 'strict-dynamic';\"\n```\nEnsure all inline scripts use the nonce."}]},{"url":"https://kawiare.ee/ahven-ja-koha","overall":55,"reasoning":"Mobile performance is critically low at 41 with an LCP of 9.2 s, far exceeding the 2.5 s threshold and causing a heavy penalty. Security configuration is flawed as HTTP requests do not redirect to HTTPS, creating a downgrade risk despite HTTPS being available. Accessibility has one serious color-contrast violation and missing skip-to-content link, though desktop performance is excellent at 96. W3C validation shows 2 errors related to invalid style placement and unescaped characters, and 11 render-blocking scripts drive the high TBT of 1.3 s. The site is functional but requires urgent mobile optimization and security hardening.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Transport Layer","problem":"Security Headers audit states 'http://kawiare.ee/ahven-ja-koha does not redirect to HTTPS', leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Defer Render-Blocking JavaScript","impact":"LCP, TBT, Mobile Performance","problem":"PSI mobile LCP is 9.2 s and TBT is 1.3 s; HTML Inventory identifies 11 render-blocking scripts including main.js and jQuery.","solution":"Add `defer` or `async` attributes to non-critical scripts in the `<head>`. For WordPress, use a plugin like 'WP Rocket' or 'Autoptimize' to defer JS, or manually update theme headers:\n```html\n<script src=\"main.js\" defer></script>\n```"},{"priority":2,"title":"Fix Accessibility Violations","impact":"WCAG 2.1 Compliance, UX","problem":"axe-core reports 1 serious color-contrast violation on `#cookiescript_accept` and 3 moderate landmark issues; skip-to-content link is missing.","solution":"- Increase contrast on `#cookiescript_accept` to ≥4.5:1.\n- Ensure `<main>` is not nested inside another landmark.\n- Add a skip link at the top of the `<body>`:\n```html\n<a href=\"#main\" class=\"skip-link\">Otse sisule</a>\n```"},{"priority":2,"title":"Strengthen Security Headers","impact":"Transport Security, Clickjacking","problem":"HSTS is present but missing the `preload` directive; X-Content-Type-Options and X-Frame-Options are present but HSTS preload is missing.","solution":"Update HSTS header to include preload for browser inclusion:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":3,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. Site signals indicate no auth, payments, or user content, so XSS risk is lower than P1 per rubric.","solution":"If user content or login is added later, deploy a nonce-based CSP:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'\"\n```"}]},{"url":"https://kawiare.ee/lumekrabi","overall":71,"reasoning":"Mobile performance (74) is dragged down significantly by LCP 5.3 s and 11 render-blocking scripts, despite an excellent TTFB of 4 ms. Security grade (40/100) is weak primarily because HTTP does not redirect to HTTPS, though HSTS and X-Frame-Options are present. Accessibility is strong (97 PSI) but contains 1 serious color-contrast violation and landmark issues. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS Redirect","impact":"Security, Transport","problem":"http://kawiare.ee/lumekrabi does not redirect to HTTPS, leaving users on insecure connections if they type the URL manually.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Defer Render-Blocking JavaScript","impact":"LCP, FCP, Performance","problem":"11 render-blocking scripts delay first paint; LCP is 5.3 s on mobile due to script execution time.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Critical CSS should be inlined, and JS moved to footer:\n```html\n<script src=\"main.js\" defer></script>\n```"},{"priority":2,"title":"Fix Color Contrast Violation","impact":"Accessibility (WCAG 1.4.3)","problem":"axe-core reports 1 serious violation on `#cookiescript_accept` where foreground/background contrast is insufficient.","solution":"Increase contrast ratio to at least 4.5:1 for normal text. Adjust CSS for the cookie accept button:\n```css\n#cookiescript_accept { color: #333; background: #fff; }\n```"},{"priority":2,"title":"Resolve Landmark Duplication","impact":"Accessibility (WCAG 1.3.1)","problem":"axe-core reports duplicate `main` landmarks (`#main` and `#primary`) and `main` nested inside another landmark.","solution":"Ensure only one `<main>` element exists per page. Remove `role=\"main\"` from `<div id=\"primary\">` if it wraps the main content, or change it to `<section>`."},{"priority":3,"title":"Add Content Security Policy","impact":"Security (XSS Defense)","problem":"CSP is missing. While site signals indicate no auth/payments, a CSP provides defense-in-depth against injected scripts.","solution":"Implement a strict CSP with nonce/hash for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"},{"priority":3,"title":"Add Meta Description","impact":"SEO","problem":"W3C and PSI report missing meta description, reducing click-through potential in search results.","solution":"Add a unique description tag in `<head>`:\n```html\n<meta name=\"description\" content=\"Lumekrabi on tervislik ja jätkusuutlik delikatess. Loe, kuidas eristada kvaliteetset kaaviari.\">\n```"}]},{"url":"https://kawiare.ee/kaaviar-tanapaeval","overall":62,"reasoning":"Mobile performance is the primary drag with a score of 67 and a critical LCP of 8.4 s, far exceeding the 4 s threshold. Security configuration is fundamentally flawed as HTTP does not redirect to HTTPS, creating a downgrade vulnerability. Accessibility is mostly strong (97) but contains one serious contrast violation and landmark issues. SEO is functional but missing a meta description. The combination of catastrophic mobile load time and insecure HTTP handling prevents a higher score despite excellent TTFB and desktop performance.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS redirect","impact":"Security, Trust, Mixed Content","problem":"HTTP requests to http://kawiare.ee/kaaviar-tanapaeval do not redirect to HTTPS, exposing users to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Eliminate render-blocking JavaScript to fix LCP","impact":"LCP, FCP, Mobile Performance","problem":"11 render-blocking scripts and 224 KB unused JS delay FCP to 2.64 s and LCP to 8.4 s on mobile.","solution":"Defer non-critical scripts and inline critical CSS. Specifically target WooCommerce and GTM scripts:\n```html\n<script src=\"...woocommerce.min.js\" defer></script>\n<script src=\"...gtag.js\" async></script>\n```\nUse a plugin like WP Rocket (already detected) to enable 'Minify and combine JavaScript' and 'Defer JS'."},{"priority":2,"title":"Fix accessibility contrast and landmarks","impact":"WCAG 1.4.3, 1.3.1, Screen Reader Navigation","problem":"1 serious color-contrast violation on #cookiescript_accept and 3 moderate landmark issues (duplicate main, nested main).","solution":"- Increase contrast on the cookie accept button to ≥4.5:1.\n- Remove duplicate `role=\"main\"` attributes; ensure only one `<main>` element exists.\n- Add a skip-to-content link at the top of the page for keyboard users."},{"priority":2,"title":"Add Content Security Policy (CSP)","impact":"XSS Defense-in-Depth","problem":"CSP is missing. While signals indicate no auth/payments on this page, WooCommerce plugins are present, increasing potential attack surface.","solution":"Implement a strict CSP with nonce/hash for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\"\n```\nEnsure all inline scripts use the nonce."},{"priority":3,"title":"Add meta description and lazy load below-fold images","impact":"SEO, Page Weight","problem":"Meta description is missing (SEO audit fail); 2 images below the fold lack loading=\"lazy\".","solution":"- Add a unique meta description tag in `<head>`.\n- Ensure all images below the fold have `loading=\"lazy\"` attribute:\n```html\n<img src=\"...\" alt=\"...\" loading=\"lazy\" width=\"...\" height=\"...\">\n```"}]}]}