# Audit Report: lootsa **Website:** https://lootsa.ee/ **Date:** 17.08.2026 **Audit Coverage:** 100% — all sources returned data **Confidence:** high **Pages Audited (1 of 1):** - https://lootsa.ee/ ## Summary of results **Overall Score:** 73 / 100 **Status:** 🟡 **Needs Improvement** PSI mobile performance is excellent at 97 with LCP 2.0 s, but security headers score 0/100 and W3C validation has 15 errors. Two serious accessibility violations (link names, contrast) impact usability despite a 96 PSI accessibility score. The site signals indicate user-generated content (textarea, upload), elevating CSP to Priority 1. Mobile FCP is 1.97 s, slightly above the 1.8 s threshold, partly due to the hero image being lazy-loaded. Confidence is high as all audit tools returned complete data. ### Per-page scores 🟡 **Needs Improvement** · https://lootsa.ee/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 73 | 97 | 96 | 100 | 92 | 0 | ## PageSpeed Insights — Mobile vs Desktop _Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._ | Strategy | Performance (M / D) | LCP (M / D) | CLS (M / D) | | --- | --- | --- | --- | | Mobile vs Desktop | **97** / 100 | **1.97 s** / 641 ms | 0.000 / **0.028** | ## Optimization Checklist **4 of 6 passing** — 4 pass · 1 warn · 1 fail · 1 n/a | Item | Status | Detail | | --- | --- | --- | | Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) | | Images lazy-loaded | **Pass** | All non-hero raster images use loading="lazy". | | Hero image eagerly loaded | **Fail** | Hero image has loading="lazy", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading="eager" (or omit loading) and add fetchpriority="high". | | Hero is a real (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. | | Responsive images (srcset / ) | **Warn** | Only 23/30 raster images use srcset or (77%). | | Reasonable number of image sizes | **Pass** | 25 distinct srcset widths. | | JS scripts not blocking in | **Pass** | No render-blocking scripts in . | ## Fixes ### Priority 1: Critical *Immediate action — impacts user experience, search rankings, or site safety.* **1A. Add baseline security headers (HSTS, X-Frame-Options, X-Content-Type-Options)** `Security` - **Impact:** Transport security, clickjacking, MIME sniffing - **Problem:** Security Headers grade is 0/100; HSTS, X-Frame-Options, and X-Content-Type-Options are missing. - **Solution:** Add these headers to your server configuration (e.g., Apache .htaccess or Nginx config): ```apache Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" Header always set X-Frame-Options "SAMEORIGIN" Header always set X-Content-Type-Options "nosniff" ``` **1B. Implement Content-Security-Policy (CSP)** `Security` - **Impact:** XSS defense-in-depth - **Problem:** CSP is missing. Site signals indicate user-generated content (textarea, upload link), making XSS a higher risk (Priority 1 per rubric). - **Solution:** Deploy a strict CSP using nonces or hashes rather than a flat allowlist: ```apache Header always set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';" ``` Ensure your server injects the nonce into `