# Audit Report: lootsa
**Website:** https://lootsa.ee/
**Date:** 17.08.2026
**Audit Coverage:** 100% — all sources returned data
**Confidence:** high
**Pages Audited (1 of 1):**
- https://lootsa.ee/
## Summary of results
**Overall Score:** 73 / 100
**Status:** 🟡 **Needs Improvement**
PSI mobile performance is excellent at 97 with LCP 2.0 s, but security headers score 0/100 and W3C validation has 15 errors. Two serious accessibility violations (link names, contrast) impact usability despite a 96 PSI accessibility score. The site signals indicate user-generated content (textarea, upload), elevating CSP to Priority 1. Mobile FCP is 1.97 s, slightly above the 1.8 s threshold, partly due to the hero image being lazy-loaded. Confidence is high as all audit tools returned complete data.
### Per-page scores
🟡 **Needs Improvement** · https://lootsa.ee/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 73 | 97 | 96 | 100 | 92 | 0 |
## PageSpeed Insights — Mobile vs Desktop
_Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._
| Strategy | Performance (M / D) | LCP (M / D) | CLS (M / D) |
| --- | --- | --- | --- |
| Mobile vs Desktop | **97** / 100 | **1.97 s** / 641 ms | 0.000 / **0.028** |
## Optimization Checklist
**4 of 6 passing** — 4 pass · 1 warn · 1 fail · 1 n/a
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | **Pass** | All non-hero raster images use loading="lazy". |
| Hero image eagerly loaded | **Fail** | Hero image has loading="lazy", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading="eager" (or omit loading) and add fetchpriority="high". |
| Hero is a real
(not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / ) | **Warn** | Only 23/30 raster images use srcset or (77%). |
| Reasonable number of image sizes | **Pass** | 25 distinct srcset widths. |
| JS scripts not blocking in | **Pass** | No render-blocking scripts in . |
## Fixes
### Priority 1: Critical
*Immediate action — impacts user experience, search rankings, or site safety.*
**1A. Add baseline security headers (HSTS, X-Frame-Options, X-Content-Type-Options)** `Security`
- **Impact:** Transport security, clickjacking, MIME sniffing
- **Problem:** Security Headers grade is 0/100; HSTS, X-Frame-Options, and X-Content-Type-Options are missing.
- **Solution:**
Add these headers to your server configuration (e.g., Apache .htaccess or Nginx config):
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
Header always set X-Frame-Options "SAMEORIGIN"
Header always set X-Content-Type-Options "nosniff"
```
**1B. Implement Content-Security-Policy (CSP)** `Security`
- **Impact:** XSS defense-in-depth
- **Problem:** CSP is missing. Site signals indicate user-generated content (textarea, upload link), making XSS a higher risk (Priority 1 per rubric).
- **Solution:**
Deploy a strict CSP using nonces or hashes rather than a flat allowlist:
```apache
Header always set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';"
```
Ensure your server injects the nonce into `