{"url":"https://lootsa.ee/","date":"2026-08-17","siteName":"lootsa","overall":73,"reasoning":"PSI mobile performance is excellent at 97 with LCP 2.0 s, but security headers score 0/100 and W3C validation has 15 errors. Two serious accessibility violations (link names, contrast) impact usability despite a 96 PSI accessibility score. The site signals indicate user-generated content (textarea, upload), elevating CSP to Priority 1. Mobile FCP is 1.97 s, slightly above the 1.8 s threshold, partly due to the hero image being lazy-loaded. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Add baseline security headers (HSTS, X-Frame-Options, X-Content-Type-Options)","impact":"Transport security, clickjacking, MIME sniffing","problem":"Security Headers grade is 0/100; HSTS, X-Frame-Options, and X-Content-Type-Options are missing.","solution":"Add these headers to your server configuration (e.g., Apache .htaccess or Nginx config):\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":1,"category":"Security","title":"Implement Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing. Site signals indicate user-generated content (textarea, upload link), making XSS a higher risk (Priority 1 per rubric).","solution":"Deploy a strict CSP using nonces or hashes rather than a flat allowlist:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\"\n```\nEnsure your server injects the nonce into `<script>` tags."},{"priority":1,"category":"Performance","title":"Fix hero image loading strategy","impact":"LCP, FCP","problem":"Hero image `lootsa_hero-320x180.jpg` has `loading=\"lazy\"`, which delays LCP (Mobile FCP 1.97 s).","solution":"Remove `loading=\"lazy\"` from the hero image and add `fetchpriority=\"high\"`:\n```html\n<img src=\"/wp-content/uploads/.../lootsa_hero-320x180.jpg\" fetchpriority=\"high\" alt=\"...\">\n```"},{"priority":1,"category":"Accessibility","title":"Add accessible names to gallery image links","impact":"WCAG 2.4.4 (Link Purpose)","problem":"Axe reports serious violations for 14+ gallery image links (`.gallery-slider__item > .image__link`) lacking discernible text.","solution":"Add `aria-label` or visible text to each link:\n```html\n<a href=\"...\" aria-label=\"View image 1 of gallery\">\n  <img src=\"...\" alt=\"...\">\n</a>\n```"},{"priority":2,"category":"Accessibility","title":"Fix color contrast on brand tags","impact":"WCAG 1.4.3 (Contrast)","problem":"Axe reports serious contrast violation on `.tag--brand` elements.","solution":"Increase contrast ratio to at least 4.5:1 for text against background. Suggest darkening text color or lightening background."},{"priority":2,"category":"SEO","title":"Add meta description and correct language tag","impact":"Search visibility, screen reader language detection","problem":"Meta description is missing; HTML `lang=\"en\"` but content is Estonian.","solution":"Add a unique meta description:\n```html\n<meta name=\"description\" content=\"Lõõtsa ärikvartal - äripinnad Tallinnas\">\n```\nChange HTML tag to:\n```html\n<html lang=\"et\">\n```"},{"priority":2,"category":"Best Practices","title":"Fix W3C validation errors (script types, hidden inputs)","impact":"Code quality, potential rendering issues","problem":"15 W3C errors including `script type=\"text/rocketlazyloadscript\"` with `defer` and `input type=\"hidden\"` with `autocomplete`.","solution":"Update WP Rocket settings or custom scripts to use valid MIME types (e.g., `application/javascript`) or remove `defer` from non-JS types. Remove `autocomplete` from hidden inputs."}],"coverage":{"pct":100,"missing":[]},"siteSummary":{"pagesAudited":1,"pagesAttempted":1,"urls":["https://lootsa.ee/"]},"psiSnapshot":{"rows":[{"pageUrl":null,"perfMobile":97,"perfDesktop":100,"lcpMobileMs":1969.5,"lcpDesktopMs":641,"clsMobile":0,"clsDesktop":0.028078718763271938}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket)","evidence":["HTML markers: WP Rocket","generator: WP Rocket 3.23.2.1"]},{"id":"lazyload","title":"Images lazy-loaded","status":"pass","detail":"All non-hero raster images use loading=\"lazy\".","evidence":[]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"fail","detail":"Hero image has loading=\"lazy\", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading=\"eager\" (or omit loading) and add fetchpriority=\"high\".","evidence":["hero: https://lootsa.ee/wp-content/uploads/2026/08/lootsa_hero-320x180.jpg","loading: lazy","fetchpriority: (not set)"]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"n/a","detail":"No CSS background-images detected on raster-image-eligible elements.","evidence":[]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"warn","detail":"Only 23/30 raster images use srcset or <picture> (77%).","evidence":["…a.ee/wp-content/themes/lootsa-arikvartal/inc/theme/img/lootsa4-plaan.jpg?v=58","…ee/wp-content/themes/lootsa-arikvartal/inc/theme/img/lootsa5-korrus1.jpg?v=58","…ee/wp-content/themes/lootsa-arikvartal/inc/theme/img/lootsa5-korrus2.jpg?v=58","…ee/wp-content/themes/lootsa-arikvartal/inc/theme/img/lootsa5-korrus3.jpg?v=58","…ee/wp-content/themes/lootsa-arikvartal/inc/theme/img/lootsa6-korrus1.jpg?v=58"]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"pass","detail":"25 distinct srcset widths.","evidence":["widths: 233, 276, 278, 300, 320, 360, 420, 465, 498, 551, 555, 640, 720, 768, 840, 996, 1003, 1024, 1080, 1360, 1536, 1600, 1920, 2048, 2560"]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"pass","detail":"No render-blocking scripts in <head>.","evidence":[]}],"summary":{"passed":4,"warned":1,"failed":1,"notApplicable":1},"priorities":[{"title":"Hero image eagerly loaded","severity":"high","detail":"Hero image has loading=\"lazy\", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading=\"eager\" (or omit loading) and add fetchpriority=\"high\"."},{"title":"Responsive images (srcset / <picture>)","severity":"medium","detail":"Only 23/30 raster images use srcset or <picture> (77%)."}]},"perPageOverall":[{"url":"https://lootsa.ee/","overall":73,"reasoning":"PSI mobile performance is excellent at 97 with LCP 2.0 s, but security headers score 0/100 and W3C validation has 15 errors. Two serious accessibility violations (link names, contrast) impact usability despite a 96 PSI accessibility score. The site signals indicate user-generated content (textarea, upload), elevating CSP to Priority 1. Mobile FCP is 1.97 s, slightly above the 1.8 s threshold, partly due to the hero image being lazy-loaded. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Add baseline security headers (HSTS, X-Frame-Options, X-Content-Type-Options)","impact":"Transport security, clickjacking, MIME sniffing","problem":"Security Headers grade is 0/100; HSTS, X-Frame-Options, and X-Content-Type-Options are missing.","solution":"Add these headers to your server configuration (e.g., Apache .htaccess or Nginx config):\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":1,"category":"Security","title":"Implement Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing. Site signals indicate user-generated content (textarea, upload link), making XSS a higher risk (Priority 1 per rubric).","solution":"Deploy a strict CSP using nonces or hashes rather than a flat allowlist:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\"\n```\nEnsure your server injects the nonce into `<script>` tags."},{"priority":1,"category":"Performance","title":"Fix hero image loading strategy","impact":"LCP, FCP","problem":"Hero image `lootsa_hero-320x180.jpg` has `loading=\"lazy\"`, which delays LCP (Mobile FCP 1.97 s).","solution":"Remove `loading=\"lazy\"` from the hero image and add `fetchpriority=\"high\"`:\n```html\n<img src=\"/wp-content/uploads/.../lootsa_hero-320x180.jpg\" fetchpriority=\"high\" alt=\"...\">\n```"},{"priority":1,"category":"Accessibility","title":"Add accessible names to gallery image links","impact":"WCAG 2.4.4 (Link Purpose)","problem":"Axe reports serious violations for 14+ gallery image links (`.gallery-slider__item > .image__link`) lacking discernible text.","solution":"Add `aria-label` or visible text to each link:\n```html\n<a href=\"...\" aria-label=\"View image 1 of gallery\">\n  <img src=\"...\" alt=\"...\">\n</a>\n```"},{"priority":2,"category":"Accessibility","title":"Fix color contrast on brand tags","impact":"WCAG 1.4.3 (Contrast)","problem":"Axe reports serious contrast violation on `.tag--brand` elements.","solution":"Increase contrast ratio to at least 4.5:1 for text against background. Suggest darkening text color or lightening background."},{"priority":2,"category":"SEO","title":"Add meta description and correct language tag","impact":"Search visibility, screen reader language detection","problem":"Meta description is missing; HTML `lang=\"en\"` but content is Estonian.","solution":"Add a unique meta description:\n```html\n<meta name=\"description\" content=\"Lõõtsa ärikvartal - äripinnad Tallinnas\">\n```\nChange HTML tag to:\n```html\n<html lang=\"et\">\n```"},{"priority":2,"category":"Best Practices","title":"Fix W3C validation errors (script types, hidden inputs)","impact":"Code quality, potential rendering issues","problem":"15 W3C errors including `script type=\"text/rocketlazyloadscript\"` with `defer` and `input type=\"hidden\"` with `autocomplete`.","solution":"Update WP Rocket settings or custom scripts to use valid MIME types (e.g., `application/javascript`) or remove `defer` from non-JS types. Remove `autocomplete` from hidden inputs."}],"perfScore":97,"a11yScore":96,"bestPracticesScore":100,"seoScore":92,"securityScore":0}]}