# Audit Report: Lõõtsa Ärikvartal
**Website:** https://lootsa.ee/
**Date:** 24.08.2026
**Audit Coverage:** 100% — all sources returned data
**Confidence:** high
**Pages Audited (1 of 1):**
- https://lootsa.ee/
## Summary of results
**Overall Score:** 78 / 100
**Status:** 🟡 **Needs Improvement**
Performance is excellent (PSI Mobile 94, LCP 2.3 s, TTFB 6 ms), which anchors the score high. However, Security Headers are completely missing (0/100) and the site has User-Generated Content (textarea/upload), creating a high-risk XSS surface that demands Priority 1 remediation. Accessibility has a critical axe violation (button-name) and serious issues (contrast, link-name) that lower the score despite a 91 PSI accessibility rating. W3C validation shows 15 errors, primarily invalid script types and hidden input attributes, indicating technical debt. Missing meta descriptions and Open Graph tags further reduce SEO readiness.
### Per-page scores
🟡 **Needs Improvement** · https://lootsa.ee/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 78 | 94 | 91 | 100 | 92 | 0 |
## PageSpeed Insights — Mobile vs Desktop
_Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._
| Strategy | Performance (M / D) | LCP (M / D) | CLS (M / D) |
| --- | --- | --- | --- |
| Mobile vs Desktop | **94** / 100 | **2.29 s** / 684 ms | 0.000 / **0.028** |
## Optimization Checklist
**5 of 6 passing** — 5 pass · 0 warn · 1 fail · 1 n/a
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | **Pass** | All non-hero raster images use loading="lazy". |
| Hero image eagerly loaded | **Fail** | Hero image has loading="lazy", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading="eager" (or omit loading) and add fetchpriority="high". |
| Hero is a real
(not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / ) | **Pass** | 36/43 raster images use srcset or (84%). |
| Reasonable number of image sizes | **Pass** | 33 distinct srcset widths. |
| JS scripts not blocking in | **Pass** | No render-blocking scripts in . |
## Fixes
### Priority 1: Critical
*Immediate action — impacts user experience, search rankings, or site safety.*
**1A. Implement HSTS and Content Security Policy (CSP)** `Security`
- **Impact:** Transport security, XSS mitigation
- **Problem:** Security Headers grade is 0/100; HSTS and CSP are missing. Site signals indicate User-Generated Content (textarea, upload link), making XSS a Priority 1 risk per the rubric.
- **Solution:**
Add the following headers to your server configuration (e.g., Apache/Nginx):
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
Header always set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';"
Header always set X-Content-Type-Options "nosniff"
Header always set X-Frame-Options "SAMEORIGIN"
```
**1B. Fix critical button and link accessibility issues** `Accessibility`
- **Impact:** WCAG 2.1 A compliance, screen reader usability
- **Problem:** axe-core reports 1 critical violation (button-name) and 2 serious violations (color-contrast, link-name). Buttons lack discernible text and links in the gallery slider are unnamed.
- **Solution:**
- Add `aria-label` or visible text to all buttons (e.g., `