# Audit Report: Lõõtsa Ärikvartal **Website:** https://lootsa.ee/ **Date:** 24.08.2026 **Audit Coverage:** 100% — all sources returned data **Confidence:** high **Pages Audited (1 of 1):** - https://lootsa.ee/ ## Summary of results **Overall Score:** 78 / 100 **Status:** 🟡 **Needs Improvement** Performance is excellent (PSI Mobile 94, LCP 2.3 s, TTFB 6 ms), which anchors the score high. However, Security Headers are completely missing (0/100) and the site has User-Generated Content (textarea/upload), creating a high-risk XSS surface that demands Priority 1 remediation. Accessibility has a critical axe violation (button-name) and serious issues (contrast, link-name) that lower the score despite a 91 PSI accessibility rating. W3C validation shows 15 errors, primarily invalid script types and hidden input attributes, indicating technical debt. Missing meta descriptions and Open Graph tags further reduce SEO readiness. ### Per-page scores 🟡 **Needs Improvement** · https://lootsa.ee/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 78 | 94 | 91 | 100 | 92 | 0 | ## PageSpeed Insights — Mobile vs Desktop _Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._ | Strategy | Performance (M / D) | LCP (M / D) | CLS (M / D) | | --- | --- | --- | --- | | Mobile vs Desktop | **94** / 100 | **2.29 s** / 684 ms | 0.000 / **0.028** | ## Optimization Checklist **5 of 6 passing** — 5 pass · 0 warn · 1 fail · 1 n/a | Item | Status | Detail | | --- | --- | --- | | Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) | | Images lazy-loaded | **Pass** | All non-hero raster images use loading="lazy". | | Hero image eagerly loaded | **Fail** | Hero image has loading="lazy", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading="eager" (or omit loading) and add fetchpriority="high". | | Hero is a real (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. | | Responsive images (srcset / ) | **Pass** | 36/43 raster images use srcset or (84%). | | Reasonable number of image sizes | **Pass** | 33 distinct srcset widths. | | JS scripts not blocking in | **Pass** | No render-blocking scripts in . | ## Fixes ### Priority 1: Critical *Immediate action — impacts user experience, search rankings, or site safety.* **1A. Implement HSTS and Content Security Policy (CSP)** `Security` - **Impact:** Transport security, XSS mitigation - **Problem:** Security Headers grade is 0/100; HSTS and CSP are missing. Site signals indicate User-Generated Content (textarea, upload link), making XSS a Priority 1 risk per the rubric. - **Solution:** Add the following headers to your server configuration (e.g., Apache/Nginx): ```apache Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" Header always set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';" Header always set X-Content-Type-Options "nosniff" Header always set X-Frame-Options "SAMEORIGIN" ``` **1B. Fix critical button and link accessibility issues** `Accessibility` - **Impact:** WCAG 2.1 A compliance, screen reader usability - **Problem:** axe-core reports 1 critical violation (button-name) and 2 serious violations (color-contrast, link-name). Buttons lack discernible text and links in the gallery slider are unnamed. - **Solution:** - Add `aria-label` or visible text to all buttons (e.g., `