# Audit Report: Viga 401 - Error 401 | Veebimajutus.ee **Website:** https://php85.gotoand.dev/larsen **Date:** 2026-06-30 **Overall Score:** 45 / 100 **Status:** ๐ŸŸ  **Poor** **Confidence:** high **Audit Coverage:** 100% โ€” all sources returned data ## Summary PSI mobile 94 indicates excellent code performance, but the HTTP 401 status blocks public access, creating a critical functional failure. Security headers are completely missing (0/100), and accessibility has a serious contrast violation. The site appears to be a staging environment given the 401 challenge and dev subdomain, but for production readiness, these must be fixed. ## PageSpeed Insights โ€” Mobile vs Desktop _Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._ | Strategy | Performance (M / D) | LCP (M / D) | CLS (M / D) | | --- | --- | --- | --- | | Mobile vs Desktop | **94** / 100 | **2.44 s** / 683 ms | **0.002** / 0.000 | ## Optimization Checklist **1 of 3 passing** โ€” 1 pass ยท 1 warn ยท 1 fail ยท 4 n/a | Item | Status | Detail | | --- | --- | --- | | Page caching plugin / CDN active | **Fail** | No WordPress cache plugin marker or CDN edge cache detected on the document response. | | Images lazy-loaded | **Pass** | All raster images use loading="lazy". | | Hero image eagerly loaded | **Warn** | Hero image has no explicit loading or fetchpriority (inferred from DOM order/size โ€” Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP. | | Hero is a real (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. | | Responsive images (srcset / ) | N/A | Only 1 raster image on the page โ€” responsive-image rule does not apply. | | Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. | | JS scripts not blocking in | N/A | No external scripts on the page. | ## Fixes ### Priority 1: Critical *Immediate action โ€” impacts user experience, search rankings, or site safety.* **1A. Resolve HTTP 401 Unauthorized Status** - **Impact:** Site Accessibility, SEO - **Problem:** The server returns a 401 status with Basic Auth challenge (www-authenticate: Basic), blocking public access and failing the PSI http-status-code audit. - **Solution:** If this is a public site, remove server-side authentication (Basic Auth) from the web server config (e.g., `.htaccess` or Nginx config). If it must remain private, ensure the URL is not indexed and provide a public landing page. **1B. Implement Baseline Security Headers** - **Impact:** Transport Security, Clickjacking, MIME Sniffing - **Problem:** Security Headers score is 0/100; HSTS, X-Frame-Options, and X-Content-Type-Options are missing. - **Solution:** Add the following headers to the server response: ```apache Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" Header always set X-Frame-Options "SAMEORIGIN" Header always set X-Content-Type-Options "nosniff" ``` ### Priority 2: Important *Essential for compliance, user reach, and search visibility.* **2A. Fix Accessibility Violations (Contrast & Landmarks)** - **Impact:** WCAG 1.4.3, 1.3.1, 2.4.1 - **Problem:** axe-core reports 1 serious color-contrast violation and missing main landmark; W3C shows 3 h1 elements. - **Solution:** - Increase contrast on `.navbar-nav` links to โ‰ฅ4.5:1. - Wrap main content in `
` and navigation in `