# Audit Report: Viga 401 - Error 401 | Veebimajutus.ee
**Website:** https://php85.gotoand.dev/larsen
**Date:** 2026-06-30
**Overall Score:** 45 / 100
**Status:** ๐ **Poor**
**Confidence:** high
**Audit Coverage:** 100% โ all sources returned data
## Summary
PSI mobile 94 indicates excellent code performance, but the HTTP 401 status blocks public access, creating a critical functional failure. Security headers are completely missing (0/100), and accessibility has a serious contrast violation. The site appears to be a staging environment given the 401 challenge and dev subdomain, but for production readiness, these must be fixed.
## PageSpeed Insights โ Mobile vs Desktop
_Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._
| Strategy | Performance (M / D) | LCP (M / D) | CLS (M / D) |
| --- | --- | --- | --- |
| Mobile vs Desktop | **94** / 100 | **2.44 s** / 683 ms | **0.002** / 0.000 |
## Optimization Checklist
**1 of 3 passing** โ 1 pass ยท 1 warn ยท 1 fail ยท 4 n/a
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | **Fail** | No WordPress cache plugin marker or CDN edge cache detected on the document response. |
| Images lazy-loaded | **Pass** | All raster images use loading="lazy". |
| Hero image eagerly loaded | **Warn** | Hero image has no explicit loading or fetchpriority (inferred from DOM order/size โ Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP. |
| Hero is a real (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / ) | N/A | Only 1 raster image on the page โ responsive-image rule does not apply. |
| Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in | N/A | No external scripts on the page. |
## Fixes
### Priority 1: Critical
*Immediate action โ impacts user experience, search rankings, or site safety.*
**1A. Resolve HTTP 401 Unauthorized Status**
- **Impact:** Site Accessibility, SEO
- **Problem:** The server returns a 401 status with Basic Auth challenge (www-authenticate: Basic), blocking public access and failing the PSI http-status-code audit.
- **Solution:**
If this is a public site, remove server-side authentication (Basic Auth) from the web server config (e.g., `.htaccess` or Nginx config). If it must remain private, ensure the URL is not indexed and provide a public landing page.
**1B. Implement Baseline Security Headers**
- **Impact:** Transport Security, Clickjacking, MIME Sniffing
- **Problem:** Security Headers score is 0/100; HSTS, X-Frame-Options, and X-Content-Type-Options are missing.
- **Solution:**
Add the following headers to the server response:
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
Header always set X-Frame-Options "SAMEORIGIN"
Header always set X-Content-Type-Options "nosniff"
```
### Priority 2: Important
*Essential for compliance, user reach, and search visibility.*
**2A. Fix Accessibility Violations (Contrast & Landmarks)**
- **Impact:** WCAG 1.4.3, 1.3.1, 2.4.1
- **Problem:** axe-core reports 1 serious color-contrast violation and missing main landmark; W3C shows 3 h1 elements.
- **Solution:**
- Increase contrast on `.navbar-nav` links to โฅ4.5:1.
- Wrap main content in `` and navigation in `