# Audit Report: Perfectly formed web development team - gotoAndPlay
**Website:** https://play.ee/
**Date:** 2026-07-15
**Overall Score:** 78 / 100
**Status:** 🟡 **Needs Improvement**
**Confidence:** high
**Audit Coverage:** 100% — all sources returned data
## Summary
Performance is excellent (94 mobile) with clean Core Web Vitals, but security configuration is critically weak (20/100 headers, HTTP does not redirect to HTTPS). This security gap significantly drags the SEO/Security budget despite strong accessibility (2 moderate violations) and light page weight. Image assets lack explicit dimensions (52 images), creating CLS risk despite the 0.000 lab score. HTML validation errors (7 found) indicate structural issues in the head/body that need correction.
## PageSpeed Insights — Mobile vs Desktop
_Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._
| Strategy | Performance (M / D) | LCP (M / D) | CLS (M / D) |
| --- | --- | --- | --- |
| Mobile vs Desktop | **94** / 100 | **2.52 s** / 572 ms | 0.000 / **0.008** |
## Optimization Checklist
**2 of 2 passing** — 2 pass · 0 warn · 0 fail · 5 n/a
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | N/A | No raster elements found (39 SVGs, 13 placeholders excluded). |
| Hero image eagerly loaded | N/A | No raster elements found (39 SVGs, 13 placeholders excluded). |
| Hero is a real (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / ) | N/A | Only 0 raster images on the page (39 SVGs, 13 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in | **Pass** | No render-blocking scripts in . |
## Fixes
### Priority 1: Critical
*Immediate action — impacts user experience, search rankings, or site safety.*
**1A. Force HTTPS redirect for all HTTP traffic**
- **Impact:** Security, Data Integrity
- **Problem:** Security Headers audit shows http://play.ee/ does not redirect to HTTPS, allowing unencrypted connections.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests:
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1B. Add HSTS and X-Content-Type-Options headers**
- **Impact:** Transport Security, MIME Sniffing
- **Problem:** HSTS and X-Content-Type-Options are missing; Security Headers grade is 20/100.
- **Solution:**
Add these headers to the server response:
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
Header always set X-Content-Type-Options "nosniff"
```
### Priority 2: Important
*Essential for compliance, user reach, and search visibility.*
**2A. Add explicit width and height to all images**
- **Impact:** CLS, Layout Stability
- **Problem:** HTML Inventory shows 52 images without width/height attributes, risking layout shifts.
- **Solution:**
Ensure every `` tag includes intrinsic dimensions:
```html
```
**2B. Fix W3C HTML validation errors**
- **Impact:** SEO, Rendering Consistency
- **Problem:** W3C Validator reports 7 errors including malformed `