# Audit Report: Perfectly formed web development team - gotoAndPlay **Website:** https://play.ee/ **Date:** 2026-07-15 **Overall Score:** 75 / 100 **Status:** ๐ŸŸก **Needs Improvement** **Confidence:** high **Audit Coverage:** 100% โ€” all sources returned data **Pages Audited (7 of 7):** - https://play.ee/ - https://play.ee/web-development-case-studies/ - https://play.ee/software-development-work-index/ - https://play.ee/wordpress-support-service/ - https://play.ee/web-development-in-estonia/ - https://play.ee/software-development-in-estonia/ - https://play.ee/website-development-contact/ ## Summary Site overall 75 is the mean of 7 pages. Scores range 72 (https://play.ee/web-development-in-estonia/) โ†’ 78 (https://play.ee/wordpress-support-service/). Weakest page: PSI mobile 93 (desktop 100) shows strong performance, but LCP 2.6 s and FCP 1.99 s are in warning zones. Security headers score 20/100 is a major drag โ€” HTTP does not redirect to HTTPS, HSTS missing, CSP weak. Accessibility has 1 serious color-contrast violation affecting 21+ nodes plus missing main landmark. W3C validator reports 7 errors with parser recovery failure at line 100. Image dimensions missing on 69 images is a CLS risk despite current 0.000 CLS score. ## Per-Page Scores | Page | Score | Status | Confidence | | --- | --- | --- | --- | | https://play.ee/ | 78 | ๐ŸŸก **Needs Improvement** | high | | https://play.ee/web-development-case-studies/ | 76 | ๐ŸŸก **Needs Improvement** | high | | https://play.ee/software-development-work-index/ | 74 | ๐ŸŸก **Needs Improvement** | high | | https://play.ee/wordpress-support-service/ | 78 | ๐ŸŸก **Needs Improvement** | high | | https://play.ee/web-development-in-estonia/ | 72 | ๐ŸŸก **Needs Improvement** | high | | https://play.ee/software-development-in-estonia/ | 77 | ๐ŸŸก **Needs Improvement** | high | | https://play.ee/website-development-contact/ | 72 | ๐ŸŸก **Needs Improvement** | high | ## PageSpeed Insights โ€” Mobile vs Desktop _Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._ | URL | Performance (M / D) | LCP (M / D) | CLS (M / D) | | --- | --- | --- | --- | | https://play.ee/ | **95** / 100 | **2.51 s** / 608 ms | 0.002 / **0.008** | | https://play.ee/web-development-case-studies/ | **97** / 100 | **2.10 s** / 575 ms | **0.003** / 0.003 | | https://play.ee/software-development-work-index/ | **96** / 100 | **2.33 s** / 557 ms | **0.041** / 0.003 | | https://play.ee/wordpress-support-service/ | **97** / 100 | **2.33 s** / 546 ms | **0.017** / 0.003 | | https://play.ee/web-development-in-estonia/ | **93** / 100 | **2.64 s** / 532 ms | 0.000 / **0.005** | | https://play.ee/software-development-in-estonia/ | **96** / 100 | **2.48 s** / 574 ms | 0.003 / **0.004** | | https://play.ee/website-development-contact/ | **93** / 94 | **2.56 s** / 763 ms | 0.000 / **0.003** | ## Optimization Checklist **2 of 2 passing** โ€” 2 pass ยท 0 warn ยท 0 fail ยท 5 n/a | Item | Status | Detail | | --- | --- | --- | | Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) | | Images lazy-loaded | N/A | No raster elements found (39 SVGs, 13 placeholders excluded). | | Hero image eagerly loaded | N/A | No raster elements found (39 SVGs, 13 placeholders excluded). | | Hero is a real (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. | | Responsive images (srcset / ) | N/A | Only 0 raster images on the page (39 SVGs, 13 placeholders excluded) โ€” responsive-image rule does not apply. | | Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. | | JS scripts not blocking in | **Pass** | No render-blocking scripts in . | ## Fixes ### Priority 1: Critical *Immediate action โ€” impacts user experience, search rankings, or site safety.* **1A. Force HTTPS Redirect and Add HSTS** - **Impact:** Security, Transport Layer - **Problem:** Security Headers report shows 'http://play.ee/ does not redirect to HTTPS' and 'strict-transport-security missing'. - **Solution:** Configure the web server to redirect all HTTP traffic to HTTPS (301) and send the HSTS header: ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" ``` **1B. Enforce HTTPS and add HSTS** - **Impact:** Security, Transport Layer - **Problem:** Security Headers tool reports HTTP does not redirect to HTTPS and HSTS is missing (Score 20/100). - **Solution:** Configure server to redirect all HTTP traffic to HTTPS and send HSTS header: ```apache Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1C. Enforce HTTPS redirect and add HSTS** - **Impact:** Security, Trust, SEO - **Problem:** HTTP does not redirect to HTTPS and HSTS is missing (Security Headers grade 20/100). - **Solution:** Configure server to redirect all HTTP traffic to HTTPS immediately. Add HSTS header: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload` **1D. Fix W3C HTML Validation Errors** - **Impact:** DOM Integrity, SEO, Rendering - **Problem:** 7 validation errors including parser recovery failure at line 100 (iframe in noscript in head). - **Solution:** Move `` out of `` or ensure it is valid HTML5. - Remove invalid `name` attribute from `` tags. - Ensure `` tag is not closed prematurely before content. **2B. Improve Accessibility Landmarks and Link Text** - **Impact:** WCAG 2.4.1, 1.3.1 - **Problem:** axe-core found 'landmark-unique' and 'region' violations; HTML Inventory notes missing 'main' landmark and 'skip-to-content' link. - **Solution:** - Add `
` to wrap primary content. - Add a skip link at the top: ``. - Replace vague 'read more' links with descriptive text or `aria-label`. **2C. Fix Accessibility Contrast and Landmarks** - **Impact:** WCAG 1.4.3, 1.3.1, 2.4.1 - **Problem:** Axe found 1 serious color-contrast violation and PSI failed `landmark-one-main` (missing `
` element). - **Solution:** - Increase contrast ratio on `.heading__main` and card text to โ‰ฅ4.5:1. - Wrap primary content in `
` tag. - Add a skip-to-content link at the top of the page. **2D. Resolve W3C HTML Validation Errors** - **Impact:** Maintainability, Rendering Consistency - **Problem:** 7 W3C errors including parser recovery failure at line 100 (bad iframe/noscript in head). - **Solution:** - Move `` out of `` (allowed in body only). - Remove invalid `name` attribute from `` tags. - Ensure `` tag is not duplicated. **2E. Fix Accessibility Violations** - **Impact:** WCAG Compliance, Usability - **Problem:** 1 serious color-contrast violation (h1, p span) and missing main landmark/skip link. - **Solution:** Increase contrast ratio for `.heading__main` and `p > span` to โ‰ฅ4.5:1. Add `
` element wrapping primary content. Add skip-to-content link at top of page. **2F. Add Explicit Image Dimensions** - **Impact:** CLS, Layout Stability - **Problem:** 53 images missing width/height attributes (HTML Inventory), risking layout shifts. - **Solution:** Add `width` and `height` attributes to all `` tags. Use CSS `aspect-ratio` if dimensions vary dynamically. **2G. Improve HTML Document Structure** - **Impact:** SEO, Screen Reader Navigation - **Problem:** HTML Inventory shows 2 `

` elements, missing `
` landmark, and no skip-to-content link. - **Solution:** - Ensure only one `

` exists per page. - Wrap primary content in `
`. - Add a skip link at the top: ``. **2H. Fix color-contrast violations on headings** - **Impact:** WCAG 1.4.3, accessibility - **Problem:** 21+ nodes fail color-contrast (serious axe violation) including .focus__heading > h1 and .capabilities__heading elements. - **Solution:** Increase contrast ratio to โ‰ฅ4.5:1 for text. Example: ```css .heading__main { color: #333333; } /* adjust to meet contrast */ ``` **2I. Add main landmark and skip-to-content link** - **Impact:** WCAG 1.3.1, 2.4.1, accessibility - **Problem:** Document missing main landmark and skip-to-content link โ€” 2 moderate axe violations. - **Solution:** Add skip link and main landmark: ```html
``` **2J. Strengthen Content Security Policy (CSP)** - **Impact:** XSS defense (User-generated content present) - **Problem:** CSP is weak (only `frame-ancestors` set). Site has a `