# Audit Report: Perfectly formed web development team - gotoAndPlay **Website:** https://play.ee/ **Date:** 22.07.2026 **Audit Coverage:** 100% — all sources returned data **Confidence:** high **Pages Audited (5 of 5):** - https://play.ee/ - https://play.ee/web-development-case-studies/ - https://play.ee/software-development-work-index/ - https://play.ee/wordpress-support-service/ - https://play.ee/web-development-in-estonia/ ## Summary of results **Overall Score:** 76 / 100 **Status:** 🟡 **Needs Improvement** Site overall 76 is the mean of 5 pages. Scores range 72 (https://play.ee/software-development-work-index/) → 82 (https://play.ee/). Weakest page: Mobile performance is strong (86) with excellent TTFB (5 ms) and TBT (0 ms), but CLS is high at 0.211 due to footer shifts. Security is the weakest area (20/100 grade) with a critical failure: HTTP does not redirect to HTTPS, plus missing HSTS and X-Content-Type-Options. Accessibility has a serious color-contrast violation and missing main landmark despite a 90 score. W3C validation shows 7 errors including parser recovery failure at line 100. Confidence is high as all audit tools returned complete data. ### Per-page scores 🟡 **Needs Improvement** · https://play.ee/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 82 | 97 | 100 | 100 | 92 | 20 | 🟡 **Needs Improvement** · https://play.ee/web-development-case-studies/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 74 | 95 | 90 | 96 | 100 | 20 | 🟡 **Needs Improvement** · https://play.ee/software-development-work-index/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 72 | 86 | 90 | 96 | 100 | 20 | 🟡 **Needs Improvement** · https://play.ee/wordpress-support-service/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 74 | 94 | 91 | 100 | 100 | 20 | 🟡 **Needs Improvement** · https://play.ee/web-development-in-estonia/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 78 | 96 | 94 | 100 | 100 | 20 | ## PageSpeed Insights — Mobile vs Desktop _Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._ | URL | Performance (M / D) | LCP (M / D) | CLS (M / D) | | --- | --- | --- | --- | | https://play.ee/ | **97** / 100 | **2.33 s** / 600 ms | 0.002 / **0.008** | | https://play.ee/web-development-case-studies/ | **95** / 100 | **2.57 s** / 574 ms | **0.003** / 0.003 | | https://play.ee/software-development-work-index/ | **86** / 100 | **2.33 s** / 534 ms | **0.211** / 0.003 | | https://play.ee/wordpress-support-service/ | **94** / 100 | **2.59 s** / 588 ms | 0.000 / **0.003** | | https://play.ee/web-development-in-estonia/ | **96** / 100 | **2.48 s** / 574 ms | 0.002 / **0.006** | ## Optimization Checklist **2 of 2 passing** — 2 pass · 0 warn · 0 fail · 5 n/a | Item | Status | Detail | | --- | --- | --- | | Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) | | Images lazy-loaded | N/A | No raster elements found (39 SVGs, 13 placeholders excluded). | | Hero image eagerly loaded | N/A | No raster elements found (39 SVGs, 13 placeholders excluded). | | Hero is a real (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. | | Responsive images (srcset / ) | N/A | Only 0 raster images on the page (39 SVGs, 13 placeholders excluded) — responsive-image rule does not apply. | | Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. | | JS scripts not blocking in | **Pass** | No render-blocking scripts in . | ## Fixes ### Priority 1: Critical *Immediate action — impacts user experience, search rankings, or site safety.* **1A. Enforce HTTPS and add HSTS** `Security` - **Impact:** Transport security, browser warnings - **Problem:** Security Headers tool reports HTTP does not redirect to HTTPS and HSTS is missing (Grade 20/100). - **Solution:** Configure server to redirect all HTTP traffic to HTTPS and send: ``` Strict-Transport-Security: max-age=63072000; includeSubDomains; preload ``` **1B. Add X-Content-Type-Options** `Security` - **Impact:** MIME sniffing protection - **Problem:** X-Content-Type-Options header is missing, leaving the site vulnerable to MIME-type sniffing attacks. - **Solution:** Add the following header to all responses: ``` X-Content-Type-Options: nosniff ``` **1C. Enforce HTTPS redirect and add HSTS** `Security` - **Impact:** Transport security, data integrity - **Problem:** HTTP does not redirect to HTTPS and HSTS is missing (Security Headers grade 20/100). - **Solution:** Configure server to redirect all HTTP traffic to HTTPS immediately. Add HSTS header: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload` **1D. Force HTTPS redirect on HTTP requests** `Security` - **Impact:** Transport security, data integrity - **Problem:** Audit detected that http://play.ee/software-development-work-index/ does not redirect to HTTPS, leaving users vulnerable to downgrade attacks. - **Solution:** Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to the HTTPS version: ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1E. Add HSTS and X-Content-Type-Options headers** `Security` - **Impact:** Transport security, MIME sniffing - **Problem:** Security Headers grade is 20/100; HSTS and X-Content-Type-Options are missing despite HTTPS being used. - **Solution:** Add the following headers to the server response: ```apache Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" Header always set X-Content-Type-Options "nosniff" ``` **1F. Fix W3C HTML Validation Errors** `SEO` - **Impact:** Document structure, rendering reliability - **Problem:** 7 validation errors including parser recovery failure at line 100 (iframe/noscript in head, stray end tags). - **Solution:** Move `` out of the `` section. Ensure `` tags are placed correctly within `` and close `` before `` starts. ### Priority 2: Important *Essential for compliance, user reach, and search visibility.* **2A. Fix HTML Validation Errors** `SEO` - **Impact:** Parser recovery, SEO rendering - **Problem:** W3C Validator reports 7 errors including 'Bad start tag in iframe in noscript in head' and parser recovery failure at line 100. - **Solution:** Move `` out of the `` section. Ensure `` tags do not use the `name` attribute where `property` is required (e.g., Open Graph). **2B. Add Skip Link and Main Landmark** `Accessibility` - **Impact:** Keyboard navigation, screen reader flow - **Problem:** HTML Inventory shows missing `main` landmark and no skip-to-content link; axe reports `region` and `landmark-unique` violations. - **Solution:** Add a skip link at the top of the ``: ```html ``` Wrap primary content in `
`. **2C. Fix color contrast and add main landmark** `Accessibility` - **Impact:** WCAG 1.4.3, 1.3.1 - **Problem:** axe-core found 1 serious color-contrast violation; HTML Inventory shows missing main landmark. - **Solution:** - Increase contrast ratio to ≥4.5:1 for `.heading__main` and card text. - Wrap primary content in `
` tag. - Add skip-to-content link at top of page. **2D. Resolve W3C HTML validation errors** `Best Practices` - **Impact:** Rendering stability, SEO - **Problem:** 7 W3C errors including parser recovery failure at line 100 and bad iframe/noscript in head. - **Solution:** - Move `