# Audit Report: Perfectly formed web development team - gotoAndPlay
**Website:** https://play.ee/
**Date:** 22.07.2026
**Audit Coverage:** 100% — all sources returned data
**Confidence:** high
**Pages Audited (5 of 5):**
- https://play.ee/
- https://play.ee/web-development-case-studies/
- https://play.ee/software-development-work-index/
- https://play.ee/wordpress-support-service/
- https://play.ee/web-development-in-estonia/
## Summary of results
**Overall Score:** 76 / 100
**Status:** 🟡 **Needs Improvement**
Site overall 76 is the mean of 5 pages. Scores range 72 (https://play.ee/software-development-work-index/) → 82 (https://play.ee/). Weakest page: Mobile performance is strong (86) with excellent TTFB (5 ms) and TBT (0 ms), but CLS is high at 0.211 due to footer shifts. Security is the weakest area (20/100 grade) with a critical failure: HTTP does not redirect to HTTPS, plus missing HSTS and X-Content-Type-Options. Accessibility has a serious color-contrast violation and missing main landmark despite a 90 score. W3C validation shows 7 errors including parser recovery failure at line 100. Confidence is high as all audit tools returned complete data.
### Per-page scores
🟡 **Needs Improvement** · https://play.ee/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 82 | 97 | 100 | 100 | 92 | 20 |
🟡 **Needs Improvement** · https://play.ee/web-development-case-studies/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 74 | 95 | 90 | 96 | 100 | 20 |
🟡 **Needs Improvement** · https://play.ee/software-development-work-index/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 72 | 86 | 90 | 96 | 100 | 20 |
🟡 **Needs Improvement** · https://play.ee/wordpress-support-service/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 74 | 94 | 91 | 100 | 100 | 20 |
🟡 **Needs Improvement** · https://play.ee/web-development-in-estonia/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 78 | 96 | 94 | 100 | 100 | 20 |
## PageSpeed Insights — Mobile vs Desktop
_Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._
| URL | Performance (M / D) | LCP (M / D) | CLS (M / D) |
| --- | --- | --- | --- |
| https://play.ee/ | **97** / 100 | **2.33 s** / 600 ms | 0.002 / **0.008** |
| https://play.ee/web-development-case-studies/ | **95** / 100 | **2.57 s** / 574 ms | **0.003** / 0.003 |
| https://play.ee/software-development-work-index/ | **86** / 100 | **2.33 s** / 534 ms | **0.211** / 0.003 |
| https://play.ee/wordpress-support-service/ | **94** / 100 | **2.59 s** / 588 ms | 0.000 / **0.003** |
| https://play.ee/web-development-in-estonia/ | **96** / 100 | **2.48 s** / 574 ms | 0.002 / **0.006** |
## Optimization Checklist
**2 of 2 passing** — 2 pass · 0 warn · 0 fail · 5 n/a
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | N/A | No raster elements found (39 SVGs, 13 placeholders excluded). |
| Hero image eagerly loaded | N/A | No raster elements found (39 SVGs, 13 placeholders excluded). |
| Hero is a real (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / ) | N/A | Only 0 raster images on the page (39 SVGs, 13 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in | **Pass** | No render-blocking scripts in . |
## Fixes
### Priority 1: Critical
*Immediate action — impacts user experience, search rankings, or site safety.*
**1A. Enforce HTTPS and add HSTS** `Security`
- **Impact:** Transport security, browser warnings
- **Problem:** Security Headers tool reports HTTP does not redirect to HTTPS and HSTS is missing (Grade 20/100).
- **Solution:**
Configure server to redirect all HTTP traffic to HTTPS and send:
```
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
```
**1B. Add X-Content-Type-Options** `Security`
- **Impact:** MIME sniffing protection
- **Problem:** X-Content-Type-Options header is missing, leaving the site vulnerable to MIME-type sniffing attacks.
- **Solution:**
Add the following header to all responses:
```
X-Content-Type-Options: nosniff
```
**1C. Enforce HTTPS redirect and add HSTS** `Security`
- **Impact:** Transport security, data integrity
- **Problem:** HTTP does not redirect to HTTPS and HSTS is missing (Security Headers grade 20/100).
- **Solution:**
Configure server to redirect all HTTP traffic to HTTPS immediately.
Add HSTS header:
`Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`
**1D. Force HTTPS redirect on HTTP requests** `Security`
- **Impact:** Transport security, data integrity
- **Problem:** Audit detected that http://play.ee/software-development-work-index/ does not redirect to HTTPS, leaving users vulnerable to downgrade attacks.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to the HTTPS version:
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1E. Add HSTS and X-Content-Type-Options headers** `Security`
- **Impact:** Transport security, MIME sniffing
- **Problem:** Security Headers grade is 20/100; HSTS and X-Content-Type-Options are missing despite HTTPS being used.
- **Solution:**
Add the following headers to the server response:
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
Header always set X-Content-Type-Options "nosniff"
```
**1F. Fix W3C HTML Validation Errors** `SEO`
- **Impact:** Document structure, rendering reliability
- **Problem:** 7 validation errors including parser recovery failure at line 100 (iframe/noscript in head, stray end tags).
- **Solution:**
Move `` out of the `` section. Ensure `` tags are placed correctly within `` and close `` before `` starts.
### Priority 2: Important
*Essential for compliance, user reach, and search visibility.*
**2A. Fix HTML Validation Errors** `SEO`
- **Impact:** Parser recovery, SEO rendering
- **Problem:** W3C Validator reports 7 errors including 'Bad start tag in iframe in noscript in head' and parser recovery failure at line 100.
- **Solution:**
Move `` out of the `` section. Ensure `` tags do not use the `name` attribute where `property` is required (e.g., Open Graph).
**2B. Add Skip Link and Main Landmark** `Accessibility`
- **Impact:** Keyboard navigation, screen reader flow
- **Problem:** HTML Inventory shows missing `main` landmark and no skip-to-content link; axe reports `region` and `landmark-unique` violations.
- **Solution:**
Add a skip link at the top of the ``:
```html
Skip to content
```
Wrap primary content in ``.
**2C. Fix color contrast and add main landmark** `Accessibility`
- **Impact:** WCAG 1.4.3, 1.3.1
- **Problem:** axe-core found 1 serious color-contrast violation; HTML Inventory shows missing main landmark.
- **Solution:**
- Increase contrast ratio to ≥4.5:1 for `.heading__main` and card text.
- Wrap primary content in `` tag.
- Add skip-to-content link at top of page.
**2D. Resolve W3C HTML validation errors** `Best Practices`
- **Impact:** Rendering stability, SEO
- **Problem:** 7 W3C errors including parser recovery failure at line 100 and bad iframe/noscript in head.
- **Solution:**
- Move `` and `` tags.
- Ensure `` tags use valid attributes (`property` or `itemprop`).
**2E. Add HSTS and X-Content-Type-Options headers** `Security`
- **Impact:** Clickjacking protection, MIME sniffing prevention
- **Problem:** Security Headers grade is 20/100; HSTS and X-Content-Type-Options are missing despite HTTPS being available.
- **Solution:**
Add these headers to the server configuration:
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
Header always set X-Content-Type-Options "nosniff"
```
**2F. Fix Cumulative Layout Shift (CLS) on footer** `Performance`
- **Impact:** CLS score (currently 0.211), User Experience
- **Problem:** Mobile CLS is 0.211 (threshold 0.1); PSI identifies `footer.footer` as the primary shift source.
- **Solution:**
Reserve space for dynamic content in the footer using CSS min-height or explicit dimensions. Ensure images/fonts load with `font-display: swap` and explicit width/height attributes.
**2G. Fix color contrast and link names** `Accessibility`
- **Impact:** WCAG 1.4.3, 2.4.4 compliance
- **Problem:** axe-core found 2 serious violations: color-contrast on multiple text nodes and link-name on logo grid links (no discernible text).
- **Solution:**
- Increase contrast on `.button--tertiary` and `.capabilities__heading` to meet 4.5:1 ratio.
- Add `aria-label` to logo links: ``.
**2H. Resolve HTML validation errors** `SEO`
- **Impact:** Parsing reliability, SEO crawlers
- **Problem:** W3C Validator reports 7 errors including 'Bad start tag in iframe in noscript in head' and parser recovery failure at line 107.
- **Solution:**
Move the GTM noscript iframe out of the `` or ensure it is properly nested. Remove stray `` and `` tags. Ensure `` tags in `` do not use invalid attributes like `name` where `property` is expected.
**2I. Fix Color Contrast Violations** `Accessibility`
- **Impact:** WCAG 1.4.3 compliance, readability
- **Problem:** axe-core reports 1 serious violation for color-contrast on multiple heading elements (e.g., `.focus__heading > h1`).
- **Solution:**
Increase contrast ratio to at least 4.5:1 for normal text. Adjust CSS for `.heading__main` and `.heading__small` classes to use darker text or lighter backgrounds.
**2J. Add Main Landmark and Skip Link** `Accessibility`
- **Impact:** Keyboard navigation, screen reader support
- **Problem:** HTML Inventory shows `main` landmark is missing and no skip-to-content link exists.
- **Solution:**
Wrap primary content in `` tag. Add a skip link at the top of the page:
```html
Skip to content
...
```
### Priority 3: Best Practice
*Recommended for long-term maintainability.*
**3A. Add Image Dimensions and Lazy Loading** `Performance`
- **Impact:** CLS, Initial Load
- **Problem:** 52 images lack explicit width/height attributes and 52 lack `loading="lazy"`, risking layout shifts despite current CLS score.
- **Solution:**
Add `width` and `height` attributes to all `` tags. Add `loading="lazy"` to images below the fold:
```html
```
**3B. Add explicit width/height to images** `Performance`
- **Impact:** CLS, Layout stability
- **Problem:** 56 images lack width/height attributes, risking layout shifts on load.
- **Solution:**
Add `width` and `height` attributes to all `` tags matching intrinsic dimensions.
Example: ``
**3C. Remove unused CSS and JavaScript** `Performance`
- **Impact:** FCP, TBT
- **Problem:** PSI findings estimate 32 KiB unused CSS and 23 KB unused JS.
- **Solution:**
- Purge unused CSS rules (WP Rocket or build tool).
- Remove or defer `jquery.bfe1bb19d13b3c17b682.min.js` if not required for core functionality.
**3D. Resolve W3C HTML validation errors** `SEO`
- **Impact:** Parser reliability, SEO crawling
- **Problem:** 7 W3C errors including `iframe` in `noscript` in `head` and parser recovery failure at line 100.
- **Solution:**
Move the Google Tag Manager `noscript` iframe out of the `` and into the `` immediately after the opening `` tag. Fix stray `` and `` tags.
**3E. Add explicit dimensions to images** `Performance`
- **Impact:** CLS prevention
- **Problem:** HTML Inventory shows 31 images without width/height attributes, risking layout shifts despite current CLS score of 0.000.
- **Solution:**
Add `width` and `height` attributes to all `` tags matching their intrinsic aspect ratio:
```html
```