{"url":"https://play.ee/","date":"2026-07-22","siteName":"Perfectly formed web development team - gotoAndPlay","overall":76,"reasoning":"Site overall 76 is the mean of 5 pages. Scores range 72 (https://play.ee/software-development-work-index/) → 82 (https://play.ee/). Weakest page: Mobile performance is strong (86) with excellent TTFB (5 ms) and TBT (0 ms), but CLS is high at 0.211 due to footer shifts. Security is the weakest area (20/100 grade) with a critical failure: HTTP does not redirect to HTTPS, plus missing HSTS and X-Content-Type-Options. Accessibility has a serious color-contrast violation and missing main landmark despite a 90 score. W3C validation shows 7 errors including parser recovery failure at line 100. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS and add HSTS","impact":"Transport security, browser warnings","problem":"Security Headers tool reports HTTP does not redirect to HTTPS and HSTS is missing (Grade 20/100).","solution":"Configure server to redirect all HTTP traffic to HTTPS and send:\n```\nStrict-Transport-Security: max-age=63072000; includeSubDomains; preload\n```"},{"priority":1,"category":"Security","title":"Add X-Content-Type-Options","impact":"MIME sniffing protection","problem":"X-Content-Type-Options header is missing, leaving the site vulnerable to MIME-type sniffing attacks.","solution":"Add the following header to all responses:\n```\nX-Content-Type-Options: nosniff\n```"},{"priority":1,"category":"Security","title":"Enforce HTTPS redirect and add HSTS","impact":"Transport security, data integrity","problem":"HTTP does not redirect to HTTPS and HSTS is missing (Security Headers grade 20/100).","solution":"Configure server to redirect all HTTP traffic to HTTPS immediately.\nAdd HSTS header:\n`Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`"},{"priority":1,"category":"Security","title":"Force HTTPS redirect on HTTP requests","impact":"Transport security, data integrity","problem":"Audit detected that http://play.ee/software-development-work-index/ does not redirect to HTTPS, leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to the HTTPS version:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Security","title":"Add HSTS and X-Content-Type-Options headers","impact":"Transport security, MIME sniffing","problem":"Security Headers grade is 20/100; HSTS and X-Content-Type-Options are missing despite HTTPS being used.","solution":"Add the following headers to the server response:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":1,"category":"SEO","title":"Fix W3C HTML Validation Errors","impact":"Document structure, rendering reliability","problem":"7 validation errors including parser recovery failure at line 100 (iframe/noscript in head, stray end tags).","solution":"Move `<noscript><iframe>...</iframe></noscript>` out of the `<head>` section. Ensure `<meta>` tags are placed correctly within `<head>` and close `<head>` before `<body>` starts."},{"priority":2,"category":"SEO","title":"Fix HTML Validation Errors","impact":"Parser recovery, SEO rendering","problem":"W3C Validator reports 7 errors including 'Bad start tag in iframe in noscript in head' and parser recovery failure at line 100.","solution":"Move `<noscript><iframe>...</iframe></noscript>` out of the `<head>` section. Ensure `<meta>` tags do not use the `name` attribute where `property` is required (e.g., Open Graph)."},{"priority":2,"category":"Accessibility","title":"Add Skip Link and Main Landmark","impact":"Keyboard navigation, screen reader flow","problem":"HTML Inventory shows missing `main` landmark and no skip-to-content link; axe reports `region` and `landmark-unique` violations.","solution":"Add a skip link at the top of the `<body>`:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n```\nWrap primary content in `<main id=\"main-content\">`."},{"priority":2,"category":"Accessibility","title":"Fix color contrast and add main landmark","impact":"WCAG 1.4.3, 1.3.1","problem":"axe-core found 1 serious color-contrast violation; HTML Inventory shows missing main landmark.","solution":"- Increase contrast ratio to ≥4.5:1 for `.heading__main` and card text.\n- Wrap primary content in `<main>` tag.\n- Add skip-to-content link at top of page."},{"priority":2,"category":"Best Practices","title":"Resolve W3C HTML validation errors","impact":"Rendering stability, SEO","problem":"7 W3C errors including parser recovery failure at line 100 and bad iframe/noscript in head.","solution":"- Move `<noscript><iframe>` block out of `<head>`.\n- Fix stray `</noscript>` and `</head>` tags.\n- Ensure `<meta>` tags use valid attributes (`property` or `itemprop`)."},{"priority":2,"category":"Security","title":"Add HSTS and X-Content-Type-Options headers","impact":"Clickjacking protection, MIME sniffing prevention","problem":"Security Headers grade is 20/100; HSTS and X-Content-Type-Options are missing despite HTTPS being available.","solution":"Add these headers to the server configuration:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Performance","title":"Fix Cumulative Layout Shift (CLS) on footer","impact":"CLS score (currently 0.211), User Experience","problem":"Mobile CLS is 0.211 (threshold 0.1); PSI identifies `footer.footer` as the primary shift source.","solution":"Reserve space for dynamic content in the footer using CSS min-height or explicit dimensions. Ensure images/fonts load with `font-display: swap` and explicit width/height attributes."},{"priority":2,"category":"Accessibility","title":"Fix color contrast and link names","impact":"WCAG 1.4.3, 2.4.4 compliance","problem":"axe-core found 2 serious violations: color-contrast on multiple text nodes and link-name on logo grid links (no discernible text).","solution":"- Increase contrast on `.button--tertiary` and `.capabilities__heading` to meet 4.5:1 ratio.\n- Add `aria-label` to logo links: `<a href=\"\" aria-label=\"Partner Name\"><img ...></a>`."},{"priority":2,"category":"SEO","title":"Resolve HTML validation errors","impact":"Parsing reliability, SEO crawlers","problem":"W3C Validator reports 7 errors including 'Bad start tag in iframe in noscript in head' and parser recovery failure at line 107.","solution":"Move the GTM noscript iframe out of the `<head>` or ensure it is properly nested. Remove stray `</noscript>` and `</head>` tags. Ensure `<meta>` tags in `<head>` do not use invalid attributes like `name` where `property` is expected."},{"priority":2,"category":"Accessibility","title":"Fix Color Contrast Violations","impact":"WCAG 1.4.3 compliance, readability","problem":"axe-core reports 1 serious violation for color-contrast on multiple heading elements (e.g., `.focus__heading > h1`).","solution":"Increase contrast ratio to at least 4.5:1 for normal text. Adjust CSS for `.heading__main` and `.heading__small` classes to use darker text or lighter backgrounds."},{"priority":2,"category":"Accessibility","title":"Add Main Landmark and Skip Link","impact":"Keyboard navigation, screen reader support","problem":"HTML Inventory shows `main` landmark is missing and no skip-to-content link exists.","solution":"Wrap primary content in `<main>` tag. Add a skip link at the top of the page:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n<div id=\"main-content\">...</div>\n```"},{"priority":3,"category":"Performance","title":"Add Image Dimensions and Lazy Loading","impact":"CLS, Initial Load","problem":"52 images lack explicit width/height attributes and 52 lack `loading=\"lazy\"`, risking layout shifts despite current CLS score.","solution":"Add `width` and `height` attributes to all `<img>` tags. Add `loading=\"lazy\"` to images below the fold:\n```html\n<img src=\"...\" alt=\"...\" width=\"300\" height=\"200\" loading=\"lazy\">\n```"},{"priority":3,"category":"Performance","title":"Add explicit width/height to images","impact":"CLS, Layout stability","problem":"56 images lack width/height attributes, risking layout shifts on load.","solution":"Add `width` and `height` attributes to all `<img>` tags matching intrinsic dimensions.\nExample: `<img src=\"...\" width=\"300\" height=\"200\" alt=\"...\">`"},{"priority":3,"category":"Performance","title":"Remove unused CSS and JavaScript","impact":"FCP, TBT","problem":"PSI findings estimate 32 KiB unused CSS and 23 KB unused JS.","solution":"- Purge unused CSS rules (WP Rocket or build tool).\n- Remove or defer `jquery.bfe1bb19d13b3c17b682.min.js` if not required for core functionality."},{"priority":3,"category":"SEO","title":"Resolve W3C HTML validation errors","impact":"Parser reliability, SEO crawling","problem":"7 W3C errors including `iframe` in `noscript` in `head` and parser recovery failure at line 100.","solution":"Move the Google Tag Manager `noscript` iframe out of the `<head>` and into the `<body>` immediately after the opening `<body>` tag. Fix stray `</noscript>` and `</head>` tags."},{"priority":3,"category":"Performance","title":"Add explicit dimensions to images","impact":"CLS prevention","problem":"HTML Inventory shows 31 images without width/height attributes, risking layout shifts despite current CLS score of 0.000.","solution":"Add `width` and `height` attributes to all `<img>` tags matching their intrinsic aspect ratio:\n```html\n<img src=\"logo.svg\" alt=\"Logo\" width=\"200\" height=\"50\">\n```"}],"coverage":{"pct":100,"missing":[]},"siteSummary":{"pagesAudited":5,"pagesAttempted":5,"urls":["https://play.ee/","https://play.ee/web-development-case-studies/","https://play.ee/software-development-work-index/","https://play.ee/wordpress-support-service/","https://play.ee/web-development-in-estonia/"]},"psiSnapshot":{"rows":[{"pageUrl":"https://play.ee/","perfMobile":97,"perfDesktop":100,"lcpMobileMs":2326,"lcpDesktopMs":600,"clsMobile":0.002002927346531788,"clsDesktop":0.007673420584566925},{"pageUrl":"https://play.ee/web-development-case-studies/","perfMobile":95,"perfDesktop":100,"lcpMobileMs":2566.5,"lcpDesktopMs":573.6945814474632,"clsMobile":0.00303102965545189,"clsDesktop":0.002826098958002235},{"pageUrl":"https://play.ee/software-development-work-index/","perfMobile":86,"perfDesktop":100,"lcpMobileMs":2332,"lcpDesktopMs":533.6955007316975,"clsMobile":0.2110856712202515,"clsDesktop":0.002671369663503337},{"pageUrl":"https://play.ee/wordpress-support-service/","perfMobile":94,"perfDesktop":100,"lcpMobileMs":2586,"lcpDesktopMs":587.8472006791376,"clsMobile":0,"clsDesktop":0.002783484555150551},{"pageUrl":"https://play.ee/web-development-in-estonia/","perfMobile":96,"perfDesktop":100,"lcpMobileMs":2476,"lcpDesktopMs":574.0086109425052,"clsMobile":0.002002927346531788,"clsDesktop":0.006006131367660494}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket)","evidence":["HTML markers: WP Rocket","generator: WP Rocket 3.23"]},{"id":"lazyload","title":"Images lazy-loaded","status":"n/a","detail":"No raster <img> elements found (39 SVGs, 13 placeholders excluded).","evidence":[]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"n/a","detail":"No raster <img> elements found (39 SVGs, 13 placeholders excluded).","evidence":[]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"n/a","detail":"No CSS background-images detected on raster-image-eligible elements.","evidence":[]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"n/a","detail":"Only 0 raster images on the page (39 SVGs, 13 placeholders excluded) — responsive-image rule does not apply.","evidence":[]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"n/a","detail":"Too few raster images to evaluate srcset width variety.","evidence":[]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"pass","detail":"No render-blocking scripts in <head>.","evidence":[]}],"summary":{"passed":2,"warned":0,"failed":0,"notApplicable":5},"priorities":[]},"perPageOverall":[{"url":"https://play.ee/","overall":82,"reasoning":"Performance is excellent (PSI Mobile 97, LCP 2.3s), but the overall score is capped by a poor security posture (Headers 20/100) and broken HTML structure (W3C 7 errors). Accessibility is mostly solid (PSI 100) but has moderate axe violations (missing landmarks, skip link). The site is a brochure/agency portfolio with no auth or payments, so security header risk is lower than e-commerce but still critical for baseline trust. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS and add HSTS","impact":"Transport security, browser warnings","problem":"Security Headers tool reports HTTP does not redirect to HTTPS and HSTS is missing (Grade 20/100).","solution":"Configure server to redirect all HTTP traffic to HTTPS and send:\n```\nStrict-Transport-Security: max-age=63072000; includeSubDomains; preload\n```"},{"priority":1,"category":"Security","title":"Add X-Content-Type-Options","impact":"MIME sniffing protection","problem":"X-Content-Type-Options header is missing, leaving the site vulnerable to MIME-type sniffing attacks.","solution":"Add the following header to all responses:\n```\nX-Content-Type-Options: nosniff\n```"},{"priority":2,"category":"SEO","title":"Fix HTML Validation Errors","impact":"Parser recovery, SEO rendering","problem":"W3C Validator reports 7 errors including 'Bad start tag in iframe in noscript in head' and parser recovery failure at line 100.","solution":"Move `<noscript><iframe>...</iframe></noscript>` out of the `<head>` section. Ensure `<meta>` tags do not use the `name` attribute where `property` is required (e.g., Open Graph)."},{"priority":2,"category":"Accessibility","title":"Add Skip Link and Main Landmark","impact":"Keyboard navigation, screen reader flow","problem":"HTML Inventory shows missing `main` landmark and no skip-to-content link; axe reports `region` and `landmark-unique` violations.","solution":"Add a skip link at the top of the `<body>`:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n```\nWrap primary content in `<main id=\"main-content\">`."},{"priority":3,"category":"Performance","title":"Add Image Dimensions and Lazy Loading","impact":"CLS, Initial Load","problem":"52 images lack explicit width/height attributes and 52 lack `loading=\"lazy\"`, risking layout shifts despite current CLS score.","solution":"Add `width` and `height` attributes to all `<img>` tags. Add `loading=\"lazy\"` to images below the fold:\n```html\n<img src=\"...\" alt=\"...\" width=\"300\" height=\"200\" loading=\"lazy\">\n```"}],"perfScore":97,"a11yScore":100,"bestPracticesScore":100,"seoScore":92,"securityScore":20},{"url":"https://play.ee/web-development-case-studies/","overall":74,"reasoning":"PSI mobile performance is strong at 95, but Core Web Vitals show warnings (LCP 2.6 s, FCP 1.95 s). Security configuration is critically weak with a 20/100 header grade and HTTP not redirecting to HTTPS. Accessibility has a serious color-contrast violation and missing main landmark. W3C validation reports 7 errors including parser recovery failure. Image dimensions are missing on 56 assets despite low CLS.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS redirect and add HSTS","impact":"Transport security, data integrity","problem":"HTTP does not redirect to HTTPS and HSTS is missing (Security Headers grade 20/100).","solution":"Configure server to redirect all HTTP traffic to HTTPS immediately.\nAdd HSTS header:\n`Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`"},{"priority":2,"category":"Accessibility","title":"Fix color contrast and add main landmark","impact":"WCAG 1.4.3, 1.3.1","problem":"axe-core found 1 serious color-contrast violation; HTML Inventory shows missing main landmark.","solution":"- Increase contrast ratio to ≥4.5:1 for `.heading__main` and card text.\n- Wrap primary content in `<main>` tag.\n- Add skip-to-content link at top of page."},{"priority":2,"category":"Best Practices","title":"Resolve W3C HTML validation errors","impact":"Rendering stability, SEO","problem":"7 W3C errors including parser recovery failure at line 100 and bad iframe/noscript in head.","solution":"- Move `<noscript><iframe>` block out of `<head>`.\n- Fix stray `</noscript>` and `</head>` tags.\n- Ensure `<meta>` tags use valid attributes (`property` or `itemprop`)."},{"priority":3,"category":"Performance","title":"Add explicit width/height to images","impact":"CLS, Layout stability","problem":"56 images lack width/height attributes, risking layout shifts on load.","solution":"Add `width` and `height` attributes to all `<img>` tags matching intrinsic dimensions.\nExample: `<img src=\"...\" width=\"300\" height=\"200\" alt=\"...\">`"},{"priority":3,"category":"Performance","title":"Remove unused CSS and JavaScript","impact":"FCP, TBT","problem":"PSI findings estimate 32 KiB unused CSS and 23 KB unused JS.","solution":"- Purge unused CSS rules (WP Rocket or build tool).\n- Remove or defer `jquery.bfe1bb19d13b3c17b682.min.js` if not required for core functionality."}],"perfScore":95,"a11yScore":90,"bestPracticesScore":96,"seoScore":100,"securityScore":20},{"url":"https://play.ee/software-development-work-index/","overall":72,"reasoning":"Mobile performance is strong (86) with excellent TTFB (5 ms) and TBT (0 ms), but CLS is high at 0.211 due to footer shifts. Security is the weakest area (20/100 grade) with a critical failure: HTTP does not redirect to HTTPS, plus missing HSTS and X-Content-Type-Options. Accessibility has a serious color-contrast violation and missing main landmark despite a 90 score. W3C validation shows 7 errors including parser recovery failure at line 100. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Force HTTPS redirect on HTTP requests","impact":"Transport security, data integrity","problem":"Audit detected that http://play.ee/software-development-work-index/ does not redirect to HTTPS, leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to the HTTPS version:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":2,"category":"Security","title":"Add HSTS and X-Content-Type-Options headers","impact":"Clickjacking protection, MIME sniffing prevention","problem":"Security Headers grade is 20/100; HSTS and X-Content-Type-Options are missing despite HTTPS being available.","solution":"Add these headers to the server configuration:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Performance","title":"Fix Cumulative Layout Shift (CLS) on footer","impact":"CLS score (currently 0.211), User Experience","problem":"Mobile CLS is 0.211 (threshold 0.1); PSI identifies `footer.footer` as the primary shift source.","solution":"Reserve space for dynamic content in the footer using CSS min-height or explicit dimensions. Ensure images/fonts load with `font-display: swap` and explicit width/height attributes."},{"priority":2,"category":"Accessibility","title":"Fix color contrast and add main landmark","impact":"WCAG 1.4.3 (Contrast), 1.3.1 (Info & Relationships)","problem":"axe-core reports 1 serious violation on `h1 > .heading__main` and `p > span`; document lacks a `<main>` landmark.","solution":"- Increase text color contrast to ≥4.5:1 for affected elements.\n- Wrap primary content in `<main id=\"main-content\">` and add a skip link: `<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>`."},{"priority":3,"category":"SEO","title":"Resolve W3C HTML validation errors","impact":"Parser reliability, SEO crawling","problem":"7 W3C errors including `iframe` in `noscript` in `head` and parser recovery failure at line 100.","solution":"Move the Google Tag Manager `noscript` iframe out of the `<head>` and into the `<body>` immediately after the opening `<body>` tag. Fix stray `</noscript>` and `</head>` tags."}],"perfScore":86,"a11yScore":90,"bestPracticesScore":96,"seoScore":100,"securityScore":20},{"url":"https://play.ee/wordpress-support-service/","overall":74,"reasoning":"PSI mobile performance is excellent (94) with strong Core Web Vitals (LCP 2.6 s, CLS 0.000), but security configuration is critically weak (Headers 20/100, HTTP does not redirect to HTTPS). Accessibility has material issues (2 serious axe violations on contrast and link names) despite a 91 PSI score. HTML validation shows 7 errors including parser recovery failure, indicating structural fragility. The overall score reflects high user experience quality offset by significant security and code quality debt.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Force HTTPS redirect on HTTP requests","impact":"Transport security, downgrade attacks","problem":"Security Headers audit reports 'http://play.ee/wordpress-support-service/ does not redirect to HTTPS', leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests.\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Security","title":"Add HSTS and X-Content-Type-Options headers","impact":"Transport security, MIME sniffing","problem":"Security Headers grade is 20/100; HSTS and X-Content-Type-Options are missing despite HTTPS being used.","solution":"Add the following headers to the server response:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Accessibility","title":"Fix color contrast and link names","impact":"WCAG 1.4.3, 2.4.4 compliance","problem":"axe-core found 2 serious violations: color-contrast on multiple text nodes and link-name on logo grid links (no discernible text).","solution":"- Increase contrast on `.button--tertiary` and `.capabilities__heading` to meet 4.5:1 ratio.\n- Add `aria-label` to logo links: `<a href=\"\" aria-label=\"Partner Name\"><img ...></a>`."},{"priority":2,"category":"SEO","title":"Resolve HTML validation errors","impact":"Parsing reliability, SEO crawlers","problem":"W3C Validator reports 7 errors including 'Bad start tag in iframe in noscript in head' and parser recovery failure at line 107.","solution":"Move the GTM noscript iframe out of the `<head>` or ensure it is properly nested. Remove stray `</noscript>` and `</head>` tags. Ensure `<meta>` tags in `<head>` do not use invalid attributes like `name` where `property` is expected."},{"priority":3,"category":"Performance","title":"Add explicit dimensions to images","impact":"CLS prevention","problem":"HTML Inventory shows 31 images without width/height attributes, risking layout shifts despite current CLS score of 0.000.","solution":"Add `width` and `height` attributes to all `<img>` tags matching their intrinsic aspect ratio:\n```html\n<img src=\"logo.svg\" alt=\"Logo\" width=\"200\" height=\"50\">\n```"}],"perfScore":94,"a11yScore":91,"bestPracticesScore":100,"seoScore":100,"securityScore":20},{"url":"https://play.ee/web-development-in-estonia/","overall":78,"reasoning":"Mobile PSI performance is excellent (96) with strong Core Web Vitals, but the score is dragged down by critical security configuration (HTTP does not redirect to HTTPS, HSTS missing) and 7 W3C validation errors causing parser recovery failure. Accessibility has a serious color-contrast violation and missing main landmark, which impacts usability. Security Headers grade is 20/100, significantly penalizing the SEO/Security bucket despite the site being a brochure. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS Redirect and Add HSTS","impact":"Transport security, user trust","problem":"HTTP does not redirect to HTTPS (http://play.ee... does not redirect) and HSTS is missing, resulting in a Security Headers grade of 20/100.","solution":"Configure the web server to redirect all HTTP traffic to HTTPS immediately. Add HSTS header:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":1,"category":"SEO","title":"Fix W3C HTML Validation Errors","impact":"Document structure, rendering reliability","problem":"7 validation errors including parser recovery failure at line 100 (iframe/noscript in head, stray end tags).","solution":"Move `<noscript><iframe>...</iframe></noscript>` out of the `<head>` section. Ensure `<meta>` tags are placed correctly within `<head>` and close `<head>` before `<body>` starts."},{"priority":2,"category":"Accessibility","title":"Fix Color Contrast Violations","impact":"WCAG 1.4.3 compliance, readability","problem":"axe-core reports 1 serious violation for color-contrast on multiple heading elements (e.g., `.focus__heading > h1`).","solution":"Increase contrast ratio to at least 4.5:1 for normal text. Adjust CSS for `.heading__main` and `.heading__small` classes to use darker text or lighter backgrounds."},{"priority":2,"category":"Accessibility","title":"Add Main Landmark and Skip Link","impact":"Keyboard navigation, screen reader support","problem":"HTML Inventory shows `main` landmark is missing and no skip-to-content link exists.","solution":"Wrap primary content in `<main>` tag. Add a skip link at the top of the page:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n<div id=\"main-content\">...</div>\n```"},{"priority":3,"category":"Performance","title":"Remove Unused CSS and JavaScript","impact":"Page load time, render-blocking resources","problem":"PSI findings estimate 31 KiB unused CSS and 23 KiB unused JS savings.","solution":"Use PurgeCSS or similar tool to remove unused CSS rules. Defer non-critical JS or use `type=\"module\"` with `defer` to reduce main thread work."},{"priority":3,"category":"Best Practices","title":"Add Explicit Dimensions to Images","impact":"Layout stability (CLS), rendering performance","problem":"HTML Inventory shows 69 images without explicit width/height attributes.","solution":"Add `width` and `height` attributes to all `<img>` tags to reserve space before loading:\n```html\n<img src=\"...\" alt=\"...\" width=\"300\" height=\"200\">\n```"}],"perfScore":96,"a11yScore":94,"bestPracticesScore":100,"seoScore":100,"securityScore":20}]}