{"url":"https://play.ee/","date":"2026-08-02","siteName":"Perfectly formed web development team - gotoAndPlay","overall":76,"reasoning":"Site overall 76 is the mean of 5 pages. Scores range 72 (https://play.ee/wordpress-support-service/) → 80 (https://play.ee/web-development-in-estonia/). Weakest page: Mobile performance is excellent (94/100) with strong Core Web Vitals, though LCP sits at 2.6 s just above the 2.5 s threshold. Security configuration is the weakest area, with a 20/100 header grade and HTTP traffic failing to redirect to HTTPS. Accessibility has two serious violations (contrast, link names) and missing landmarks, while HTML validation shows 7 errors including parser recovery failure. The overall score reflects high technical performance offset by significant security and compliance debt.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Force HTTPS Redirect","impact":"Transport security, downgrade attacks","problem":"Security Headers report states 'http://play.ee/ does not redirect to HTTPS', leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to redirect all HTTP traffic to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Security","title":"Force HTTPS redirect on HTTP requests","impact":"Transport security, MITM protection","problem":"Security Headers audit reports 'HTTP redirect: ✗' — http://play.ee/web-development-case-studies/ does not redirect to HTTPS.","solution":"Configure server (Apache/Nginx) to return 301/302 redirect for all HTTP traffic to HTTPS.\n\n**Apache example:**\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Security","title":"Add HSTS and X-Content-Type-Options headers","impact":"Protocol downgrade protection, MIME sniffing","problem":"Security Headers grade 20/100; HSTS and X-Content-Type-Options are missing regardless of site signals.","solution":"Add headers to server configuration.\n\n**Apache example:**\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":1,"category":"Security","title":"Enable HSTS","impact":"Protocol downgrade protection","problem":"strict-transport-security header is missing; security score is 20/100.","solution":"Add HSTS header with max-age >= 1 year and includeSubDomains.\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\n```"},{"priority":1,"category":"Security","title":"Force HTTPS redirect on HTTP traffic","impact":"Transport security, data integrity","problem":"HTTP requests to http://play.ee/wordpress-support-service/ do not redirect to HTTPS, exposing users to potential MITM attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to the HTTPS equivalent:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Security","title":"Enforce HTTPS redirect for all HTTP requests","impact":"Transport security, data integrity","problem":"Security report indicates http://play.ee/... does not redirect to HTTPS, leaving traffic vulnerable to interception.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":2,"category":"Security","title":"Add HSTS and X-Content-Type-Options","impact":"Header security grade, MIME sniffing protection","problem":"Security Headers grade is 20/100; HSTS and X-Content-Type-Options are missing despite being cheap baseline defenses.","solution":"Add the following headers to the server response:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Best Practices","title":"Fix W3C HTML Validation Errors","impact":"Parser recovery, rendering consistency","problem":"W3C Validator reports 7 errors including 'Bad start tag in iframe in noscript in head' and parser recovery failure at line 100.","solution":"Move the GTM iframe snippet out of the `<head>` or ensure it is properly closed within `<body>`. Remove invalid `name` attributes on `<meta>` tags inside the head context."},{"priority":2,"category":"Accessibility","title":"Add Main Landmark and Skip Link","impact":"Screen reader navigation, WCAG 2.4.1","problem":"HTML Inventory shows 'main: missing' and 'Skip-to-content link: missing'; axe-core flags 'region' and 'landmark-unique' violations.","solution":"Wrap the primary content in `<main>` and add a skip link at the top of the `<body>`:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n...\n<main id=\"main-content\">\n  <!-- content -->\n</main>\n```"},{"priority":2,"category":"Accessibility","title":"Fix color contrast and add main landmark","impact":"WCAG 1.4.3, 1.3.1","problem":"axe-core reports 1 serious violation (color-contrast on .heading__main etc.) and missing `main` landmark.","solution":"- Increase contrast ratio to ≥4.5:1 for text elements.\n- Wrap primary content in `<main>` tag.\n- Add skip link: `<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>`."},{"priority":2,"category":"Accessibility","title":"Add main landmark and fix contrast","impact":"Screen reader navigation, WCAG 1.4.3","problem":"PSI `landmark-one-main` failed; axe reports 1 serious color-contrast violation on h1/span.","solution":"- Wrap primary content in `<main>` tag.\n- Increase contrast ratio for `.heading__main` and `p > span` to ≥4.5:1.\n- Add skip-to-content link at top of page."},{"priority":2,"category":"Best Practices","title":"Fix HTML validation errors","impact":"Rendering stability, SEO","problem":"W3C Validator reports 7 errors including malformed `<noscript>`/`<iframe>` in `<head>` and parser recovery failure.","solution":"Move `<noscript>` containing GTM iframe outside `<head>` or ensure valid nesting. Remove invalid `name` attribute on `<meta>` tags. Validate full document after fixes."},{"priority":2,"category":"Accessibility","title":"Fix color contrast and link names","impact":"WCAG 1.4.3, 2.4.4 compliance","problem":"axe-core reports 2 serious violations: color-contrast on multiple nodes and link-name on logo grid links.","solution":"- Increase contrast ratio on `.button--tertiary` and `.heading__small` elements to ≥4.5:1.\n- Add `aria-label` or visible text to logo grid links (e.g., `<a href=\"\" aria-label=\"Partner Logo\">`)."},{"priority":2,"category":"SEO","title":"Resolve W3C validation errors and H1 structure","impact":"Document outline, SEO indexing","problem":"W3C validator found 7 errors including parser recovery failure; HTML inventory shows 2 `<h1>` elements.","solution":"- Ensure only one `<h1>` exists per page.\n- Fix `<noscript><iframe>` nesting in `<head>` (move to `<body>`).\n- Remove invalid `name` attribute on `<meta>` tags."},{"priority":2,"category":"Security","title":"Add HSTS and X-Content-Type-Options headers","impact":"Clickjacking, MIME sniffing, downgrade attacks","problem":"HSTS and X-Content-Type-Options are missing; grade is 20/100. These are baseline headers required regardless of site signals.","solution":"Add the following headers to the server configuration:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Best Practices","title":"Resolve W3C HTML validation errors","impact":"Parser reliability, SEO crawling","problem":"7 errors found, including parser recovery failure at line 101 and invalid `<iframe>` inside `<noscript>` within `<head>`.","solution":"- Move `<noscript><iframe>...</iframe></noscript>` out of the `<head>` (Google Tag Manager snippet should be in `<body>` or properly placed).\n- Ensure `<meta>` tags are valid and do not use forbidden attributes like `name` in contexts requiring `property`."},{"priority":3,"category":"Performance","title":"Add Explicit Width and Height to Images","impact":"CLS, layout stability","problem":"HTML Inventory shows 52 images without width/height attributes, which risks layout shifts despite current low CLS.","solution":"Ensure all `<img>` tags include `width` and `height` attributes matching the intrinsic dimensions:\n```html\n<img src=\"image.svg\" alt=\"...\" width=\"360\" height=\"420\">\n```"},{"priority":3,"category":"Performance","title":"Add explicit width/height to images","impact":"CLS, Layout stability","problem":"HTML Inventory shows 56 images without width/height attributes, risking layout shifts despite current CLS 0.000.","solution":"Add `width` and `height` attributes to all `<img>` tags matching the intrinsic aspect ratio.\n\n```html\n<img src=\"hero.jpg\" alt=\"...\" width=\"1200\" height=\"600\">\n```"},{"priority":3,"category":"Security","title":"Implement Content Security Policy","impact":"XSS defense-in-depth","problem":"CSP is missing (only frame-ancestors set). Site signals show no auth/payments, so risk is lower but defense is recommended.","solution":"Deploy a strict CSP with nonce/hash approach when ready.\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"},{"priority":3,"category":"Security","title":"Implement Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing or weak (only `frame-ancestors`); site signals indicate no auth/payments, lowering immediate risk.","solution":"Deploy a strict CSP with nonce/hash for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none';\"\n```"},{"priority":3,"category":"Performance","title":"Remove unused CSS and JavaScript","impact":"FCP, TBT, Page weight","problem":"PSI findings indicate 31 KiB unused CSS and 23 KiB unused JS, contributing to FCP warning (1.96 s on mobile).","solution":"- Use PurgeCSS or similar tooling to remove unused CSS rules.\n- Code-split JavaScript bundles and defer non-critical scripts.\n- Verify WP Rocket configuration to ensure unused CSS is purged."}],"coverage":{"pct":100,"missing":[]},"siteSummary":{"pagesAudited":5,"pagesAttempted":5,"urls":["https://play.ee/","https://play.ee/web-development-case-studies/","https://play.ee/software-development-work-index/","https://play.ee/wordpress-support-service/","https://play.ee/web-development-in-estonia/"]},"psiSnapshot":{"rows":[{"pageUrl":"https://play.ee/","perfMobile":97,"perfDesktop":100,"lcpMobileMs":2183.631337225227,"lcpDesktopMs":532.7107493164553,"clsMobile":0.0020364859322068427,"clsDesktop":0.007757081267648048},{"pageUrl":"https://play.ee/web-development-case-studies/","perfMobile":94,"perfDesktop":100,"lcpMobileMs":2581,"lcpDesktopMs":545.5376564793296,"clsMobile":0,"clsDesktop":0.0026357958450812895},{"pageUrl":"https://play.ee/software-development-work-index/","perfMobile":95,"perfDesktop":100,"lcpMobileMs":2513,"lcpDesktopMs":597,"clsMobile":0.04103362197089203,"clsDesktop":0.00281041673381916},{"pageUrl":"https://play.ee/wordpress-support-service/","perfMobile":94,"perfDesktop":100,"lcpMobileMs":2577,"lcpDesktopMs":544.7540932244982,"clsMobile":0,"clsDesktop":0.00281041673381916},{"pageUrl":"https://play.ee/web-development-in-estonia/","perfMobile":97,"perfDesktop":100,"lcpMobileMs":2251,"lcpDesktopMs":573.6956391637094,"clsMobile":0.0017369935143734987,"clsDesktop":0.004675665744215261}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket)","evidence":["HTML markers: WP Rocket","generator: WP Rocket 3.23.1"]},{"id":"lazyload","title":"Images lazy-loaded","status":"n/a","detail":"No raster <img> elements found (39 SVGs, 13 placeholders excluded).","evidence":[]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"n/a","detail":"No raster <img> elements found (39 SVGs, 13 placeholders excluded).","evidence":[]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"n/a","detail":"No CSS background-images detected on raster-image-eligible elements.","evidence":[]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"n/a","detail":"Only 0 raster images on the page (39 SVGs, 13 placeholders excluded) — responsive-image rule does not apply.","evidence":[]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"n/a","detail":"Too few raster images to evaluate srcset width variety.","evidence":[]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"pass","detail":"No render-blocking scripts in <head>.","evidence":[]}],"summary":{"passed":2,"warned":0,"failed":0,"notApplicable":5},"priorities":[]},"perPageOverall":[{"url":"https://play.ee/","overall":78,"reasoning":"PSI mobile 97 indicates excellent performance (LCP 2.2 s, TTFB 9 ms), but security posture is weak with HTTP not redirecting to HTTPS and a 20/100 header grade. W3C validation shows 7 errors including parser recovery failure, and accessibility lacks a main landmark and skip link. The site is a web development agency portfolio with no commerce or auth signals, lowering the urgency of CSP but not baseline headers. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Force HTTPS Redirect","impact":"Transport security, downgrade attacks","problem":"Security Headers report states 'http://play.ee/ does not redirect to HTTPS', leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to redirect all HTTP traffic to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":2,"category":"Security","title":"Add HSTS and X-Content-Type-Options","impact":"Header security grade, MIME sniffing protection","problem":"Security Headers grade is 20/100; HSTS and X-Content-Type-Options are missing despite being cheap baseline defenses.","solution":"Add the following headers to the server response:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Best Practices","title":"Fix W3C HTML Validation Errors","impact":"Parser recovery, rendering consistency","problem":"W3C Validator reports 7 errors including 'Bad start tag in iframe in noscript in head' and parser recovery failure at line 100.","solution":"Move the GTM iframe snippet out of the `<head>` or ensure it is properly closed within `<body>`. Remove invalid `name` attributes on `<meta>` tags inside the head context."},{"priority":2,"category":"Accessibility","title":"Add Main Landmark and Skip Link","impact":"Screen reader navigation, WCAG 2.4.1","problem":"HTML Inventory shows 'main: missing' and 'Skip-to-content link: missing'; axe-core flags 'region' and 'landmark-unique' violations.","solution":"Wrap the primary content in `<main>` and add a skip link at the top of the `<body>`:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n...\n<main id=\"main-content\">\n  <!-- content -->\n</main>\n```"},{"priority":3,"category":"Performance","title":"Add Explicit Width and Height to Images","impact":"CLS, layout stability","problem":"HTML Inventory shows 52 images without width/height attributes, which risks layout shifts despite current low CLS.","solution":"Ensure all `<img>` tags include `width` and `height` attributes matching the intrinsic dimensions:\n```html\n<img src=\"image.svg\" alt=\"...\" width=\"360\" height=\"420\">\n```"}],"perfScore":97,"a11yScore":100,"bestPracticesScore":100,"seoScore":92,"securityScore":20},{"url":"https://play.ee/web-development-case-studies/","overall":74,"reasoning":"Performance is strong (PSI mobile 94) with clean Core Web Vitals except LCP at 2.6 s. However, security posture is weak (Headers grade 20/100) with a critical HTTP-to-HTTPS redirect failure and missing HSTS. Accessibility has a serious color-contrast violation and missing main landmark. HTML validation shows 7 errors including structural issues with GTM snippets. The score reflects high performance offset by significant security and structural debt.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Force HTTPS redirect on HTTP requests","impact":"Transport security, MITM protection","problem":"Security Headers audit reports 'HTTP redirect: ✗' — http://play.ee/web-development-case-studies/ does not redirect to HTTPS.","solution":"Configure server (Apache/Nginx) to return 301/302 redirect for all HTTP traffic to HTTPS.\n\n**Apache example:**\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Security","title":"Add HSTS and X-Content-Type-Options headers","impact":"Protocol downgrade protection, MIME sniffing","problem":"Security Headers grade 20/100; HSTS and X-Content-Type-Options are missing regardless of site signals.","solution":"Add headers to server configuration.\n\n**Apache example:**\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Accessibility","title":"Fix color contrast and add main landmark","impact":"WCAG 1.4.3, 1.3.1","problem":"axe-core reports 1 serious violation (color-contrast on .heading__main etc.) and missing `main` landmark.","solution":"- Increase contrast ratio to ≥4.5:1 for text elements.\n- Wrap primary content in `<main>` tag.\n- Add skip link: `<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>`."},{"priority":2,"category":"SEO","title":"Fix W3C HTML validation errors","impact":"Parsing reliability, SEO","problem":"W3C Validator reports 7 errors including 'Bad start tag in iframe in noscript in head' (GTM snippet).","solution":"Move Google Tag Manager noscript snippet outside of `<head>` (it belongs in `<body>`). Ensure meta tags do not use `name` attribute where `property` is required."},{"priority":3,"category":"Performance","title":"Add explicit width/height to images","impact":"CLS, Layout stability","problem":"HTML Inventory shows 56 images without width/height attributes, risking layout shifts despite current CLS 0.000.","solution":"Add `width` and `height` attributes to all `<img>` tags matching the intrinsic aspect ratio.\n\n```html\n<img src=\"hero.jpg\" alt=\"...\" width=\"1200\" height=\"600\">\n```"}],"perfScore":94,"a11yScore":90,"bestPracticesScore":96,"seoScore":100,"securityScore":20},{"url":"https://play.ee/software-development-work-index/","overall":74,"reasoning":"Performance is excellent (PSI Mobile 95, LCP 2.5 s), but security configuration is critically weak (Headers 20/100, HTTP does not redirect to HTTPS). Accessibility has material issues including 1 serious contrast violation and a missing main landmark. HTML validation shows 7 errors with parser recovery, indicating structural fragility. The site functions well for users but exposes significant security and compliance risks.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Force HTTPS redirect","impact":"Transport security, data integrity","problem":"Security Headers audit reports 'http://play.ee/... does not redirect to HTTPS', allowing unencrypted access.","solution":"Configure server (Apache/Nginx) to return 301/302 redirect from HTTP to HTTPS for all requests.\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Security","title":"Enable HSTS","impact":"Protocol downgrade protection","problem":"strict-transport-security header is missing; security score is 20/100.","solution":"Add HSTS header with max-age >= 1 year and includeSubDomains.\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\n```"},{"priority":2,"category":"Accessibility","title":"Add main landmark and fix contrast","impact":"Screen reader navigation, WCAG 1.4.3","problem":"PSI `landmark-one-main` failed; axe reports 1 serious color-contrast violation on h1/span.","solution":"- Wrap primary content in `<main>` tag.\n- Increase contrast ratio for `.heading__main` and `p > span` to ≥4.5:1.\n- Add skip-to-content link at top of page."},{"priority":2,"category":"Best Practices","title":"Fix HTML validation errors","impact":"Rendering stability, SEO","problem":"W3C Validator reports 7 errors including malformed `<noscript>`/`<iframe>` in `<head>` and parser recovery failure.","solution":"Move `<noscript>` containing GTM iframe outside `<head>` or ensure valid nesting. Remove invalid `name` attribute on `<meta>` tags. Validate full document after fixes."},{"priority":3,"category":"Security","title":"Implement Content Security Policy","impact":"XSS defense-in-depth","problem":"CSP is missing (only frame-ancestors set). Site signals show no auth/payments, so risk is lower but defense is recommended.","solution":"Deploy a strict CSP with nonce/hash approach when ready.\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"}],"perfScore":95,"a11yScore":90,"bestPracticesScore":96,"seoScore":100,"securityScore":20},{"url":"https://play.ee/wordpress-support-service/","overall":72,"reasoning":"Mobile performance is excellent (94/100) with strong Core Web Vitals, though LCP sits at 2.6 s just above the 2.5 s threshold. Security configuration is the weakest area, with a 20/100 header grade and HTTP traffic failing to redirect to HTTPS. Accessibility has two serious violations (contrast, link names) and missing landmarks, while HTML validation shows 7 errors including parser recovery failure. The overall score reflects high technical performance offset by significant security and compliance debt.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Force HTTPS redirect on HTTP traffic","impact":"Transport security, data integrity","problem":"HTTP requests to http://play.ee/wordpress-support-service/ do not redirect to HTTPS, exposing users to potential MITM attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to the HTTPS equivalent:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Security","title":"Add HSTS and X-Content-Type-Options headers","impact":"Protocol downgrade protection, MIME sniffing","problem":"HSTS and X-Content-Type-Options are missing; security headers grade is 20/100.","solution":"Add these headers to the server configuration:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Accessibility","title":"Fix color contrast and link names","impact":"WCAG 1.4.3, 2.4.4 compliance","problem":"axe-core reports 2 serious violations: color-contrast on multiple nodes and link-name on logo grid links.","solution":"- Increase contrast ratio on `.button--tertiary` and `.heading__small` elements to ≥4.5:1.\n- Add `aria-label` or visible text to logo grid links (e.g., `<a href=\"\" aria-label=\"Partner Logo\">`)."},{"priority":2,"category":"SEO","title":"Resolve W3C validation errors and H1 structure","impact":"Document outline, SEO indexing","problem":"W3C validator found 7 errors including parser recovery failure; HTML inventory shows 2 `<h1>` elements.","solution":"- Ensure only one `<h1>` exists per page.\n- Fix `<noscript><iframe>` nesting in `<head>` (move to `<body>`).\n- Remove invalid `name` attribute on `<meta>` tags."},{"priority":3,"category":"Security","title":"Implement Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing or weak (only `frame-ancestors`); site signals indicate no auth/payments, lowering immediate risk.","solution":"Deploy a strict CSP with nonce/hash for scripts:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none';\"\n```"}],"perfScore":94,"a11yScore":91,"bestPracticesScore":100,"seoScore":100,"securityScore":20},{"url":"https://play.ee/web-development-in-estonia/","overall":80,"reasoning":"PSI mobile performance is excellent (97) with strong Core Web Vitals (LCP 2.3 s, CLS 0.002), but security configuration is critically weak (Headers grade 20/100, HTTP lacks HTTPS redirect). Accessibility has a serious color-contrast violation and missing main landmark despite a high PSI score. W3C validation shows 7 errors including parser recovery failure, indicating structural HTML issues. Mobile FCP (1.96 s) lags significantly behind desktop (554 ms), suggesting mobile-specific resource loading delays.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS redirect for all HTTP requests","impact":"Transport security, data integrity","problem":"Security report indicates http://play.ee/... does not redirect to HTTPS, leaving traffic vulnerable to interception.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":2,"category":"Security","title":"Add HSTS and X-Content-Type-Options headers","impact":"Clickjacking, MIME sniffing, downgrade attacks","problem":"HSTS and X-Content-Type-Options are missing; grade is 20/100. These are baseline headers required regardless of site signals.","solution":"Add the following headers to the server configuration:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Accessibility","title":"Fix color contrast and add main landmark","impact":"WCAG 1.4.3 contrast, 1.3.1 info and relationships","problem":"axe-core reports 1 serious color-contrast violation and PSI fails `landmark-one-main`. Multiple headings and sections lack proper semantic structure.","solution":"- Increase text color contrast to ≥4.5:1 for `.focus__heading` and `.capabilities__heading`.\n- Wrap primary content in `<main>` tag.\n- Add a skip-to-content link at the top of the page."},{"priority":2,"category":"Best Practices","title":"Resolve W3C HTML validation errors","impact":"Parser reliability, SEO crawling","problem":"7 errors found, including parser recovery failure at line 101 and invalid `<iframe>` inside `<noscript>` within `<head>`.","solution":"- Move `<noscript><iframe>...</iframe></noscript>` out of the `<head>` (Google Tag Manager snippet should be in `<body>` or properly placed).\n- Ensure `<meta>` tags are valid and do not use forbidden attributes like `name` in contexts requiring `property`."},{"priority":3,"category":"Performance","title":"Remove unused CSS and JavaScript","impact":"FCP, TBT, Page weight","problem":"PSI findings indicate 31 KiB unused CSS and 23 KiB unused JS, contributing to FCP warning (1.96 s on mobile).","solution":"- Use PurgeCSS or similar tooling to remove unused CSS rules.\n- Code-split JavaScript bundles and defer non-critical scripts.\n- Verify WP Rocket configuration to ensure unused CSS is purged."}],"perfScore":97,"a11yScore":94,"bestPracticesScore":100,"seoScore":100,"securityScore":20}]}