# Audit Report: Perfectly formed web development team - gotoAndPlay
**Website:** https://play.ee/
**Date:** 01.09.2026
**Audit Coverage:** 100% — all sources returned data
**Confidence:** high
**Pages Audited (5 of 5):**
- https://play.ee/
- https://play.ee/web-development-case-studies/
- https://play.ee/software-development-work-index/
- https://play.ee/wordpress-support-service/
- https://play.ee/web-development-in-estonia/
## Summary of results
**Overall Score:** 76 / 100
**Status:** 🟡 **Needs Improvement**
Site overall 76 is the mean of 5 pages. Scores range 73 (https://play.ee/software-development-work-index/) → 79 (https://play.ee/web-development-case-studies/). Weakest page: Mobile PSI 96 indicates strong performance (LCP 2.3 s, CLS 0.04), but security configuration is critically weak (Grade 20/100, HTTP not redirecting to HTTPS). W3C validation shows 8 errors with parser recovery failure at line 106, indicating broken DOM structure. Accessibility has a serious color-contrast violation and missing main landmark. Image assets lack explicit dimensions on all 53 instances, risking CLS. Overall score reflects high performance weighed down by security and structural quality issues.
### Per-page scores
🟡 **Needs Improvement** · https://play.ee/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 75 | 94 | 100 | 100 | 92 | 20 |
🟡 **Needs Improvement** · https://play.ee/web-development-case-studies/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 79 | 97 | 90 | 96 | 100 | 20 |
🟡 **Needs Improvement** · https://play.ee/software-development-work-index/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 73 | 96 | 90 | 96 | 100 | 20 |
🟡 **Needs Improvement** · https://play.ee/wordpress-support-service/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 76 | 94 | 91 | 100 | 100 | 20 |
🟡 **Needs Improvement** · https://play.ee/web-development-in-estonia/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 78 | 96 | 94 | 100 | 100 | 20 |
## PageSpeed Insights — Mobile vs Desktop
_Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._
| URL | Performance (M / D) | LCP (M / D) | CLS (M / D) |
| --- | --- | --- | --- |
| https://play.ee/ | **94** / 100 | **2.51 s** / 662 ms | 0.000 / **0.007** |
| https://play.ee/web-development-case-studies/ | 97 / **93** | **2.13 s** / 544 ms | 0.005 / **0.005** |
| https://play.ee/software-development-work-index/ | **96** / 100 | **2.33 s** / 582 ms | **0.041** / 0.004 |
| https://play.ee/wordpress-support-service/ | **94** / 100 | **2.57 s** / 546 ms | 0.000 / **0.002** |
| https://play.ee/web-development-in-estonia/ | **96** / 100 | **2.40 s** / 623 ms | 0.002 / **0.006** |
## Optimization Checklist
**2 of 2 passing** — 2 pass · 0 warn · 0 fail · 5 n/a
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | N/A | No raster
elements found (37 SVGs, 13 placeholders excluded). |
| Hero image eagerly loaded | N/A | No raster
elements found (37 SVGs, 13 placeholders excluded). |
| Hero is a real
(not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / ) | N/A | Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in | **Pass** | No render-blocking scripts in . |
## Fixes
### Priority 1: Critical
*Immediate action — impacts user experience, search rankings, or site safety.*
**1A. Force HTTPS redirect** `Security`
- **Impact:** Transport security, MITM protection
- **Problem:** http://play.ee/ does not redirect to HTTPS, leaving the site vulnerable to downgrade attacks despite HTTPS support.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS:
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1B. Enforce HTTPS redirect** `Security`
- **Impact:** Transport security, downgrade attack prevention
- **Problem:** Security audit reports 'http://play.ee/web-development-case-studies/ does not redirect to HTTPS', leaving users vulnerable to downgrade attacks.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1C. Fix color contrast violations** `Accessibility`
- **Impact:** WCAG 1.4.3 compliance, readability
- **Problem:** axe-core reports 1 serious violation: 'color-contrast' on multiple nodes including h1 and card titles.
- **Solution:**
Increase contrast ratio to ≥4.5:1 for normal text. Adjust CSS colors for `.heading__main` and `.card__title`:
```css
.heading__main { color: #333333; } /* Example adjustment */
```
**1D. Enforce HTTPS redirect and add baseline security headers** `Security`
- **Impact:** Transport security, clickjacking protection, MIME sniffing
- **Problem:** HTTP does not redirect to HTTPS (Grade 20/100); HSTS, X-Content-Type-Options, and X-Frame-Options are missing.
- **Solution:**
Configure server to redirect all HTTP traffic to HTTPS. Add these headers:
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
Header always set X-Content-Type-Options "nosniff"
Header always set X-Frame-Options "SAMEORIGIN"
```
**1E. Fix HTML validation errors and parser recovery failure** `Best Practices`
- **Impact:** DOM integrity, SEO rendering, cross-browser compatibility
- **Problem:** W3C reports 8 errors including parser recovery failure at line 106; stray tags and invalid attributes detected.
- **Solution:**
Review lines 52–106 in source. Fix empty `href` on ``, remove `