# Audit Report: Perfectly formed web development team - gotoAndPlay **Website:** https://play.ee/ **Date:** 01.09.2026 **Audit Coverage:** 100% — all sources returned data **Confidence:** high **Pages Audited (5 of 5):** - https://play.ee/ - https://play.ee/web-development-case-studies/ - https://play.ee/software-development-work-index/ - https://play.ee/wordpress-support-service/ - https://play.ee/web-development-in-estonia/ ## Summary of results **Overall Score:** 76 / 100 **Status:** 🟡 **Needs Improvement** Site overall 76 is the mean of 5 pages. Scores range 73 (https://play.ee/software-development-work-index/) → 79 (https://play.ee/web-development-case-studies/). Weakest page: Mobile PSI 96 indicates strong performance (LCP 2.3 s, CLS 0.04), but security configuration is critically weak (Grade 20/100, HTTP not redirecting to HTTPS). W3C validation shows 8 errors with parser recovery failure at line 106, indicating broken DOM structure. Accessibility has a serious color-contrast violation and missing main landmark. Image assets lack explicit dimensions on all 53 instances, risking CLS. Overall score reflects high performance weighed down by security and structural quality issues. ### Per-page scores 🟡 **Needs Improvement** · https://play.ee/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 75 | 94 | 100 | 100 | 92 | 20 | 🟡 **Needs Improvement** · https://play.ee/web-development-case-studies/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 79 | 97 | 90 | 96 | 100 | 20 | 🟡 **Needs Improvement** · https://play.ee/software-development-work-index/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 73 | 96 | 90 | 96 | 100 | 20 | 🟡 **Needs Improvement** · https://play.ee/wordpress-support-service/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 76 | 94 | 91 | 100 | 100 | 20 | 🟡 **Needs Improvement** · https://play.ee/web-development-in-estonia/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 78 | 96 | 94 | 100 | 100 | 20 | ## PageSpeed Insights — Mobile vs Desktop _Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._ | URL | Performance (M / D) | LCP (M / D) | CLS (M / D) | | --- | --- | --- | --- | | https://play.ee/ | **94** / 100 | **2.51 s** / 662 ms | 0.000 / **0.007** | | https://play.ee/web-development-case-studies/ | 97 / **93** | **2.13 s** / 544 ms | 0.005 / **0.005** | | https://play.ee/software-development-work-index/ | **96** / 100 | **2.33 s** / 582 ms | **0.041** / 0.004 | | https://play.ee/wordpress-support-service/ | **94** / 100 | **2.57 s** / 546 ms | 0.000 / **0.002** | | https://play.ee/web-development-in-estonia/ | **96** / 100 | **2.40 s** / 623 ms | 0.002 / **0.006** | ## Optimization Checklist **2 of 2 passing** — 2 pass · 0 warn · 0 fail · 5 n/a | Item | Status | Detail | | --- | --- | --- | | Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) | | Images lazy-loaded | N/A | No raster elements found (37 SVGs, 13 placeholders excluded). | | Hero image eagerly loaded | N/A | No raster elements found (37 SVGs, 13 placeholders excluded). | | Hero is a real (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. | | Responsive images (srcset / ) | N/A | Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply. | | Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. | | JS scripts not blocking in | **Pass** | No render-blocking scripts in . | ## Fixes ### Priority 1: Critical *Immediate action — impacts user experience, search rankings, or site safety.* **1A. Force HTTPS redirect** `Security` - **Impact:** Transport security, MITM protection - **Problem:** http://play.ee/ does not redirect to HTTPS, leaving the site vulnerable to downgrade attacks despite HTTPS support. - **Solution:** Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS: ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1B. Enforce HTTPS redirect** `Security` - **Impact:** Transport security, downgrade attack prevention - **Problem:** Security audit reports 'http://play.ee/web-development-case-studies/ does not redirect to HTTPS', leaving users vulnerable to downgrade attacks. - **Solution:** Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS: ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1C. Fix color contrast violations** `Accessibility` - **Impact:** WCAG 1.4.3 compliance, readability - **Problem:** axe-core reports 1 serious violation: 'color-contrast' on multiple nodes including h1 and card titles. - **Solution:** Increase contrast ratio to ≥4.5:1 for normal text. Adjust CSS colors for `.heading__main` and `.card__title`: ```css .heading__main { color: #333333; } /* Example adjustment */ ``` **1D. Enforce HTTPS redirect and add baseline security headers** `Security` - **Impact:** Transport security, clickjacking protection, MIME sniffing - **Problem:** HTTP does not redirect to HTTPS (Grade 20/100); HSTS, X-Content-Type-Options, and X-Frame-Options are missing. - **Solution:** Configure server to redirect all HTTP traffic to HTTPS. Add these headers: ```apache Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" Header always set X-Content-Type-Options "nosniff" Header always set X-Frame-Options "SAMEORIGIN" ``` **1E. Fix HTML validation errors and parser recovery failure** `Best Practices` - **Impact:** DOM integrity, SEO rendering, cross-browser compatibility - **Problem:** W3C reports 8 errors including parser recovery failure at line 106; stray tags and invalid attributes detected. - **Solution:** Review lines 52–106 in source. Fix empty `href` on ``, remove `