{"url":"https://play.ee/","date":"2026-09-01","siteName":"Perfectly formed web development team - gotoAndPlay","overall":76,"reasoning":"Site overall 76 is the mean of 5 pages. Scores range 73 (https://play.ee/software-development-work-index/) → 79 (https://play.ee/web-development-case-studies/). Weakest page: Mobile PSI 96 indicates strong performance (LCP 2.3 s, CLS 0.04), but security configuration is critically weak (Grade 20/100, HTTP not redirecting to HTTPS). W3C validation shows 8 errors with parser recovery failure at line 106, indicating broken DOM structure. Accessibility has a serious color-contrast violation and missing main landmark. Image assets lack explicit dimensions on all 53 instances, risking CLS. Overall score reflects high performance weighed down by security and structural quality issues.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Force HTTPS redirect","impact":"Transport security, MITM protection","problem":"http://play.ee/ does not redirect to HTTPS, leaving the site vulnerable to downgrade attacks despite HTTPS support.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Security","title":"Enforce HTTPS redirect","impact":"Transport security, downgrade attack prevention","problem":"Security audit reports 'http://play.ee/web-development-case-studies/ does not redirect to HTTPS', leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Accessibility","title":"Fix color contrast violations","impact":"WCAG 1.4.3 compliance, readability","problem":"axe-core reports 1 serious violation: 'color-contrast' on multiple nodes including h1 and card titles.","solution":"Increase contrast ratio to ≥4.5:1 for normal text. Adjust CSS colors for `.heading__main` and `.card__title`:\n```css\n.heading__main { color: #333333; } /* Example adjustment */\n```"},{"priority":1,"category":"Security","title":"Enforce HTTPS redirect and add baseline security headers","impact":"Transport security, clickjacking protection, MIME sniffing","problem":"HTTP does not redirect to HTTPS (Grade 20/100); HSTS, X-Content-Type-Options, and X-Frame-Options are missing.","solution":"Configure server to redirect all HTTP traffic to HTTPS. Add these headers:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\n```"},{"priority":1,"category":"Best Practices","title":"Fix HTML validation errors and parser recovery failure","impact":"DOM integrity, SEO rendering, cross-browser compatibility","problem":"W3C reports 8 errors including parser recovery failure at line 106; stray tags and invalid attributes detected.","solution":"Review lines 52–106 in source. Fix empty `href` on `<link>`, remove `<iframe>` from `<head>` (move to `<body>`), and correct `<meta>` attributes. Ensure `<noscript>` is closed properly."},{"priority":1,"category":"Security","title":"Force HTTPS redirect and add HSTS","impact":"Transport security, trust","problem":"HTTP does not redirect to HTTPS and HSTS is missing; Security Headers grade is 20/100.","solution":"Configure server to redirect all HTTP traffic to HTTPS and send HSTS header:\n```\nStrict-Transport-Security: max-age=63072000; includeSubDomains; preload\n```"},{"priority":1,"category":"Best Practices","title":"Fix HTML validation errors and parser recovery","impact":"DOM integrity, SEO, rendering","problem":"W3C validator reports 7 errors including parser recovery failure at line 107 (iframe in noscript in head).","solution":"Move `<noscript><iframe>` tags out of `<head>` and ensure `<meta>` tags are valid. Fix stray end tags to allow full DOM parsing."},{"priority":1,"category":"Security","title":"Enforce HTTPS redirect and add HSTS","impact":"Transport security, user trust","problem":"HTTP does not redirect to HTTPS and HSTS is missing (Security Headers grade 20/100).","solution":"Configure server to redirect all HTTP traffic to HTTPS and send HSTS header:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":2,"category":"Security","title":"Add HSTS and X-Content-Type-Options","impact":"Protocol downgrade, MIME sniffing","problem":"Security Headers grade is 20/100; HSTS and X-Content-Type-Options are missing regardless of site signals.","solution":"Add these headers to the server configuration:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Accessibility","title":"Add main landmark and skip-to-content link","impact":"Screen reader navigation, WCAG 2.4.1","problem":"axe-core reports missing `main` landmark and no skip-to-content link; 50 images lack dimensions.","solution":"Wrap primary content in `<main>` and add a skip link at the top:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n...\n<main id=\"main-content\">\n```"},{"priority":2,"category":"SEO","title":"Fix W3C HTML validation errors","impact":"Rendering consistency, SEO crawling","problem":"8 W3C errors including empty href attributes, stray end tags, and parser recovery failure at line 107.","solution":"Review the HTML source around line 54 and 104. Remove empty `href=\"\"` on links, fix `<noscript>` nesting inside `<head>`, and ensure `<meta>` tags are in valid locations."},{"priority":2,"category":"Accessibility","title":"Add main landmark and skip link","impact":"Screen reader navigation, WCAG 2.4.1","problem":"HTML Inventory confirms 'main: missing' and 'Skip-to-content link: missing'; axe reports 'landmark-one-main' failure.","solution":"Wrap primary content in `<main>` and add a skip link at the top:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n...\n<main id=\"main-content\">\n  <!-- Page content -->\n</main>\n```"},{"priority":2,"category":"Accessibility","title":"Fix contrast violations and add main landmark","impact":"WCAG 1.4.3 contrast, 1.3.1 info relationships","problem":"axe-core reports 1 serious `color-contrast` violation (h1, p span); PSI `landmark-one-main` failed; no skip-to-content link.","solution":"- Increase contrast ratio on `.heading__main` and `p > span` to ≥4.5:1.\n- Add `<main id=\"main-content\">` wrapper around primary content.\n- Add `<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>` before header."},{"priority":2,"category":"Performance","title":"Add explicit width and height to all images","impact":"CLS (Cumulative Layout Shift)","problem":"53 images lack width/height attributes, risking layout shifts despite low lab CLS score.","solution":"Add `width` and `height` attributes to every `<img>` tag matching intrinsic dimensions. For responsive images, use `width`/`height` on the `<img>` and `sizes` on `<source>`."},{"priority":2,"category":"Accessibility","title":"Fix color contrast and link names","impact":"WCAG 1.4.3, 2.4.4 compliance","problem":"axe-core reports 2 serious violations: color-contrast on multiple nodes and link-name on logo grid links.","solution":"Increase contrast ratio to ≥4.5:1 for `.button--tertiary` and `.heading__small`. Add `aria-label` to logo links with empty `href`."},{"priority":2,"category":"Performance","title":"Eliminate render-blocking resources","impact":"LCP, FCP, Speed Index","problem":"PSI findings indicate potential savings of 1,270 ms from render-blocking insight; LCP is 2.6 s.","solution":"Defer non-critical scripts and inline critical CSS. Ensure `jquery.bfe1bb19d13b3c17b682.min.js` is deferred if not needed for initial paint."},{"priority":2,"category":"SEO","title":"Fix W3C validation errors and heading structure","impact":"Document outline, parser reliability","problem":"W3C reports 7 errors including parser recovery failure at line 100 and 2 `<h1>` elements.","solution":"Ensure exactly one `<h1>` per page. Fix malformed `<noscript>`/`<iframe>` nesting in `<head>` and remove invalid `name` attributes on `<meta>` tags."},{"priority":3,"category":"SEO","title":"Disambiguate vague link text","impact":"Link context, SEO anchor text","problem":"9 instances of 'read more' and repeated generic text ('visit our facebook page') reduce link descriptiveness.","solution":"Update link text to describe the destination, e.g., 'Read more about our case studies' or use `aria-label` if visual text must remain generic."},{"priority":3,"category":"Performance","title":"Add explicit width/height to images","impact":"CLS prevention, layout stability","problem":"HTML Inventory shows 56 images without width/height attributes, risking layout shifts despite current CLS score.","solution":"Add `width` and `height` attributes to all `<img>` tags or use CSS aspect-ratio:\n```html\n<img src=\"...\" width=\"300\" height=\"200\" alt=\"...\">\n```"},{"priority":3,"category":"Performance","title":"Remove unused CSS and JavaScript","impact":"FCP, TBT, Total Page Weight","problem":"32 KiB unused CSS and 23 KiB unused JS detected; FCP is 1.96 s (warning zone).","solution":"- Purge unused CSS rules (WP Rocket may handle this).\n- Defer non-critical JS or remove `jquery.bfe1bb19d13b3c17b682.min.js` if not needed.\n- Enable tree-shaking in build process."},{"priority":3,"category":"Performance","title":"Add image dimensions and lazy loading","impact":"CLS, bandwidth","problem":"31 images lack explicit width/height attributes and `loading=\"lazy\"` despite low total weight.","solution":"Add `width` and `height` attributes to all `<img>` tags to reserve space. Add `loading=\"lazy\"` to images below the fold."},{"priority":3,"category":"Security","title":"Implement Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing. Site signals show no auth/payments/UGC, so risk is lower but defense-in-depth is recommended.","solution":"Deploy a strict CSP with nonces for scripts:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\"\n```"}],"coverage":{"pct":100,"missing":[]},"siteSummary":{"pagesAudited":5,"pagesAttempted":5,"urls":["https://play.ee/","https://play.ee/web-development-case-studies/","https://play.ee/software-development-work-index/","https://play.ee/wordpress-support-service/","https://play.ee/web-development-in-estonia/"]},"psiSnapshot":{"rows":[{"pageUrl":"https://play.ee/","perfMobile":94,"perfDesktop":100,"lcpMobileMs":2513,"lcpDesktopMs":662,"clsMobile":0,"clsDesktop":0.00678706602142075},{"pageUrl":"https://play.ee/web-development-case-studies/","perfMobile":97,"perfDesktop":93,"lcpMobileMs":2134.5488505495628,"lcpDesktopMs":544.0981683589364,"clsMobile":0.004538940511363545,"clsDesktop":0.004581493588205395},{"pageUrl":"https://play.ee/software-development-work-index/","perfMobile":96,"perfDesktop":100,"lcpMobileMs":2327,"lcpDesktopMs":582.3828516223246,"clsMobile":0.0409673995458489,"clsDesktop":0.004334318404438869},{"pageUrl":"https://play.ee/wordpress-support-service/","perfMobile":94,"perfDesktop":100,"lcpMobileMs":2569.5,"lcpDesktopMs":545.6992225260861,"clsMobile":0,"clsDesktop":0.001513033049024603},{"pageUrl":"https://play.ee/web-development-in-estonia/","perfMobile":96,"perfDesktop":100,"lcpMobileMs":2401,"lcpDesktopMs":623,"clsMobile":0.002002927346531788,"clsDesktop":0.006006131367660494}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket)","evidence":["HTML markers: WP Rocket","generator: WP Rocket 3.23.3.3"]},{"id":"lazyload","title":"Images lazy-loaded","status":"n/a","detail":"No raster <img> elements found (37 SVGs, 13 placeholders excluded).","evidence":[]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"n/a","detail":"No raster <img> elements found (37 SVGs, 13 placeholders excluded).","evidence":[]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"n/a","detail":"No CSS background-images detected on raster-image-eligible elements.","evidence":[]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"n/a","detail":"Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply.","evidence":[]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"n/a","detail":"Too few raster images to evaluate srcset width variety.","evidence":[]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"pass","detail":"No render-blocking scripts in <head>.","evidence":[]}],"summary":{"passed":2,"warned":0,"failed":0,"notApplicable":5},"priorities":[]},"perPageOverall":[{"url":"https://play.ee/","overall":75,"reasoning":"Performance is excellent (PSI Mobile 94, TTFB 36 ms, 178 KB payload), but security posture is critically weak (Headers 20/100, HTTP does not redirect to HTTPS). HTML validity is compromised by 8 W3C errors including parser recovery failure, and accessibility lacks structural landmarks (main, skip-link). The high performance score prevents a lower rating, but security and markup debt require immediate attention.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Force HTTPS redirect","impact":"Transport security, MITM protection","problem":"http://play.ee/ does not redirect to HTTPS, leaving the site vulnerable to downgrade attacks despite HTTPS support.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":2,"category":"Security","title":"Add HSTS and X-Content-Type-Options","impact":"Protocol downgrade, MIME sniffing","problem":"Security Headers grade is 20/100; HSTS and X-Content-Type-Options are missing regardless of site signals.","solution":"Add these headers to the server configuration:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Accessibility","title":"Add main landmark and skip-to-content link","impact":"Screen reader navigation, WCAG 2.4.1","problem":"axe-core reports missing `main` landmark and no skip-to-content link; 50 images lack dimensions.","solution":"Wrap primary content in `<main>` and add a skip link at the top:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n...\n<main id=\"main-content\">\n```"},{"priority":2,"category":"SEO","title":"Fix W3C HTML validation errors","impact":"Rendering consistency, SEO crawling","problem":"8 W3C errors including empty href attributes, stray end tags, and parser recovery failure at line 107.","solution":"Review the HTML source around line 54 and 104. Remove empty `href=\"\"` on links, fix `<noscript>` nesting inside `<head>`, and ensure `<meta>` tags are in valid locations."},{"priority":3,"category":"SEO","title":"Disambiguate vague link text","impact":"Link context, SEO anchor text","problem":"9 instances of 'read more' and repeated generic text ('visit our facebook page') reduce link descriptiveness.","solution":"Update link text to describe the destination, e.g., 'Read more about our case studies' or use `aria-label` if visual text must remain generic."}],"perfScore":94,"a11yScore":100,"bestPracticesScore":100,"seoScore":92,"securityScore":20},{"url":"https://play.ee/web-development-case-studies/","overall":79,"reasoning":"Performance is excellent (PSI Mobile 97, LCP 2.1 s), but foundational hygiene drags the score down. Security is weak (20/100) with a critical HTTP→HTTPS redirect failure and missing HSTS. Accessibility has a serious color-contrast violation and missing main landmark. W3C validation shows 7 errors including parser recovery failure, indicating broken HTML structure. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS redirect","impact":"Transport security, downgrade attack prevention","problem":"Security audit reports 'http://play.ee/web-development-case-studies/ does not redirect to HTTPS', leaving users vulnerable to downgrade attacks.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Accessibility","title":"Fix color contrast violations","impact":"WCAG 1.4.3 compliance, readability","problem":"axe-core reports 1 serious violation: 'color-contrast' on multiple nodes including h1 and card titles.","solution":"Increase contrast ratio to ≥4.5:1 for normal text. Adjust CSS colors for `.heading__main` and `.card__title`:\n```css\n.heading__main { color: #333333; } /* Example adjustment */\n```"},{"priority":2,"category":"Security","title":"Add HSTS and X-Content-Type-Options","impact":"Protocol downgrade protection, MIME sniffing","problem":"Security Headers grade 20/100; HSTS and X-Content-Type-Options are missing despite HTTPS being active.","solution":"Add headers to server config:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Accessibility","title":"Add main landmark and skip link","impact":"Screen reader navigation, WCAG 2.4.1","problem":"HTML Inventory confirms 'main: missing' and 'Skip-to-content link: missing'; axe reports 'landmark-one-main' failure.","solution":"Wrap primary content in `<main>` and add a skip link at the top:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n...\n<main id=\"main-content\">\n  <!-- Page content -->\n</main>\n```"},{"priority":2,"category":"SEO","title":"Fix W3C HTML validation errors","impact":"Parser reliability, SEO indexing","problem":"W3C Validator reports 7 errors including 'Bad start tag in iframe in noscript in head' and parser recovery failure at line 105.","solution":"Move the Google Tag Manager iframe outside the `<head>` or ensure it is properly closed before `</head>`. Check WP Rocket or GTM plugin settings for head injection conflicts."},{"priority":3,"category":"Performance","title":"Add explicit width/height to images","impact":"CLS prevention, layout stability","problem":"HTML Inventory shows 56 images without width/height attributes, risking layout shifts despite current CLS score.","solution":"Add `width` and `height` attributes to all `<img>` tags or use CSS aspect-ratio:\n```html\n<img src=\"...\" width=\"300\" height=\"200\" alt=\"...\">\n```"}],"perfScore":97,"a11yScore":90,"bestPracticesScore":96,"seoScore":100,"securityScore":20},{"url":"https://play.ee/software-development-work-index/","overall":73,"reasoning":"Mobile PSI 96 indicates strong performance (LCP 2.3 s, CLS 0.04), but security configuration is critically weak (Grade 20/100, HTTP not redirecting to HTTPS). W3C validation shows 8 errors with parser recovery failure at line 106, indicating broken DOM structure. Accessibility has a serious color-contrast violation and missing main landmark. Image assets lack explicit dimensions on all 53 instances, risking CLS. Overall score reflects high performance weighed down by security and structural quality issues.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS redirect and add baseline security headers","impact":"Transport security, clickjacking protection, MIME sniffing","problem":"HTTP does not redirect to HTTPS (Grade 20/100); HSTS, X-Content-Type-Options, and X-Frame-Options are missing.","solution":"Configure server to redirect all HTTP traffic to HTTPS. Add these headers:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\n```"},{"priority":1,"category":"Best Practices","title":"Fix HTML validation errors and parser recovery failure","impact":"DOM integrity, SEO rendering, cross-browser compatibility","problem":"W3C reports 8 errors including parser recovery failure at line 106; stray tags and invalid attributes detected.","solution":"Review lines 52–106 in source. Fix empty `href` on `<link>`, remove `<iframe>` from `<head>` (move to `<body>`), and correct `<meta>` attributes. Ensure `<noscript>` is closed properly."},{"priority":2,"category":"Accessibility","title":"Fix contrast violations and add main landmark","impact":"WCAG 1.4.3 contrast, 1.3.1 info relationships","problem":"axe-core reports 1 serious `color-contrast` violation (h1, p span); PSI `landmark-one-main` failed; no skip-to-content link.","solution":"- Increase contrast ratio on `.heading__main` and `p > span` to ≥4.5:1.\n- Add `<main id=\"main-content\">` wrapper around primary content.\n- Add `<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>` before header."},{"priority":2,"category":"Performance","title":"Add explicit width and height to all images","impact":"CLS (Cumulative Layout Shift)","problem":"53 images lack width/height attributes, risking layout shifts despite low lab CLS score.","solution":"Add `width` and `height` attributes to every `<img>` tag matching intrinsic dimensions. For responsive images, use `width`/`height` on the `<img>` and `sizes` on `<source>`."},{"priority":3,"category":"Performance","title":"Remove unused CSS and JavaScript","impact":"FCP, TBT, Total Page Weight","problem":"32 KiB unused CSS and 23 KiB unused JS detected; FCP is 1.96 s (warning zone).","solution":"- Purge unused CSS rules (WP Rocket may handle this).\n- Defer non-critical JS or remove `jquery.bfe1bb19d13b3c17b682.min.js` if not needed.\n- Enable tree-shaking in build process."}],"perfScore":96,"a11yScore":90,"bestPracticesScore":96,"seoScore":100,"securityScore":20},{"url":"https://play.ee/wordpress-support-service/","overall":76,"reasoning":"PSI mobile performance is strong at 94, but LCP (2.6 s) slightly exceeds the 2.5 s threshold. Security headers are critically weak (20/100) with HTTP not redirecting to HTTPS. W3C validation shows 7 errors including parser recovery failure, indicating broken DOM structure. Accessibility has 2 serious violations (contrast, link names) despite a 91 PSI score. Image assets lack dimensions and lazy loading, posing CLS risks despite low total weight.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Force HTTPS redirect and add HSTS","impact":"Transport security, trust","problem":"HTTP does not redirect to HTTPS and HSTS is missing; Security Headers grade is 20/100.","solution":"Configure server to redirect all HTTP traffic to HTTPS and send HSTS header:\n```\nStrict-Transport-Security: max-age=63072000; includeSubDomains; preload\n```"},{"priority":1,"category":"Best Practices","title":"Fix HTML validation errors and parser recovery","impact":"DOM integrity, SEO, rendering","problem":"W3C validator reports 7 errors including parser recovery failure at line 107 (iframe in noscript in head).","solution":"Move `<noscript><iframe>` tags out of `<head>` and ensure `<meta>` tags are valid. Fix stray end tags to allow full DOM parsing."},{"priority":2,"category":"Accessibility","title":"Fix color contrast and link names","impact":"WCAG 1.4.3, 2.4.4 compliance","problem":"axe-core reports 2 serious violations: color-contrast on multiple nodes and link-name on logo grid links.","solution":"Increase contrast ratio to ≥4.5:1 for `.button--tertiary` and `.heading__small`. Add `aria-label` to logo links with empty `href`."},{"priority":2,"category":"Performance","title":"Eliminate render-blocking resources","impact":"LCP, FCP, Speed Index","problem":"PSI findings indicate potential savings of 1,270 ms from render-blocking insight; LCP is 2.6 s.","solution":"Defer non-critical scripts and inline critical CSS. Ensure `jquery.bfe1bb19d13b3c17b682.min.js` is deferred if not needed for initial paint."},{"priority":3,"category":"Performance","title":"Add image dimensions and lazy loading","impact":"CLS, bandwidth","problem":"31 images lack explicit width/height attributes and `loading=\"lazy\"` despite low total weight.","solution":"Add `width` and `height` attributes to all `<img>` tags to reserve space. Add `loading=\"lazy\"` to images below the fold."}],"perfScore":94,"a11yScore":91,"bestPracticesScore":100,"seoScore":100,"securityScore":20},{"url":"https://play.ee/web-development-in-estonia/","overall":78,"reasoning":"PSI mobile 96 indicates excellent performance (LCP 2.4s, TTFB 9ms), but Security Headers grade 20/100 and missing HTTPS redirect create a critical trust gap. Accessibility is compromised by serious color-contrast violations and a missing main landmark despite a 94 PSI score. W3C validation shows 7 errors including parser recovery failure, and 67 images lack dimensions. The score reflects high technical performance offset by foundational security and accessibility debt.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS redirect and add HSTS","impact":"Transport security, user trust","problem":"HTTP does not redirect to HTTPS and HSTS is missing (Security Headers grade 20/100).","solution":"Configure server to redirect all HTTP traffic to HTTPS and send HSTS header:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Accessibility","title":"Fix color contrast violations","impact":"WCAG 1.4.3 compliance, readability","problem":"axe-core reports 1 serious violation with 21+ nodes failing contrast (e.g., .focus__heading, .capabilities__heading).","solution":"Increase contrast ratio to ≥4.5:1 for text elements. Adjust CSS colors for `.heading__main` and `.heading__small` classes to meet WCAG AA standards."},{"priority":2,"category":"Accessibility","title":"Add main landmark and skip link","impact":"Screen reader navigation, keyboard access","problem":"HTML Inventory confirms missing `<main>` landmark and skip-to-content link; axe-core flags `landmark-one-main` and `region` violations.","solution":"Wrap primary content in `<main>` tag and add a skip link at the top of `<body>`:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n...\n<main id=\"main-content\">...</main>\n```"},{"priority":2,"category":"SEO","title":"Fix W3C validation errors and heading structure","impact":"Document outline, parser reliability","problem":"W3C reports 7 errors including parser recovery failure at line 100 and 2 `<h1>` elements.","solution":"Ensure exactly one `<h1>` per page. Fix malformed `<noscript>`/`<iframe>` nesting in `<head>` and remove invalid `name` attributes on `<meta>` tags."},{"priority":3,"category":"Security","title":"Implement Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing. Site signals show no auth/payments/UGC, so risk is lower but defense-in-depth is recommended.","solution":"Deploy a strict CSP with nonces for scripts:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\"\n```"}],"perfScore":96,"a11yScore":94,"bestPracticesScore":100,"seoScore":100,"securityScore":20}]}