# Audit Report: Perfectly formed web development team - gotoAndPlay
**Website:** https://play.ee/
**Date:** 02.09.2026
**Audit Coverage:** 100% — all sources returned data
**Confidence:** high
**Pages Audited (5 of 5):**
- https://play.ee/
- https://play.ee/web-development-case-studies/
- https://play.ee/software-development-work-index/
- https://play.ee/wordpress-support-service/
- https://play.ee/web-development-in-estonia/
## Summary of results
**Overall Score:** 75 / 100
**Status:** 🟡 **Needs Improvement**
Site overall 75 is the mean of 5 pages. Scores range 72 (https://play.ee/web-development-in-estonia/) → 78 (https://play.ee/web-development-case-studies/). Weakest page: Performance is excellent (PSI Mobile 95, LCP 2.7s), but security posture is critically weak with an HTTP redirect failure and a 20/100 header grade. Accessibility has serious issues including color contrast violations on 21+ nodes and a missing main landmark. W3C validation shows 7 errors with parser recovery failure, indicating broken DOM structure. The score reflects high technical performance undermined by significant security and accessibility debt.
### Per-page scores
🟡 **Needs Improvement** · https://play.ee/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 76 | 95 | 100 | 100 | 92 | 20 |
🟡 **Needs Improvement** · https://play.ee/web-development-case-studies/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 78 | 95 | 90 | 96 | 100 | 20 |
🟡 **Needs Improvement** · https://play.ee/software-development-work-index/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 74 | 94 | 90 | 96 | 100 | 20 |
🟡 **Needs Improvement** · https://play.ee/wordpress-support-service/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 74 | 93 | 91 | 100 | 100 | 20 |
🟡 **Needs Improvement** · https://play.ee/web-development-in-estonia/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 72 | 95 | 94 | 100 | 100 | 20 |
## PageSpeed Insights — Mobile vs Desktop
_Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._
| URL | Performance (M / D) | LCP (M / D) | CLS (M / D) |
| --- | --- | --- | --- |
| https://play.ee/ | **95** / 100 | **2.50 s** / 624 ms | 0.000 / **0.006** |
| https://play.ee/web-development-case-studies/ | **95** / 100 | **2.57 s** / 589 ms | 0.005 / **0.006** |
| https://play.ee/software-development-work-index/ | **94** / 100 | **2.56 s** / 513 ms | 0.000 / **0.004** |
| https://play.ee/wordpress-support-service/ | **93** / 100 | **2.56 s** / 591 ms | 0.000 / **0.001** |
| https://play.ee/web-development-in-estonia/ | **95** / 100 | **2.65 s** / 545 ms | 0.000 / **0.005** |
## Optimization Checklist
**2 of 2 passing** — 2 pass · 0 warn · 0 fail · 5 n/a
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | N/A | No raster
elements found (37 SVGs, 13 placeholders excluded). |
| Hero image eagerly loaded | N/A | No raster
elements found (37 SVGs, 13 placeholders excluded). |
| Hero is a real
(not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / ) | N/A | Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in | **Pass** | No render-blocking scripts in . |
## Fixes
### Priority 1: Critical
*Immediate action — impacts user experience, search rankings, or site safety.*
**1A. Enforce HTTPS redirect and add HSTS** `Security`
- **Impact:** Transport security, MITM protection
- **Problem:** HTTP does not redirect to HTTPS (target: none) and HSTS is missing, resulting in a Security Headers grade of 20/100.
- **Solution:**
Configure the web server to redirect all HTTP traffic to HTTPS and send HSTS headers:
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
```
**1B. Enforce HTTPS redirect** `Security`
- **Impact:** Transport security, data integrity
- **Problem:** HTTP traffic does not redirect to HTTPS (http://play.ee/... does not redirect), leaving users vulnerable to interception.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1C. Fix color contrast violations** `Accessibility`
- **Impact:** WCAG 1.4.3 compliance, readability
- **Problem:** axe-core reports 1 serious violation for color-contrast on multiple nodes (e.g., h1 > .heading__main).
- **Solution:**
Increase contrast ratio to at least 4.5:1 for normal text. Adjust CSS colors for `.heading__main` and `.card__meta` elements to meet WCAG AA standards.
**1D. Force HTTPS redirect and add baseline headers** `Security`
- **Impact:** Transport security, data integrity
- **Problem:** HTTP version does not redirect to HTTPS; HSTS and X-Content-Type-Options are missing (Security Headers grade 20/100).
- **Solution:**
Configure server to redirect all HTTP traffic to HTTPS. Add these headers:
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
Header always set X-Content-Type-Options "nosniff"
```
**1E. Enable HTTPS redirect** `Security`
- **Impact:** Security, User Trust
- **Problem:** HTTP does not redirect to HTTPS (http://play.ee/wordpress-support-service/ does not redirect to HTTPS).
- **Solution:**
Configure server to redirect all HTTP traffic to HTTPS (301). Ensure the redirect chain is clean and immediate.
**1F. Force HTTPS Redirect** `Security`
- **Impact:** Transport security, MITM protection
- **Problem:** Security Headers report states 'HTTPS redirect: ✗ http://play.ee/web-development-in-estonia/ does not redirect to HTTPS'.
- **Solution:**
Configure the web server (Apache/Nginx) to redirect all HTTP traffic to HTTPS:
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1G. Add HSTS Header** `Security`
- **Impact:** Protocol downgrade protection
- **Problem:** Security Headers grade is 20/100; 'strict-transport-security' is missing.
- **Solution:**
Send HSTS with max-age >= 1 year and includeSubDomains:
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
```
### Priority 2: Important
*Essential for compliance, user reach, and search visibility.*
**2A. Add X-Content-Type-Options header** `Security`
- **Impact:** MIME sniffing protection
- **Problem:** X-Content-Type-Options is missing from the response headers, leaving the site vulnerable to MIME-type sniffing attacks.
- **Solution:**
Add the following header to the server configuration:
```apache
Header always set X-Content-Type-Options "nosniff"
```
**2B. Fix W3C HTML validation errors** `SEO`
- **Impact:** Rendering consistency, SEO crawlability
- **Problem:** W3C validator reports 8 errors including parser recovery failure at line 107, empty href attributes, and stray end tags.
- **Solution:**
Review the HTML source around line 107 to fix:
- Remove empty `href` on `` elements.
- Ensure `