# Audit Report: Perfectly formed web development team - gotoAndPlay **Website:** https://play.ee/ **Date:** 02.09.2026 **Audit Coverage:** 100% — all sources returned data **Confidence:** high **Pages Audited (5 of 5):** - https://play.ee/ - https://play.ee/web-development-case-studies/ - https://play.ee/software-development-work-index/ - https://play.ee/wordpress-support-service/ - https://play.ee/web-development-in-estonia/ ## Summary of results **Overall Score:** 75 / 100 **Status:** 🟡 **Needs Improvement** Site overall 75 is the mean of 5 pages. Scores range 72 (https://play.ee/web-development-in-estonia/) → 78 (https://play.ee/web-development-case-studies/). Weakest page: Performance is excellent (PSI Mobile 95, LCP 2.7s), but security posture is critically weak with an HTTP redirect failure and a 20/100 header grade. Accessibility has serious issues including color contrast violations on 21+ nodes and a missing main landmark. W3C validation shows 7 errors with parser recovery failure, indicating broken DOM structure. The score reflects high technical performance undermined by significant security and accessibility debt. ### Per-page scores 🟡 **Needs Improvement** · https://play.ee/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 76 | 95 | 100 | 100 | 92 | 20 | 🟡 **Needs Improvement** · https://play.ee/web-development-case-studies/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 78 | 95 | 90 | 96 | 100 | 20 | 🟡 **Needs Improvement** · https://play.ee/software-development-work-index/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 74 | 94 | 90 | 96 | 100 | 20 | 🟡 **Needs Improvement** · https://play.ee/wordpress-support-service/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 74 | 93 | 91 | 100 | 100 | 20 | 🟡 **Needs Improvement** · https://play.ee/web-development-in-estonia/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 72 | 95 | 94 | 100 | 100 | 20 | ## PageSpeed Insights — Mobile vs Desktop _Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._ | URL | Performance (M / D) | LCP (M / D) | CLS (M / D) | | --- | --- | --- | --- | | https://play.ee/ | **95** / 100 | **2.50 s** / 624 ms | 0.000 / **0.006** | | https://play.ee/web-development-case-studies/ | **95** / 100 | **2.57 s** / 589 ms | 0.005 / **0.006** | | https://play.ee/software-development-work-index/ | **94** / 100 | **2.56 s** / 513 ms | 0.000 / **0.004** | | https://play.ee/wordpress-support-service/ | **93** / 100 | **2.56 s** / 591 ms | 0.000 / **0.001** | | https://play.ee/web-development-in-estonia/ | **95** / 100 | **2.65 s** / 545 ms | 0.000 / **0.005** | ## Optimization Checklist **2 of 2 passing** — 2 pass · 0 warn · 0 fail · 5 n/a | Item | Status | Detail | | --- | --- | --- | | Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) | | Images lazy-loaded | N/A | No raster elements found (37 SVGs, 13 placeholders excluded). | | Hero image eagerly loaded | N/A | No raster elements found (37 SVGs, 13 placeholders excluded). | | Hero is a real (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. | | Responsive images (srcset / ) | N/A | Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply. | | Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. | | JS scripts not blocking in | **Pass** | No render-blocking scripts in . | ## Fixes ### Priority 1: Critical *Immediate action — impacts user experience, search rankings, or site safety.* **1A. Enforce HTTPS redirect and add HSTS** `Security` - **Impact:** Transport security, MITM protection - **Problem:** HTTP does not redirect to HTTPS (target: none) and HSTS is missing, resulting in a Security Headers grade of 20/100. - **Solution:** Configure the web server to redirect all HTTP traffic to HTTPS and send HSTS headers: ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" ``` **1B. Enforce HTTPS redirect** `Security` - **Impact:** Transport security, data integrity - **Problem:** HTTP traffic does not redirect to HTTPS (http://play.ee/... does not redirect), leaving users vulnerable to interception. - **Solution:** Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS: ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1C. Fix color contrast violations** `Accessibility` - **Impact:** WCAG 1.4.3 compliance, readability - **Problem:** axe-core reports 1 serious violation for color-contrast on multiple nodes (e.g., h1 > .heading__main). - **Solution:** Increase contrast ratio to at least 4.5:1 for normal text. Adjust CSS colors for `.heading__main` and `.card__meta` elements to meet WCAG AA standards. **1D. Force HTTPS redirect and add baseline headers** `Security` - **Impact:** Transport security, data integrity - **Problem:** HTTP version does not redirect to HTTPS; HSTS and X-Content-Type-Options are missing (Security Headers grade 20/100). - **Solution:** Configure server to redirect all HTTP traffic to HTTPS. Add these headers: ```apache Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" Header always set X-Content-Type-Options "nosniff" ``` **1E. Enable HTTPS redirect** `Security` - **Impact:** Security, User Trust - **Problem:** HTTP does not redirect to HTTPS (http://play.ee/wordpress-support-service/ does not redirect to HTTPS). - **Solution:** Configure server to redirect all HTTP traffic to HTTPS (301). Ensure the redirect chain is clean and immediate. **1F. Force HTTPS Redirect** `Security` - **Impact:** Transport security, MITM protection - **Problem:** Security Headers report states 'HTTPS redirect: ✗ http://play.ee/web-development-in-estonia/ does not redirect to HTTPS'. - **Solution:** Configure the web server (Apache/Nginx) to redirect all HTTP traffic to HTTPS: ```apache RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1G. Add HSTS Header** `Security` - **Impact:** Protocol downgrade protection - **Problem:** Security Headers grade is 20/100; 'strict-transport-security' is missing. - **Solution:** Send HSTS with max-age >= 1 year and includeSubDomains: ```apache Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" ``` ### Priority 2: Important *Essential for compliance, user reach, and search visibility.* **2A. Add X-Content-Type-Options header** `Security` - **Impact:** MIME sniffing protection - **Problem:** X-Content-Type-Options is missing from the response headers, leaving the site vulnerable to MIME-type sniffing attacks. - **Solution:** Add the following header to the server configuration: ```apache Header always set X-Content-Type-Options "nosniff" ``` **2B. Fix W3C HTML validation errors** `SEO` - **Impact:** Rendering consistency, SEO crawlability - **Problem:** W3C validator reports 8 errors including parser recovery failure at line 107, empty href attributes, and stray end tags. - **Solution:** Review the HTML source around line 107 to fix: - Remove empty `href` on `` elements. - Ensure `` out of the `` section. Ensure `` tags do not use invalid attributes like `name` where `property` is required. ### Priority 3: Best Practice *Recommended for long-term maintainability.* **3A. Improve link text descriptiveness** `SEO` - **Impact:** SEO `link-text` audit, User navigation - **Problem:** PSI SEO audit fails `link-text` with 9 links using vague text like "read more". - **Solution:** Update anchor text to describe the destination: - Change "read more" to "Read more about [Topic]". - Use `aria-label` if visual text must remain short: `Read more`. **3B. Add explicit width and height to images** `Performance` - **Impact:** CLS prevention, Layout stability - **Problem:** HTML Inventory shows 50 images without width/height attributes, risking layout shifts despite current CLS of 0.000. - **Solution:** Add `width` and `height` attributes to all `` tags based on their intrinsic dimensions: ```html ... ``` **3C. Optimize Largest Contentful Paint** `Performance` - **Impact:** LCP metric (2.6 s) - **Problem:** LCP is 2.6 s on mobile, slightly above the 2.5 s good threshold. - **Solution:** Preload the hero image or critical CSS. Ensure the LCP element (likely the h1 or hero image) is not blocked by render-blocking resources. **3D. Add image dimensions** `Best Practices` - **Impact:** CLS prevention - **Problem:** 56 images lack explicit width/height attributes, risking layout shifts. - **Solution:** Add `width` and `height` attributes to all `` tags matching the intrinsic dimensions of the source files. **3E. Add image dimensions and lazy loading** `Performance` - **Impact:** CLS, Layout stability - **Problem:** 53 images lack width/height attributes and loading="lazy"; CLS is currently 0.000 but at risk. - **Solution:** Add explicit `width` and `height` attributes to all `` tags. Add `loading="lazy"` to images below the fold: ```html ... ``` **3F. Disambiguate vague link text** `SEO` - **Impact:** Screen reader usability, SEO anchor text - **Problem:** Repeated vague text like 'visit the website' (×21) and 'read more' (×15) found in HTML Inventory. - **Solution:** Update link text to be descriptive of the destination, e.g., 'Visit Tallink website' instead of 'visit the website', or use `aria-label` to clarify context. **3G. Remove unused JavaScript** `Performance` - **Impact:** JS Execution Time - **Problem:** 23 KB unused JS identified in PSI findings. - **Solution:** Audit and remove unused code or use code splitting. **3H. Implement Content Security Policy (CSP)** `Security` - **Impact:** XSS defense-in-depth - **Problem:** CSP is missing (only `frame-ancestors` set). Site signals indicate no auth/payments, so this is lower priority per rubric. - **Solution:** Deploy a strict CSP with nonces for scripts: ```apache Header always set Content-Security-Policy "default-src 'self'; script-src 'nonce-{RANDOM}' 'strict-dynamic'; object-src 'none';" ```