{"url":"https://play.ee/","date":"2026-09-02","siteName":"Perfectly formed web development team - gotoAndPlay","overall":75,"reasoning":"Site overall 75 is the mean of 5 pages. Scores range 72 (https://play.ee/web-development-in-estonia/) → 78 (https://play.ee/web-development-case-studies/). Weakest page: Performance is excellent (PSI Mobile 95, LCP 2.7s), but security posture is critically weak with an HTTP redirect failure and a 20/100 header grade. Accessibility has serious issues including color contrast violations on 21+ nodes and a missing main landmark. W3C validation shows 7 errors with parser recovery failure, indicating broken DOM structure. The score reflects high technical performance undermined by significant security and accessibility debt.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS redirect and add HSTS","impact":"Transport security, MITM protection","problem":"HTTP does not redirect to HTTPS (target: none) and HSTS is missing, resulting in a Security Headers grade of 20/100.","solution":"Configure the web server to redirect all HTTP traffic to HTTPS and send HSTS headers:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":1,"category":"Security","title":"Enforce HTTPS redirect","impact":"Transport security, data integrity","problem":"HTTP traffic does not redirect to HTTPS (http://play.ee/... does not redirect), leaving users vulnerable to interception.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Accessibility","title":"Fix color contrast violations","impact":"WCAG 1.4.3 compliance, readability","problem":"axe-core reports 1 serious violation for color-contrast on multiple nodes (e.g., h1 > .heading__main).","solution":"Increase contrast ratio to at least 4.5:1 for normal text. Adjust CSS colors for `.heading__main` and `.card__meta` elements to meet WCAG AA standards."},{"priority":1,"category":"Security","title":"Force HTTPS redirect and add baseline headers","impact":"Transport security, data integrity","problem":"HTTP version does not redirect to HTTPS; HSTS and X-Content-Type-Options are missing (Security Headers grade 20/100).","solution":"Configure server to redirect all HTTP traffic to HTTPS. Add these headers:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":1,"category":"Security","title":"Enable HTTPS redirect","impact":"Security, User Trust","problem":"HTTP does not redirect to HTTPS (http://play.ee/wordpress-support-service/ does not redirect to HTTPS).","solution":"Configure server to redirect all HTTP traffic to HTTPS (301). Ensure the redirect chain is clean and immediate."},{"priority":1,"category":"Security","title":"Force HTTPS Redirect","impact":"Transport security, MITM protection","problem":"Security Headers report states 'HTTPS redirect: ✗ http://play.ee/web-development-in-estonia/ does not redirect to HTTPS'.","solution":"Configure the web server (Apache/Nginx) to redirect all HTTP traffic to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Security","title":"Add HSTS Header","impact":"Protocol downgrade protection","problem":"Security Headers grade is 20/100; 'strict-transport-security' is missing.","solution":"Send HSTS with max-age >= 1 year and includeSubDomains:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":2,"category":"Security","title":"Add X-Content-Type-Options header","impact":"MIME sniffing protection","problem":"X-Content-Type-Options is missing from the response headers, leaving the site vulnerable to MIME-type sniffing attacks.","solution":"Add the following header to the server configuration:\n```apache\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"SEO","title":"Fix W3C HTML validation errors","impact":"Rendering consistency, SEO crawlability","problem":"W3C validator reports 8 errors including parser recovery failure at line 107, empty href attributes, and stray end tags.","solution":"Review the HTML source around line 107 to fix:\n- Remove empty `href` on `<link>` elements.\n- Ensure `<iframe>` is not placed inside `<noscript>` within `<head>`.\n- Remove stray `</noscript>` and `</head>` tags.\n- Correct `<meta>` attributes to comply with HTML5 spec."},{"priority":2,"category":"Accessibility","title":"Add main landmark and skip-to-content link","impact":"Screen reader navigation, WCAG 2.4.1","problem":"HTML Inventory shows `main` landmark is missing and no skip-to-content link exists; axe reports `region` and `landmark-unique` violations.","solution":"Wrap the primary content in `<main>` and add a skip link at the top of the `<body>`:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n<!-- ... header nav ... -->\n<main id=\"main-content\">\n  <!-- page content -->\n</main>\n```"},{"priority":2,"category":"Security","title":"Add HSTS and strengthen CSP","impact":"Protocol downgrade protection, XSS defense","problem":"HSTS is missing (score 20/100). CSP only has `frame-ancestors` without `default-src`.","solution":"Add HSTS header with preload:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```\nExpand CSP to include `default-src 'self'` and `object-src 'none'`."},{"priority":2,"category":"Accessibility","title":"Add main landmark and skip link","impact":"Screen reader navigation, WCAG 2.4.1","problem":"HTML Inventory shows `main` landmark is missing; axe-core reports `region` violations.","solution":"Wrap primary content in `<main>` tag. Add a skip-to-content link at the top of the page:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n<div id=\"main-content\" role=\"main\">...</div>\n```"},{"priority":2,"category":"Accessibility","title":"Fix contrast and add main landmark","impact":"WCAG 1.4.3, 1.3.1","problem":"1 serious axe violation (color-contrast on h1/span); HTML Inventory confirms missing <main> landmark and skip-to-content link.","solution":"- Adjust `.heading__main` and `p > span` colors to meet 4.5:1 contrast.\n- Wrap primary content in `<main>`.\n- Add `<a href=\"#content\" class=\"skip-link\">Skip to content</a>` before navigation."},{"priority":2,"category":"SEO","title":"Resolve W3C validation errors","impact":"Parsing stability, SEO rendering","problem":"8 validation errors including empty href, stray tags, and parser recovery failure at line 106.","solution":"- Remove empty `href=\"\"` on `<link>` tags.\n- Fix `<noscript>` nesting (iframe inside noscript in head is invalid).\n- Ensure `<meta>` tags are in valid locations (head only)."},{"priority":2,"category":"Security","title":"Add HSTS and X-Content-Type-Options","impact":"Security Headers","problem":"HSTS and X-Content-Type-Options are missing; Security Headers grade is 20/100.","solution":"Add headers:\n```\nStrict-Transport-Security: max-age=63072000; includeSubDomains\nX-Content-Type-Options: nosniff\n```"},{"priority":2,"category":"Accessibility","title":"Fix color contrast and link names","impact":"WCAG 1.4.3, 2.4.4","problem":"2 serious axe violations: color-contrast (16 nodes) and link-name (10 nodes).","solution":"Increase contrast ratios to 4.5:1; add aria-label or text to icon links."},{"priority":2,"category":"SEO","title":"Fix HTML validation errors","impact":"Parsing, SEO","problem":"7 W3C errors including iframe in noscript in head, stray end tags, meta attribute issues.","solution":"Move iframe out of head; fix meta tag attributes; ensure proper nesting."},{"priority":2,"category":"Accessibility","title":"Fix Color Contrast Violations","impact":"WCAG 1.4.3 compliance, readability","problem":"axe-core reports 1 serious violation with 21+ nodes failing contrast (e.g., `.focus__heading > h1`).","solution":"Increase contrast ratio to at least 4.5:1 for normal text. Adjust CSS colors for `.heading__main` and `.heading__small` elements to meet WCAG AA standards."},{"priority":2,"category":"Accessibility","title":"Add Main Landmark and Fix H1 Structure","impact":"Screen reader navigation, document outline","problem":"HTML Inventory shows 'main: missing' and '2 <h1> elements'; axe-core flags 'landmark-one-main'.","solution":"Wrap primary content in `<main>` tag and ensure only one `<h1>` exists per page:\n```html\n<main id=\"main-content\">\n  <h1>Expert web development in Estonia</h1>\n  <!-- content -->\n</main>\n```"},{"priority":2,"category":"SEO","title":"Resolve W3C HTML Validation Errors","impact":"Parsing reliability, SEO indexing","problem":"W3C Validator reports 7 errors including 'Bad start tag in iframe in noscript in head' and parser recovery failure at line 100.","solution":"Move `<noscript><iframe>...</iframe></noscript>` out of the `<head>` section. Ensure `<meta>` tags do not use invalid attributes like `name` where `property` is required."},{"priority":3,"category":"SEO","title":"Improve link text descriptiveness","impact":"SEO `link-text` audit, User navigation","problem":"PSI SEO audit fails `link-text` with 9 links using vague text like \"read more\".","solution":"Update anchor text to describe the destination:\n- Change \"read more\" to \"Read more about [Topic]\".\n- Use `aria-label` if visual text must remain short: `<a href=\"...\" aria-label=\"Read more about our case studies\">Read more</a>`."},{"priority":3,"category":"Performance","title":"Add explicit width and height to images","impact":"CLS prevention, Layout stability","problem":"HTML Inventory shows 50 images without width/height attributes, risking layout shifts despite current CLS of 0.000.","solution":"Add `width` and `height` attributes to all `<img>` tags based on their intrinsic dimensions:\n```html\n<img src=\"image.jpg\" alt=\"...\" width=\"800\" height=\"600\">\n```"},{"priority":3,"category":"Performance","title":"Optimize Largest Contentful Paint","impact":"LCP metric (2.6 s)","problem":"LCP is 2.6 s on mobile, slightly above the 2.5 s good threshold.","solution":"Preload the hero image or critical CSS. Ensure the LCP element (likely the h1 or hero image) is not blocked by render-blocking resources."},{"priority":3,"category":"Best Practices","title":"Add image dimensions","impact":"CLS prevention","problem":"56 images lack explicit width/height attributes, risking layout shifts.","solution":"Add `width` and `height` attributes to all `<img>` tags matching the intrinsic dimensions of the source files."},{"priority":3,"category":"Performance","title":"Add image dimensions and lazy loading","impact":"CLS, Layout stability","problem":"53 images lack width/height attributes and loading=\"lazy\"; CLS is currently 0.000 but at risk.","solution":"Add explicit `width` and `height` attributes to all `<img>` tags. Add `loading=\"lazy\"` to images below the fold:\n```html\n<img src=\"...\" alt=\"...\" width=\"800\" height=\"600\" loading=\"lazy\">\n```"},{"priority":3,"category":"SEO","title":"Disambiguate vague link text","impact":"Screen reader usability, SEO anchor text","problem":"Repeated vague text like 'visit the website' (×21) and 'read more' (×15) found in HTML Inventory.","solution":"Update link text to be descriptive of the destination, e.g., 'Visit Tallink website' instead of 'visit the website', or use `aria-label` to clarify context."},{"priority":3,"category":"Performance","title":"Remove unused JavaScript","impact":"JS Execution Time","problem":"23 KB unused JS identified in PSI findings.","solution":"Audit and remove unused code or use code splitting."},{"priority":3,"category":"Security","title":"Implement Content Security Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing (only `frame-ancestors` set). Site signals indicate no auth/payments, so this is lower priority per rubric.","solution":"Deploy a strict CSP with nonces for scripts:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{RANDOM}' 'strict-dynamic'; object-src 'none';\"\n```"}],"coverage":{"pct":100,"missing":[]},"siteSummary":{"pagesAudited":5,"pagesAttempted":5,"urls":["https://play.ee/","https://play.ee/web-development-case-studies/","https://play.ee/software-development-work-index/","https://play.ee/wordpress-support-service/","https://play.ee/web-development-in-estonia/"]},"psiSnapshot":{"rows":[{"pageUrl":"https://play.ee/","perfMobile":95,"perfDesktop":100,"lcpMobileMs":2505,"lcpDesktopMs":624,"clsMobile":0,"clsDesktop":0.006012985631903462},{"pageUrl":"https://play.ee/web-development-case-studies/","perfMobile":95,"perfDesktop":100,"lcpMobileMs":2570,"lcpDesktopMs":589,"clsMobile":0.004538940511363545,"clsDesktop":0.005944180329960488},{"pageUrl":"https://play.ee/software-development-work-index/","perfMobile":94,"perfDesktop":100,"lcpMobileMs":2557,"lcpDesktopMs":513.2195519606005,"clsMobile":0,"clsDesktop":0.004172756726217496},{"pageUrl":"https://play.ee/wordpress-support-service/","perfMobile":93,"perfDesktop":100,"lcpMobileMs":2565,"lcpDesktopMs":590.7148678677719,"clsMobile":0,"clsDesktop":0.0014799110147398226},{"pageUrl":"https://play.ee/web-development-in-estonia/","perfMobile":95,"perfDesktop":100,"lcpMobileMs":2653,"lcpDesktopMs":544.7425095435757,"clsMobile":0,"clsDesktop":0.004754761755267665}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket)","evidence":["HTML markers: WP Rocket","generator: WP Rocket 3.23.3.3"]},{"id":"lazyload","title":"Images lazy-loaded","status":"n/a","detail":"No raster <img> elements found (37 SVGs, 13 placeholders excluded).","evidence":[]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"n/a","detail":"No raster <img> elements found (37 SVGs, 13 placeholders excluded).","evidence":[]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"n/a","detail":"No CSS background-images detected on raster-image-eligible elements.","evidence":[]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"n/a","detail":"Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply.","evidence":[]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"n/a","detail":"Too few raster images to evaluate srcset width variety.","evidence":[]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"pass","detail":"No render-blocking scripts in <head>.","evidence":[]}],"summary":{"passed":2,"warned":0,"failed":0,"notApplicable":5},"priorities":[]},"perPageOverall":[{"url":"https://play.ee/","overall":76,"reasoning":"PSI mobile performance is excellent at 95 with LCP 2.5 s and TTFB 40 ms, but the Security Headers grade is critically low at 20/100 due to missing HTTPS redirect and HSTS. W3C validation reports 8 errors including a parser recovery failure at line 107, indicating structural HTML risks. Accessibility is mostly clean with 0 critical axe violations, though 2 moderate issues exist regarding landmarks. The site is a web development agency portfolio with no auth or payment signals, lowering CSP priority but not baseline header requirements.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS redirect and add HSTS","impact":"Transport security, MITM protection","problem":"HTTP does not redirect to HTTPS (target: none) and HSTS is missing, resulting in a Security Headers grade of 20/100.","solution":"Configure the web server to redirect all HTTP traffic to HTTPS and send HSTS headers:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":2,"category":"Security","title":"Add X-Content-Type-Options header","impact":"MIME sniffing protection","problem":"X-Content-Type-Options is missing from the response headers, leaving the site vulnerable to MIME-type sniffing attacks.","solution":"Add the following header to the server configuration:\n```apache\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"SEO","title":"Fix W3C HTML validation errors","impact":"Rendering consistency, SEO crawlability","problem":"W3C validator reports 8 errors including parser recovery failure at line 107, empty href attributes, and stray end tags.","solution":"Review the HTML source around line 107 to fix:\n- Remove empty `href` on `<link>` elements.\n- Ensure `<iframe>` is not placed inside `<noscript>` within `<head>`.\n- Remove stray `</noscript>` and `</head>` tags.\n- Correct `<meta>` attributes to comply with HTML5 spec."},{"priority":2,"category":"Accessibility","title":"Add main landmark and skip-to-content link","impact":"Screen reader navigation, WCAG 2.4.1","problem":"HTML Inventory shows `main` landmark is missing and no skip-to-content link exists; axe reports `region` and `landmark-unique` violations.","solution":"Wrap the primary content in `<main>` and add a skip link at the top of the `<body>`:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n<!-- ... header nav ... -->\n<main id=\"main-content\">\n  <!-- page content -->\n</main>\n```"},{"priority":3,"category":"SEO","title":"Improve link text descriptiveness","impact":"SEO `link-text` audit, User navigation","problem":"PSI SEO audit fails `link-text` with 9 links using vague text like \"read more\".","solution":"Update anchor text to describe the destination:\n- Change \"read more\" to \"Read more about [Topic]\".\n- Use `aria-label` if visual text must remain short: `<a href=\"...\" aria-label=\"Read more about our case studies\">Read more</a>`."},{"priority":3,"category":"Performance","title":"Add explicit width and height to images","impact":"CLS prevention, Layout stability","problem":"HTML Inventory shows 50 images without width/height attributes, risking layout shifts despite current CLS of 0.000.","solution":"Add `width` and `height` attributes to all `<img>` tags based on their intrinsic dimensions:\n```html\n<img src=\"image.jpg\" alt=\"...\" width=\"800\" height=\"600\">\n```"}],"perfScore":95,"a11yScore":100,"bestPracticesScore":100,"seoScore":92,"securityScore":20},{"url":"https://play.ee/web-development-case-studies/","overall":78,"reasoning":"Mobile performance is strong (95/100) with LCP 2.6 s and CLS 0.005, but security posture is critically weak (20/100) due to missing HTTPS enforcement and HSTS. Accessibility has a serious color-contrast violation and missing main landmark, dragging the score down despite a 90/100 PSI accessibility score. W3C validation shows 7 errors with parser recovery failure, indicating structural HTML issues. The overall score reflects high technical performance offset by foundational security and code quality gaps.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS redirect","impact":"Transport security, data integrity","problem":"HTTP traffic does not redirect to HTTPS (http://play.ee/... does not redirect), leaving users vulnerable to interception.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Accessibility","title":"Fix color contrast violations","impact":"WCAG 1.4.3 compliance, readability","problem":"axe-core reports 1 serious violation for color-contrast on multiple nodes (e.g., h1 > .heading__main).","solution":"Increase contrast ratio to at least 4.5:1 for normal text. Adjust CSS colors for `.heading__main` and `.card__meta` elements to meet WCAG AA standards."},{"priority":2,"category":"Security","title":"Add HSTS and strengthen CSP","impact":"Protocol downgrade protection, XSS defense","problem":"HSTS is missing (score 20/100). CSP only has `frame-ancestors` without `default-src`.","solution":"Add HSTS header with preload:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```\nExpand CSP to include `default-src 'self'` and `object-src 'none'`."},{"priority":2,"category":"SEO","title":"Fix W3C HTML validation errors","impact":"DOM parsing, SEO indexing","problem":"7 validation errors including parser recovery failure at line 105 (bad iframe/noscript structure).","solution":"Correct the `<noscript><iframe>` placement in `<head>`. Ensure `<meta>` tags do not use invalid `name` attributes in this context. Validate HTML after changes."},{"priority":2,"category":"Accessibility","title":"Add main landmark and skip link","impact":"Screen reader navigation, WCAG 2.4.1","problem":"HTML Inventory shows `main` landmark is missing; axe-core reports `region` violations.","solution":"Wrap primary content in `<main>` tag. Add a skip-to-content link at the top of the page:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n<div id=\"main-content\" role=\"main\">...</div>\n```"},{"priority":3,"category":"Performance","title":"Optimize Largest Contentful Paint","impact":"LCP metric (2.6 s)","problem":"LCP is 2.6 s on mobile, slightly above the 2.5 s good threshold.","solution":"Preload the hero image or critical CSS. Ensure the LCP element (likely the h1 or hero image) is not blocked by render-blocking resources."},{"priority":3,"category":"Best Practices","title":"Add image dimensions","impact":"CLS prevention","problem":"56 images lack explicit width/height attributes, risking layout shifts.","solution":"Add `width` and `height` attributes to all `<img>` tags matching the intrinsic dimensions of the source files."}],"perfScore":95,"a11yScore":90,"bestPracticesScore":96,"seoScore":100,"securityScore":20},{"url":"https://play.ee/software-development-work-index/","overall":74,"reasoning":"Performance is excellent (PSI Mobile 94, LCP 2.6 s), but security configuration is critically weak (HTTP does not redirect to HTTPS, Headers grade 20/100). Accessibility has one serious violation (contrast) and missing landmarks, while W3C validation shows 8 errors with parser recovery failure. Image assets lack dimensions and lazy loading, posing CLS risks despite current 0.000 CLS. The score reflects high performance offset by significant security and structural HTML debt.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Force HTTPS redirect and add baseline headers","impact":"Transport security, data integrity","problem":"HTTP version does not redirect to HTTPS; HSTS and X-Content-Type-Options are missing (Security Headers grade 20/100).","solution":"Configure server to redirect all HTTP traffic to HTTPS. Add these headers:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Accessibility","title":"Fix contrast and add main landmark","impact":"WCAG 1.4.3, 1.3.1","problem":"1 serious axe violation (color-contrast on h1/span); HTML Inventory confirms missing <main> landmark and skip-to-content link.","solution":"- Adjust `.heading__main` and `p > span` colors to meet 4.5:1 contrast.\n- Wrap primary content in `<main>`.\n- Add `<a href=\"#content\" class=\"skip-link\">Skip to content</a>` before navigation."},{"priority":2,"category":"SEO","title":"Resolve W3C validation errors","impact":"Parsing stability, SEO rendering","problem":"8 validation errors including empty href, stray tags, and parser recovery failure at line 106.","solution":"- Remove empty `href=\"\"` on `<link>` tags.\n- Fix `<noscript>` nesting (iframe inside noscript in head is invalid).\n- Ensure `<meta>` tags are in valid locations (head only)."},{"priority":3,"category":"Performance","title":"Add image dimensions and lazy loading","impact":"CLS, Layout stability","problem":"53 images lack width/height attributes and loading=\"lazy\"; CLS is currently 0.000 but at risk.","solution":"Add explicit `width` and `height` attributes to all `<img>` tags. Add `loading=\"lazy\"` to images below the fold:\n```html\n<img src=\"...\" alt=\"...\" width=\"800\" height=\"600\" loading=\"lazy\">\n```"},{"priority":3,"category":"SEO","title":"Disambiguate vague link text","impact":"Screen reader usability, SEO anchor text","problem":"Repeated vague text like 'visit the website' (×21) and 'read more' (×15) found in HTML Inventory.","solution":"Update link text to be descriptive of the destination, e.g., 'Visit Tallink website' instead of 'visit the website', or use `aria-label` to clarify context."}],"perfScore":94,"a11yScore":90,"bestPracticesScore":96,"seoScore":100,"securityScore":20},{"url":"https://play.ee/wordpress-support-service/","overall":74,"reasoning":"PSI mobile 93 indicates strong performance, but LCP 2.6s is in warning range. Security is critically weak (20/100) with no HTTPS redirect and missing HSTS. Accessibility has serious violations (color-contrast, link-name) despite a 91 score. HTML validation shows 7 errors including parser recovery failure. The overall score reflects strong performance weighed down by critical security gaps and accessibility failures.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enable HTTPS redirect","impact":"Security, User Trust","problem":"HTTP does not redirect to HTTPS (http://play.ee/wordpress-support-service/ does not redirect to HTTPS).","solution":"Configure server to redirect all HTTP traffic to HTTPS (301). Ensure the redirect chain is clean and immediate."},{"priority":2,"category":"Security","title":"Add HSTS and X-Content-Type-Options","impact":"Security Headers","problem":"HSTS and X-Content-Type-Options are missing; Security Headers grade is 20/100.","solution":"Add headers:\n```\nStrict-Transport-Security: max-age=63072000; includeSubDomains\nX-Content-Type-Options: nosniff\n```"},{"priority":2,"category":"Accessibility","title":"Fix color contrast and link names","impact":"WCAG 1.4.3, 2.4.4","problem":"2 serious axe violations: color-contrast (16 nodes) and link-name (10 nodes).","solution":"Increase contrast ratios to 4.5:1; add aria-label or text to icon links."},{"priority":2,"category":"Accessibility","title":"Add main landmark and skip-to-content link","impact":"Navigation, Screen Readers","problem":"Missing main landmark and skip-to-content link; 2 moderate axe violations (landmark-unique, region).","solution":"Wrap main content in <main>; add <a href=\"#main\" class=\"skip-link\">Skip to content</a>."},{"priority":2,"category":"SEO","title":"Fix HTML validation errors","impact":"Parsing, SEO","problem":"7 W3C errors including iframe in noscript in head, stray end tags, meta attribute issues.","solution":"Move iframe out of head; fix meta tag attributes; ensure proper nesting."},{"priority":3,"category":"Performance","title":"Remove unused JavaScript","impact":"JS Execution Time","problem":"23 KB unused JS identified in PSI findings.","solution":"Audit and remove unused code or use code splitting."},{"priority":3,"category":"Performance","title":"Add image dimensions and lazy loading","impact":"CLS, Load Performance","problem":"31 images without width/height or loading=\"lazy\".","solution":"Add width/height attributes; add loading=\"lazy\" to below-fold images."}],"perfScore":93,"a11yScore":91,"bestPracticesScore":100,"seoScore":100,"securityScore":20},{"url":"https://play.ee/web-development-in-estonia/","overall":72,"reasoning":"Performance is excellent (PSI Mobile 95, LCP 2.7s), but security posture is critically weak with an HTTP redirect failure and a 20/100 header grade. Accessibility has serious issues including color contrast violations on 21+ nodes and a missing main landmark. W3C validation shows 7 errors with parser recovery failure, indicating broken DOM structure. The score reflects high technical performance undermined by significant security and accessibility debt.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Force HTTPS Redirect","impact":"Transport security, MITM protection","problem":"Security Headers report states 'HTTPS redirect: ✗ http://play.ee/web-development-in-estonia/ does not redirect to HTTPS'.","solution":"Configure the web server (Apache/Nginx) to redirect all HTTP traffic to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Security","title":"Add HSTS Header","impact":"Protocol downgrade protection","problem":"Security Headers grade is 20/100; 'strict-transport-security' is missing.","solution":"Send HSTS with max-age >= 1 year and includeSubDomains:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":2,"category":"Accessibility","title":"Fix Color Contrast Violations","impact":"WCAG 1.4.3 compliance, readability","problem":"axe-core reports 1 serious violation with 21+ nodes failing contrast (e.g., `.focus__heading > h1`).","solution":"Increase contrast ratio to at least 4.5:1 for normal text. Adjust CSS colors for `.heading__main` and `.heading__small` elements to meet WCAG AA standards."},{"priority":2,"category":"Accessibility","title":"Add Main Landmark and Fix H1 Structure","impact":"Screen reader navigation, document outline","problem":"HTML Inventory shows 'main: missing' and '2 <h1> elements'; axe-core flags 'landmark-one-main'.","solution":"Wrap primary content in `<main>` tag and ensure only one `<h1>` exists per page:\n```html\n<main id=\"main-content\">\n  <h1>Expert web development in Estonia</h1>\n  <!-- content -->\n</main>\n```"},{"priority":2,"category":"SEO","title":"Resolve W3C HTML Validation Errors","impact":"Parsing reliability, SEO indexing","problem":"W3C Validator reports 7 errors including 'Bad start tag in iframe in noscript in head' and parser recovery failure at line 100.","solution":"Move `<noscript><iframe>...</iframe></noscript>` out of the `<head>` section. Ensure `<meta>` tags do not use invalid attributes like `name` where `property` is required."},{"priority":3,"category":"Security","title":"Implement Content Security Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing (only `frame-ancestors` set). Site signals indicate no auth/payments, so this is lower priority per rubric.","solution":"Deploy a strict CSP with nonces for scripts:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{RANDOM}' 'strict-dynamic'; object-src 'none';\"\n```"}],"perfScore":95,"a11yScore":94,"bestPracticesScore":100,"seoScore":100,"securityScore":20}]}