# Audit Report: Perfectly formed web development team - gotoAndPlay
**Website:** https://play.ee/
**Date:** 15.09.2026
**Audit Coverage:** 100% — all sources returned data
**Confidence:** high
**Pages Audited (5 of 5):**
- https://play.ee/
- https://play.ee/web-development-case-studies/
- https://play.ee/software-development-work-index/
- https://play.ee/wordpress-support-service/
- https://play.ee/web-development-in-estonia/
## Summary of results
**Overall Score:** 75 / 100
**Status:** 🟡 **Needs Improvement**
Site overall 75 is the mean of 5 pages. Scores range 72 (https://play.ee/software-development-work-index/) → 78 (https://play.ee/). Weakest page: PSI mobile performance is strong at 91, but the Security Headers grade of 20/100 and missing HTTP-to-HTTPS redirect create critical exposure regardless of site signals. W3C validation shows 7 errors including a parser recovery failure, and axe-core flags 1 serious contrast violation alongside missing landmarks. Image assets lack dimensions (53 images), risking CLS regression despite the current 0.039 score. Confidence is high due to complete tool coverage and consistent signals.
### Per-page scores
🟡 **Needs Improvement** · https://play.ee/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 78 | 95 | 100 | 100 | 92 | 20 |
🟡 **Needs Improvement** · https://play.ee/web-development-case-studies/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 75 | 95 | 90 | 96 | 100 | 20 |
🟡 **Needs Improvement** · https://play.ee/software-development-work-index/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 72 | 91 | 90 | 96 | 100 | 20 |
🟡 **Needs Improvement** · https://play.ee/wordpress-support-service/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 72 | 96 | 91 | 100 | 100 | 20 |
🟡 **Needs Improvement** · https://play.ee/web-development-in-estonia/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 76 | 96 | 94 | 100 | 100 | 20 |
## PageSpeed Insights — Mobile vs Desktop
_Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._
| URL | Performance (M / D) | LCP (M / D) | CLS (M / D) |
| --- | --- | --- | --- |
| https://play.ee/ | **95** / 100 | **2.51 s** / 547 ms | 0.001 / **0.005** |
| https://play.ee/web-development-case-studies/ | **95** / 99 | **2.57 s** / 582 ms | 0.005 / **0.005** |
| https://play.ee/software-development-work-index/ | **91** / 100 | **2.48 s** / 540 ms | **0.039** / 0.004 |
| https://play.ee/wordpress-support-service/ | **96** / 100 | **2.35 s** / 580 ms | **0.017** / 0.001 |
| https://play.ee/web-development-in-estonia/ | 96 / 96 | **2.40 s** / 555 ms | 0.002 / **0.005** |
## Optimization Checklist
**2 of 2 passing** — 2 pass · 0 warn · 0 fail · 5 n/a
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | N/A | No raster
elements found (37 SVGs, 13 placeholders excluded). |
| Hero image eagerly loaded | N/A | No raster
elements found (37 SVGs, 13 placeholders excluded). |
| Hero is a real
(not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / ) | N/A | Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in | **Pass** | No render-blocking scripts in . |
## Fixes
### Priority 1: Critical
*Immediate action — impacts user experience, search rankings, or site safety.*
**1A. Enforce HTTPS and add baseline security headers** `Security`
- **Impact:** Transport security, clickjacking, MIME sniffing
- **Problem:** Security Headers grade is 20/100; HTTP does not redirect to HTTPS, and HSTS, X-Content-Type-Options are missing.
- **Solution:**
Configure server to redirect all HTTP traffic to HTTPS (301). Add these headers:
```
Strict-Transport-Security: max-age=63072000; includeSubDomains
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
```
**1B. Force HTTPS redirect and add HSTS** `Security`
- **Impact:** Transport security, MITM protection
- **Problem:** HTTP does not redirect to HTTPS and HSTS is missing (Security Headers grade 20/100).
- **Solution:**
Configure server to redirect all HTTP traffic to HTTPS (301) and send HSTS header:
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1C. Fix W3C HTML Validation Errors** `SEO`
- **Impact:** Rendering consistency, SEO indexing
- **Problem:** 7 errors including parser recovery failure at line 100; iframe/noscript in head is invalid.
- **Solution:**
Move `