{"url":"https://play.ee/","date":"2026-09-15","siteName":"Perfectly formed web development team - gotoAndPlay","overall":75,"reasoning":"Site overall 75 is the mean of 5 pages. Scores range 72 (https://play.ee/software-development-work-index/) → 78 (https://play.ee/). Weakest page: PSI mobile performance is strong at 91, but the Security Headers grade of 20/100 and missing HTTP-to-HTTPS redirect create critical exposure regardless of site signals. W3C validation shows 7 errors including a parser recovery failure, and axe-core flags 1 serious contrast violation alongside missing landmarks. Image assets lack dimensions (53 images), risking CLS regression despite the current 0.039 score. Confidence is high due to complete tool coverage and consistent signals.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS and add baseline security headers","impact":"Transport security, clickjacking, MIME sniffing","problem":"Security Headers grade is 20/100; HTTP does not redirect to HTTPS, and HSTS, X-Content-Type-Options are missing.","solution":"Configure server to redirect all HTTP traffic to HTTPS (301). Add these headers:\n```\nStrict-Transport-Security: max-age=63072000; includeSubDomains\nX-Content-Type-Options: nosniff\nX-Frame-Options: SAMEORIGIN\n```"},{"priority":1,"category":"Security","title":"Force HTTPS redirect and add HSTS","impact":"Transport security, MITM protection","problem":"HTTP does not redirect to HTTPS and HSTS is missing (Security Headers grade 20/100).","solution":"Configure server to redirect all HTTP traffic to HTTPS (301) and send HSTS header:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"SEO","title":"Fix W3C HTML Validation Errors","impact":"Rendering consistency, SEO indexing","problem":"7 errors including parser recovery failure at line 100; iframe/noscript in head is invalid.","solution":"Move `<noscript><iframe>` block out of `<head>` or use valid placement. Fix meta tag attributes (`name` vs `property`). Ensure `<body>` opens after `<head>` closes properly."},{"priority":1,"category":"Security","title":"Enforce HTTPS redirect and add HSTS","impact":"Transport security, MITM protection","problem":"HTTP does not redirect to HTTPS (Security Headers finding) and HSTS is missing, leaving initial requests vulnerable.","solution":"Configure server to redirect all HTTP traffic to HTTPS (301) and send HSTS header:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Security","title":"Add X-Content-Type-Options and X-Frame-Options","impact":"MIME sniffing, clickjacking","problem":"X-Content-Type-Options and X-Frame-Options are missing (Security Headers grade 20/100).","solution":"Add these headers to all responses:\n```apache\nHeader always set X-Content-Type-Options \"nosniff\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\n```"},{"priority":1,"category":"Security","title":"Enforce HTTPS and add HSTS","impact":"Transport security, data integrity","problem":"HTTP does not redirect to HTTPS and HSTS is missing (Security Headers grade 20/100).","solution":"Configure server to redirect all HTTP traffic to HTTPS and add HSTS header:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":1,"category":"Accessibility","title":"Fix contrast and link names","impact":"WCAG 1.4.3, 2.4.4 compliance","problem":"2 serious axe violations: color-contrast on `.button--tertiary` and link-name on logo links.","solution":"- Increase contrast ratio for `.button--tertiary` text to ≥4.5:1.\n- Add `aria-label` to logo links (e.g., `<a aria-label=\"Client Logo\">`)."},{"priority":1,"category":"Security","title":"Force HTTPS Redirect","impact":"Transport security, data integrity","problem":"HTTP does not redirect to HTTPS (http://play.ee... does not redirect to HTTPS).","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS.\n\n**Apache (.htaccess):**\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":2,"category":"SEO","title":"Fix W3C HTML validation errors","impact":"Parser recovery, document structure","problem":"W3C Validator reports 7 errors including 'Cannot recover after last error' at line 101 and invalid iframe/noscript placement in head.","solution":"Move `<noscript><iframe>` tags out of the `<head>` section. Ensure all `<meta>` tags are valid and remove stray end tags. Fix the parser recovery issue to ensure full document parsing."},{"priority":2,"category":"Accessibility","title":"Add skip link and main landmark","impact":"Keyboard navigation, screen reader flow","problem":"HTML Inventory shows 'main' landmark missing and no skip-to-content link; axe-core flags 'region' violations.","solution":"Add a skip link at the top of the page:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n```\nWrap primary content in `<main id=\"main-content\">`."},{"priority":2,"category":"Accessibility","title":"Fix Color Contrast and Add Main Landmark","impact":"WCAG 1.4.3, 1.3.1","problem":"1 serious axe violation on color-contrast (h1, cards); Document lacks `main` landmark.","solution":"- Increase text contrast to ≥4.5:1 (e.g., darken `#heading__main`).\n- Wrap primary content in `<main>` tag.\n- Add `<a href=\"#content\" class=\"skip-link\">Skip to content</a>`."},{"priority":2,"category":"Performance","title":"Add Image Dimensions and Lazy Loading","impact":"CLS, LCP","problem":"56 images missing width/height attributes and lazy loading (CLS risk).","solution":"Add `width` and `height` attributes to all `<img>` tags. Add `loading=\"lazy\"` to images below the fold:\n```html\n<img src=\"...\" alt=\"...\" width=\"300\" height=\"200\" loading=\"lazy\">\n```"},{"priority":2,"category":"Performance","title":"Add explicit width and height to images","impact":"CLS, Layout stability","problem":"HTML Inventory shows 53 images without width/height attributes, risking CLS despite current 0.039 score.","solution":"Add `width` and `height` attributes to all `<img>` tags:\n```html\n<img src=\"image.jpg\" alt=\"...\" width=\"800\" height=\"600\">\n```"},{"priority":2,"category":"SEO","title":"Fix HTML structure and headings","impact":"Document outline, W3C validation","problem":"7 W3C errors (malformed `<head>`/`<body>`) and 2 `<h1>` elements found.","solution":"- Ensure only one `<h1>` per page.\n- Fix `<noscript>` injection in `<head>` (likely GTM/Plugin issue).\n- Add `<main>` landmark wrapping primary content."},{"priority":2,"category":"Performance","title":"Eliminate render-blocking resources","impact":"FCP, LCP, Time to Interactive","problem":"Render-blocking insight estimates 990 ms savings; unused CSS (31 KiB) and JS (23 KiB) detected.","solution":"- Defer non-critical CSS.\n- Inline critical CSS.\n- Remove unused JS/CSS rules via build process or plugin settings."},{"priority":2,"category":"Security","title":"Add HSTS and X-Content-Type-Options","impact":"Protocol downgrade protection, MIME sniffing","problem":"HSTS and X-Content-Type-Options headers are missing (Security Headers grade 20/100).","solution":"Add these headers to the server response.\n\n**Apache:**\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Best Practices","title":"Resolve W3C HTML Validation Errors","impact":"DOM parsing, SEO, rendering stability","problem":"7 validation errors including parser recovery failure at line 100 (W3C Validator).","solution":"Fix the `<noscript>` iframe placement in `<head>` and remove stray end tags.\n- Move Google Tag Manager `<noscript>` iframe to `<body>`.\n- Ensure `<meta>` tags do not use invalid `name` attributes in this context.\n- Validate the document structure after changes."},{"priority":3,"category":"Performance","title":"Eliminate render-blocking resources","impact":"FCP, LCP","problem":"PageSpeed Insights flags 1 render-blocking script and 30 KiB unused CSS; LCP is 2.5 s.","solution":"Defer non-critical scripts. Inline critical CSS or use `preload` for critical stylesheets. Remove unused CSS rules identified in the audit."},{"priority":3,"category":"Best Practices","title":"Add explicit dimensions to images","impact":"CLS, Layout stability","problem":"HTML Inventory shows 50 images missing width/height attributes, which can cause layout shifts despite current CLS of 0.001.","solution":"Add `width` and `height` attributes to all `<img>` tags. For SVGs, use `viewBox` and CSS aspect-ratio if intrinsic dimensions are not available."},{"priority":3,"category":"Security","title":"Strengthen Content Security Policy","impact":"XSS defense-in-depth","problem":"CSP is weak (only `frame-ancestors`); site signals show no auth/payments, so P3 per rubric.","solution":"If adding forms or user content later, deploy a nonce-based CSP:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none';\"\n```"},{"priority":3,"category":"Security","title":"Implement Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing or weak (only frame-ancestors). Site signals show no auth/payments, so this is P3 per rubric.","solution":"Deploy a nonce-based CSP when ready:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\"\n```"},{"priority":3,"category":"Security","title":"Implement Content Security Policy","impact":"XSS defense-in-depth","problem":"CSP is missing (only `frame-ancestors` set). Site signals show no auth/payments/UGC.","solution":"Add a restrictive CSP header. Since this is a brochure site, start with a strict default-src:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline';\"\n```"},{"priority":3,"category":"Performance","title":"Add Image Dimensions and Lazy Loading","impact":"CLS, Initial Load","problem":"67 images missing explicit width/height and `loading=\"lazy\"` (HTML Inventory).","solution":"Add `width` and `height` attributes to all `<img>` tags to reserve space.\nAdd `loading=\"lazy\"` to images below the fold.\n\n```html\n<img src=\"image.jpg\" alt=\"...\" width=\"300\" height=\"200\" loading=\"lazy\">\n```"}],"coverage":{"pct":100,"missing":[]},"siteSummary":{"pagesAudited":5,"pagesAttempted":5,"urls":["https://play.ee/","https://play.ee/web-development-case-studies/","https://play.ee/software-development-work-index/","https://play.ee/wordpress-support-service/","https://play.ee/web-development-in-estonia/"]},"psiSnapshot":{"rows":[{"pageUrl":"https://play.ee/","perfMobile":95,"perfDesktop":100,"lcpMobileMs":2508,"lcpDesktopMs":546.5436549639668,"clsMobile":0.001012894925207863,"clsDesktop":0.005429360175900731},{"pageUrl":"https://play.ee/web-development-case-studies/","perfMobile":95,"perfDesktop":99,"lcpMobileMs":2570.5,"lcpDesktopMs":582,"clsMobile":0.004538940511363545,"clsDesktop":0.004854240310566847},{"pageUrl":"https://play.ee/software-development-work-index/","perfMobile":91,"perfDesktop":100,"lcpMobileMs":2476,"lcpDesktopMs":540.3401127628489,"clsMobile":0.0392620144285477,"clsDesktop":0.004334318404438869},{"pageUrl":"https://play.ee/wordpress-support-service/","perfMobile":96,"perfDesktop":100,"lcpMobileMs":2355,"lcpDesktopMs":580,"clsMobile":0.01679482402085737,"clsDesktop":0.001282508698859273},{"pageUrl":"https://play.ee/web-development-in-estonia/","perfMobile":96,"perfDesktop":96,"lcpMobileMs":2401,"lcpDesktopMs":555.3723969797569,"clsMobile":0.002002927346531788,"clsDesktop":0.004827055629199457}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket)","evidence":["HTML markers: WP Rocket","generator: WP Rocket 3.23.3.3"]},{"id":"lazyload","title":"Images lazy-loaded","status":"n/a","detail":"No raster <img> elements found (37 SVGs, 13 placeholders excluded).","evidence":[]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"n/a","detail":"No raster <img> elements found (37 SVGs, 13 placeholders excluded).","evidence":[]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"n/a","detail":"No CSS background-images detected on raster-image-eligible elements.","evidence":[]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"n/a","detail":"Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply.","evidence":[]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"n/a","detail":"Too few raster images to evaluate srcset width variety.","evidence":[]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"pass","detail":"No render-blocking scripts in <head>.","evidence":[]}],"summary":{"passed":2,"warned":0,"failed":0,"notApplicable":5},"priorities":[]},"perPageOverall":[{"url":"https://play.ee/","overall":78,"reasoning":"Mobile performance is excellent at 95 with LCP 2.5 s, but foundational security hygiene is poor (Headers grade 20/100) due to missing HSTS and lack of HTTP-to-HTTPS redirection. W3C validation shows 7 errors including parser recovery failure, indicating structural HTML issues in the head section. Accessibility scores 100 in Lighthouse but manual checks reveal missing landmarks and vague link text. The overall score reflects high runtime quality offset by significant configuration and markup debt.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS and add baseline security headers","impact":"Transport security, clickjacking, MIME sniffing","problem":"Security Headers grade is 20/100; HTTP does not redirect to HTTPS, and HSTS, X-Content-Type-Options are missing.","solution":"Configure server to redirect all HTTP traffic to HTTPS (301). Add these headers:\n```\nStrict-Transport-Security: max-age=63072000; includeSubDomains\nX-Content-Type-Options: nosniff\nX-Frame-Options: SAMEORIGIN\n```"},{"priority":2,"category":"SEO","title":"Fix W3C HTML validation errors","impact":"Parser recovery, document structure","problem":"W3C Validator reports 7 errors including 'Cannot recover after last error' at line 101 and invalid iframe/noscript placement in head.","solution":"Move `<noscript><iframe>` tags out of the `<head>` section. Ensure all `<meta>` tags are valid and remove stray end tags. Fix the parser recovery issue to ensure full document parsing."},{"priority":2,"category":"Accessibility","title":"Add skip link and main landmark","impact":"Keyboard navigation, screen reader flow","problem":"HTML Inventory shows 'main' landmark missing and no skip-to-content link; axe-core flags 'region' violations.","solution":"Add a skip link at the top of the page:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n```\nWrap primary content in `<main id=\"main-content\">`."},{"priority":3,"category":"Performance","title":"Eliminate render-blocking resources","impact":"FCP, LCP","problem":"PageSpeed Insights flags 1 render-blocking script and 30 KiB unused CSS; LCP is 2.5 s.","solution":"Defer non-critical scripts. Inline critical CSS or use `preload` for critical stylesheets. Remove unused CSS rules identified in the audit."},{"priority":3,"category":"Best Practices","title":"Add explicit dimensions to images","impact":"CLS, Layout stability","problem":"HTML Inventory shows 50 images missing width/height attributes, which can cause layout shifts despite current CLS of 0.001.","solution":"Add `width` and `height` attributes to all `<img>` tags. For SVGs, use `viewBox` and CSS aspect-ratio if intrinsic dimensions are not available."}],"perfScore":95,"a11yScore":100,"bestPracticesScore":100,"seoScore":92,"securityScore":20},{"url":"https://play.ee/web-development-case-studies/","overall":75,"reasoning":"PSI mobile performance is excellent at 95 with a 4 ms TTFB, but the overall score is dragged down by critical security configuration and structural HTML errors. Security headers grade is 20/100 with HTTP not redirecting to HTTPS, which is a fundamental trust failure. Accessibility has 1 serious color-contrast violation and missing main landmark. W3C validation shows 7 errors including parser recovery failure. Image assets lack dimensions on all 56 instances, risking layout shifts.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Force HTTPS redirect and add HSTS","impact":"Transport security, MITM protection","problem":"HTTP does not redirect to HTTPS and HSTS is missing (Security Headers grade 20/100).","solution":"Configure server to redirect all HTTP traffic to HTTPS (301) and send HSTS header:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"SEO","title":"Fix W3C HTML Validation Errors","impact":"Rendering consistency, SEO indexing","problem":"7 errors including parser recovery failure at line 100; iframe/noscript in head is invalid.","solution":"Move `<noscript><iframe>` block out of `<head>` or use valid placement. Fix meta tag attributes (`name` vs `property`). Ensure `<body>` opens after `<head>` closes properly."},{"priority":2,"category":"Accessibility","title":"Fix Color Contrast and Add Main Landmark","impact":"WCAG 1.4.3, 1.3.1","problem":"1 serious axe violation on color-contrast (h1, cards); Document lacks `main` landmark.","solution":"- Increase text contrast to ≥4.5:1 (e.g., darken `#heading__main`).\n- Wrap primary content in `<main>` tag.\n- Add `<a href=\"#content\" class=\"skip-link\">Skip to content</a>`."},{"priority":2,"category":"Performance","title":"Add Image Dimensions and Lazy Loading","impact":"CLS, LCP","problem":"56 images missing width/height attributes and lazy loading (CLS risk).","solution":"Add `width` and `height` attributes to all `<img>` tags. Add `loading=\"lazy\"` to images below the fold:\n```html\n<img src=\"...\" alt=\"...\" width=\"300\" height=\"200\" loading=\"lazy\">\n```"},{"priority":3,"category":"Security","title":"Strengthen Content Security Policy","impact":"XSS defense-in-depth","problem":"CSP is weak (only `frame-ancestors`); site signals show no auth/payments, so P3 per rubric.","solution":"If adding forms or user content later, deploy a nonce-based CSP:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none';\"\n```"}],"perfScore":95,"a11yScore":90,"bestPracticesScore":96,"seoScore":100,"securityScore":20},{"url":"https://play.ee/software-development-work-index/","overall":72,"reasoning":"PSI mobile performance is strong at 91, but the Security Headers grade of 20/100 and missing HTTP-to-HTTPS redirect create critical exposure regardless of site signals. W3C validation shows 7 errors including a parser recovery failure, and axe-core flags 1 serious contrast violation alongside missing landmarks. Image assets lack dimensions (53 images), risking CLS regression despite the current 0.039 score. Confidence is high due to complete tool coverage and consistent signals.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS redirect and add HSTS","impact":"Transport security, MITM protection","problem":"HTTP does not redirect to HTTPS (Security Headers finding) and HSTS is missing, leaving initial requests vulnerable.","solution":"Configure server to redirect all HTTP traffic to HTTPS (301) and send HSTS header:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Security","title":"Add X-Content-Type-Options and X-Frame-Options","impact":"MIME sniffing, clickjacking","problem":"X-Content-Type-Options and X-Frame-Options are missing (Security Headers grade 20/100).","solution":"Add these headers to all responses:\n```apache\nHeader always set X-Content-Type-Options \"nosniff\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\n```"},{"priority":2,"category":"Accessibility","title":"Fix color contrast and add main landmark","impact":"WCAG 1.4.3, 1.3.1","problem":"axe-core reports 1 serious violation on h1/span contrast; HTML Inventory shows missing `main` landmark and skip link.","solution":"- Increase contrast on `.heading__main` and `p > span` to ≥4.5:1.\n- Add `<main id=\"main-content\">` wrapper around primary content.\n- Add `<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>` before navigation."},{"priority":2,"category":"SEO","title":"Fix W3C HTML validation errors","impact":"Parser recovery, rendering consistency","problem":"W3C Validator reports 7 errors including 'Bad start tag in iframe in noscript in head' and parser recovery failure at line 100.","solution":"Move GTM iframe snippet out of `<head>` or ensure it is valid HTML5. Remove stray `</noscript>` or `</head>` tags causing parser recovery failure."},{"priority":2,"category":"Performance","title":"Add explicit width and height to images","impact":"CLS, Layout stability","problem":"HTML Inventory shows 53 images without width/height attributes, risking CLS despite current 0.039 score.","solution":"Add `width` and `height` attributes to all `<img>` tags:\n```html\n<img src=\"image.jpg\" alt=\"...\" width=\"800\" height=\"600\">\n```"},{"priority":3,"category":"Security","title":"Implement Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing or weak (only frame-ancestors). Site signals show no auth/payments, so this is P3 per rubric.","solution":"Deploy a nonce-based CSP when ready:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\"\n```"}],"perfScore":91,"a11yScore":90,"bestPracticesScore":96,"seoScore":100,"securityScore":20},{"url":"https://play.ee/wordpress-support-service/","overall":72,"reasoning":"Mobile performance is excellent (96) with good Core Web Vitals, but security headers are critically low (20/100) with HTTP not forcing HTTPS. Accessibility has two serious violations (contrast, link names) and missing landmarks which impact usability. HTML validation shows 7 errors including structural issues in `<head>` and duplicate `<h1>` tags. Security and accessibility issues prevent a higher score despite strong performance metrics.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS and add HSTS","impact":"Transport security, data integrity","problem":"HTTP does not redirect to HTTPS and HSTS is missing (Security Headers grade 20/100).","solution":"Configure server to redirect all HTTP traffic to HTTPS and add HSTS header:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":1,"category":"Accessibility","title":"Fix contrast and link names","impact":"WCAG 1.4.3, 2.4.4 compliance","problem":"2 serious axe violations: color-contrast on `.button--tertiary` and link-name on logo links.","solution":"- Increase contrast ratio for `.button--tertiary` text to ≥4.5:1.\n- Add `aria-label` to logo links (e.g., `<a aria-label=\"Client Logo\">`)."},{"priority":2,"category":"SEO","title":"Fix HTML structure and headings","impact":"Document outline, W3C validation","problem":"7 W3C errors (malformed `<head>`/`<body>`) and 2 `<h1>` elements found.","solution":"- Ensure only one `<h1>` per page.\n- Fix `<noscript>` injection in `<head>` (likely GTM/Plugin issue).\n- Add `<main>` landmark wrapping primary content."},{"priority":2,"category":"Performance","title":"Eliminate render-blocking resources","impact":"FCP, LCP, Time to Interactive","problem":"Render-blocking insight estimates 990 ms savings; unused CSS (31 KiB) and JS (23 KiB) detected.","solution":"- Defer non-critical CSS.\n- Inline critical CSS.\n- Remove unused JS/CSS rules via build process or plugin settings."},{"priority":3,"category":"Security","title":"Implement Content Security Policy","impact":"XSS defense-in-depth","problem":"CSP is missing (only `frame-ancestors` set). Site signals show no auth/payments/UGC.","solution":"Add a restrictive CSP header. Since this is a brochure site, start with a strict default-src:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline';\"\n```"}],"perfScore":96,"a11yScore":91,"bestPracticesScore":100,"seoScore":100,"securityScore":20},{"url":"https://play.ee/web-development-in-estonia/","overall":76,"reasoning":"Performance is excellent (PSI Mobile 96, LCP 2.4s), but security configuration is critically weak (HTTP redirect missing, HSTS absent, grade 20/100). Accessibility has serious contrast violations and a missing main landmark despite a 93 score. HTML validation shows 7 errors with parser recovery failure, indicating structural DOM issues. Image attributes are missing on 67 assets, posing future CLS risks. The overall score reflects high user experience quality undermined by foundational security and code hygiene issues.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Force HTTPS Redirect","impact":"Transport security, data integrity","problem":"HTTP does not redirect to HTTPS (http://play.ee... does not redirect to HTTPS).","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS.\n\n**Apache (.htaccess):**\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":2,"category":"Security","title":"Add HSTS and X-Content-Type-Options","impact":"Protocol downgrade protection, MIME sniffing","problem":"HSTS and X-Content-Type-Options headers are missing (Security Headers grade 20/100).","solution":"Add these headers to the server response.\n\n**Apache:**\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Accessibility","title":"Fix Color Contrast and Add Main Landmark","impact":"WCAG 1.4.3, 1.3.1","problem":"Serious color-contrast violations on multiple nodes; document lacks a main landmark (axe-core).","solution":"- Increase text contrast to ≥4.5:1 for `.heading__main` and `.heading__small`.\n- Wrap primary content in `<main>` or add `role=\"main\"` to the container.\n- Add a skip-to-content link at the top of the page."},{"priority":2,"category":"Best Practices","title":"Resolve W3C HTML Validation Errors","impact":"DOM parsing, SEO, rendering stability","problem":"7 validation errors including parser recovery failure at line 100 (W3C Validator).","solution":"Fix the `<noscript>` iframe placement in `<head>` and remove stray end tags.\n- Move Google Tag Manager `<noscript>` iframe to `<body>`.\n- Ensure `<meta>` tags do not use invalid `name` attributes in this context.\n- Validate the document structure after changes."},{"priority":3,"category":"Performance","title":"Add Image Dimensions and Lazy Loading","impact":"CLS, Initial Load","problem":"67 images missing explicit width/height and `loading=\"lazy\"` (HTML Inventory).","solution":"Add `width` and `height` attributes to all `<img>` tags to reserve space.\nAdd `loading=\"lazy\"` to images below the fold.\n\n```html\n<img src=\"image.jpg\" alt=\"...\" width=\"300\" height=\"200\" loading=\"lazy\">\n```"}],"perfScore":96,"a11yScore":94,"bestPracticesScore":100,"seoScore":100,"securityScore":20}]}