# Audit Report: Perfectly formed web development team - gotoAndPlay
**Website:** https://play.ee/
**Date:** 15.09.2026
**Audit Coverage:** 100% — all sources returned data
**Confidence:** high
**Pages Audited (5 of 5):**
- https://play.ee/
- https://play.ee/web-development-case-studies/
- https://play.ee/software-development-work-index/
- https://play.ee/wordpress-support-service/
- https://play.ee/web-development-in-estonia/
## Summary of results
**Overall Score:** 74 / 100
**Status:** 🟡 **Needs Improvement**
Site overall 74 is the mean of 5 pages. Scores range 68 (https://play.ee/web-development-case-studies/) → 82 (https://play.ee/). Weakest page: Mobile performance is strong (88) with acceptable LCP (2.7 s), but the Speed Index (5.89 s) indicates render delays. Security configuration is critically weak (Grade 20/100) with HTTP not redirecting to HTTPS and missing HSTS, which heavily penalizes the SEO/Security bucket. Accessibility has a serious color-contrast violation and missing main landmark, preventing a higher score. HTML validation shows 7 errors including parser recovery failure, indicating structural issues in the head section. Confidence is high as all audit tools returned complete data.
### Per-page scores
🟡 **Needs Improvement** · https://play.ee/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 82 | 93 | 100 | 100 | 92 | 20 |
🟡 **Needs Improvement** · https://play.ee/web-development-case-studies/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 68 | 88 | 90 | 96 | 100 | 20 |
🟡 **Needs Improvement** · https://play.ee/software-development-work-index/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 74 | 94 | 90 | 96 | 100 | 20 |
🟡 **Needs Improvement** · https://play.ee/wordpress-support-service/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 72 | 94 | 91 | 100 | 100 | 20 |
🟡 **Needs Improvement** · https://play.ee/web-development-in-estonia/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 75 | 93 | 94 | 100 | 100 | 20 |
## PageSpeed Insights — Mobile vs Desktop
_Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._
| URL | Performance (M / D) | LCP (M / D) | CLS (M / D) |
| --- | --- | --- | --- |
| https://play.ee/ | **93** / 100 | **2.62 s** / 591 ms | 0.000 / **0.007** |
| https://play.ee/web-development-case-studies/ | **88** / 100 | **2.68 s** / 547 ms | 0.005 / **0.006** |
| https://play.ee/software-development-work-index/ | **94** / 100 | **2.50 s** / 536 ms | 0.000 / **0.003** |
| https://play.ee/wordpress-support-service/ | **94** / 100 | **2.59 s** / 621 ms | 0.000 / **0.002** |
| https://play.ee/web-development-in-estonia/ | **93** / 99 | **2.62 s** / 536 ms | 0.000 / **0.005** |
## Optimization Checklist
**2 of 2 passing** — 2 pass · 0 warn · 0 fail · 5 n/a
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | N/A | No raster
elements found (37 SVGs, 13 placeholders excluded). |
| Hero image eagerly loaded | N/A | No raster
elements found (37 SVGs, 13 placeholders excluded). |
| Hero is a real
(not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / ) | N/A | Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in | **Pass** | No render-blocking scripts in . |
## Fixes
### Priority 1: Critical
*Immediate action — impacts user experience, search rankings, or site safety.*
**1A. Enforce HTTPS redirect** `Security`
- **Impact:** Transport security, data integrity
- **Problem:** HTTP does not redirect to HTTPS (http://play.ee/ does not redirect to https://play.ee/), exposing users to man-in-the-middle risks.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301/302 redirect for all HTTP requests to the HTTPS equivalent:
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1B. Force HTTPS Redirect** `Security`
- **Impact:** Transport security, data integrity
- **Problem:** HTTP requests to http://play.ee/web-development-case-studies/ do not redirect to HTTPS, leaving users vulnerable to interception.
- **Solution:**
Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS:
```apache
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
```
**1C. Add HSTS Header** `Security`
- **Impact:** HTTPS enforcement, downgrade attacks
- **Problem:** Strict-Transport-Security header is missing; browsers cannot enforce HTTPS on subsequent visits.
- **Solution:**
Add HSTS with a long max-age and includeSubDomains:
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
```
**1D. Enforce HTTPS and add baseline security headers** `Security`
- **Impact:** Transport security, clickjacking, MIME sniffing
- **Problem:** HTTP does not redirect to HTTPS; HSTS, X-Content-Type-Options, and X-Frame-Options are missing (Security Headers grade 20/100).
- **Solution:**
Configure server to redirect all HTTP traffic to HTTPS. Add the following headers:
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
Header always set X-Content-Type-Options "nosniff"
Header always set X-Frame-Options "SAMEORIGIN"
```
**1E. Enforce HTTPS and add HSTS** `Security`
- **Impact:** Transport security, downgrade attacks
- **Problem:** HTTP does not redirect to HTTPS and HSTS is missing (Security Headers Grade 20/100).
- **Solution:**
Configure server to redirect all HTTP traffic to HTTPS and send:
```
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
```
**1F. Fix color contrast and link names** `Accessibility`
- **Impact:** WCAG 1.4.3, 2.4.4 compliance
- **Problem:** 2 serious axe violations: color-contrast on multiple text elements and logo grid links lack discernible names.
- **Solution:**
- Increase contrast ratio to ≥4.5:1 for `.button--tertiary` and `.capabilities__heading`.
- Add `aria-label` to logo links (e.g., ``).
**1G. Add HSTS and X-Content-Type-Options** `Security`
- **Impact:** Clickjacking, MIME sniffing, downgrade attacks
- **Problem:** Security Headers grade is 20/100; HSTS and X-Content-Type-Options are missing.
- **Solution:**
Add these headers to the server response.
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
Header always set X-Content-Type-Options "nosniff"
```
### Priority 2: Important
*Essential for compliance, user reach, and search visibility.*
**2A. Add HSTS and X-Content-Type-Options** `Security`
- **Impact:** Protocol downgrade protection, MIME sniffing
- **Problem:** Security Headers grade is 20/100; HSTS and X-Content-Type-Options are missing despite HTTPS being available.
- **Solution:**
Add the following headers to the server configuration:
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
Header always set X-Content-Type-Options "nosniff"
```
**2B. Add main landmark and skip-to-content link** `Accessibility`
- **Impact:** Keyboard navigation, screen reader usability
- **Problem:** axe-core reports missing `main` landmark and `region` violations; HTML inventory confirms no skip-to-content link.
- **Solution:**
Wrap the primary content in `` and add a skip link at the top of the ``:
```html
Skip to content
```
**2C. Fix W3C HTML validation errors** `SEO`
- **Impact:** Parser reliability, SEO crawling
- **Problem:** W3C Validator reports 7 errors including parser recovery failure at line 101 and invalid iframe placement in ``.
- **Solution:**
Move the Google Tag Manager iframe out of the `` or ensure it is properly closed within ``. Remove invalid `name` attributes on `` tags. Ensure `