{"url":"https://play.ee/","date":"2026-09-15","siteName":"Perfectly formed web development team - gotoAndPlay","overall":74,"reasoning":"Site overall 74 is the mean of 5 pages. Scores range 68 (https://play.ee/web-development-case-studies/) → 82 (https://play.ee/). Weakest page: Mobile performance is strong (88) with acceptable LCP (2.7 s), but the Speed Index (5.89 s) indicates render delays. Security configuration is critically weak (Grade 20/100) with HTTP not redirecting to HTTPS and missing HSTS, which heavily penalizes the SEO/Security bucket. Accessibility has a serious color-contrast violation and missing main landmark, preventing a higher score. HTML validation shows 7 errors including parser recovery failure, indicating structural issues in the head section. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS redirect","impact":"Transport security, data integrity","problem":"HTTP does not redirect to HTTPS (http://play.ee/ does not redirect to https://play.ee/), exposing users to man-in-the-middle risks.","solution":"Configure the web server (Apache/Nginx) to return a 301/302 redirect for all HTTP requests to the HTTPS equivalent:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Security","title":"Force HTTPS Redirect","impact":"Transport security, data integrity","problem":"HTTP requests to http://play.ee/web-development-case-studies/ do not redirect to HTTPS, leaving users vulnerable to interception.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Security","title":"Add HSTS Header","impact":"HTTPS enforcement, downgrade attacks","problem":"Strict-Transport-Security header is missing; browsers cannot enforce HTTPS on subsequent visits.","solution":"Add HSTS with a long max-age and includeSubDomains:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":1,"category":"Security","title":"Enforce HTTPS and add baseline security headers","impact":"Transport security, clickjacking, MIME sniffing","problem":"HTTP does not redirect to HTTPS; HSTS, X-Content-Type-Options, and X-Frame-Options are missing (Security Headers grade 20/100).","solution":"Configure server to redirect all HTTP traffic to HTTPS. Add the following headers:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\n```"},{"priority":1,"category":"Security","title":"Enforce HTTPS and add HSTS","impact":"Transport security, downgrade attacks","problem":"HTTP does not redirect to HTTPS and HSTS is missing (Security Headers Grade 20/100).","solution":"Configure server to redirect all HTTP traffic to HTTPS and send:\n```\nStrict-Transport-Security: max-age=63072000; includeSubDomains; preload\n```"},{"priority":1,"category":"Accessibility","title":"Fix color contrast and link names","impact":"WCAG 1.4.3, 2.4.4 compliance","problem":"2 serious axe violations: color-contrast on multiple text elements and logo grid links lack discernible names.","solution":"- Increase contrast ratio to ≥4.5:1 for `.button--tertiary` and `.capabilities__heading`.\n- Add `aria-label` to logo links (e.g., `<a aria-label=\"Client Name Logo\">`)."},{"priority":1,"category":"Security","title":"Add HSTS and X-Content-Type-Options","impact":"Clickjacking, MIME sniffing, downgrade attacks","problem":"Security Headers grade is 20/100; HSTS and X-Content-Type-Options are missing.","solution":"Add these headers to the server response.\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Security","title":"Add HSTS and X-Content-Type-Options","impact":"Protocol downgrade protection, MIME sniffing","problem":"Security Headers grade is 20/100; HSTS and X-Content-Type-Options are missing despite HTTPS being available.","solution":"Add the following headers to the server configuration:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Accessibility","title":"Add main landmark and skip-to-content link","impact":"Keyboard navigation, screen reader usability","problem":"axe-core reports missing `main` landmark and `region` violations; HTML inventory confirms no skip-to-content link.","solution":"Wrap the primary content in `<main>` and add a skip link at the top of the `<body>`:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n<!-- ... header ... -->\n<main id=\"main-content\">\n  <!-- content -->\n</main>\n```"},{"priority":2,"category":"SEO","title":"Fix W3C HTML validation errors","impact":"Parser reliability, SEO crawling","problem":"W3C Validator reports 7 errors including parser recovery failure at line 101 and invalid iframe placement in `<head>`.","solution":"Move the Google Tag Manager iframe out of the `<head>` or ensure it is properly closed within `<body>`. Remove invalid `name` attributes on `<meta>` tags. Ensure `<noscript>` tags are not nested incorrectly inside `<head>`."},{"priority":2,"category":"Accessibility","title":"Fix Color Contrast Violations","impact":"WCAG 1.4.3 compliance, readability","problem":"axe-core reports 1 serious violation on multiple nodes (e.g., h1 > .heading__main) where foreground/background contrast is insufficient.","solution":"Adjust CSS colors to meet a 4.5:1 contrast ratio for normal text. Use a contrast checker tool to verify specific hex codes for `.heading__main` and `.card__meta`."},{"priority":2,"category":"Accessibility","title":"Add Main Landmark and Skip Link","impact":"Screen reader navigation, keyboard access","problem":"HTML Inventory confirms `main` landmark is missing; PSI audit `landmark-one-main` fails. No skip-to-content link exists.","solution":"Wrap primary content in `<main id=\"main-content\">` and add a skip link at the top of `<body>`:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n<!-- ... content ... -->\n<main id=\"main-content\">...</main>\n```"},{"priority":2,"category":"Best Practices","title":"Resolve HTML Validation Errors","impact":"Parser reliability, SEO rendering","problem":"W3C Validator reports 7 errors including bad start tags in `iframe`/`noscript` and parser recovery failure at line 100.","solution":"Inspect the `<head>` section around line 97-100. Fix the Google Tag Manager `noscript` iframe nesting and remove invalid `meta` attributes (e.g., `name` on meta where not allowed)."},{"priority":2,"category":"Accessibility","title":"Fix contrast and landmark structure","impact":"WCAG 1.4.3 contrast, 1.3.1 info and relationships","problem":"axe-core reports 1 serious color-contrast violation (h1, span) and missing `main` landmark; skip-to-content link is absent.","solution":"- Increase contrast on `.heading__main` and `p > span` to ≥4.5:1.\n- Wrap main content in `<main>` tag.\n- Add `<a href=\"#content\" class=\"skip-link\">Skip to content</a>` before navigation."},{"priority":2,"category":"Performance","title":"Eliminate render-blocking resources","impact":"LCP, FCP, Speed Index","problem":"Render-blocking insight estimates 980 ms savings; LCP is 2.6 s (warning threshold 2.5 s).","solution":"- Defer non-critical scripts (e.g., `jquery.bfe1bb19d13b3c17b682.min.js`).\n- Inline critical CSS and defer non-critical stylesheets."},{"priority":2,"category":"Accessibility","title":"Fix color contrast on headings","impact":"WCAG 1.4.3 compliance, readability","problem":"axe-core found 1 serious violation: color-contrast on `.focus__heading` and `.capabilities__heading` elements.","solution":"Increase contrast ratio to at least 4.5:1 for normal text. Adjust CSS colors for `.heading__main` and `.heading__small` elements."},{"priority":3,"category":"Performance","title":"Optimize LCP and font loading","impact":"LCP (2.6 s), FCP (1.96 s)","problem":"LCP is 2.6 s on mobile; Browser Runtime shows 3 font requests taking ~580 ms each, contributing to render delay.","solution":"Preload the primary font used for the LCP element and use `font-display: swap` in CSS. Consider reducing font file sizes or using variable fonts:\n```html\n<link rel=\"preload\" href=\"/fonts/primary.woff2\" as=\"font\" type=\"font/woff2\" crossorigin>\n```"},{"priority":3,"category":"Security","title":"Implement Content Security Policy (CSP)","impact":"XSS mitigation (low risk site)","problem":"CSP is weak (only `frame-ancestors`). Site signals indicate no auth/payments/UGC, so XSS risk is lower but defense-in-depth is recommended.","solution":"Deploy a strict CSP with nonces for scripts rather than a flat allowlist:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{RANDOM}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\"\n```"},{"priority":3,"category":"Performance","title":"Add Explicit Image Dimensions","impact":"CLS, Layout stability","problem":"HTML Inventory shows 56 images missing width/height attributes, risking layout shifts during load.","solution":"Ensure all `<img>` tags include `width` and `height` attributes matching the intrinsic aspect ratio:\n```html\n<img src=\"image.jpg\" alt=\"...\" width=\"800\" height=\"600\">\n```"},{"priority":3,"category":"Performance","title":"Add explicit dimensions to images","impact":"CLS (Cumulative Layout Shift)","problem":"53 images lack width/height attributes, risking layout shifts despite current CLS 0.000 score.","solution":"Add `width` and `height` attributes to all `<img>` tags matching their intrinsic aspect ratio. Use CSS `aspect-ratio` if dimensions vary."},{"priority":3,"category":"Best Practices","title":"Add image dimensions and lazy loading","impact":"CLS, bandwidth","problem":"31 images missing width/height attributes and `loading=\"lazy\"`.","solution":"- Add `width` and `height` to all `<img>` tags to reserve space.\n- Add `loading=\"lazy\"` to images below the fold."},{"priority":3,"category":"Security","title":"Implement Content-Security-Policy","impact":"XSS defense-in-depth","problem":"CSP is missing (only `frame-ancestors` set). Site has no auth/payments, so risk is lower but still recommended.","solution":"Deploy a strict CSP with nonce/hash:\n```\nContent-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none';\n```"},{"priority":3,"category":"Performance","title":"Add explicit width/height to images","impact":"CLS (Cumulative Layout Shift)","problem":"HTML Inventory shows 67 images without explicit width/height attributes, risking layout shifts despite current CLS 0.000.","solution":"Add `width` and `height` attributes to all `<img>` tags matching the intrinsic aspect ratio.\n```html\n<img src=\"logo.svg\" alt=\"Logo\" width=\"200\" height=\"50\">\n```"}],"coverage":{"pct":100,"missing":[]},"siteSummary":{"pagesAudited":5,"pagesAttempted":5,"urls":["https://play.ee/","https://play.ee/web-development-case-studies/","https://play.ee/software-development-work-index/","https://play.ee/wordpress-support-service/","https://play.ee/web-development-in-estonia/"]},"psiSnapshot":{"rows":[{"pageUrl":"https://play.ee/","perfMobile":93,"perfDesktop":100,"lcpMobileMs":2622,"lcpDesktopMs":591.064375324659,"clsMobile":0,"clsDesktop":0.00678706602142075},{"pageUrl":"https://play.ee/web-development-case-studies/","perfMobile":88,"perfDesktop":100,"lcpMobileMs":2677.5,"lcpDesktopMs":546.8849463722686,"clsMobile":0.004505446540033813,"clsDesktop":0.006146794005699904},{"pageUrl":"https://play.ee/software-development-work-index/","perfMobile":94,"perfDesktop":100,"lcpMobileMs":2499,"lcpDesktopMs":535.6186387572109,"clsMobile":0,"clsDesktop":0.003111686122982179},{"pageUrl":"https://play.ee/wordpress-support-service/","perfMobile":94,"perfDesktop":100,"lcpMobileMs":2587.5,"lcpDesktopMs":621,"clsMobile":0,"clsDesktop":0.001513033049024603},{"pageUrl":"https://play.ee/web-development-in-estonia/","perfMobile":93,"perfDesktop":99,"lcpMobileMs":2615,"lcpDesktopMs":536.1370004072642,"clsMobile":0,"clsDesktop":0.0046367525162785105}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket)","evidence":["HTML markers: WP Rocket","generator: WP Rocket 3.23.3.3"]},{"id":"lazyload","title":"Images lazy-loaded","status":"n/a","detail":"No raster <img> elements found (37 SVGs, 13 placeholders excluded).","evidence":[]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"n/a","detail":"No raster <img> elements found (37 SVGs, 13 placeholders excluded).","evidence":[]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"n/a","detail":"No CSS background-images detected on raster-image-eligible elements.","evidence":[]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"n/a","detail":"Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply.","evidence":[]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"n/a","detail":"Too few raster images to evaluate srcset width variety.","evidence":[]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"pass","detail":"No render-blocking scripts in <head>.","evidence":[]}],"summary":{"passed":2,"warned":0,"failed":0,"notApplicable":5},"priorities":[]},"perPageOverall":[{"url":"https://play.ee/","overall":82,"reasoning":"Performance is excellent (PSI Mobile 93, Desktop 100) with strong Core Web Vitals, though LCP (2.6 s) is slightly above the 2.5 s threshold. Accessibility is strong (PSI 100) with only moderate axe violations regarding landmarks. However, security configuration is critically weak (Grade 20/100) due to missing HSTS and lack of HTTP-to-HTTPS redirection. W3C validation shows 7 errors including parser recovery failure, indicating structural HTML issues. The overall score reflects high technical quality in rendering and UX, penalized significantly by security misconfigurations.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS redirect","impact":"Transport security, data integrity","problem":"HTTP does not redirect to HTTPS (http://play.ee/ does not redirect to https://play.ee/), exposing users to man-in-the-middle risks.","solution":"Configure the web server (Apache/Nginx) to return a 301/302 redirect for all HTTP requests to the HTTPS equivalent:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":2,"category":"Security","title":"Add HSTS and X-Content-Type-Options","impact":"Protocol downgrade protection, MIME sniffing","problem":"Security Headers grade is 20/100; HSTS and X-Content-Type-Options are missing despite HTTPS being available.","solution":"Add the following headers to the server configuration:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Accessibility","title":"Add main landmark and skip-to-content link","impact":"Keyboard navigation, screen reader usability","problem":"axe-core reports missing `main` landmark and `region` violations; HTML inventory confirms no skip-to-content link.","solution":"Wrap the primary content in `<main>` and add a skip link at the top of the `<body>`:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n<!-- ... header ... -->\n<main id=\"main-content\">\n  <!-- content -->\n</main>\n```"},{"priority":2,"category":"SEO","title":"Fix W3C HTML validation errors","impact":"Parser reliability, SEO crawling","problem":"W3C Validator reports 7 errors including parser recovery failure at line 101 and invalid iframe placement in `<head>`.","solution":"Move the Google Tag Manager iframe out of the `<head>` or ensure it is properly closed within `<body>`. Remove invalid `name` attributes on `<meta>` tags. Ensure `<noscript>` tags are not nested incorrectly inside `<head>`."},{"priority":3,"category":"Performance","title":"Optimize LCP and font loading","impact":"LCP (2.6 s), FCP (1.96 s)","problem":"LCP is 2.6 s on mobile; Browser Runtime shows 3 font requests taking ~580 ms each, contributing to render delay.","solution":"Preload the primary font used for the LCP element and use `font-display: swap` in CSS. Consider reducing font file sizes or using variable fonts:\n```html\n<link rel=\"preload\" href=\"/fonts/primary.woff2\" as=\"font\" type=\"font/woff2\" crossorigin>\n```"}],"perfScore":93,"a11yScore":100,"bestPracticesScore":100,"seoScore":92,"securityScore":20},{"url":"https://play.ee/web-development-case-studies/","overall":68,"reasoning":"Mobile performance is strong (88) with acceptable LCP (2.7 s), but the Speed Index (5.89 s) indicates render delays. Security configuration is critically weak (Grade 20/100) with HTTP not redirecting to HTTPS and missing HSTS, which heavily penalizes the SEO/Security bucket. Accessibility has a serious color-contrast violation and missing main landmark, preventing a higher score. HTML validation shows 7 errors including parser recovery failure, indicating structural issues in the head section. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Force HTTPS Redirect","impact":"Transport security, data integrity","problem":"HTTP requests to http://play.ee/web-development-case-studies/ do not redirect to HTTPS, leaving users vulnerable to interception.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS:\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Security","title":"Add HSTS Header","impact":"HTTPS enforcement, downgrade attacks","problem":"Strict-Transport-Security header is missing; browsers cannot enforce HTTPS on subsequent visits.","solution":"Add HSTS with a long max-age and includeSubDomains:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":2,"category":"Accessibility","title":"Fix Color Contrast Violations","impact":"WCAG 1.4.3 compliance, readability","problem":"axe-core reports 1 serious violation on multiple nodes (e.g., h1 > .heading__main) where foreground/background contrast is insufficient.","solution":"Adjust CSS colors to meet a 4.5:1 contrast ratio for normal text. Use a contrast checker tool to verify specific hex codes for `.heading__main` and `.card__meta`."},{"priority":2,"category":"Accessibility","title":"Add Main Landmark and Skip Link","impact":"Screen reader navigation, keyboard access","problem":"HTML Inventory confirms `main` landmark is missing; PSI audit `landmark-one-main` fails. No skip-to-content link exists.","solution":"Wrap primary content in `<main id=\"main-content\">` and add a skip link at the top of `<body>`:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n<!-- ... content ... -->\n<main id=\"main-content\">...</main>\n```"},{"priority":2,"category":"Best Practices","title":"Resolve HTML Validation Errors","impact":"Parser reliability, SEO rendering","problem":"W3C Validator reports 7 errors including bad start tags in `iframe`/`noscript` and parser recovery failure at line 100.","solution":"Inspect the `<head>` section around line 97-100. Fix the Google Tag Manager `noscript` iframe nesting and remove invalid `meta` attributes (e.g., `name` on meta where not allowed)."},{"priority":3,"category":"Security","title":"Implement Content Security Policy (CSP)","impact":"XSS mitigation (low risk site)","problem":"CSP is weak (only `frame-ancestors`). Site signals indicate no auth/payments/UGC, so XSS risk is lower but defense-in-depth is recommended.","solution":"Deploy a strict CSP with nonces for scripts rather than a flat allowlist:\n```apache\nHeader set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{RANDOM}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\"\n```"},{"priority":3,"category":"Performance","title":"Add Explicit Image Dimensions","impact":"CLS, Layout stability","problem":"HTML Inventory shows 56 images missing width/height attributes, risking layout shifts during load.","solution":"Ensure all `<img>` tags include `width` and `height` attributes matching the intrinsic aspect ratio:\n```html\n<img src=\"image.jpg\" alt=\"...\" width=\"800\" height=\"600\">\n```"}],"perfScore":88,"a11yScore":90,"bestPracticesScore":96,"seoScore":100,"securityScore":20},{"url":"https://play.ee/software-development-work-index/","overall":74,"reasoning":"Mobile Performance 94 is strong, but Security Headers grade 20/100 and missing HTTPS redirect create significant risk. W3C validation shows 7 errors with parser recovery failure, indicating broken DOM structure. Accessibility has a serious contrast violation and missing main landmark. LCP 2.5s sits on the warning threshold. Confidence is high as all audit sources returned data.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS and add baseline security headers","impact":"Transport security, clickjacking, MIME sniffing","problem":"HTTP does not redirect to HTTPS; HSTS, X-Content-Type-Options, and X-Frame-Options are missing (Security Headers grade 20/100).","solution":"Configure server to redirect all HTTP traffic to HTTPS. Add the following headers:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\n```"},{"priority":2,"category":"Accessibility","title":"Fix contrast and landmark structure","impact":"WCAG 1.4.3 contrast, 1.3.1 info and relationships","problem":"axe-core reports 1 serious color-contrast violation (h1, span) and missing `main` landmark; skip-to-content link is absent.","solution":"- Increase contrast on `.heading__main` and `p > span` to ≥4.5:1.\n- Wrap main content in `<main>` tag.\n- Add `<a href=\"#content\" class=\"skip-link\">Skip to content</a>` before navigation."},{"priority":2,"category":"SEO","title":"Resolve HTML validation errors","impact":"DOM parsing, SEO indexing reliability","problem":"W3C Validator reports 7 errors including parser recovery failure at line 100; bad start tag in iframe in noscript in head.","solution":"Move the Google Tag Manager `noscript` iframe out of the `<head>` section. Ensure `<meta>` tags do not use invalid attributes like `name` in contexts requiring `property` or `itemprop`."},{"priority":3,"category":"Performance","title":"Add explicit dimensions to images","impact":"CLS (Cumulative Layout Shift)","problem":"53 images lack width/height attributes, risking layout shifts despite current CLS 0.000 score.","solution":"Add `width` and `height` attributes to all `<img>` tags matching their intrinsic aspect ratio. Use CSS `aspect-ratio` if dimensions vary."}],"perfScore":94,"a11yScore":90,"bestPracticesScore":96,"seoScore":100,"securityScore":20},{"url":"https://play.ee/wordpress-support-service/","overall":72,"reasoning":"Performance is strong (PSI 94) but LCP 2.6s and FCP 1.96s slightly exceed recommended thresholds. Security is a major drag (Grade 20/100) due to missing HSTS and lack of HTTP-to-HTTPS redirect enforcement. Accessibility has 2 serious axe violations (contrast, link names) despite a 91 PSI score. HTML validity is poor with 7 W3C errors including parser recovery failure. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS and add HSTS","impact":"Transport security, downgrade attacks","problem":"HTTP does not redirect to HTTPS and HSTS is missing (Security Headers Grade 20/100).","solution":"Configure server to redirect all HTTP traffic to HTTPS and send:\n```\nStrict-Transport-Security: max-age=63072000; includeSubDomains; preload\n```"},{"priority":1,"category":"Accessibility","title":"Fix color contrast and link names","impact":"WCAG 1.4.3, 2.4.4 compliance","problem":"2 serious axe violations: color-contrast on multiple text elements and logo grid links lack discernible names.","solution":"- Increase contrast ratio to ≥4.5:1 for `.button--tertiary` and `.capabilities__heading`.\n- Add `aria-label` to logo links (e.g., `<a aria-label=\"Client Name Logo\">`)."},{"priority":2,"category":"SEO","title":"Resolve HTML validation errors","impact":"Rendering consistency, SEO indexing","problem":"W3C reports 7 errors including parser recovery failure at line 107 and multiple `<h1>` elements.","solution":"- Ensure exactly one `<h1>` per page.\n- Fix `<noscript><iframe>` nesting in `<head>` (move to `<body>` or use valid structure).\n- Remove invalid `name` attribute on `<meta>` tags."},{"priority":2,"category":"Performance","title":"Eliminate render-blocking resources","impact":"LCP, FCP, Speed Index","problem":"Render-blocking insight estimates 980 ms savings; LCP is 2.6 s (warning threshold 2.5 s).","solution":"- Defer non-critical scripts (e.g., `jquery.bfe1bb19d13b3c17b682.min.js`).\n- Inline critical CSS and defer non-critical stylesheets."},{"priority":3,"category":"Best Practices","title":"Add image dimensions and lazy loading","impact":"CLS, bandwidth","problem":"31 images missing width/height attributes and `loading=\"lazy\"`.","solution":"- Add `width` and `height` to all `<img>` tags to reserve space.\n- Add `loading=\"lazy\"` to images below the fold."},{"priority":3,"category":"Security","title":"Implement Content-Security-Policy","impact":"XSS defense-in-depth","problem":"CSP is missing (only `frame-ancestors` set). Site has no auth/payments, so risk is lower but still recommended.","solution":"Deploy a strict CSP with nonce/hash:\n```\nContent-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none';\n```"}],"perfScore":94,"a11yScore":91,"bestPracticesScore":100,"seoScore":100,"securityScore":20},{"url":"https://play.ee/web-development-in-estonia/","overall":75,"reasoning":"Performance is excellent (PSI Mobile 93, LCP 2.6 s) but security configuration is critically weak (Headers 20/100, HTTP does not redirect to HTTPS). Accessibility has a serious contrast violation and missing main landmark, dragging the score down despite a 94 PSI score. W3C validation shows 7 errors with parser recovery, indicating structural HTML issues. The HTTP redirect failure is a high-priority security risk regardless of site signals.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS redirect","impact":"Transport security, data integrity","problem":"Audit found 'http://play.ee/... does not redirect to HTTPS', allowing unencrypted traffic.","solution":"Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests.\n```apache\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Security","title":"Add HSTS and X-Content-Type-Options","impact":"Clickjacking, MIME sniffing, downgrade attacks","problem":"Security Headers grade is 20/100; HSTS and X-Content-Type-Options are missing.","solution":"Add these headers to the server response.\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Accessibility","title":"Fix color contrast on headings","impact":"WCAG 1.4.3 compliance, readability","problem":"axe-core found 1 serious violation: color-contrast on `.focus__heading` and `.capabilities__heading` elements.","solution":"Increase contrast ratio to at least 4.5:1 for normal text. Adjust CSS colors for `.heading__main` and `.heading__small` elements."},{"priority":2,"category":"SEO","title":"Fix W3C HTML validation errors","impact":"Document parsing, SEO indexing","problem":"W3C Validator reported 7 errors including 'Bad start tag in iframe in noscript in head' and parser recovery failure at line 100.","solution":"Move the Google Tag Manager `noscript` iframe outside the `<head>` section. Ensure `<meta>` tags are valid and remove stray end tags."},{"priority":3,"category":"Performance","title":"Add explicit width/height to images","impact":"CLS (Cumulative Layout Shift)","problem":"HTML Inventory shows 67 images without explicit width/height attributes, risking layout shifts despite current CLS 0.000.","solution":"Add `width` and `height` attributes to all `<img>` tags matching the intrinsic aspect ratio.\n```html\n<img src=\"logo.svg\" alt=\"Logo\" width=\"200\" height=\"50\">\n```"}],"perfScore":93,"a11yScore":94,"bestPracticesScore":100,"seoScore":100,"securityScore":20}]}