# Audit Report: Perfectly formed web development team - gotoAndPlay **Website:** https://play.ee/ **Date:** 24.09.2026 **Audit Coverage:** 95% โ€” PageSpeed Insights (desktop): PSI HTTP 429; PageSpeed Insights (mobile): PSI HTTP 429; PageSpeed Insights: mobile: PSI HTTP 429; desktop: PSI HTTP 429 **Confidence:** low **Pages Audited (5 of 5):** - https://play.ee/ - https://play.ee/team - https://play.ee/privacy-policy - https://play.ee/et/meeskond - https://play.ee/wordpress-support-service ## Summary of results **Overall Score:** 76 / 100 **Status:** โš  ๐ŸŸก **Needs Improvement** Site overall 76 is the mean of 4 pages. Scores range 73 (https://play.ee/team) โ†’ 78 (https://play.ee/privacy-policy). Weakest page: PSI mobile performance is strong at 94 with excellent TTFB and CLS, though LCP sits at 2.8 s in the warning range. However, the Security basics verdict is FAILED due to missing HTTP-to-HTTPS redirects and HSTS, which caps the overall score below 90 per the rubric. Accessibility has a serious color-contrast violation and missing landmarks despite a 94 score. W3C validation reports 7 errors including parser recovery failure, indicating broken HTML structure. Confidence is high as all audit tools returned complete data. ### Per-page scores ๐ŸŸก **Needs Improvement** ยท https://play.ee/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 78 | 96 | 94 | 100 | 92 | FAILED | ๐ŸŸก **Needs Improvement** ยท https://play.ee/team | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 73 | 94 | 94 | 100 | 100 | FAILED | ๐ŸŸก **Needs Improvement** ยท https://play.ee/privacy-policy | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 78 | 93 | 87 | 100 | 100 | FAILED | ๐ŸŸก **Needs Improvement** ยท https://play.ee/et/meeskond | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 74 | 100 | 93 | 100 | 100 | FAILED | โ€” ยท https://play.ee/wordpress-support-service | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | โ€” | โ€” | โ€” | โ€” | โ€” | FAILED | ## PageSpeed Insights โ€” Mobile vs Desktop _Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._ | URL | Performance (M / D) | LCP (M / D) | CLS (M / D) | | --- | --- | --- | --- | | https://play.ee/ | **96** / 100 | **2.48 s** / 546 ms | 0.001 / **0.005** | | https://play.ee/team | **94** / 100 | **2.78 s** / 633 ms | **0.037** / 0.003 | | https://play.ee/privacy-policy | 93 / โ€” | 2.80 s / โ€” | 0.002 / โ€” | | https://play.ee/et/meeskond | โ€” / 100 | โ€” / 629 ms | โ€” / 0.003 | ## Optimization Checklist **3 of 3 passing** โ€” 3 pass ยท 0 warn ยท 0 fail ยท 5 n/a | Item | Status | Detail | | --- | --- | --- | | Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) | | Response compressed (gzip / brotli) | **Pass** | Document response is compressed with gzip. | | Images lazy-loaded | N/A | No raster elements found (37 SVGs, 13 placeholders excluded). | | Hero image eagerly loaded | N/A | No raster elements found (37 SVGs, 13 placeholders excluded). | | Hero is a real (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. | | Responsive images (srcset / ) | N/A | Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) โ€” responsive-image rule does not apply. | | Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. | | JS scripts not blocking in | **Pass** | No render-blocking scripts in . | ## Fixes ### Priority 1: Critical *Immediate action โ€” impacts user experience, search rankings, or site safety.* **1A. Enforce HTTPS redirect and add HSTS** `Security` - **Impact:** Transport security, trust, security basics score - **Problem:** Security basics verdict is FAILED; HTTP does not redirect to HTTPS and Strict-Transport-Security header is missing. - **Solution:** Configure the web server to redirect all HTTP traffic to HTTPS (301) and send the HSTS header: ```apache Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1B. Fix W3C HTML validation errors** `Best Practices` - **Impact:** Rendering stability, SEO indexing - **Problem:** W3C validator reports 7 errors including parser recovery failure at line 101 (bad start tag in iframe/noscript in head). - **Solution:** Move the Google Tag Manager iframe snippet out of the `` or ensure it is properly closed within `