{"url":"https://play.ee/","date":"2026-09-24","siteName":"Perfectly formed web development team - gotoAndPlay","overall":76,"reasoning":"Site overall 76 is the mean of 4 pages. Scores range 73 (https://play.ee/team) → 78 (https://play.ee/privacy-policy). Weakest page: PSI mobile performance is strong at 94 with excellent TTFB and CLS, though LCP sits at 2.8 s in the warning range. However, the Security basics verdict is FAILED due to missing HTTP-to-HTTPS redirects and HSTS, which caps the overall score below 90 per the rubric. Accessibility has a serious color-contrast violation and missing landmarks despite a 94 score. W3C validation reports 7 errors including parser recovery failure, indicating broken HTML structure. Confidence is high as all audit tools returned complete data.","confidence":"low","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS redirect and add HSTS","impact":"Transport security, trust, security basics score","problem":"Security basics verdict is FAILED; HTTP does not redirect to HTTPS and Strict-Transport-Security header is missing.","solution":"Configure the web server to redirect all HTTP traffic to HTTPS (301) and send the HSTS header:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Best Practices","title":"Fix W3C HTML validation errors","impact":"Rendering stability, SEO indexing","problem":"W3C validator reports 7 errors including parser recovery failure at line 101 (bad start tag in iframe/noscript in head).","solution":"Move the Google Tag Manager iframe snippet out of the `<head>` or ensure it is properly closed within `<noscript>` without breaking the `<head>` structure. Remove invalid `name` attributes on `<meta>` tags inside the `<head>`."},{"priority":1,"category":"Security","title":"Fix HTTP redirect and add baseline security headers","impact":"Transport security, clickjacking, MIME sniffing","problem":"Security basics verdict is FAILED: HTTP does not redirect to HTTPS, HSTS is missing, and X-Content-Type-Options is missing.","solution":"Configure server to redirect HTTP to HTTPS and add headers:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Security","title":"Enforce HTTPS and add baseline security headers","impact":"Transport security, clickjacking, MIME sniffing","problem":"Security basics verdict is FAILED: HTTP does not redirect to HTTPS, HSTS is missing, and X-Content-Type-Options is missing.","solution":"Configure the web server to redirect all HTTP traffic to HTTPS and send these headers:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":1,"category":"Security","title":"Disable WordPress xmlrpc.php POST requests","impact":"Brute-force protection, pingback vector","problem":"Security basics report shows xmlrpc.php accepts POST requests, a known brute-force vector.","solution":"Block POST requests to xmlrpc.php in .htaccess or via a security plugin:\n```apache\n<Files xmlrpc.php>\n  <Limit POST>\n    deny from all\n  </Limit>\n</Files>\n```"},{"priority":1,"category":"Security","title":"Fix HTTP to HTTPS redirect and add HSTS","impact":"Transport security, Security Basics verdict","problem":"Security Basics FAILED: HTTP does not redirect to HTTPS and Strict-Transport-Security header is missing.","solution":"Configure server to redirect all HTTP traffic to HTTPS immediately.\n\nAdd HSTS header:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":1,"category":"Security","title":"Add X-Content-Type-Options header","impact":"MIME sniffing protection","problem":"Security Basics FAILED: X-Content-Type-Options header is missing.","solution":"Add the following header to prevent MIME type sniffing:\n```apache\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Performance","title":"Add explicit width and height to images","impact":"CLS (Cumulative Layout Shift)","problem":"50 images lack explicit width/height attributes, creating a high risk for layout shifts even though current CLS is 0.001.","solution":"Add `width` and `height` attributes to all `<img>` tags matching the intrinsic aspect ratio:\n```html\n<img src=\"image.jpg\" width=\"800\" height=\"600\" alt=\"...\">\n```"},{"priority":2,"category":"Accessibility","title":"Add skip-to-content link and main landmark","impact":"Keyboard navigation, screen reader usability","problem":"HTML inventory shows missing `main` landmark and no skip-to-content link; axe reports `region` and `landmark-unique` violations.","solution":"Add a skip link at the top of the body:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n```\nWrap the primary content in `<main id=\"main-content\">`."},{"priority":2,"category":"Security","title":"Disable WordPress xmlrpc.php POST requests","impact":"Brute-force protection, server load","problem":"Security basics report indicates xmlrpc.php accepts POST requests, a known brute-force vector.","solution":"Block POST requests to xmlrpc.php in `.htaccess`:\n```apache\n<Files xmlrpc.php>\n  <Limit POST>\n    deny from all\n  </Limit>\n</Files>\n```"},{"priority":2,"category":"Accessibility","title":"Fix color contrast and add main landmark","impact":"WCAG 1.4.3 contrast, 1.3.1 info and relationships","problem":"axe-core reports 1 serious violation on .heading__main contrast; document lacks a main landmark and skip-to-content link.","solution":"- Increase contrast on `.heading__main` to ≥4.5:1.\n- Add `<main id=\"main-content\">` wrapper around primary content.\n- Add skip link at top: `<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>`."},{"priority":2,"category":"Best Practices","title":"Resolve W3C HTML validation errors","impact":"Parser compatibility, SEO rendering","problem":"W3C Validator reports 7 errors including parser recovery failure at line 105 and invalid iframe/noscript placement in head.","solution":"- Move `<noscript><iframe>...</iframe></noscript>` out of `<head>` (likely GTM snippet).\n- Fix stray end tags and meta attributes.\n- Ensure `<body>` opens correctly after `</head>`."},{"priority":2,"category":"Accessibility","title":"Fix color contrast and heading hierarchy","impact":"WCAG 1.4.3 contrast, 1.3.1 heading order","problem":"axe-core found 1 serious color-contrast violation on h1 and .button, plus heading order skips (h1→h4).","solution":"- Adjust text colors to meet 4.5:1 contrast ratio.\n- Ensure headings follow sequential order (h1 → h2 → h3) without skipping levels."},{"priority":2,"category":"SEO","title":"Fix W3C HTML validation errors","impact":"Parser recovery, rendering consistency","problem":"W3C validator reported 7 errors including parser recovery failure at line 100 and invalid iframe/noscript placement in head.","solution":"- Move `<noscript><iframe>...</iframe></noscript>` out of `<head>`.\n- Ensure `<meta>` tags are placed correctly within `<head>`.\n- Validate HTML structure to prevent parser recovery mode."},{"priority":2,"category":"SEO","title":"Fix HTML validation errors","impact":"Parsing, SEO, Accessibility","problem":"W3C Validator reported 8 errors including parser recovery failure at line 102 and bad href attributes.","solution":"- Remove empty `href` attributes on `<link>` tags.\n- Fix `<noscript>` placement (not allowed in `<head>`).\n- Ensure `<meta>` tags are correctly placed within `<head>`."},{"priority":3,"category":"Security","title":"Strengthen Content-Security-Policy","impact":"XSS defense-in-depth","problem":"CSP is present but weak (missing default-src, object-src not 'none'). Site signals show no auth/payments/UGC, lowering priority.","solution":"Add `default-src 'self'` and `object-src 'none'` to the CSP header. Since this is a brochure site, a strict allowlist is less critical than basic headers, but improves defense-in-depth."},{"priority":3,"category":"Performance","title":"Add explicit width and height to images","impact":"CLS (Cumulative Layout Shift)","problem":"45 images lack width/height attributes, risking layout shifts despite current CLS of 0.037.","solution":"Add `width` and `height` attributes to all `<img>` tags:\n```html\n<img src=\"...\" alt=\"...\" width=\"300\" height=\"200\">\n```"},{"priority":3,"category":"Security","title":"Harden WordPress configuration","impact":"Brute-force protection, attack surface","problem":"xmlrpc.php accepts POST requests and /wp-admin/install.php is reachable.","solution":"- Disable xmlrpc.php in .htaccess or via plugin.\n- Block /wp-admin/install.php access after installation.\n- Consider changing default login path."},{"priority":3,"category":"Performance","title":"Eliminate render-blocking JavaScript","impact":"FCP, LCP, TBT","problem":"PSI findings estimate 1,230 ms savings from render-blocking insights; unused JS detected (23 KB).","solution":"- Add `defer` or `async` to non-critical scripts.\n- Inline critical CSS and defer non-critical JS.\n- Remove or tree-shake the 23 KB of unused jQuery code."},{"priority":3,"category":"Security","title":"Harden Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"Current CSP only sets `frame-ancestors 'self'`; missing `default-src` and `object-src 'none'`.","solution":"Since the site has no auth/payments (signals: no), a strict CSP is P3. If implemented later, use nonce-based CSP:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none';\"\n```"},{"priority":3,"category":"Performance","title":"Add image dimensions and lazy loading","impact":"CLS, Layout stability","problem":"HTML Inventory shows 45 images without explicit width/height and 45 without loading=\"lazy\".","solution":"Add `width` and `height` attributes to all `<img>` tags to reserve space.\nAdd `loading=\"lazy\"` to images below the fold:\n```html\n<img src=\"...\" alt=\"...\" width=\"300\" height=\"200\" loading=\"lazy\">\n```"},{"priority":3,"category":"Security","title":"Harden WordPress security endpoints","impact":"Brute-force protection, Attack surface","problem":"Security basics warn: xmlrpc.php accepts POST requests and /wp-admin/install.php is reachable.","solution":"- Disable xmlrpc.php in .htaccess or via plugin.\n- Block access to /wp-admin/install.php after installation:\n```apache\n<Files \"install.php\">\n  Require all denied\n</Files>\n```"}],"coverage":{"pct":95,"missing":["PageSpeed Insights (desktop): PSI HTTP 429","PageSpeed Insights (mobile): PSI HTTP 429","PageSpeed Insights: mobile: PSI HTTP 429; desktop: PSI HTTP 429"]},"siteSummary":{"pagesAudited":5,"pagesAttempted":5,"urls":["https://play.ee/","https://play.ee/team","https://play.ee/privacy-policy","https://play.ee/et/meeskond","https://play.ee/wordpress-support-service"]},"psiSnapshot":{"rows":[{"pageUrl":"https://play.ee/","perfMobile":96,"perfDesktop":100,"lcpMobileMs":2483,"lcpDesktopMs":546.2312592432351,"clsMobile":0.0005064474626039315,"clsDesktop":0.005474765902680219},{"pageUrl":"https://play.ee/team","perfMobile":94,"perfDesktop":100,"lcpMobileMs":2779,"lcpDesktopMs":633.2135074999999,"clsMobile":0.03746172483587625,"clsDesktop":0.00281041673381916},{"pageUrl":"https://play.ee/privacy-policy","perfMobile":93,"perfDesktop":null,"lcpMobileMs":2797.2842175000005,"lcpDesktopMs":null,"clsMobile":0.0018556562197882581,"clsDesktop":null},{"pageUrl":"https://play.ee/et/meeskond","perfMobile":null,"perfDesktop":100,"lcpMobileMs":null,"lcpDesktopMs":629.1196,"clsMobile":null,"clsDesktop":0.0033709687985643095}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket)","evidence":["HTML markers: WP Rocket","generator: WP Rocket 3.23.3.3"]},{"id":"compression","title":"Response compressed (gzip / brotli)","status":"pass","detail":"Document response is compressed with gzip.","evidence":["content-encoding: gzip","decoded body: 221727 bytes","ratio: 0.16"]},{"id":"lazyload","title":"Images lazy-loaded","status":"n/a","detail":"No raster <img> elements found (37 SVGs, 13 placeholders excluded).","evidence":[]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"n/a","detail":"No raster <img> elements found (37 SVGs, 13 placeholders excluded).","evidence":[]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"n/a","detail":"No CSS background-images detected on raster-image-eligible elements.","evidence":[]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"n/a","detail":"Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply.","evidence":[]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"n/a","detail":"Too few raster images to evaluate srcset width variety.","evidence":[]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"pass","detail":"No render-blocking scripts in <head>.","evidence":[]}],"summary":{"passed":3,"warned":0,"failed":0,"notApplicable":5},"priorities":[]},"perPageOverall":[{"url":"https://play.ee/","overall":78,"reasoning":"PSI mobile performance is excellent at 96, and accessibility scores are high at 94, indicating strong core UX. However, the Security basics verdict is FAILED due to missing HTTP-to-HTTPS redirect and HSTS, which caps the overall score below 90 per the rubric. W3C validation shows 7 errors with parser recovery failure, risking rendering stability and SEO indexing. Additionally, 50 images lack explicit dimensions, creating a latent CLS risk despite current low CLS scores.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS redirect and add HSTS","impact":"Transport security, trust, security basics score","problem":"Security basics verdict is FAILED; HTTP does not redirect to HTTPS and Strict-Transport-Security header is missing.","solution":"Configure the web server to redirect all HTTP traffic to HTTPS (301) and send the HSTS header:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Best Practices","title":"Fix W3C HTML validation errors","impact":"Rendering stability, SEO indexing","problem":"W3C validator reports 7 errors including parser recovery failure at line 101 (bad start tag in iframe/noscript in head).","solution":"Move the Google Tag Manager iframe snippet out of the `<head>` or ensure it is properly closed within `<noscript>` without breaking the `<head>` structure. Remove invalid `name` attributes on `<meta>` tags inside the `<head>`."},{"priority":2,"category":"Performance","title":"Add explicit width and height to images","impact":"CLS (Cumulative Layout Shift)","problem":"50 images lack explicit width/height attributes, creating a high risk for layout shifts even though current CLS is 0.001.","solution":"Add `width` and `height` attributes to all `<img>` tags matching the intrinsic aspect ratio:\n```html\n<img src=\"image.jpg\" width=\"800\" height=\"600\" alt=\"...\">\n```"},{"priority":2,"category":"Accessibility","title":"Add skip-to-content link and main landmark","impact":"Keyboard navigation, screen reader usability","problem":"HTML inventory shows missing `main` landmark and no skip-to-content link; axe reports `region` and `landmark-unique` violations.","solution":"Add a skip link at the top of the body:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n```\nWrap the primary content in `<main id=\"main-content\">`."},{"priority":2,"category":"Security","title":"Disable WordPress xmlrpc.php POST requests","impact":"Brute-force protection, server load","problem":"Security basics report indicates xmlrpc.php accepts POST requests, a known brute-force vector.","solution":"Block POST requests to xmlrpc.php in `.htaccess`:\n```apache\n<Files xmlrpc.php>\n  <Limit POST>\n    deny from all\n  </Limit>\n</Files>\n```"},{"priority":3,"category":"Security","title":"Strengthen Content-Security-Policy","impact":"XSS defense-in-depth","problem":"CSP is present but weak (missing default-src, object-src not 'none'). Site signals show no auth/payments/UGC, lowering priority.","solution":"Add `default-src 'self'` and `object-src 'none'` to the CSP header. Since this is a brochure site, a strict allowlist is less critical than basic headers, but improves defense-in-depth."}],"perfScore":96,"a11yScore":94,"bestPracticesScore":100,"seoScore":92,"securityScore":61,"securityVerdict":"FAILED"},{"url":"https://play.ee/team","overall":73,"reasoning":"PSI mobile performance is strong at 94 with excellent TTFB and CLS, though LCP sits at 2.8 s in the warning range. However, the Security basics verdict is FAILED due to missing HTTP-to-HTTPS redirects and HSTS, which caps the overall score below 90 per the rubric. Accessibility has a serious color-contrast violation and missing landmarks despite a 94 score. W3C validation reports 7 errors including parser recovery failure, indicating broken HTML structure. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Fix HTTP redirect and add baseline security headers","impact":"Transport security, clickjacking, MIME sniffing","problem":"Security basics verdict is FAILED: HTTP does not redirect to HTTPS, HSTS is missing, and X-Content-Type-Options is missing.","solution":"Configure server to redirect HTTP to HTTPS and add headers:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":2,"category":"Accessibility","title":"Fix color contrast and add main landmark","impact":"WCAG 1.4.3 contrast, 1.3.1 info and relationships","problem":"axe-core reports 1 serious violation on .heading__main contrast; document lacks a main landmark and skip-to-content link.","solution":"- Increase contrast on `.heading__main` to ≥4.5:1.\n- Add `<main id=\"main-content\">` wrapper around primary content.\n- Add skip link at top: `<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>`."},{"priority":2,"category":"Best Practices","title":"Resolve W3C HTML validation errors","impact":"Parser compatibility, SEO rendering","problem":"W3C Validator reports 7 errors including parser recovery failure at line 105 and invalid iframe/noscript placement in head.","solution":"- Move `<noscript><iframe>...</iframe></noscript>` out of `<head>` (likely GTM snippet).\n- Fix stray end tags and meta attributes.\n- Ensure `<body>` opens correctly after `</head>`."},{"priority":3,"category":"Performance","title":"Add explicit width and height to images","impact":"CLS (Cumulative Layout Shift)","problem":"45 images lack width/height attributes, risking layout shifts despite current CLS of 0.037.","solution":"Add `width` and `height` attributes to all `<img>` tags:\n```html\n<img src=\"...\" alt=\"...\" width=\"300\" height=\"200\">\n```"},{"priority":3,"category":"Security","title":"Harden WordPress configuration","impact":"Brute-force protection, attack surface","problem":"xmlrpc.php accepts POST requests and /wp-admin/install.php is reachable.","solution":"- Disable xmlrpc.php in .htaccess or via plugin.\n- Block /wp-admin/install.php access after installation.\n- Consider changing default login path."}],"perfScore":94,"a11yScore":94,"bestPracticesScore":100,"seoScore":100,"securityScore":59,"securityVerdict":"FAILED"},{"url":"https://play.ee/privacy-policy","overall":78,"reasoning":"PSI mobile performance is strong at 93, but LCP (2.8 s) and FCP (2.33 s) sit in warning zones. The Security basics verdict is FAILED due to missing HTTP→HTTPS redirects and HSTS, which caps the overall score below 90 per the rubric. Accessibility has a serious color-contrast violation and missing main landmark. W3C validation shows 7 errors including parser recovery failure, indicating structural HTML issues. Confidence is medium because PSI desktop errored and W3C output was truncated.","confidence":"medium","fixes":[{"priority":1,"category":"Security","title":"Enforce HTTPS and add baseline security headers","impact":"Transport security, clickjacking, MIME sniffing","problem":"Security basics verdict is FAILED: HTTP does not redirect to HTTPS, HSTS is missing, and X-Content-Type-Options is missing.","solution":"Configure the web server to redirect all HTTP traffic to HTTPS and send these headers:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":1,"category":"Security","title":"Disable WordPress xmlrpc.php POST requests","impact":"Brute-force protection, pingback vector","problem":"Security basics report shows xmlrpc.php accepts POST requests, a known brute-force vector.","solution":"Block POST requests to xmlrpc.php in .htaccess or via a security plugin:\n```apache\n<Files xmlrpc.php>\n  <Limit POST>\n    deny from all\n  </Limit>\n</Files>\n```"},{"priority":2,"category":"Accessibility","title":"Fix color contrast and heading hierarchy","impact":"WCAG 1.4.3 contrast, 1.3.1 heading order","problem":"axe-core found 1 serious color-contrast violation on h1 and .button, plus heading order skips (h1→h4).","solution":"- Adjust text colors to meet 4.5:1 contrast ratio.\n- Ensure headings follow sequential order (h1 → h2 → h3) without skipping levels."},{"priority":2,"category":"SEO","title":"Fix W3C HTML validation errors","impact":"Parser recovery, rendering consistency","problem":"W3C validator reported 7 errors including parser recovery failure at line 100 and invalid iframe/noscript placement in head.","solution":"- Move `<noscript><iframe>...</iframe></noscript>` out of `<head>`.\n- Ensure `<meta>` tags are placed correctly within `<head>`.\n- Validate HTML structure to prevent parser recovery mode."},{"priority":3,"category":"Performance","title":"Eliminate render-blocking JavaScript","impact":"FCP, LCP, TBT","problem":"PSI findings estimate 1,230 ms savings from render-blocking insights; unused JS detected (23 KB).","solution":"- Add `defer` or `async` to non-critical scripts.\n- Inline critical CSS and defer non-critical JS.\n- Remove or tree-shake the 23 KB of unused jQuery code."},{"priority":3,"category":"Security","title":"Harden Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"Current CSP only sets `frame-ancestors 'self'`; missing `default-src` and `object-src 'none'`.","solution":"Since the site has no auth/payments (signals: no), a strict CSP is P3. If implemented later, use nonce-based CSP:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none';\"\n```"}],"perfScore":93,"a11yScore":87,"bestPracticesScore":100,"seoScore":100,"securityScore":59,"securityVerdict":"FAILED"},{"url":"https://play.ee/et/meeskond","overall":74,"reasoning":"Performance scores appear excellent (100) but mobile data is unreliable due to PSI HTTP 429 error (desktop data duplicated), lowering confidence. Security Basics FAILED (missing HSTS, X-Content-Type-Options, HTTP redirect) caps the score below 90 per rubric. Accessibility has 1 serious violation (color-contrast) and missing main landmark. HTML validation shows 8 errors including parser recovery failure, indicating structural issues. Image assets lack dimensions (45 images) risking CLS despite low lab scores.","confidence":"medium","fixes":[{"priority":1,"category":"Security","title":"Fix HTTP to HTTPS redirect and add HSTS","impact":"Transport security, Security Basics verdict","problem":"Security Basics FAILED: HTTP does not redirect to HTTPS and Strict-Transport-Security header is missing.","solution":"Configure server to redirect all HTTP traffic to HTTPS immediately.\n\nAdd HSTS header:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":1,"category":"Security","title":"Add X-Content-Type-Options header","impact":"MIME sniffing protection","problem":"Security Basics FAILED: X-Content-Type-Options header is missing.","solution":"Add the following header to prevent MIME type sniffing:\n```apache\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Accessibility","title":"Fix color contrast and add main landmark","impact":"WCAG 1.4.3, WCAG 1.3.1","problem":"axe-core found 1 serious violation (color-contrast on h1 headings) and missing main landmark.","solution":"- Increase contrast ratio for `.heading__main` text to ≥4.5:1.\n- Wrap primary content in `<main>` tag.\n- Add skip-to-content link at top of page."},{"priority":2,"category":"SEO","title":"Fix HTML validation errors","impact":"Parsing, SEO, Accessibility","problem":"W3C Validator reported 8 errors including parser recovery failure at line 102 and bad href attributes.","solution":"- Remove empty `href` attributes on `<link>` tags.\n- Fix `<noscript>` placement (not allowed in `<head>`).\n- Ensure `<meta>` tags are correctly placed within `<head>`."},{"priority":3,"category":"Performance","title":"Add image dimensions and lazy loading","impact":"CLS, Layout stability","problem":"HTML Inventory shows 45 images without explicit width/height and 45 without loading=\"lazy\".","solution":"Add `width` and `height` attributes to all `<img>` tags to reserve space.\nAdd `loading=\"lazy\"` to images below the fold:\n```html\n<img src=\"...\" alt=\"...\" width=\"300\" height=\"200\" loading=\"lazy\">\n```"},{"priority":3,"category":"Security","title":"Harden WordPress security endpoints","impact":"Brute-force protection, Attack surface","problem":"Security basics warn: xmlrpc.php accepts POST requests and /wp-admin/install.php is reachable.","solution":"- Disable xmlrpc.php in .htaccess or via plugin.\n- Block access to /wp-admin/install.php after installation:\n```apache\n<Files \"install.php\">\n  Require all denied\n</Files>\n```"}],"perfScore":100,"a11yScore":93,"bestPracticesScore":100,"seoScore":100,"securityScore":59,"securityVerdict":"FAILED"},{"url":"https://play.ee/wordpress-support-service","overall":null,"reasoning":"Insufficient data to score this site — PageSpeed Insights did not return usable data for either mobile or desktop. Re-run the audit once the source is reachable.","confidence":"low","fixes":[],"perfScore":null,"a11yScore":null,"bestPracticesScore":null,"seoScore":null,"securityScore":59,"securityVerdict":"FAILED"}]}