# Audit Report: Perfectly formed web development team - gotoAndPlay **Website:** https://play.ee/ **Date:** 24.09.2026 **Audit Coverage:** 98% — PageSpeed Insights: mobile: PSI HTTP 429; desktop: PSI HTTP 429 **Confidence:** low **Pages Audited (5 of 5):** - https://play.ee/ - https://play.ee/team - https://play.ee/privacy-policy - https://play.ee/et/meeskond - https://play.ee/wordpress-support-service ## Summary of results **Overall Score:** 75 / 100 **Status:** ⚠ 🟡 **Needs Improvement** Site overall 75 is the mean of 4 pages. Scores range 72 (https://play.ee/et/meeskond) → 78 (https://play.ee/team). Weakest page: Mobile PSI 83 with CLS 0.23 and LCP 2.6s indicates moderate performance issues. Security Basics FAILED due to missing HSTS and HTTP redirect, capping the score below 90. One serious accessibility violation on color contrast and 45 images missing dimensions further reduce quality. W3C validation shows 8 errors including parser recovery failure. Confidence is high as all audit tools returned data. ### Per-page scores 🟡 **Needs Improvement** · https://play.ee/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 76 | 97 | 94 | 100 | 92 | FAILED | 🟡 **Needs Improvement** · https://play.ee/team | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 78 | 95 | 94 | 100 | 100 | FAILED | 🟡 **Needs Improvement** · https://play.ee/privacy-policy | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 74 | 94 | 87 | 100 | 100 | FAILED | 🟡 **Needs Improvement** · https://play.ee/et/meeskond | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 72 | 83 | 94 | 100 | 100 | FAILED | — · https://play.ee/wordpress-support-service | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | — | — | — | — | — | FAILED | ## PageSpeed Insights — Mobile vs Desktop _Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._ | URL | Performance (M / D) | LCP (M / D) | CLS (M / D) | | --- | --- | --- | --- | | https://play.ee/ | **97** / 100 | **2.33 s** / 548 ms | 0.001 / **0.006** | | https://play.ee/team | **95** / 99 | **2.58 s** / 645 ms | **0.036** / 0.003 | | https://play.ee/privacy-policy | **94** / 99 | **2.73 s** / 788 ms | 0.002 / **0.003** | | https://play.ee/et/meeskond | **83** / 100 | **2.63 s** / 704 ms | **0.230** / 0.004 | ## Optimization Checklist **3 of 3 passing** — 3 pass · 0 warn · 0 fail · 5 n/a | Item | Status | Detail | | --- | --- | --- | | Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) | | Response compressed (gzip / brotli) | **Pass** | Document response is compressed with gzip. | | Images lazy-loaded | N/A | No raster elements found (37 SVGs, 13 placeholders excluded). | | Hero image eagerly loaded | N/A | No raster elements found (37 SVGs, 13 placeholders excluded). | | Hero is a real (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. | | Responsive images (srcset / ) | N/A | Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply. | | Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. | | JS scripts not blocking in | **Pass** | No render-blocking scripts in . | ## Fixes ### Priority 1: Critical *Immediate action — impacts user experience, search rankings, or site safety.* **1A. Fix HTTP redirect and add baseline security headers** `Security` - **Impact:** Transport security, clickjacking, MIME sniffing - **Problem:** Security Basics FAILED: http://play.ee/ does not redirect to HTTPS, HSTS is missing, and X-Content-Type-Options is missing. - **Solution:** Configure server to redirect HTTP to HTTPS and send these headers: ```apache Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" Header always set X-Content-Type-Options "nosniff" RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **1B. Fix color contrast failures** `Accessibility` - **Impact:** WCAG 1.4.3 Contrast - **Problem:** PSI Accessibility audit `color-contrast` failed with score 0.00, indicating insufficient contrast on foreground/background elements. - **Solution:** Audit all text elements against WCAG 2.1 AA (4.5:1 for normal text). Increase contrast ratios on low-contrast text blocks identified in the PSI report. **1C. Fix color contrast on headings and buttons** `Accessibility` - **Impact:** WCAG 1.4.3 Contrast, Screen Reader usability - **Problem:** axe-core reports 1 serious violation: color-contrast on h1 > .heading__main and .button elements. - **Solution:** Increase contrast ratio to at least 4.5:1 for normal text. - Adjust `.heading__main` color to darker shade (e.g., #333 on #fff). - Adjust `.button` text/background colors to meet AA standards. **1D. Add baseline security headers and enforce HTTPS** `Security` - **Impact:** Transport security, clickjacking, MIME sniffing - **Problem:** Security basics verdict FAILED: HTTP does not redirect to HTTPS, HSTS missing, X-Content-Type-Options missing. - **Solution:** Configure server to redirect HTTP to HTTPS, add HSTS (max-age=31536000; includeSubDomains), and X-Content-Type-Options: nosniff. **1E. Add explicit width and height to images** `Performance` - **Impact:** CLS, LCP - **Problem:** CLS 0.23 (warning) and 45 images missing width/height attributes in HTML inventory. - **Solution:** Add `width` and `height` attributes to all `` tags or use CSS aspect-ratio to reserve space. ### Priority 2: Important *Essential for compliance, user reach, and search visibility.* **2A. Fix W3C HTML validation errors** `SEO` - **Impact:** Rendering, SEO, Maintainability - **Problem:** W3C Validator reported 7 errors including parser recovery failure at line 101 and invalid iframe placement in noscript within head. - **Solution:** Move `` out of `` and into ``. Ensure `` tags in head do not use invalid attributes like `name` where `property` is required. **2B. Harden WordPress installation** `Security` - **Impact:** Brute-force protection, Attack surface - **Problem:** xmlrpc.php accepts POST requests (brute-force vector) and /wp-admin/install.php is reachable. - **Solution:** Disable xmlrpc.php via .htaccess or plugin. Block access to /wp-admin/install.php after installation: ```apache Require all denied ``` **2C. Fix color contrast and add main landmark** `Accessibility` - **Impact:** WCAG 1.4.3 contrast, 1.3.1 info and relationships - **Problem:** axe-core found 1 serious color-contrast violation on headings and missing `main` landmark (PSI Accessibility 94 but axe found issues). - **Solution:** - Increase contrast on `.heading__main` to ≥4.5:1. - Wrap primary content in `
` tag. - Add `` before navigation. **2D. Resolve W3C HTML validation errors** `Best Practices` - **Impact:** SEO indexing, rendering stability - **Problem:** W3C validator reported 7 errors including parser recovery failure at line 105 (iframe/noscript in head). - **Solution:** - Move `` out of `` (allowed in ``). - Fix stray `` and `` tags. - Ensure `` tags use valid attributes (`property` or `itemprop` instead of `name` where required). **2E. Add baseline security headers (HSTS, HTTP redirect, X-Content-Type-Options)** `Security` - **Impact:** Transport security, Clickjacking, MIME sniffing - **Problem:** Security Basics verdict is FAILED: HTTP does not redirect to HTTPS, HSTS missing, X-Content-Type-Options missing. - **Solution:** Configure server to enforce HTTPS and send headers: ```apache Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" Header always set X-Content-Type-Options "nosniff" RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] ``` **2F. Fix HTML validation errors (Parser recovery, iframe in noscript)** `Best Practices` - **Impact:** SEO, Rendering consistency - **Problem:** W3C Validator reports 7 errors including parser recovery failure at line 100 and bad start tag in iframe in noscript in head. - **Solution:** Move Google Tag Manager iframe out of `` or ensure proper `