{"url":"https://play.ee/","date":"2026-09-24","siteName":"Perfectly formed web development team - gotoAndPlay","overall":75,"reasoning":"Site overall 75 is the mean of 4 pages. Scores range 72 (https://play.ee/et/meeskond) → 78 (https://play.ee/team). Weakest page: Mobile PSI 83 with CLS 0.23 and LCP 2.6s indicates moderate performance issues. Security Basics FAILED due to missing HSTS and HTTP redirect, capping the score below 90. One serious accessibility violation on color contrast and 45 images missing dimensions further reduce quality. W3C validation shows 8 errors including parser recovery failure. Confidence is high as all audit tools returned data.","confidence":"low","fixes":[{"priority":1,"category":"Security","title":"Fix HTTP redirect and add baseline security headers","impact":"Transport security, clickjacking, MIME sniffing","problem":"Security Basics FAILED: http://play.ee/ does not redirect to HTTPS, HSTS is missing, and X-Content-Type-Options is missing.","solution":"Configure server to redirect HTTP to HTTPS and send these headers:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Accessibility","title":"Fix color contrast failures","impact":"WCAG 1.4.3 Contrast","problem":"PSI Accessibility audit `color-contrast` failed with score 0.00, indicating insufficient contrast on foreground/background elements.","solution":"Audit all text elements against WCAG 2.1 AA (4.5:1 for normal text). Increase contrast ratios on low-contrast text blocks identified in the PSI report."},{"priority":1,"category":"Accessibility","title":"Fix color contrast on headings and buttons","impact":"WCAG 1.4.3 Contrast, Screen Reader usability","problem":"axe-core reports 1 serious violation: color-contrast on h1 > .heading__main and .button elements.","solution":"Increase contrast ratio to at least 4.5:1 for normal text.\n- Adjust `.heading__main` color to darker shade (e.g., #333 on #fff).\n- Adjust `.button` text/background colors to meet AA standards."},{"priority":1,"category":"Security","title":"Add baseline security headers and enforce HTTPS","impact":"Transport security, clickjacking, MIME sniffing","problem":"Security basics verdict FAILED: HTTP does not redirect to HTTPS, HSTS missing, X-Content-Type-Options missing.","solution":"Configure server to redirect HTTP to HTTPS, add HSTS (max-age=31536000; includeSubDomains), and X-Content-Type-Options: nosniff."},{"priority":1,"category":"Performance","title":"Add explicit width and height to images","impact":"CLS, LCP","problem":"CLS 0.23 (warning) and 45 images missing width/height attributes in HTML inventory.","solution":"Add `width` and `height` attributes to all `<img>` tags or use CSS aspect-ratio to reserve space."},{"priority":2,"category":"SEO","title":"Fix W3C HTML validation errors","impact":"Rendering, SEO, Maintainability","problem":"W3C Validator reported 7 errors including parser recovery failure at line 101 and invalid iframe placement in noscript within head.","solution":"Move `<noscript><iframe>...</iframe></noscript>` out of `<head>` and into `<body>`. Ensure `<meta>` tags in head do not use invalid attributes like `name` where `property` is required."},{"priority":2,"category":"Security","title":"Harden WordPress installation","impact":"Brute-force protection, Attack surface","problem":"xmlrpc.php accepts POST requests (brute-force vector) and /wp-admin/install.php is reachable.","solution":"Disable xmlrpc.php via .htaccess or plugin. Block access to /wp-admin/install.php after installation:\n```apache\n<Files \"install.php\">\n  Require all denied\n</Files>\n```"},{"priority":2,"category":"Accessibility","title":"Fix color contrast and add main landmark","impact":"WCAG 1.4.3 contrast, 1.3.1 info and relationships","problem":"axe-core found 1 serious color-contrast violation on headings and missing `main` landmark (PSI Accessibility 94 but axe found issues).","solution":"- Increase contrast on `.heading__main` to ≥4.5:1.\n- Wrap primary content in `<main>` tag.\n- Add `<a href=\"#content\" class=\"skip-link\">Skip to content</a>` before navigation."},{"priority":2,"category":"Best Practices","title":"Resolve W3C HTML validation errors","impact":"SEO indexing, rendering stability","problem":"W3C validator reported 7 errors including parser recovery failure at line 105 (iframe/noscript in head).","solution":"- Move `<noscript><iframe>...</iframe></noscript>` out of `<head>` (allowed in `<body>`).\n- Fix stray `</noscript>` and `</head>` tags.\n- Ensure `<meta>` tags use valid attributes (`property` or `itemprop` instead of `name` where required)."},{"priority":2,"category":"Security","title":"Add baseline security headers (HSTS, HTTP redirect, X-Content-Type-Options)","impact":"Transport security, Clickjacking, MIME sniffing","problem":"Security Basics verdict is FAILED: HTTP does not redirect to HTTPS, HSTS missing, X-Content-Type-Options missing.","solution":"Configure server to enforce HTTPS and send headers:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":2,"category":"Best Practices","title":"Fix HTML validation errors (Parser recovery, iframe in noscript)","impact":"SEO, Rendering consistency","problem":"W3C Validator reports 7 errors including parser recovery failure at line 100 and bad start tag in iframe in noscript in head.","solution":"Move Google Tag Manager iframe out of `<head>` or ensure proper `<noscript>` nesting.\n- Remove `<meta name=\"generator\">` or ensure it complies with HTML5 spec.\n- Validate HTML structure to prevent parser recovery mode."},{"priority":2,"category":"Accessibility","title":"Fix color contrast on headings","impact":"WCAG 1.4.3","problem":"axe-core reports 1 serious violation: color-contrast on h1 and .heading__main.","solution":"Increase contrast ratio to ≥4.5:1 for text against background (e.g., darken text or lighten background)."},{"priority":2,"category":"Security","title":"Harden WordPress security endpoints","impact":"Brute-force protection","problem":"xmlrpc.php accepts POST requests and /wp-admin/install.php is reachable.","solution":"Disable xmlrpc.php via .htaccess or plugin, and block access to /wp-admin/install.php after installation."},{"priority":3,"category":"Performance","title":"Add explicit width and height to images","impact":"CLS, Layout stability","problem":"HTML Inventory shows 50 images without width/height attributes, risking layout shifts on load.","solution":"Add `width` and `height` attributes to all `<img>` tags matching their intrinsic dimensions. For responsive images, use `width` and `height` on the `<img>` tag and `srcset` on the source."},{"priority":3,"category":"Security","title":"Harden Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is present but weak (missing `default-src`, `object-src 'none'`). Site signals show no auth/payments, so this is lower priority.","solution":"Update CSP to include restrictive defaults:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self';\"\n```"},{"priority":3,"category":"Performance","title":"Optimize Largest Contentful Paint (LCP)","impact":"LCP, FCP, Perceived load speed","problem":"Mobile LCP is 2.7s (warning range) with render-blocking insights estimating 1,030ms savings.","solution":"- Preload critical fonts and LCP image.\n- Defer non-critical JavaScript.\n- Ensure server response time (TTFB 34ms is good) remains low under load."}],"coverage":{"pct":98,"missing":["PageSpeed Insights: mobile: PSI HTTP 429; desktop: PSI HTTP 429"]},"siteSummary":{"pagesAudited":5,"pagesAttempted":5,"urls":["https://play.ee/","https://play.ee/team","https://play.ee/privacy-policy","https://play.ee/et/meeskond","https://play.ee/wordpress-support-service"]},"psiSnapshot":{"rows":[{"pageUrl":"https://play.ee/","perfMobile":97,"perfDesktop":100,"lcpMobileMs":2326,"lcpDesktopMs":547.8212749194603,"clsMobile":0.001012894925207863,"clsDesktop":0.006012985631903462},{"pageUrl":"https://play.ee/team","perfMobile":95,"perfDesktop":99,"lcpMobileMs":2580.9777400000003,"lcpDesktopMs":644.9522474999999,"clsMobile":0.03626382017082964,"clsDesktop":0.0026357958450812895},{"pageUrl":"https://play.ee/privacy-policy","perfMobile":94,"perfDesktop":99,"lcpMobileMs":2728.0124800000003,"lcpDesktopMs":788.2058200000001,"clsMobile":0.002002927346531788,"clsDesktop":0.00281041673381916},{"pageUrl":"https://play.ee/et/meeskond","perfMobile":83,"perfDesktop":100,"lcpMobileMs":2629,"lcpDesktopMs":704.049595,"clsMobile":0.2300093455322303,"clsDesktop":0.0036013958895362384}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket)","evidence":["HTML markers: WP Rocket","generator: WP Rocket 3.23.3.3"]},{"id":"compression","title":"Response compressed (gzip / brotli)","status":"pass","detail":"Document response is compressed with gzip.","evidence":["content-encoding: gzip","decoded body: 221727 bytes","ratio: 0.16"]},{"id":"lazyload","title":"Images lazy-loaded","status":"n/a","detail":"No raster <img> elements found (37 SVGs, 13 placeholders excluded).","evidence":[]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"n/a","detail":"No raster <img> elements found (37 SVGs, 13 placeholders excluded).","evidence":[]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"n/a","detail":"No CSS background-images detected on raster-image-eligible elements.","evidence":[]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"n/a","detail":"Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply.","evidence":[]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"n/a","detail":"Too few raster images to evaluate srcset width variety.","evidence":[]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"pass","detail":"No render-blocking scripts in <head>.","evidence":[]}],"summary":{"passed":3,"warned":0,"failed":0,"notApplicable":5},"priorities":[]},"perPageOverall":[{"url":"https://play.ee/","overall":76,"reasoning":"Performance is excellent (PSI Mobile 97, LCP 2.3 s), but foundational hygiene drags the score down significantly. Security Basics FAILED due to missing HTTP→HTTPS redirect, HSTS, and X-Content-Type-Options headers. Accessibility has a critical failure in PSI `color-contrast` (score 0.00) alongside 7 W3C validation errors including parser recovery failure. Image assets lack dimensions (50 images), posing CLS risk despite current low CLS. WordPress hardening is incomplete (xmlrpc.php open, install.php reachable).","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Fix HTTP redirect and add baseline security headers","impact":"Transport security, clickjacking, MIME sniffing","problem":"Security Basics FAILED: http://play.ee/ does not redirect to HTTPS, HSTS is missing, and X-Content-Type-Options is missing.","solution":"Configure server to redirect HTTP to HTTPS and send these headers:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"category":"Accessibility","title":"Fix color contrast failures","impact":"WCAG 1.4.3 Contrast","problem":"PSI Accessibility audit `color-contrast` failed with score 0.00, indicating insufficient contrast on foreground/background elements.","solution":"Audit all text elements against WCAG 2.1 AA (4.5:1 for normal text). Increase contrast ratios on low-contrast text blocks identified in the PSI report."},{"priority":2,"category":"SEO","title":"Fix W3C HTML validation errors","impact":"Rendering, SEO, Maintainability","problem":"W3C Validator reported 7 errors including parser recovery failure at line 101 and invalid iframe placement in noscript within head.","solution":"Move `<noscript><iframe>...</iframe></noscript>` out of `<head>` and into `<body>`. Ensure `<meta>` tags in head do not use invalid attributes like `name` where `property` is required."},{"priority":2,"category":"Security","title":"Harden WordPress installation","impact":"Brute-force protection, Attack surface","problem":"xmlrpc.php accepts POST requests (brute-force vector) and /wp-admin/install.php is reachable.","solution":"Disable xmlrpc.php via .htaccess or plugin. Block access to /wp-admin/install.php after installation:\n```apache\n<Files \"install.php\">\n  Require all denied\n</Files>\n```"},{"priority":3,"category":"Performance","title":"Add explicit width and height to images","impact":"CLS, Layout stability","problem":"HTML Inventory shows 50 images without width/height attributes, risking layout shifts on load.","solution":"Add `width` and `height` attributes to all `<img>` tags matching their intrinsic dimensions. For responsive images, use `width` and `height` on the `<img>` tag and `srcset` on the source."}],"perfScore":97,"a11yScore":94,"bestPracticesScore":100,"seoScore":92,"securityScore":61,"securityVerdict":"FAILED"},{"url":"https://play.ee/team","overall":78,"reasoning":"PSI mobile 95 indicates strong performance (LCP 2.6 s, CLS 0.036), but Security Basics FAILED due to missing HTTP→HTTPS redirect and HSTS, capping the overall score below 90. W3C validation returned 7 errors including parser recovery failure at line 105, risking rendering stability. Accessibility has one serious color-contrast violation and missing main landmark despite a 94 PSI score. Image assets lack explicit dimensions (45 images), posing a CLS risk despite current low shift. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Fix HTTP redirect and add baseline security headers","impact":"Transport security, clickjacking, MIME sniffing","problem":"Security Basics FAILED: HTTP does not redirect to HTTPS, HSTS is missing, and X-Content-Type-Options is missing.","solution":"Configure server to force HTTPS and send these headers:\n```apache\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Accessibility","title":"Fix color contrast and add main landmark","impact":"WCAG 1.4.3 contrast, 1.3.1 info and relationships","problem":"axe-core found 1 serious color-contrast violation on headings and missing `main` landmark (PSI Accessibility 94 but axe found issues).","solution":"- Increase contrast on `.heading__main` to ≥4.5:1.\n- Wrap primary content in `<main>` tag.\n- Add `<a href=\"#content\" class=\"skip-link\">Skip to content</a>` before navigation."},{"priority":2,"category":"Best Practices","title":"Resolve W3C HTML validation errors","impact":"SEO indexing, rendering stability","problem":"W3C validator reported 7 errors including parser recovery failure at line 105 (iframe/noscript in head).","solution":"- Move `<noscript><iframe>...</iframe></noscript>` out of `<head>` (allowed in `<body>`).\n- Fix stray `</noscript>` and `</head>` tags.\n- Ensure `<meta>` tags use valid attributes (`property` or `itemprop` instead of `name` where required)."},{"priority":3,"category":"Performance","title":"Add explicit width and height to images","impact":"CLS (Cumulative Layout Shift)","problem":"45 images lack explicit width/height attributes, which can cause layout shifts when images load.","solution":"Add `width` and `height` attributes to all `<img>` tags matching the intrinsic aspect ratio:\n```html\n<img src=\"team.jpg\" alt=\"Name\" width=\"300\" height=\"400\">\n```"},{"priority":3,"category":"Security","title":"Harden Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is present but weak (missing `default-src`, `object-src 'none'`). Site signals show no auth/payments, so this is lower priority.","solution":"Update CSP to include restrictive defaults:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self';\"\n```"}],"perfScore":95,"a11yScore":94,"bestPracticesScore":100,"seoScore":100,"securityScore":59,"securityVerdict":"FAILED"},{"url":"https://play.ee/privacy-policy","overall":74,"reasoning":"PSI mobile 94 indicates strong performance, but Security Basics FAILED caps the overall score below 90 per rubric. Accessibility has 1 serious color-contrast violation and missing `main` landmark, dragging the A11y score. W3C reports 7 errors including parser recovery failure, indicating structural HTML issues. LCP is 2.7s (warning range) despite the high performance score due to render-blocking resources. Confidence is high as all tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Accessibility","title":"Fix color contrast on headings and buttons","impact":"WCAG 1.4.3 Contrast, Screen Reader usability","problem":"axe-core reports 1 serious violation: color-contrast on h1 > .heading__main and .button elements.","solution":"Increase contrast ratio to at least 4.5:1 for normal text.\n- Adjust `.heading__main` color to darker shade (e.g., #333 on #fff).\n- Adjust `.button` text/background colors to meet AA standards."},{"priority":2,"category":"Security","title":"Add baseline security headers (HSTS, HTTP redirect, X-Content-Type-Options)","impact":"Transport security, Clickjacking, MIME sniffing","problem":"Security Basics verdict is FAILED: HTTP does not redirect to HTTPS, HSTS missing, X-Content-Type-Options missing.","solution":"Configure server to enforce HTTPS and send headers:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":2,"category":"Best Practices","title":"Fix HTML validation errors (Parser recovery, iframe in noscript)","impact":"SEO, Rendering consistency","problem":"W3C Validator reports 7 errors including parser recovery failure at line 100 and bad start tag in iframe in noscript in head.","solution":"Move Google Tag Manager iframe out of `<head>` or ensure proper `<noscript>` nesting.\n- Remove `<meta name=\"generator\">` or ensure it complies with HTML5 spec.\n- Validate HTML structure to prevent parser recovery mode."},{"priority":3,"category":"Performance","title":"Optimize Largest Contentful Paint (LCP)","impact":"LCP, FCP, Perceived load speed","problem":"Mobile LCP is 2.7s (warning range) with render-blocking insights estimating 1,030ms savings.","solution":"- Preload critical fonts and LCP image.\n- Defer non-critical JavaScript.\n- Ensure server response time (TTFB 34ms is good) remains low under load."}],"perfScore":94,"a11yScore":87,"bestPracticesScore":100,"seoScore":100,"securityScore":59,"securityVerdict":"FAILED"},{"url":"https://play.ee/et/meeskond","overall":72,"reasoning":"Mobile PSI 83 with CLS 0.23 and LCP 2.6s indicates moderate performance issues. Security Basics FAILED due to missing HSTS and HTTP redirect, capping the score below 90. One serious accessibility violation on color contrast and 45 images missing dimensions further reduce quality. W3C validation shows 8 errors including parser recovery failure. Confidence is high as all audit tools returned data.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Add baseline security headers and enforce HTTPS","impact":"Transport security, clickjacking, MIME sniffing","problem":"Security basics verdict FAILED: HTTP does not redirect to HTTPS, HSTS missing, X-Content-Type-Options missing.","solution":"Configure server to redirect HTTP to HTTPS, add HSTS (max-age=31536000; includeSubDomains), and X-Content-Type-Options: nosniff."},{"priority":1,"category":"Performance","title":"Add explicit width and height to images","impact":"CLS, LCP","problem":"CLS 0.23 (warning) and 45 images missing width/height attributes in HTML inventory.","solution":"Add `width` and `height` attributes to all `<img>` tags or use CSS aspect-ratio to reserve space."},{"priority":2,"category":"Accessibility","title":"Fix color contrast on headings","impact":"WCAG 1.4.3","problem":"axe-core reports 1 serious violation: color-contrast on h1 and .heading__main.","solution":"Increase contrast ratio to ≥4.5:1 for text against background (e.g., darken text or lighten background)."},{"priority":2,"category":"Best Practices","title":"Resolve W3C HTML validation errors","impact":"Parser reliability, SEO","problem":"W3C Validator reports 8 errors including parser recovery failure at line 102.","solution":"Fix malformed tags in `<head>` (e.g., empty href on link, iframe in noscript) to ensure valid DOM structure."},{"priority":2,"category":"Security","title":"Harden WordPress security endpoints","impact":"Brute-force protection","problem":"xmlrpc.php accepts POST requests and /wp-admin/install.php is reachable.","solution":"Disable xmlrpc.php via .htaccess or plugin, and block access to /wp-admin/install.php after installation."}],"perfScore":83,"a11yScore":94,"bestPracticesScore":100,"seoScore":100,"securityScore":59,"securityVerdict":"FAILED"},{"url":"https://play.ee/wordpress-support-service","overall":null,"reasoning":"Insufficient data to score this site — PageSpeed Insights did not return usable data for either mobile or desktop. Re-run the audit once the source is reachable.","confidence":"low","fixes":[],"perfScore":null,"a11yScore":null,"bestPracticesScore":null,"seoScore":null,"securityScore":59,"securityVerdict":"FAILED"}]}