{"url":"https://play.ee/","date":"2026-09-24","siteName":"Perfectly formed web development team - gotoAndPlay","overall":78,"reasoning":"PSI mobile 97 indicates excellent performance (LCP 2.3 s, CLS 0.001), but the Security basics verdict is FAILED. Per the audit protocol: 'Treat FAILED as a must-fix and PASS as a starting point, not a certificate.' W3C validation returned 7 errors including parser recovery failure, and accessibility has 2 moderate violations plus missing landmarks. Image assets lack width/height attributes on all 50 images, risking future CLS. These structural and security hygiene issues prevent a higher score despite the fast load times.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Fix HTTP redirect and add baseline security headers","impact":"Transport security, clickjacking, MIME sniffing","problem":"Security basics verdict is FAILED: http:// does not redirect to https, HSTS is missing, and X-Content-Type-Options is missing.","solution":"Configure server to redirect HTTP to HTTPS and send these headers:\n```\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\nRedirect permanent / https://play.ee/\n```"},{"priority":2,"category":"SEO","title":"Fix W3C HTML validation errors","impact":"Parser recovery, document structure","problem":"W3C validator reported 7 errors including 'Cannot recover after last error' at line 101 and bad iframe/noscript nesting in head.","solution":"Move `<noscript><iframe>...</iframe></noscript>` out of `<head>` or ensure it is valid HTML5. Remove stray end tags and fix meta tag attributes (e.g., `name` vs `property`)."},{"priority":2,"category":"Accessibility","title":"Add skip-to-content link and fix landmarks","impact":"Keyboard navigation, screen reader flow","problem":"axe-core found `landmark-unique` and `region` violations; HTML inventory confirms missing `main` landmark and skip link.","solution":"Add a skip link at the top of the body:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n```\nWrap main content in `<main id=\"main-content\">` and ensure nav/footer have unique labels."},{"priority":2,"category":"Performance","title":"Add width and height to all images","impact":"CLS (Cumulative Layout Shift)","problem":"HTML inventory shows 50 images without explicit width/height attributes, risking layout shifts despite current CLS of 0.001.","solution":"Add `width` and `height` attributes to all `<img>` tags matching their intrinsic dimensions. For responsive images, use `srcset` with corresponding sizes."},{"priority":2,"category":"Security","title":"Harden WordPress installation","impact":"Brute-force protection, attack surface","problem":"Security basics flagged `xmlrpc.php` accepts POST requests and `/wp-admin/install.php` is reachable.","solution":"Disable xmlrpc.php in .htaccess or via plugin. Block access to `/wp-admin/install.php` after installation:\n```apache\n<Files install.php>\n  Order Allow,Deny\n  Deny from all\n</Files>\n```"}],"coverage":{"pct":100,"missing":[]},"siteSummary":{"pagesAudited":1,"pagesAttempted":1,"urls":["https://play.ee/"]},"psiSnapshot":{"rows":[{"pageUrl":null,"perfMobile":97,"perfDesktop":100,"lcpMobileMs":2326,"lcpDesktopMs":588,"clsMobile":0.001012894925207863,"clsDesktop":0.00678706602142075}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket)","evidence":["HTML markers: WP Rocket","generator: WP Rocket 3.23.3.3"]},{"id":"compression","title":"Response compressed (gzip / brotli)","status":"pass","detail":"Document response is compressed with gzip.","evidence":["content-encoding: gzip","decoded body: 221727 bytes","ratio: 0.16"]},{"id":"lazyload","title":"Images lazy-loaded","status":"n/a","detail":"No raster <img> elements found (37 SVGs, 13 placeholders excluded).","evidence":[]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"n/a","detail":"No raster <img> elements found (37 SVGs, 13 placeholders excluded).","evidence":[]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"n/a","detail":"No CSS background-images detected on raster-image-eligible elements.","evidence":[]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"n/a","detail":"Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply.","evidence":[]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"n/a","detail":"Too few raster images to evaluate srcset width variety.","evidence":[]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"pass","detail":"No render-blocking scripts in <head>.","evidence":[]}],"summary":{"passed":3,"warned":0,"failed":0,"notApplicable":5},"priorities":[]},"perPageOverall":[{"url":"https://play.ee/","overall":78,"reasoning":"PSI mobile 97 indicates excellent performance (LCP 2.3 s, CLS 0.001), but the Security basics verdict is FAILED. Per the audit protocol: 'Treat FAILED as a must-fix and PASS as a starting point, not a certificate.' W3C validation returned 7 errors including parser recovery failure, and accessibility has 2 moderate violations plus missing landmarks. Image assets lack width/height attributes on all 50 images, risking future CLS. These structural and security hygiene issues prevent a higher score despite the fast load times.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Fix HTTP redirect and add baseline security headers","impact":"Transport security, clickjacking, MIME sniffing","problem":"Security basics verdict is FAILED: http:// does not redirect to https, HSTS is missing, and X-Content-Type-Options is missing.","solution":"Configure server to redirect HTTP to HTTPS and send these headers:\n```\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\nRedirect permanent / https://play.ee/\n```"},{"priority":2,"category":"SEO","title":"Fix W3C HTML validation errors","impact":"Parser recovery, document structure","problem":"W3C validator reported 7 errors including 'Cannot recover after last error' at line 101 and bad iframe/noscript nesting in head.","solution":"Move `<noscript><iframe>...</iframe></noscript>` out of `<head>` or ensure it is valid HTML5. Remove stray end tags and fix meta tag attributes (e.g., `name` vs `property`)."},{"priority":2,"category":"Accessibility","title":"Add skip-to-content link and fix landmarks","impact":"Keyboard navigation, screen reader flow","problem":"axe-core found `landmark-unique` and `region` violations; HTML inventory confirms missing `main` landmark and skip link.","solution":"Add a skip link at the top of the body:\n```html\n<a href=\"#main-content\" class=\"skip-link\">Skip to content</a>\n```\nWrap main content in `<main id=\"main-content\">` and ensure nav/footer have unique labels."},{"priority":2,"category":"Performance","title":"Add width and height to all images","impact":"CLS (Cumulative Layout Shift)","problem":"HTML inventory shows 50 images without explicit width/height attributes, risking layout shifts despite current CLS of 0.001.","solution":"Add `width` and `height` attributes to all `<img>` tags matching their intrinsic dimensions. For responsive images, use `srcset` with corresponding sizes."},{"priority":2,"category":"Security","title":"Harden WordPress installation","impact":"Brute-force protection, attack surface","problem":"Security basics flagged `xmlrpc.php` accepts POST requests and `/wp-admin/install.php` is reachable.","solution":"Disable xmlrpc.php in .htaccess or via plugin. Block access to `/wp-admin/install.php` after installation:\n```apache\n<Files install.php>\n  Order Allow,Deny\n  Deny from all\n</Files>\n```"}],"perfScore":97,"a11yScore":94,"bestPracticesScore":100,"seoScore":92,"securityScore":61,"securityVerdict":"FAILED"}]}