# Audit Report: Avaleht - Restate **Website:** https://restate.ee/ **Date:** 16.09.2026 **Audit Coverage:** 100% — all sources returned data **Confidence:** high **Pages Audited (5 of 5):** - https://restate.ee/ - https://restate.ee/privacy-policy - https://restate.ee/ettevote/blogi - https://restate.ee/varahaldus-kuidas-hoida-kinnisvaraportfell-toos - https://restate.ee/aripinna-uurimine-viis-asja-mida-enne-lepingu-allkirjastamist-kontrollida ## Summary of results **Overall Score:** 72 / 100 **Status:** 🟡 **Needs Improvement** Site overall 72 is the mean of 5 pages. Scores range 68 (https://restate.ee/ettevote/blogi) → 78 (https://restate.ee/). Weakest page: Mobile performance (83) is dragged down by a 4.2 s LCP, exceeding the 4 s 'poor' threshold despite a 99 desktop score. Security headers are completely absent (0/100), missing baseline protections like HSTS. Accessibility is mostly strong (95) but fails touch target sizing (0.00 score). W3C validation shows 7 script errors from plugin configuration. The site is a commercial real estate blog with no auth/payment risk, lowering CSP priority. ### Per-page scores 🟡 **Needs Improvement** · https://restate.ee/ | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 78 | 93 | 95 | 100 | 92 | 0 | 🟡 **Needs Improvement** · https://restate.ee/privacy-policy | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 71 | 78 | 95 | 100 | 100 | 0 | 🟡 **Needs Improvement** · https://restate.ee/ettevote/blogi | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 68 | 83 | 96 | 100 | 92 | 0 | 🟡 **Needs Improvement** · https://restate.ee/varahaldus-kuidas-hoida-kinnisvaraportfell-toos | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 72 | 85 | 96 | 100 | 100 | 0 | 🟡 **Needs Improvement** · https://restate.ee/aripinna-uurimine-viis-asja-mida-enne-lepingu-allkirjastamist-kontrollida | Score | Performance | Accessibility | Best Practices | SEO | Security | | --- | --- | --- | --- | --- | --- | | 73 | 81 | 96 | 100 | 100 | 0 | ## PageSpeed Insights — Mobile vs Desktop _Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._ | URL | Performance (M / D) | LCP (M / D) | CLS (M / D) | | --- | --- | --- | --- | | https://restate.ee/ | **93** / 100 | **2.85 s** / 563 ms | 0.003 / **0.003** | | https://restate.ee/privacy-policy | **78** / 99 | **2.50 s** / 684 ms | **0.377** / 0.000 | | https://restate.ee/ettevote/blogi | **83** / 99 | **4.18 s** / 937 ms | **0.005** / 0.000 | | https://restate.ee/varahaldus-kuidas-hoida-kinnisvaraportfell-toos | **85** / 99 | **4.08 s** / 825 ms | 0.000 / **0.000** | | https://restate.ee/aripinna-uurimine-viis-asja-mida-enne-lepingu-allkirjastamist-kontrollida | **81** / 99 | **4.22 s** / 819 ms | 0.000 / **0.000** | ## Optimization Checklist **2 of 3 passing** — 2 pass · 0 warn · 1 fail · 4 n/a | Item | Status | Detail | | --- | --- | --- | | Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) | | Images lazy-loaded | N/A | No raster elements found. | | Hero image eagerly loaded | **Fail** | Hero image has loading="lazy", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading="eager" (or omit loading) and add fetchpriority="high". | | Hero is a real (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. | | Responsive images (srcset / ) | N/A | Only 0 raster images on the page — responsive-image rule does not apply. | | Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. | | JS scripts not blocking in | **Pass** | No render-blocking scripts in . | ## Fixes ### Priority 1: Critical *Immediate action — impacts user experience, search rankings, or site safety.* **1A. Add HSTS header** `Security` - **Impact:** Transport security, HTTPS enforcement - **Problem:** Security Headers grade is 0/100; strict-transport-security is missing. - **Solution:** Add the following header to your server configuration (Apache example): ```apache Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" ``` **1B. Eagerly load the hero image** `Performance` - **Impact:** LCP, FCP - **Problem:** Optimized-Web Checklist flagged hero image `hammer.png` as having `loading="lazy"`, contributing to LCP 2.9 s. - **Solution:** Remove `loading="lazy"` from the hero `` and add `fetchpriority="high"`: ```html ... ``` **1C. Fix Cumulative Layout Shift (CLS) of 0.377** `Performance` - **Impact:** LCP, CLS, Core Web Vitals - **Problem:** CLS 0.377 exceeds 0.25 threshold; shift source identified in footer (div#page > div.main > div.main__footer > footer.footer). - **Solution:** Reserve space for dynamic content in footer: ```css footer.footer { min-height: 200px; /* or actual content height */ } ``` - Add explicit width/height to any embedded content (iframes, ads, videos) - Use `aspect-ratio` CSS property for dynamic elements - Avoid inserting content above existing content **1D. Remove lazy loading from hero image** `Performance` - **Impact:** LCP, FCP - **Problem:** Hero image has loading="lazy", which delays LCP to 4.2 s on mobile (Optimized-Web Checklist fail). - **Solution:** Remove `loading="lazy"` and add `fetchpriority="high"` to the hero ``: ```html ... ``` **1E. Improve Largest Contentful Paint (LCP)** `Performance` - **Impact:** LCP, FCP, Mobile Performance Score - **Problem:** Mobile LCP is 4.1 s (threshold is ≤4 s), flagged as a high-priority PSI failure despite low page weight. - **Solution:** 1. Preload the LCP image and critical fonts. 2. Ensure `font-display: swap` is used for web fonts. 3. Optimize the hero image delivery (check if `fetchpriority="high"` is needed). 4. Review server-side rendering or caching to reduce render-blocking resources. **1F. Optimize Largest Contentful Paint (LCP) resource** `Performance` - **Impact:** LCP, FCP, Mobile Performance - **Problem:** Mobile LCP is 4.2 s (threshold >4 s is heavy penalty); PSI flags `largest-contentful-paint` and `font-display-insight` as high priority. - **Solution:** - Preload the LCP image (hero) with ``. - Convert hero image to WebP/AVIF with fallback. - Ensure `font-display: swap` is active for Open Sans to prevent render blocking. ### Priority 2: Important *Essential for compliance, user reach, and search visibility.* **2A. Add X-Content-Type-Options and X-Frame-Options** `Security` - **Impact:** MIME sniffing, clickjacking protection - **Problem:** Security Headers grade 0/100; both headers are missing. - **Solution:** Add these headers to your server configuration: ```apache Header always set X-Content-Type-Options "nosniff" Header always set X-Frame-Options "SAMEORIGIN" ``` **2B. Increase touch target sizes** `Accessibility` - **Impact:** WCAG 2.5.8 Target Size - **Problem:** PSI `target-size` audit failed with score 0.00, indicating interactive elements are too small or lack spacing. - **Solution:** Ensure all clickable elements (links, buttons) have a minimum touch target of 44×44 CSS pixels. Add padding or margin to increase the clickable area without changing visual size. **2C. Add meta description** `SEO` - **Impact:** Search snippet quality - **Problem:** HTML Inventory shows meta description is not set; PSI SEO audit failed `metaDescription`. - **Solution:** Add a unique description tag in the ``: ```html ``` **2D. Add baseline security headers (HSTS, X-Content-Type-Options, X-Frame-Options)** `Security` - **Impact:** Transport security, clickjacking, MIME sniffing - **Problem:** All 9 security headers missing (score 0/100). HSTS, X-Content-Type-Options, X-Frame-Options are baseline protections regardless of site signals. - **Solution:** Send from origin (Apache shown): ``` Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" Header always set X-Content-Type-Options "nosniff" Header always set X-Frame-Options "SAMEORIGIN" ``` - Consider CSP (priority 3 for this site per rubric — no auth/payments/UGC) **2E. Fix W3C HTML validator errors (7 script type/defer conflicts)** `Best Practices` - **Impact:** HTML validity, potential JS execution issues - **Problem:** 7 errors: script elements with type="text/rocketlazyloadscript" and defer attribute — invalid per HTML spec (data blocks must not have defer). - **Solution:** Remove `defer` from non-JavaScript script types: ```html