# Audit Report: Avaleht - Restate
**Website:** https://restate.ee/
**Date:** 16.09.2026
**Audit Coverage:** 100% — all sources returned data
**Confidence:** high
**Pages Audited (5 of 5):**
- https://restate.ee/
- https://restate.ee/privacy-policy
- https://restate.ee/ettevote/blogi
- https://restate.ee/varahaldus-kuidas-hoida-kinnisvaraportfell-toos
- https://restate.ee/aripinna-uurimine-viis-asja-mida-enne-lepingu-allkirjastamist-kontrollida
## Summary of results
**Overall Score:** 72 / 100
**Status:** 🟡 **Needs Improvement**
Site overall 72 is the mean of 5 pages. Scores range 68 (https://restate.ee/ettevote/blogi) → 78 (https://restate.ee/). Weakest page: Mobile performance (83) is dragged down by a 4.2 s LCP, exceeding the 4 s 'poor' threshold despite a 99 desktop score. Security headers are completely absent (0/100), missing baseline protections like HSTS. Accessibility is mostly strong (95) but fails touch target sizing (0.00 score). W3C validation shows 7 script errors from plugin configuration. The site is a commercial real estate blog with no auth/payment risk, lowering CSP priority.
### Per-page scores
🟡 **Needs Improvement** · https://restate.ee/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 78 | 93 | 95 | 100 | 92 | 0 |
🟡 **Needs Improvement** · https://restate.ee/privacy-policy
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 71 | 78 | 95 | 100 | 100 | 0 |
🟡 **Needs Improvement** · https://restate.ee/ettevote/blogi
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 68 | 83 | 96 | 100 | 92 | 0 |
🟡 **Needs Improvement** · https://restate.ee/varahaldus-kuidas-hoida-kinnisvaraportfell-toos
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 72 | 85 | 96 | 100 | 100 | 0 |
🟡 **Needs Improvement** · https://restate.ee/aripinna-uurimine-viis-asja-mida-enne-lepingu-allkirjastamist-kontrollida
| Score | Performance | Accessibility | Best Practices | SEO | Security |
| --- | --- | --- | --- | --- | --- |
| 73 | 81 | 96 | 100 | 100 | 0 |
## PageSpeed Insights — Mobile vs Desktop
_Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is **bolded**._
| URL | Performance (M / D) | LCP (M / D) | CLS (M / D) |
| --- | --- | --- | --- |
| https://restate.ee/ | **93** / 100 | **2.85 s** / 563 ms | 0.003 / **0.003** |
| https://restate.ee/privacy-policy | **78** / 99 | **2.50 s** / 684 ms | **0.377** / 0.000 |
| https://restate.ee/ettevote/blogi | **83** / 99 | **4.18 s** / 937 ms | **0.005** / 0.000 |
| https://restate.ee/varahaldus-kuidas-hoida-kinnisvaraportfell-toos | **85** / 99 | **4.08 s** / 825 ms | 0.000 / **0.000** |
| https://restate.ee/aripinna-uurimine-viis-asja-mida-enne-lepingu-allkirjastamist-kontrollida | **81** / 99 | **4.22 s** / 819 ms | 0.000 / **0.000** |
## Optimization Checklist
**2 of 3 passing** — 2 pass · 0 warn · 1 fail · 4 n/a
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | **Pass** | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | N/A | No raster
elements found. |
| Hero image eagerly loaded | **Fail** | Hero image has loading="lazy", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading="eager" (or omit loading) and add fetchpriority="high". |
| Hero is a real
(not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / ) | N/A | Only 0 raster images on the page — responsive-image rule does not apply. |
| Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in | **Pass** | No render-blocking scripts in . |
## Fixes
### Priority 1: Critical
*Immediate action — impacts user experience, search rankings, or site safety.*
**1A. Add HSTS header** `Security`
- **Impact:** Transport security, HTTPS enforcement
- **Problem:** Security Headers grade is 0/100; strict-transport-security is missing.
- **Solution:**
Add the following header to your server configuration (Apache example):
```apache
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
```
**1B. Eagerly load the hero image** `Performance`
- **Impact:** LCP, FCP
- **Problem:** Optimized-Web Checklist flagged hero image `hammer.png` as having `loading="lazy"`, contributing to LCP 2.9 s.
- **Solution:**
Remove `loading="lazy"` from the hero `
` and add `fetchpriority="high"`:
```html
```
**1C. Fix Cumulative Layout Shift (CLS) of 0.377** `Performance`
- **Impact:** LCP, CLS, Core Web Vitals
- **Problem:** CLS 0.377 exceeds 0.25 threshold; shift source identified in footer (div#page > div.main > div.main__footer > footer.footer).
- **Solution:**
Reserve space for dynamic content in footer:
```css
footer.footer {
min-height: 200px; /* or actual content height */
}
```
- Add explicit width/height to any embedded content (iframes, ads, videos)
- Use `aspect-ratio` CSS property for dynamic elements
- Avoid inserting content above existing content
**1D. Remove lazy loading from hero image** `Performance`
- **Impact:** LCP, FCP
- **Problem:** Hero image has loading="lazy", which delays LCP to 4.2 s on mobile (Optimized-Web Checklist fail).
- **Solution:**
Remove `loading="lazy"` and add `fetchpriority="high"` to the hero `
`:
```html
```
**1E. Improve Largest Contentful Paint (LCP)** `Performance`
- **Impact:** LCP, FCP, Mobile Performance Score
- **Problem:** Mobile LCP is 4.1 s (threshold is ≤4 s), flagged as a high-priority PSI failure despite low page weight.
- **Solution:**
1. Preload the LCP image and critical fonts.
2. Ensure `font-display: swap` is used for web fonts.
3. Optimize the hero image delivery (check if `fetchpriority="high"` is needed).
4. Review server-side rendering or caching to reduce render-blocking resources.
**1F. Optimize Largest Contentful Paint (LCP) resource** `Performance`
- **Impact:** LCP, FCP, Mobile Performance
- **Problem:** Mobile LCP is 4.2 s (threshold >4 s is heavy penalty); PSI flags `largest-contentful-paint` and `font-display-insight` as high priority.
- **Solution:**
- Preload the LCP image (hero) with ``.
- Convert hero image to WebP/AVIF with fallback.
- Ensure `font-display: swap` is active for Open Sans to prevent render blocking.
### Priority 2: Important
*Essential for compliance, user reach, and search visibility.*
**2A. Add X-Content-Type-Options and X-Frame-Options** `Security`
- **Impact:** MIME sniffing, clickjacking protection
- **Problem:** Security Headers grade 0/100; both headers are missing.
- **Solution:**
Add these headers to your server configuration:
```apache
Header always set X-Content-Type-Options "nosniff"
Header always set X-Frame-Options "SAMEORIGIN"
```
**2B. Increase touch target sizes** `Accessibility`
- **Impact:** WCAG 2.5.8 Target Size
- **Problem:** PSI `target-size` audit failed with score 0.00, indicating interactive elements are too small or lack spacing.
- **Solution:**
Ensure all clickable elements (links, buttons) have a minimum touch target of 44×44 CSS pixels. Add padding or margin to increase the clickable area without changing visual size.
**2C. Add meta description** `SEO`
- **Impact:** Search snippet quality
- **Problem:** HTML Inventory shows meta description is not set; PSI SEO audit failed `metaDescription`.
- **Solution:**
Add a unique description tag in the ``:
```html
```
**2D. Add baseline security headers (HSTS, X-Content-Type-Options, X-Frame-Options)** `Security`
- **Impact:** Transport security, clickjacking, MIME sniffing
- **Problem:** All 9 security headers missing (score 0/100). HSTS, X-Content-Type-Options, X-Frame-Options are baseline protections regardless of site signals.
- **Solution:**
Send from origin (Apache shown):
```
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
Header always set X-Content-Type-Options "nosniff"
Header always set X-Frame-Options "SAMEORIGIN"
```
- Consider CSP (priority 3 for this site per rubric — no auth/payments/UGC)
**2E. Fix W3C HTML validator errors (7 script type/defer conflicts)** `Best Practices`
- **Impact:** HTML validity, potential JS execution issues
- **Problem:** 7 errors: script elements with type="text/rocketlazyloadscript" and defer attribute — invalid per HTML spec (data blocks must not have defer).
- **Solution:**
Remove `defer` from non-JavaScript script types:
```html