{"url":"https://restate.ee/","date":"2026-09-16","siteName":"Avaleht - Restate","overall":72,"reasoning":"Site overall 72 is the mean of 5 pages. Scores range 68 (https://restate.ee/ettevote/blogi) → 78 (https://restate.ee/). Weakest page: Mobile performance (83) is dragged down by a 4.2 s LCP, exceeding the 4 s 'poor' threshold despite a 99 desktop score. Security headers are completely absent (0/100), missing baseline protections like HSTS. Accessibility is mostly strong (95) but fails touch target sizing (0.00 score). W3C validation shows 7 script errors from plugin configuration. The site is a commercial real estate blog with no auth/payment risk, lowering CSP priority.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Add HSTS header","impact":"Transport security, HTTPS enforcement","problem":"Security Headers grade is 0/100; strict-transport-security is missing.","solution":"Add the following header to your server configuration (Apache example):\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":1,"category":"Performance","title":"Eagerly load the hero image","impact":"LCP, FCP","problem":"Optimized-Web Checklist flagged hero image `hammer.png` as having `loading=\"lazy\"`, contributing to LCP 2.9 s.","solution":"Remove `loading=\"lazy\"` from the hero `<img>` and add `fetchpriority=\"high\"`:\n```html\n<img src=\"/path/to/hammer.png\" alt=\"...\" fetchpriority=\"high\">\n```"},{"priority":1,"category":"Performance","title":"Fix Cumulative Layout Shift (CLS) of 0.377","impact":"LCP, CLS, Core Web Vitals","problem":"CLS 0.377 exceeds 0.25 threshold; shift source identified in footer (div#page > div.main > div.main__footer > footer.footer).","solution":"Reserve space for dynamic content in footer:\n```css\nfooter.footer {\n  min-height: 200px; /* or actual content height */\n}\n```\n- Add explicit width/height to any embedded content (iframes, ads, videos)\n- Use `aspect-ratio` CSS property for dynamic elements\n- Avoid inserting content above existing content"},{"priority":1,"category":"Performance","title":"Remove lazy loading from hero image","impact":"LCP, FCP","problem":"Hero image has loading=\"lazy\", which delays LCP to 4.2 s on mobile (Optimized-Web Checklist fail).","solution":"Remove `loading=\"lazy\"` and add `fetchpriority=\"high\"` to the hero `<img>`:\n```html\n<img src=\"/hero.jpg\" alt=\"...\" fetchpriority=\"high\" width=\"...\" height=\"...\">\n```"},{"priority":1,"category":"Performance","title":"Improve Largest Contentful Paint (LCP)","impact":"LCP, FCP, Mobile Performance Score","problem":"Mobile LCP is 4.1 s (threshold is ≤4 s), flagged as a high-priority PSI failure despite low page weight.","solution":"1. Preload the LCP image and critical fonts.\n2. Ensure `font-display: swap` is used for web fonts.\n3. Optimize the hero image delivery (check if `fetchpriority=\"high\"` is needed).\n4. Review server-side rendering or caching to reduce render-blocking resources."},{"priority":1,"category":"Performance","title":"Optimize Largest Contentful Paint (LCP) resource","impact":"LCP, FCP, Mobile Performance","problem":"Mobile LCP is 4.2 s (threshold >4 s is heavy penalty); PSI flags `largest-contentful-paint` and `font-display-insight` as high priority.","solution":"- Preload the LCP image (hero) with `<link rel=\"preload\" as=\"image\">`.\n- Convert hero image to WebP/AVIF with fallback.\n- Ensure `font-display: swap` is active for Open Sans to prevent render blocking."},{"priority":2,"category":"Security","title":"Add X-Content-Type-Options and X-Frame-Options","impact":"MIME sniffing, clickjacking protection","problem":"Security Headers grade 0/100; both headers are missing.","solution":"Add these headers to your server configuration:\n```apache\nHeader always set X-Content-Type-Options \"nosniff\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\n```"},{"priority":2,"category":"Accessibility","title":"Increase touch target sizes","impact":"WCAG 2.5.8 Target Size","problem":"PSI `target-size` audit failed with score 0.00, indicating interactive elements are too small or lack spacing.","solution":"Ensure all clickable elements (links, buttons) have a minimum touch target of 44×44 CSS pixels. Add padding or margin to increase the clickable area without changing visual size."},{"priority":2,"category":"SEO","title":"Add meta description","impact":"Search snippet quality","problem":"HTML Inventory shows meta description is not set; PSI SEO audit failed `metaDescription`.","solution":"Add a unique description tag in the `<head>`:\n```html\n<meta name=\"description\" content=\"Brief summary of Restate services for search engines.\">\n```"},{"priority":2,"category":"Security","title":"Add baseline security headers (HSTS, X-Content-Type-Options, X-Frame-Options)","impact":"Transport security, clickjacking, MIME sniffing","problem":"All 9 security headers missing (score 0/100). HSTS, X-Content-Type-Options, X-Frame-Options are baseline protections regardless of site signals.","solution":"Send from origin (Apache shown):\n```\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\n```\n- Consider CSP (priority 3 for this site per rubric — no auth/payments/UGC)"},{"priority":2,"category":"Best Practices","title":"Fix W3C HTML validator errors (7 script type/defer conflicts)","impact":"HTML validity, potential JS execution issues","problem":"7 errors: script elements with type=\"text/rocketlazyloadscript\" and defer attribute — invalid per HTML spec (data blocks must not have defer).","solution":"Remove `defer` from non-JavaScript script types:\n```html\n<!-- Before -->\n<script type=\"text/rocketlazyloadscript\" data-wp-strategy=\"defer\" defer>\n\n<!-- After -->\n<script type=\"text/rocketlazyloadscript\" data-wp-strategy=\"defer\">\n```\n- Or change type to a valid JavaScript MIME type if defer is needed"},{"priority":2,"category":"Accessibility","title":"Fix landmark-unique violation and touch target sizes","impact":"WCAG 1.3.1, 2.5.8","problem":"axe-core: 1 moderate violation (landmark-unique on .footer__social). PSI: target-size failures for touch targets.","solution":"- Add unique aria-label to footer social landmarks: `<nav aria-label=\"Social media links\">`\n- Ensure all interactive elements have 44×44px minimum touch target\n- Add visible focus indicators to all interactive elements"},{"priority":2,"category":"Security","title":"Add baseline security headers (HSTS, X-Frame-Options, X-Content-Type-Options)","impact":"Transport security, clickjacking, MIME sniffing","problem":"Security Headers grade is 0/100; HSTS, X-Frame-Options, and X-Content-Type-Options are missing.","solution":"Configure server (Apache example):\n```\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\n```"},{"priority":2,"category":"Accessibility","title":"Increase touch target sizes for interactive elements","impact":"Mobile usability, WCAG 2.5.8","problem":"PSI `target-size` audit score is 0.00, indicating touch targets are too small or lack spacing.","solution":"Ensure all interactive elements (links, buttons) have a minimum 44×44 px touch target area. Add padding or margins to small icons/links."},{"priority":2,"category":"Security","title":"Add Baseline Security Headers","impact":"Transport security, clickjacking protection","problem":"Security Headers grade is 0/100; HSTS, X-Frame-Options, and X-Content-Type-Options are missing.","solution":"Configure the web server (Apache/Nginx) to send:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Best Practices","title":"Fix W3C HTML Validation Errors","impact":"Parser recovery, SEO, maintainability","problem":"10 W3C errors found, including 7 instances of invalid `script` tags using `type=\"text/rocketlazyloadscript\"` with `defer`.","solution":"Update the WP Rocket plugin configuration or version. The `type` attribute on scripts should be omitted or set to `module`/`text/javascript`. Invalid types can cause parsing issues in some browsers."},{"priority":2,"category":"Accessibility","title":"Fix Touch Targets and Landmarks","impact":"WCAG 2.5.8 (Target Size), 1.3.1 (Info and Relationships)","problem":"PSI reports `tapTargets` failure; axe reports `landmark-unique` violation on `.footer__social`.","solution":"1. Increase spacing or size of interactive elements to at least 44×44 px.\n2. Add unique `aria-label` or `title` attributes to duplicate footer landmarks to distinguish them for screen readers."},{"priority":2,"category":"Performance","title":"Correct Cache-Control Headers","impact":"Repeat visit performance, bandwidth","problem":"Response header `cache-control: max-age=0` prevents effective browser caching despite WP Rocket detection.","solution":"Configure WP Rocket or server rules to set `Cache-Control: public, max-age=31536000` for static assets and `max-age=3600` for HTML, ensuring the `Vary: Accept-Encoding` header is preserved."},{"priority":2,"category":"Accessibility","title":"Increase touch target sizes and fix landmark uniqueness","impact":"WCAG 2.5.8 Target Size, 1.3.1 Info and Relationships","problem":"PSI `target-size` audit fails; axe reports `landmark-unique` violation on `.footer__social`.","solution":"- Ensure all interactive elements have 44×44 px minimum touch area.\n- Add unique `aria-label` or `role` to the footer social landmark to distinguish it from other nav regions."},{"priority":3,"category":"Security","title":"Implement Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower but still recommended.","solution":"Start with a restrictive policy allowing only necessary origins:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com;\"\n```"},{"priority":3,"category":"Best Practices","title":"Fix W3C script type errors","impact":"HTML validity, potential parsing issues","problem":"W3C Validator reported 7 errors: `script` elements with `type=\"text/rocketlazyloadscript\"` incorrectly use the `defer` attribute.","solution":"Update WP Rocket settings or custom code to use standard MIME types (`text/javascript`) or remove `defer` from non-standard script types."},{"priority":3,"category":"SEO","title":"Add meta description and hreflang tags","impact":"Search snippet quality, international SEO","problem":"Missing meta description (SEO audit suggests text). No hreflang tags for multi-language support.","solution":"Add to `<head>`:\n```html\n<meta name=\"description\" content=\"Restate privacy policy details how we collect, use, and protect your personal information.\">\n<link rel=\"alternate\" hreflang=\"et\" href=\"https://restate.ee/privacy-policy/\">\n<link rel=\"alternate\" hreflang=\"en\" href=\"https://restate.ee/en/privacy-policy/\">\n```"},{"priority":3,"category":"Security","title":"Consider CSP implementation (lower priority for this site)","impact":"XSS defense-in-depth","problem":"CSP missing. Site signals show no auth, payments, or user-generated content — XSS attack surface minimal per rubric.","solution":"If/when adding login or user content, deploy nonce-based CSP:\n```\nContent-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\n```\n- For current brochure/privacy policy page, focus on P1/P2 items first"},{"priority":3,"category":"SEO","title":"Add a meta description","impact":"Search snippet quality, CTR","problem":"HTML Inventory shows meta description is not set; PSI SEO audit fails `metaDescription`.","solution":"Add a unique `<meta name=\"description\" content=\"...\">` tag in the `<head>` summarizing the blog page content."},{"priority":3,"category":"Best Practices","title":"Fix invalid script type attributes","impact":"HTML validation, potential parsing issues","problem":"W3C Validator reports 7 errors: `type=\"text/rocketlazyloadscript\"` with `defer` is invalid.","solution":"Update WP Rocket configuration or custom scripts to use standard MIME types (`text/javascript`) or remove the `type` attribute entirely for JS."},{"priority":3,"category":"Security","title":"Implement Content Security Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing. Site signals indicate no auth, payments, or user content, lowering immediate risk but CSP remains a best practice.","solution":"Deploy a strict CSP using nonces or hashes rather than a flat allowlist:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"},{"priority":3,"category":"Best Practices","title":"Fix W3C HTML validation errors (Script types and SVG attributes)","impact":"Parser recovery, SEO, Maintainability","problem":"10 W3C errors: 7x `script` with invalid `type` + `defer`, 2x `preserveAspectRatio` on `use`.","solution":"- Remove `type=\"text/rocketlazyloadscript\"` or change to `text/javascript`.\n- Remove `defer` from scripts with non-standard MIME types.\n- Remove `preserveAspectRatio` from `<use>` elements (valid on `<svg>` only)."}],"coverage":{"pct":100,"missing":[]},"siteSummary":{"pagesAudited":5,"pagesAttempted":5,"urls":["https://restate.ee/","https://restate.ee/privacy-policy","https://restate.ee/ettevote/blogi","https://restate.ee/varahaldus-kuidas-hoida-kinnisvaraportfell-toos","https://restate.ee/aripinna-uurimine-viis-asja-mida-enne-lepingu-allkirjastamist-kontrollida"]},"psiSnapshot":{"rows":[{"pageUrl":"https://restate.ee/","perfMobile":93,"perfDesktop":100,"lcpMobileMs":2851,"lcpDesktopMs":562.5,"clsMobile":0.0026491437179780755,"clsDesktop":0.0033309856075793383},{"pageUrl":"https://restate.ee/privacy-policy","perfMobile":78,"perfDesktop":99,"lcpMobileMs":2498.4118,"lcpDesktopMs":684.4198500000001,"clsMobile":0.3772195869732434,"clsDesktop":0.0003590495948764738},{"pageUrl":"https://restate.ee/ettevote/blogi","perfMobile":83,"perfDesktop":99,"lcpMobileMs":4175.98525,"lcpDesktopMs":936.657115,"clsMobile":0.004608937444419568,"clsDesktop":0.0004673198384430411},{"pageUrl":"https://restate.ee/varahaldus-kuidas-hoida-kinnisvaraportfell-toos","perfMobile":85,"perfDesktop":99,"lcpMobileMs":4081.903674999999,"lcpDesktopMs":824.5328,"clsMobile":0,"clsDesktop":0.0003590495948764738},{"pageUrl":"https://restate.ee/aripinna-uurimine-viis-asja-mida-enne-lepingu-allkirjastamist-kontrollida","perfMobile":81,"perfDesktop":99,"lcpMobileMs":4220.294979999999,"lcpDesktopMs":819.3841400000001,"clsMobile":0,"clsDesktop":0.0003590495948764738}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket)","evidence":["HTML markers: WP Rocket","generator: WP Rocket 3.23.3.3"]},{"id":"lazyload","title":"Images lazy-loaded","status":"n/a","detail":"No raster <img> elements found.","evidence":[]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"fail","detail":"Hero image has loading=\"lazy\", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading=\"eager\" (or omit loading) and add fetchpriority=\"high\".","evidence":["hero: https://restate.ee/wp-content/themes/restate/inc/theme/img/footer/hammer.png","loading: lazy","fetchpriority: (not set)"]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"n/a","detail":"No CSS background-images detected on raster-image-eligible elements.","evidence":[]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"n/a","detail":"Only 0 raster images on the page — responsive-image rule does not apply.","evidence":[]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"n/a","detail":"Too few raster images to evaluate srcset width variety.","evidence":[]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"pass","detail":"No render-blocking scripts in <head>.","evidence":[]}],"summary":{"passed":2,"warned":0,"failed":1,"notApplicable":4},"priorities":[{"title":"Hero image eagerly loaded","severity":"high","detail":"Hero image has loading=\"lazy\", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading=\"eager\" (or omit loading) and add fetchpriority=\"high\"."}]},"perPageOverall":[{"url":"https://restate.ee/","overall":78,"reasoning":"PSI mobile performance is strong at 93, but LCP 2.9 s exceeds the 2.5 s threshold, primarily due to the hero image being lazy-loaded. Security Headers score 0/100 is a significant technical debt despite the site being a brochure without auth or payments. W3C validation returned 7 errors related to invalid script attributes, and accessibility has a critical failure on touch target sizes (PSI score 0.00) despite a 95 axe score. Confidence is high because all audit sources returned complete data with consistent signals.","confidence":"high","fixes":[{"priority":1,"category":"Security","title":"Add HSTS header","impact":"Transport security, HTTPS enforcement","problem":"Security Headers grade is 0/100; strict-transport-security is missing.","solution":"Add the following header to your server configuration (Apache example):\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":1,"category":"Performance","title":"Eagerly load the hero image","impact":"LCP, FCP","problem":"Optimized-Web Checklist flagged hero image `hammer.png` as having `loading=\"lazy\"`, contributing to LCP 2.9 s.","solution":"Remove `loading=\"lazy\"` from the hero `<img>` and add `fetchpriority=\"high\"`:\n```html\n<img src=\"/path/to/hammer.png\" alt=\"...\" fetchpriority=\"high\">\n```"},{"priority":2,"category":"Security","title":"Add X-Content-Type-Options and X-Frame-Options","impact":"MIME sniffing, clickjacking protection","problem":"Security Headers grade 0/100; both headers are missing.","solution":"Add these headers to your server configuration:\n```apache\nHeader always set X-Content-Type-Options \"nosniff\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\n```"},{"priority":2,"category":"Accessibility","title":"Increase touch target sizes","impact":"WCAG 2.5.8 Target Size","problem":"PSI `target-size` audit failed with score 0.00, indicating interactive elements are too small or lack spacing.","solution":"Ensure all clickable elements (links, buttons) have a minimum touch target of 44×44 CSS pixels. Add padding or margin to increase the clickable area without changing visual size."},{"priority":2,"category":"SEO","title":"Add meta description","impact":"Search snippet quality","problem":"HTML Inventory shows meta description is not set; PSI SEO audit failed `metaDescription`.","solution":"Add a unique description tag in the `<head>`:\n```html\n<meta name=\"description\" content=\"Brief summary of Restate services for search engines.\">\n```"},{"priority":3,"category":"Security","title":"Implement Content-Security-Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower but still recommended.","solution":"Start with a restrictive policy allowing only necessary origins:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com;\"\n```"},{"priority":3,"category":"Best Practices","title":"Fix W3C script type errors","impact":"HTML validity, potential parsing issues","problem":"W3C Validator reported 7 errors: `script` elements with `type=\"text/rocketlazyloadscript\"` incorrectly use the `defer` attribute.","solution":"Update WP Rocket settings or custom code to use standard MIME types (`text/javascript`) or remove `defer` from non-standard script types."}],"perfScore":93,"a11yScore":95,"bestPracticesScore":100,"seoScore":92,"securityScore":0},{"url":"https://restate.ee/privacy-policy","overall":71,"reasoning":"PSI mobile 78 (desktop 99) with CLS 0.377 is the primary drag — this exceeds the 0.25 threshold and heavily penalizes performance. Security headers score 0/100 (all 9 missing), but site signals show no auth/payments/UGC/commerce, reducing real-world risk. W3C reports 7 errors from invalid script type attributes. Accessibility is strong (95/100) with only 1 moderate landmark-unique violation. Missing meta description and hreflang tags affect SEO completeness. Confidence is high because all audit sources returned data without errors.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Fix Cumulative Layout Shift (CLS) of 0.377","impact":"LCP, CLS, Core Web Vitals","problem":"CLS 0.377 exceeds 0.25 threshold; shift source identified in footer (div#page > div.main > div.main__footer > footer.footer).","solution":"Reserve space for dynamic content in footer:\n```css\nfooter.footer {\n  min-height: 200px; /* or actual content height */\n}\n```\n- Add explicit width/height to any embedded content (iframes, ads, videos)\n- Use `aspect-ratio` CSS property for dynamic elements\n- Avoid inserting content above existing content"},{"priority":2,"category":"Security","title":"Add baseline security headers (HSTS, X-Content-Type-Options, X-Frame-Options)","impact":"Transport security, clickjacking, MIME sniffing","problem":"All 9 security headers missing (score 0/100). HSTS, X-Content-Type-Options, X-Frame-Options are baseline protections regardless of site signals.","solution":"Send from origin (Apache shown):\n```\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nHeader always set X-Content-Type-Options \"nosniff\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\n```\n- Consider CSP (priority 3 for this site per rubric — no auth/payments/UGC)"},{"priority":2,"category":"Best Practices","title":"Fix W3C HTML validator errors (7 script type/defer conflicts)","impact":"HTML validity, potential JS execution issues","problem":"7 errors: script elements with type=\"text/rocketlazyloadscript\" and defer attribute — invalid per HTML spec (data blocks must not have defer).","solution":"Remove `defer` from non-JavaScript script types:\n```html\n<!-- Before -->\n<script type=\"text/rocketlazyloadscript\" data-wp-strategy=\"defer\" defer>\n\n<!-- After -->\n<script type=\"text/rocketlazyloadscript\" data-wp-strategy=\"defer\">\n```\n- Or change type to a valid JavaScript MIME type if defer is needed"},{"priority":2,"category":"Accessibility","title":"Fix landmark-unique violation and touch target sizes","impact":"WCAG 1.3.1, 2.5.8","problem":"axe-core: 1 moderate violation (landmark-unique on .footer__social). PSI: target-size failures for touch targets.","solution":"- Add unique aria-label to footer social landmarks: `<nav aria-label=\"Social media links\">`\n- Ensure all interactive elements have 44×44px minimum touch target\n- Add visible focus indicators to all interactive elements"},{"priority":3,"category":"SEO","title":"Add meta description and hreflang tags","impact":"Search snippet quality, international SEO","problem":"Missing meta description (SEO audit suggests text). No hreflang tags for multi-language support.","solution":"Add to `<head>`:\n```html\n<meta name=\"description\" content=\"Restate privacy policy details how we collect, use, and protect your personal information.\">\n<link rel=\"alternate\" hreflang=\"et\" href=\"https://restate.ee/privacy-policy/\">\n<link rel=\"alternate\" hreflang=\"en\" href=\"https://restate.ee/en/privacy-policy/\">\n```"},{"priority":3,"category":"Security","title":"Consider CSP implementation (lower priority for this site)","impact":"XSS defense-in-depth","problem":"CSP missing. Site signals show no auth, payments, or user-generated content — XSS attack surface minimal per rubric.","solution":"If/when adding login or user content, deploy nonce-based CSP:\n```\nContent-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\n```\n- For current brochure/privacy policy page, focus on P1/P2 items first"}],"perfScore":78,"a11yScore":95,"bestPracticesScore":100,"seoScore":100,"securityScore":0},{"url":"https://restate.ee/ettevote/blogi","overall":68,"reasoning":"Mobile performance (83) is dragged down by a 4.2 s LCP, exceeding the 4 s 'poor' threshold despite a 99 desktop score. Security headers are completely absent (0/100), missing baseline protections like HSTS. Accessibility is mostly strong (95) but fails touch target sizing (0.00 score). W3C validation shows 7 script errors from plugin configuration. The site is a commercial real estate blog with no auth/payment risk, lowering CSP priority.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Remove lazy loading from hero image","impact":"LCP, FCP","problem":"Hero image has loading=\"lazy\", which delays LCP to 4.2 s on mobile (Optimized-Web Checklist fail).","solution":"Remove `loading=\"lazy\"` and add `fetchpriority=\"high\"` to the hero `<img>`:\n```html\n<img src=\"/hero.jpg\" alt=\"...\" fetchpriority=\"high\" width=\"...\" height=\"...\">\n```"},{"priority":2,"category":"Security","title":"Add baseline security headers (HSTS, X-Frame-Options, X-Content-Type-Options)","impact":"Transport security, clickjacking, MIME sniffing","problem":"Security Headers grade is 0/100; HSTS, X-Frame-Options, and X-Content-Type-Options are missing.","solution":"Configure server (Apache example):\n```\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Content-Type-Options \"nosniff\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\n```"},{"priority":2,"category":"Accessibility","title":"Increase touch target sizes for interactive elements","impact":"Mobile usability, WCAG 2.5.8","problem":"PSI `target-size` audit score is 0.00, indicating touch targets are too small or lack spacing.","solution":"Ensure all interactive elements (links, buttons) have a minimum 44×44 px touch target area. Add padding or margins to small icons/links."},{"priority":3,"category":"SEO","title":"Add a meta description","impact":"Search snippet quality, CTR","problem":"HTML Inventory shows meta description is not set; PSI SEO audit fails `metaDescription`.","solution":"Add a unique `<meta name=\"description\" content=\"...\">` tag in the `<head>` summarizing the blog page content."},{"priority":3,"category":"Best Practices","title":"Fix invalid script type attributes","impact":"HTML validation, potential parsing issues","problem":"W3C Validator reports 7 errors: `type=\"text/rocketlazyloadscript\"` with `defer` is invalid.","solution":"Update WP Rocket configuration or custom scripts to use standard MIME types (`text/javascript`) or remove the `type` attribute entirely for JS."}],"perfScore":83,"a11yScore":96,"bestPracticesScore":100,"seoScore":92,"securityScore":0},{"url":"https://restate.ee/varahaldus-kuidas-hoida-kinnisvaraportfell-toos","overall":72,"reasoning":"Mobile LCP of 4.1 s exceeds the 4 s threshold for a passing Core Web Vital, significantly impacting the performance score despite a low total page weight (535 KB). Security headers score is 0/100 with HSTS and X-Frame-Options missing, though the site lacks authentication or payments. W3C validation reports 10 errors, primarily invalid script types generated by the WP Rocket plugin. Accessibility is generally strong with only 1 moderate axe violation and PSI tap-target warnings. Confidence is high as all audit sources returned complete data without errors.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Improve Largest Contentful Paint (LCP)","impact":"LCP, FCP, Mobile Performance Score","problem":"Mobile LCP is 4.1 s (threshold is ≤4 s), flagged as a high-priority PSI failure despite low page weight.","solution":"1. Preload the LCP image and critical fonts.\n2. Ensure `font-display: swap` is used for web fonts.\n3. Optimize the hero image delivery (check if `fetchpriority=\"high\"` is needed).\n4. Review server-side rendering or caching to reduce render-blocking resources."},{"priority":2,"category":"Security","title":"Add Baseline Security Headers","impact":"Transport security, clickjacking protection","problem":"Security Headers grade is 0/100; HSTS, X-Frame-Options, and X-Content-Type-Options are missing.","solution":"Configure the web server (Apache/Nginx) to send:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Best Practices","title":"Fix W3C HTML Validation Errors","impact":"Parser recovery, SEO, maintainability","problem":"10 W3C errors found, including 7 instances of invalid `script` tags using `type=\"text/rocketlazyloadscript\"` with `defer`.","solution":"Update the WP Rocket plugin configuration or version. The `type` attribute on scripts should be omitted or set to `module`/`text/javascript`. Invalid types can cause parsing issues in some browsers."},{"priority":2,"category":"Accessibility","title":"Fix Touch Targets and Landmarks","impact":"WCAG 2.5.8 (Target Size), 1.3.1 (Info and Relationships)","problem":"PSI reports `tapTargets` failure; axe reports `landmark-unique` violation on `.footer__social`.","solution":"1. Increase spacing or size of interactive elements to at least 44×44 px.\n2. Add unique `aria-label` or `title` attributes to duplicate footer landmarks to distinguish them for screen readers."},{"priority":3,"category":"Security","title":"Implement Content Security Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP is missing. Site signals indicate no auth, payments, or user content, lowering immediate risk but CSP remains a best practice.","solution":"Deploy a strict CSP using nonces or hashes rather than a flat allowlist:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\"\n```"},{"priority":2,"category":"Performance","title":"Correct Cache-Control Headers","impact":"Repeat visit performance, bandwidth","problem":"Response header `cache-control: max-age=0` prevents effective browser caching despite WP Rocket detection.","solution":"Configure WP Rocket or server rules to set `Cache-Control: public, max-age=31536000` for static assets and `max-age=3600` for HTML, ensuring the `Vary: Accept-Encoding` header is preserved."}],"perfScore":85,"a11yScore":96,"bestPracticesScore":100,"seoScore":100,"securityScore":0},{"url":"https://restate.ee/aripinna-uurimine-viis-asja-mida-enne-lepingu-allkirjastamist-kontrollida","overall":73,"reasoning":"Mobile Performance 81 is solid, but LCP 4.2 s exceeds the 4 s heavy-penalty threshold, dragging the score down despite good CLS/TBT. Security Headers grade 0/100 (missing HSTS, X-Frame-Options) is a critical baseline failure regardless of site signals. W3C validation shows 10 errors, primarily script `type`/`defer` misuse, indicating plugin configuration issues. Accessibility is mostly strong (96) but fails `target-size` and has a landmark uniqueness issue. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Optimize Largest Contentful Paint (LCP) resource","impact":"LCP, FCP, Mobile Performance","problem":"Mobile LCP is 4.2 s (threshold >4 s is heavy penalty); PSI flags `largest-contentful-paint` and `font-display-insight` as high priority.","solution":"- Preload the LCP image (hero) with `<link rel=\"preload\" as=\"image\">`.\n- Convert hero image to WebP/AVIF with fallback.\n- Ensure `font-display: swap` is active for Open Sans to prevent render blocking."},{"priority":2,"category":"Security","title":"Add baseline security headers (HSTS, X-Frame-Options, X-Content-Type-Options)","impact":"Transport security, clickjacking, MIME sniffing","problem":"Security Headers grade 0/100; HSTS, X-Frame-Options, and X-Content-Type-Options are missing despite HTTPS being present.","solution":"Configure server (Apache example):\n```\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains\"\nHeader always set X-Frame-Options \"SAMEORIGIN\"\nHeader always set X-Content-Type-Options \"nosniff\"\n```"},{"priority":2,"category":"Accessibility","title":"Increase touch target sizes and fix landmark uniqueness","impact":"WCAG 2.5.8 Target Size, 1.3.1 Info and Relationships","problem":"PSI `target-size` audit fails; axe reports `landmark-unique` violation on `.footer__social`.","solution":"- Ensure all interactive elements have 44×44 px minimum touch area.\n- Add unique `aria-label` or `role` to the footer social landmark to distinguish it from other nav regions."},{"priority":3,"category":"Best Practices","title":"Fix W3C HTML validation errors (Script types and SVG attributes)","impact":"Parser recovery, SEO, Maintainability","problem":"10 W3C errors: 7x `script` with invalid `type` + `defer`, 2x `preserveAspectRatio` on `use`.","solution":"- Remove `type=\"text/rocketlazyloadscript\"` or change to `text/javascript`.\n- Remove `defer` from scripts with non-standard MIME types.\n- Remove `preserveAspectRatio` from `<use>` elements (valid on `<svg>` only)."}],"perfScore":81,"a11yScore":96,"bestPracticesScore":100,"seoScore":100,"securityScore":0}]}