{"url":"https://www.sorainen.com/","date":"2026-08-12","siteName":"Law firm Sorainen - helping clients succeed in business","overall":53,"reasoning":"Site overall 53 is the mean of 10 pages. Scores range 42 (https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year) → 66 (https://www.sorainen.com/lv/zinas). Weakest page: Mobile PSI performance is critically low at 48, driven by a catastrophic LCP of 11.7 s and 15.61 MB of media weight. Accessibility is compromised by 2 critical axe violations (image-alt, button-name) and 3 serious issues. Security headers score 40/100 with weak HSTS and CSP allowing unsafe-inline, which is elevated to Priority 1 due to the inferred user-generated content signal. W3C validation shows 6 errors including nesting violations and missing alt attributes. Desktop performance (77) is significantly better than mobile, but mobile-first indexing penalizes the overall score heavily.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Reduce page weight and optimize media","impact":"LCP, FCP, Total Page Weight","problem":"Total page weight is 18.34 MB with 15.61 MB in media; LCP is 17.1s on mobile (vs 1.9s desktop).","solution":"- Compress video assets (splash.webm failed to load, likely oversized).\n- Convert images to WebP/AVIF.\n- Implement lazy loading for below-fold images (19 currently missing).\n- Use `fetchpriority=\"low\"` for non-critical media."},{"priority":1,"category":"Accessibility","title":"Add alt text to all images","impact":"WCAG 1.1.1, SEO","problem":"12 images missing `alt` attribute (W3C errors + axe critical violations).","solution":"- Audit all `<img>` tags.\n- Add descriptive `alt` text for content images.\n- Use `alt=\"\"` for decorative images (e.g., lines, icons)."},{"priority":1,"category":"Security","title":"Harden Content Security Policy (CSP)","impact":"XSS Protection","problem":"CSP allows `unsafe-inline` and `unsafe-eval` despite UGC signal (anchor href contains 'post').","solution":"- Remove `'unsafe-inline'` and `'unsafe-eval'` from `script-src`.\n- Implement nonce-based CSP for third-party scripts (GTM, Recaptcha).\n- Ensure `connect-src` allows font checks (hello.myfonts.net currently blocked)."},{"priority":1,"category":"Performance","title":"Reduce Page Weight & Optimize Video","impact":"LCP, FCP, Total Page Weight","problem":"Mobile LCP is 11.6 s and total page weight is 17.42 MB, with a 15.61 MB video asset failing to load.","solution":"- Compress or lazy-load the splash video (currently 15.61 MB).\n- Defer non-critical JavaScript (18 render-blocking scripts found).\n- Implement responsive images to reduce payload on mobile."},{"priority":1,"category":"Accessibility","title":"Fix Critical Form & Button Labels","impact":"WCAG 2.1.1, 4.1.2","problem":"3 critical axe violations: buttons lack discernible text, and form elements (search, newsletter) lack labels.","solution":"- Add `aria-label` to all icon buttons (e.g., `.search-submit`).\n- Associate `<label>` elements with all form inputs (e.g., `#search-text-1`).\n- Ensure `<select>` elements have visible labels."},{"priority":1,"category":"Security","title":"Harden CSP and HSTS","impact":"XSS Defense, Transport Security","problem":"CSP allows `unsafe-inline` and `unsafe-eval` despite UGC signals; HSTS missing `includeSubDomains` and `preload`.","solution":"- Remove `'unsafe-inline'` and `'unsafe-eval'` from `script-src` in CSP.\n- Update HSTS header: `Strict-Transport-Security: max-age=31536000; includeSubDomains; preload`."},{"priority":1,"category":"Accessibility","title":"Fix critical form and button accessibility violations","impact":"WCAG 2.1 A/AA compliance, screen reader usability","problem":"3 critical axe violations: buttons lack discernible text, form elements (search, selects) lack labels, and select elements have no accessible names.","solution":"- Add `aria-label` or visible text to all buttons (e.g., `.search-submit`).\n- Associate `<label>` elements with all form inputs using `for`/`id`.\n- Ensure `<select>` elements have visible labels or `aria-label`."},{"priority":1,"category":"Performance","title":"Eliminate render-blocking JavaScript","impact":"FCP, TBT, LCP","problem":"18 render-blocking scripts in <head> (including jQuery, GTM, Facebook Pixel) delay FCP to 3.06 s and contribute to 992 ms TBT.","solution":"- Add `defer` or `async` to non-critical scripts in `<head>`.\n- Move analytics and third-party tags (GTM, Facebook) to the footer or load via `requestIdleCallback`.\n- Inline critical CSS and defer non-critical CSS."},{"priority":1,"category":"Performance","title":"Eliminate render-blocking JavaScript to improve LCP","impact":"LCP, FCP, Speed Index","problem":"LCP is 4.1 s on mobile; 18 render-blocking scripts identified including jQuery and analytics trackers.","solution":"Move non-critical scripts to footer or add `defer`/`async` attributes. Prioritize deferring `gtag.js`, `recaptcha`, and `facebook_pixel`.\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":1,"category":"SEO","title":"Add a single H1 heading element","impact":"Document outline, Search ranking","problem":"HTML Inventory shows 0 H1 elements; page starts with H2. This breaks document hierarchy.","solution":"Ensure the main page title is wrapped in `<h1>`. Avoid multiple H1s.\n```html\n<h1>Ziņas</h1>\n```"},{"priority":1,"category":"Accessibility","title":"Fix critical form and button accessibility issues","impact":"WCAG 2.1 A/AA compliance, Screen Reader usability","problem":"3 critical axe violations: buttons lack discernible text, form elements lack labels, and select elements lack accessible names.","solution":"- Add `aria-label` or visible text to all buttons (e.g., `.search-submit`).\n- Associate `<label>` elements with all form inputs (`#search-text-1`, `#taxonomy-select-2`).\n- Ensure all interactive elements have focusable, named targets."},{"priority":1,"category":"Performance","title":"Reduce media weight and optimize LCP","impact":"LCP (10.9 s), Page Weight (17.39 MB), TBT (1.01 s)","problem":"Browser runtime shows 15.61 MB of media (video) and LCP is 10.9 s on mobile; 16 render-blocking scripts contribute to TBT.","solution":"- Replace the 15.61 MB video with a lightweight poster image and lazy-load the video.\n- Add `defer` or `async` to the 16 render-blocking scripts in `<head>`.\n- Preload critical LCP image if it is an `<img>`."},{"priority":1,"category":"Accessibility","title":"Fix critical axe violations","impact":"WCAG 2.1 Level A (button-name, image-alt)","problem":"axe-core found 2 critical violations: buttons without discernible text (`.search-submit`) and images without alt attributes (`.newsIntro__line--2`).","solution":"- Add `aria-label` or visible text to `.search-submit` button.\n- Add descriptive `alt` text to all content images; use `alt=\"\"` for decorative SVGs.\n- Ensure color contrast ratio is ≥4.5:1 for `.menu-item` links."},{"priority":1,"category":"Security","title":"Harden Content Security Policy","impact":"XSS protection (CSP currently allows unsafe-inline/eval)","problem":"CSP allows `'unsafe-inline'` and `'unsafe-eval'`, negating XSS protection; site signals indicate user-generated content exists.","solution":"- Remove `'unsafe-inline'` and `'unsafe-eval'` from `script-src`.\n- Implement nonce-based CSP: `script-src 'nonce-{random}' 'strict-dynamic'`.\n- Whitelist only necessary third-party domains (e.g., Google Fonts, Analytics)."},{"priority":1,"category":"Accessibility","title":"Fix critical axe-core violations","impact":"WCAG 2.1 AA Compliance","problem":"2 critical violations: buttons lack discernible text (`.search-submit`), images lack alt text (`.newsIntro__line--2`).","solution":"- Add `aria-label` or visible text to all buttons.\n- Ensure all `<img>` tags have descriptive `alt` attributes.\n- Fix color contrast issues on menu links (serious violation)."},{"priority":1,"category":"Security","title":"Harden Content Security Policy and HSTS","impact":"XSS Protection, Transport Security","problem":"CSP allows `unsafe-inline` and `unsafe-eval` (high risk for UGC site). HSTS missing `includeSubDomains` and `preload`.","solution":"- Remove `unsafe-inline` and `unsafe-eval` from CSP; use nonces/hashes for scripts.\n- Update HSTS: `max-age=31536000; includeSubDomains; preload`.\n- Add `Referrer-Policy: strict-origin-when-cross-origin`."},{"priority":1,"category":"Performance","title":"Reduce media weight and fix failed video request","impact":"LCP, FCP, Total Page Weight","problem":"Total page weight is 17.4 MB with 15.6 MB from media; LCP is 11.0 s on mobile. A video splash.webm request failed (ERR_ABORTED).","solution":"- Compress and convert video to modern formats (WebM/MP4) with lower bitrate.\n- Implement lazy loading for non-critical media.\n- Ensure the hero image is optimized (WebP/AVIF) and uses `fetchpriority=\"high\"`.\n- Fix the broken video source path or remove the element if not essential."},{"priority":1,"category":"Performance","title":"Reduce media weight and fix broken video","impact":"LCP, FCP, Page Weight","problem":"Browser runtime shows 15.61 MB of media (15.61 MB total page weight), with a failed video request (splash.webm) and LCP at 11.7 s.","solution":"- Compress or lazy-load the hero video; consider using a poster image instead of autoplaying video.\n- Convert large images to WebP/AVIF.\n- Implement `fetchpriority=\"high\"` on the LCP image.\n- Fix the broken `splash.webm` request or remove the reference."},{"priority":1,"category":"Accessibility","title":"Fix critical image-alt and button-name violations","impact":"WCAG 2.1 A Compliance, Screen Reader Usability","problem":"axe-core reports 2 critical violations: images missing `[alt]` attributes and buttons (`.search-submit`, `.col-tp-none`) lacking discernible text.","solution":"- Add descriptive `alt` text to all content images; use `alt=\"\"` for decorative SVGs.\n- Add `aria-label` or visible text to search and close buttons, e.g., `<button aria-label=\"Close\">`."},{"priority":1,"category":"Security","title":"Harden HSTS and CSP (UGC Signal)","impact":"Transport Security, XSS Defense","problem":"HSTS missing `includeSubDomains`/`preload`; CSP allows `unsafe-inline` and `unsafe-eval`. UGC signal elevates XSS risk to Priority 1 per rubric.","solution":"- Update HSTS: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`.\n- Remove `unsafe-inline` and `unsafe-eval` from CSP `script-src`. Use nonces or hashes for inline scripts.\n- Add `Referrer-Policy: strict-origin-when-cross-origin`."},{"priority":1,"category":"Performance","title":"Reduce media weight and fix LCP","impact":"LCP, FCP, Page Weight","problem":"LCP is 11.0 s on mobile; total page weight is 17.39 MB with 15.61 MB in media (video splash.webm failed to load).","solution":"- Replace the 15.6 MB video splash with a lightweight poster image or compressed WebM.\n- Implement lazy loading for off-screen media.\n- Ensure the LCP element (likely hero image) is preloaded and sized correctly."},{"priority":1,"category":"Accessibility","title":"Fix critical axe violations (buttons, images)","impact":"WCAG 2.1 A Compliance","problem":"2 critical violations: `button-name` (search-submit, col-tp-none) and `image-alt` (newsIntro__line--2).","solution":"- Add `aria-label` or visible text to `.search-submit` and `.col-tp-none` buttons.\n- Add descriptive `alt` text to `.newsIntro__line--2` image.\n- Ensure all decorative images use `alt=\"\"`."},{"priority":2,"category":"Performance","title":"Defer render-blocking scripts","impact":"FCP, TBT","problem":"11 render-blocking scripts detected; 4 in `<head>` blocking rendering.","solution":"- Add `defer` or `async` to non-critical scripts (jQuery, GTM, Analytics).\n- Move scripts to footer where possible.\n- Inline critical CSS and defer non-critical CSS."},{"priority":2,"category":"Security","title":"Complete HSTS configuration","impact":"Transport Security","problem":"HSTS present but missing `includeSubDomains` and `preload` directives.","solution":"- Update header to: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`.\n- Submit domain to hstspreload.org after testing."},{"priority":2,"category":"Best Practices","title":"Resolve HTML Validation Errors","impact":"DOM Stability, SEO","problem":"10 W3C errors including duplicate IDs (e.g., `select-50-8002b801-adc4a003`) and invalid attributes (`stylr`, `pause`).","solution":"- Ensure all `id` attributes are unique across the document.\n- Remove invalid attributes like `stylr` on `<a>` and `pause` on `<video>`.\n- Add missing spaces between attributes."},{"priority":2,"category":"Performance","title":"Optimize media assets and video loading","impact":"Page weight, LCP, bandwidth","problem":"Total page weight is 17.4 MB, with media consuming 15.6 MB. A video resource failed to load (`splash.webm`), and images lack dimensions.","solution":"- Compress video or use adaptive streaming (HLS/DASH) instead of direct `.webm`.\n- Add `width` and `height` attributes to all images to prevent layout shifts.\n- Implement lazy loading for off-screen media."},{"priority":2,"category":"Accessibility","title":"Fix heading hierarchy and landmarks","impact":"Screen reader navigation, SEO structure","problem":"Document has 0 `<h1>` elements, missing `<main>` landmark, and no skip-to-content link.","solution":"- Add a single `<h1>` at the top of the content (e.g., 'Uudised').\n- Wrap main content in `<main>` tag.\n- Add a skip-link anchor at the top of the `<body>`."},{"priority":2,"category":"Security","title":"Strengthen HSTS and add missing headers","impact":"Transport security, clickjacking protection","problem":"HSTS is missing `includeSubDomains` and `preload`. Referrer-Policy and Permissions-Policy are absent.","solution":"- Update HSTS to: `max-age=63072000; includeSubDomains; preload`.\n- Add `Referrer-Policy: strict-origin-when-cross-origin`.\n- Add `Permissions-Policy` to disable unused features (e.g., geolocation, camera)."},{"priority":2,"category":"Security","title":"Strengthen HSTS and resolve CSP blocking errors","impact":"Transport security, Resource loading stability","problem":"HSTS missing `includeSubDomains`; CSP blocks `hello.myfonts.net` causing console errors and potential font load failures.","solution":"Update HSTS header:\n```http\nStrict-Transport-Security: max-age=31536000; includeSubDomains; preload\n```\nUpdate CSP `connect-src` to allow `hello.myfonts.net` if required, or remove the script causing the violation."},{"priority":2,"category":"Performance","title":"Defer unused third-party JavaScript","impact":"TBT, Page Weight","problem":"164 KB wasted on recaptcha, 71 KB on gtag; long tasks detected from these scripts.","solution":"Load analytics and marketing scripts only after user interaction or via `defer`. Consider removing unused tracking pixels."},{"priority":2,"category":"Security","title":"Fix CSP blocking and harden HSTS","impact":"Resource loading, Transport security","problem":"CSP blocks `hello.myfonts.net` causing console errors; HSTS missing `includeSubDomains` and `preload`.","solution":"- Update CSP `connect-src` to allow `https://hello.myfonts.net`.\n- Update HSTS header: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`.\n- Remove `unsafe-inline` from CSP `script-src` if possible, or use nonces."},{"priority":2,"category":"SEO","title":"Fix HTML validation and meta tags","impact":"Search indexing, crawlability","problem":"W3C reports 5 errors (nesting, illegal href characters); HTML Inventory shows missing meta description.","solution":"- Add `<meta name=\"description\" content=\"...\">` summarizing the article.\n- Fix `<a>` hrefs to remove spaces (encode as `%20`).\n- Close `<a>` tags properly to fix nesting errors."},{"priority":2,"category":"SEO","title":"Add meta description and fix HTML validation","impact":"Search Snippets, Crawlability","problem":"Meta description is missing. W3C validator reports 5 errors including bad href characters and nesting violations.","solution":"- Add a unique `<meta name=\"description\">` tag (150-160 chars).\n- Fix W3C errors: remove spaces in URL query strings, close `<a>` tags properly.\n- Ensure `lang` attribute is set correctly on `<html>`."},{"priority":2,"category":"Performance","title":"Defer render-blocking JavaScript","impact":"FCP, TBT, Time to Interactive","problem":"16 render-blocking scripts detected in HTML inventory; 4 in <head> per checklist. TBT is 504 ms.","solution":"- Add `defer` or `async` attributes to non-critical scripts (analytics, widgets).\n- Move script tags to the end of `<body>` where possible.\n- Inline critical CSS and defer non-critical stylesheets."},{"priority":2,"category":"Security","title":"Harden Security Headers (HSTS & CSP)","impact":"Transport Security, XSS Defense","problem":"HSTS missing `includeSubDomains` and `preload`. CSP allows `unsafe-inline` and `unsafe-eval`, negating XSS protection.","solution":"- Update HSTS: `max-age=31536000; includeSubDomains; preload`.\n- Refine CSP: Remove `unsafe-inline` and `unsafe-eval` from `script-src`. Use nonces or hashes for allowed scripts.\n- Add `Referrer-Policy: strict-origin-when-cross-origin`."},{"priority":2,"category":"Best Practices","title":"Resolve W3C HTML Validation Errors","impact":"Render Consistency, SEO","problem":"20 validation errors including unknown element `o_p` (x7) and missing `alt` attributes. Parser recovery failed at line 311.","solution":"- Identify and remove the plugin/theme generating the invalid `<o_p>` element.\n- Fix nesting errors (e.g., `<a>` inside `<a>`).\n- Ensure all `<img>` tags have `alt` attributes."},{"priority":2,"category":"SEO","title":"Add meta description and fix W3C errors","impact":"Search Snippets, HTML Validity","problem":"Missing meta description; W3C reports 6 errors including illegal href characters and nesting violations.","solution":"- Add `<meta name=\"description\" content=\"...\">` summarizing the article.\n- Fix W3C errors: ensure `<a>` tags are not nested, fix illegal characters in `href` (spaces), and ensure proper nesting of `<img>` inside `<a>`."},{"priority":2,"category":"Security","title":"Harden HSTS and CSP headers","impact":"Transport Security, XSS Defense","problem":"HSTS missing `includeSubDomains` and `preload`; CSP allows `unsafe-inline` and `unsafe-eval` (Grade 40/100).","solution":"- Update HSTS: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`\n- Tighten CSP: Remove `unsafe-inline` and `unsafe-eval`; use nonces/hashes for scripts.\n- Add `Referrer-Policy: strict-origin-when-cross-origin`."},{"priority":3,"category":"Best Practices","title":"Fix HTML nesting and validation errors","impact":"Maintainability, SEO","problem":"W3C reports 15 errors including 'Start tag seen but element already open' and 'End tag violates nesting rules'.","solution":"- Fix anchor nesting (e.g., `<a>` inside `<a>`).\n- Ensure proper heading hierarchy (no empty `<h2>`).\n- Validate HTML after script changes."},{"priority":3,"category":"SEO","title":"Add Meta Description","impact":"Search Snippets, CTR","problem":"SEO audit failed `metaDescription`; document lacks a summary for search engines.","solution":"- Add a `<meta name=\"description\" content=\"...\">` tag with 150–160 characters summarizing the newsroom content."},{"priority":3,"category":"SEO","title":"Add meta description and fix HTML errors","impact":"Search snippet quality, validation","problem":"Meta description is missing. W3C validator reports 8 errors (duplicate IDs, bad attributes, no space between attributes).","solution":"- Write a unique meta description (150–160 chars).\n- Fix duplicate ID `select-kapitaliturud`.\n- Correct malformed attributes (e.g., `stylr` → `style`, `pause` on video)."},{"priority":3,"category":"Security","title":"Harden Content Security Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP allows `unsafe-inline` and `unsafe-eval`, reducing XSS protection. Site signals show no auth/payments, so this is lower priority.","solution":"Replace `unsafe-inline` with nonces or hashes for scripts/styles. Remove `unsafe-eval` where possible."},{"priority":3,"category":"Best Practices","title":"Fix HTML validation errors (Duplicate IDs)","impact":"Maintainability, DOM stability","problem":"W3C reports 11 errors including duplicate IDs (e.g., `select-50-8002b801-ae3c5c07`) and attribute syntax issues.","solution":"Ensure all `id` attributes are unique within the document. Fix attribute spacing syntax (e.g., `value=\"\" placeholder=\"\"`)."},{"priority":3,"category":"SEO","title":"Fix HTML structure and validation errors","impact":"Document outline, Search indexing","problem":"12 W3C errors including missing H1, duplicate IDs, and invalid attributes (`stylr`, `pause` on video).","solution":"- Add exactly one `<h1>` element describing the page topic.\n- Ensure unique IDs for all elements (fix `select-finansai-ir-draudimas` duplicates).\n- Remove invalid attributes and fix `</p>` tag nesting."}],"coverage":{"pct":100,"missing":[]},"siteSummary":{"pagesAudited":10,"pagesAttempted":10,"urls":["https://www.sorainen.com/","https://www.sorainen.com/newsroom","https://www.sorainen.com/et/uudised","https://www.sorainen.com/lv/zinas","https://www.sorainen.com/lt/naujienos","https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus","https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen","https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards","https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year","https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys"]},"psiSnapshot":{"rows":[{"pageUrl":"https://www.sorainen.com/","perfMobile":55,"perfDesktop":64,"lcpMobileMs":17127.887038115692,"lcpDesktopMs":1915.8195967731958,"clsMobile":0,"clsDesktop":0.0001901657860736475},{"pageUrl":"https://www.sorainen.com/newsroom","perfMobile":55,"perfDesktop":72,"lcpMobileMs":11610.666154826024,"lcpDesktopMs":1042.2079495901403,"clsMobile":0,"clsDesktop":0.0001901657860736475},{"pageUrl":"https://www.sorainen.com/et/uudised","perfMobile":58,"perfDesktop":97,"lcpMobileMs":3831.816581578425,"lcpDesktopMs":872.7904549853456,"clsMobile":0,"clsDesktop":0.000454270243790409},{"pageUrl":"https://www.sorainen.com/lv/zinas","perfMobile":72,"perfDesktop":79,"lcpMobileMs":4114.476730265006,"lcpDesktopMs":1116.6196467857303,"clsMobile":0,"clsDesktop":0.0005279003777103866},{"pageUrl":"https://www.sorainen.com/lt/naujienos","perfMobile":61,"perfDesktop":81,"lcpMobileMs":3955.285779832646,"lcpDesktopMs":1238.66784774122,"clsMobile":0,"clsDesktop":0.004208795902086294},{"pageUrl":"https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus","perfMobile":45,"perfDesktop":81,"lcpMobileMs":10934.583216621148,"lcpDesktopMs":1858.7155780822748,"clsMobile":0.004479044021099038,"clsDesktop":0.002750361951934932},{"pageUrl":"https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen","perfMobile":56,"perfDesktop":71,"lcpMobileMs":11026.671104388584,"lcpDesktopMs":929.0846112382194,"clsMobile":0,"clsDesktop":0.0008200125172246142},{"pageUrl":"https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards","perfMobile":55,"perfDesktop":85,"lcpMobileMs":11008.643703419373,"lcpDesktopMs":1570.1996210839943,"clsMobile":0.0009144714876410535,"clsDesktop":0.004686250683836216},{"pageUrl":"https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year","perfMobile":48,"perfDesktop":77,"lcpMobileMs":11743.25838942706,"lcpDesktopMs":974.171697054205,"clsMobile":0.03642955803827218,"clsDesktop":0.0008466485534010051},{"pageUrl":"https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys","perfMobile":55,"perfDesktop":75,"lcpMobileMs":11007.501609728542,"lcpDesktopMs":2104.78856532282,"clsMobile":0,"clsDesktop":0.0001901657860736475}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket)","evidence":["HTML markers: WP Rocket","generator: WPML ver:4.9.6 stt:1,15,32,33;"]},{"id":"lazyload","title":"Images lazy-loaded","status":"n/a","detail":"No raster <img> elements found (4 SVGs excluded).","evidence":[]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"warn","detail":"Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority=\"high\" helps LCP.","evidence":["hero: …nen.com/UserFiles/content%20images/thumbs/__thumb_-2-Darius%20Raulusaitis.jpg","loading: (not set)","fetchpriority: (not set)"]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"warn","detail":"Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.","evidence":["selector: div.expertiseIntro__img.bg-cover","url: …sorainen.com/wp-content/uploads/2026/05/eva-berlaus-sorainen-2026-500x738.jpg","box: 419×624px"]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"n/a","detail":"Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply.","evidence":[]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"n/a","detail":"Too few raster images to evaluate srcset width variety.","evidence":[]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"fail","detail":"4 render-blocking scripts in <head>. Move to footer or add defer/async.","evidence":["…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5","https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1","…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2","https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js"]}],"summary":{"passed":1,"warned":2,"failed":1,"notApplicable":3},"priorities":[{"title":"JS scripts not blocking in <head>","severity":"high","detail":"4 render-blocking scripts in <head>. Move to footer or add defer/async."},{"title":"Hero is a real <img> (not a CSS background-image)","severity":"medium","detail":"Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file."},{"title":"Hero image eagerly loaded","severity":"medium","detail":"Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority=\"high\" helps LCP."}]},"perPageOverall":[{"url":"https://www.sorainen.com/","overall":53,"reasoning":"Mobile performance is critically low (55/100) with an LCP of 17.1s driven by an 18.34 MB page weight, whereas desktop LCP is 1.9s. Accessibility is compromised by 2 critical axe violations including 12 images missing alt text. Security headers are weak (40/100) with HSTS missing includeSubDomains and CSP allowing unsafe-inline despite user-generated content signals. W3C validation shows 15 errors including nesting violations. The site requires urgent optimization of media assets and script loading to meet Core Web Vitals.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Reduce page weight and optimize media","impact":"LCP, FCP, Total Page Weight","problem":"Total page weight is 18.34 MB with 15.61 MB in media; LCP is 17.1s on mobile (vs 1.9s desktop).","solution":"- Compress video assets (splash.webm failed to load, likely oversized).\n- Convert images to WebP/AVIF.\n- Implement lazy loading for below-fold images (19 currently missing).\n- Use `fetchpriority=\"low\"` for non-critical media."},{"priority":1,"category":"Accessibility","title":"Add alt text to all images","impact":"WCAG 1.1.1, SEO","problem":"12 images missing `alt` attribute (W3C errors + axe critical violations).","solution":"- Audit all `<img>` tags.\n- Add descriptive `alt` text for content images.\n- Use `alt=\"\"` for decorative images (e.g., lines, icons)."},{"priority":1,"category":"Security","title":"Harden Content Security Policy (CSP)","impact":"XSS Protection","problem":"CSP allows `unsafe-inline` and `unsafe-eval` despite UGC signal (anchor href contains 'post').","solution":"- Remove `'unsafe-inline'` and `'unsafe-eval'` from `script-src`.\n- Implement nonce-based CSP for third-party scripts (GTM, Recaptcha).\n- Ensure `connect-src` allows font checks (hello.myfonts.net currently blocked)."},{"priority":2,"category":"Performance","title":"Defer render-blocking scripts","impact":"FCP, TBT","problem":"11 render-blocking scripts detected; 4 in `<head>` blocking rendering.","solution":"- Add `defer` or `async` to non-critical scripts (jQuery, GTM, Analytics).\n- Move scripts to footer where possible.\n- Inline critical CSS and defer non-critical CSS."},{"priority":2,"category":"Security","title":"Complete HSTS configuration","impact":"Transport Security","problem":"HSTS present but missing `includeSubDomains` and `preload` directives.","solution":"- Update header to: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`.\n- Submit domain to hstspreload.org after testing."},{"priority":3,"category":"Best Practices","title":"Fix HTML nesting and validation errors","impact":"Maintainability, SEO","problem":"W3C reports 15 errors including 'Start tag seen but element already open' and 'End tag violates nesting rules'.","solution":"- Fix anchor nesting (e.g., `<a>` inside `<a>`).\n- Ensure proper heading hierarchy (no empty `<h2>`).\n- Validate HTML after script changes."}],"perfScore":55,"a11yScore":77,"bestPracticesScore":92,"seoScore":92,"securityScore":40},{"url":"https://www.sorainen.com/newsroom","overall":53,"reasoning":"Mobile performance is critically poor (55/100) with an LCP of 11.6 seconds driven by 17.42 MB of page weight and render-blocking scripts. Accessibility is compromised by 3 critical violations (buttons, labels) and a missing H1 element, failing WCAG standards. Security headers are weak (40/100) with a permissive CSP allowing unsafe-inline despite user-generated content signals. HTML validation errors (10) and duplicate IDs indicate maintenance debt that affects stability. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Reduce Page Weight & Optimize Video","impact":"LCP, FCP, Total Page Weight","problem":"Mobile LCP is 11.6 s and total page weight is 17.42 MB, with a 15.61 MB video asset failing to load.","solution":"- Compress or lazy-load the splash video (currently 15.61 MB).\n- Defer non-critical JavaScript (18 render-blocking scripts found).\n- Implement responsive images to reduce payload on mobile."},{"priority":1,"category":"Accessibility","title":"Fix Critical Form & Button Labels","impact":"WCAG 2.1.1, 4.1.2","problem":"3 critical axe violations: buttons lack discernible text, and form elements (search, newsletter) lack labels.","solution":"- Add `aria-label` to all icon buttons (e.g., `.search-submit`).\n- Associate `<label>` elements with all form inputs (e.g., `#search-text-1`).\n- Ensure `<select>` elements have visible labels."},{"priority":1,"category":"Security","title":"Harden CSP and HSTS","impact":"XSS Defense, Transport Security","problem":"CSP allows `unsafe-inline` and `unsafe-eval` despite UGC signals; HSTS missing `includeSubDomains` and `preload`.","solution":"- Remove `'unsafe-inline'` and `'unsafe-eval'` from `script-src` in CSP.\n- Update HSTS header: `Strict-Transport-Security: max-age=31536000; includeSubDomains; preload`."},{"priority":2,"category":"Best Practices","title":"Resolve HTML Validation Errors","impact":"DOM Stability, SEO","problem":"10 W3C errors including duplicate IDs (e.g., `select-50-8002b801-adc4a003`) and invalid attributes (`stylr`, `pause`).","solution":"- Ensure all `id` attributes are unique across the document.\n- Remove invalid attributes like `stylr` on `<a>` and `pause` on `<video>`.\n- Add missing spaces between attributes."},{"priority":3,"category":"SEO","title":"Add Meta Description","impact":"Search Snippets, CTR","problem":"SEO audit failed `metaDescription`; document lacks a summary for search engines.","solution":"- Add a `<meta name=\"description\" content=\"...\">` tag with 150–160 characters summarizing the newsroom content."}],"perfScore":55,"a11yScore":85,"bestPracticesScore":92,"seoScore":85,"securityScore":40},{"url":"https://www.sorainen.com/et/uudised","overall":58,"reasoning":"Mobile performance is the primary drag (PSI 58, LCP 3.8 s, TBT 992 ms) compared to desktop (97), driven by 18 render-blocking scripts and 15.6 MB media weight. Accessibility has critical failures (3 critical axe violations including missing labels and button names) alongside a missing h1 and main landmark. Security headers are weak (Grade 40/100) with CSP allowing unsafe-inline despite inferred user content signals. HTML validity is compromised by 8 errors including duplicate IDs and malformed attributes. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Accessibility","title":"Fix critical form and button accessibility violations","impact":"WCAG 2.1 A/AA compliance, screen reader usability","problem":"3 critical axe violations: buttons lack discernible text, form elements (search, selects) lack labels, and select elements have no accessible names.","solution":"- Add `aria-label` or visible text to all buttons (e.g., `.search-submit`).\n- Associate `<label>` elements with all form inputs using `for`/`id`.\n- Ensure `<select>` elements have visible labels or `aria-label`."},{"priority":1,"category":"Performance","title":"Eliminate render-blocking JavaScript","impact":"FCP, TBT, LCP","problem":"18 render-blocking scripts in <head> (including jQuery, GTM, Facebook Pixel) delay FCP to 3.06 s and contribute to 992 ms TBT.","solution":"- Add `defer` or `async` to non-critical scripts in `<head>`.\n- Move analytics and third-party tags (GTM, Facebook) to the footer or load via `requestIdleCallback`.\n- Inline critical CSS and defer non-critical CSS."},{"priority":1,"category":"Security","title":"Harden Content Security Policy (CSP)","impact":"XSS mitigation, security headers grade","problem":"CSP allows `unsafe-inline` and `unsafe-eval` scripts. Site signals indicate user-generated content (post links), elevating XSS risk per rubric.","solution":"- Remove `unsafe-inline` and `unsafe-eval` from `script-src`.\n- Implement nonce-based CSP for allowed scripts.\n- Use `strict-dynamic` to allow trusted third-party scripts without whitelisting every domain."},{"priority":2,"category":"Performance","title":"Optimize media assets and video loading","impact":"Page weight, LCP, bandwidth","problem":"Total page weight is 17.4 MB, with media consuming 15.6 MB. A video resource failed to load (`splash.webm`), and images lack dimensions.","solution":"- Compress video or use adaptive streaming (HLS/DASH) instead of direct `.webm`.\n- Add `width` and `height` attributes to all images to prevent layout shifts.\n- Implement lazy loading for off-screen media."},{"priority":2,"category":"Accessibility","title":"Fix heading hierarchy and landmarks","impact":"Screen reader navigation, SEO structure","problem":"Document has 0 `<h1>` elements, missing `<main>` landmark, and no skip-to-content link.","solution":"- Add a single `<h1>` at the top of the content (e.g., 'Uudised').\n- Wrap main content in `<main>` tag.\n- Add a skip-link anchor at the top of the `<body>`."},{"priority":2,"category":"Security","title":"Strengthen HSTS and add missing headers","impact":"Transport security, clickjacking protection","problem":"HSTS is missing `includeSubDomains` and `preload`. Referrer-Policy and Permissions-Policy are absent.","solution":"- Update HSTS to: `max-age=63072000; includeSubDomains; preload`.\n- Add `Referrer-Policy: strict-origin-when-cross-origin`.\n- Add `Permissions-Policy` to disable unused features (e.g., geolocation, camera)."},{"priority":3,"category":"SEO","title":"Add meta description and fix HTML errors","impact":"Search snippet quality, validation","problem":"Meta description is missing. W3C validator reports 8 errors (duplicate IDs, bad attributes, no space between attributes).","solution":"- Write a unique meta description (150–160 chars).\n- Fix duplicate ID `select-kapitaliturud`.\n- Correct malformed attributes (e.g., `stylr` → `style`, `pause` on video)."}],"perfScore":58,"a11yScore":85,"bestPracticesScore":92,"seoScore":92,"securityScore":40},{"url":"https://www.sorainen.com/lv/zinas","overall":66,"reasoning":"Mobile performance 72 is significantly dragged down by LCP 4.1 s (>4 s threshold) and 18 render-blocking scripts. Accessibility 85 masks 3 critical axe violations (buttons, labels) and a missing H1 tag which impacts SEO structure. Security headers score 40/100 due to weak HSTS and permissive CSP, though site signals indicate low auth risk. W3C validation shows 11 errors including duplicate IDs. Overall score reflects significant performance and accessibility debt despite good SEO/Best Practice scores.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Eliminate render-blocking JavaScript to improve LCP","impact":"LCP, FCP, Speed Index","problem":"LCP is 4.1 s on mobile; 18 render-blocking scripts identified including jQuery and analytics trackers.","solution":"Move non-critical scripts to footer or add `defer`/`async` attributes. Prioritize deferring `gtag.js`, `recaptcha`, and `facebook_pixel`.\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":1,"category":"Accessibility","title":"Fix critical form and button accessibility violations","impact":"WCAG 2.1 A/AA compliance, Screen Reader usability","problem":"3 critical axe violations: buttons without discernible text, form inputs without labels, select elements without names.","solution":"Add `aria-label` or visible text to buttons. Associate `<label>` elements with inputs using `for`/`id`.\n```html\n<button aria-label=\"Filter posts\">Filter</button>\n<input id=\"search\" aria-labelledby=\"search-label\">\n<label for=\"search\">Search</label>\n```"},{"priority":1,"category":"SEO","title":"Add a single H1 heading element","impact":"Document outline, Search ranking","problem":"HTML Inventory shows 0 H1 elements; page starts with H2. This breaks document hierarchy.","solution":"Ensure the main page title is wrapped in `<h1>`. Avoid multiple H1s.\n```html\n<h1>Ziņas</h1>\n```"},{"priority":2,"category":"Security","title":"Strengthen HSTS and resolve CSP blocking errors","impact":"Transport security, Resource loading stability","problem":"HSTS missing `includeSubDomains`; CSP blocks `hello.myfonts.net` causing console errors and potential font load failures.","solution":"Update HSTS header:\n```http\nStrict-Transport-Security: max-age=31536000; includeSubDomains; preload\n```\nUpdate CSP `connect-src` to allow `hello.myfonts.net` if required, or remove the script causing the violation."},{"priority":2,"category":"Performance","title":"Defer unused third-party JavaScript","impact":"TBT, Page Weight","problem":"164 KB wasted on recaptcha, 71 KB on gtag; long tasks detected from these scripts.","solution":"Load analytics and marketing scripts only after user interaction or via `defer`. Consider removing unused tracking pixels."},{"priority":3,"category":"Security","title":"Harden Content Security Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP allows `unsafe-inline` and `unsafe-eval`, reducing XSS protection. Site signals show no auth/payments, so this is lower priority.","solution":"Replace `unsafe-inline` with nonces or hashes for scripts/styles. Remove `unsafe-eval` where possible."},{"priority":3,"category":"Best Practices","title":"Fix HTML validation errors (Duplicate IDs)","impact":"Maintainability, DOM stability","problem":"W3C reports 11 errors including duplicate IDs (e.g., `select-50-8002b801-ae3c5c07`) and attribute syntax issues.","solution":"Ensure all `id` attributes are unique within the document. Fix attribute spacing syntax (e.g., `value=\"\" placeholder=\"\"`)."}],"perfScore":72,"a11yScore":85,"bestPracticesScore":92,"seoScore":92,"securityScore":40},{"url":"https://www.sorainen.com/lt/naujienos","overall":58,"reasoning":"Mobile performance 61 masks severe metric penalties (LCP 4.0s, TBT 759ms) driven by a massive 17.4 MB page weight. Accessibility has 3 critical axe violations despite an 85 Lighthouse score, indicating significant usability barriers. Security headers grade 40/100 with CSP actively blocking legitimate font resources. W3C validation shows 12 errors including a missing H1 and duplicate IDs. Confidence is high as all tools returned data without errors.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Reduce page weight and optimize media","impact":"LCP, TBT, Total Page Weight","problem":"Total page weight is 17.4 MB with 15.6 MB in media; LCP is 4.0 s and TBT is 759 ms on mobile.","solution":"- Compress or lazy-load the 15.6 MB media assets (video/splash.webm failed to load).\n- Implement responsive images (`srcset`) and modern formats (WebP/AVIF).\n- Remove unused video resources if not critical for above-the-fold content."},{"priority":1,"category":"Accessibility","title":"Fix critical form and button accessibility issues","impact":"WCAG 2.1 A/AA compliance, Screen Reader usability","problem":"3 critical axe violations: buttons lack discernible text, form elements lack labels, and select elements lack accessible names.","solution":"- Add `aria-label` or visible text to all buttons (e.g., `.search-submit`).\n- Associate `<label>` elements with all form inputs (`#search-text-1`, `#taxonomy-select-2`).\n- Ensure all interactive elements have focusable, named targets."},{"priority":2,"category":"Security","title":"Fix CSP blocking and harden HSTS","impact":"Resource loading, Transport security","problem":"CSP blocks `hello.myfonts.net` causing console errors; HSTS missing `includeSubDomains` and `preload`.","solution":"- Update CSP `connect-src` to allow `https://hello.myfonts.net`.\n- Update HSTS header: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`.\n- Remove `unsafe-inline` from CSP `script-src` if possible, or use nonces."},{"priority":2,"category":"Performance","title":"Defer render-blocking scripts","impact":"FCP, TBT, Speed Index","problem":"18 render-blocking scripts found; TBT is 759 ms due to long tasks from GTM and Recaptcha.","solution":"- Add `defer` or `async` to non-critical scripts in `<head>`.\n- Move analytics and third-party tags (GTM, Facebook Pixel) to footer or load via `requestIdleCallback`.\n- Remove unused JavaScript (154 KB wasted in Recaptcha)."},{"priority":3,"category":"SEO","title":"Fix HTML structure and validation errors","impact":"Document outline, Search indexing","problem":"12 W3C errors including missing H1, duplicate IDs, and invalid attributes (`stylr`, `pause` on video).","solution":"- Add exactly one `<h1>` element describing the page topic.\n- Ensure unique IDs for all elements (fix `select-finansai-ir-draudimas` duplicates).\n- Remove invalid attributes and fix `</p>` tag nesting."}],"perfScore":61,"a11yScore":85,"bestPracticesScore":92,"seoScore":92,"securityScore":40},{"url":"https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus","overall":48,"reasoning":"Mobile performance is critically low (45/100) with an LCP of 10.9 s and TBT of 1.01 s, primarily driven by a 17.39 MB page weight including 15.61 MB of media. Accessibility has critical axe violations (button-name, image-alt) and serious contrast issues despite a PSI score of 81. Security headers are weak (CSP allows unsafe-inline/eval, HSTS missing includeSubDomains) which is significant given the inferred user-generated content signal. W3C validation shows 5 errors including nesting and illegal characters, and SEO lacks a meta description. The score reflects the catastrophic mobile performance and critical accessibility/security gaps.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Reduce media weight and optimize LCP","impact":"LCP (10.9 s), Page Weight (17.39 MB), TBT (1.01 s)","problem":"Browser runtime shows 15.61 MB of media (video) and LCP is 10.9 s on mobile; 16 render-blocking scripts contribute to TBT.","solution":"- Replace the 15.61 MB video with a lightweight poster image and lazy-load the video.\n- Add `defer` or `async` to the 16 render-blocking scripts in `<head>`.\n- Preload critical LCP image if it is an `<img>`."},{"priority":1,"category":"Accessibility","title":"Fix critical axe violations","impact":"WCAG 2.1 Level A (button-name, image-alt)","problem":"axe-core found 2 critical violations: buttons without discernible text (`.search-submit`) and images without alt attributes (`.newsIntro__line--2`).","solution":"- Add `aria-label` or visible text to `.search-submit` button.\n- Add descriptive `alt` text to all content images; use `alt=\"\"` for decorative SVGs.\n- Ensure color contrast ratio is ≥4.5:1 for `.menu-item` links."},{"priority":1,"category":"Security","title":"Harden Content Security Policy","impact":"XSS protection (CSP currently allows unsafe-inline/eval)","problem":"CSP allows `'unsafe-inline'` and `'unsafe-eval'`, negating XSS protection; site signals indicate user-generated content exists.","solution":"- Remove `'unsafe-inline'` and `'unsafe-eval'` from `script-src`.\n- Implement nonce-based CSP: `script-src 'nonce-{random}' 'strict-dynamic'`.\n- Whitelist only necessary third-party domains (e.g., Google Fonts, Analytics)."},{"priority":2,"category":"Security","title":"Strengthen HSTS and add missing headers","impact":"Transport security, clickjacking protection","problem":"HSTS is missing `includeSubDomains` and `preload`; Referrer-Policy and Permissions-Policy are absent.","solution":"- Update HSTS: `max-age=31536000; includeSubDomains; preload`.\n- Add `Referrer-Policy: strict-origin-when-cross-origin`.\n- Add `Permissions-Policy` to disable unused features (e.g., `geolocation=()`)."},{"priority":2,"category":"SEO","title":"Fix HTML validation and meta tags","impact":"Search indexing, crawlability","problem":"W3C reports 5 errors (nesting, illegal href characters); HTML Inventory shows missing meta description.","solution":"- Add `<meta name=\"description\" content=\"...\">` summarizing the article.\n- Fix `<a>` hrefs to remove spaces (encode as `%20`).\n- Close `<a>` tags properly to fix nesting errors."}],"perfScore":45,"a11yScore":81,"bestPracticesScore":92,"seoScore":77,"securityScore":40},{"url":"https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen","overall":48,"reasoning":"Mobile performance is critically low (56/100) driven by a catastrophic LCP of 11.0 s and excessive page weight (17.4 MB total, 15.6 MB media). Accessibility has 2 critical violations (button-name, image-alt) despite an 81/100 score, indicating hidden severity. Security headers are weak (40/100) with CSP allowing unsafe-inline, which is risky given the inferred user-generated content signal. HTML validation shows 5 errors including nesting violations, and SEO lacks a meta description. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Reduce page weight and optimize media","impact":"LCP, FCP, Total Page Weight","problem":"Total page weight is 17.40 MB with media alone at 15.61 MB; LCP is 11.0 s on mobile.","solution":"- Compress and resize all images/video assets.\n- Convert video to modern formats (WebM/MP4) with lower bitrates.\n- Implement lazy loading for below-the-fold media.\n- Use a CDN to serve static assets closer to users."},{"priority":1,"category":"Performance","title":"Eliminate render-blocking JavaScript","impact":"FCP, LCP, TBT","problem":"16 render-blocking scripts detected; 4 in <head> causing delays. Long tasks from gtag/recaptcha contribute to TBT (408 ms).","solution":"- Add `defer` or `async` to non-critical scripts.\n- Move scripts to the bottom of `<body>` where possible.\n- Inline critical CSS and defer non-critical CSS.\n- Remove unused JavaScript (164 KB wasted recaptcha, 71 KB gtag)."},{"priority":1,"category":"Accessibility","title":"Fix critical axe-core violations","impact":"WCAG 2.1 AA Compliance","problem":"2 critical violations: buttons lack discernible text (`.search-submit`), images lack alt text (`.newsIntro__line--2`).","solution":"- Add `aria-label` or visible text to all buttons.\n- Ensure all `<img>` tags have descriptive `alt` attributes.\n- Fix color contrast issues on menu links (serious violation)."},{"priority":1,"category":"Security","title":"Harden Content Security Policy and HSTS","impact":"XSS Protection, Transport Security","problem":"CSP allows `unsafe-inline` and `unsafe-eval` (high risk for UGC site). HSTS missing `includeSubDomains` and `preload`.","solution":"- Remove `unsafe-inline` and `unsafe-eval` from CSP; use nonces/hashes for scripts.\n- Update HSTS: `max-age=31536000; includeSubDomains; preload`.\n- Add `Referrer-Policy: strict-origin-when-cross-origin`."},{"priority":2,"category":"SEO","title":"Add meta description and fix HTML validation","impact":"Search Snippets, Crawlability","problem":"Meta description is missing. W3C validator reports 5 errors including bad href characters and nesting violations.","solution":"- Add a unique `<meta name=\"description\">` tag (150-160 chars).\n- Fix W3C errors: remove spaces in URL query strings, close `<a>` tags properly.\n- Ensure `lang` attribute is set correctly on `<html>`."}],"perfScore":56,"a11yScore":81,"bestPracticesScore":69,"seoScore":77,"securityScore":40},{"url":"https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards","overall":52,"reasoning":"Mobile performance is critically low (55/100) with an LCP of 11.0 s and a massive 17.4 MB page weight, primarily driven by 15.6 MB of media assets. Accessibility is compromised by 7 axe violations including critical issues with image alt text and button names. Security headers score only 40/100, with HSTS missing directives and CSP allowing unsafe-inline/eval. HTML validation reveals 20 errors including unknown elements, indicating template or plugin corruption. Desktop performance (85) is significantly better than mobile, highlighting a mobile-first optimization gap.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Reduce media weight and fix failed video request","impact":"LCP, FCP, Total Page Weight","problem":"Total page weight is 17.4 MB with 15.6 MB from media; LCP is 11.0 s on mobile. A video splash.webm request failed (ERR_ABORTED).","solution":"- Compress and convert video to modern formats (WebM/MP4) with lower bitrate.\n- Implement lazy loading for non-critical media.\n- Ensure the hero image is optimized (WebP/AVIF) and uses `fetchpriority=\"high\"`.\n- Fix the broken video source path or remove the element if not essential."},{"priority":1,"category":"Accessibility","title":"Fix critical axe-core violations","impact":"WCAG Compliance, Screen Reader Usability","problem":"7 axe violations found, including 2 critical: missing `alt` on images and buttons without discernible text (`.search-submit`, `.col-tp-none`).","solution":"- Add descriptive `alt` text to all content images (2 missing).\n- Add `aria-label` or visible text to all icon buttons and links.\n- Ensure form inputs (search, contact) have associated `<label>` elements."},{"priority":2,"category":"Performance","title":"Defer render-blocking JavaScript","impact":"FCP, TBT, Time to Interactive","problem":"16 render-blocking scripts detected in HTML inventory; 4 in <head> per checklist. TBT is 504 ms.","solution":"- Add `defer` or `async` attributes to non-critical scripts (analytics, widgets).\n- Move script tags to the end of `<body>` where possible.\n- Inline critical CSS and defer non-critical stylesheets."},{"priority":2,"category":"Security","title":"Harden Security Headers (HSTS & CSP)","impact":"Transport Security, XSS Defense","problem":"HSTS missing `includeSubDomains` and `preload`. CSP allows `unsafe-inline` and `unsafe-eval`, negating XSS protection.","solution":"- Update HSTS: `max-age=31536000; includeSubDomains; preload`.\n- Refine CSP: Remove `unsafe-inline` and `unsafe-eval` from `script-src`. Use nonces or hashes for allowed scripts.\n- Add `Referrer-Policy: strict-origin-when-cross-origin`."},{"priority":2,"category":"Best Practices","title":"Resolve W3C HTML Validation Errors","impact":"Render Consistency, SEO","problem":"20 validation errors including unknown element `o_p` (x7) and missing `alt` attributes. Parser recovery failed at line 311.","solution":"- Identify and remove the plugin/theme generating the invalid `<o_p>` element.\n- Fix nesting errors (e.g., `<a>` inside `<a>`).\n- Ensure all `<img>` tags have `alt` attributes."}],"perfScore":55,"a11yScore":78,"bestPracticesScore":88,"seoScore":77,"securityScore":40},{"url":"https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year","overall":42,"reasoning":"Mobile PSI performance is critically low at 48, driven by a catastrophic LCP of 11.7 s and 15.61 MB of media weight. Accessibility is compromised by 2 critical axe violations (image-alt, button-name) and 3 serious issues. Security headers score 40/100 with weak HSTS and CSP allowing unsafe-inline, which is elevated to Priority 1 due to the inferred user-generated content signal. W3C validation shows 6 errors including nesting violations and missing alt attributes. Desktop performance (77) is significantly better than mobile, but mobile-first indexing penalizes the overall score heavily.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Reduce media weight and fix broken video","impact":"LCP, FCP, Page Weight","problem":"Browser runtime shows 15.61 MB of media (15.61 MB total page weight), with a failed video request (splash.webm) and LCP at 11.7 s.","solution":"- Compress or lazy-load the hero video; consider using a poster image instead of autoplaying video.\n- Convert large images to WebP/AVIF.\n- Implement `fetchpriority=\"high\"` on the LCP image.\n- Fix the broken `splash.webm` request or remove the reference."},{"priority":1,"category":"Accessibility","title":"Fix critical image-alt and button-name violations","impact":"WCAG 2.1 A Compliance, Screen Reader Usability","problem":"axe-core reports 2 critical violations: images missing `[alt]` attributes and buttons (`.search-submit`, `.col-tp-none`) lacking discernible text.","solution":"- Add descriptive `alt` text to all content images; use `alt=\"\"` for decorative SVGs.\n- Add `aria-label` or visible text to search and close buttons, e.g., `<button aria-label=\"Close\">`."},{"priority":1,"category":"Security","title":"Harden HSTS and CSP (UGC Signal)","impact":"Transport Security, XSS Defense","problem":"HSTS missing `includeSubDomains`/`preload`; CSP allows `unsafe-inline` and `unsafe-eval`. UGC signal elevates XSS risk to Priority 1 per rubric.","solution":"- Update HSTS: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`.\n- Remove `unsafe-inline` and `unsafe-eval` from CSP `script-src`. Use nonces or hashes for inline scripts.\n- Add `Referrer-Policy: strict-origin-when-cross-origin`."},{"priority":2,"category":"Performance","title":"Defer render-blocking scripts","impact":"FCP, TBT, Time to Interactive","problem":"16 render-blocking scripts detected in `<head>`; TBT is 832 ms on mobile.","solution":"- Add `defer` or `async` to non-critical scripts (e.g., GTM, Facebook Pixel, CookieYes).\n- Move scripts to `<body>` end where possible.\n- Inline critical CSS and defer non-critical CSS."},{"priority":2,"category":"SEO","title":"Add meta description and fix W3C errors","impact":"Search Snippets, HTML Validity","problem":"Missing meta description; W3C reports 6 errors including illegal href characters and nesting violations.","solution":"- Add `<meta name=\"description\" content=\"...\">` summarizing the article.\n- Fix W3C errors: ensure `<a>` tags are not nested, fix illegal characters in `href` (spaces), and ensure proper nesting of `<img>` inside `<a>`."}],"perfScore":48,"a11yScore":81,"bestPracticesScore":88,"seoScore":77,"securityScore":40},{"url":"https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys","overall":48,"reasoning":"Mobile performance is critically poor (LCP 11.0 s, 17.39 MB total weight), dragging the score into the 'Poor' band despite decent desktop metrics. Accessibility has critical failures (buttons, images) alongside serious contrast issues. Security headers are weak (HSTS, CSP) though the site lacks auth/payments, and the UGC signal appears to be a heuristic false positive for a blog post link. The heavy media weight and render-blocking scripts are the primary technical blockers. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Reduce media weight and fix LCP","impact":"LCP, FCP, Page Weight","problem":"LCP is 11.0 s on mobile; total page weight is 17.39 MB with 15.61 MB in media (video splash.webm failed to load).","solution":"- Replace the 15.6 MB video splash with a lightweight poster image or compressed WebM.\n- Implement lazy loading for off-screen media.\n- Ensure the LCP element (likely hero image) is preloaded and sized correctly."},{"priority":1,"category":"Accessibility","title":"Fix critical axe violations (buttons, images)","impact":"WCAG 2.1 A Compliance","problem":"2 critical violations: `button-name` (search-submit, col-tp-none) and `image-alt` (newsIntro__line--2).","solution":"- Add `aria-label` or visible text to `.search-submit` and `.col-tp-none` buttons.\n- Add descriptive `alt` text to `.newsIntro__line--2` image.\n- Ensure all decorative images use `alt=\"\"`."},{"priority":2,"category":"Performance","title":"Defer render-blocking scripts","impact":"TBT, FCP, Speed Index","problem":"16 render-blocking scripts in <head> (jQuery, GTM, Facebook Pixel) contribute to TBT 479 ms and FCP 3.06 s.","solution":"- Add `defer` or `async` to non-critical scripts in <head>.\n- Move analytics and third-party pixels to the footer or use `type=\"module\"` with `defer`.\n- Example: `<script src=\"...\" defer></script>`"},{"priority":2,"category":"Security","title":"Harden HSTS and CSP headers","impact":"Transport Security, XSS Defense","problem":"HSTS missing `includeSubDomains` and `preload`; CSP allows `unsafe-inline` and `unsafe-eval` (Grade 40/100).","solution":"- Update HSTS: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`\n- Tighten CSP: Remove `unsafe-inline` and `unsafe-eval`; use nonces/hashes for scripts.\n- Add `Referrer-Policy: strict-origin-when-cross-origin`."},{"priority":3,"category":"SEO","title":"Add meta description","impact":"Search Snippets, CTR","problem":"SEO audit flagged missing `metaDescription`; HTML inventory confirms no description tag.","solution":"- Add a unique meta description (150–160 chars) summarizing the article.\n- Example: `<meta name=\"description\" content=\"Edvîns Draba joins the Latvian Association of Patent Attorneys at Sorainen law firm.\">`"}],"perfScore":55,"a11yScore":81,"bestPracticesScore":92,"seoScore":77,"securityScore":40}]}