{"url":"https://www.sorainen.com/et/","date":"2026-08-12","siteName":"Advokaadibüroo Sorainen","overall":54,"reasoning":"Site overall 54 is the mean of 10 pages. Scores range 38 (https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen) → 68 (https://www.sorainen.com/et/uudised). Weakest page: Mobile performance is critically low (42/100) with an LCP of 9.3 s and 15.6 MB of media weight, dragging the score into the 'Poor' band. Accessibility is broken with 7 violations including 2 critical issues (missing alt text, button names) that block WCAG compliance. Security headers are weak (40/100) with a CSP allowing unsafe-inline, which is high risk given the inferred user-generated content signal. Desktop performance (97) contrasts sharply with mobile (42), indicating mobile-specific bottlenecks like render-blocking scripts and unoptimized media.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Reduce media weight and optimize LCP","impact":"LCP, FCP, Page Weight","problem":"LCP is 10.5 s on mobile; total page weight is 18.45 MB with 15.61 MB in media (likely video).","solution":"- Replace the 15.6 MB video asset with a lightweight poster image or compressed WebM.\n- Implement lazy loading for all non-critical media.\n- Use `fetchpriority=\"high\"` only on the actual LCP element."},{"priority":1,"category":"Accessibility","title":"Add alt text to all images and label buttons","impact":"WCAG 1.1.1, 4.1.2","problem":"12 images lack `alt` attributes; 4 buttons (search, close) lack discernible text (axe critical violations).","solution":"- Add descriptive `alt` text to content images; use `alt=\"\"` for decorative SVGs.\n- Add `aria-label` or visible text to `.search-submit`, `.close`, and `.submit` buttons."},{"priority":1,"category":"Security","title":"Harden Content Security Policy (CSP)","impact":"XSS Defense","problem":"CSP allows `unsafe-inline` and `unsafe-eval` scripts; UGC signal is yes, increasing XSS risk.","solution":"- Remove `'unsafe-inline'` and `'unsafe-eval'` from `script-src`.\n- Implement nonce-based CSP for third-party scripts (GTM, Recaptcha).\n- Ensure `connect-src` allows font counting endpoints (hello.myfonts.net)."},{"priority":1,"category":"Performance","title":"Reduce Page Weight and Fix LCP","impact":"LCP, FCP, Speed Index, Mobile Score","problem":"LCP is 11.6 s on mobile; total page weight is 17.42 MB (15.61 MB media). Video splash asset failed to load (ERR_ABORTED).","solution":"- Compress or lazy-load the hero video; ensure fallback image loads first.\n- Implement responsive images (`srcset`) for raster assets.\n- Preload critical LCP image if it is an `<img>`.\n- Audit third-party scripts (recaptcha, gtag) for necessity."},{"priority":1,"category":"Accessibility","title":"Fix Critical Button and Label Violations","impact":"WCAG 2.1 Level A Compliance","problem":"3 critical axe violations: 5 buttons lack discernible text, search/select forms lack labels.","solution":"- Add `aria-label` or visible text to all buttons (e.g., `.search-submit`).\n- Associate `<label>` elements with all form inputs (`for`/`id` matching).\n- Ensure all interactive elements have accessible names."},{"priority":1,"category":"SEO","title":"Add a Single H1 Element","impact":"Document Outline, Search Ranking","problem":"HTML Inventory shows 0 h1 elements; page starts with h2. W3C warns no h1.","solution":"- Ensure exactly one `<h1>` exists per page, typically matching the `<title>` or main heading.\n- Example: `<h1>Newsroom</h1>` at the top of the main content area."},{"priority":1,"category":"Performance","title":"Reduce LCP and render-blocking resources","impact":"LCP, FCP, TBT","problem":"LCP is 4.9 s (threshold 2.5 s) with 15.6 MB media weight and 18 render-blocking scripts in the head.","solution":"- Optimize the 15.6 MB video asset (compress, use modern codecs, lazy load if not above fold).\n- Add `defer` or `async` to non-critical scripts (e.g., GTM, Facebook Pixel).\n- Inline critical CSS and move non-critical stylesheets to the footer."},{"priority":1,"category":"Accessibility","title":"Fix critical form and button accessibility issues","impact":"WCAG 2.1 A/AA compliance","problem":"3 critical violations: buttons lack discernible text, search form lacks labels, select elements lack names.","solution":"- Add `aria-label` or visible text to all icon buttons (e.g., search submit).\n- Associate `<label>` elements with all form inputs using `for` and `id`.\n- Ensure all `<select>` elements have an associated label or `aria-label`."},{"priority":1,"category":"Performance","title":"Defer non-critical JavaScript to reduce TBT","impact":"TBT, FCP, LCP","problem":"TBT is 728 ms (>600 ms heavy penalty) and LCP is 3.9 s due to 18 render-blocking scripts and unused JS (recaptcha, gtag).","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Specifically target:\n- `gtag.js`\n- `gtm.js`\n- `recaptcha__en.js`\n- `facebook_signal.js`\n\nExample:\n```html\n<script src=\"/js/main.js\" defer></script>\n```"},{"priority":1,"category":"Performance","title":"Defer non-critical third-party scripts","impact":"LCP, FCP, TBT (590 ms)","problem":"18 render-blocking scripts and heavy JS (recaptcha, gtag, facebook-pixel) cause LCP 4.0 s and FCP 3.07 s on mobile.","solution":"- Move non-critical scripts to footer or add `defer`/`async` attributes.\n- Load recaptcha only on interaction (e.g., form focus).\n- Use `preconnect` for third-party domains (googleapis, gstatic).\n- Example: `<script src=\"...\" defer></script>`"},{"priority":1,"category":"Performance","title":"Fix Largest Contentful Paint (LCP) of 12.1 s","impact":"Core Web Vitals, Mobile Performance Score","problem":"LCP is 12.1 s on mobile (threshold is 2.5 s), caused by heavy media (15.6 MB video) and render-blocking resources.","solution":"- Preload the LCP image/video resource.\n- Convert video to adaptive streaming (HLS/DASH) or lazy-load below the fold.\n- Defer non-critical JavaScript to reduce main thread blocking."},{"priority":1,"category":"Accessibility","title":"Resolve Critical Accessibility Violations","impact":"WCAG Compliance, Screen Reader Usability","problem":"axe-core found 2 critical violations: buttons without discernible text (`.search-submit`) and images missing alt attributes (`.newsIntro__line--2`).","solution":"- Add `aria-label` or visible text to all buttons.\n- Ensure every `<img>` has a descriptive `alt` attribute.\n- Fix color contrast issues on menu links (`#menu-item-5479 > a`)."},{"priority":1,"category":"Security","title":"Harden Content Security Policy (CSP) and HSTS","impact":"XSS Protection, Transport Security","problem":"CSP allows `unsafe-inline` and `unsafe-eval` (high risk for UGC sites); HSTS missing `includeSubDomains` and `preload`. Site signals indicate User-Generated Content.","solution":"- Remove `unsafe-inline` and `unsafe-eval` from CSP; use nonces/hashes for scripts.\n- Update HSTS: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`.\n- Add `Referrer-Policy: strict-origin-when-cross-origin`."},{"priority":1,"category":"Performance","title":"Reduce media weight and fix LCP","impact":"LCP, Page Weight, Mobile Performance","problem":"Mobile LCP is 9.3 s and total page weight is 17.4 MB (15.6 MB media), causing severe load delays on mobile networks.","solution":"- Compress or lazy-load the 15.6 MB media assets (likely video splash).\n- Use `fetchpriority=\"high\"` on the LCP image.\n- Serve WebP/AVIF formats and implement responsive `srcset`."},{"priority":1,"category":"Accessibility","title":"Fix critical axe-core violations","impact":"WCAG 2.1 Compliance, Screen Reader Usability","problem":"2 critical violations found: missing `alt` attributes on images and buttons without discernible text (`.search-submit`, `.col-tp-none`).","solution":"- Add descriptive `alt` text to all content images.\n- Add `aria-label` or visible text to icon buttons.\n- Ensure form inputs have associated `<label>` elements."},{"priority":1,"category":"Accessibility","title":"Fix critical axe violations","impact":"WCAG 2.1 A/AA Compliance","problem":"2 critical violations: `button-name` (search-submit, col-tp-none) and `image-alt` (2 images missing alt).","solution":"- Add `aria-label` or visible text to `.search-submit` and `.col-tp-none` buttons.\n- Add descriptive `alt` text to all content images; use `alt=\"\"` for decorative SVGs.\n- Ensure form inputs have associated `<label>` elements."},{"priority":1,"category":"Security","title":"Harden CSP and HSTS headers","impact":"XSS Defense, Transport Security","problem":"CSP allows `unsafe-inline` and `unsafe-eval` (high risk with UGC signal); HSTS missing `includeSubDomains` and `preload`.","solution":"- Remove `'unsafe-inline'` and `'unsafe-eval'` from CSP; use nonces/hashes for scripts.\n- Update HSTS: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`.\n- Add `X-Content-Type-Options: nosniff` (present) and `Referrer-Policy: strict-origin-when-cross-origin`."},{"priority":1,"category":"Performance","title":"Reduce Largest Contentful Paint (LCP) from 10.0 s","impact":"LCP, FCP, Mobile Performance Score","problem":"LCP is 10.0 s on mobile (target ≤2.5 s) due to 15.6 MB media weight and render-blocking scripts.","solution":"- Compress or lazy-load the 15.6 MB video asset; use a poster image for the hero.\n- Add `fetchpriority=\"high\"` to the LCP image.\n- Defer non-critical JavaScript to reduce main thread blocking."},{"priority":1,"category":"Security","title":"Harden Content Security Policy (CSP) for User-Generated Content","impact":"XSS Protection, Security Headers Grade","problem":"CSP allows `unsafe-inline` and `unsafe-eval`, negating XSS protection. Site signals indicate user-generated content exists.","solution":"- Remove `'unsafe-inline'` and `'unsafe-eval'` from `script-src`.\n- Implement nonce-based CSP for inline scripts.\n- Ensure `connect-src` allows only necessary third-party domains (currently blocking `hello.myfonts.net`)."},{"priority":1,"category":"Accessibility","title":"Fix Critical Axe Violations (Buttons & Images)","impact":"WCAG 2.1 A Compliance, Screen Reader Support","problem":"2 critical violations: buttons lack accessible names (`.search-submit`) and images lack `alt` attributes.","solution":"- Add `aria-label` or visible text to `.search-submit` button.\n- Add descriptive `alt` text to all content images; use `alt=\"\"` for decorative SVGs.\n- Ensure form inputs have associated `<label>` elements."},{"priority":1,"category":"Performance","title":"Reduce media asset weight (15.6 MB)","impact":"LCP, FCP, Page Weight","problem":"Browser Runtime shows 15.61 MB of media (likely a background video) causing LCP to hit 10.9 s on mobile.","solution":"Replace the heavy video with a compressed WebM/MP4 (<5 MB) or a static poster image. If video is essential, use `preload=\"none\"` and lazy-load it after interaction."},{"priority":1,"category":"Accessibility","title":"Fix critical axe violations (buttons, images)","impact":"WCAG 2.1 A Compliance","problem":"axe-core reports 2 critical violations: buttons lack discernible text (`.search-submit`) and images lack alt text (`.newsIntro__line--2`).","solution":"- Add `aria-label` or visible text to `.search-submit`.\n- Add descriptive `alt` text to all content images. Decorative images should use `alt=\"\"`."},{"priority":2,"category":"Performance","title":"Defer render-blocking scripts","impact":"FCP, TBT","problem":"11 render-blocking scripts in `<head>` contribute to FCP 3.07 s and TBT 318 ms.","solution":"- Add `defer` or `async` to non-critical scripts (analytics, GTM, cookie consent).\n- Move jQuery and theme JS to the footer or load after LCP."},{"priority":2,"category":"Security","title":"Strengthen HSTS and add missing headers","impact":"Transport Security, Clickjacking","problem":"HSTS missing `includeSubDomains` and `preload`; Referrer-Policy and COOP missing.","solution":"- Update HSTS: `max-age=31536000; includeSubDomains; preload`.\n- Add `Referrer-Policy: strict-origin-when-cross-origin`.\n- Add `Permissions-Policy` to disable unused features."},{"priority":2,"category":"Performance","title":"Defer Render-Blocking JavaScript","impact":"TBT, FCP, Main Thread Blocking","problem":"18 render-blocking scripts found; 4 in `<head>` flagged by checklist. TBT is 570 ms.","solution":"- Add `defer` or `async` to non-critical scripts.\n- Move analytics and tracking scripts to the footer.\n- Inline critical CSS and defer non-critical CSS."},{"priority":2,"category":"Security","title":"Harden CSP and complete security headers","impact":"XSS protection, transport security","problem":"CSP allows `unsafe-inline` and `unsafe-eval`; HSTS missing `includeSubDomains` and `preload`.","solution":"- Remove `'unsafe-inline'` and `'unsafe-eval'` from CSP; use nonces for scripts.\n- Update HSTS to: `max-age=31536000; includeSubDomains; preload`.\n- Add `Referrer-Policy: strict-origin-when-cross-origin`."},{"priority":2,"category":"SEO","title":"Add H1 and fix HTML validation errors","impact":"Document outline, search ranking","problem":"Page has 0 `<h1>` elements and 8 W3C errors (duplicate IDs, bad attributes).","solution":"- Add a single `<h1>` describing the page content (e.g., 'Uudised').\n- Fix duplicate ID `select-kapitaliturud`.\n- Correct invalid attributes (e.g., `stylr` -> `style`, `pause` on video)."},{"priority":2,"category":"Security","title":"Strengthen HSTS and fix CSP console errors","impact":"Transport security, XSS defense","problem":"HSTS missing `includeSubDomains` and `preload`; CSP blocks `hello.myfonts.net` causing console errors.","solution":"- Update HSTS header: `Strict-Transport-Security: max-age=31536000; includeSubDomains; preload`\n- Add `https://hello.myfonts.net` to `connect-src` in CSP if required, or remove the font counting script."},{"priority":2,"category":"SEO","title":"Add H1 tag and main landmark","impact":"SEO ranking, Screen Reader navigation","problem":"W3C reports 0 h1 elements; HTML Inventory shows missing `<main>` landmark.","solution":"- Ensure exactly one `<h1>` exists per page (e.g., `<h1>Ziņas</h1>`).\n- Wrap primary content in `<main role=\"main\">`.\n- Add a skip-link at the top: `<a href=\"#main\" class=\"skip-link\">Iet uz saturu</a>`."},{"priority":2,"category":"Security","title":"Strengthen HSTS and baseline headers","impact":"Transport security, clickjacking protection","problem":"HSTS is missing `includeSubDomains` and `preload` directives; X-Frame-Options and X-Content-Type-Options are present but HSTS is weak.","solution":"- Update HSTS header: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`\n- Ensure `X-Frame-Options: SAMEORIGIN` remains active.\n- Remove `Server` header disclosure (Apache/ZoneOS)."},{"priority":2,"category":"Performance","title":"Eliminate Render-Blocking JavaScript","impact":"FCP, TBT, Time to Interactive","problem":"16 render-blocking scripts detected in `<head>`, including jQuery and analytics trackers, delaying first paint.","solution":"- Add `defer` or `async` to all non-critical scripts.\n- Move scripts to the end of `<body>` where possible.\n- Inline critical CSS and defer non-critical stylesheets."},{"priority":2,"category":"Security","title":"Complete HSTS configuration","impact":"Transport Security, Man-in-the-Middle Protection","problem":"HSTS header is present but missing `includeSubDomains` and `preload` directives, reducing protection scope.","solution":"- Update header to: `Strict-Transport-Security: max-age=31536000; includeSubDomains; preload`.\n- Submit domain to hstspreload.org after testing."},{"priority":2,"category":"SEO","title":"Fix HTML validation errors and meta data","impact":"Search Indexing, Rendering Reliability","problem":"W3C reports 20 errors including unknown `o_p` elements and nesting issues; missing meta description.","solution":"- Remove or fix the `o_p` custom element (likely plugin artifact).\n- Add `<meta name=\"description\" content=\"...\">`.\n- Ensure `<main>` landmark exists and heading hierarchy is logical."},{"priority":2,"category":"SEO","title":"Add Meta Description and Fix W3C Errors","impact":"Search Snippets, HTML Validity","problem":"Missing meta description; 6 W3C errors including nesting violations and illegal characters in URLs.","solution":"- Add `<meta name=\"description\" content=\"...\">` summarizing the article.\n- Fix `<a>` href spaces (encode as `%20`).\n- Close unclosed `<a>` tags to resolve nesting errors."},{"priority":3,"category":"SEO","title":"Fix HTML validation errors","impact":"Crawlability, Rendering","problem":"W3C reports 16 errors including parser recovery failure at line 407 and empty `href` attributes.","solution":"- Fix nested `<a>` tags causing parser recovery failure.\n- Remove empty `href` attributes on `<link>` elements.\n- Ensure all `<section>` elements have headings."},{"priority":3,"category":"Performance","title":"Resolve failed resource requests","impact":"Page load stability","problem":"Console shows failed requests for `splash.webm`, recaptcha, and analytics.","solution":"- Verify `splash.webm` path and availability.\n- Ensure recaptcha keys are valid and not blocked by CSP.\n- Check analytics endpoints for CORS or network issues."},{"priority":3,"category":"Security","title":"Harden Content Security Policy (CSP)","impact":"XSS mitigation","problem":"CSP allows `unsafe-inline` and `unsafe-eval`, which bypasses XSS protection.","solution":"Since this is a brochure site (no auth/payments), prioritize P1/P2 first. When ready, migrate to nonce-based CSP:\n```http\nContent-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic';\n```\nRemove `unsafe-inline` from `script-src`."},{"priority":3,"category":"SEO","title":"Add Meta Description and Fix HTML Validation","impact":"Search Snippets, Code Quality","problem":"Meta description is missing; W3C validator reports 5 errors including illegal characters in href and nesting violations.","solution":"- Add a unique `<meta name=\"description\">` tag (150–160 chars).\n- Fix W3C errors: remove spaces in query strings, ensure proper `<a>` nesting, and add missing `alt` attributes."},{"priority":3,"category":"SEO","title":"Add meta description and fix HTML errors","impact":"Search Snippets, Validation","problem":"Meta description is missing; W3C validator reports 5 errors including illegal characters in href and nesting violations.","solution":"- Write a unique meta description (150–160 chars) for the press release.\n- Fix W3C errors: remove spaces in query strings, close tags properly, and ensure `alt` attributes are present."}],"coverage":{"pct":100,"missing":[]},"siteSummary":{"pagesAudited":10,"pagesAttempted":10,"urls":["https://www.sorainen.com/et","https://www.sorainen.com/newsroom","https://www.sorainen.com/et/uudised","https://www.sorainen.com/lv/zinas","https://www.sorainen.com/lt/naujienos","https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus","https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen","https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards","https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year","https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys"]},"psiSnapshot":{"rows":[{"pageUrl":"https://www.sorainen.com/et","perfMobile":57,"perfDesktop":78,"lcpMobileMs":10473.10393803466,"lcpDesktopMs":1964.3909749160218,"clsMobile":0,"clsDesktop":0.006810036342928977},{"pageUrl":"https://www.sorainen.com/newsroom","perfMobile":52,"perfDesktop":82,"lcpMobileMs":11561.518978978918,"lcpDesktopMs":1025.9292598254615,"clsMobile":0,"clsDesktop":0.0004065613357436601},{"pageUrl":"https://www.sorainen.com/et/uudised","perfMobile":59,"perfDesktop":68,"lcpMobileMs":4880.404770271787,"lcpDesktopMs":1173.454420380744,"clsMobile":0,"clsDesktop":0.000454270243790409},{"pageUrl":"https://www.sorainen.com/lv/zinas","perfMobile":60,"perfDesktop":91,"lcpMobileMs":3943.517947463749,"lcpDesktopMs":1067.4195845706906,"clsMobile":0,"clsDesktop":0.0005279003777103866},{"pageUrl":"https://www.sorainen.com/lt/naujienos","perfMobile":65,"perfDesktop":75,"lcpMobileMs":3969.88033057647,"lcpDesktopMs":1033.0681868714046,"clsMobile":0,"clsDesktop":0.004208795902086294},{"pageUrl":"https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus","perfMobile":67,"perfDesktop":98,"lcpMobileMs":12060.136594042611,"lcpDesktopMs":871.6158925738,"clsMobile":0.004479044021099038,"clsDesktop":0.002750361951934932},{"pageUrl":"https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen","perfMobile":42,"perfDesktop":97,"lcpMobileMs":9311.055845944333,"lcpDesktopMs":920.9851682269232,"clsMobile":0,"clsDesktop":0.0006175779707591186},{"pageUrl":"https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards","perfMobile":61,"perfDesktop":60,"lcpMobileMs":12146.265220983576,"lcpDesktopMs":1777.8176445508443,"clsMobile":0.0009144714876410535,"clsDesktop":0.003007858632363383},{"pageUrl":"https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year","perfMobile":46,"perfDesktop":89,"lcpMobileMs":10025.028472567377,"lcpDesktopMs":1190.2419177216138,"clsMobile":0.03642955803827218,"clsDesktop":0.0019493344516461767},{"pageUrl":"https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys","perfMobile":53,"perfDesktop":58,"lcpMobileMs":10929.537760599893,"lcpDesktopMs":2166.6806664669675,"clsMobile":0,"clsDesktop":0.0001901657860736475}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket)","evidence":["HTML markers: WP Rocket","generator: WPML ver:4.9.6 stt:1,15,32,33;"]},{"id":"lazyload","title":"Images lazy-loaded","status":"n/a","detail":"No raster <img> elements found (4 SVGs excluded).","evidence":[]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"warn","detail":"Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority=\"high\" helps LCP.","evidence":["hero: …nen.com/UserFiles/content%20images/thumbs/__thumb_-2-Darius%20Raulusaitis.jpg","loading: (not set)","fetchpriority: (not set)"]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"warn","detail":"Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.","evidence":["selector: div.expertiseIntro__img.bg-cover","url: …sorainen.com/wp-content/uploads/2026/05/eva-berlaus-sorainen-2026-500x738.jpg","box: 419×624px"]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"n/a","detail":"Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply.","evidence":[]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"n/a","detail":"Too few raster images to evaluate srcset width variety.","evidence":[]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"fail","detail":"4 render-blocking scripts in <head>. Move to footer or add defer/async.","evidence":["…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5","https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1","…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2","https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js"]}],"summary":{"passed":1,"warned":2,"failed":1,"notApplicable":3},"priorities":[{"title":"JS scripts not blocking in <head>","severity":"high","detail":"4 render-blocking scripts in <head>. Move to footer or add defer/async."},{"title":"Hero is a real <img> (not a CSS background-image)","severity":"medium","detail":"Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file."},{"title":"Hero image eagerly loaded","severity":"medium","detail":"Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority=\"high\" helps LCP."}]},"perPageOverall":[{"url":"https://www.sorainen.com/et","overall":58,"reasoning":"Mobile performance is critically low (57/100) with an LCP of 10.5 s driven by 18.45 MB of page weight, primarily media. Accessibility has critical failures (12 missing alt attributes, unlabeled buttons) despite a 77/100 score. Security headers are weak (Grade 40) with unsafe CSP directives, though no auth/payment risk exists. Desktop performance is significantly better (78/100), but mobile-first indexing penalizes the mobile experience heavily.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Reduce media weight and optimize LCP","impact":"LCP, FCP, Page Weight","problem":"LCP is 10.5 s on mobile; total page weight is 18.45 MB with 15.61 MB in media (likely video).","solution":"- Replace the 15.6 MB video asset with a lightweight poster image or compressed WebM.\n- Implement lazy loading for all non-critical media.\n- Use `fetchpriority=\"high\"` only on the actual LCP element."},{"priority":1,"category":"Accessibility","title":"Add alt text to all images and label buttons","impact":"WCAG 1.1.1, 4.1.2","problem":"12 images lack `alt` attributes; 4 buttons (search, close) lack discernible text (axe critical violations).","solution":"- Add descriptive `alt` text to content images; use `alt=\"\"` for decorative SVGs.\n- Add `aria-label` or visible text to `.search-submit`, `.close`, and `.submit` buttons."},{"priority":1,"category":"Security","title":"Harden Content Security Policy (CSP)","impact":"XSS Defense","problem":"CSP allows `unsafe-inline` and `unsafe-eval` scripts; UGC signal is yes, increasing XSS risk.","solution":"- Remove `'unsafe-inline'` and `'unsafe-eval'` from `script-src`.\n- Implement nonce-based CSP for third-party scripts (GTM, Recaptcha).\n- Ensure `connect-src` allows font counting endpoints (hello.myfonts.net)."},{"priority":2,"category":"Performance","title":"Defer render-blocking scripts","impact":"FCP, TBT","problem":"11 render-blocking scripts in `<head>` contribute to FCP 3.07 s and TBT 318 ms.","solution":"- Add `defer` or `async` to non-critical scripts (analytics, GTM, cookie consent).\n- Move jQuery and theme JS to the footer or load after LCP."},{"priority":2,"category":"Security","title":"Strengthen HSTS and add missing headers","impact":"Transport Security, Clickjacking","problem":"HSTS missing `includeSubDomains` and `preload`; Referrer-Policy and COOP missing.","solution":"- Update HSTS: `max-age=31536000; includeSubDomains; preload`.\n- Add `Referrer-Policy: strict-origin-when-cross-origin`.\n- Add `Permissions-Policy` to disable unused features."},{"priority":3,"category":"SEO","title":"Fix HTML validation errors","impact":"Crawlability, Rendering","problem":"W3C reports 16 errors including parser recovery failure at line 407 and empty `href` attributes.","solution":"- Fix nested `<a>` tags causing parser recovery failure.\n- Remove empty `href` attributes on `<link>` elements.\n- Ensure all `<section>` elements have headings."}],"perfScore":57,"a11yScore":77,"bestPracticesScore":92,"seoScore":92,"securityScore":40},{"url":"https://www.sorainen.com/newsroom","overall":48,"reasoning":"Mobile performance 52 is dragged down by a catastrophic LCP of 11.6 s and 17.4 MB page weight. Accessibility is compromised by 9 violations including 3 critical button/label issues. Security headers are weak (Grade 40) with CSP allowing unsafe-inline on a site with user-generated content. SEO structure fails due to 0 h1 elements and 10 W3C validation errors. Desktop performance (82) is significantly better than mobile, highlighting mobile-specific bottlenecks.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Reduce Page Weight and Fix LCP","impact":"LCP, FCP, Speed Index, Mobile Score","problem":"LCP is 11.6 s on mobile; total page weight is 17.42 MB (15.61 MB media). Video splash asset failed to load (ERR_ABORTED).","solution":"- Compress or lazy-load the hero video; ensure fallback image loads first.\n- Implement responsive images (`srcset`) for raster assets.\n- Preload critical LCP image if it is an `<img>`.\n- Audit third-party scripts (recaptcha, gtag) for necessity."},{"priority":1,"category":"Accessibility","title":"Fix Critical Button and Label Violations","impact":"WCAG 2.1 Level A Compliance","problem":"3 critical axe violations: 5 buttons lack discernible text, search/select forms lack labels.","solution":"- Add `aria-label` or visible text to all buttons (e.g., `.search-submit`).\n- Associate `<label>` elements with all form inputs (`for`/`id` matching).\n- Ensure all interactive elements have accessible names."},{"priority":1,"category":"SEO","title":"Add a Single H1 Element","impact":"Document Outline, Search Ranking","problem":"HTML Inventory shows 0 h1 elements; page starts with h2. W3C warns no h1.","solution":"- Ensure exactly one `<h1>` exists per page, typically matching the `<title>` or main heading.\n- Example: `<h1>Newsroom</h1>` at the top of the main content area."},{"priority":1,"category":"Security","title":"Harden Content Security Policy (CSP)","impact":"XSS Protection (Critical for UGC)","problem":"Site has User-Generated Content (newsroom posts). Current CSP allows `unsafe-inline` and `unsafe-eval`, negating XSS protection.","solution":"- Remove `'unsafe-inline'` and `'unsafe-eval'` from `script-src`.\n- Implement nonces or hashes for allowed inline scripts.\n- Use `'strict-dynamic'` to allow trusted third-party scripts without a whitelist."},{"priority":2,"category":"Performance","title":"Defer Render-Blocking JavaScript","impact":"TBT, FCP, Main Thread Blocking","problem":"18 render-blocking scripts found; 4 in `<head>` flagged by checklist. TBT is 570 ms.","solution":"- Add `defer` or `async` to non-critical scripts.\n- Move analytics and tracking scripts to the footer.\n- Inline critical CSS and defer non-critical CSS."}],"perfScore":52,"a11yScore":85,"bestPracticesScore":92,"seoScore":85,"securityScore":40},{"url":"https://www.sorainen.com/et/uudised","overall":68,"reasoning":"Mobile performance is 59/100 with LCP at 4.9 s, driven by 15.6 MB media weight and 18 render-blocking scripts. Accessibility has 9 violations including 3 critical (missing form labels, button names) and lacks an `<h1>` or `<main>` landmark. Security headers are weak (CSP allows `unsafe-inline`, HSTS missing `includeSubDomains`), though HTTPS is present. HTML validation shows 8 errors including duplicate IDs and invalid attributes. Desktop performance is better (68) but mobile-first indexing penalizes the mobile experience.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Reduce LCP and render-blocking resources","impact":"LCP, FCP, TBT","problem":"LCP is 4.9 s (threshold 2.5 s) with 15.6 MB media weight and 18 render-blocking scripts in the head.","solution":"- Optimize the 15.6 MB video asset (compress, use modern codecs, lazy load if not above fold).\n- Add `defer` or `async` to non-critical scripts (e.g., GTM, Facebook Pixel).\n- Inline critical CSS and move non-critical stylesheets to the footer."},{"priority":1,"category":"Accessibility","title":"Fix critical form and button accessibility issues","impact":"WCAG 2.1 A/AA compliance","problem":"3 critical violations: buttons lack discernible text, search form lacks labels, select elements lack names.","solution":"- Add `aria-label` or visible text to all icon buttons (e.g., search submit).\n- Associate `<label>` elements with all form inputs using `for` and `id`.\n- Ensure all `<select>` elements have an associated label or `aria-label`."},{"priority":2,"category":"Security","title":"Harden CSP and complete security headers","impact":"XSS protection, transport security","problem":"CSP allows `unsafe-inline` and `unsafe-eval`; HSTS missing `includeSubDomains` and `preload`.","solution":"- Remove `'unsafe-inline'` and `'unsafe-eval'` from CSP; use nonces for scripts.\n- Update HSTS to: `max-age=31536000; includeSubDomains; preload`.\n- Add `Referrer-Policy: strict-origin-when-cross-origin`."},{"priority":2,"category":"SEO","title":"Add H1 and fix HTML validation errors","impact":"Document outline, search ranking","problem":"Page has 0 `<h1>` elements and 8 W3C errors (duplicate IDs, bad attributes).","solution":"- Add a single `<h1>` describing the page content (e.g., 'Uudised').\n- Fix duplicate ID `select-kapitaliturud`.\n- Correct invalid attributes (e.g., `stylr` -> `style`, `pause` on video)."},{"priority":3,"category":"Performance","title":"Resolve failed resource requests","impact":"Page load stability","problem":"Console shows failed requests for `splash.webm`, recaptcha, and analytics.","solution":"- Verify `splash.webm` path and availability.\n- Ensure recaptcha keys are valid and not blocked by CSP.\n- Check analytics endpoints for CORS or network issues."}],"perfScore":59,"a11yScore":85,"bestPracticesScore":92,"seoScore":92,"securityScore":40},{"url":"https://www.sorainen.com/lv/zinas","overall":58,"reasoning":"Mobile PSI score of 60 with LCP 3.9s and TBT 728ms incurs heavy performance penalties, dragging the overall quality down despite a strong Desktop score of 91. Accessibility is compromised by 3 critical violations (buttons, labels, selects) and 11 W3C errors including a missing <h1>. Security headers grade 40/100 reflects weak HSTS and permissive CSP, though the lack of auth/payments signals lowers CSP priority. The site functions but requires significant mobile optimization and structural fixes to meet modern standards.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Defer non-critical JavaScript to reduce TBT","impact":"TBT, FCP, LCP","problem":"TBT is 728 ms (>600 ms heavy penalty) and LCP is 3.9 s due to 18 render-blocking scripts and unused JS (recaptcha, gtag).","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Specifically target:\n- `gtag.js`\n- `gtm.js`\n- `recaptcha__en.js`\n- `facebook_signal.js`\n\nExample:\n```html\n<script src=\"/js/main.js\" defer></script>\n```"},{"priority":1,"category":"Accessibility","title":"Fix critical form and button accessibility issues","impact":"WCAG 2.1 A/AA compliance","problem":"3 critical axe violations: buttons lack discernible text, form inputs (search, selects) lack labels.","solution":"- Add `aria-label` or visible text to filter buttons (e.g., `#alm-filter-1`).\n- Associate `<label>` elements with search/select inputs using `for` and `id`.\n- Ensure all `<select>` elements have visible labels or `aria-label`."},{"priority":2,"category":"Security","title":"Strengthen HSTS and fix CSP console errors","impact":"Transport security, XSS defense","problem":"HSTS missing `includeSubDomains` and `preload`; CSP blocks `hello.myfonts.net` causing console errors.","solution":"- Update HSTS header: `Strict-Transport-Security: max-age=31536000; includeSubDomains; preload`\n- Add `https://hello.myfonts.net` to `connect-src` in CSP if required, or remove the font counting script."},{"priority":2,"category":"SEO","title":"Add H1 tag and main landmark","impact":"SEO ranking, Screen Reader navigation","problem":"W3C reports 0 h1 elements; HTML Inventory shows missing `<main>` landmark.","solution":"- Ensure exactly one `<h1>` exists per page (e.g., `<h1>Ziņas</h1>`).\n- Wrap primary content in `<main role=\"main\">`.\n- Add a skip-link at the top: `<a href=\"#main\" class=\"skip-link\">Iet uz saturu</a>`."},{"priority":3,"category":"Security","title":"Harden Content Security Policy (CSP)","impact":"XSS mitigation","problem":"CSP allows `unsafe-inline` and `unsafe-eval`, which bypasses XSS protection.","solution":"Since this is a brochure site (no auth/payments), prioritize P1/P2 first. When ready, migrate to nonce-based CSP:\n```http\nContent-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic';\n```\nRemove `unsafe-inline` from `script-src`."}],"perfScore":60,"a11yScore":85,"bestPracticesScore":92,"seoScore":92,"securityScore":40},{"url":"https://www.sorainen.com/lt/naujienos","overall":58,"reasoning":"Mobile performance is poor (65/100) with LCP at 4.0 s and FCP at 3.07 s, driven by 18 render-blocking scripts and heavy third-party JS (recaptcha, gtag). Accessibility is critical with 3 critical violations (buttons, form labels) blocking screen reader users. SEO structure is broken with 0 <h1> elements and 12 W3C validation errors. Security headers are weak (Grade 40/100) with HSTS missing includeSubDomains and CSP allowing unsafe-inline. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Accessibility","title":"Fix critical form and button accessibility issues","impact":"WCAG 2.1 A compliance, screen reader usability","problem":"3 critical axe violations: buttons without discernible text (.search-submit, .alm-filter buttons) and form elements missing labels (search, select).","solution":"- Add `aria-label` or visible text to all buttons (e.g., `<button aria-label=\"Search\">`).\n- Associate labels with inputs using `for`/`id` or wrap inputs in `<label>`.\n- Ensure `<select>` elements have visible labels or `aria-label`."},{"priority":1,"category":"Performance","title":"Defer non-critical third-party scripts","impact":"LCP, FCP, TBT (590 ms)","problem":"18 render-blocking scripts and heavy JS (recaptcha, gtag, facebook-pixel) cause LCP 4.0 s and FCP 3.07 s on mobile.","solution":"- Move non-critical scripts to footer or add `defer`/`async` attributes.\n- Load recaptcha only on interaction (e.g., form focus).\n- Use `preconnect` for third-party domains (googleapis, gstatic).\n- Example: `<script src=\"...\" defer></script>`"},{"priority":2,"category":"Security","title":"Strengthen HSTS and baseline headers","impact":"Transport security, clickjacking protection","problem":"HSTS is missing `includeSubDomains` and `preload` directives; X-Frame-Options and X-Content-Type-Options are present but HSTS is weak.","solution":"- Update HSTS header: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`\n- Ensure `X-Frame-Options: SAMEORIGIN` remains active.\n- Remove `Server` header disclosure (Apache/ZoneOS)."},{"priority":2,"category":"SEO","title":"Add H1 and fix HTML validation errors","impact":"Search ranking, document outline, rendering stability","problem":"0 <h1> elements found; 12 W3C errors including duplicate IDs and invalid attributes (`stylr`, `pause` on video).","solution":"- Add exactly one `<h1>` describing the page topic (e.g., \"Naujienos\").\n- Fix duplicate IDs (e.g., `select-finansai-ir-draudimas`).\n- Remove invalid attributes (`stylr`, `pause` on `<video>`).\n- Ensure `<main>` landmark exists."},{"priority":3,"category":"Security","title":"Harden Content Security Policy (CSP)","impact":"XSS defense-in-depth","problem":"CSP allows `unsafe-inline` and `unsafe-eval`, which bypasses XSS protections. Site signals show no auth/payments, lowering immediate risk.","solution":"- Migrate to nonce-based CSP: `script-src 'nonce-{random}' 'strict-dynamic'`.\n- Remove `unsafe-inline` and `unsafe-eval` from `script-src`.\n- Add `hello.myfonts.net` to `connect-src` to fix console CSP violations."}],"perfScore":65,"a11yScore":85,"bestPracticesScore":92,"seoScore":92,"securityScore":40},{"url":"https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus","overall":56,"reasoning":"Mobile performance is critically low (PSI 67) driven by a 12.1 s LCP and 16 render-blocking scripts, despite a strong desktop score (98). Accessibility is compromised by 7 axe violations including 2 critical issues (button-name, image-alt). Security headers are weak (40/100) with a permissive CSP and incomplete HSTS, which is elevated to Priority 1 due to the inferred User-Generated Content signal. W3C validation shows 5 errors indicating code quality issues. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Fix Largest Contentful Paint (LCP) of 12.1 s","impact":"Core Web Vitals, Mobile Performance Score","problem":"LCP is 12.1 s on mobile (threshold is 2.5 s), caused by heavy media (15.6 MB video) and render-blocking resources.","solution":"- Preload the LCP image/video resource.\n- Convert video to adaptive streaming (HLS/DASH) or lazy-load below the fold.\n- Defer non-critical JavaScript to reduce main thread blocking."},{"priority":1,"category":"Accessibility","title":"Resolve Critical Accessibility Violations","impact":"WCAG Compliance, Screen Reader Usability","problem":"axe-core found 2 critical violations: buttons without discernible text (`.search-submit`) and images missing alt attributes (`.newsIntro__line--2`).","solution":"- Add `aria-label` or visible text to all buttons.\n- Ensure every `<img>` has a descriptive `alt` attribute.\n- Fix color contrast issues on menu links (`#menu-item-5479 > a`)."},{"priority":1,"category":"Security","title":"Harden Content Security Policy (CSP) and HSTS","impact":"XSS Protection, Transport Security","problem":"CSP allows `unsafe-inline` and `unsafe-eval` (high risk for UGC sites); HSTS missing `includeSubDomains` and `preload`. Site signals indicate User-Generated Content.","solution":"- Remove `unsafe-inline` and `unsafe-eval` from CSP; use nonces/hashes for scripts.\n- Update HSTS: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`.\n- Add `Referrer-Policy: strict-origin-when-cross-origin`."},{"priority":2,"category":"Performance","title":"Eliminate Render-Blocking JavaScript","impact":"FCP, TBT, Time to Interactive","problem":"16 render-blocking scripts detected in `<head>`, including jQuery and analytics trackers, delaying first paint.","solution":"- Add `defer` or `async` to all non-critical scripts.\n- Move scripts to the end of `<body>` where possible.\n- Inline critical CSS and defer non-critical stylesheets."},{"priority":3,"category":"SEO","title":"Add Meta Description and Fix HTML Validation","impact":"Search Snippets, Code Quality","problem":"Meta description is missing; W3C validator reports 5 errors including illegal characters in href and nesting violations.","solution":"- Add a unique `<meta name=\"description\">` tag (150–160 chars).\n- Fix W3C errors: remove spaces in query strings, ensure proper `<a>` nesting, and add missing `alt` attributes."}],"perfScore":67,"a11yScore":81,"bestPracticesScore":92,"seoScore":77,"securityScore":40},{"url":"https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen","overall":38,"reasoning":"Mobile performance is critically low (42/100) with an LCP of 9.3 s and 15.6 MB of media weight, dragging the score into the 'Poor' band. Accessibility is broken with 7 violations including 2 critical issues (missing alt text, button names) that block WCAG compliance. Security headers are weak (40/100) with a CSP allowing unsafe-inline, which is high risk given the inferred user-generated content signal. Desktop performance (97) contrasts sharply with mobile (42), indicating mobile-specific bottlenecks like render-blocking scripts and unoptimized media.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Reduce media weight and fix LCP","impact":"LCP, Page Weight, Mobile Performance","problem":"Mobile LCP is 9.3 s and total page weight is 17.4 MB (15.6 MB media), causing severe load delays on mobile networks.","solution":"- Compress or lazy-load the 15.6 MB media assets (likely video splash).\n- Use `fetchpriority=\"high\"` on the LCP image.\n- Serve WebP/AVIF formats and implement responsive `srcset`."},{"priority":1,"category":"Accessibility","title":"Fix critical axe-core violations","impact":"WCAG 2.1 Compliance, Screen Reader Usability","problem":"2 critical violations found: missing `alt` attributes on images and buttons without discernible text (`.search-submit`, `.col-tp-none`).","solution":"- Add descriptive `alt` text to all content images.\n- Add `aria-label` or visible text to icon buttons.\n- Ensure form inputs have associated `<label>` elements."},{"priority":1,"category":"Security","title":"Harden Content Security Policy (CSP)","impact":"XSS Protection, Data Integrity","problem":"CSP allows `unsafe-inline` and `unsafe-eval`, negating XSS protection. Site signals indicate user-generated content (post anchor), elevating risk.","solution":"- Remove `'unsafe-inline'` and `'unsafe-eval'` from `script-src`.\n- Implement nonce-based CSP with `'strict-dynamic'`.\n- Whitelist only necessary third-party domains (e.g., Google Fonts, Analytics)."},{"priority":2,"category":"Performance","title":"Defer render-blocking JavaScript","impact":"FCP, TBT, Time to Interactive","problem":"16 render-blocking scripts detected in `<head>`, contributing to TBT of 1.3 s and FCP of 3.05 s.","solution":"- Add `defer` or `async` attributes to non-critical scripts.\n- Move analytics and tracking scripts to the footer.\n- Inline critical CSS and defer non-critical stylesheets."},{"priority":2,"category":"Security","title":"Complete HSTS configuration","impact":"Transport Security, Man-in-the-Middle Protection","problem":"HSTS header is present but missing `includeSubDomains` and `preload` directives, reducing protection scope.","solution":"- Update header to: `Strict-Transport-Security: max-age=31536000; includeSubDomains; preload`.\n- Submit domain to hstspreload.org after testing."},{"priority":3,"category":"SEO","title":"Add meta description and fix HTML errors","impact":"Search Snippets, Validation","problem":"Meta description is missing; W3C validator reports 5 errors including illegal characters in href and nesting violations.","solution":"- Write a unique meta description (150–160 chars) for the press release.\n- Fix W3C errors: remove spaces in query strings, close tags properly, and ensure `alt` attributes are present."}],"perfScore":42,"a11yScore":81,"bestPracticesScore":69,"seoScore":77,"securityScore":40},{"url":"https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards","overall":52,"reasoning":"Mobile performance is critically low (61) driven by a 12.1s LCP and 17.4 MB page weight dominated by media. Accessibility is compromised by 2 critical violations (missing alt, button names) and contrast issues. Security headers are weak (40/100) with a permissive CSP that allows unsafe-inline despite user-generated content signals. HTML validation shows 20 errors including unknown elements, indicating template corruption. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Reduce media weight and fix LCP","impact":"LCP, Page Weight, Core Web Vitals","problem":"LCP is 12.1 s (threshold 2.5 s) and total page weight is 17.4 MB with 15.6 MB from media assets.","solution":"- Compress and resize images/video; serve WebP/AVIF.\n- Use `fetchpriority=\"high\"` on the LCP image.\n- Implement lazy loading for below-the-fold media.\n- Remove or defer the 15.6 MB video asset if not essential."},{"priority":1,"category":"Accessibility","title":"Fix critical axe violations","impact":"WCAG 2.1 A/AA Compliance","problem":"2 critical violations: `button-name` (search-submit, col-tp-none) and `image-alt` (2 images missing alt).","solution":"- Add `aria-label` or visible text to `.search-submit` and `.col-tp-none` buttons.\n- Add descriptive `alt` text to all content images; use `alt=\"\"` for decorative SVGs.\n- Ensure form inputs have associated `<label>` elements."},{"priority":1,"category":"Security","title":"Harden CSP and HSTS headers","impact":"XSS Defense, Transport Security","problem":"CSP allows `unsafe-inline` and `unsafe-eval` (high risk with UGC signal); HSTS missing `includeSubDomains` and `preload`.","solution":"- Remove `'unsafe-inline'` and `'unsafe-eval'` from CSP; use nonces/hashes for scripts.\n- Update HSTS: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`.\n- Add `X-Content-Type-Options: nosniff` (present) and `Referrer-Policy: strict-origin-when-cross-origin`."},{"priority":2,"category":"Performance","title":"Defer render-blocking scripts","impact":"FCP, TBT, Time to Interactive","problem":"16 render-blocking external scripts found in <head>; 4 identified in Optimized-Web checklist.","solution":"- Add `defer` or `async` to non-critical scripts (analytics, tracking, widgets).\n- Move critical CSS inline and defer non-critical CSS.\n- Example: `<script src=\"analytics.js\" defer></script>`."},{"priority":2,"category":"SEO","title":"Fix HTML validation errors and meta data","impact":"Search Indexing, Rendering Reliability","problem":"W3C reports 20 errors including unknown `o_p` elements and nesting issues; missing meta description.","solution":"- Remove or fix the `o_p` custom element (likely plugin artifact).\n- Add `<meta name=\"description\" content=\"...\">`.\n- Ensure `<main>` landmark exists and heading hierarchy is logical."}],"perfScore":61,"a11yScore":78,"bestPracticesScore":88,"seoScore":77,"securityScore":40},{"url":"https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year","overall":48,"reasoning":"Mobile performance is critically low at 46/100 with an LCP of 10.0 s, driven by 15.6 MB media weight and render-blocking scripts. Accessibility has 7 violations including 2 critical issues on buttons and images. Security headers are weak (40/100) with a permissive CSP allowing unsafe-inline despite user-generated content signals. W3C validation shows 6 errors including parser recovery failure. Desktop performance is strong (89) but mobile-first indexing penalizes the mobile experience.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Reduce Largest Contentful Paint (LCP) from 10.0 s","impact":"LCP, FCP, Mobile Performance Score","problem":"LCP is 10.0 s on mobile (target ≤2.5 s) due to 15.6 MB media weight and render-blocking scripts.","solution":"- Compress or lazy-load the 15.6 MB video asset; use a poster image for the hero.\n- Add `fetchpriority=\"high\"` to the LCP image.\n- Defer non-critical JavaScript to reduce main thread blocking."},{"priority":1,"category":"Security","title":"Harden Content Security Policy (CSP) for User-Generated Content","impact":"XSS Protection, Security Headers Grade","problem":"CSP allows `unsafe-inline` and `unsafe-eval`, negating XSS protection. Site signals indicate user-generated content exists.","solution":"- Remove `'unsafe-inline'` and `'unsafe-eval'` from `script-src`.\n- Implement nonce-based CSP for inline scripts.\n- Ensure `connect-src` allows only necessary third-party domains (currently blocking `hello.myfonts.net`)."},{"priority":1,"category":"Accessibility","title":"Fix Critical Axe Violations (Buttons & Images)","impact":"WCAG 2.1 A Compliance, Screen Reader Support","problem":"2 critical violations: buttons lack accessible names (`.search-submit`) and images lack `alt` attributes.","solution":"- Add `aria-label` or visible text to `.search-submit` button.\n- Add descriptive `alt` text to all content images; use `alt=\"\"` for decorative SVGs.\n- Ensure form inputs have associated `<label>` elements."},{"priority":2,"category":"Performance","title":"Eliminate Render-Blocking JavaScript","impact":"FCP, TBT, Time to Interactive","problem":"16 render-blocking scripts detected; 4 in `<head>` causing 930 ms TBT.","solution":"- Add `defer` or `async` to non-critical scripts (e.g., analytics, GTM).\n- Move footer scripts to the bottom of the body.\n- Inline critical CSS and defer non-critical stylesheets."},{"priority":2,"category":"SEO","title":"Add Meta Description and Fix W3C Errors","impact":"Search Snippets, HTML Validity","problem":"Missing meta description; 6 W3C errors including nesting violations and illegal characters in URLs.","solution":"- Add `<meta name=\"description\" content=\"...\">` summarizing the article.\n- Fix `<a>` href spaces (encode as `%20`).\n- Close unclosed `<a>` tags to resolve nesting errors."}],"perfScore":46,"a11yScore":81,"bestPracticesScore":88,"seoScore":77,"securityScore":40},{"url":"https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys","overall":55,"reasoning":"Mobile performance is critically low (PSI 53) with an LCP of 10.9 s driven by a 15.6 MB media asset and 16 render-blocking scripts. Accessibility has 2 critical violations (button-name, image-alt) and 3 serious issues (contrast, labels). Security headers are weak (CSP allows unsafe-inline/eval) despite inferred user-generated content signals, creating XSS risk. W3C validation found 5 errors including nesting violations and missing alt attributes. The 17.39 MB total page weight is unsustainable for a news article.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Reduce media asset weight (15.6 MB)","impact":"LCP, FCP, Page Weight","problem":"Browser Runtime shows 15.61 MB of media (likely a background video) causing LCP to hit 10.9 s on mobile.","solution":"Replace the heavy video with a compressed WebM/MP4 (<5 MB) or a static poster image. If video is essential, use `preload=\"none\"` and lazy-load it after interaction."},{"priority":1,"category":"Security","title":"Harden Content Security Policy (CSP)","impact":"XSS Defense","problem":"CSP allows `unsafe-inline` and `unsafe-eval` scripts. Site signals indicate user-generated content potential, making this a high-risk XSS vector.","solution":"Remove `unsafe-inline` and `unsafe-eval`. Implement a nonce-based CSP:\n```http\nContent-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\n```\nUpdate all inline scripts to use the nonce."},{"priority":1,"category":"Accessibility","title":"Fix critical axe violations (buttons, images)","impact":"WCAG 2.1 A Compliance","problem":"axe-core reports 2 critical violations: buttons lack discernible text (`.search-submit`) and images lack alt text (`.newsIntro__line--2`).","solution":"- Add `aria-label` or visible text to `.search-submit`.\n- Add descriptive `alt` text to all content images. Decorative images should use `alt=\"\"`."},{"priority":2,"category":"Performance","title":"Defer render-blocking JavaScript","impact":"FCP, TBT, LCP","problem":"16 render-blocking scripts (jQuery, GTM, Facebook Pixel) delay first paint. Optimization Checklist flags 4 blocking scripts in `<head>`.","solution":"Add `defer` or `async` to non-critical scripts:\n```html\n<script src=\"...\" defer></script>\n```\nMove analytics and third-party tags to the bottom of `<body>` or use `type=\"module\"`."},{"priority":2,"category":"Security","title":"Strengthen HSTS and add missing headers","impact":"Transport Security, Clickjacking","problem":"HSTS is missing `includeSubDomains` and `preload`. Referrer-Policy, Permissions-Policy, and COOP are missing.","solution":"Update HSTS header:\n```http\nStrict-Transport-Security: max-age=63072000; includeSubDomains; preload\n```\nAdd:\n```http\nReferrer-Policy: strict-origin-when-cross-origin\nPermissions-Policy: geolocation=(), microphone=()\nCross-Origin-Opener-Policy: same-origin\n```"},{"priority":3,"category":"SEO","title":"Add meta description and fix HTML errors","impact":"Search Snippets, Validation","problem":"HTML Inventory shows no meta description. W3C found 5 errors including illegal characters in URLs and missing `alt` attributes.","solution":"- Add `<meta name=\"description\" content=\"...\">`.\n- Fix W3C errors: remove spaces in query strings, fix `<a>` nesting, ensure all `<img>` have `alt`."}],"perfScore":53,"a11yScore":81,"bestPracticesScore":92,"seoScore":77,"securityScore":40}]}