{"url":"https://www.sorainen.com/et/","date":"2026-08-24","siteName":"Advokaadibüroo Sorainen","overall":66,"reasoning":"Site overall 66 is the mean of 5 pages. Scores range 62 (https://www.sorainen.com/et) → 70 (https://www.sorainen.com/lv/zinas). Weakest page: Mobile performance is critically low (52) with an LCP of 10.2 s, driven by 15 render-blocking scripts and heavy third-party JS. Accessibility has critical gaps (12 missing alt attributes) despite a decent 88 score. Security is weak (40/100) with a permissive CSP on a site that hosts user content, elevating XSS risk. Desktop performance (96) is strong, but mobile-first indexing penalizes the mobile experience significantly.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Eliminate render-blocking JavaScript and optimize LCP","impact":"LCP (10.2 s), FCP (3.1 s), TBT (466 ms)","problem":"15 render-blocking scripts and heavy third-party JS (Recaptcha, GTM) delay rendering; LCP is 10.2 s on mobile.","solution":"- Move non-critical scripts to footer or add `defer`/`async`.\n- Defer Recaptcha until user interaction (e.g., form focus).\n- Convert hero CSS background to `<img>` with `fetchpriority=\"high\"` and `srcset`."},{"priority":1,"category":"Accessibility","title":"Add alt text to all content images","impact":"WCAG 1.1.1 (Non-text Content), SEO","problem":"12 images lack `alt` attributes (W3C + axe-core critical violations), blocking screen reader users.","solution":"- Audit all `<img>` tags.\n- Add descriptive `alt` text for content images.\n- Use `alt=\"\"` for purely decorative images (e.g., icons, lines)."},{"priority":1,"category":"Security","title":"Harden CSP and HSTS for User-Generated Content","impact":"XSS protection, Transport security","problem":"Site has user content (`hasUserContent: yes`) but CSP allows `unsafe-inline`/`unsafe-eval`; HSTS missing `includeSubDomains`.","solution":"- Remove `'unsafe-inline'` and `'unsafe-eval'` from CSP; use nonces/hashes for scripts.\n- Update HSTS: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`."},{"priority":1,"category":"Performance","title":"Defer non-critical JavaScript to fix LCP","impact":"LCP, FCP, TBT","problem":"LCP is 11.3 s on mobile; 17 render-blocking scripts and 1.08 MB of JS (reCAPTCHA, GTM) delay rendering.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Specifically defer `gtag.js`, `gtm.js`, and `recaptcha__en.js` until after `DOMContentLoaded`.\n```html\n<script src=\".../gtag.js\" async></script>\n<script src=\".../recaptcha__en.js\" defer></script>\n```"},{"priority":1,"category":"Accessibility","title":"Add accessible labels to forms and buttons","impact":"WCAG 2.1.1, 4.1.2","problem":"3 critical axe violations: buttons lack discernible text, form inputs (search, select) lack labels.","solution":"Associate `<label>` elements with inputs via `for`/`id`. Add `aria-label` to icon-only buttons.\n```html\n<label for=\"search-text\">Search</label>\n<input id=\"search-text\" ...>\n<button aria-label=\"Close modal\">X</button>\n```"},{"priority":1,"category":"Security","title":"Harden Content Security Policy (CSP)","impact":"XSS protection","problem":"Site has user-generated content signals, but CSP allows `unsafe-inline` and `unsafe-eval`, negating XSS defense.","solution":"Remove `unsafe-inline` and `unsafe-eval` from `script-src`. Use nonces or hashes for inline scripts.\n```http\nContent-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic';\n```"},{"priority":1,"category":"Performance","title":"Defer render-blocking scripts to improve LCP","impact":"LCP (5.2 s), FCP (2.97 s), Speed Index (4.83 s)","problem":"17 render-blocking external scripts found in HTML inventory; LCP is 5.2 s on mobile (heavy penalty >4 s).","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Move analytics and third-party widgets to footer.\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":1,"category":"Accessibility","title":"Fix critical form and button accessibility violations","impact":"WCAG 2.1 Level A (button-name, label, select-name)","problem":"3 critical axe violations: buttons lack discernible text, form elements lack labels, select elements lack accessible names.","solution":"- Add `aria-label` or visible text to filter buttons.\n- Associate `<label>` elements with inputs using `for`/`id`.\n- Add `aria-label` to `<select>` elements if visual label is missing."},{"priority":1,"category":"Security","title":"Harden Content Security Policy (CSP) for UGC","impact":"XSS protection, Security Headers Grade (40/100)","problem":"CSP allows `unsafe-inline` and `unsafe-eval` scripts. Site signals indicate User-Generated Content (UGC) exists, raising XSS risk.","solution":"Remove `'unsafe-inline'` and `'unsafe-eval'` from `script-src`. Implement nonce-based CSP:\n```http\nContent-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic';\n```"},{"priority":1,"category":"Performance","title":"Defer render-blocking JavaScript to improve LCP","impact":"LCP, FCP, Speed Index","problem":"LCP is 4.1 s on mobile; 17 render-blocking scripts identified including jQuery, GTM, and CookieYes.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Move jQuery and analytics to footer or load after interaction.\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":1,"category":"Accessibility","title":"Fix critical button and form label violations","impact":"WCAG 2.1.1, 4.1.2","problem":"3 critical axe violations: filter buttons lack discernible text; search/select elements lack labels.","solution":"Add `aria-label` to icon buttons and associate `<label>` elements with form inputs.\n```html\n<button aria-label=\"Filter posts\">...</button>\n<label for=\"search\">Search</label>\n<input id=\"search\" ...>\n```"},{"priority":1,"category":"Performance","title":"Eliminate render-blocking JavaScript","impact":"LCP, FCP, Speed Index","problem":"17 render-blocking scripts found in <head>; LCP is 4.7 s on mobile (target ≤2.5 s).","solution":"Add `defer` or `async` to non-critical scripts. Move analytics and third-party tags to footer.\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":1,"category":"Accessibility","title":"Fix critical form and button labels","impact":"WCAG 2.4.4, 4.1.2","problem":"3 critical axe violations: buttons lack discernible text, form elements lack labels, select elements lack accessible names.","solution":"Add `aria-label` or visible text to filter buttons and search inputs.\n```html\n<button aria-label=\"Apply filters\">Apply</button>\n<input aria-label=\"Search\" type=\"text\">\n```"},{"priority":2,"category":"Accessibility","title":"Fix contrast, labels, and landmarks","impact":"WCAG 1.4.3 (Contrast), 2.4.1 (Bypass Blocks)","problem":"Menu links fail contrast; search fields lack labels; no `main` landmark or skip-link.","solution":"- Increase text contrast to ≥4.5:1.\n- Add `<label>` or `aria-label` to search inputs.\n- Add `<main>` tag and a 'Skip to content' link at the top."},{"priority":2,"category":"SEO","title":"Add H1 and Meta Description","impact":"Search ranking, CTR","problem":"W3C reports 0 H1 elements; SEO audit flags missing meta description.","solution":"Ensure exactly one `<h1>` per page reflecting the main topic. Add `<meta name=\"description\" content=\"...\">` summarizing the newsroom content."},{"priority":2,"category":"Security","title":"Complete HSTS Configuration","impact":"Transport security","problem":"HSTS header present but missing `includeSubDomains` and `preload` directives.","solution":"Update server config to include subdomains and preload flag.\n```http\nStrict-Transport-Security: max-age=63072000; includeSubDomains; preload\n```"},{"priority":2,"category":"SEO","title":"Add a single H1 element to the page","impact":"Document outline, Search ranking","problem":"HTML inventory shows 0 H1 elements; page starts with H2. W3C validator notes heading structure issues.","solution":"Ensure the main page title is wrapped in a single `<h1>` tag at the top of the content flow.\n```html\n<h1>Videod - Sorainen</h1>\n```"},{"priority":2,"category":"Best Practices","title":"Fix HTML validation errors and duplicate IDs","impact":"Code quality, Rendering consistency","problem":"W3C validator reports 7 errors including duplicate ID 'select-kapitaliturud' and malformed attributes (e.g., 'stylr').","solution":"- Ensure all IDs are unique.\n- Correct attribute typos (e.g., `stylr` → `style`).\n- Fix empty `href` attributes on `<link>` elements."},{"priority":2,"category":"SEO","title":"Add a unique H1 heading","impact":"Document outline, Search ranking","problem":"HTML Inventory confirms 0 `<h1>` elements; W3C notes no heading level 1.","solution":"Ensure the page title is wrapped in a single `<h1>` tag at the top of the main content.\n```html\n<h1>Ziņas</h1>\n```"},{"priority":2,"category":"Security","title":"Harden HSTS and review CSP","impact":"Transport security, XSS defense","problem":"HSTS missing `includeSubDomains`; CSP allows `unsafe-inline` and `unsafe-eval`.","solution":"Update HSTS header to include subdomains. For CSP, remove `unsafe-inline` where possible or use nonces.\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":2,"category":"Security","title":"Strengthen HSTS header","impact":"Transport security, downgrade attacks","problem":"HSTS present but missing `includeSubDomains` and `preload` directives (Grade 40/100).","solution":"Update server config to include subdomains and preload flag.\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":2,"category":"SEO","title":"Add H1 and Main landmark","impact":"Document outline, Screen readers","problem":"0 `<h1>` elements and missing `<main>` landmark detected in HTML inventory.","solution":"Ensure exactly one `<h1>` per page and wrap primary content in `<main>`.\n```html\n<h1>Naujienos</h1>\n<main>...</main>\n```"},{"priority":3,"category":"Performance","title":"Reduce image weight and add dimensions","impact":"CLS, Page Weight (2.67 MB)","problem":"16 images missing width/height attributes; 19 images missing lazy loading.","solution":"- Add `width` and `height` attributes to all `<img>` tags.\n- Ensure `loading=\"lazy\"` is present on off-screen images.\n- Convert remaining PNG/JPEG to WebP/AVIF."},{"priority":3,"category":"Best Practices","title":"Fix HTML validation errors","impact":"Code quality, Rendering consistency","problem":"W3C reports 11 errors including duplicate IDs and invalid attributes (e.g., `stylr`).","solution":"Audit the HTML source for duplicate `id` attributes and correct typos in attribute names. Ensure unique IDs for form elements."},{"priority":3,"category":"Security","title":"Harden Content Security Policy","impact":"XSS defense-in-depth","problem":"CSP allows `unsafe-inline` and `unsafe-eval`, which bypasses XSS protections.","solution":"Replace `unsafe-inline` with nonce/hash strategy for scripts and styles.\n```apache\nContent-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic';\n```"}],"coverage":{"pct":100,"missing":[]},"siteSummary":{"pagesAudited":5,"pagesAttempted":5,"urls":["https://www.sorainen.com/et","https://www.sorainen.com/newsroom","https://www.sorainen.com/et/uudised","https://www.sorainen.com/lv/zinas","https://www.sorainen.com/lt/naujienos"]},"psiSnapshot":{"rows":[{"pageUrl":"https://www.sorainen.com/et","perfMobile":52,"perfDesktop":86,"lcpMobileMs":10160.282023345095,"lcpDesktopMs":2117.325261941603,"clsMobile":0,"clsDesktop":0.006810036342928977},{"pageUrl":"https://www.sorainen.com/newsroom","perfMobile":58,"perfDesktop":93,"lcpMobileMs":11266.721789231458,"lcpDesktopMs":1221.2773612974038,"clsMobile":0,"clsDesktop":0.0002904468416392013},{"pageUrl":"https://www.sorainen.com/et/uudised","perfMobile":72,"perfDesktop":93,"lcpMobileMs":5191.317161214583,"lcpDesktopMs":1097.4930238095908,"clsMobile":0,"clsDesktop":0.005549353052886618},{"pageUrl":"https://www.sorainen.com/lv/zinas","perfMobile":78,"perfDesktop":93,"lcpMobileMs":4059.8370933798287,"lcpDesktopMs":1048.6354131930618,"clsMobile":0,"clsDesktop":0.0005279003777103866},{"pageUrl":"https://www.sorainen.com/lt/naujienos","perfMobile":75,"perfDesktop":97,"lcpMobileMs":4714.361881383258,"lcpDesktopMs":1047.1253119257944,"clsMobile":0,"clsDesktop":0.003642542208326134}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket)","evidence":["HTML markers: WP Rocket","generator: WPML ver:4.9.7 stt:1,15,32,33;"]},{"id":"lazyload","title":"Images lazy-loaded","status":"n/a","detail":"No raster <img> elements found (4 SVGs excluded).","evidence":[]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"n/a","detail":"No raster <img> elements found (4 SVGs excluded).","evidence":[]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"warn","detail":"Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.","evidence":["selector: div.expertiseIntro__img.bg-cover","url: ….sorainen.com/wp-content/uploads/2026/05/eva-berlaus-sorainen-2026-scaled.jpg","box: 419×624px"]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"n/a","detail":"Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply.","evidence":[]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"n/a","detail":"Too few raster images to evaluate srcset width variety.","evidence":[]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"fail","detail":"3 render-blocking scripts in <head>. Move to footer or add defer/async.","evidence":["…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5","https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1","https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js"]}],"summary":{"passed":1,"warned":1,"failed":1,"notApplicable":4},"priorities":[{"title":"JS scripts not blocking in <head>","severity":"high","detail":"3 render-blocking scripts in <head>. Move to footer or add defer/async."},{"title":"Hero is a real <img> (not a CSS background-image)","severity":"medium","detail":"Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file."}]},"perPageOverall":[{"url":"https://www.sorainen.com/et","overall":62,"reasoning":"Mobile performance is critically low (52) with an LCP of 10.2 s, driven by 15 render-blocking scripts and heavy third-party JS. Accessibility has critical gaps (12 missing alt attributes) despite a decent 88 score. Security is weak (40/100) with a permissive CSP on a site that hosts user content, elevating XSS risk. Desktop performance (96) is strong, but mobile-first indexing penalizes the mobile experience significantly.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Eliminate render-blocking JavaScript and optimize LCP","impact":"LCP (10.2 s), FCP (3.1 s), TBT (466 ms)","problem":"15 render-blocking scripts and heavy third-party JS (Recaptcha, GTM) delay rendering; LCP is 10.2 s on mobile.","solution":"- Move non-critical scripts to footer or add `defer`/`async`.\n- Defer Recaptcha until user interaction (e.g., form focus).\n- Convert hero CSS background to `<img>` with `fetchpriority=\"high\"` and `srcset`."},{"priority":1,"category":"Accessibility","title":"Add alt text to all content images","impact":"WCAG 1.1.1 (Non-text Content), SEO","problem":"12 images lack `alt` attributes (W3C + axe-core critical violations), blocking screen reader users.","solution":"- Audit all `<img>` tags.\n- Add descriptive `alt` text for content images.\n- Use `alt=\"\"` for purely decorative images (e.g., icons, lines)."},{"priority":1,"category":"Security","title":"Harden CSP and HSTS for User-Generated Content","impact":"XSS protection, Transport security","problem":"Site has user content (`hasUserContent: yes`) but CSP allows `unsafe-inline`/`unsafe-eval`; HSTS missing `includeSubDomains`.","solution":"- Remove `'unsafe-inline'` and `'unsafe-eval'` from CSP; use nonces/hashes for scripts.\n- Update HSTS: `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload`."},{"priority":2,"category":"Accessibility","title":"Fix contrast, labels, and landmarks","impact":"WCAG 1.4.3 (Contrast), 2.4.1 (Bypass Blocks)","problem":"Menu links fail contrast; search fields lack labels; no `main` landmark or skip-link.","solution":"- Increase text contrast to ≥4.5:1.\n- Add `<label>` or `aria-label` to search inputs.\n- Add `<main>` tag and a 'Skip to content' link at the top."},{"priority":3,"category":"Performance","title":"Reduce image weight and add dimensions","impact":"CLS, Page Weight (2.67 MB)","problem":"16 images missing width/height attributes; 19 images missing lazy loading.","solution":"- Add `width` and `height` attributes to all `<img>` tags.\n- Ensure `loading=\"lazy\"` is present on off-screen images.\n- Convert remaining PNG/JPEG to WebP/AVIF."}],"perfScore":52,"a11yScore":88,"bestPracticesScore":92,"seoScore":92,"securityScore":40},{"url":"https://www.sorainen.com/newsroom","overall":62,"reasoning":"PSI mobile performance is critically low at 58 with an LCP of 11.3 s, driven by 1.08 MB of render-blocking JavaScript. Accessibility is compromised by 8 violations including 3 critical issues on form labels and buttons. Security headers score 40/100; while a CSP exists, it allows unsafe-inline/eval despite user-generated content signals, creating XSS risk. SEO suffers from a missing H1 and meta description. Desktop performance (93) contrasts sharply with mobile (58), indicating mobile-specific resource bottlenecks.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Defer non-critical JavaScript to fix LCP","impact":"LCP, FCP, TBT","problem":"LCP is 11.3 s on mobile; 17 render-blocking scripts and 1.08 MB of JS (reCAPTCHA, GTM) delay rendering.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Specifically defer `gtag.js`, `gtm.js`, and `recaptcha__en.js` until after `DOMContentLoaded`.\n```html\n<script src=\".../gtag.js\" async></script>\n<script src=\".../recaptcha__en.js\" defer></script>\n```"},{"priority":1,"category":"Accessibility","title":"Add accessible labels to forms and buttons","impact":"WCAG 2.1.1, 4.1.2","problem":"3 critical axe violations: buttons lack discernible text, form inputs (search, select) lack labels.","solution":"Associate `<label>` elements with inputs via `for`/`id`. Add `aria-label` to icon-only buttons.\n```html\n<label for=\"search-text\">Search</label>\n<input id=\"search-text\" ...>\n<button aria-label=\"Close modal\">X</button>\n```"},{"priority":1,"category":"Security","title":"Harden Content Security Policy (CSP)","impact":"XSS protection","problem":"Site has user-generated content signals, but CSP allows `unsafe-inline` and `unsafe-eval`, negating XSS defense.","solution":"Remove `unsafe-inline` and `unsafe-eval` from `script-src`. Use nonces or hashes for inline scripts.\n```http\nContent-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic';\n```"},{"priority":2,"category":"SEO","title":"Add H1 and Meta Description","impact":"Search ranking, CTR","problem":"W3C reports 0 H1 elements; SEO audit flags missing meta description.","solution":"Ensure exactly one `<h1>` per page reflecting the main topic. Add `<meta name=\"description\" content=\"...\">` summarizing the newsroom content."},{"priority":2,"category":"Security","title":"Complete HSTS Configuration","impact":"Transport security","problem":"HSTS header present but missing `includeSubDomains` and `preload` directives.","solution":"Update server config to include subdomains and preload flag.\n```http\nStrict-Transport-Security: max-age=63072000; includeSubDomains; preload\n```"}],"perfScore":58,"a11yScore":94,"bestPracticesScore":92,"seoScore":85,"securityScore":40},{"url":"https://www.sorainen.com/et/uudised","overall":68,"reasoning":"Mobile performance (72) is dragged by LCP 5.2s (>4s heavy penalty) and 17 render-blocking scripts. Accessibility has 3 critical axe violations (buttons, labels) despite a 94 PSI score. Security headers grade 40/100 with weak CSP on a site with UGC signals, elevating XSS risk. Missing H1 breaks document outline and SEO structure. Desktop is significantly better (96 perf) indicating mobile-specific bottlenecks.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Defer render-blocking scripts to improve LCP","impact":"LCP (5.2 s), FCP (2.97 s), Speed Index (4.83 s)","problem":"17 render-blocking external scripts found in HTML inventory; LCP is 5.2 s on mobile (heavy penalty >4 s).","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Move analytics and third-party widgets to footer.\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":1,"category":"Accessibility","title":"Fix critical form and button accessibility violations","impact":"WCAG 2.1 Level A (button-name, label, select-name)","problem":"3 critical axe violations: buttons lack discernible text, form elements lack labels, select elements lack accessible names.","solution":"- Add `aria-label` or visible text to filter buttons.\n- Associate `<label>` elements with inputs using `for`/`id`.\n- Add `aria-label` to `<select>` elements if visual label is missing."},{"priority":1,"category":"Security","title":"Harden Content Security Policy (CSP) for UGC","impact":"XSS protection, Security Headers Grade (40/100)","problem":"CSP allows `unsafe-inline` and `unsafe-eval` scripts. Site signals indicate User-Generated Content (UGC) exists, raising XSS risk.","solution":"Remove `'unsafe-inline'` and `'unsafe-eval'` from `script-src`. Implement nonce-based CSP:\n```http\nContent-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic';\n```"},{"priority":2,"category":"SEO","title":"Add a single H1 element to the page","impact":"Document outline, Search ranking","problem":"HTML inventory shows 0 H1 elements; page starts with H2. W3C validator notes heading structure issues.","solution":"Ensure the main page title is wrapped in a single `<h1>` tag at the top of the content flow.\n```html\n<h1>Videod - Sorainen</h1>\n```"},{"priority":2,"category":"Best Practices","title":"Fix HTML validation errors and duplicate IDs","impact":"Code quality, Rendering consistency","problem":"W3C validator reports 7 errors including duplicate ID 'select-kapitaliturud' and malformed attributes (e.g., 'stylr').","solution":"- Ensure all IDs are unique.\n- Correct attribute typos (e.g., `stylr` → `style`).\n- Fix empty `href` attributes on `<link>` elements."}],"perfScore":72,"a11yScore":94,"bestPracticesScore":92,"seoScore":92,"securityScore":40},{"url":"https://www.sorainen.com/lv/zinas","overall":70,"reasoning":"Mobile PSI 78 is dragged down by LCP 4.1 s (>4 s heavy penalty) and 17 render-blocking scripts. Accessibility has 3 critical axe violations (buttons/labels) despite a 94 PSI score. Security headers grade 40/100 lacks HSTS hardening and uses permissive CSP. SEO suffers from missing H1 and meta description. W3C reports 11 errors including duplicate IDs.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Defer render-blocking JavaScript to improve LCP","impact":"LCP, FCP, Speed Index","problem":"LCP is 4.1 s on mobile; 17 render-blocking scripts identified including jQuery, GTM, and CookieYes.","solution":"Add `defer` or `async` to non-critical scripts in `<head>`. Move jQuery and analytics to footer or load after interaction.\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":1,"category":"Accessibility","title":"Fix critical button and form label violations","impact":"WCAG 2.1.1, 4.1.2","problem":"3 critical axe violations: filter buttons lack discernible text; search/select elements lack labels.","solution":"Add `aria-label` to icon buttons and associate `<label>` elements with form inputs.\n```html\n<button aria-label=\"Filter posts\">...</button>\n<label for=\"search\">Search</label>\n<input id=\"search\" ...>\n```"},{"priority":2,"category":"SEO","title":"Add a unique H1 heading","impact":"Document outline, Search ranking","problem":"HTML Inventory confirms 0 `<h1>` elements; W3C notes no heading level 1.","solution":"Ensure the page title is wrapped in a single `<h1>` tag at the top of the main content.\n```html\n<h1>Ziņas</h1>\n```"},{"priority":2,"category":"Security","title":"Harden HSTS and review CSP","impact":"Transport security, XSS defense","problem":"HSTS missing `includeSubDomains`; CSP allows `unsafe-inline` and `unsafe-eval`.","solution":"Update HSTS header to include subdomains. For CSP, remove `unsafe-inline` where possible or use nonces.\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":3,"category":"Best Practices","title":"Fix HTML validation errors","impact":"Code quality, Rendering consistency","problem":"W3C reports 11 errors including duplicate IDs and invalid attributes (e.g., `stylr`).","solution":"Audit the HTML source for duplicate `id` attributes and correct typos in attribute names. Ensure unique IDs for form elements."}],"perfScore":78,"a11yScore":94,"bestPracticesScore":92,"seoScore":92,"securityScore":40},{"url":"https://www.sorainen.com/lt/naujienos","overall":68,"reasoning":"Mobile performance 75 is dragged down by LCP 4.7 s and 17 render-blocking scripts, despite good TTFB. Accessibility has 8 axe violations including 3 critical (buttons, labels, selects) and a missing h1, contradicting the Lighthouse 94 score. Security headers grade 40/100 reflects weak HSTS and permissive CSP, though no auth signals lower CSP priority. HTML validation shows 11 errors including duplicate IDs. Overall score reflects significant performance and accessibility debt despite solid desktop metrics.","confidence":"high","fixes":[{"priority":1,"category":"Performance","title":"Eliminate render-blocking JavaScript","impact":"LCP, FCP, Speed Index","problem":"17 render-blocking scripts found in <head>; LCP is 4.7 s on mobile (target ≤2.5 s).","solution":"Add `defer` or `async` to non-critical scripts. Move analytics and third-party tags to footer.\n```html\n<script src=\"...\" defer></script>\n```"},{"priority":1,"category":"Accessibility","title":"Fix critical form and button labels","impact":"WCAG 2.4.4, 4.1.2","problem":"3 critical axe violations: buttons lack discernible text, form elements lack labels, select elements lack accessible names.","solution":"Add `aria-label` or visible text to filter buttons and search inputs.\n```html\n<button aria-label=\"Apply filters\">Apply</button>\n<input aria-label=\"Search\" type=\"text\">\n```"},{"priority":2,"category":"Security","title":"Strengthen HSTS header","impact":"Transport security, downgrade attacks","problem":"HSTS present but missing `includeSubDomains` and `preload` directives (Grade 40/100).","solution":"Update server config to include subdomains and preload flag.\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":2,"category":"SEO","title":"Add H1 and Main landmark","impact":"Document outline, Screen readers","problem":"0 `<h1>` elements and missing `<main>` landmark detected in HTML inventory.","solution":"Ensure exactly one `<h1>` per page and wrap primary content in `<main>`.\n```html\n<h1>Naujienos</h1>\n<main>...</main>\n```"},{"priority":3,"category":"Security","title":"Harden Content Security Policy","impact":"XSS defense-in-depth","problem":"CSP allows `unsafe-inline` and `unsafe-eval`, which bypasses XSS protections.","solution":"Replace `unsafe-inline` with nonce/hash strategy for scripts and styles.\n```apache\nContent-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic';\n```"}],"perfScore":75,"a11yScore":94,"bestPracticesScore":92,"seoScore":92,"securityScore":40}]}