{"url":"https://thediplomat.ee/","date":"2026-07-03","siteName":"A place with a character.  In a neighbourhood that has one too. - The Diplomat","overall":78,"reasoning":"Site overall 78 is the mean of 5 pages. Scores range 74 (https://thediplomat.ee/faq) → 82 (https://thediplomat.ee/). Weakest page: Mobile performance is strong at 88 with excellent TTFB (6 ms), but LCP (3.0 s) exceeds the 2.5 s threshold. Security is the weakest area with a 13/100 header grade and HTTP failing to redirect to HTTPS, which is critical given the site accepts user content. Accessibility has one critical axe violation regarding invalid ARIA values on accordions. SEO is mostly solid but lacks a meta description. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Add HSTS and Content-Security-Policy headers","impact":"Security Headers Grade, XSS/Clickjacking protection","problem":"Security Headers grade is 13/100; HSTS and CSP are missing despite site signals indicating user-generated content (upload link).","solution":"Add HSTS with preload and a strict CSP:\n```http\nStrict-Transport-Security: max-age=63072000; includeSubDomains; preload\nContent-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\n```"},{"priority":1,"title":"Fix serious color-contrast violation","impact":"WCAG 1.4.3 Compliance, Accessibility Score","problem":"axe-core reports 1 serious violation on `.button--secondary` where background and foreground colors lack sufficient contrast.","solution":"Increase contrast ratio to at least 4.5:1 for the secondary button text. Use a darker text color or lighter background in CSS."},{"priority":1,"title":"Enforce HTTPS redirect and add HSTS","impact":"Transport security, data integrity","problem":"HTTP does not redirect to HTTPS (http://thediplomat.ee/contact stays on HTTP), and HSTS is missing. Security Headers grade is 13/100.","solution":"Configure the web server or CDN (Cloudflare) to redirect all HTTP traffic to HTTPS immediately.\n\n**Cloudflare Page Rule:**\n- URL: `thediplomat.ee/*`\n- Setting: `Always Use HTTPS`\n\n**Apache/Nginx (Origin):**\n```apache\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```\n\n**Add HSTS Header:**\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":1,"title":"Implement Content Security Policy (CSP)","impact":"XSS protection, data exfiltration prevention","problem":"CSP is missing. Site signals indicate User-Generated Content (textarea, upload link), making XSS risk high per the security rubric.","solution":"Deploy a strict CSP with nonces for scripts. Start with a report-only mode to avoid breaking WP Rocket/CDN scripts.\n\n**Header:**\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{RANDOM}' 'strict-dynamic' https:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https:; font-src 'self' https://fonts.gstatic.com; form-action 'self'; frame-ancestors 'self';\"\n```\n\n**Implementation:**\n- Generate a random nonce per request in PHP/WordPress.\n- Add `nonce=\"{NONCE}\"` to all `<script>` tags.\n- Monitor `Content-Security-Policy-Report-Only` before enforcing."},{"priority":1,"title":"Enforce HTTPS and Add Critical Security Headers","impact":"Transport security, XSS protection, clickjacking","problem":"HTTP does not redirect to HTTPS, and HSTS/CSP are missing. Site signals indicate User-Generated Content (textarea/upload), making XSS protection critical.","solution":"Configure server/CDN to redirect all HTTP traffic to HTTPS. Add the following headers:\n```\nStrict-Transport-Security: max-age=63072000; includeSubDomains; preload\nContent-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\nX-Frame-Options: SAMEORIGIN\n```"},{"priority":1,"title":"Fix Critical ARIA Attribute Values","impact":"Accessibility (WCAG 4.1.2)","problem":"Critical axe violation: `aria-expanded` uses value '1' instead of 'true'/'false' on accordion buttons. W3C validator confirms 4 instances of this error.","solution":"Update accordion buttons to use boolean strings:\n```html\n<button aria-expanded=\"true\" aria-controls=\"...\">\n  Toggle Section\n</button>\n```"},{"priority":1,"title":"Force HTTPS redirect and add HSTS","impact":"Transport security, MITM protection","problem":"HTTP does not redirect to HTTPS (http://thediplomat.ee/et/kkk does not redirect) and HSTS is missing, leaving users vulnerable on insecure connections.","solution":"Configure the web server (Nginx/Apache) to return 301 redirects for all HTTP traffic to HTTPS. Add HSTS header:\n```nginx\nadd_header Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\" always;\n```"},{"priority":2,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Performance Score, LCP Metric","problem":"Mobile LCP is 3.2 s (warning zone), flagged by PSI `largest-contentful-paint` and `image-delivery-insight`.","solution":"- Preload the LCP image resource.\n- Ensure hero image uses `fetchpriority=\"high\"`.\n- Convert remaining heavy images to WebP/AVIF if not already done."},{"priority":2,"title":"Fix W3C script type/defer errors","impact":"HTML Validity, Potential JS Execution Issues","problem":"W3C Validator reports 4 errors where `script` elements with non-standard `type` attributes (e.g., `text/rocketlazyloadscript`) incorrectly use the `defer` attribute.","solution":"Update WP Rocket configuration or custom scripts to remove `defer` from non-standard script types, or change `type` to `text/javascript` where appropriate."},{"priority":2,"title":"Fix W3C Validation Errors (Scripts & ARIA)","impact":"Maintainability, Accessibility compliance","problem":"19 W3C errors found, including 11 instances of `type=\"text/rocketlazyloadscript\"` with `defer` and 3 invalid `aria-expanded=\"\"` attributes.","solution":"1. **Scripts:** Remove `type` attribute from standard JS or use valid MIME types (`text/javascript`). WP Rocket's lazyload script type is non-standard.\n2. **ARIA:** Fix `aria-expanded` to be `true` or `false` (not empty string).\n3. **Hidden Inputs:** Remove `autocomplete` from `type=\"hidden\"` inputs.\n\n**Example Fix:**\n```html\n<!-- Before -->\n<button aria-expanded=\"\" ...>\n<!-- After -->\n<button aria-expanded=\"false\" ...>\n```"},{"priority":2,"title":"Add Meta Description and Structured Data","impact":"SEO, Search Result CTR","problem":"PSI SEO audit fails `metaDescription` and `structuredData`. HTML Inventory confirms Description is not set.","solution":"Add a unique meta description (150-160 chars) in the `<head>`.\n\n```html\n<meta name=\"description\" content=\"Contact The Diplomat for inquiries regarding apartments, payments, and general support. Reach out via our secure form.\">\n```\n\nAdd JSON-LD for `ContactPage` or `LocalBusiness`:\n```html\n<script type=\"application/ld+json\">\n{\n  \"@context\": \"https://schema.org\",\n  \"@type\": \"ContactPage\",\n  \"name\": \"Contact The Diplomat\"\n}\n</script>\n```"},{"priority":2,"title":"Add Meta Description for SEO","impact":"SEO (Search Snippets)","problem":"W3C and PSI report missing meta description. This affects click-through rates in search results.","solution":"Add a concise description (150–160 characters) in the `<head>`:\n```html\n<meta name=\"description\" content=\"Frequently asked questions about The Diplomat apartments, payments, and move-in process.\">\n```"},{"priority":2,"title":"Fix W3C validation errors and ARIA attributes","impact":"Accessibility, Standards compliance","problem":"19 W3C errors including invalid `aria-expanded=\"1\"` (should be true/false) and invalid script types with `defer` attribute.","solution":"- Update `aria-expanded` values to boolean strings (`true`/`false`).\n- Remove `type=\"text/rocketlazyloadscript\"` or use valid MIME types for scripts.\n- Fix hidden input autocomplete attributes per W3C spec."},{"priority":2,"title":"Add Meta Description","impact":"SEO, Click-through rate","problem":"SEO audit flags `metaDescription` as missing; document has no description tag.","solution":"Add a concise description (150–160 chars) in the `<head>`:\n```html\n<meta name=\"description\" content=\"Korduma kippuvad küsimused The Diplomat'i teenuste kohta. Leia vastused broneerimise, maksete ja majutuse küsimustele.\">\n```"},{"priority":2,"title":"Fix W3C HTML Validation Errors","impact":"Maintainability, Compliance","problem":"15 errors found, including 11 instances of `script` with invalid `type` attributes (WP Rocket) and hidden inputs with `autocomplete`.","solution":"- Remove `type` attribute from standard JS scripts (or use valid MIME types).\n- Remove `autocomplete` from `input type=\"hidden\"` elements.\n- Move `meta charset` to the first 1024 bytes of the document.\n- Fix unclosed `<p>` tags."},{"priority":3,"title":"Ensure lazy loading for below-fold images","impact":"Page Weight, Initial Load Time","problem":"HTML Inventory shows 2 images missing `loading=\"lazy\"` despite being below the fold.","solution":"Add `loading=\"lazy\"` to all `<img>` tags that are not the LCP element or above the fold."},{"priority":3,"title":"Optimize LCP and Font Loading","impact":"Core Web Vitals (LCP 2.8 s)","problem":"Mobile LCP is 2.8 s (warning zone). PSI suggests 80 ms savings from font-display and 142 KiB from image delivery.","solution":"1. **Fonts:** Add `font-display: swap` to CSS or use `display=swap` in Google Fonts URL.\n2. **Images:** Ensure the LCP image (likely the hero) is preloaded or has `fetchpriority=\"high\"` (already present per checklist, verify priority).\n3. **Images:** Convert remaining raster images to WebP/AVIF if not already done.\n\n**Google Fonts:**\n```html\n<link href=\"https://fonts.googleapis.com/css?family=Open+Sans&display=swap\" rel=\"stylesheet\">\n```"},{"priority":3,"title":"Resolve W3C HTML Validation Errors","impact":"Maintainability, Browser Compatibility","problem":"19 errors found, including invalid script types (`text/rocketlazyloadscript` with `defer`) and hidden inputs with `autocomplete`.","solution":"- Remove `defer` from non-JavaScript script types (WP Rocket optimization).\n- Remove `autocomplete` from `type=\"hidden\"` inputs.\n- Move `meta charset` to the first 1024 bytes of the document."},{"priority":3,"title":"Optimize LCP and Image Delivery","impact":"Performance (LCP 2.9 s)","problem":"LCP is 2.9 s (warning threshold) and PSI suggests 187 KiB savings via image delivery optimization.","solution":"- Convert remaining JPEGs to WebP/AVIF.\n- Ensure the LCP image (likely the hero) has `fetchpriority=\"high\"`.\n- Preload the LCP image resource in the `<head>`."}],"coverage":{"pct":100,"missing":[]},"siteSummary":{"pagesAudited":5,"pagesAttempted":5,"urls":["https://thediplomat.ee/","https://thediplomat.ee/contact","https://thediplomat.ee/faq","https://thediplomat.ee/et/kkk","https://thediplomat.ee/for-business-customers"]},"psiSnapshot":{"rows":[{"pageUrl":"https://thediplomat.ee/","perfMobile":91,"perfDesktop":100,"lcpMobileMs":3163.5,"lcpDesktopMs":775.5,"clsMobile":0.012213,"clsDesktop":0.000317},{"pageUrl":"https://thediplomat.ee/contact","perfMobile":94,"perfDesktop":99,"lcpMobileMs":2753.61984,"lcpDesktopMs":909.94625,"clsMobile":0.009934,"clsDesktop":0.000317},{"pageUrl":"https://thediplomat.ee/faq","perfMobile":88,"perfDesktop":100,"lcpMobileMs":2958.113875,"lcpDesktopMs":731.0774,"clsMobile":0,"clsDesktop":0.000317},{"pageUrl":"https://thediplomat.ee/et/kkk","perfMobile":88,"perfDesktop":99,"lcpMobileMs":3052.0508200000004,"lcpDesktopMs":723.7640500000002,"clsMobile":0,"clsDesktop":0.000611},{"pageUrl":"https://thediplomat.ee/for-business-customers","perfMobile":94,"perfDesktop":99,"lcpMobileMs":2866.7291999999998,"lcpDesktopMs":873.4519999999999,"clsMobile":0.016467,"clsDesktop":0.000529}]},"optimizationChecklist":{"items":[{"id":"caching","title":"Page caching plugin / CDN active","status":"pass","detail":"Caching plugin detected (WP Rocket) + CDN Cloudflare/Kinsta","evidence":["HTML markers: WP Rocket","generator: WP Rocket 3.22.0.3","CDN: Cloudflare, Kinsta (HIT)"]},{"id":"lazyload","title":"Images lazy-loaded","status":"pass","detail":"All non-hero raster images use loading=\"lazy\" except one.","evidence":["…p-content/uploads/2026/06/bd904a05d03dd97f3298ab818a9187d1748380cd-120x35.jpg"]},{"id":"heroEager","title":"Hero image eagerly loaded","status":"pass","detail":"Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable).","evidence":["hero: …-content/uploads/2026/06/e8d4ce07c088fedd0c5f9440ed88c14722cda6ad-320x180.jpg","loading: eager","fetchpriority: (not set)"]},{"id":"heroBackground","title":"Hero is a real <img> (not a CSS background-image)","status":"n/a","detail":"No CSS background-images detected on raster-image-eligible elements.","evidence":[]},{"id":"responsive","title":"Responsive images (srcset / <picture>)","status":"n/a","detail":"Only 2 raster images on the page — responsive-image rule does not apply.","evidence":[]},{"id":"imageSizes","title":"Reasonable number of image sizes","status":"n/a","detail":"Too few raster images to evaluate srcset width variety.","evidence":[]},{"id":"scriptsFooter","title":"JS scripts not blocking in <head>","status":"pass","detail":"No render-blocking scripts in <head>.","evidence":[]}],"summary":{"passed":4,"warned":0,"failed":0,"notApplicable":3},"priorities":[]},"perPageOverall":[{"url":"https://thediplomat.ee/","overall":82,"reasoning":"Mobile performance is strong at 91, though LCP sits in the warning zone at 3.2 s. Accessibility is mostly solid with a 90 score but contains one serious color-contrast violation. Security headers are critically low at 13/100, missing HSTS and CSP despite user-content signals. W3C validation shows 4 script-related errors that need cleanup. The site is high-quality overall but requires security hardening and contrast fixes to reach excellence.","confidence":"high","fixes":[{"priority":1,"title":"Add HSTS and Content-Security-Policy headers","impact":"Security Headers Grade, XSS/Clickjacking protection","problem":"Security Headers grade is 13/100; HSTS and CSP are missing despite site signals indicating user-generated content (upload link).","solution":"Add HSTS with preload and a strict CSP:\n```http\nStrict-Transport-Security: max-age=63072000; includeSubDomains; preload\nContent-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\n```"},{"priority":1,"title":"Fix serious color-contrast violation","impact":"WCAG 1.4.3 Compliance, Accessibility Score","problem":"axe-core reports 1 serious violation on `.button--secondary` where background and foreground colors lack sufficient contrast.","solution":"Increase contrast ratio to at least 4.5:1 for the secondary button text. Use a darker text color or lighter background in CSS."},{"priority":2,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Performance Score, LCP Metric","problem":"Mobile LCP is 3.2 s (warning zone), flagged by PSI `largest-contentful-paint` and `image-delivery-insight`.","solution":"- Preload the LCP image resource.\n- Ensure hero image uses `fetchpriority=\"high\"`.\n- Convert remaining heavy images to WebP/AVIF if not already done."},{"priority":2,"title":"Fix W3C script type/defer errors","impact":"HTML Validity, Potential JS Execution Issues","problem":"W3C Validator reports 4 errors where `script` elements with non-standard `type` attributes (e.g., `text/rocketlazyloadscript`) incorrectly use the `defer` attribute.","solution":"Update WP Rocket configuration or custom scripts to remove `defer` from non-standard script types, or change `type` to `text/javascript` where appropriate."},{"priority":3,"title":"Ensure lazy loading for below-fold images","impact":"Page Weight, Initial Load Time","problem":"HTML Inventory shows 2 images missing `loading=\"lazy\"` despite being below the fold.","solution":"Add `loading=\"lazy\"` to all `<img>` tags that are not the LCP element or above the fold."}]},{"url":"https://thediplomat.ee/contact","overall":78,"reasoning":"PSI mobile performance is strong at 94 with excellent TTFB (3 ms), but security configuration is critically weak with a 13/100 header grade and no HTTP-to-HTTPS redirect. The presence of user-generated content (textarea/upload) elevates the missing CSP to Priority 1 per the security rubric. Accessibility is generally good (axe 0 violations) but W3C validation shows 19 errors including ARIA and script type issues. SEO suffers from a missing meta description and structured data. The overall score reflects high technical performance offset by significant security and validation debt.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS redirect and add HSTS","impact":"Transport security, data integrity","problem":"HTTP does not redirect to HTTPS (http://thediplomat.ee/contact stays on HTTP), and HSTS is missing. Security Headers grade is 13/100.","solution":"Configure the web server or CDN (Cloudflare) to redirect all HTTP traffic to HTTPS immediately.\n\n**Cloudflare Page Rule:**\n- URL: `thediplomat.ee/*`\n- Setting: `Always Use HTTPS`\n\n**Apache/Nginx (Origin):**\n```apache\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```\n\n**Add HSTS Header:**\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\n```"},{"priority":1,"title":"Implement Content Security Policy (CSP)","impact":"XSS protection, data exfiltration prevention","problem":"CSP is missing. Site signals indicate User-Generated Content (textarea, upload link), making XSS risk high per the security rubric.","solution":"Deploy a strict CSP with nonces for scripts. Start with a report-only mode to avoid breaking WP Rocket/CDN scripts.\n\n**Header:**\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{RANDOM}' 'strict-dynamic' https:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https:; font-src 'self' https://fonts.gstatic.com; form-action 'self'; frame-ancestors 'self';\"\n```\n\n**Implementation:**\n- Generate a random nonce per request in PHP/WordPress.\n- Add `nonce=\"{NONCE}\"` to all `<script>` tags.\n- Monitor `Content-Security-Policy-Report-Only` before enforcing."},{"priority":2,"title":"Fix W3C Validation Errors (Scripts & ARIA)","impact":"Maintainability, Accessibility compliance","problem":"19 W3C errors found, including 11 instances of `type=\"text/rocketlazyloadscript\"` with `defer` and 3 invalid `aria-expanded=\"\"` attributes.","solution":"1. **Scripts:** Remove `type` attribute from standard JS or use valid MIME types (`text/javascript`). WP Rocket's lazyload script type is non-standard.\n2. **ARIA:** Fix `aria-expanded` to be `true` or `false` (not empty string).\n3. **Hidden Inputs:** Remove `autocomplete` from `type=\"hidden\"` inputs.\n\n**Example Fix:**\n```html\n<!-- Before -->\n<button aria-expanded=\"\" ...>\n<!-- After -->\n<button aria-expanded=\"false\" ...>\n```"},{"priority":2,"title":"Add Meta Description and Structured Data","impact":"SEO, Search Result CTR","problem":"PSI SEO audit fails `metaDescription` and `structuredData`. HTML Inventory confirms Description is not set.","solution":"Add a unique meta description (150-160 chars) in the `<head>`.\n\n```html\n<meta name=\"description\" content=\"Contact The Diplomat for inquiries regarding apartments, payments, and general support. Reach out via our secure form.\">\n```\n\nAdd JSON-LD for `ContactPage` or `LocalBusiness`:\n```html\n<script type=\"application/ld+json\">\n{\n  \"@context\": \"https://schema.org\",\n  \"@type\": \"ContactPage\",\n  \"name\": \"Contact The Diplomat\"\n}\n</script>\n```"},{"priority":3,"title":"Optimize LCP and Font Loading","impact":"Core Web Vitals (LCP 2.8 s)","problem":"Mobile LCP is 2.8 s (warning zone). PSI suggests 80 ms savings from font-display and 142 KiB from image delivery.","solution":"1. **Fonts:** Add `font-display: swap` to CSS or use `display=swap` in Google Fonts URL.\n2. **Images:** Ensure the LCP image (likely the hero) is preloaded or has `fetchpriority=\"high\"` (already present per checklist, verify priority).\n3. **Images:** Convert remaining raster images to WebP/AVIF if not already done.\n\n**Google Fonts:**\n```html\n<link href=\"https://fonts.googleapis.com/css?family=Open+Sans&display=swap\" rel=\"stylesheet\">\n```"}]},{"url":"https://thediplomat.ee/faq","overall":74,"reasoning":"Mobile performance is strong at 88 with excellent TTFB (6 ms), but LCP (3.0 s) exceeds the 2.5 s threshold. Security is the weakest area with a 13/100 header grade and HTTP failing to redirect to HTTPS, which is critical given the site accepts user content. Accessibility has one critical axe violation regarding invalid ARIA values on accordions. SEO is mostly solid but lacks a meta description. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Enforce HTTPS and Add Critical Security Headers","impact":"Transport security, XSS protection, clickjacking","problem":"HTTP does not redirect to HTTPS, and HSTS/CSP are missing. Site signals indicate User-Generated Content (textarea/upload), making XSS protection critical.","solution":"Configure server/CDN to redirect all HTTP traffic to HTTPS. Add the following headers:\n```\nStrict-Transport-Security: max-age=63072000; includeSubDomains; preload\nContent-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';\nX-Frame-Options: SAMEORIGIN\n```"},{"priority":1,"title":"Fix Critical ARIA Attribute Values","impact":"Accessibility (WCAG 4.1.2)","problem":"Critical axe violation: `aria-expanded` uses value '1' instead of 'true'/'false' on accordion buttons. W3C validator confirms 4 instances of this error.","solution":"Update accordion buttons to use boolean strings:\n```html\n<button aria-expanded=\"true\" aria-controls=\"...\">\n  Toggle Section\n</button>\n```"},{"priority":2,"title":"Optimize Largest Contentful Paint (LCP)","impact":"Performance (LCP, FCP)","problem":"Mobile LCP is 3.0 s (warning threshold >2.5 s) and FCP is 2.73 s. PSI flags render-blocking resources and font loading.","solution":"- Preload the LCP image and critical fonts.\n- Ensure `font-display: swap` is used.\n- Minimize main-thread work (TBT is 0 ms, but FCP is high).\n- Check if the LCP element is a font or image and optimize accordingly."},{"priority":2,"title":"Add Meta Description for SEO","impact":"SEO (Search Snippets)","problem":"W3C and PSI report missing meta description. This affects click-through rates in search results.","solution":"Add a concise description (150–160 characters) in the `<head>`:\n```html\n<meta name=\"description\" content=\"Frequently asked questions about The Diplomat apartments, payments, and move-in process.\">\n```"},{"priority":3,"title":"Resolve W3C HTML Validation Errors","impact":"Maintainability, Browser Compatibility","problem":"19 errors found, including invalid script types (`text/rocketlazyloadscript` with `defer`) and hidden inputs with `autocomplete`.","solution":"- Remove `defer` from non-JavaScript script types (WP Rocket optimization).\n- Remove `autocomplete` from `type=\"hidden\"` inputs.\n- Move `meta charset` to the first 1024 bytes of the document."}]},{"url":"https://thediplomat.ee/et/kkk","overall":76,"reasoning":"Mobile performance is solid (88) with excellent TTFB (4 ms) but LCP (3.1 s) and FCP (2.9 s) fall into warning thresholds. Accessibility is generally good (89) but marred by 1 critical axe violation and 19 W3C validation errors affecting ARIA and script tags. Security configuration is negligent (Grade 13/100) with HTTP not redirecting to HTTPS and missing HSTS/CSP, which is critical given the site accepts user-generated content. SEO basics are incomplete with a missing meta description. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Force HTTPS redirect and add HSTS","impact":"Transport security, MITM protection","problem":"HTTP does not redirect to HTTPS (http://thediplomat.ee/et/kkk does not redirect) and HSTS is missing, leaving users vulnerable on insecure connections.","solution":"Configure the web server (Nginx/Apache) to return 301 redirects for all HTTP traffic to HTTPS. Add HSTS header:\n```nginx\nadd_header Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\" always;\n```"},{"priority":1,"title":"Implement Content Security Policy (CSP)","impact":"XSS protection, data integrity","problem":"CSP is missing despite `User-generated content: yes` signal (textarea/upload), creating a high risk for stored XSS attacks.","solution":"Deploy a strict CSP with nonce/hash for scripts. Start with a report-only policy to identify breakage:\n```http\nContent-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\n```"},{"priority":2,"title":"Fix W3C validation errors and ARIA attributes","impact":"Accessibility, Standards compliance","problem":"19 W3C errors including invalid `aria-expanded=\"1\"` (should be true/false) and invalid script types with `defer` attribute.","solution":"- Update `aria-expanded` values to boolean strings (`true`/`false`).\n- Remove `type=\"text/rocketlazyloadscript\"` or use valid MIME types for scripts.\n- Fix hidden input autocomplete attributes per W3C spec."},{"priority":2,"title":"Add Meta Description","impact":"SEO, Click-through rate","problem":"SEO audit flags `metaDescription` as missing; document has no description tag.","solution":"Add a concise description (150–160 chars) in the `<head>`:\n```html\n<meta name=\"description\" content=\"Korduma kippuvad küsimused The Diplomat'i teenuste kohta. Leia vastused broneerimise, maksete ja majutuse küsimustele.\">\n```"},{"priority":3,"title":"Optimize LCP and Font Loading","impact":"Core Web Vitals (LCP, FCP)","problem":"LCP is 3.1 s and FCP is 2.9 s on mobile; font requests contribute to render delay.","solution":"- Add `font-display: swap` to CSS.\n- Preload the primary font file.\n- Ensure the LCP image (hero) has `fetchpriority=\"high\"` and is not lazy-loaded."}]},{"url":"https://thediplomat.ee/for-business-customers","overall":78,"reasoning":"Performance (94) and Accessibility (94) are excellent, with TTFB at 3 ms and zero axe violations. However, the Security Headers grade (13/100) significantly drags the score due to missing HSTS, CSP, and a critical failure where HTTP does not redirect to HTTPS. W3C validation shows 15 errors (script types, hidden inputs), and SEO lacks a meta description and structured data. LCP is in the warning zone (2.9 s) despite high overall performance. Confidence is high as all audit tools returned complete data.","confidence":"high","fixes":[{"priority":1,"title":"Force HTTPS redirect and add HSTS","impact":"Security, Transport Encryption","problem":"HTTP does not redirect to HTTPS (Security Headers report), and HSTS is missing despite HTTPS being available.","solution":"Configure the web server to redirect all HTTP traffic to HTTPS (301) and send the HSTS header:\n```apache\nHeader always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"\nRewriteEngine On\nRewriteCond %{HTTPS} off\nRewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]\n```"},{"priority":1,"title":"Implement Content Security Policy (CSP)","impact":"XSS Defense","problem":"CSP is missing and the site has user-generated content (textarea + upload link), creating XSS risk per the security rubric.","solution":"Deploy a strict CSP using nonces rather than a static allowlist:\n```apache\nHeader always set Content-Security-Policy \"default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';\"\n```\nEnsure all inline scripts use the nonce attribute."},{"priority":2,"title":"Fix W3C HTML Validation Errors","impact":"Maintainability, Compliance","problem":"15 errors found, including 11 instances of `script` with invalid `type` attributes (WP Rocket) and hidden inputs with `autocomplete`.","solution":"- Remove `type` attribute from standard JS scripts (or use valid MIME types).\n- Remove `autocomplete` from `input type=\"hidden\"` elements.\n- Move `meta charset` to the first 1024 bytes of the document.\n- Fix unclosed `<p>` tags."},{"priority":2,"title":"Add Meta Description and Structured Data","impact":"SEO, Search Visibility","problem":"PSI SEO audit fails `metaDescription` and `structuredData`; HTML inventory confirms both are missing.","solution":"- Add a unique `<meta name=\"description\" content=\"...\">` tag summarizing the business page.\n- Implement JSON-LD for `LocalBusiness` or `Organization` schema to enhance rich snippets."},{"priority":3,"title":"Optimize LCP and Image Delivery","impact":"Performance (LCP 2.9 s)","problem":"LCP is 2.9 s (warning threshold) and PSI suggests 187 KiB savings via image delivery optimization.","solution":"- Convert remaining JPEGs to WebP/AVIF.\n- Ensure the LCP image (likely the hero) has `fetchpriority=\"high\"`.\n- Preload the LCP image resource in the `<head>`."}]}]}