Audit

20260610T094310Z-9a23

← Back to avalahee
Audited URL
https://avalah.ee/
Timestamp
2026-06-10T09:44:37.299Z
Kind
single
Pages
1
Audit summary
https://avalah.ee/
Pagespeed scores
Other checks
LLM Report

Weighted audit summary

76
Overall site quality
Needs Improvementhigh confidence

Mobile PSI 93 indicates strong performance, but LCP 2.6s and 6 render-blocking scripts show optimization room. Security headers grade 13/100 is a significant drag due to missing HSTS and X-Frame-Options. One critical accessibility violation (button-name) and 4 W3C errors reduce quality. SEO suffers from missing meta description and vague link text. Confidence is high as all tools returned complete data.

Audit Report: Front page - Avalah

Website: https://avalah.ee/
Date: 2026-06-10

Overall Score: 76 / 100
Status: 🟡 Needs Improvement
Confidence: high
Audit Coverage: 100% — all sources returned data

Summary

Mobile PSI 93 indicates strong performance, but LCP 2.6s and 6 render-blocking scripts show optimization room. Security headers grade 13/100 is a significant drag due to missing HSTS and X-Frame-Options. One critical accessibility violation (button-name) and 4 W3C errors reduce quality. SEO suffers from missing meta description and vague link text. Confidence is high as all tools returned complete data.

PageSpeed Insights — Mobile vs Desktop

Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.

Strategy Performance (M / D) LCP (M / D) CLS (M / D)
Mobile vs Desktop 93 / 99 2.60 s / 851 ms 0.000 / 0.000

Optimization Checklist

1 of 2 passing — 1 pass · 1 warn · 0 fail · 5 n/a

Item Status Detail
Page caching plugin / CDN active Pass Caching plugin detected (WP Rocket) + CDN Cloudflare/Kinsta
Images lazy-loaded N/A No raster <img> elements found (3 SVGs excluded).
Hero image eagerly loaded N/A No raster <img> elements found (3 SVGs excluded).
Hero is a real <img> (not a CSS background-image) N/A No CSS background-images detected on raster-image-eligible elements.
Responsive images (srcset / <picture>) N/A Only 0 raster images on the page (3 SVGs excluded) — responsive-image rule does not apply.
Reasonable number of image sizes N/A Too few raster images to evaluate srcset width variety.
JS scripts not blocking in <head> Warn 2 render-blocking scripts in <head>. Move to footer or add defer/async.

Fixes

Priority 1: Critical

Immediate action — impacts user experience, search rankings, or site safety.

1A. Fix critical accessibility violation on search button

  • Impact: WCAG 4.1.2, Screen Reader usability
  • Problem: axe-core reports 1 critical violation: .header__search-submit button lacks discernible text.
  • Solution: Add aria-label or visible text to the button:
    <button class="header__search-submit" aria-label="Search">🔍</button>
    

Priority 2: Important

Essential for compliance, user reach, and search visibility.

2A. Add baseline security headers (HSTS, X-Frame-Options)

  • Impact: Transport security, Clickjacking protection
  • Problem: Security Headers grade 13/100; HSTS and X-Frame-Options are missing despite HTTPS being active.
  • Solution: Add headers via server config (e.g., Nginx/Apache):
    add_header Strict-Transport-Security "max-age=63072000; includeSubDomains" always;
    add_header X-Frame-Options "SAMEORIGIN" always;
    

2B. Defer or async render-blocking scripts

  • Impact: FCP, LCP, Mobile Performance
  • Problem: 6 render-blocking scripts found; FCP is 2.6s on mobile. Unused JS (122KB) also contributes.
  • Solution: Add defer or async to non-critical scripts in <head>:
    <script src="/js/global.js" defer></script>
    
    Remove unused JS (e.g., theme/js/global.7edaaf903ba7302f.js if not needed).

Priority 3: Best Practice

Recommended for long-term maintainability.

3A. Add meta description and fix link text

  • Impact: SEO, Click-through rate
  • Problem: SEO audit fails metaDescription; 13 links use vague text like "read more".
  • Solution: Add <meta name="description" content="...">. Change link text to be descriptive:
    <a href="/services">Read more about our Services</a>
    

3B. Fix W3C HTML validation errors

  • Impact: Browser compatibility, SEO
  • Problem: 4 errors found including area-hidden on form, empty name on input, and p inside span.
  • Solution: Correct HTML structure:
    • Remove area-hidden from <form>.
    • Add name attribute to <input>.
    • Move <p> outside <span>.
    • Remove aria-label from <label> elements.
▸Raw Markdown sent to the LLM
# Audit — https://avalah.ee/

Run: 2026-06-10T09:43:11.061Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 18254 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **93** | 99 |
| Accessibility | 94 | 94 |
| Best Practices | 100 | 100 |
| SEO | 83 | 83 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **2.6 s** | 0.9 s |
| CLS | 0.000 | **0.000** |
| TBT | **98 ms** | 12 ms |
| FCP | **2.60 s** | 809 ms |
| Speed Index | **2.60 s** | 809 ms |
| TTFB | 2 ms | **21 ms** |

### Priority fixes
1. **first-contentful-paint** (medium) — 2.6 s
2. **largest-contentful-paint** (low) — 2.6 s
3. **cache-insight** (medium) — Est savings of 3 KiB
4. **legacy-javascript-insight** (medium) — Est savings of 13 KiB
5. **network-dependency-tree-insight** (high)

### Findings (mobile)

#### Unused JavaScript
- https://avalah.ee/wp-content/themes/avalah/inc/theme/js/global.7edaaf903ba7302f.js — 122 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-YV6V380PD6 — 68 KB wasted

#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-YV6V380PD6 — 111 ms
- https://cdn-cookieyes.com/client_data/21a9a507575a3122bba40932c0a7ad97/script.js — 101 ms
- https://www.googletagmanager.com/gtag/js?id=G-YV6V380PD6 — 72 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `first-contentful-paint` (performance, score 0.64, weight 10) — First Contentful Paint — 2.6 s
- `largest-contentful-paint` (performance, score 0.88, weight 25) — Largest Contentful Paint — 2.6 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 13 links found
- `interactive` (performance, score 0.84, weight 0) — Time to Interactive — 4.3 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 251 ms._

**Transport:**
- Final URL: https://avalah.ee/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `public, max-age=0, s-maxage=86400`
- etag: n/a
- last-modified: n/a
- expires: n/a
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: br
- content-length: n/a
- Decoded body: 81.1 KB

### Priority fixes
1. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
4. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
5. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
6. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
7. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
8. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
9. **server header discloses technology** (low) — Server: cloudflare

### Findings

#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Cookies
- __cf_bm — HttpOnly=true, Secure=true, SameSite=None

#### Info disclosure
- Server: `cloudflare`


#### All response headers
```
alt-svc: h3=":443"; ma=86400
cache-control: public, max-age=0, s-maxage=86400
cache-tag: 1344add5-ee91-4c5e-84a0-6a1979f9a584,a92be48a6eec83491241851b930b7768344d855b6b82d5b32a8b2bb9cd64f238
cf-cache-status: DYNAMIC
cf-ray: a0976e265cac8d37-TLL
connection: keep-alive
content-encoding: br
content-type: text/html; charset=UTF-8
date: Wed, 10 Jun 2026 09:43:11 GMT
ki-cache-tag: 1344add5-ee91-4c5e-84a0-6a1979f9a584,a92be48a6eec83491241851b930b7768344d855b6b82d5b32a8b2bb9cd64f238
ki-cache-type: None
ki-cf-cache-status: SAVING
ki-edge: v=28.2.1;mv=99.9.9
ki-origin: o1i
link: <https://avalah.ee/wp-json/>; rel="https://api.w.org/", <https://avalah.ee/wp-json/wp/v2/pages/10>; rel="alternate"; title="JSON"; type="application/json", <https://avalah.ee/>; rel=shortlink
nel: {"success_fraction":0.01,"report_to":"cf-nel","max_age":604800}
report-to: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=DCUbH3KaEuMuLZtEphFS2SpKJyFaO56rYe4tUUanQy4OuyFtZAxkrAmc80k3Er4K0Ql4Z86FhJN7dJ%2F6WMluLcFvHWQAO098L24f7id5ujGG%2BTOzz%2FdYIDlh3g%3D%3D"}],"group":"cf-nel","max_age":604800}
server: cloudflare
set-cookie: __cf_bm=SyAhgxTis81fEwcfTXiN6sLLszZ3dmTbmlKL6innZZ4-1781084591-1.0.1.1-f0nRrsF6H4hvAcIfiflCdPCeXxJBz0ne0AxBt9GbTt1EMQtDJ38yCZDz.uWYbSnp_lsSa7ANGUc_wN5E.ZWRT.8UHdXv8NY858iplbHwQRY; path=/; expires=Wed, 10-Jun-26 10:13:11 GMT; domain=.avalah.ee; HttpOnly; Secure; SameSite=None
transfer-encoding: chunked
vary: Accept-Encoding
x-content-type-options: nosniff
x-edge-location-klb: 1
x-kinsta-cache: HIT
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1065 ms._

**Scoring:** 4 errors · 1 warnings · 29 cosmetic (suppressed)

### Priority fixes
1. **Attribute “area-hidden” not allowed on element “form” at this point.** (medium) — x1, first at line 408
2. **Bad value “” for attribute “name” on element “input”: Must not be empty.** (medium) — x1, first at line 994
3. **Element “p” not allowed as child of element “span” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 1039
4. **The “aria-label” attribute must not be used on any “label” element that is associated with a labelable element.** (medium) — x1, first at line 995

### Issue groups
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 13 `banner --><script id="cookieyes" type="text/javascript" src="https://cdn-cookiey`
- (×1) [error] Attribute “area-hidden” not allowed on element “form” at this point. — first at line 408 `div>
					<form id="header-search" class="header__search-form"  area-hidden="tru`
- (×1) [error] Bad value “” for attribute “name” on element “input”: Must not be empty. — first at line 994 `gle">
    <input
        type="checkbox"
        id="theme-toggle"
        name=`
- (×1) [error] Element “p” not allowed as child of element “span” in this context. (Suppressing further errors from this subtree.) — first at line 1039 `opyright"><p>2026 ©`
- (×1) [error] The “aria-label” attribute must not be used on any “label” element that is associated with a labelable element. — first at line 995 `>
    <label for="theme-toggle" class="toggle__label" aria-label="Toggle between`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2378 ms._

**Scoring:** 1 violations · 41 passes · critical 1 · serious 0 · moderate 0 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.header__search-submit`

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2388 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 27 network requests · 204.6 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| script | 9 | 176.5 KB |
| font | 1 | 24.4 KB |
| stylesheet | 4 | 1.8 KB |
| xhr | 2 | 1.8 KB |
| fetch | 5 | 44 B |
| document | 1 | 0 B |
| ping | 1 | 0 B |
| other | 1 | 0 B |
| image | 3 | 0 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 173.5 KB
- https://fonts.gstatic.com — 1 request, 24.4 KB
- https://cdn.jsdelivr.net — 3 requests, 6.7 KB
- https://cdn-cookieyes.com — 9 requests, 44 B
- https://log.cookieyes.com — 1 request, 0 B
- https://fonts.googleapis.com — 2 requests, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.googletagmanager.com/gtag/js?id=G-YV6V380PD6 (script) — 284 ms, 173.5 KB
- https://avalah.ee/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js (script) — 195 ms, 0 B
- https://cdn-cookieyes.com/client_data/21a9a507575a3122bba40932c0a7ad97/banner.js (script) — 175 ms, 0 B
- https://fonts.googleapis.com/css2?family=Geologica:wght@300;400;500;600&display=swap (xhr) — 155 ms, 0 B
- https://fonts.gstatic.com/s/geologica/v5/oY1l8evIr7j9P3TN9YwNAdyjzUyDKkKdAGOJh1UlCDUIhAIdhCZOn1fLsig7jfvCCPHZckUWE1lE.woff2 (font) — 147 ms, 24.4 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-YV6V380PD6&gtm=45je6641v873663608za200zd873663608&_p=1781084591427&gcd=13l3l3l2l1l1&npa=1&dma_cps=a&dma=1&_eu=AAAAAAAC&are=1&cid=1817550956.1781084592&frm=0&pscdl=noapi&rcb=15&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=0~115938466~115938468&sid=1781084591&sct=1&seg=0&dl=https%3A%2F%2Favalah.ee%2F&dt=Front%20page%20-%20Avalah&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=637 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-YV6V380PD6&gtm=45je6641v873663608za200zd873663608&_p=1781084591427&gcd=13l3l3l2l1l1&npa=1&dma_cps=a&dma=1&_eu=AAAAAAAC&are=1&cid=1817550956.1781084592&frm=0&pscdl=noapi&rcb=15&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=0~115938466~115938468&sid=1781084591&sct=1&seg=0&dl=https%3A%2F%2Favalah.ee%2F&dt=Front%20page%20-%20Avalah&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=637 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2388 ms._

**Document:**
- Lang: en
- Title: Front page - Avalah
- Canonical: https://avalah.ee/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 114899

**Meta tags:**
- Description: not set
- Robots: index, follow, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 6 (og:locale, og:type, og:title, og:url, og:site_name, og:updated_time)
- Twitter tags: 6
- hreflang:
  - en → https://avalah.ee/
  - et → https://avalah.ee/et/
  - fi → https://avalah.ee/fi/
  - x-default → https://avalah.ee/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×4, h3 ×5, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Odoo Manufacturing ERP Partner for European Manufacturers
  - h2: Partner who understands production, not just software.
  - h3: Services
  - h3: Solutions
  - h2: Reasons why manufacturing companies choose Avalah
  - h3: A decade of manufacturing ERP implementations.
  - h3: A senior team with manufacturing background.
  - h3: We grow with our customers.
  - h2: Expertise that delivers results
  - h2: Considering new ERP for your Factory?

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 18 total — 1 defer, 2 async, 6 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js
- https://cdn-cookieyes.com/client_data/21a9a507575a3122bba40932c0a7ad97/script.js
- https://cdn-cookieyes.com/client_data/21a9a507575a3122bba40932c0a7ad97/banner.js (async)
- https://www.googletagmanager.com/gtag/js?id=G-YV6V380PD6 (async)
- https://avalah.ee/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js (defer)
- https://avalah.ee/wp-content/themes/avalah/inc/theme/js/jquery.418e072ae989eeda.js
- https://avalah.ee/wp-content/themes/avalah/inc/theme/js/core.5eafc85d0ffd4a75.js
- https://avalah.ee/wp-content/themes/avalah/inc/theme/js/global.7edaaf903ba7302f.js
- https://avalah.ee/wp-includes/js/jquery/jquery-migrate.min.js

**Stylesheets:** 4 external, 4 inline (30.1 KB)

**Images:** 3 total — **0 without alt**, **3 without width/height**, 3 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/revisit.svg | Revisit consent button | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/close.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |

**Links:** 56 anchors — 2 external, 0 preconnect, 0 preload.

Vague repeated link text:
- "read more" ×13
- "book a consultation" ×3
- "services" ×2
- "deep dive into services" ×2
- "solutions" ×2
- "deep dive into solutions" ×2
- "references" ×2
- "about us" ×2
- "contact" ×2

**Forms:**
Form 1:
- search — labeled

### Priority fixes
1. **3 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
2. **6 render-blocking external scripts** (medium) — Only 1 defer, 2 async; add defer/async to non-critical scripts
3. **Vague link text repeated** (medium) — "read more" ×13

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 1 pass · 1 warn · 0 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) + CDN Cloudflare/Kinsta |
| Images lazy-loaded | – n/a | No raster <img> elements found (3 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (3 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (3 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ! warn | 2 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `CDN: Cloudflare, Kinsta (DYNAMIC)`
- JS scripts not blocking in <head>:
  - `https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js`
  - `https://cdn-cookieyes.com/client_data/21a9a507575a3122bba40932c0a7ad97/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (medium) — 2 render-blocking scripts in <head>. Move to footer or add defer/async.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).