20260831T081404Z-ffe7
- Audited URL
- https://gigainvesteeringud.giga.ee/
- Timestamp
- 2026-08-31T08:27:48.404Z
- Kind
- site
- Pages
- 5
Weighted audit summary
Site overall 73 is the mean of 5 pages. Scores range 68 (https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil) → 87 (https://gigainvesteeringud.giga.ee/). Weakest page: Mobile performance is the primary constraint with an LCP of 4.1 s and FCP of 3.04 s, both exceeding recommended thresholds. Security posture is critically weak with a 0/100 header score, missing HSTS and CSP despite user-generated content signals. Accessibility has two serious axe violations regarding color contrast and link names that require immediate remediation. HTML validation errors in `srcset` and script attributes further degrade code quality. SEO is hindered by missing meta descriptions and structured data.
Audit Report: Giga Investeeringud
Website: https://gigainvesteeringud.giga.ee/
Date: 31.08.2026
Audit Coverage: 100% — all sources returned data
Confidence: high
Pages Audited (5 of 5):
- https://gigainvesteeringud.giga.ee/
- https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil
- https://gigainvesteeringud.giga.ee/test
- https://gigainvesteeringud.giga.ee/meist
- https://gigainvesteeringud.giga.ee/kinnitus
Summary of results
Overall Score: 73 / 100
Status: 🟡 Needs Improvement
Site overall 73 is the mean of 5 pages. Scores range 68 (https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil) → 87 (https://gigainvesteeringud.giga.ee/). Weakest page: Mobile performance is the primary constraint with an LCP of 4.1 s and FCP of 3.04 s, both exceeding recommended thresholds. Security posture is critically weak with a 0/100 header score, missing HSTS and CSP despite user-generated content signals. Accessibility has two serious axe violations regarding color contrast and link names that require immediate remediation. HTML validation errors in srcset and script attributes further degrade code quality. SEO is hindered by missing meta descriptions and structured data.
Per-page scores
🟡 Needs Improvement · https://gigainvesteeringud.giga.ee/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 87 | 97 | 89 | 100 | 92 | 0 |
🟡 Needs Improvement · https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 68 | 81 | 85 | 100 | 92 | 0 |
🟡 Needs Improvement · https://gigainvesteeringud.giga.ee/test
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 68 | 87 | 94 | 96 | 83 | 0 |
🟡 Needs Improvement · https://gigainvesteeringud.giga.ee/meist
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 68 | 73 | 89 | 100 | 92 | 0 |
🟡 Needs Improvement · https://gigainvesteeringud.giga.ee/kinnitus
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 76 | 97 | 94 | 100 | 92 | 0 |
PageSpeed Insights — Mobile vs Desktop
Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.
| URL | Performance (M / D) | LCP (M / D) | CLS (M / D) |
|---|---|---|---|
| https://gigainvesteeringud.giga.ee/ | 97 / 98 | 1.95 s / 446 ms | 0.090 / 0.090 |
| https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil | 81 / 99 | 4.10 s / 995 ms | 0.000 / 0.000 |
| https://gigainvesteeringud.giga.ee/test | 87 / 100 | 3.16 s / 432 ms | 0.000 / 0.000 |
| https://gigainvesteeringud.giga.ee/meist | 73 / 99 | 5.80 s / 732 ms | 0.034 / 0.064 |
| https://gigainvesteeringud.giga.ee/kinnitus | 97 / 98 | 1.86 s / 564 ms | 0.090 / 0.090 |
Optimization Checklist
2 of 2 passing — 2 pass · 0 warn · 0 fail · 5 n/a
| Item | Status | Detail |
|---|---|---|
| Page caching plugin / CDN active | Pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | N/A | No raster <img> elements found (15 SVGs excluded). |
| Hero image eagerly loaded | N/A | No raster <img> elements found (15 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | N/A | Only 0 raster images on the page (15 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | Pass | No render-blocking scripts in <head>. |
Fixes
Priority 1: Critical
Immediate action — impacts user experience, search rankings, or site safety.
1A. Add HSTS and X-Content-Type-Options headers Security
- Impact: Transport security, MIME sniffing protection
- Problem: Security Headers grade is 0/100; HSTS and X-Content-Type-Options are missing despite HTTPS being enabled.
- Solution:
Add the following headers to your server configuration (Apache example):
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" Header always set X-Content-Type-Options "nosniff"
1B. Fix color contrast on navigation links Accessibility
- Impact: WCAG 1.4.3 Compliance, Screen Reader usability
- Problem: axe-core reports 1 serious violation: color-contrast on multiple menu items (e.g., .menu-item-543).
- Solution:
Increase the contrast ratio between text and background to at least 4.5:1. Adjust CSS for
.menu-item-543 > aand similar selectors to use darker text or lighter backgrounds.
1C. Implement Critical Security Headers (HSTS, CSP) Security
- Impact: Transport security, XSS defense
- Problem: Security Headers grade is 0/100; HSTS and CSP are missing. Site signals indicate user-generated content (upload anchor), elevating XSS risk.
- Solution:
Add HSTS with preload and a strict CSP:
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload Content-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';
1D. Optimize Largest Contentful Paint (LCP) Performance
- Impact: LCP 4.1 s, FCP 3.04 s
- Problem: Mobile LCP is 4.1 s (heavy penalty zone >4 s) and FCP is 3.04 s. Unused JS (23 KB) and image delivery (227 KiB savings) identified.
- Solution:
- Preload LCP image resource.
- Defer unused JavaScript (
jquery.7e52f38a196e6397.js). - Optimize image delivery (227 KiB savings potential).
1E. Resolve 404 Status Code SEO
- Impact: SEO, User Experience
- Problem: W3C, PSI, and Browser Runtime all confirm the URL returns HTTP 404 (Page Not Found).
- Solution:
Ensure the target URL returns a 200 OK status if content is intended to be live. If this is a test page, do not index it (add
noindexmeta tag) or move it to a staging environment.
Priority 2: Important
Essential for compliance, user reach, and search visibility.
2A. Add a meta description SEO
- Impact: Search result click-through rate, SEO audit score
- Problem: Lighthouse SEO audit fails
metaDescription; HTML Inventory confirms Description meta tag is not set. - Solution:
Add a concise description (150–160 characters) in the
<head>:<meta name="description" content="Giga Investeeringud – Äri- ja elamukinnisvara spetsialist. Uurige meie pakkumisi ja arendusi.">
2B. Fix srcset width descriptors on SVGs Best Practices
- Impact: HTML Validation, Image rendering consistency
- Problem: W3C Validator reports 9 errors where
srcsetlacks width specifications (e.g.,giga-invest.svg) whilesizesis present. - Solution:
Update
<img>tags to include width descriptors insrcset(e.g.,srcset="image.svg 100w") or removesizesif not needed for SVGs.
2C. Fix Color Contrast and Link Names Accessibility
- Impact: WCAG 1.4.3, 2.4.4 compliance
- Problem: axe-core reports 2 serious violations: color-contrast on menu links and link-name on gallery images.
- Solution:
- Increase contrast ratio on
.menu-item-543links to ≥4.5:1. - Add
aria-labelor visible text to gallery links (e.g.,data-fancyboxelements).
- Increase contrast ratio on
2D. Resolve W3C HTML Validation Errors Best Practices
- Impact: Code quality, rendering consistency
- Problem: 4 errors found:
srcsetmissing width (x2),sizes'auto' withoutloading='lazy', and invalidscripttype/defer combination. - Solution:
- Add width descriptors to
srcset(e.g.,100w). - Add
loading="lazy"to images withsizes="auto". - Remove
deferfrom non-JS script types or correct MIME type.
- Add width descriptors to
2E. Add Baseline Security Headers Security
- Impact: Transport security, clickjacking, MIME sniffing
- Problem: Security Headers grade is 0/100. HSTS, X-Frame-Options, and X-Content-Type-Options are missing.
- Solution:
Send the following headers from the server (Apache example):
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" Header always set X-Content-Type-Options "nosniff" Header always set X-Frame-Options "SAMEORIGIN"
2F. Enable Browser Caching Performance
- Impact: Repeat visit load time, TTFB
- Problem: Cache-Control header is set to
no-store, no-cache, max-age=0, preventing the browser from caching the document despite WP Rocket being active. - Solution:
Update server configuration to allow caching for static assets and the document itself (e.g.,
Cache-Control: public, max-age=31536000for assets,max-age=600for HTML).
2G. Fix Color Contrast on Navigation Accessibility
- Impact: WCAG 1.4.3 Contrast
- Problem: axe-core reports a serious color-contrast violation on 23+ nodes, including menu links like
.menu-item-543. - Solution:
Increase the contrast ratio of text against its background to at least 4.5:1. Adjust CSS for
.menu-item-543 > aand similar classes.
2H. Implement Baseline Security Headers Security
- Impact: Transport security, clickjacking protection, MIME sniffing
- Problem: Security Headers grade is 0/100; HSTS, X-Frame-Options, and X-Content-Type-Options are missing despite HTTPS being active.
- Solution:
Add the following headers to the server configuration (Apache example):
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" Header always set X-Frame-Options "SAMEORIGIN" Header always set X-Content-Type-Options "nosniff"
2I. Fix Color Contrast on Navigation Links Accessibility
- Impact: WCAG 1.4.3 (Contrast), Accessibility Score
- Problem: axe-core reports 1 serious violation: multiple menu links (e.g.,
.menu-item-543 > a) fail minimum contrast ratios. - Solution:
- Increase text color luminance or darken background for affected links.
- Target a contrast ratio of at least 4.5:1 for normal text.
- Verify changes with a contrast checker tool before deployment.
2J. Add baseline security headers (HSTS, X-Content-Type-Options, X-Frame-Options) Security
- Impact: Transport security, clickjacking protection, MIME sniffing
- Problem: Security Headers grade is 0/100; HSTS, X-Content-Type-Options, and X-Frame-Options are missing.
- Solution:
Configure server to send:
Strict-Transport-Security: max-age=63072000; includeSubDomains X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN
2K. Provide accessible names for buttons Accessibility
- Impact: WCAG 4.1.2 Name, Role, Value
- Problem: PSI failing audit
button-name(score 0.00) indicates buttons lack accessible names. - Solution:
Ensure all
<button>elements have visible text oraria-labelattributes describing their action.
2L. Add meta description and structured data SEO
- Impact: Search snippet quality, rich results eligibility
- Problem: PSI SEO audit fails
metaDescriptionandstructuredData; HTML Inventory confirms no meta description or JSON-LD. - Solution:
Add
<meta name="description" content="...">and implement relevant JSON-LD (e.g., Organization or WebPage).
Priority 3: Best Practice
Recommended for long-term maintainability.
3A. Implement Content-Security-Policy (CSP) Security
- Impact: XSS defense-in-depth
- Problem: CSP is missing. Site signals show no auth/payments, so risk is lower, but CSP is still a best practice.
- Solution:
Deploy a restrictive CSP with nonces for scripts:
Header always set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';"
3B. Add Meta Description and Structured Data SEO
- Impact: Search snippet quality, rich results
- Problem: SEO audit fails
metaDescriptionandstructuredData; HTML inventory confirms no JSON-LD or meta description. - Solution:
- Add
<meta name="description" content="...">summarizing the Raadi homes article. - Implement
ArticleorNewsArticleJSON-LD schema.
- Add
3C. Implement Content Security Policy (CSP) Security
- Impact: XSS defense-in-depth
- Problem: CSP is missing. Site signals indicate no auth, payments, or user content, lowering immediate risk but CSP remains best practice.
- Solution:
Deploy a strict CSP with nonces for scripts. Example:
Content-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';
3D. Add Meta Description and Open Graph Tags SEO
- Impact: Search snippet quality, Social sharing
- Problem: HTML Inventory shows no meta description, no Open Graph tags, and no Twitter tags; PSI SEO audit flags
metaDescriptionas failing. - Solution:
Add to
<head>:<meta name="description" content="Giga Investeeringud on ambitsioonikas äri- ja elamukinnisvara arendaja."> <meta property="og:title" content="Meist - Giga Investeeringud"> <meta property="og:description" content="..."> <meta property="og:image" content="/path/to/og-image.jpg">
3E. Fix W3C srcset Width Errors Best Practices
- Impact: HTML Validity, Image Rendering
- Problem: W3C Validator reports 7 errors where
srcsetattributes lack width descriptors (e.g.,100w) whilesizesis present. - Solution:
Update
<img>tags to include width descriptors insrcset:<!-- Incorrect --> <img srcset="/img.svg" sizes="100vw"> <!-- Correct --> <img srcset="/img.svg 100w" sizes="100vw">
3F. Consider Content-Security-Policy (CSP) Security
- Impact: XSS defense-in-depth
- Problem: CSP is missing. Site signals indicate no auth, payments, or user content, lowering immediate risk but CSP remains a best practice.
- Solution:
If user content or login is added later, deploy a nonce-based CSP:
For now, prioritize P1/P2 fixes.Header always set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'"
▸Raw Markdown sent to the LLM
# Site Audit — https://gigainvesteeringud.giga.ee/
Run: 2026-08-31T08:14:04.626Z
Audited **5** of 5 discovered pages.
Average per-page audit coverage: **100%**
Pages audited:
- https://gigainvesteeringud.giga.ee/
- https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil
- https://gigainvesteeringud.giga.ee/test
- https://gigainvesteeringud.giga.ee/meist
- https://gigainvesteeringud.giga.ee/kinnitus
---
# Page 1 of 5 — https://gigainvesteeringud.giga.ee/
Run: 2026-08-31T08:14:05.388Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 16229 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **97** | 98 |
| Accessibility | **89** | 95 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **2.0 s** | 0.4 s |
| CLS | **0.090** | 0.090 |
| TBT | 0 ms | 0 ms |
| FCP | **1.66 s** | 446 ms |
| Speed Index | **1.66 s** | 792 ms |
| TTFB | 3 ms | 3 ms |
### Priority fixes
1. **image-delivery-insight** (medium) — Est savings of 773 KiB
2. **network-dependency-tree-insight** (high)
3. **render-blocking-insight** (high) — Est savings of 190 ms
4. **unused-css-rules** (high) — Est savings of 31 KiB
5. **unused-javascript** (high) — Est savings of 23 KiB
### Findings (mobile)
#### Unused JavaScript
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js — 23 KB wasted
#### Layout-shift sources
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 12 ms._
**Transport:**
- Final URL: https://gigainvesteeringud.giga.ee/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 31 Aug 2026 08:14:05 GMT
- expires: Mon, 31 Aug 2026 08:14:05 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 16129
- Decoded body: 77.9 KB
- Compression ratio: 0.202
### Priority fixes
1. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 16129
content-type: text/html; charset=UTF-8
date: Mon, 31 Aug 2026 08:14:05 GMT
expires: Mon, 31 Aug 2026 08:14:05 GMT
keep-alive: timeout=5, max=95
last-modified: Mon, 31 Aug 2026 08:14:05 GMT
server: Apache / ZoneOS
vary: Accept-Encoding
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 911 ms._
**Scoring:** 9 errors · 1 warnings · 16 cosmetic (suppressed)
### Priority fixes
1. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/giga-invest.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…s/2026/06/giga-invest.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x2, first at line 90
2. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Giga_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…26/06/Giga_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x1, first at line 605
3. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Giga_ehitus_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…iga_ehitus_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x1, first at line 629
4. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Holttem_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…06/Holttem_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x1, first at line 654
5. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/HUT_A_valge_v2.8.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…6/06/HUT_A_valge_v2.8.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x1, first at line 679
### Issue groups
- (×2) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/giga-invest.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…s/2026/06/giga-invest.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 90 `<img
alt=""
class="image__img"
loading="lazy"
wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Giga_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…26/06/Giga_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 605 `<img
alt=""
class="image__img"
loading="lazy"
wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Giga_ehitus_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…iga_ehitus_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 629 `<img
alt=""
class="image__img"
loading="lazy"
wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Holttem_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…06/Holttem_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 654 `<img
alt=""
class="image__img"
loading="lazy"
wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/HUT_A_valge_v2.8.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…6/06/HUT_A_valge_v2.8.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 679 `<img
alt=""
class="image__img"
loading="lazy"
wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Villa_cartelloni_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…cartelloni_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 704 `<img
alt=""
class="image__img"
loading="lazy"
wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Hake_ja_kyte_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…ke_ja_kyte_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 729 `<img
alt=""
class="image__img"
loading="lazy"
wi`
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 815 `/noscript><script nowprocket type="text/javascript">var el`
- (×1) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 888 `</script>
<script type="text/rocketlazyloadscript" id="jquery-js" data-rocket-sr`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 1536 ms._
**Scoring:** 1 violations · 34 passes · critical 0 · serious 1 · moderate 0 · minor 0
### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
### Findings
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `.menu-item-543 > a[href$="arikinnisvara/"]`
- `.menu-item-544 > a[href$="elamukinnisvara/"]`
- `.menu-item-545 > a[href$="pakkumised/"]`
- `.menu-item-546 > .header-navigation__link[target="_self"]`
- `.menu-item-547 > .header-navigation__link[target="_self"]`
- … and 5 more nodes
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 1545 ms._
**Capture summary:** 0 console events · 0 mixed-content requests · 17 network requests · 748.2 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 647.1 KB |
| script | 3 | 45.5 KB |
| stylesheet | 3 | 33.8 KB |
| document | 1 | 15.8 KB |
| other | 1 | 6.0 KB |
| font | 2 | 0 B |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://fonts.googleapis.com — 2 requests, 0 B
**Slowest requests (top 5):**
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 50 ms, 0 B
- https://gigainvesteeringud.giga.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (script) — 50 ms, 7.9 KB
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js (script) — 50 ms, 32.8 KB
- https://gigainvesteeringud.giga.ee/wp-includes/js/jquery/jquery-migrate.min.js (script) — 49 ms, 4.8 KB
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 47 ms, 0 B
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 1545 ms._
**Document:**
- Lang: et
- Title: Giga Investeeringud
- Canonical: https://gigainvesteeringud.giga.ee/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 77369
**Meta tags:**
- Description: not set
- Robots: max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 0 (none)
- Twitter tags: 0
- hreflang:
- et → https://gigainvesteeringud.giga.ee
- JSON-LD: none
**Heading outline:**
- Counts: h1 ×1, h2 ×5, h3 ×5, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Äri- ja elamukinnisvara spetsialist
- h2: Giga Investeeringud tegeleb äri- ning elukondliku kinnisvara üürimise ja arendam
- h2: Giga arendused
- h3: Narva mnt. 124 kodud
- h3: Lõõtsa arendus
- h2: Giga Investeeringud kinnisvaraportfelli kuulub üle 20 ärihoone, üüritava kogupin
- h2: Ärikinnisvara objektid
- h3: Uus-Karlowa ärihooned (tulevane arendus)
- h3: Sadama kvartali äripinnad (tulevane arendus)
- h3: Meie äri- ja elamukinnisvara pakkumised
- h2: Kuulume Giga kontserni, mille koosseisus on lisaks meile 6 ettevõtet.
**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 15 total — 2 defer, 1 async, 0 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js (defer)
- https://gigainvesteeringud.giga.ee/wp-includes/js/jquery/jquery-migrate.min.js (defer)
- https://gigainvesteeringud.giga.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)
**Stylesheets:** 3 external, 4 inline (9.7 KB)
**Images:** 15 total — **0 without alt**, **0 without width/height**, 0 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| 00%2Fsvg%22%20viewBox%3D%220%200%2084%2055%22%3E%3C%2Fsvg%3E | _(empty)_ | 84×55 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20400%20170%22%3E%3C%2Fsvg%3E | _(empty)_ | 400×170 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20400%20250%22%3E%3C%2Fsvg%3E | _(empty)_ | 400×250 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20400%20250%22%3E%3C%2Fsvg%3E | _(empty)_ | 400×250 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20320%20240%22%3E%3C%2Fsvg%3E | _(empty)_ | 320×240 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20320%20240%22%3E%3C%2Fsvg%3E | _(empty)_ | 320×240 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20320%20240%22%3E%3C%2Fsvg%3E | _(empty)_ | 320×240 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20190%20106%22%3E%3C%2Fsvg%3E | _(empty)_ | 190×106 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20190%20106%22%3E%3C%2Fsvg%3E | _(empty)_ | 190×106 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20190%20106%22%3E%3C%2Fsvg%3E | _(empty)_ | 190×106 | lazy | ✓ |
| 0%2Fsvg%22%20viewBox%3D%220%200%20122%2048%22%3E%3C%2Fsvg%3E | _(empty)_ | 122×48 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20190%20106%22%3E%3C%2Fsvg%3E | _(empty)_ | 190×106 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20190%20106%22%3E%3C%2Fsvg%3E | _(empty)_ | 190×106 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20320%20180%22%3E%3C%2Fsvg%3E | _(empty)_ | 320×180 | lazy | ✓ |
| 00%2Fsvg%22%20viewBox%3D%220%200%2084%2055%22%3E%3C%2Fsvg%3E | _(empty)_ | 84×55 | lazy | ✓ |
**Links:** 39 anchors — 15 external, 1 preconnect, 1 preload.
Vague repeated link text:
- "pakkumised" ×3
- "töös arendused" ×2
- "ärikinnisvara" ×2
- "elamukinnisvara" ×2
- "uudised" ×2
- "meist" ×2
- "kontakt" ×2
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 2 pass · 0 warn · 0 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (15 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (15 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (15 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.23.3.3`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 2 of 5 — https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil
Run: 2026-08-31T08:14:05.390Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "upload"
- E-commerce: no
## PageSpeed Insights
_Captured in 14995 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **81** | 99 |
| Accessibility | **85** | 91 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **4.1 s** | 1.0 s |
| CLS | 0.000 | **0.000** |
| TBT | 0 ms | 0 ms |
| FCP | **3.04 s** | 678 ms |
| Speed Index | **3.20 s** | 678 ms |
| TTFB | **3 ms** | 2 ms |
### Priority fixes
1. **largest-contentful-paint** (high) — 4.1 s
2. **first-contentful-paint** (high) — 3.0 s
3. **document-latency-insight** (high) — Est savings of 190 ms
4. **image-delivery-insight** (high) — Est savings of 227 KiB
5. **network-dependency-tree-insight** (high)
### Findings (mobile)
#### Unused JavaScript
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js — 23 KB wasted
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.47, weight 25) — Largest Contentful Paint — 4.1 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.48, weight 10) — First Contentful Paint — 3.0 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.86, weight 0) — Time to Interactive — 4.2 s
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 93 ms._
**Transport:**
- Final URL: https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 31 Aug 2026 08:11:57 GMT
- expires: Mon, 31 Aug 2026 08:14:05 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 15904
- Decoded body: 73.6 KB
- Compression ratio: 0.211
### Priority fixes
1. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 15904
content-type: text/html; charset=UTF-8
date: Mon, 31 Aug 2026 08:14:05 GMT
expires: Mon, 31 Aug 2026 08:14:05 GMT
keep-alive: timeout=5, max=94
last-modified: Mon, 31 Aug 2026 08:11:57 GMT
server: Apache / ZoneOS
vary: Accept-Encoding
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1253 ms._
**Scoring:** 4 errors · 1 warnings · 16 cosmetic (suppressed)
### Priority fixes
1. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/giga-invest.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…s/2026/06/giga-invest.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x2, first at line 90
2. **The “sizes” attribute value starting with “auto” is only valid for lazy-loaded images. Add “loading=”“lazy” to this element.** (medium) — x1, first at line 252
3. **A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute.** (medium) — x1, first at line 733
### Issue groups
- (×2) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/giga-invest.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…s/2026/06/giga-invest.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 90 `<img
alt=""
class="image__img"
loading="lazy"
wi`
- (×1) [error] The “sizes” attribute value starting with “auto” is only valid for lazy-loaded images. Add “loading=”“lazy” to this element. — first at line 252 `<img fetchpriority="high" decoding="async"
alt=""
class="image__`
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 660 `/noscript><script nowprocket type="text/javascript">var el`
- (×1) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 733 `</script>
<script type="text/rocketlazyloadscript" id="jquery-js" data-rocket-sr`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 1536 ms._
**Scoring:** 2 violations · 36 passes · critical 0 · serious 2 · moderate 0 · minor 0
### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **link-name** (high) — Links must have discernible text
### Findings
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `.menu-item-543 > a[href$="arikinnisvara/"]`
- `.menu-item-544 > a[href$="elamukinnisvara/"]`
- `.menu-item-545 > a[href$="pakkumised/"]`
- `.current_page_parent > .header-navigation__link[target="_self"]`
- `.menu-item-547 > .header-navigation__link[target="_self"]`
- … and 2 more nodes
#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.gallery__main > .image--full > .image__link[data-fancybox="6a95374d28b8a"]`
- `.gallery__thumb:nth-child(1) > .image--full > .image__link[data-fancybox="6a95374d28b8a"]`
- `.gallery__thumb:nth-child(2) > .image--full > .image__link[data-fancybox="6a95374d28b8a"]`
- `.gallery__thumb:nth-child(3) > .image--full > .image__link[data-fancybox="6a95374d28b8a"]`
- `.gallery__thumb:nth-child(4) > .image--full > .image__link[data-fancybox="6a95374d28b8a"]`
### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 1547 ms._
**Capture summary:** 0 console events · 0 mixed-content requests · 23 network requests · 553.5 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 10 | 452.7 KB |
| script | 3 | 45.5 KB |
| stylesheet | 3 | 33.8 KB |
| document | 2 | 15.5 KB |
| other | 1 | 6.0 KB |
| font | 3 | 0 B |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://fonts.googleapis.com — 2 requests, 0 B
**Slowest requests (top 5):**
- https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil (document) — 107 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 54 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 47 ms, 0 B
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/fonts/AeonikPro-Bold.woff2 (font) — 27 ms, 0 B
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/fonts/AeonikPro-Medium.woff2 (font) — 27 ms, 0 B
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 1547 ms._
**Document:**
- Lang: et
- Title: Tutvustame uusi kodusid Raadil
- Canonical: https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 72364
**Meta tags:**
- Description: not set
- Robots: max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 0 (none)
- Twitter tags: 0
- hreflang:
- et → https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil
- JSON-LD: none
**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×3, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Tutvustame uusi kodusid Raadil
- h2: Vaata lisaks
- h3: Uus-Karlowa kvartal toob Emajõe kaldale 200 kodu ja uue promenaadi
- h3: Lõõtsa 6 ärihoone sarikapidu
- h3: Lõõtsa Ärikvartali esimest hoonet tähistati pidulikul avamisõhtul
**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 15 total — 2 defer, 1 async, 0 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js (defer)
- https://gigainvesteeringud.giga.ee/wp-includes/js/jquery/jquery-migrate.min.js (defer)
- https://gigainvesteeringud.giga.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)
**Stylesheets:** 3 external, 4 inline (9.7 KB)
**Images:** 15 total — **0 without alt**, **0 without width/height**, 1 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| 00%2Fsvg%22%20viewBox%3D%220%200%2084%2055%22%3E%3C%2Fsvg%3E | _(empty)_ | 84×55 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20280%20155%22%3E%3C%2Fsvg%3E | _(empty)_ | 280×155 | lazy | ✓ |
| ds/2026/06/gigainvesteeringud_narvamnt124_vaade1-320x240.jpg | _(empty)_ | 320×240 | eager | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20100%20100%22%3E%3C%2Fsvg%3E | _(empty)_ | 100×100 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20100%20100%22%3E%3C%2Fsvg%3E | _(empty)_ | 100×100 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20100%20100%22%3E%3C%2Fsvg%3E | _(empty)_ | 100×100 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20100%20100%22%3E%3C%2Fsvg%3E | _(empty)_ | 100×100 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20100%20100%22%3E%3C%2Fsvg%3E | _(empty)_ | 100×100 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20100%20100%22%3E%3C%2Fsvg%3E | _(empty)_ | 100×100 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20100%20100%22%3E%3C%2Fsvg%3E | _(empty)_ | 100×100 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20100%20100%22%3E%3C%2Fsvg%3E | _(empty)_ | 100×100 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20280%20155%22%3E%3C%2Fsvg%3E | _(empty)_ | 280×155 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20280%20155%22%3E%3C%2Fsvg%3E | _(empty)_ | 280×155 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20280%20155%22%3E%3C%2Fsvg%3E | _(empty)_ | 280×155 | lazy | ✓ |
| 00%2Fsvg%22%20viewBox%3D%220%200%2084%2055%22%3E%3C%2Fsvg%3E | _(empty)_ | 84×55 | lazy | ✓ |
**Links:** 40 anchors — 9 external, 1 preconnect, 1 preload.
Vague repeated link text:
- "töös arendused" ×2
- "ärikinnisvara" ×2
- "elamukinnisvara" ×2
- "pakkumised" ×2
- "uudised" ×2
- "meist" ×2
- "kontakt" ×2
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 4 pass · 0 warn · 0 fail · 3 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy" (14 SVGs excluded). |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 1 raster image on the page (14 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.23.3.3`
- Hero image eagerly loaded:
- `hero: …/wp-content/uploads/2026/06/gigainvesteeringud_narvamnt124_vaade1-320x240.jpg`
- `loading: eager`
- `fetchpriority: high`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 3 of 5 — https://gigainvesteeringud.giga.ee/test
Run: 2026-08-31T08:14:30.253Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 16638 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **87** | 100 |
| Accessibility | **94** | 95 |
| Best Practices | 96 | 96 |
| SEO | 83 | 83 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **3.2 s** | 0.4 s |
| CLS | **0.000** | 0.000 |
| TBT | 0 ms | 0 ms |
| FCP | **3.16 s** | 432 ms |
| Speed Index | **3.16 s** | 522 ms |
| TTFB | 2 ms | 2 ms |
### Priority fixes
1. **largest-contentful-paint** (medium) — 3.2 s
2. **first-contentful-paint** (high) — 3.2 s
3. **legacy-javascript-insight** (high) — Est savings of 13 KiB
4. **network-dependency-tree-insight** (high)
5. **render-blocking-insight** (high) — Est savings of 2,700 ms
### Findings (mobile)
#### Unused JavaScript
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/global.df676e5aea00c812.js — 113 KB wasted
#### Layout-shift sources
- div.grid > div.grid__col > div.footer__text > p — shift 0.000
#### Long tasks
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/global.df676e5aea00c812.js — 149 ms
- https://gigainvesteeringud.giga.ee/test — 102 ms
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js — 73 ms
- https://gigainvesteeringud.giga.ee/test — 53 ms
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `canonical`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
#### All failing PSI audits (sorted by weight × failure margin)
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `largest-contentful-paint` (performance, score 0.74, weight 25) — Largest Contentful Paint — 3.2 s
- `first-contentful-paint` (performance, score 0.44, weight 10) — First Contentful Paint — 3.2 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `http-status-code` (seo, score 0.00, weight 1) — Page has unsuccessful HTTP status code — 404
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 141 ms._
**Transport:**
- Final URL: https://gigainvesteeringud.giga.ee/test
- Status: 404
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `no-cache, must-revalidate, max-age=0, no-store, private`
- etag: n/a
- last-modified: n/a
- expires: Wed, 11 Jan 1984 05:00:00 GMT
- pragma: n/a
- vary: Accept-Encoding
- Issues:
- no-store directive (browser cannot cache document)
**Compression:**
- content-encoding: gzip
- content-length: 7733
- Decoded body: 31.4 KB
- Compression ratio: 0.24
### Priority fixes
1. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **cache-control: no-store on document** (high) — Browser cannot cache the document — every page view re-downloads everything
4. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
5. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
6. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
7. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
8. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
9. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
10. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: no-cache, must-revalidate, max-age=0, no-store, private
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 7733
content-type: text/html; charset=UTF-8
date: Mon, 31 Aug 2026 08:14:30 GMT
expires: Wed, 11 Jan 1984 05:00:00 GMT
keep-alive: timeout=5, max=100
link: <https://gigainvesteeringud.giga.ee/wp-json/>; rel="https://api.w.org/"
server: Apache / ZoneOS
vary: Accept-Encoding
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 952 ms._
**Scoring:** 1 errors · 0 warnings · 0 cosmetic (suppressed)
### Priority fixes
1. **HTTP resource not retrievable. The HTTP status from the remote server was: 404.** (medium) — x1, first at line 0
### Issue groups
- (×1) [error] HTTP resource not retrievable. The HTTP status from the remote server was: 404. — first at line 0
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 1247 ms._
**Scoring:** 1 violations · 34 passes · critical 0 · serious 1 · moderate 0 · minor 0
### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
### Findings
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `.menu-item-543 > a[href$="arikinnisvara/"]`
- `.menu-item-544 > a[href$="elamukinnisvara/"]`
- `.menu-item-545 > a[href$="pakkumised/"]`
- `.current_page_parent > .header-navigation__link[target="_self"]`
- `.menu-item-547 > .header-navigation__link[target="_self"]`
- … and 23 more nodes
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 1252 ms._
**Capture summary:** 1 console events · 0 mixed-content requests · 13 network requests · 89.8 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| script | 4 | 40.2 KB |
| stylesheet | 3 | 33.8 KB |
| document | 1 | 7.6 KB |
| other | 1 | 6.0 KB |
| image | 1 | 2.2 KB |
| font | 2 | 0 B |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://fonts.googleapis.com — 2 requests, 0 B
**Slowest requests (top 5):**
- https://gigainvesteeringud.giga.ee/test (document) — 120 ms, 7.6 KB
- https://fonts.googleapis.com/css?family=Open+Sans:400,400i,600,700,700i&display=swap&subset=cyrillic (stylesheet) — 49 ms, 0 B
- https://fonts.googleapis.com/css?family=Open+Sans:400,400i,600,700,700i&display=swap&subset=cyrillic (xhr) — 49 ms, 0 B
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/fonts/AeonikPro-Regular.woff2 (font) — 33 ms, 0 B
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/fonts/AeonikPro-Medium.woff2 (font) — 33 ms, 0 B
### Priority fixes
1. **console error** (medium) — Failed to load resource: the server responded with a status of 404 ()
### Findings
#### Console events
- [error] Failed to load resource: the server responded with a status of 404 () (https://gigainvesteeringud.giga.ee/test)
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 1252 ms._
**Document:**
- Lang: et
- Title: Lehte ei leitud
- Canonical: not set
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 31479
**Meta tags:**
- Description: not set
- Robots: max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 0 (none)
- Twitter tags: 0
- hreflang:
- et → https://gigainvesteeringud.giga.ee/test
- JSON-LD: none
**Heading outline:**
- Counts: h1 ×1, h2 ×0, h3 ×0, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Whoops, that page is gone.
**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 11 total — 0 defer, 0 async, 4 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/core.81daa612c4c401d9.js
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/global.df676e5aea00c812.js
- https://gigainvesteeringud.giga.ee/wp-includes/js/jquery/jquery-migrate.min.js
**Stylesheets:** 3 external, 4 inline (9.7 KB)
**Images:** 2 total — **0 without alt**, **0 without width/height**, 0 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| teeringud.giga.ee/wp-content/uploads/2026/06/giga-invest.svg | _(empty)_ | 84×55 | lazy | ✓ |
| teeringud.giga.ee/wp-content/uploads/2026/06/giga-invest.svg | _(empty)_ | 84×55 | lazy | ✓ |
**Links:** 27 anchors — 9 external, 1 preconnect, 0 preload.
Vague repeated link text:
- "töös arendused" ×2
- "ärikinnisvara" ×2
- "elamukinnisvara" ×2
- "pakkumised" ×2
- "uudised" ×2
- "meist" ×2
- "kontakt" ×2
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 2 pass · 0 warn · 0 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (2 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (2 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (2 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 4 of 5 — https://gigainvesteeringud.giga.ee/meist
Run: 2026-08-31T08:14:33.901Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 13816 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **73** | 99 |
| Accessibility | **89** | 95 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **5.8 s** | 0.7 s |
| CLS | 0.034 | **0.064** |
| TBT | 0 ms | 0 ms |
| FCP | **3.01 s** | 691 ms |
| Speed Index | **3.20 s** | 691 ms |
| TTFB | **3 ms** | 2 ms |
### Priority fixes
1. **largest-contentful-paint** (high) — 5.8 s
2. **first-contentful-paint** (high) — 3.0 s
3. **document-latency-insight** (high) — Est savings of 220 ms
4. **image-delivery-insight** (high) — Est savings of 452 KiB
5. **network-dependency-tree-insight** (high)
### Findings (mobile)
#### Unused JavaScript
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js — 23 KB wasted
#### Layout-shift sources
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.001
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.001
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.001
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.001
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.001
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.001
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.001
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.001
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.001
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.001
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.15, weight 25) — Largest Contentful Paint — 5.8 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.49, weight 10) — First Contentful Paint — 3.0 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.65, weight 0) — Time to Interactive — 5.9 s
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 244 ms._
**Transport:**
- Final URL: https://gigainvesteeringud.giga.ee/meist/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 31 Aug 2026 08:14:34 GMT
- expires: Mon, 31 Aug 2026 08:14:33 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 15867
- Decoded body: 72.3 KB
- Compression ratio: 0.214
### Priority fixes
1. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 15867
content-type: text/html; charset=UTF-8
date: Mon, 31 Aug 2026 08:14:33 GMT
expires: Mon, 31 Aug 2026 08:14:33 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 31 Aug 2026 08:14:34 GMT
link: <https://gigainvesteeringud.giga.ee/wp-json/>; rel="https://api.w.org/", <https://gigainvesteeringud.giga.ee/wp-json/wp/v2/pages/288>; rel="alternate"; title="JSON"; type="application/json", <https://gigainvesteeringud.giga.ee/?p=288>; rel=shortlink
server: Apache / ZoneOS
vary: Accept-Encoding
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 896 ms._
**Scoring:** 9 errors · 1 warnings · 16 cosmetic (suppressed)
### Priority fixes
1. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/giga-invest.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…s/2026/06/giga-invest.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x2, first at line 90
2. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Giga_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…26/06/Giga_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x1, first at line 308
3. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Giga_ehitus_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…iga_ehitus_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x1, first at line 332
4. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Holttem_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…06/Holttem_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x1, first at line 357
5. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/HUT_A_valge_v2.7.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…6/06/HUT_A_valge_v2.7.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x1, first at line 382
### Issue groups
- (×2) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/giga-invest.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…s/2026/06/giga-invest.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 90 `<img
alt=""
class="image__img"
loading="lazy"
wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Giga_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…26/06/Giga_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 308 `<img
alt=""
class="image__img"
loading="lazy"
wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Giga_ehitus_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…iga_ehitus_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 332 `<img
alt=""
class="image__img"
loading="lazy"
wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Holttem_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…06/Holttem_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 357 `<img
alt=""
class="image__img"
loading="lazy"
wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/HUT_A_valge_v2.7.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…6/06/HUT_A_valge_v2.7.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 382 `<img
alt=""
class="image__img"
loading="lazy"
wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Villa_cartelloni_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…cartelloni_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 407 `<img
alt=""
class="image__img"
loading="lazy"
wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Hake_ja_kyte_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…ke_ja_kyte_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 432 `<img
alt=""
class="image__img"
loading="lazy"
wi`
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 727 `/noscript><script nowprocket type="text/javascript">var el`
- (×1) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 800 `</script>
<script type="text/rocketlazyloadscript" id="jquery-js" data-rocket-sr`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 1527 ms._
**Scoring:** 1 violations · 35 passes · critical 0 · serious 1 · moderate 0 · minor 0
### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
### Findings
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `.menu-item-543 > a[href$="arikinnisvara/"]`
- `.menu-item-544 > a[href$="elamukinnisvara/"]`
- `.menu-item-545 > a[href$="pakkumised/"]`
- `.menu-item-546 > .header-navigation__link[target="_self"]`
- `.menu-item-548 > .header-navigation__link[target="_self"]`
- … and 4 more nodes
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 1541 ms._
**Capture summary:** 0 console events · 0 mixed-content requests · 24 network requests · 761.7 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 11 | 660.9 KB |
| script | 3 | 45.5 KB |
| stylesheet | 3 | 33.8 KB |
| document | 2 | 15.5 KB |
| other | 1 | 6.0 KB |
| font | 3 | 0 B |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://fonts.googleapis.com — 2 requests, 0 B
**Slowest requests (top 5):**
- https://gigainvesteeringud.giga.ee/meist/ (document) — 168 ms, 15.5 KB
- https://gigainvesteeringud.giga.ee/meist (document) — 98 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 58 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 46 ms, 0 B
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/fonts/AeonikPro-Bold.woff2 (font) — 35 ms, 0 B
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 1540 ms._
**Document:**
- Lang: et
- Title: Meist
- Canonical: https://gigainvesteeringud.giga.ee/meist/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 71772
**Meta tags:**
- Description: not set
- Robots: max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 0 (none)
- Twitter tags: 0
- hreflang:
- et → https://gigainvesteeringud.giga.ee/meist
- JSON-LD: none
**Heading outline:**
- Counts: h1 ×1, h2 ×3, h3 ×4, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Äri- ja elamukinnisvara spetsialist
- h2: Giga Investeeringud on ambitsioonikas äri- ja elamukinnisvara arendaja, üürilean
- h3: Giga kinnisvaraportfelli kuulub enam kui 20 ärihoonet, üüritava kogupinnaga üle
- h2: Kuulume Giga kontserni, kus on kokku 6 sihikindlat ja tugevat ettevõtet.
- h2: Ärikinnisvara objektid
- h3: Uus-Karlowa ärihooned (tulevane arendus)
- h3: Sadama kvartali äripinnad (tulevane arendus)
- h3: Tutvu meie äri- ja eramukinnisvara pakkumistega
**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 15 total — 2 defer, 1 async, 0 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js (defer)
- https://gigainvesteeringud.giga.ee/wp-includes/js/jquery/jquery-migrate.min.js (defer)
- https://gigainvesteeringud.giga.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)
**Stylesheets:** 3 external, 4 inline (9.7 KB)
**Images:** 14 total — **0 without alt**, **0 without width/height**, 0 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| 00%2Fsvg%22%20viewBox%3D%220%200%2084%2055%22%3E%3C%2Fsvg%3E | _(empty)_ | 84×55 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20400%20283%22%3E%3C%2Fsvg%3E | _(empty)_ | 400×283 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20320%20240%22%3E%3C%2Fsvg%3E | _(empty)_ | 320×240 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20190%20106%22%3E%3C%2Fsvg%3E | _(empty)_ | 190×106 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20190%20106%22%3E%3C%2Fsvg%3E | _(empty)_ | 190×106 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20190%20106%22%3E%3C%2Fsvg%3E | _(empty)_ | 190×106 | lazy | ✓ |
| 0%2Fsvg%22%20viewBox%3D%220%200%20122%2048%22%3E%3C%2Fsvg%3E | _(empty)_ | 122×48 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20190%20106%22%3E%3C%2Fsvg%3E | _(empty)_ | 190×106 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20190%20106%22%3E%3C%2Fsvg%3E | _(empty)_ | 190×106 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20320%20240%22%3E%3C%2Fsvg%3E | _(empty)_ | 320×240 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20320%20240%22%3E%3C%2Fsvg%3E | _(empty)_ | 320×240 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20320%20240%22%3E%3C%2Fsvg%3E | _(empty)_ | 320×240 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20320%20180%22%3E%3C%2Fsvg%3E | _(empty)_ | 320×180 | lazy | ✓ |
| 00%2Fsvg%22%20viewBox%3D%220%200%2084%2055%22%3E%3C%2Fsvg%3E | _(empty)_ | 84×55 | lazy | ✓ |
**Links:** 38 anchors — 14 external, 1 preconnect, 1 preload.
Vague repeated link text:
- "ärikinnisvara" ×3
- "elamukinnisvara" ×3
- "töös arendused" ×2
- "pakkumised" ×2
- "uudised" ×2
- "meist" ×2
- "kontakt" ×2
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 2 pass · 0 warn · 0 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (14 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (14 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (14 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.23.3.3`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 5 of 5 — https://gigainvesteeringud.giga.ee/kinnitus
Run: 2026-08-31T08:14:57.802Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 13637 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **97** | 98 |
| Accessibility | **94** | 95 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **1.9 s** | 0.6 s |
| CLS | 0.090 | **0.090** |
| TBT | 0 ms | 0 ms |
| FCP | **1.70 s** | 524 ms |
| Speed Index | **1.70 s** | 524 ms |
| TTFB | **3 ms** | 2 ms |
### Priority fixes
1. **document-latency-insight** (high) — Est savings of 220 ms
2. **network-dependency-tree-insight** (high)
3. **render-blocking-insight** (high) — Est savings of 40 ms
4. **unused-css-rules** (high) — Est savings of 32 KiB
5. **unused-javascript** (medium) — Est savings of 23 KiB
### Findings (mobile)
#### Unused JavaScript
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js — 23 KB wasted
#### Layout-shift sources
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 223 ms._
**Transport:**
- Final URL: https://gigainvesteeringud.giga.ee/kinnitus/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 31 Aug 2026 08:14:58 GMT
- expires: Mon, 31 Aug 2026 08:14:57 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 13014
- Decoded body: 50.4 KB
- Compression ratio: 0.252
### Priority fixes
1. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 13014
content-type: text/html; charset=UTF-8
date: Mon, 31 Aug 2026 08:14:57 GMT
expires: Mon, 31 Aug 2026 08:14:57 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 31 Aug 2026 08:14:58 GMT
link: <https://gigainvesteeringud.giga.ee/wp-json/>; rel="https://api.w.org/", <https://gigainvesteeringud.giga.ee/wp-json/wp/v2/pages/290>; rel="alternate"; title="JSON"; type="application/json", <https://gigainvesteeringud.giga.ee/?p=290>; rel=shortlink
server: Apache / ZoneOS
vary: Accept-Encoding
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 788 ms._
**Scoring:** 3 errors · 1 warnings · 16 cosmetic (suppressed)
### Priority fixes
1. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/giga-invest.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…s/2026/06/giga-invest.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x2, first at line 90
2. **A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute.** (medium) — x1, first at line 338
### Issue groups
- (×2) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/giga-invest.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…s/2026/06/giga-invest.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 90 `<img
alt=""
class="image__img"
loading="lazy"
wi`
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 265 `/noscript><script nowprocket type="text/javascript">var el`
- (×1) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 338 `</script>
<script type="text/rocketlazyloadscript" id="jquery-js" data-rocket-sr`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 1302 ms._
**Scoring:** 1 violations · 34 passes · critical 0 · serious 1 · moderate 0 · minor 0
### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
### Findings
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `.menu-item-543 > a[href$="arikinnisvara/"]`
- `.menu-item-544 > a[href$="elamukinnisvara/"]`
- `.menu-item-545 > a[href$="pakkumised/"]`
- `.menu-item-546 > .header-navigation__link[target="_self"]`
- `.menu-item-547 > .header-navigation__link[target="_self"]`
- … and 1 more nodes
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 1311 ms._
**Capture summary:** 0 console events · 0 mixed-content requests · 14 network requests · 162.3 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 2 | 64.3 KB |
| script | 3 | 45.5 KB |
| stylesheet | 3 | 33.8 KB |
| document | 2 | 12.7 KB |
| other | 1 | 6.0 KB |
| font | 2 | 0 B |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://fonts.googleapis.com — 2 requests, 0 B
**Slowest requests (top 5):**
- https://gigainvesteeringud.giga.ee/kinnitus/ (document) — 130 ms, 12.7 KB
- https://gigainvesteeringud.giga.ee/kinnitus (document) — 94 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 51 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 45 ms, 0 B
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/fonts/AeonikPro-Medium.woff2 (font) — 23 ms, 0 B
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 1311 ms._
**Document:**
- Lang: et
- Title: Kinnitus
- Canonical: https://gigainvesteeringud.giga.ee/kinnitus/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 50647
**Meta tags:**
- Description: not set
- Robots: max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 0 (none)
- Twitter tags: 0
- hreflang:
- et → https://gigainvesteeringud.giga.ee/kinnitus
- JSON-LD: none
**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×0, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Kiri on edukalt saadetud
- h2: Võtame teiega ühendust esimesel võimalusel.
**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 15 total — 2 defer, 1 async, 0 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js (defer)
- https://gigainvesteeringud.giga.ee/wp-includes/js/jquery/jquery-migrate.min.js (defer)
- https://gigainvesteeringud.giga.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)
**Stylesheets:** 3 external, 4 inline (9.7 KB)
**Images:** 3 total — **0 without alt**, **0 without width/height**, 0 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| 00%2Fsvg%22%20viewBox%3D%220%200%2084%2055%22%3E%3C%2Fsvg%3E | _(empty)_ | 84×55 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20400%20225%22%3E%3C%2Fsvg%3E | _(empty)_ | 400×225 | lazy | ✓ |
| 00%2Fsvg%22%20viewBox%3D%220%200%2084%2055%22%3E%3C%2Fsvg%3E | _(empty)_ | 84×55 | lazy | ✓ |
**Links:** 27 anchors — 9 external, 1 preconnect, 1 preload.
Vague repeated link text:
- "töös arendused" ×2
- "ärikinnisvara" ×2
- "elamukinnisvara" ×2
- "pakkumised" ×2
- "uudised" ×2
- "meist" ×2
- "kontakt" ×2
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 2 pass · 0 warn · 0 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (3 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (3 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (3 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.23.3.3`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).