Audit

20260831T081404Z-ffe7

← Back to gigainvesteeringudgigaee
Audited URL
https://gigainvesteeringud.giga.ee/
Timestamp
2026-08-31T08:27:48.404Z
Kind
site
Pages
5
Audit summary
https://gigainvesteeringud.giga.ee/
5 of 5 pages audited
Pagespeed scores
Other checks
LLM Report

Weighted audit summary

73
Overall site quality
Needs Improvementhigh confidence

Site overall 73 is the mean of 5 pages. Scores range 68 (https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil) → 87 (https://gigainvesteeringud.giga.ee/). Weakest page: Mobile performance is the primary constraint with an LCP of 4.1 s and FCP of 3.04 s, both exceeding recommended thresholds. Security posture is critically weak with a 0/100 header score, missing HSTS and CSP despite user-generated content signals. Accessibility has two serious axe violations regarding color contrast and link names that require immediate remediation. HTML validation errors in `srcset` and script attributes further degrade code quality. SEO is hindered by missing meta descriptions and structured data.

Per-page scores
87
Home
high
68
…ame-uusi-kodusid-raadil
high
68
/test
high
68
/meist
high
76
/kinnitus
high

Audit Report: Giga Investeeringud

Website: https://gigainvesteeringud.giga.ee/
Date: 31.08.2026
Audit Coverage: 100% — all sources returned data
Confidence: high

Pages Audited (5 of 5):

Summary of results

Overall Score: 73 / 100
Status: 🟡 Needs Improvement

Site overall 73 is the mean of 5 pages. Scores range 68 (https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil) → 87 (https://gigainvesteeringud.giga.ee/). Weakest page: Mobile performance is the primary constraint with an LCP of 4.1 s and FCP of 3.04 s, both exceeding recommended thresholds. Security posture is critically weak with a 0/100 header score, missing HSTS and CSP despite user-generated content signals. Accessibility has two serious axe violations regarding color contrast and link names that require immediate remediation. HTML validation errors in srcset and script attributes further degrade code quality. SEO is hindered by missing meta descriptions and structured data.

Per-page scores

🟡 Needs Improvement · https://gigainvesteeringud.giga.ee/

Score Performance Accessibility Best Practices SEO Security
87 97 89 100 92 0

🟡 Needs Improvement · https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil

Score Performance Accessibility Best Practices SEO Security
68 81 85 100 92 0

🟡 Needs Improvement · https://gigainvesteeringud.giga.ee/test

Score Performance Accessibility Best Practices SEO Security
68 87 94 96 83 0

🟡 Needs Improvement · https://gigainvesteeringud.giga.ee/meist

Score Performance Accessibility Best Practices SEO Security
68 73 89 100 92 0

🟡 Needs Improvement · https://gigainvesteeringud.giga.ee/kinnitus

Score Performance Accessibility Best Practices SEO Security
76 97 94 100 92 0

PageSpeed Insights — Mobile vs Desktop

Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.

URL Performance (M / D) LCP (M / D) CLS (M / D)
https://gigainvesteeringud.giga.ee/ 97 / 98 1.95 s / 446 ms 0.090 / 0.090
https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil 81 / 99 4.10 s / 995 ms 0.000 / 0.000
https://gigainvesteeringud.giga.ee/test 87 / 100 3.16 s / 432 ms 0.000 / 0.000
https://gigainvesteeringud.giga.ee/meist 73 / 99 5.80 s / 732 ms 0.034 / 0.064
https://gigainvesteeringud.giga.ee/kinnitus 97 / 98 1.86 s / 564 ms 0.090 / 0.090

Optimization Checklist

2 of 2 passing — 2 pass · 0 warn · 0 fail · 5 n/a

Item Status Detail
Page caching plugin / CDN active Pass Caching plugin detected (WP Rocket)
Images lazy-loaded N/A No raster <img> elements found (15 SVGs excluded).
Hero image eagerly loaded N/A No raster <img> elements found (15 SVGs excluded).
Hero is a real <img> (not a CSS background-image) N/A No CSS background-images detected on raster-image-eligible elements.
Responsive images (srcset / <picture>) N/A Only 0 raster images on the page (15 SVGs excluded) — responsive-image rule does not apply.
Reasonable number of image sizes N/A Too few raster images to evaluate srcset width variety.
JS scripts not blocking in <head> Pass No render-blocking scripts in <head>.

Fixes

Priority 1: Critical

Immediate action — impacts user experience, search rankings, or site safety.

1A. Add HSTS and X-Content-Type-Options headers Security

  • Impact: Transport security, MIME sniffing protection
  • Problem: Security Headers grade is 0/100; HSTS and X-Content-Type-Options are missing despite HTTPS being enabled.
  • Solution: Add the following headers to your server configuration (Apache example):
    Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
    Header always set X-Content-Type-Options "nosniff"
    

1B. Fix color contrast on navigation links Accessibility

  • Impact: WCAG 1.4.3 Compliance, Screen Reader usability
  • Problem: axe-core reports 1 serious violation: color-contrast on multiple menu items (e.g., .menu-item-543).
  • Solution: Increase the contrast ratio between text and background to at least 4.5:1. Adjust CSS for .menu-item-543 > a and similar selectors to use darker text or lighter backgrounds.

1C. Implement Critical Security Headers (HSTS, CSP) Security

  • Impact: Transport security, XSS defense
  • Problem: Security Headers grade is 0/100; HSTS and CSP are missing. Site signals indicate user-generated content (upload anchor), elevating XSS risk.
  • Solution: Add HSTS with preload and a strict CSP:
    Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
    Content-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';
    

1D. Optimize Largest Contentful Paint (LCP) Performance

  • Impact: LCP 4.1 s, FCP 3.04 s
  • Problem: Mobile LCP is 4.1 s (heavy penalty zone >4 s) and FCP is 3.04 s. Unused JS (23 KB) and image delivery (227 KiB savings) identified.
  • Solution:
    • Preload LCP image resource.
    • Defer unused JavaScript (jquery.7e52f38a196e6397.js).
    • Optimize image delivery (227 KiB savings potential).

1E. Resolve 404 Status Code SEO

  • Impact: SEO, User Experience
  • Problem: W3C, PSI, and Browser Runtime all confirm the URL returns HTTP 404 (Page Not Found).
  • Solution: Ensure the target URL returns a 200 OK status if content is intended to be live. If this is a test page, do not index it (add noindex meta tag) or move it to a staging environment.

Priority 2: Important

Essential for compliance, user reach, and search visibility.

2A. Add a meta description SEO

  • Impact: Search result click-through rate, SEO audit score
  • Problem: Lighthouse SEO audit fails metaDescription; HTML Inventory confirms Description meta tag is not set.
  • Solution: Add a concise description (150–160 characters) in the <head>:
    <meta name="description" content="Giga Investeeringud – Äri- ja elamukinnisvara spetsialist. Uurige meie pakkumisi ja arendusi.">
    

2B. Fix srcset width descriptors on SVGs Best Practices

  • Impact: HTML Validation, Image rendering consistency
  • Problem: W3C Validator reports 9 errors where srcset lacks width specifications (e.g., giga-invest.svg) while sizes is present.
  • Solution: Update <img> tags to include width descriptors in srcset (e.g., srcset="image.svg 100w") or remove sizes if not needed for SVGs.

2C. Fix Color Contrast and Link Names Accessibility

  • Impact: WCAG 1.4.3, 2.4.4 compliance
  • Problem: axe-core reports 2 serious violations: color-contrast on menu links and link-name on gallery images.
  • Solution:
    • Increase contrast ratio on .menu-item-543 links to ≥4.5:1.
    • Add aria-label or visible text to gallery links (e.g., data-fancybox elements).

2D. Resolve W3C HTML Validation Errors Best Practices

  • Impact: Code quality, rendering consistency
  • Problem: 4 errors found: srcset missing width (x2), sizes 'auto' without loading='lazy', and invalid script type/defer combination.
  • Solution:
    • Add width descriptors to srcset (e.g., 100w).
    • Add loading="lazy" to images with sizes="auto".
    • Remove defer from non-JS script types or correct MIME type.

2E. Add Baseline Security Headers Security

  • Impact: Transport security, clickjacking, MIME sniffing
  • Problem: Security Headers grade is 0/100. HSTS, X-Frame-Options, and X-Content-Type-Options are missing.
  • Solution: Send the following headers from the server (Apache example):
    Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
    Header always set X-Content-Type-Options "nosniff"
    Header always set X-Frame-Options "SAMEORIGIN"
    

2F. Enable Browser Caching Performance

  • Impact: Repeat visit load time, TTFB
  • Problem: Cache-Control header is set to no-store, no-cache, max-age=0, preventing the browser from caching the document despite WP Rocket being active.
  • Solution: Update server configuration to allow caching for static assets and the document itself (e.g., Cache-Control: public, max-age=31536000 for assets, max-age=600 for HTML).

2G. Fix Color Contrast on Navigation Accessibility

  • Impact: WCAG 1.4.3 Contrast
  • Problem: axe-core reports a serious color-contrast violation on 23+ nodes, including menu links like .menu-item-543.
  • Solution: Increase the contrast ratio of text against its background to at least 4.5:1. Adjust CSS for .menu-item-543 > a and similar classes.

2H. Implement Baseline Security Headers Security

  • Impact: Transport security, clickjacking protection, MIME sniffing
  • Problem: Security Headers grade is 0/100; HSTS, X-Frame-Options, and X-Content-Type-Options are missing despite HTTPS being active.
  • Solution: Add the following headers to the server configuration (Apache example):
    Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
    Header always set X-Frame-Options "SAMEORIGIN"
    Header always set X-Content-Type-Options "nosniff"
    

2I. Fix Color Contrast on Navigation Links Accessibility

  • Impact: WCAG 1.4.3 (Contrast), Accessibility Score
  • Problem: axe-core reports 1 serious violation: multiple menu links (e.g., .menu-item-543 > a) fail minimum contrast ratios.
  • Solution:
    • Increase text color luminance or darken background for affected links.
    • Target a contrast ratio of at least 4.5:1 for normal text.
    • Verify changes with a contrast checker tool before deployment.

2J. Add baseline security headers (HSTS, X-Content-Type-Options, X-Frame-Options) Security

  • Impact: Transport security, clickjacking protection, MIME sniffing
  • Problem: Security Headers grade is 0/100; HSTS, X-Content-Type-Options, and X-Frame-Options are missing.
  • Solution: Configure server to send:
    Strict-Transport-Security: max-age=63072000; includeSubDomains
    X-Content-Type-Options: nosniff
    X-Frame-Options: SAMEORIGIN
    

2K. Provide accessible names for buttons Accessibility

  • Impact: WCAG 4.1.2 Name, Role, Value
  • Problem: PSI failing audit button-name (score 0.00) indicates buttons lack accessible names.
  • Solution: Ensure all <button> elements have visible text or aria-label attributes describing their action.

2L. Add meta description and structured data SEO

  • Impact: Search snippet quality, rich results eligibility
  • Problem: PSI SEO audit fails metaDescription and structuredData; HTML Inventory confirms no meta description or JSON-LD.
  • Solution: Add <meta name="description" content="..."> and implement relevant JSON-LD (e.g., Organization or WebPage).

Priority 3: Best Practice

Recommended for long-term maintainability.

3A. Implement Content-Security-Policy (CSP) Security

  • Impact: XSS defense-in-depth
  • Problem: CSP is missing. Site signals show no auth/payments, so risk is lower, but CSP is still a best practice.
  • Solution: Deploy a restrictive CSP with nonces for scripts:
    Header always set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';"
    

3B. Add Meta Description and Structured Data SEO

  • Impact: Search snippet quality, rich results
  • Problem: SEO audit fails metaDescription and structuredData; HTML inventory confirms no JSON-LD or meta description.
  • Solution:
    • Add <meta name="description" content="..."> summarizing the Raadi homes article.
    • Implement Article or NewsArticle JSON-LD schema.

3C. Implement Content Security Policy (CSP) Security

  • Impact: XSS defense-in-depth
  • Problem: CSP is missing. Site signals indicate no auth, payments, or user content, lowering immediate risk but CSP remains best practice.
  • Solution: Deploy a strict CSP with nonces for scripts. Example:
    Content-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';
    

3D. Add Meta Description and Open Graph Tags SEO

  • Impact: Search snippet quality, Social sharing
  • Problem: HTML Inventory shows no meta description, no Open Graph tags, and no Twitter tags; PSI SEO audit flags metaDescription as failing.
  • Solution: Add to <head>:
    <meta name="description" content="Giga Investeeringud on ambitsioonikas äri- ja elamukinnisvara arendaja.">
    <meta property="og:title" content="Meist - Giga Investeeringud">
    <meta property="og:description" content="...">
    <meta property="og:image" content="/path/to/og-image.jpg">
    

3E. Fix W3C srcset Width Errors Best Practices

  • Impact: HTML Validity, Image Rendering
  • Problem: W3C Validator reports 7 errors where srcset attributes lack width descriptors (e.g., 100w) while sizes is present.
  • Solution: Update <img> tags to include width descriptors in srcset:
    <!-- Incorrect -->
    <img srcset="/img.svg" sizes="100vw">
    
    <!-- Correct -->
    <img srcset="/img.svg 100w" sizes="100vw">
    

3F. Consider Content-Security-Policy (CSP) Security

  • Impact: XSS defense-in-depth
  • Problem: CSP is missing. Site signals indicate no auth, payments, or user content, lowering immediate risk but CSP remains a best practice.
  • Solution: If user content or login is added later, deploy a nonce-based CSP:
    Header always set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'"
    
    For now, prioritize P1/P2 fixes.
▸Raw Markdown sent to the LLM
# Site Audit — https://gigainvesteeringud.giga.ee/
Run: 2026-08-31T08:14:04.626Z

Audited **5** of 5 discovered pages.
Average per-page audit coverage: **100%**

Pages audited:
- https://gigainvesteeringud.giga.ee/
- https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil
- https://gigainvesteeringud.giga.ee/test
- https://gigainvesteeringud.giga.ee/meist
- https://gigainvesteeringud.giga.ee/kinnitus

---

# Page 1 of 5 — https://gigainvesteeringud.giga.ee/

Run: 2026-08-31T08:14:05.388Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 16229 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **97** | 98 |
| Accessibility | **89** | 95 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **2.0 s** | 0.4 s |
| CLS | **0.090** | 0.090 |
| TBT | 0 ms | 0 ms |
| FCP | **1.66 s** | 446 ms |
| Speed Index | **1.66 s** | 792 ms |
| TTFB | 3 ms | 3 ms |

### Priority fixes
1. **image-delivery-insight** (medium) — Est savings of 773 KiB
2. **network-dependency-tree-insight** (high)
3. **render-blocking-insight** (high) — Est savings of 190 ms
4. **unused-css-rules** (high) — Est savings of 31 KiB
5. **unused-javascript** (high) — Est savings of 23 KiB

### Findings (mobile)

#### Unused JavaScript
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js — 23 KB wasted

#### Layout-shift sources
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 12 ms._

**Transport:**
- Final URL: https://gigainvesteeringud.giga.ee/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 31 Aug 2026 08:14:05 GMT
- expires: Mon, 31 Aug 2026 08:14:05 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 16129
- Decoded body: 77.9 KB
- Compression ratio: 0.202

### Priority fixes
1. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 16129
content-type: text/html; charset=UTF-8
date: Mon, 31 Aug 2026 08:14:05 GMT
expires: Mon, 31 Aug 2026 08:14:05 GMT
keep-alive: timeout=5, max=95
last-modified: Mon, 31 Aug 2026 08:14:05 GMT
server: Apache / ZoneOS
vary: Accept-Encoding
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 911 ms._

**Scoring:** 9 errors · 1 warnings · 16 cosmetic (suppressed)

### Priority fixes
1. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/giga-invest.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…s/2026/06/giga-invest.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x2, first at line 90
2. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Giga_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…26/06/Giga_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x1, first at line 605
3. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Giga_ehitus_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…iga_ehitus_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x1, first at line 629
4. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Holttem_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…06/Holttem_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x1, first at line 654
5. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/HUT_A_valge_v2.8.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…6/06/HUT_A_valge_v2.8.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x1, first at line 679

### Issue groups
- (×2) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/giga-invest.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…s/2026/06/giga-invest.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 90 `<img
        alt=""
        class="image__img"
        loading="lazy"
        wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Giga_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…26/06/Giga_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 605 `<img
        alt=""
        class="image__img"
        loading="lazy"
        wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Giga_ehitus_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…iga_ehitus_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 629 `<img
        alt=""
        class="image__img"
        loading="lazy"
        wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Holttem_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…06/Holttem_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 654 `<img
        alt=""
        class="image__img"
        loading="lazy"
        wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/HUT_A_valge_v2.8.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…6/06/HUT_A_valge_v2.8.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 679 `<img
        alt=""
        class="image__img"
        loading="lazy"
        wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Villa_cartelloni_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…cartelloni_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 704 `<img
        alt=""
        class="image__img"
        loading="lazy"
        wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Hake_ja_kyte_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…ke_ja_kyte_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 729 `<img
        alt=""
        class="image__img"
        loading="lazy"
        wi`
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 815 `/noscript><script nowprocket type="text/javascript">var el`
- (×1) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 888 `</script>
<script type="text/rocketlazyloadscript" id="jquery-js" data-rocket-sr`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 1536 ms._

**Scoring:** 1 violations · 34 passes · critical 0 · serious 1 · moderate 0 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `.menu-item-543 > a[href$="arikinnisvara/"]`
- `.menu-item-544 > a[href$="elamukinnisvara/"]`
- `.menu-item-545 > a[href$="pakkumised/"]`
- `.menu-item-546 > .header-navigation__link[target="_self"]`
- `.menu-item-547 > .header-navigation__link[target="_self"]`
- … and 5 more nodes

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 1545 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 17 network requests · 748.2 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 647.1 KB |
| script | 3 | 45.5 KB |
| stylesheet | 3 | 33.8 KB |
| document | 1 | 15.8 KB |
| other | 1 | 6.0 KB |
| font | 2 | 0 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://fonts.googleapis.com — 2 requests, 0 B

**Slowest requests (top 5):**
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 50 ms, 0 B
- https://gigainvesteeringud.giga.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (script) — 50 ms, 7.9 KB
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js (script) — 50 ms, 32.8 KB
- https://gigainvesteeringud.giga.ee/wp-includes/js/jquery/jquery-migrate.min.js (script) — 49 ms, 4.8 KB
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 47 ms, 0 B

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 1545 ms._

**Document:**
- Lang: et
- Title: Giga Investeeringud
- Canonical: https://gigainvesteeringud.giga.ee/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 77369

**Meta tags:**
- Description: not set
- Robots: max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 0 (none)
- Twitter tags: 0
- hreflang:
  - et → https://gigainvesteeringud.giga.ee
- JSON-LD: none

**Heading outline:**
- Counts: h1 ×1, h2 ×5, h3 ×5, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Äri- ja elamukinnisvara spetsialist
  - h2: Giga Investeeringud tegeleb äri- ning elukondliku kinnisvara üürimise ja arendam
  - h2: Giga arendused
  - h3: Narva mnt. 124 kodud
  - h3: Lõõtsa arendus
  - h2: Giga Investeeringud kinnisvaraportfelli kuulub üle 20 ärihoone, üüritava kogupin
  - h2: Ärikinnisvara objektid
  - h3: Uus-Karlowa ärihooned (tulevane arendus)
  - h3: Sadama kvartali äripinnad (tulevane arendus)
  - h3: Meie äri- ja elamukinnisvara pakkumised
  - h2: Kuulume Giga kontserni, mille koosseisus on lisaks meile 6 ettevõtet.

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 15 total — 2 defer, 1 async, 0 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js (defer)
- https://gigainvesteeringud.giga.ee/wp-includes/js/jquery/jquery-migrate.min.js (defer)
- https://gigainvesteeringud.giga.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)

**Stylesheets:** 3 external, 4 inline (9.7 KB)

**Images:** 15 total — **0 without alt**, **0 without width/height**, 0 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| 00%2Fsvg%22%20viewBox%3D%220%200%2084%2055%22%3E%3C%2Fsvg%3E | _(empty)_ | 84×55 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20400%20170%22%3E%3C%2Fsvg%3E | _(empty)_ | 400×170 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20400%20250%22%3E%3C%2Fsvg%3E | _(empty)_ | 400×250 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20400%20250%22%3E%3C%2Fsvg%3E | _(empty)_ | 400×250 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20320%20240%22%3E%3C%2Fsvg%3E | _(empty)_ | 320×240 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20320%20240%22%3E%3C%2Fsvg%3E | _(empty)_ | 320×240 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20320%20240%22%3E%3C%2Fsvg%3E | _(empty)_ | 320×240 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20190%20106%22%3E%3C%2Fsvg%3E | _(empty)_ | 190×106 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20190%20106%22%3E%3C%2Fsvg%3E | _(empty)_ | 190×106 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20190%20106%22%3E%3C%2Fsvg%3E | _(empty)_ | 190×106 | lazy | ✓ |
| 0%2Fsvg%22%20viewBox%3D%220%200%20122%2048%22%3E%3C%2Fsvg%3E | _(empty)_ | 122×48 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20190%20106%22%3E%3C%2Fsvg%3E | _(empty)_ | 190×106 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20190%20106%22%3E%3C%2Fsvg%3E | _(empty)_ | 190×106 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20320%20180%22%3E%3C%2Fsvg%3E | _(empty)_ | 320×180 | lazy | ✓ |
| 00%2Fsvg%22%20viewBox%3D%220%200%2084%2055%22%3E%3C%2Fsvg%3E | _(empty)_ | 84×55 | lazy | ✓ |

**Links:** 39 anchors — 15 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "pakkumised" ×3
- "töös arendused" ×2
- "ärikinnisvara" ×2
- "elamukinnisvara" ×2
- "uudised" ×2
- "meist" ×2
- "kontakt" ×2

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 2 pass · 0 warn · 0 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (15 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (15 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (15 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WP Rocket 3.23.3.3`

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 2 of 5 — https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil

Run: 2026-08-31T08:14:05.390Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "upload"
- E-commerce: no

## PageSpeed Insights
_Captured in 14995 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **81** | 99 |
| Accessibility | **85** | 91 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **4.1 s** | 1.0 s |
| CLS | 0.000 | **0.000** |
| TBT | 0 ms | 0 ms |
| FCP | **3.04 s** | 678 ms |
| Speed Index | **3.20 s** | 678 ms |
| TTFB | **3 ms** | 2 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 4.1 s
2. **first-contentful-paint** (high) — 3.0 s
3. **document-latency-insight** (high) — Est savings of 190 ms
4. **image-delivery-insight** (high) — Est savings of 227 KiB
5. **network-dependency-tree-insight** (high)

### Findings (mobile)

#### Unused JavaScript
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js — 23 KB wasted

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.47, weight 25) — Largest Contentful Paint — 4.1 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.48, weight 10) — First Contentful Paint — 3.0 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.86, weight 0) — Time to Interactive — 4.2 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 93 ms._

**Transport:**
- Final URL: https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 31 Aug 2026 08:11:57 GMT
- expires: Mon, 31 Aug 2026 08:14:05 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 15904
- Decoded body: 73.6 KB
- Compression ratio: 0.211

### Priority fixes
1. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 15904
content-type: text/html; charset=UTF-8
date: Mon, 31 Aug 2026 08:14:05 GMT
expires: Mon, 31 Aug 2026 08:14:05 GMT
keep-alive: timeout=5, max=94
last-modified: Mon, 31 Aug 2026 08:11:57 GMT
server: Apache / ZoneOS
vary: Accept-Encoding
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1253 ms._

**Scoring:** 4 errors · 1 warnings · 16 cosmetic (suppressed)

### Priority fixes
1. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/giga-invest.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…s/2026/06/giga-invest.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x2, first at line 90
2. **The “sizes” attribute value starting with “auto” is only valid for lazy-loaded images. Add “loading=”“lazy” to this element.** (medium) — x1, first at line 252
3. **A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute.** (medium) — x1, first at line 733

### Issue groups
- (×2) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/giga-invest.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…s/2026/06/giga-invest.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 90 `<img
        alt=""
        class="image__img"
        loading="lazy"
        wi`
- (×1) [error] The “sizes” attribute value starting with “auto” is only valid for lazy-loaded images. Add “loading=”“lazy” to this element. — first at line 252 `<img fetchpriority="high" decoding="async"
        alt=""
        class="image__`
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 660 `/noscript><script nowprocket type="text/javascript">var el`
- (×1) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 733 `</script>
<script type="text/rocketlazyloadscript" id="jquery-js" data-rocket-sr`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 1536 ms._

**Scoring:** 2 violations · 36 passes · critical 0 · serious 2 · moderate 0 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **link-name** (high) — Links must have discernible text

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `.menu-item-543 > a[href$="arikinnisvara/"]`
- `.menu-item-544 > a[href$="elamukinnisvara/"]`
- `.menu-item-545 > a[href$="pakkumised/"]`
- `.current_page_parent > .header-navigation__link[target="_self"]`
- `.menu-item-547 > .header-navigation__link[target="_self"]`
- … and 2 more nodes

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.gallery__main > .image--full > .image__link[data-fancybox="6a95374d28b8a"]`
- `.gallery__thumb:nth-child(1) > .image--full > .image__link[data-fancybox="6a95374d28b8a"]`
- `.gallery__thumb:nth-child(2) > .image--full > .image__link[data-fancybox="6a95374d28b8a"]`
- `.gallery__thumb:nth-child(3) > .image--full > .image__link[data-fancybox="6a95374d28b8a"]`
- `.gallery__thumb:nth-child(4) > .image--full > .image__link[data-fancybox="6a95374d28b8a"]`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 1547 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 23 network requests · 553.5 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 10 | 452.7 KB |
| script | 3 | 45.5 KB |
| stylesheet | 3 | 33.8 KB |
| document | 2 | 15.5 KB |
| other | 1 | 6.0 KB |
| font | 3 | 0 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://fonts.googleapis.com — 2 requests, 0 B

**Slowest requests (top 5):**
- https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil (document) — 107 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 54 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 47 ms, 0 B
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/fonts/AeonikPro-Bold.woff2 (font) — 27 ms, 0 B
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/fonts/AeonikPro-Medium.woff2 (font) — 27 ms, 0 B

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 1547 ms._

**Document:**
- Lang: et
- Title: Tutvustame uusi kodusid Raadil
- Canonical: https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 72364

**Meta tags:**
- Description: not set
- Robots: max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 0 (none)
- Twitter tags: 0
- hreflang:
  - et → https://gigainvesteeringud.giga.ee/uudised/tutvustame-uusi-kodusid-raadil
- JSON-LD: none

**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×3, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Tutvustame uusi kodusid Raadil
  - h2: Vaata lisaks
  - h3: Uus-Karlowa kvartal toob Emajõe kaldale 200 kodu ja uue promenaadi
  - h3: Lõõtsa 6 ärihoone sarikapidu
  - h3: Lõõtsa Ärikvartali esimest hoonet tähistati pidulikul avamisõhtul

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 15 total — 2 defer, 1 async, 0 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js (defer)
- https://gigainvesteeringud.giga.ee/wp-includes/js/jquery/jquery-migrate.min.js (defer)
- https://gigainvesteeringud.giga.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)

**Stylesheets:** 3 external, 4 inline (9.7 KB)

**Images:** 15 total — **0 without alt**, **0 without width/height**, 1 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| 00%2Fsvg%22%20viewBox%3D%220%200%2084%2055%22%3E%3C%2Fsvg%3E | _(empty)_ | 84×55 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20280%20155%22%3E%3C%2Fsvg%3E | _(empty)_ | 280×155 | lazy | ✓ |
| ds/2026/06/gigainvesteeringud_narvamnt124_vaade1-320x240.jpg | _(empty)_ | 320×240 | eager | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20100%20100%22%3E%3C%2Fsvg%3E | _(empty)_ | 100×100 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20100%20100%22%3E%3C%2Fsvg%3E | _(empty)_ | 100×100 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20100%20100%22%3E%3C%2Fsvg%3E | _(empty)_ | 100×100 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20100%20100%22%3E%3C%2Fsvg%3E | _(empty)_ | 100×100 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20100%20100%22%3E%3C%2Fsvg%3E | _(empty)_ | 100×100 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20100%20100%22%3E%3C%2Fsvg%3E | _(empty)_ | 100×100 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20100%20100%22%3E%3C%2Fsvg%3E | _(empty)_ | 100×100 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20100%20100%22%3E%3C%2Fsvg%3E | _(empty)_ | 100×100 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20280%20155%22%3E%3C%2Fsvg%3E | _(empty)_ | 280×155 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20280%20155%22%3E%3C%2Fsvg%3E | _(empty)_ | 280×155 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20280%20155%22%3E%3C%2Fsvg%3E | _(empty)_ | 280×155 | lazy | ✓ |
| 00%2Fsvg%22%20viewBox%3D%220%200%2084%2055%22%3E%3C%2Fsvg%3E | _(empty)_ | 84×55 | lazy | ✓ |

**Links:** 40 anchors — 9 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "töös arendused" ×2
- "ärikinnisvara" ×2
- "elamukinnisvara" ×2
- "pakkumised" ×2
- "uudised" ×2
- "meist" ×2
- "kontakt" ×2

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 0 warn · 0 fail · 3 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy" (14 SVGs excluded). |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 1 raster image on the page (14 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WP Rocket 3.23.3.3`
- Hero image eagerly loaded:
  - `hero: …/wp-content/uploads/2026/06/gigainvesteeringud_narvamnt124_vaade1-320x240.jpg`
  - `loading: eager`
  - `fetchpriority: high`

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 3 of 5 — https://gigainvesteeringud.giga.ee/test

Run: 2026-08-31T08:14:30.253Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 16638 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **87** | 100 |
| Accessibility | **94** | 95 |
| Best Practices | 96 | 96 |
| SEO | 83 | 83 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **3.2 s** | 0.4 s |
| CLS | **0.000** | 0.000 |
| TBT | 0 ms | 0 ms |
| FCP | **3.16 s** | 432 ms |
| Speed Index | **3.16 s** | 522 ms |
| TTFB | 2 ms | 2 ms |

### Priority fixes
1. **largest-contentful-paint** (medium) — 3.2 s
2. **first-contentful-paint** (high) — 3.2 s
3. **legacy-javascript-insight** (high) — Est savings of 13 KiB
4. **network-dependency-tree-insight** (high)
5. **render-blocking-insight** (high) — Est savings of 2,700 ms

### Findings (mobile)

#### Unused JavaScript
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/global.df676e5aea00c812.js — 113 KB wasted

#### Layout-shift sources
- div.grid > div.grid__col > div.footer__text > p — shift 0.000

#### Long tasks
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/global.df676e5aea00c812.js — 149 ms
- https://gigainvesteeringud.giga.ee/test — 102 ms
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js — 73 ms
- https://gigainvesteeringud.giga.ee/test — 53 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `canonical`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`

#### All failing PSI audits (sorted by weight × failure margin)
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `largest-contentful-paint` (performance, score 0.74, weight 25) — Largest Contentful Paint — 3.2 s
- `first-contentful-paint` (performance, score 0.44, weight 10) — First Contentful Paint — 3.2 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `http-status-code` (seo, score 0.00, weight 1) — Page has unsuccessful HTTP status code — 404

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 141 ms._

**Transport:**
- Final URL: https://gigainvesteeringud.giga.ee/test
- Status: 404
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `no-cache, must-revalidate, max-age=0, no-store, private`
- etag: n/a
- last-modified: n/a
- expires: Wed, 11 Jan 1984 05:00:00 GMT
- pragma: n/a
- vary: Accept-Encoding
- Issues:
  - no-store directive (browser cannot cache document)

**Compression:**
- content-encoding: gzip
- content-length: 7733
- Decoded body: 31.4 KB
- Compression ratio: 0.24

### Priority fixes
1. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **cache-control: no-store on document** (high) — Browser cannot cache the document — every page view re-downloads everything
4. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
5. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
6. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
7. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
8. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
9. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
10. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests

### Findings

#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: no-cache, must-revalidate, max-age=0, no-store, private
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 7733
content-type: text/html; charset=UTF-8
date: Mon, 31 Aug 2026 08:14:30 GMT
expires: Wed, 11 Jan 1984 05:00:00 GMT
keep-alive: timeout=5, max=100
link: <https://gigainvesteeringud.giga.ee/wp-json/>; rel="https://api.w.org/"
server: Apache / ZoneOS
vary: Accept-Encoding
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 952 ms._

**Scoring:** 1 errors · 0 warnings · 0 cosmetic (suppressed)

### Priority fixes
1. **HTTP resource not retrievable. The HTTP status from the remote server was: 404.** (medium) — x1, first at line 0

### Issue groups
- (×1) [error] HTTP resource not retrievable. The HTTP status from the remote server was: 404. — first at line 0

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 1247 ms._

**Scoring:** 1 violations · 34 passes · critical 0 · serious 1 · moderate 0 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `.menu-item-543 > a[href$="arikinnisvara/"]`
- `.menu-item-544 > a[href$="elamukinnisvara/"]`
- `.menu-item-545 > a[href$="pakkumised/"]`
- `.current_page_parent > .header-navigation__link[target="_self"]`
- `.menu-item-547 > .header-navigation__link[target="_self"]`
- … and 23 more nodes

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 1252 ms._

**Capture summary:** 1 console events · 0 mixed-content requests · 13 network requests · 89.8 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| script | 4 | 40.2 KB |
| stylesheet | 3 | 33.8 KB |
| document | 1 | 7.6 KB |
| other | 1 | 6.0 KB |
| image | 1 | 2.2 KB |
| font | 2 | 0 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://fonts.googleapis.com — 2 requests, 0 B

**Slowest requests (top 5):**
- https://gigainvesteeringud.giga.ee/test (document) — 120 ms, 7.6 KB
- https://fonts.googleapis.com/css?family=Open+Sans:400,400i,600,700,700i&display=swap&subset=cyrillic (stylesheet) — 49 ms, 0 B
- https://fonts.googleapis.com/css?family=Open+Sans:400,400i,600,700,700i&display=swap&subset=cyrillic (xhr) — 49 ms, 0 B
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/fonts/AeonikPro-Regular.woff2 (font) — 33 ms, 0 B
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/fonts/AeonikPro-Medium.woff2 (font) — 33 ms, 0 B

### Priority fixes
1. **console error** (medium) — Failed to load resource: the server responded with a status of 404 ()

### Findings

#### Console events
- [error] Failed to load resource: the server responded with a status of 404 () (https://gigainvesteeringud.giga.ee/test)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 1252 ms._

**Document:**
- Lang: et
- Title: Lehte ei leitud
- Canonical: not set
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 31479

**Meta tags:**
- Description: not set
- Robots: max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 0 (none)
- Twitter tags: 0
- hreflang:
  - et → https://gigainvesteeringud.giga.ee/test
- JSON-LD: none

**Heading outline:**
- Counts: h1 ×1, h2 ×0, h3 ×0, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Whoops, that page is gone.

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 11 total — 0 defer, 0 async, 4 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/core.81daa612c4c401d9.js
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/global.df676e5aea00c812.js
- https://gigainvesteeringud.giga.ee/wp-includes/js/jquery/jquery-migrate.min.js

**Stylesheets:** 3 external, 4 inline (9.7 KB)

**Images:** 2 total — **0 without alt**, **0 without width/height**, 0 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| teeringud.giga.ee/wp-content/uploads/2026/06/giga-invest.svg | _(empty)_ | 84×55 | lazy | ✓ |
| teeringud.giga.ee/wp-content/uploads/2026/06/giga-invest.svg | _(empty)_ | 84×55 | lazy | ✓ |

**Links:** 27 anchors — 9 external, 1 preconnect, 0 preload.

Vague repeated link text:
- "töös arendused" ×2
- "ärikinnisvara" ×2
- "elamukinnisvara" ×2
- "pakkumised" ×2
- "uudised" ×2
- "meist" ×2
- "kontakt" ×2

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 2 pass · 0 warn · 0 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (2 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (2 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (2 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 4 of 5 — https://gigainvesteeringud.giga.ee/meist

Run: 2026-08-31T08:14:33.901Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 13816 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **73** | 99 |
| Accessibility | **89** | 95 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **5.8 s** | 0.7 s |
| CLS | 0.034 | **0.064** |
| TBT | 0 ms | 0 ms |
| FCP | **3.01 s** | 691 ms |
| Speed Index | **3.20 s** | 691 ms |
| TTFB | **3 ms** | 2 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 5.8 s
2. **first-contentful-paint** (high) — 3.0 s
3. **document-latency-insight** (high) — Est savings of 220 ms
4. **image-delivery-insight** (high) — Est savings of 452 KiB
5. **network-dependency-tree-insight** (high)

### Findings (mobile)

#### Unused JavaScript
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js — 23 KB wasted

#### Layout-shift sources
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.001
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.001
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.001
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.001
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.001
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.001
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.001
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.001
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.001
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.001

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.15, weight 25) — Largest Contentful Paint — 5.8 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.49, weight 10) — First Contentful Paint — 3.0 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.65, weight 0) — Time to Interactive — 5.9 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 244 ms._

**Transport:**
- Final URL: https://gigainvesteeringud.giga.ee/meist/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 31 Aug 2026 08:14:34 GMT
- expires: Mon, 31 Aug 2026 08:14:33 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 15867
- Decoded body: 72.3 KB
- Compression ratio: 0.214

### Priority fixes
1. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 15867
content-type: text/html; charset=UTF-8
date: Mon, 31 Aug 2026 08:14:33 GMT
expires: Mon, 31 Aug 2026 08:14:33 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 31 Aug 2026 08:14:34 GMT
link: <https://gigainvesteeringud.giga.ee/wp-json/>; rel="https://api.w.org/", <https://gigainvesteeringud.giga.ee/wp-json/wp/v2/pages/288>; rel="alternate"; title="JSON"; type="application/json", <https://gigainvesteeringud.giga.ee/?p=288>; rel=shortlink
server: Apache / ZoneOS
vary: Accept-Encoding
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 896 ms._

**Scoring:** 9 errors · 1 warnings · 16 cosmetic (suppressed)

### Priority fixes
1. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/giga-invest.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…s/2026/06/giga-invest.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x2, first at line 90
2. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Giga_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…26/06/Giga_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x1, first at line 308
3. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Giga_ehitus_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…iga_ehitus_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x1, first at line 332
4. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Holttem_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…06/Holttem_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x1, first at line 357
5. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/HUT_A_valge_v2.7.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…6/06/HUT_A_valge_v2.7.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x1, first at line 382

### Issue groups
- (×2) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/giga-invest.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…s/2026/06/giga-invest.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 90 `<img
        alt=""
        class="image__img"
        loading="lazy"
        wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Giga_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…26/06/Giga_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 308 `<img
        alt=""
        class="image__img"
        loading="lazy"
        wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Giga_ehitus_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…iga_ehitus_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 332 `<img
        alt=""
        class="image__img"
        loading="lazy"
        wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Holttem_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…06/Holttem_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 357 `<img
        alt=""
        class="image__img"
        loading="lazy"
        wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/HUT_A_valge_v2.7.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…6/06/HUT_A_valge_v2.7.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 382 `<img
        alt=""
        class="image__img"
        loading="lazy"
        wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Villa_cartelloni_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…cartelloni_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 407 `<img
        alt=""
        class="image__img"
        loading="lazy"
        wi`
- (×1) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/Hake_ja_kyte_logo_white.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…ke_ja_kyte_logo_white.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 432 `<img
        alt=""
        class="image__img"
        loading="lazy"
        wi`
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 727 `/noscript><script nowprocket type="text/javascript">var el`
- (×1) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 800 `</script>
<script type="text/rocketlazyloadscript" id="jquery-js" data-rocket-sr`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 1527 ms._

**Scoring:** 1 violations · 35 passes · critical 0 · serious 1 · moderate 0 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `.menu-item-543 > a[href$="arikinnisvara/"]`
- `.menu-item-544 > a[href$="elamukinnisvara/"]`
- `.menu-item-545 > a[href$="pakkumised/"]`
- `.menu-item-546 > .header-navigation__link[target="_self"]`
- `.menu-item-548 > .header-navigation__link[target="_self"]`
- … and 4 more nodes

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 1541 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 24 network requests · 761.7 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 11 | 660.9 KB |
| script | 3 | 45.5 KB |
| stylesheet | 3 | 33.8 KB |
| document | 2 | 15.5 KB |
| other | 1 | 6.0 KB |
| font | 3 | 0 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://fonts.googleapis.com — 2 requests, 0 B

**Slowest requests (top 5):**
- https://gigainvesteeringud.giga.ee/meist/ (document) — 168 ms, 15.5 KB
- https://gigainvesteeringud.giga.ee/meist (document) — 98 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 58 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 46 ms, 0 B
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/fonts/AeonikPro-Bold.woff2 (font) — 35 ms, 0 B

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 1540 ms._

**Document:**
- Lang: et
- Title: Meist
- Canonical: https://gigainvesteeringud.giga.ee/meist/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 71772

**Meta tags:**
- Description: not set
- Robots: max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 0 (none)
- Twitter tags: 0
- hreflang:
  - et → https://gigainvesteeringud.giga.ee/meist
- JSON-LD: none

**Heading outline:**
- Counts: h1 ×1, h2 ×3, h3 ×4, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Äri- ja elamukinnisvara spetsialist
  - h2: Giga Investeeringud on ambitsioonikas äri- ja elamukinnisvara arendaja, üürilean
  - h3: Giga kinnisvaraportfelli kuulub enam kui 20 ärihoonet, üüritava kogupinnaga üle 
  - h2: Kuulume Giga kontserni, kus on kokku 6 sihikindlat ja tugevat ettevõtet.
  - h2: Ärikinnisvara objektid
  - h3: Uus-Karlowa ärihooned (tulevane arendus)
  - h3: Sadama kvartali äripinnad (tulevane arendus)
  - h3: Tutvu meie äri- ja eramukinnisvara pakkumistega

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 15 total — 2 defer, 1 async, 0 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js (defer)
- https://gigainvesteeringud.giga.ee/wp-includes/js/jquery/jquery-migrate.min.js (defer)
- https://gigainvesteeringud.giga.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)

**Stylesheets:** 3 external, 4 inline (9.7 KB)

**Images:** 14 total — **0 without alt**, **0 without width/height**, 0 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| 00%2Fsvg%22%20viewBox%3D%220%200%2084%2055%22%3E%3C%2Fsvg%3E | _(empty)_ | 84×55 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20400%20283%22%3E%3C%2Fsvg%3E | _(empty)_ | 400×283 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20320%20240%22%3E%3C%2Fsvg%3E | _(empty)_ | 320×240 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20190%20106%22%3E%3C%2Fsvg%3E | _(empty)_ | 190×106 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20190%20106%22%3E%3C%2Fsvg%3E | _(empty)_ | 190×106 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20190%20106%22%3E%3C%2Fsvg%3E | _(empty)_ | 190×106 | lazy | ✓ |
| 0%2Fsvg%22%20viewBox%3D%220%200%20122%2048%22%3E%3C%2Fsvg%3E | _(empty)_ | 122×48 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20190%20106%22%3E%3C%2Fsvg%3E | _(empty)_ | 190×106 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20190%20106%22%3E%3C%2Fsvg%3E | _(empty)_ | 190×106 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20320%20240%22%3E%3C%2Fsvg%3E | _(empty)_ | 320×240 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20320%20240%22%3E%3C%2Fsvg%3E | _(empty)_ | 320×240 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20320%20240%22%3E%3C%2Fsvg%3E | _(empty)_ | 320×240 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20320%20180%22%3E%3C%2Fsvg%3E | _(empty)_ | 320×180 | lazy | ✓ |
| 00%2Fsvg%22%20viewBox%3D%220%200%2084%2055%22%3E%3C%2Fsvg%3E | _(empty)_ | 84×55 | lazy | ✓ |

**Links:** 38 anchors — 14 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "ärikinnisvara" ×3
- "elamukinnisvara" ×3
- "töös arendused" ×2
- "pakkumised" ×2
- "uudised" ×2
- "meist" ×2
- "kontakt" ×2

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 2 pass · 0 warn · 0 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (14 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (14 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (14 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WP Rocket 3.23.3.3`

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 5 of 5 — https://gigainvesteeringud.giga.ee/kinnitus

Run: 2026-08-31T08:14:57.802Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 13637 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **97** | 98 |
| Accessibility | **94** | 95 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **1.9 s** | 0.6 s |
| CLS | 0.090 | **0.090** |
| TBT | 0 ms | 0 ms |
| FCP | **1.70 s** | 524 ms |
| Speed Index | **1.70 s** | 524 ms |
| TTFB | **3 ms** | 2 ms |

### Priority fixes
1. **document-latency-insight** (high) — Est savings of 220 ms
2. **network-dependency-tree-insight** (high)
3. **render-blocking-insight** (high) — Est savings of 40 ms
4. **unused-css-rules** (high) — Est savings of 32 KiB
5. **unused-javascript** (medium) — Est savings of 23 KiB

### Findings (mobile)

#### Unused JavaScript
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js — 23 KB wasted

#### Layout-shift sources
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003
- div.front-hero__inner > div.front-hero__banner > figure.image > ::after — shift 0.003

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 223 ms._

**Transport:**
- Final URL: https://gigainvesteeringud.giga.ee/kinnitus/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 31 Aug 2026 08:14:58 GMT
- expires: Mon, 31 Aug 2026 08:14:57 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 13014
- Decoded body: 50.4 KB
- Compression ratio: 0.252

### Priority fixes
1. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 13014
content-type: text/html; charset=UTF-8
date: Mon, 31 Aug 2026 08:14:57 GMT
expires: Mon, 31 Aug 2026 08:14:57 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 31 Aug 2026 08:14:58 GMT
link: <https://gigainvesteeringud.giga.ee/wp-json/>; rel="https://api.w.org/", <https://gigainvesteeringud.giga.ee/wp-json/wp/v2/pages/290>; rel="alternate"; title="JSON"; type="application/json", <https://gigainvesteeringud.giga.ee/?p=290>; rel=shortlink
server: Apache / ZoneOS
vary: Accept-Encoding
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 788 ms._

**Scoring:** 3 errors · 1 warnings · 16 cosmetic (suppressed)

### Priority fixes
1. **Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/giga-invest.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…s/2026/06/giga-invest.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.)** (medium) — x2, first at line 90
2. **A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute.** (medium) — x1, first at line 338

### Issue groups
- (×2) [error] Bad value “https://gigainvesteeringud.giga.ee/wp-content/uploads/2026/06/giga-invest.svg” for attribute “srcset” on element “img”: No width specified for image “https://gigainvesteeringu…s/2026/06/giga-invest.svg”. (When the “sizes” attribute is present, all image candidate strings must specify a width.) — first at line 90 `<img
        alt=""
        class="image__img"
        loading="lazy"
        wi`
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 265 `/noscript><script nowprocket type="text/javascript">var el`
- (×1) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 338 `</script>
<script type="text/rocketlazyloadscript" id="jquery-js" data-rocket-sr`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 1302 ms._

**Scoring:** 1 violations · 34 passes · critical 0 · serious 1 · moderate 0 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `.menu-item-543 > a[href$="arikinnisvara/"]`
- `.menu-item-544 > a[href$="elamukinnisvara/"]`
- `.menu-item-545 > a[href$="pakkumised/"]`
- `.menu-item-546 > .header-navigation__link[target="_self"]`
- `.menu-item-547 > .header-navigation__link[target="_self"]`
- … and 1 more nodes

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 1311 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 14 network requests · 162.3 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 2 | 64.3 KB |
| script | 3 | 45.5 KB |
| stylesheet | 3 | 33.8 KB |
| document | 2 | 12.7 KB |
| other | 1 | 6.0 KB |
| font | 2 | 0 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://fonts.googleapis.com — 2 requests, 0 B

**Slowest requests (top 5):**
- https://gigainvesteeringud.giga.ee/kinnitus/ (document) — 130 ms, 12.7 KB
- https://gigainvesteeringud.giga.ee/kinnitus (document) — 94 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 51 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 45 ms, 0 B
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/fonts/AeonikPro-Medium.woff2 (font) — 23 ms, 0 B

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 1311 ms._

**Document:**
- Lang: et
- Title: Kinnitus
- Canonical: https://gigainvesteeringud.giga.ee/kinnitus/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 50647

**Meta tags:**
- Description: not set
- Robots: max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 0 (none)
- Twitter tags: 0
- hreflang:
  - et → https://gigainvesteeringud.giga.ee/kinnitus
- JSON-LD: none

**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×0, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Kiri on edukalt saadetud
  - h2: Võtame teiega ühendust esimesel võimalusel.

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 15 total — 2 defer, 1 async, 0 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://gigainvesteeringud.giga.ee/wp-content/themes/gigainvesteeringud/inc/theme/js/jquery.7e52f38a196e6397.js (defer)
- https://gigainvesteeringud.giga.ee/wp-includes/js/jquery/jquery-migrate.min.js (defer)
- https://gigainvesteeringud.giga.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)

**Stylesheets:** 3 external, 4 inline (9.7 KB)

**Images:** 3 total — **0 without alt**, **0 without width/height**, 0 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| 00%2Fsvg%22%20viewBox%3D%220%200%2084%2055%22%3E%3C%2Fsvg%3E | _(empty)_ | 84×55 | lazy | ✓ |
| %2Fsvg%22%20viewBox%3D%220%200%20400%20225%22%3E%3C%2Fsvg%3E | _(empty)_ | 400×225 | lazy | ✓ |
| 00%2Fsvg%22%20viewBox%3D%220%200%2084%2055%22%3E%3C%2Fsvg%3E | _(empty)_ | 84×55 | lazy | ✓ |

**Links:** 27 anchors — 9 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "töös arendused" ×2
- "ärikinnisvara" ×2
- "elamukinnisvara" ×2
- "pakkumised" ×2
- "uudised" ×2
- "meist" ×2
- "kontakt" ×2

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 2 pass · 0 warn · 0 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (3 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (3 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (3 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WP Rocket 3.23.3.3`

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).