Audit

20260709T081025Z-990e

← Back to gotoanddev
Audited URL
https://gotoand.dev/larsen
Timestamp
2026-07-09T08:12:10.366Z
Kind
single
Pages
1
Audit summary
https://gotoand.dev/larsen
Pagespeed scores
Other checks
LLM Report

Weighted audit summary

25
Overall site quality
Criticalhigh confidence

The site returns a 401 Unauthorized status, making content inaccessible to the public, which is a core functional failure. Security headers are completely missing (0/100) and HTTP does not redirect to HTTPS, creating significant security exposure. Accessibility has 1 serious color-contrast violation and missing landmarks. Performance is strong (PSI 94) but irrelevant if the site is locked. SEO basics are missing.

Audit Report: Viga 401 - Error 401 | Veebimajutus.ee

Website: https://gotoand.dev/larsen
Date: 2026-07-09

Overall Score: 25 / 100
Status: 🔴 Critical
Confidence: high
Audit Coverage: 100% — all sources returned data

Summary

The site returns a 401 Unauthorized status, making content inaccessible to the public, which is a core functional failure. Security headers are completely missing (0/100) and HTTP does not redirect to HTTPS, creating significant security exposure. Accessibility has 1 serious color-contrast violation and missing landmarks. Performance is strong (PSI 94) but irrelevant if the site is locked. SEO basics are missing.

PageSpeed Insights — Mobile vs Desktop

Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.

Strategy Performance (M / D) LCP (M / D) CLS (M / D)
Mobile vs Desktop 94 / 100 2.47 s / 687 ms 0.002 / 0.000

Optimization Checklist

1 of 3 passing — 1 pass · 1 warn · 1 fail · 4 n/a

Item Status Detail
Page caching plugin / CDN active Fail No WordPress cache plugin marker or CDN edge cache detected on the document response.
Images lazy-loaded Pass All raster images use loading="lazy".
Hero image eagerly loaded Warn Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP.
Hero is a real <img> (not a CSS background-image) N/A No CSS background-images detected on raster-image-eligible elements.
Responsive images (srcset / <picture>) N/A Only 1 raster image on the page — responsive-image rule does not apply.
Reasonable number of image sizes N/A Too few raster images to evaluate srcset width variety.
JS scripts not blocking in <head> N/A No external scripts on the page.

Fixes

Priority 1: Critical

Immediate action — impacts user experience, search rankings, or site safety.

1A. Resolve 401 Unauthorized Status

  • Impact: Core functionality, Public Access
  • Problem: W3C and Security Headers report HTTP status 401; page is blocked from public access.
  • Solution: Remove authentication requirements for this URL or configure the server to return 200 OK for public visitors. If this is a private resource, ensure it is not indexed or linked publicly.

1B. Enforce HTTPS Redirect

  • Impact: Transport Security
  • Problem: Security Headers report 'http://gotoand.dev/larsen does not redirect to HTTPS'.
  • Solution: Configure the web server (Apache/Nginx) to redirect all HTTP traffic to HTTPS:
    RewriteEngine On
    RewriteCond %{HTTPS} off
    RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
    

Priority 2: Important

Essential for compliance, user reach, and search visibility.

2A. Add Security Headers (HSTS, X-Frame-Options, CSP)

  • Impact: Security Headers Grade (0/100)
  • Problem: Missing HSTS, X-Content-Type-Options, X-Frame-Options, and CSP. Grade is 0/100.
  • Solution: Add headers to server config:
    Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
    Header always set X-Frame-Options "SAMEORIGIN"
    Header always set X-Content-Type-Options "nosniff"
    

2B. Fix Color Contrast and Landmarks

  • Impact: Accessibility (axe-core 3 violations)
  • Problem: Serious color-contrast violation on navigation links; missing main landmark and skip link.
  • Solution:
    • Increase contrast ratio to ≥4.5:1 for .navbar-nav > a links.
    • Wrap main content in <main> and navigation in <nav>.
    • Add a skip link: <a href="#main-content" class="skip-link">Skip to content</a>.

Priority 3: Best Practice

Recommended for long-term maintainability.

3A. Add SEO Meta Tags

  • Impact: SEO Score (82/100)
  • Problem: Missing meta description, canonical URL, and robots meta tag.
  • Solution: Add to <head>:
    <meta name="description" content="...">
    <link rel="canonical" href="https://gotoand.dev/larsen">
    <meta name="robots" content="index, follow">
    
▸Raw Markdown sent to the LLM
# Audit — https://gotoand.dev/larsen

Run: 2026-07-09T08:10:25.741Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 11236 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **94** | 100 |
| Accessibility | 87 | 87 |
| Best Practices | **92** | 96 |
| SEO | 82 | 82 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **2.5 s** | 0.7 s |
| CLS | **0.002** | 0.000 |
| TBT | 0 ms | 0 ms |
| FCP | **2.47 s** | 687 ms |
| Speed Index | **2.47 s** | 687 ms |
| TTFB | 35 ms | **40 ms** |

### Priority fixes
1. **first-contentful-paint** (medium) — 2.5 s
2. **document-latency-insight** (medium) — Est savings of 18 KiB
3. **font-display-insight** (medium) — Est savings of 10 ms
4. **network-dependency-tree-insight** (high)
5. **render-blocking-insight** (high) — Est savings of 1,520 ms

### Findings (mobile)

#### Layout-shift sources
- body > div.container > div.footer--inner — shift 0.002

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `canonical`
- SEO: `robotsTxt`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`

#### All failing PSI audits (sorted by weight × failure margin)
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.68, weight 10) — First Contentful Paint — 2.5 s
- `landmark-one-main` (accessibility, score 0.00, weight 3) — Document does not have a main landmark.
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `image-size-responsive` (best-practices, score 0.00, weight 1) — Serves images with low resolution
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `http-status-code` (seo, score 0.00, weight 1) — Page has unsuccessful HTTP status code — 401

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 55 ms._

**Transport:**
- Final URL: https://gotoand.dev/larsen
- Status: 401
- Redirected: false
- HTTPS redirect: ✗ http://gotoand.dev/larsen does not redirect to HTTPS (target: none)

**Caching:**
- cache-control: not set
- etag: "6d1f-584ad22484129"
- last-modified: Fri, 22 Mar 2019 11:27:02 GMT
- expires: n/a
- pragma: n/a
- vary: n/a
- Issues:
  - no cache-control header — caching behavior is unpredictable

**Compression:**
- content-encoding: n/a
- content-length: 27935
- Decoded body: 27.3 KB
- Compression ratio: 1
- Issues:
  - response not compressed (27935 bytes uncompressed)

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://gotoand.dev/larsen does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
5. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
6. **weak caching policy** (medium) — no cache-control header — caching behavior is unpredictable
7. **response not compressed** (medium) — response not compressed (27935 bytes uncompressed)
8. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
9. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
10. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context

### Findings

#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
accept-ranges: bytes
connection: Upgrade, Keep-Alive
content-length: 27935
content-type: text/html
date: Thu, 09 Jul 2026 08:10:26 GMT
etag: "6d1f-584ad22484129"
keep-alive: timeout=5, max=100
last-modified: Fri, 22 Mar 2019 11:27:02 GMT
server: Apache
upgrade: h2,h2c
www-authenticate: Basic realm="Hidden from public. Enter username and password to continue..."
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 687 ms._

**Scoring:** 1 errors · 0 warnings · 0 cosmetic (suppressed)

### Priority fixes
1. **HTTP resource not retrievable. The HTTP status from the remote server was: 401.** (medium) — x1, first at line 0

### Issue groups
- (×1) [error] HTTP resource not retrievable. The HTTP status from the remote server was: 401. — first at line 0

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 1483 ms._

**Scoring:** 3 violations · 16 passes · critical 0 · serious 1 · moderate 2 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-one-main** (medium) — Document should have one main landmark
3. **region** (medium) — All page content should be contained by landmarks

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `.navbar-nav > a[href$="veebimajutus.ee/"]`
- `.link--row:nth-child(2) > div:nth-child(1) > a`
- `.link--row:nth-child(2) > div:nth-child(2) > a`
- `.link--row:nth-child(2) > div:nth-child(3) > a`
- `.link--row:nth-child(3) > div:nth-child(1) > a`
- … and 2 more nodes

#### `landmark-one-main` (moderate)
[Document should have one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-one-main?application=playwright)
- `html`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.navbar`
- `.container`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 4 nodes

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 1488 ms._

**Capture summary:** 1 console events · 0 mixed-content requests · 4 network requests · 48.0 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| document | 1 | 27.3 KB |
| font | 1 | 20.7 KB |
| stylesheet | 1 | 0 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://fonts.gstatic.com — 1 request, 20.7 KB
- https://fonts.googleapis.com — 2 requests, 0 B

**Slowest requests (top 5):**
- https://fonts.googleapis.com/css?family=Droid+Sans:400,700 (stylesheet) — 122 ms, 0 B
- https://fonts.gstatic.com/s/droidsans/v19/SlGVmQWMvZQIdix7AFxXkHNSbQ.woff2 (font) — 121 ms, 20.7 KB
- https://fonts.googleapis.com/css?family=Droid+Sans:400,700 (xhr) — 119 ms, 0 B
- https://gotoand.dev/larsen (document) — 25 ms, 27.3 KB

### Priority fixes
1. **console error** (medium) — Failed to load resource: the server responded with a status of 401 ()

### Findings

#### Console events
- [error] Failed to load resource: the server responded with a status of 401 () (https://gotoand.dev/larsen)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 1488 ms._

**Document:**
- Lang: en
- Title: Viga 401 - Error 401 | Veebimajutus.ee
- Canonical: not set
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 29605

**Meta tags:**
- Description: not set
- Robots: not set
- Theme color: not set
- Open Graph tags: 0 (none)
- Twitter tags: 0
- hreflang: none
- JSON-LD: none

**Heading outline:**
- Counts: h1 ×3, h2 ×0, h3 ×0, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Viga 401
  - h1: Error 401
  - h1: Vaata lisaks

**Landmarks:**
- nav: **missing**
- main: **missing**
- header: **missing**
- footer: **missing**
- Skip-to-content link: **missing**

**Scripts:** 1 total — 0 defer, 0 async, 0 render-blocking. Speculation rules: no.


**Stylesheets:** 1 external, 1 inline (16.8 KB)

**Images:** 1 total — **0 without alt**, **1 without width/height**, 1 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| kpBQBYmiJCRUQaIoCQlVkChKQkIV/D+cxxFa72wHXQAAAABJRU5ErkJggg== | Veebimajutus | _n/a_ | _n/a_ | ✗ |

**Links:** 11 anchors — 11 external, 0 preconnect, 0 preload.

Vague repeated link text:
- "abi@veebimajutus.ee" ×2

### Priority fixes
1. **Document has 3 <h1> elements** (medium) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing <nav> landmark** (medium) — No <nav> element found in document
3. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
4. **1 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 1 pass · 1 warn · 1 fail · 4 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✗ fail | No WordPress cache plugin marker or CDN edge cache detected on the document response. |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ! warn | Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP. |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 1 raster image on the page — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | – n/a | No external scripts on the page. |

**Evidence:**
- Hero image eagerly loaded:
  - `hero: …iKAkJVZAoSkJCFSSKkpBQBYmiJCRUQaIoCQlVkChKQkIV/D+cxxFa72wHXQAAAABJRU5ErkJggg==`
  - `loading: (not set)`
  - `fetchpriority: (not set)`

### Priority fixes
1. **Page caching plugin / CDN active** (high) — No WordPress cache plugin marker or CDN edge cache detected on the document response.
2. **Hero image eagerly loaded** (medium) — Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).