20260709T081025Z-990e
- Audited URL
- https://gotoand.dev/larsen
- Timestamp
- 2026-07-09T08:12:10.366Z
- Kind
- single
- Pages
- 1
Weighted audit summary
The site returns a 401 Unauthorized status, making content inaccessible to the public, which is a core functional failure. Security headers are completely missing (0/100) and HTTP does not redirect to HTTPS, creating significant security exposure. Accessibility has 1 serious color-contrast violation and missing landmarks. Performance is strong (PSI 94) but irrelevant if the site is locked. SEO basics are missing.
Audit Report: Viga 401 - Error 401 | Veebimajutus.ee
Website: https://gotoand.dev/larsen
Date: 2026-07-09
Overall Score: 25 / 100
Status: 🔴 Critical
Confidence: high
Audit Coverage: 100% — all sources returned data
Summary
The site returns a 401 Unauthorized status, making content inaccessible to the public, which is a core functional failure. Security headers are completely missing (0/100) and HTTP does not redirect to HTTPS, creating significant security exposure. Accessibility has 1 serious color-contrast violation and missing landmarks. Performance is strong (PSI 94) but irrelevant if the site is locked. SEO basics are missing.
PageSpeed Insights — Mobile vs Desktop
Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.
| Strategy | Performance (M / D) | LCP (M / D) | CLS (M / D) |
|---|---|---|---|
| Mobile vs Desktop | 94 / 100 | 2.47 s / 687 ms | 0.002 / 0.000 |
Optimization Checklist
1 of 3 passing — 1 pass · 1 warn · 1 fail · 4 n/a
| Item | Status | Detail |
|---|---|---|
| Page caching plugin / CDN active | Fail | No WordPress cache plugin marker or CDN edge cache detected on the document response. |
| Images lazy-loaded | Pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | Warn | Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP. |
| Hero is a real <img> (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | N/A | Only 1 raster image on the page — responsive-image rule does not apply. |
| Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | N/A | No external scripts on the page. |
Fixes
Priority 1: Critical
Immediate action — impacts user experience, search rankings, or site safety.
1A. Resolve 401 Unauthorized Status
- Impact: Core functionality, Public Access
- Problem: W3C and Security Headers report HTTP status 401; page is blocked from public access.
- Solution: Remove authentication requirements for this URL or configure the server to return 200 OK for public visitors. If this is a private resource, ensure it is not indexed or linked publicly.
1B. Enforce HTTPS Redirect
- Impact: Transport Security
- Problem: Security Headers report 'http://gotoand.dev/larsen does not redirect to HTTPS'.
- Solution:
Configure the web server (Apache/Nginx) to redirect all HTTP traffic to HTTPS:
RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
Priority 2: Important
Essential for compliance, user reach, and search visibility.
2A. Add Security Headers (HSTS, X-Frame-Options, CSP)
- Impact: Security Headers Grade (0/100)
- Problem: Missing HSTS, X-Content-Type-Options, X-Frame-Options, and CSP. Grade is 0/100.
- Solution:
Add headers to server config:
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" Header always set X-Frame-Options "SAMEORIGIN" Header always set X-Content-Type-Options "nosniff"
2B. Fix Color Contrast and Landmarks
- Impact: Accessibility (axe-core 3 violations)
- Problem: Serious color-contrast violation on navigation links; missing main landmark and skip link.
- Solution:
- Increase contrast ratio to ≥4.5:1 for
.navbar-nav > alinks. - Wrap main content in
<main>and navigation in<nav>. - Add a skip link:
<a href="#main-content" class="skip-link">Skip to content</a>.
- Increase contrast ratio to ≥4.5:1 for
Priority 3: Best Practice
Recommended for long-term maintainability.
3A. Add SEO Meta Tags
- Impact: SEO Score (82/100)
- Problem: Missing meta description, canonical URL, and robots meta tag.
- Solution:
Add to
<head>:<meta name="description" content="..."> <link rel="canonical" href="https://gotoand.dev/larsen"> <meta name="robots" content="index, follow">
▸Raw Markdown sent to the LLM
# Audit — https://gotoand.dev/larsen Run: 2026-07-09T08:10:25.741Z ## Audit Coverage **100%** of audit sources returned data. _All sources OK._ ## Methodology Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula. Severity scale in `priorities[]`: - **high** — blocking issue / vulnerability / fail. - **medium** — significant degradation. - **low** — minor improvement. Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify. ## Site Signals (inferred) Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong. - Auth surface: no - Payments: no - User-generated content: no - E-commerce: no ## PageSpeed Insights _Captured in 11236 ms (mobile + desktop in parallel)._ **Lighthouse scores (mobile vs desktop; worse value bolded):** | Category | Mobile | Desktop | | --- | --- | --- | | Performance | **94** | 100 | | Accessibility | 87 | 87 | | Best Practices | **92** | 96 | | SEO | 82 | 82 | **Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:** | Metric | Mobile | Desktop | | --- | --- | --- | | LCP | **2.5 s** | 0.7 s | | CLS | **0.002** | 0.000 | | TBT | 0 ms | 0 ms | | FCP | **2.47 s** | 687 ms | | Speed Index | **2.47 s** | 687 ms | | TTFB | 35 ms | **40 ms** | ### Priority fixes 1. **first-contentful-paint** (medium) — 2.5 s 2. **document-latency-insight** (medium) — Est savings of 18 KiB 3. **font-display-insight** (medium) — Est savings of 10 ms 4. **network-dependency-tree-insight** (high) 5. **render-blocking-insight** (high) — Est savings of 1,520 ms ### Findings (mobile) #### Layout-shift sources - body > div.container > div.footer--inner — shift 0.002 #### DOM size - Total nodes: 0 #### Failing modeled audits - SEO: `metaDescription` - SEO: `canonical` - SEO: `robotsTxt` - SEO: `tapTargets` - SEO: `structuredData` - Best Practices: `errorsInConsole` #### All failing PSI audits (sorted by weight × failure margin) - `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio. - `first-contentful-paint` (performance, score 0.68, weight 10) — First Contentful Paint — 2.5 s - `landmark-one-main` (accessibility, score 0.00, weight 3) — Document does not have a main landmark. - `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree - `image-size-responsive` (best-practices, score 0.00, weight 1) — Serves images with low resolution - `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console - `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description - `http-status-code` (seo, score 0.00, weight 1) — Page has unsuccessful HTTP status code — 401 ### Manual checks - Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation). - Sustained INP under typical user interaction, not just initial load. - CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing. ## Security Headers & HTTP _Captured in 55 ms._ **Transport:** - Final URL: https://gotoand.dev/larsen - Status: 401 - Redirected: false - HTTPS redirect: ✗ http://gotoand.dev/larsen does not redirect to HTTPS (target: none) **Caching:** - cache-control: not set - etag: "6d1f-584ad22484129" - last-modified: Fri, 22 Mar 2019 11:27:02 GMT - expires: n/a - pragma: n/a - vary: n/a - Issues: - no cache-control header — caching behavior is unpredictable **Compression:** - content-encoding: n/a - content-length: 27935 - Decoded body: 27.3 KB - Compression ratio: 1 - Issues: - response not compressed (27935 bytes uncompressed) ### Priority fixes 1. **HTTP does not redirect to HTTPS** (high) — http://gotoand.dev/larsen does not redirect to HTTPS 2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload 3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions 4. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback 5. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff 6. **weak caching policy** (medium) — no cache-control header — caching behavior is unpredictable 7. **response not compressed** (medium) — response not compressed (27935 bytes uncompressed) 8. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin 9. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features 10. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context ### Findings #### Tracked headers - **strict-transport-security** (missing, high) - **content-security-policy** (missing, high) - **x-frame-options** (missing, medium) - **x-content-type-options** (missing, medium) - **referrer-policy** (missing, low) - **permissions-policy** (missing, low) - **cross-origin-opener-policy** (missing, low) - **cross-origin-resource-policy** (missing, low) - **x-permitted-cross-domain-policies** (missing, low) #### Info disclosure - Server: `Apache` #### All response headers ``` accept-ranges: bytes connection: Upgrade, Keep-Alive content-length: 27935 content-type: text/html date: Thu, 09 Jul 2026 08:10:26 GMT etag: "6d1f-584ad22484129" keep-alive: timeout=5, max=100 last-modified: Fri, 22 Mar 2019 11:27:02 GMT server: Apache upgrade: h2,h2c www-authenticate: Basic realm="Hidden from public. Enter username and password to continue..." ``` ### Manual checks - Cookie attributes set via JavaScript (not visible in HTTP response). - CORS preflight behavior under non-GET methods (only GET response headers checked). - HSTS preload list inclusion (check hstspreload.org). - WAF / DDoS posture beyond what static headers reveal. ## W3C HTML Validator _Captured in 687 ms._ **Scoring:** 1 errors · 0 warnings · 0 cosmetic (suppressed) ### Priority fixes 1. **HTTP resource not retrievable. The HTTP status from the remote server was: 401.** (medium) — x1, first at line 0 ### Issue groups - (×1) [error] HTTP resource not retrievable. The HTTP status from the remote server was: 401. — first at line 0 ### Manual checks - Whether each `<section>` / `<article>` wraps semantically meaningful content. - Language tag accuracy for multi-language pages or quoted content. - Whether structural choices align with the document outline algorithm in screen readers. ## axe-core (Accessibility) _Captured in 1483 ms._ **Scoring:** 3 violations · 16 passes · critical 0 · serious 1 · moderate 2 · minor 0 ### Priority fixes 1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds 2. **landmark-one-main** (medium) — Document should have one main landmark 3. **region** (medium) — All page content should be contained by landmarks ### Findings #### `color-contrast` (serious) — WCAG: wcag2aa, wcag143 [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) - `.navbar-nav > a[href$="veebimajutus.ee/"]` - `.link--row:nth-child(2) > div:nth-child(1) > a` - `.link--row:nth-child(2) > div:nth-child(2) > a` - `.link--row:nth-child(2) > div:nth-child(3) > a` - `.link--row:nth-child(3) > div:nth-child(1) > a` - … and 2 more nodes #### `landmark-one-main` (moderate) [Document should have one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-one-main?application=playwright) - `html` #### `region` (moderate) [All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright) - `.navbar` - `.container` ### Incomplete (axe could not determine) - [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 4 nodes ### Manual checks - Keyboard-only navigation flow + visible focus indicators on every interactive element. - Screen reader output (NVDA, VoiceOver) for actual auditory experience. - Modal focus trapping and restoration on close. - Touch target sizes (44×44 px minimum per WCAG 2.5.8). - Color contrast for elements with alpha-transparency or gradients (axe skips these). ## Browser Runtime _Captured in 1488 ms._ **Capture summary:** 1 console events · 0 mixed-content requests · 4 network requests · 48.0 KB total **Network bytes by resource type:** | Type | Count | Bytes | | --- | --- | --- | | document | 1 | 27.3 KB | | font | 1 | 20.7 KB | | stylesheet | 1 | 0 B | | xhr | 1 | 0 B | **Third-party origins (by bytes):** - https://fonts.gstatic.com — 1 request, 20.7 KB - https://fonts.googleapis.com — 2 requests, 0 B **Slowest requests (top 5):** - https://fonts.googleapis.com/css?family=Droid+Sans:400,700 (stylesheet) — 122 ms, 0 B - https://fonts.gstatic.com/s/droidsans/v19/SlGVmQWMvZQIdix7AFxXkHNSbQ.woff2 (font) — 121 ms, 20.7 KB - https://fonts.googleapis.com/css?family=Droid+Sans:400,700 (xhr) — 119 ms, 0 B - https://gotoand.dev/larsen (document) — 25 ms, 27.3 KB ### Priority fixes 1. **console error** (medium) — Failed to load resource: the server responded with a status of 401 () ### Findings #### Console events - [error] Failed to load resource: the server responded with a status of 401 () (https://gotoand.dev/larsen) ### Manual checks - Console output during user interaction (load-only capture). - Behavior on slow networks and constrained devices. - WebGL / canvas FPS profiling via DevTools Layers panel. - Service worker / cache behavior on repeat visits. ## HTML Inventory _Captured in 1488 ms._ **Document:** - Lang: en - Title: Viga 401 - Error 401 | Veebimajutus.ee - Canonical: not set - Viewport: width=device-width, initial-scale=1 - Charset: UTF-8 - HTML bytes: 29605 **Meta tags:** - Description: not set - Robots: not set - Theme color: not set - Open Graph tags: 0 (none) - Twitter tags: 0 - hreflang: none - JSON-LD: none **Heading outline:** - Counts: h1 ×3, h2 ×0, h3 ×0, h4 ×0, h5 ×0, h6 ×0 - Sequence (first 20): - h1: Viga 401 - h1: Error 401 - h1: Vaata lisaks **Landmarks:** - nav: **missing** - main: **missing** - header: **missing** - footer: **missing** - Skip-to-content link: **missing** **Scripts:** 1 total — 0 defer, 0 async, 0 render-blocking. Speculation rules: no. **Stylesheets:** 1 external, 1 inline (16.8 KB) **Images:** 1 total — **0 without alt**, **1 without width/height**, 1 without loading="lazy" Image inventory (first 15): | src | alt | w×h | loading | srcset | | --- | --- | --- | --- | --- | | kpBQBYmiJCRUQaIoCQlVkChKQkIV/D+cxxFa72wHXQAAAABJRU5ErkJggg== | Veebimajutus | _n/a_ | _n/a_ | ✗ | **Links:** 11 anchors — 11 external, 0 preconnect, 0 preload. Vague repeated link text: - "abi@veebimajutus.ee" ×2 ### Priority fixes 1. **Document has 3 <h1> elements** (medium) — A page should have exactly one h1; multiple h1s break document outline 2. **Missing <nav> landmark** (medium) — No <nav> element found in document 3. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found 4. **1 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS) ### Manual checks - Visual rendering of detected mojibake (browser may auto-correct for display). - Whether decorative images correctly use empty `alt=""` (vs. content images missing it). - Whether headings reflect actual document hierarchy semantically. - Whether vague link text is disambiguated by `aria-label` or surrounding context. ## Optimized-Web Checklist _Captured in 0 ms._ **Summary:** 1 pass · 1 warn · 1 fail · 4 n/a **Checklist:** | Item | Status | Detail | | --- | --- | --- | | Page caching plugin / CDN active | ✗ fail | No WordPress cache plugin marker or CDN edge cache detected on the document response. | | Images lazy-loaded | ✓ pass | All raster images use loading="lazy". | | Hero image eagerly loaded | ! warn | Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP. | | Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. | | Responsive images (srcset / <picture>) | – n/a | Only 1 raster image on the page — responsive-image rule does not apply. | | Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. | | JS scripts not blocking in <head> | – n/a | No external scripts on the page. | **Evidence:** - Hero image eagerly loaded: - `hero: …iKAkJVZAoSkJCFSSKkpBQBYmiJCRUQaIoCQlVkChKQkIV/D+cxxFa72wHXQAAAABJRU5ErkJggg==` - `loading: (not set)` - `fetchpriority: (not set)` ### Priority fixes 1. **Page caching plugin / CDN active** (high) — No WordPress cache plugin marker or CDN edge cache detected on the document response. 2. **Hero image eagerly loaded** (medium) — Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP. ### Manual checks - Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX. - Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost). - Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages. - Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).