Audit

20260707T061445Z-68de

← Back to kawiareee
Audited URL
https://kawiare.ee/
Timestamp
2026-07-07T06:25:03.328Z
Kind
site
Pages
10
Audit summary
https://kawiare.ee/
10 of 10 pages audited
Pagespeed scores
Other checks
LLM Report

Weighted audit summary

61
Overall site quality
Needs Improvementhigh confidence

Site overall 61 is the mean of 10 pages. Scores range 42 (https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta) → 72 (https://kawiare.ee/lumekrabi). Weakest page: Mobile performance is critically low (61) with LCP 8.5s and FCP 4.6s, driven by 11 render-blocking scripts. Security configuration is weak (40/100) with HTTP not redirecting to HTTPS, creating a downgrade risk. Accessibility has 1 serious contrast violation and missing skip-link despite high PSI score. SEO lacks a meta description and has W3C errors. Confidence is high due to complete data coverage.

Per-page scores
55
Home
high
63
/artiklid
high
72
…eetset-punast-kalamarja
high
42
…-kaaviar-ilma-muutideta
high
65
…iselt-head-kaheksajalga
high
55
…a-kvaliteetset-kaaviari
high
68
/kammkarp
high
58
/ahven-ja-koha
high
72
/lumekrabi
high
58
/kaaviar-tanapaeval
high

Audit Report: Kawiare - Experience of Taste

Website: https://kawiare.ee/
Date: 2026-07-07

Overall Score: 61 / 100
Status: 🟡 Needs Improvement
Confidence: high
Audit Coverage: 100% — all sources returned data

Pages Audited (10 of 10):

Summary

Site overall 61 is the mean of 10 pages. Scores range 42 (https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta) → 72 (https://kawiare.ee/lumekrabi). Weakest page: Mobile performance is critically low (61) with LCP 8.5s and FCP 4.6s, driven by 11 render-blocking scripts. Security configuration is weak (40/100) with HTTP not redirecting to HTTPS, creating a downgrade risk. Accessibility has 1 serious contrast violation and missing skip-link despite high PSI score. SEO lacks a meta description and has W3C errors. Confidence is high due to complete data coverage.

Per-Page Scores

Page Score Status Confidence
https://kawiare.ee/ 55 🟠 Poor high
https://kawiare.ee/artiklid 63 🟡 Needs Improvement high
https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja 72 🟡 Needs Improvement high
https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta 42 🟠 Poor high
https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga 65 🟡 Needs Improvement high
https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari 55 🟠 Poor high
https://kawiare.ee/kammkarp 68 🟡 Needs Improvement high
https://kawiare.ee/ahven-ja-koha 58 🟠 Poor high
https://kawiare.ee/lumekrabi 72 🟡 Needs Improvement high
https://kawiare.ee/kaaviar-tanapaeval 58 🟠 Poor high

PageSpeed Insights — Mobile vs Desktop

Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.

URL Performance (M / D) LCP (M / D) CLS (M / D)
https://kawiare.ee/ 44 / 72 9.77 s / 1.52 s 1.000 / 0.637
https://kawiare.ee/artiklid 67 / 93 10.28 s / 1.73 s 0.001 / 0.001
https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja 71 / 92 6.56 s / 1.72 s 0.000 / 0.000
https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta 61 / 93 8.49 s / 1.69 s 0.000 / 0.000
https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga 60 / 93 8.89 s / 1.62 s 0.000 / 0.000
https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari 68 / 93 8.71 s / 1.65 s 0.000 / 0.000
https://kawiare.ee/kammkarp 71 / 95 7.22 s / 1.49 s 0.000 / 0.000
https://kawiare.ee/ahven-ja-koha 67 / 93 9.44 s / 1.62 s 0.000 / 0.000
https://kawiare.ee/lumekrabi 70 / 94 7.23 s / 1.58 s 0.000 / 0.000
https://kawiare.ee/kaaviar-tanapaeval 61 / 99 8.36 s / 926 ms 0.000 / 0.000

Optimization Checklist

4 of 7 passing — 4 pass · 2 warn · 1 fail

Item Status Detail
Page caching plugin / CDN active Pass Caching plugin detected (WP Rocket)
Images lazy-loaded Pass All raster images use loading="lazy".
Hero image eagerly loaded Pass Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable).
Hero is a real <img> (not a CSS background-image) Warn Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.
Responsive images (srcset / <picture>) Warn Only 15/22 raster images use srcset or <picture> (68%).
Reasonable number of image sizes Pass 17 distinct srcset widths.
JS scripts not blocking in <head> Fail 5 render-blocking scripts in <head>. Move to footer or add defer/async.

Fixes

Priority 1: Critical

Immediate action — impacts user experience, search rankings, or site safety.

1A. Fix Mobile LCP and CLS

  • Impact: LCP, CLS, Performance Score
  • Problem: Mobile LCP is 9.8s (threshold 2.5s) and CLS is 1.0 (threshold 0.1), causing a Performance score of 44.
  • Solution:
    1. Preload the LCP image (hero) with <link rel="preload" as="image">.
    2. Reserve space for dynamic content to prevent CLS (add width/height or aspect-ratio CSS).
    3. Convert hero PNG to WebP/AVIF to reduce 1.46 MB image weight.

1B. Defer Render-Blocking JavaScript

  • Impact: FCP, TBT, Performance Score
  • Problem: 11 render-blocking scripts (including jQuery and WooCommerce) delay FCP to 1.99s and contribute to LCP delay.
  • Solution: Add defer or async to non-critical scripts in <head>:
    <script src="..." defer></script>
    
    Move WooCommerce frontend scripts to footer if not needed for initial paint.

1C. Force HTTPS Redirect

  • Impact: Security, Transport Layer
  • Problem: Security Headers audit reports 'http://kawiare.ee/artiklid does not redirect to HTTPS', leaving users vulnerable to downgrade attacks.
  • Solution: Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:
    RewriteEngine On
    RewriteCond %{HTTPS} off
    RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
    

1D. Optimize Largest Contentful Paint (LCP)

  • Impact: Performance, Mobile UX
  • Problem: Mobile LCP is 10.3 s (target ≤2.5 s), caused by 16 render-blocking scripts and a hero image loaded via CSS background.
  • Solution:
    • Move non-critical scripts to defer or async (16 currently blocking).
    • Replace CSS background hero with a real <img> or <picture> element with fetchpriority="high".
    • Inline critical CSS and defer the rest.

1E. Enforce HTTPS Redirect

  • Impact: Security, Transport Layer

  • Problem: Security Headers audit shows http://kawiare.ee/... does not redirect to HTTPS, leaving users vulnerable to MITM attacks on unencrypted connections.

  • Solution: Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS.

    Apache (.htaccess):

    RewriteEngine On
    RewriteCond %{HTTPS} off
    RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
    

1F. Eliminate Render-Blocking JavaScript

  • Impact: LCP, FCP, Performance
  • Problem: 11 render-blocking scripts identified in HTML Inventory; LCP is 8.5s and FCP is 4.6s on mobile.
  • Solution: Add defer or async to non-critical scripts in <head>. Move critical CSS inline and defer JS execution.
    <script src="..." defer></script>
    

1G. Force HTTPS redirect on HTTP requests

  • Impact: Security, Transport Layer
  • Problem: Security Headers audit reports 'http://kawiare.ee/... does not redirect to HTTPS', leaving users on unencrypted connections if they type http.
  • Solution: Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests.
    RewriteEngine On
    RewriteCond %{HTTPS} off
    RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
    

1H. Reduce render-blocking JavaScript to improve LCP

  • Impact: LCP, FCP, Mobile Performance
  • Problem: Mobile LCP is 8.9 s; HTML Inventory identifies 11 render-blocking scripts (5 in <head>), including main.js and jQuery.
  • Solution: Add defer or async to non-critical scripts. Move critical CSS inline and defer JS execution.
    <script src="main.js" defer></script>
    

Priority 2: Important

Essential for compliance, user reach, and search visibility.

2A. Strengthen Security Headers

  • Impact: Security Score, XSS Protection
  • Problem: Security Headers grade is 40/100; CSP is missing despite WooCommerce assets indicating potential cart data exposure.
  • Solution: Add Content-Security-Policy (nonce-based) and HSTS preload:
    Content-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';
    Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
    

2B. Fix Accessibility Structure and Contrast

  • Impact: WCAG Compliance, Screen Reader Usability
  • Problem: HTML Inventory shows 3 <h1> elements and missing skip-link; axe-core found 1 serious contrast violation on #cookiescript_accept.
  • Solution:
    1. Ensure only one <h1> per page.
    2. Add <a href="#main" class="skip-link">Skip to content</a>.
    3. Increase contrast on cookie accept button to 4.5:1 ratio.

2C. Fix Accessibility Violations

  • Impact: WCAG Compliance, SEO
  • Problem: axe-core reports 1 serious color-contrast violation (#cookiescript_accept) and 1 moderate heading-order violation (h1→h3 skip).
  • Solution:
    • Increase contrast on .cookiescript_accept to ≥4.5:1 ratio.
    • Insert an <h2> between the <h1> and <h3> elements to maintain sequential heading levels.

2D. Eliminate Render-Blocking JavaScript

  • Impact: FCP, TBT, Performance

  • Problem: 11 render-blocking scripts found in HTML Inventory; 5 specifically in <head> per Optimization Checklist.

  • Solution: Add defer or async to script tags that do not need to execute before DOM parsing.

    Example:

    <script src="main.js" defer></script>
    

2E. Strengthen HSTS Configuration

  • Impact: Security, Transport Layer

  • Problem: HSTS is present but missing the preload directive, preventing inclusion in browser preload lists.

  • Solution: Update the Strict-Transport-Security header to include preload.

    Header: Strict-Transport-Security: max-age=63072000; includeSubDomains; preload

2F. Fix color contrast on cookie consent button

  • Impact: Accessibility (WCAG 1.4.3)
  • Problem: axe-core reports 1 serious violation on #cookiescript_accept for insufficient color contrast.
  • Solution: Increase contrast ratio to at least 4.5:1 for text on the button. Test with a contrast checker tool and adjust CSS colors.

2G. Fix Render-Blocking Scripts

  • Impact: FCP, TBT, Performance
  • Problem: 11 render-blocking scripts detected in <head>, including jQuery and WooCommerce assets, delaying first paint.
  • Solution: Move scripts to the footer or add defer/async attributes:
    <script src="..." defer></script>
    <script src="..." async></script>
    

2H. Defer Render-Blocking Scripts

  • Impact: FCP, LCP, TBT
  • Problem: 11 render-blocking external scripts detected in <head>, delaying first paint and increasing TBT.
  • Solution: Add defer or async to non-critical scripts in the <head>:
    <script src="..." defer></script>
    
    Move non-essential scripts to the footer or use a plugin to optimize script loading order.

2I. Fix Color Contrast Violation

  • Impact: Accessibility (WCAG 1.4.3)
  • Problem: Serious axe violation on #cookiescript_accept element fails minimum contrast ratio thresholds.
  • Solution: Adjust the text color or background color of the cookie consent button to achieve a contrast ratio of at least 4.5:1. Use a tool like WebAIM Contrast Checker to verify.

2J. Implement Content Security Policy (CSP)

  • Impact: Security, XSS Defense
  • Problem: CSP is missing. WooCommerce scripts detected in HTML inventory suggest e-commerce capability, raising XSS risk despite inferred signals.
  • Solution: Deploy a strict CSP with nonce/hash for scripts:
    Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';"
    

2K. Fix Color Contrast on Cookie Button

  • Impact: Accessibility (WCAG 1.4.3)
  • Problem: Axe reports serious contrast violation on #cookiescript_accept.
  • Solution: Increase contrast ratio to ≥4.5:1. Adjust background or text color in CSS:
    #cookiescript_accept { color: #333; background: #f0f0f0; }
    

2L. Add Meta Description

  • Impact: SEO, Click-Through Rate
  • Problem: PSI SEO audit fails metaDescription; document lacks summary.
  • Solution: Add a unique description tag (150-160 chars) in <head>:
    <meta name="description" content="Lumekrabi on tervislik, jätkusuutlik ja peene maitsega delikatess. Tutvuge meie valikuga.">
    

2M. Fix Color Contrast on Cookie Banner

  • Impact: Accessibility (WCAG 1.4.3)

  • Problem: Serious axe-core violation: #cookiescript_accept fails minimum contrast ratio thresholds.

  • Solution: Increase contrast between text and background on the cookie accept button.

    CSS:

    #cookiescript_accept {
      color: #333333; /* Darker text */
      background-color: #ffffff;
    }
    

Priority 3: Best Practice

Recommended for long-term maintainability.

3A. Add Meta Description and Lazy Load Remaining Images

  • Impact: SEO, Page Weight
  • Problem: SEO audit fails metaDescription; 6 images below the fold lack loading="lazy".
  • Solution:
    1. Add <meta name="description" content="...">.
    2. Add loading="lazy" to all images not in the viewport:
    <img src="..." loading="lazy" alt="...">
    

3B. Add Content Security Policy (CSP)

  • Impact: XSS Defense-in-Depth
  • Problem: CSP is missing. Site signals indicate no auth/payments, so risk is lower, but CSP remains a best practice for content integrity.
  • Solution: Implement a strict CSP with nonce-based script execution:
    Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';"
    

3C. Fix Accessibility Contrast & SEO Meta

  • Impact: Accessibility, SEO
  • Problem: axe-core reports 1 serious color-contrast violation on #cookiescript_accept. Meta description is missing (SEO score 92).
  • Solution:
    1. Contrast: Increase text color contrast on #cookiescript_accept to meet WCAG AA (4.5:1).
    2. Meta: Add a <meta name="description" content="..."> tag summarizing the article content.

3D. Add Meta Description

  • Impact: SEO, Click-Through Rate
  • Problem: HTML Inventory shows meta description is not set; W3C validator reports SEO failing audit.
  • Solution: Add a unique meta description tag (150-160 characters) summarizing the article content.
    <meta name="description" content="...">
    

3E. Add meta description for SEO

  • Impact: Search Visibility, CTR
  • Problem: PSI and HTML Inventory confirm 'metaDescription' is missing; document has no meta description tag.
  • Solution: Add a concise meta description (150–160 characters) summarizing the article content.
    <meta name="description" content="Learn how to identify high-quality octopus and caviar with these expert tips.">
    

3F. Implement Content Security Policy (CSP)

  • Impact: XSS Defense-in-Depth
  • Problem: CSP is missing. Site signals indicate no auth, payments, or user content, lowering immediate risk but CSP remains a best practice.
  • Solution: Deploy a strict CSP with nonces for scripts. Since the site is brochure/blog focused, a strict allowlist is less critical than on an app, but recommended for defense-in-depth.
    Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';"
    

3G. Add Meta Description and Fix Landmarks

  • Impact: SEO, Accessibility
  • Problem: SEO audit flags missing meta description; axe-core reports duplicate main landmarks and missing skip-to-content link.
  • Solution:
    • Add <meta name="description" content="...">.
    • Add <a href="#main" class="skip-link">Skip to content</a>.
    • Ensure only one <main> element exists in the DOM.

3H. Implement Content Security Policy

  • Impact: XSS Defense-in-Depth
  • Problem: CSP is missing. Site signals show no auth/payments, so risk is lower, but defense is recommended.
  • Solution: Deploy a strict CSP with nonce/hash for scripts:
    Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';"
    
▸Raw Markdown sent to the LLM
# Site Audit — https://kawiare.ee/
Run: 2026-07-07T06:14:46.082Z

Audited **10** of 10 discovered pages.
Average per-page audit coverage: **100%**

Pages audited:
- https://kawiare.ee/
- https://kawiare.ee/artiklid
- https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja
- https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta
- https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga
- https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari
- https://kawiare.ee/kammkarp
- https://kawiare.ee/ahven-ja-koha
- https://kawiare.ee/lumekrabi
- https://kawiare.ee/kaaviar-tanapaeval

---

# Page 1 of 10 — https://kawiare.ee/

Run: 2026-07-07T06:14:47.392Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 17291 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **44** | 72 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **9.8 s** | 1.5 s |
| CLS | **1.000** | 0.637 |
| TBT | **122 ms** | 20 ms |
| FCP | **1.99 s** | 384 ms |
| Speed Index | **5.17 s** | 957 ms |
| TTFB | 3 ms | **4 ms** |

### Priority fixes
1. **largest-contentful-paint** (high) — 9.8 s
2. **cumulative-layout-shift** (high) — 1
3. **speed-index** (medium) — 5.2 s
4. **first-contentful-paint** (low) — 2.0 s
5. **cls-culprits-insight** (high)

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 163 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Layout-shift sources
- body.home > div#page > main#primary > div.grid — shift 1.000

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 147 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 75 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 9.8 s
- `cumulative-layout-shift` (performance, score 0.02, weight 25) — Cumulative Layout Shift — 1
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `speed-index` (performance, score 0.60, weight 10) — Speed Index — 5.2 s
- `first-contentful-paint` (performance, score 0.84, weight 10) — First Contentful Paint — 2.0 s
- `cls-culprits-insight` (performance, score 0.00, weight 0) — Layout shift culprits
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.28, weight 0) — Time to Interactive — 9.8 s
- `max-potential-fid` (performance, score 0.85, weight 0) — Max Potential First Input Delay — 150 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 233 ms._

**Transport:**
- Final URL: https://kawiare.ee/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 07 Jul 2026 06:03:06 GMT
- expires: Tue, 07 Jul 2026 06:14:47 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 32486
- Decoded body: 148.1 KB
- Compression ratio: 0.214

### Priority fixes
1. **strict-transport-security weak** (high) — missing preload directive
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
4. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
5. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
6. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
7. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 32486
content-type: text/html; charset=UTF-8
date: Tue, 07 Jul 2026 06:14:47 GMT
expires: Tue, 07 Jul 2026 06:14:47 GMT
keep-alive: timeout=5, max=95
last-modified: Tue, 07 Jul 2026 06:03:06 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 783 ms._

**Scoring:** 1 errors · 6 warnings · 70 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 174

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 174 `te">

    <style>
    /`
- (×1) [warning] Section lacks heading. Consider using “h2”-“h6” elements to add identifying headings to all sections, or else use a “div” element instead for any cases where no heading is needed. — first at line 394 `</script>
<section  class="relative">
<div`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 401 `<h2 class="text-center">MAITSE`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2621 ms._

**Scoring:** 1 violations · 54 passes · critical 0 · serious 1 · moderate 0 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 74 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2634 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 53 network requests · 1.84 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 21 | 1.46 MB |
| script | 19 | 251.6 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 1 | 31.7 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 161.2 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 422 ms, 22 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 346 ms, 215 B
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 343 ms, 161.2 KB
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (script) — 79 ms, 1.4 KB
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (script) — 78 ms, 170 B

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783404887553&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=219789259.1783404888&frm=0&pscdl=denied&rcb=10&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938465~115938469~119027224~119576881~119576885~119576891~119576895&sid=1783404887&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2F&dt=Kawiare%20-%20Experience%20of%20Taste&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=921 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783404887553&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=219789259.1783404888&frm=0&pscdl=denied&rcb=10&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938465~115938469~119027224~119576881~119576885~119576891~119576895&sid=1783404887&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2F&dt=Kawiare%20-%20Experience%20of%20Taste&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=921 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2634 ms._

**Document:**
- Lang: et
- Title: Kawiare - Experience of Taste
- Canonical: https://kawiare.ee/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 259279

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang:
  - en → https://kawiare.eu/
  - et → https://kawiare.ee/
  - lv → https://kawiare.lv/
  - x-default → https://kawiare.ee/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×3, h2 ×5, h3 ×15, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: MAITSE, MILLEL ON TÄHENDUS
  - h1: HEA MAITSE ALGAB PÄRITOLUST
  - h1: KUS MAITSE KOHTUB TEADMISEGA
  - h2: MAITSE SÜNNIBTEADLIKEST VALIKUTEST
  - h2: Tutvu valikuga
  - h3: Lumekrabi liha
  - h3: Siberian, 100g
  - h3: Forellimari, 100g
  - h3: Kohafilee
  - h2: TUTVU MEREANDIDE MAAILMAGA
  - h3: 20 punkti, kuidas eristada kvaliteetset kaaviari
  - h3: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi
  - h3: Kuidas ära tunda tõeliselt head kaheksajalga
  - h3: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid
  - h2: Kulinaarne inspiratsioon
  - h3: Krabiliha “Crab Roll”
  - h3: Külm roheline karri röstitud kammkarpidega
  - h3: Kammkarbi crudo kirevilja ponzuga
  - h2: Liitu meie kogukonnaga
  - h3: POOD

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 46 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 22 total — **0 without alt**, **0 without width/height**, 6 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| //kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-1.png | MAITSE, MILLEL ON TÄHENDUS | 2560×1900 | eager | ✗ |
| wp-content/uploads/2026/06/Kawiare-tooted-e1782658950478.png | MAITSE, MILLEL ON TÄHENDUS | 1900×2560 | eager | ✗ |
| tent/uploads/2026/02/Kawiare_paisepildid_mob_2_1900x2560.jpg | HEA MAITSE ALGAB PÄRITOLUST | 2560×1900 | lazy | ✗ |
| ee/wp-content/uploads/2026/02/pais2_uus_2595x1467-scaled.jpg | HEA MAITSE ALGAB PÄRITOLUST | 1900×2560 | lazy | ✗ |
| tent/uploads/2026/02/Kawiare_paisepildid_mob_3_1900x2560.jpg | KUS MAITSE KOHTUB TEADMISEGA | 2560×1900 | lazy | ✗ |
| are.ee/wp-content/uploads/2026/02/pais2_2595x1467-scaled.jpg | KUS MAITSE KOHTUB TEADMISEGA | 1900×2560 | lazy | ✗ |
| nt/uploads/2026/01/Kawiare_crab_legs_500g_2000px-300x300.png | _(empty)_ | 300×300 | _n/a_ | ✓ |
| 026/01/828829589-kawiare_crab_legs_hover1_2000px-300x300.jpg | Lumekrabi liha | 300×300 | lazy | ✓ |
| ads/2026/01/Kawiare_caviar_siberian_big_2000px_2-300x300.png | _(empty)_ | 300×300 | _n/a_ | ✓ |
| //kawiare.ee/wp-content/uploads/2026/01/Siberian-300x300.jpg | Siberian, 100g | 300×300 | lazy | ✓ |
| p-content/uploads/2026/01/Kawiare_trout_2000px_2-300x300.png | _(empty)_ | 300×300 | _n/a_ | ✓ |
| ds/2026/01/828829653-kawiare_trout_hover1_2000px-300x300.jpg | Forellimari, 100g | 300×300 | lazy | ✓ |
| t/uploads/2026/01/Kawiare_pike-uerch_500g_2000px-300x300.png | _(empty)_ | 300×300 | lazy | ✓ |
| 26/01/828829676-kawiare_pike-perch_hover1_2000px-300x300.jpg | Kohafilee | 300×300 | lazy | ✓ |
| t/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |

**Links:** 59 anchors — 5 external, 1 preconnect, 2 preload.

Vague repeated link text:
- "artiklid" ×6
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "meie valik" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Document has 3 <h1> elements** (medium) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 15/22 raster images use srcset or <picture> (68%). |
| Reasonable number of image sizes | ✓ pass | 17 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0`
- Hero image eagerly loaded:
  - `hero: https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-1.png`
  - `loading: eager`
  - `fetchpriority: (not set)`
- Responsive images (srcset / <picture>):
  - `https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-1.png`
  - `https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-e1782658950478.png`
  - `…kawiare.ee/wp-content/uploads/2026/02/Kawiare_paisepildid_mob_2_1900x2560.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/02/pais2_uus_2595x1467-scaled.jpg`
  - `…kawiare.ee/wp-content/uploads/2026/02/Kawiare_paisepildid_mob_3_1900x2560.jpg`
- Reasonable number of image sizes:
  - `widths: 100, 150, 200, 225, 300, 600, 683, 768, 800, 1024, 1080, 1152, 1365, 1536, 1707, 1920, 2000`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 15/22 raster images use srcset or <picture> (68%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 2 of 10 — https://kawiare.ee/artiklid

Run: 2026-07-07T06:14:47.396Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 14822 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **67** | 93 |
| Accessibility | 96 | 96 |
| Best Practices | 100 | 100 |
| SEO | 85 | 85 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **10.3 s** | 1.7 s |
| CLS | 0.001 | **0.001** |
| TBT | **78 ms** | 56 ms |
| FCP | **2.78 s** | 647 ms |
| Speed Index | **4.88 s** | 960 ms |
| TTFB | 3 ms | 3 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 10.3 s
2. **first-contentful-paint** (medium) — 2.8 s
3. **speed-index** (medium) — 4.9 s
4. **document-latency-insight** (high) — Est savings of 350 ms
5. **image-delivery-insight** (high) — Est savings of 158 KiB

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Layout-shift sources
- section.relative > div.pt-24 > div.mx-auto > h1.mb-4 — shift 0.001

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 151 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 77 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 10.3 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.57, weight 10) — First Contentful Paint — 2.8 s
- `speed-index` (performance, score 0.65, weight 10) — Speed Index — 4.9 s
- `heading-order` (accessibility, score 0.00, weight 3) — Heading elements are not in a sequentially-descending order
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `crawlable-anchors` (seo, score 0.00, weight 1) — Links are not crawlable
- `interactive` (performance, score 0.24, weight 0) — Time to Interactive — 10.3 s
- `max-potential-fid` (performance, score 0.83, weight 0) — Max Potential First Input Delay — 150 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 489 ms._

**Transport:**
- Final URL: https://kawiare.ee/artiklid/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/artiklid does not redirect to HTTPS (target: http://kawiare.ee/artiklid/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 06 Jul 2026 22:26:35 GMT
- expires: Tue, 07 Jul 2026 06:14:47 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 31627
- Decoded body: 141.7 KB
- Compression ratio: 0.218

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/artiklid does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 31627
content-type: text/html; charset=UTF-8
date: Tue, 07 Jul 2026 06:14:47 GMT
expires: Tue, 07 Jul 2026 06:14:47 GMT
keep-alive: timeout=5, max=94
last-modified: Mon, 06 Jul 2026 22:26:35 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1055 ms._

**Scoring:** 2 errors · 5 warnings · 63 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 170
2. **The heading “h3” (with computed level 3) follows the heading “h1” (with computed level 1), skipping 1 heading level.** (medium) — x1, first at line 476

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 170 `te">

    <style>
    /`
- (×1) [warning] Text run is not in Unicode Normalization Form C. Should instead be “
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta           ”. (Copy and paste that into your source document to replace the un-normalized text.) — first at line 717 `px] mt-8">
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma mu`
- (×1) [error] The heading “h3” (with computed level 3) follows the heading “h1” (with computed level 1), skipping 1 heading level. — first at line 476 `<h3 class="text-[24px] leading-[100%] text-white mb-[20px] mt-8">`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2947 ms._

**Scoring:** 2 violations · 54 passes · critical 0 · serious 1 · moderate 1 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **heading-order** (medium) — Heading levels should only increase by one

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `heading-order` (moderate)
[Heading levels should only increase by one](https://dequeuniversity.com/rules/axe/4.11/heading-order?application=playwright)
- `.product__item.group.justify-between:nth-child(1) > div:nth-child(1) > .lg\:px-6.px-4 > .text-\[24px\].mb-\[20px\].mt-8`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 65 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2958 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 51 network requests · 1.26 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 11 | 867.2 KB |
| script | 24 | 272.2 KB |
| font | 2 | 58.9 KB |
| stylesheet | 9 | 58.6 KB |
| document | 2 | 30.9 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 161.2 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 492 ms, 161.2 KB
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 (script) — 423 ms, 0 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 341 ms, 22 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 337 ms, 215 B
- https://kawiare.ee/artiklid (document) — 239 ms, 0 B

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783404887764&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1647909729.1783404889&frm=0&pscdl=denied&rcb=2&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616985~115938465~115938468~118395334~118826209~119027224~119576881~119576885~119576891~119576895&sid=1783404888&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fartiklid%2F&dt=Artiklid%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.plf=4.5.3&tfd=1341 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783404887764&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1647909729.1783404889&frm=0&pscdl=denied&rcb=2&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616985~115938465~115938468~118395334~118826209~119027224~119576881~119576885~119576891~119576895&sid=1783404888&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fartiklid%2F&dt=Artiklid%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.plf=4.5.3&tfd=1341 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2958 ms._

**Document:**
- Lang: et
- Title: Artiklid - Kawiare
- Canonical: https://kawiare.ee/artiklid/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 248645

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang:
  - en → https://kawiare.eu/insights/
  - et → https://kawiare.ee/artiklid/
  - lv → https://kawiare.lv/zurnals/
  - x-default → https://kawiare.ee/artiklid/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×12, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: MEREANDIDE MAAILM
  - h3: 20 punkti, kuidas eristada kvaliteetset kaaviari
  - h3: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi
  - h3: Kuidas ära tunda tõeliselt head kaheksajalga
  - h3: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid
  - h3: Ahven ja koha – kaks Balti järvede kala, mille väärtus vajab uuesti mõtestamist
  - h3: Kuidas eristada kvaliteetset punast kalamarja
  - h3: Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta
  - h3: Lumekrabi on tervislik, jätkusuutlik ja peene maitsega delikatess
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE
- Skips:
  - h1 → h3 after "MEREANDIDE MAAILM"

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 51 total — 6 defer, 2 async, 16 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/jquery/ui/core.min.js?ver=1.13.3

**Stylesheets:** 9 external, 17 inline (68.3 KB)

**Images:** 9 total — **0 without alt**, **0 without width/height**, 4 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| t/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_thumb.jpg | _(empty)_ | 800×450 | _n/a_ | ✓ |
| content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_thumb.jpg | _(empty)_ | 800×450 | _n/a_ | ✓ |
| .ee/wp-content/uploads/2026/01/Kawiare_kaheksajalg_thumb.jpg | _(empty)_ | 800×450 | _n/a_ | ✓ |
| are.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| e/wp-content/uploads/2026/01/Kawiare_ahven-ja-koha_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| wp-content/uploads/2026/01/Kawiare_punane-kalamari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| oads/2026/01/Kawiare_kaaviar-looduslik-toidulisand_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| re.ee/wp-content/uploads/2026/01/Kawiare_lumekrabi_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 54 anchors — 6 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Heading level skips** (medium) — h1→h3 after "MEREANDIDE MAAILM"
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **16 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 5 pass · 1 warn · 1 fail

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | ! warn | Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file. |
| Responsive images (srcset / <picture>) | ✓ pass | 8/9 raster images use srcset or <picture> (89%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0`
- Hero image eagerly loaded:
  - `hero: …iare.ee/wp-content/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_thumb.jpg`
  - `loading: (not set)`
  - `fetchpriority: high`
- Hero is a real <img> (not a CSS background-image):
  - `selector: div.pt-24.pb-16`
  - `url: …e.ee/wp-content/uploads/2026/01/823960696-teadmuskeskus_2592x726_b-scaled.jpg`
  - `box: 1280×464px`
- Responsive images (srcset / <picture>):
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Hero is a real <img> (not a CSS background-image)** (medium) — Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 3 of 10 — https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja

Run: 2026-07-07T06:15:14.538Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 16181 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **71** | 92 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **6.6 s** | 1.7 s |
| CLS | 0.000 | **0.000** |
| TBT | **85 ms** | 64 ms |
| FCP | **2.70 s** | 632 ms |
| Speed Index | **3.55 s** | 1.12 s |
| TTFB | 4 ms | 4 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 6.6 s
2. **first-contentful-paint** (medium) — 2.7 s
3. **speed-index** (low) — 3.6 s
4. **document-latency-insight** (high) — Est savings of 400 ms
5. **image-delivery-insight** (high) — Est savings of 220 KiB

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 65 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 153 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 83 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.08, weight 25) — Largest Contentful Paint — 6.6 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.60, weight 10) — First Contentful Paint — 2.7 s
- `speed-index` (performance, score 0.87, weight 10) — Speed Index — 3.6 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.46, weight 0) — Time to Interactive — 7.6 s
- `max-potential-fid` (performance, score 0.83, weight 0) — Max Potential First Input Delay — 150 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 446 ms._

**Transport:**
- Final URL: https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja does not redirect to HTTPS (target: http://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 06 Jul 2026 22:26:37 GMT
- expires: Tue, 07 Jul 2026 06:15:14 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 32005
- Decoded body: 130.7 KB
- Compression ratio: 0.239

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 32005
content-type: text/html; charset=UTF-8
date: Tue, 07 Jul 2026 06:15:14 GMT
expires: Tue, 07 Jul 2026 06:15:14 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 06 Jul 2026 22:26:37 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1023 ms._

**Scoring:** 2 errors · 5 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2633 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 84 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2645 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 976.7 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 587.7 KB |
| script | 19 | 251.6 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 31.3 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 161.2 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 477 ms, 161.2 KB
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 339 ms, 215 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 331 ms, 22 B
- https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_thumb-600x338.jpg (image) — 264 ms, 12.6 KB
- https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_thumb-600x338.jpg (image) — 264 ms, 13.0 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711h1v9244324978za200zd9244324978&_p=1783404914818&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1181351796.1783404916&frm=0&pscdl=denied&rcb=15&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616985~115938465~115938469~119027224~119576881~119576885~119576891~119576895&sid=1783404915&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkuidas-eristada-kvaliteetset-punast-kalamarja%2F&dt=Kuidas%20eristada%20kvaliteetset%20punast%20kalamarja%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.plf=4.5.3&tfd=1238 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711h1v9244324978za200zd9244324978&_p=1783404914818&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1181351796.1783404916&frm=0&pscdl=denied&rcb=15&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616985~115938465~115938469~119027224~119576881~119576885~119576891~119576895&sid=1783404915&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkuidas-eristada-kvaliteetset-punast-kalamarja%2F&dt=Kuidas%20eristada%20kvaliteetset%20punast%20kalamarja%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.plf=4.5.3&tfd=1238 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2645 ms._

**Document:**
- Lang: et
- Title: Kuidas eristada kvaliteetset punast kalamarja - Kawiare
- Canonical: https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 237289

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/how-to-identify-quality-red-fish-roe/
  - et → https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja/
  - lv → https://kawiare.lv/ka-atskirt-kvalitativus-sarkanos-zivju-ikrus/
  - x-default → https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×8, h3 ×7, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Kuidas eristada kvaliteetset punast kalamarja
  - h2: Välimus ja tera ühtlus
  - h2: Lõhn
  - h2: Maitse ja tekstuur
  - h2: Soolasus
  - h2: Koostis ja lisandid
  - h2: Päritolu ja jälgitavus
  - h2: Soovid rohkem teada saada?
  - h3: 20 punkti, kuidas eristada kvaliteetset kaaviari
  - h3: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi
  - h3: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| nt/uploads/2026/01/Kawiare_punane-kalamari_header-scaled.jpg | Kuidas eristada kvaliteetset punast kala | 2560×717 | eager | ✗ |
| t/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| are.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 1 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0`
- Hero image eagerly loaded:
  - `hero: …wiare.ee/wp-content/uploads/2026/01/Kawiare_punane-kalamari_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `…wiare.ee/wp-content/uploads/2026/01/Kawiare_punane-kalamari_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 4 of 10 — https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta

Run: 2026-07-07T06:15:19.702Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 16731 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **61** | 93 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **8.5 s** | 1.7 s |
| CLS | 0.000 | **0.000** |
| TBT | 76 ms | **85 ms** |
| FCP | **4.59 s** | 617 ms |
| Speed Index | **6.42 s** | 957 ms |
| TTFB | 4 ms | 4 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 8.5 s
2. **first-contentful-paint** (high) — 4.6 s
3. **speed-index** (high) — 6.4 s
4. **document-latency-insight** (high) — Est savings of 250 ms
5. **forced-reflow-insight** (high)

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 115 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 61 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.02, weight 25) — Largest Contentful Paint — 8.5 s
- `first-contentful-paint` (performance, score 0.14, weight 10) — First Contentful Paint — 4.6 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `speed-index` (performance, score 0.40, weight 10) — Speed Index — 6.4 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.38, weight 0) — Time to Interactive — 8.5 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 436 ms._

**Transport:**
- Final URL: https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta does not redirect to HTTPS (target: http://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 06 Jul 2026 22:26:39 GMT
- expires: Tue, 07 Jul 2026 06:15:19 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 32617
- Decoded body: 132.5 KB
- Compression ratio: 0.24

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 32617
content-type: text/html; charset=UTF-8
date: Tue, 07 Jul 2026 06:15:19 GMT
expires: Tue, 07 Jul 2026 06:15:19 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 06 Jul 2026 22:26:39 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 842 ms._

**Scoring:** 2 errors · 10 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [warning] Text run is not in Unicode Normalization Form C. Should instead be “Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta - Kawiar”. (Copy and paste that into your source document to replace the un-normalized text.) — first at line 43 `>
	<title>Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta - Kawia`
- (×1) [warning] The value of attribute “content” on element “meta” from namespace “http://www.w3.org/1999/xhtml” is not in Unicode Normalization Form C. — first at line 47 `icle" />
	<meta property="og:title" content="Kaaviar kui looduslik toidulisand e`
- (×1) [warning] Text run is not in Unicode Normalization Form C. Should instead be “{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/kawiare.ee\/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta\/#article","isPartOf":{"@id":"https:\/\/kawiare.ee\/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta\/"},"author":{"name":"artur","@id":"https:\/\/kawiare.ee\/#\/schema\/person\/03967b4e81b1b99ca46d262a3463ac35"},"headline":"Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta","datePublished":"2026-01-14T12:37:14+00:00","dateModified":"2026-03-02T17:57:24+00:00","mainEntityOfPage":{"@id":"https:\/\/kawiare.ee\/kaaviar-kui-l”. (Copy and paste that into your source document to replace the un-normalized text.) — first at line 63 `ma-graph">{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":`
- (×1) [warning] The value of attribute “title” on element “link” from namespace “http://www.w3.org/1999/xhtml” is not in Unicode Normalization Form C. — first at line 69 `.com' />

<link rel="alternate" type="application/rss+xml" title="Kawiare &raquo`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`
- (×1) [warning] The value of attribute “alt” on element “img” from namespace “http://www.w3.org/1999/xhtml” is not in Unicode Normalization Form C. — first at line 418 `<img fetchpriority="high" width="2560" height="717" class="mb-8 w-full h-auto" s`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3035 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 80 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3050 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 959.8 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 570.2 KB |
| script | 19 | 251.6 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 31.9 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 161.2 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 542 ms, 161.2 KB
- https://kawiare.ee/wp-content/themes/kawiare/assets/Josefin_Sans/static/JosefinSans-SemiBold.ttf (font) — 477 ms, 29.3 KB
- https://kawiare.ee/wp-content/themes/kawiare/assets/Josefin_Sans/static/JosefinSans-Regular.ttf (font) — 477 ms, 29.5 KB
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 339 ms, 22 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 334 ms, 215 B

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6760h2v9244324978za200zd9244324978&_p=1783404919992&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1181700935.1783404921&frm=0&pscdl=denied&rcb=11&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616986~115938466~115938468~118395333~119027224~119576881~119576885~119576891~119576895~119787196&sid=1783404920&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta%2F&dt=Kaaviar%20kui%20looduslik%20toidulisand%20ehk%20kaaviar%20ilma%20mu%CC%88u%CC%88tideta%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1715 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6760h2v9244324978za200zd9244324978&_p=1783404919992&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1181700935.1783404921&frm=0&pscdl=denied&rcb=11&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616986~115938466~115938468~118395333~119027224~119576881~119576885~119576891~119576895~119787196&sid=1783404920&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta%2F&dt=Kaaviar%20kui%20looduslik%20toidulisand%20ehk%20kaaviar%20ilma%20mu%CC%88u%CC%88tideta%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1715 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3050 ms._

**Document:**
- Lang: et
- Title: Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta - Kawiare
- Canonical: https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 239046

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/caviar-without-the-myths/
  - et → https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta/
  - lv → https://kawiare.lv/kaviars-ka-dabisks-uztura-bagatinatajs-jeb-kaviars-bez-mitiem/
  - x-default → https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×5, h3 ×11, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Kaaviar kui looduslik toidulisand
  - h2: Kaaviar enne pidulauda
  - h2: Kaaviar kui kontsentreeritud toit
  - h3: Väike kogus, reaalne mõju
  - h3: Omega-3 rasvhapped ilma kapslita
  - h3: Miks kaaviar ei ole “liiga rasvane”
  - h3: Kaaviar ja aju
  - h2: Lugu, mida kaaviar ei vaja
  - h2: Soovid rohkem teada saada?
  - h3: Kuidas eristada kvaliteetset punast kalamarja
  - h3: Kuidas ära tunda tõeliselt head kaheksajalga
  - h3: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| 6/01/Kawiare_kaaviar-looduslik-toidulisand_header-scaled.jpg | Kaaviar kui looduslik toidulisand ehk ka | 2560×717 | eager | ✗ |
| wp-content/uploads/2026/01/Kawiare_punane-kalamari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| .ee/wp-content/uploads/2026/01/Kawiare_kaheksajalg_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| are.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0`
- Hero image eagerly loaded:
  - `hero: …ntent/uploads/2026/01/Kawiare_kaaviar-looduslik-toidulisand_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `…ntent/uploads/2026/01/Kawiare_kaaviar-looduslik-toidulisand_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 5 of 10 — https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga

Run: 2026-07-07T06:15:42.838Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 17951 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **60** | 93 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **8.9 s** | 1.6 s |
| CLS | 0.000 | **0.000** |
| TBT | **86 ms** | 80 ms |
| FCP | **4.62 s** | 669 ms |
| Speed Index | **6.89 s** | 1.15 s |
| TTFB | **5 ms** | 4 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 8.9 s
2. **first-contentful-paint** (high) — 4.6 s
3. **speed-index** (high) — 6.9 s
4. **document-latency-insight** (high) — Est savings of 330 ms
5. **image-delivery-insight** (high) — Est savings of 264 KiB

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 125 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 61 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.01, weight 25) — Largest Contentful Paint — 8.9 s
- `first-contentful-paint` (performance, score 0.13, weight 10) — First Contentful Paint — 4.6 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `speed-index` (performance, score 0.34, weight 10) — Speed Index — 6.9 s
- `lcp-breakdown-insight` (performance, score 0.00, weight 0) — LCP breakdown
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.35, weight 0) — Time to Interactive — 8.9 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 488 ms._

**Transport:**
- Final URL: https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga does not redirect to HTTPS (target: http://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 06 Jul 2026 22:26:41 GMT
- expires: Tue, 07 Jul 2026 06:15:43 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 31993
- Decoded body: 130.9 KB
- Compression ratio: 0.239

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 31993
content-type: text/html; charset=UTF-8
date: Tue, 07 Jul 2026 06:15:43 GMT
expires: Tue, 07 Jul 2026 06:15:43 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 06 Jul 2026 22:26:41 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 840 ms._

**Scoring:** 2 errors · 5 warnings · 66 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2472 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 77 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2483 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 1.04 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 675.8 KB |
| script | 19 | 251.6 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 31.2 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 161.2 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 495 ms, 215 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 444 ms, 22 B
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 310 ms, 161.2 KB
- https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga (document) — 223 ms, 0 B
- https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_thumb-600x338.jpg (image) — 69 ms, 14.4 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783404943137&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=79358648.1783404944&frm=0&pscdl=denied&rcb=18&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938465~115938468~118395334~119027224~119576881~119576885~119576891~119576895&sid=1783404943&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkuidas-ara-tunda-toeliselt-head-kaheksajalga%2F&dt=Kuidas%20%C3%A4ra%20tunda%20t%C3%B5eliselt%20head%20kaheksajalga%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1091 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783404943137&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=79358648.1783404944&frm=0&pscdl=denied&rcb=18&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938465~115938468~118395334~119027224~119576881~119576885~119576891~119576895&sid=1783404943&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkuidas-ara-tunda-toeliselt-head-kaheksajalga%2F&dt=Kuidas%20%C3%A4ra%20tunda%20t%C3%B5eliselt%20head%20kaheksajalga%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1091 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2483 ms._

**Document:**
- Lang: et
- Title: Kuidas ära tunda tõeliselt head kaheksajalga - Kawiare
- Canonical: https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 237416

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/how-to-identify-high-quality-octopus/
  - et → https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga/
  - lv → https://kawiare.lv/ka-atpazit-patiesi-labu-astonkaji-astonkaja-kvalitates-anatomija/
  - x-default → https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×8, h3 ×8, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Kuidas ära tunda tõeliselt head kaheksajalga
  - h2: Miks kõik kaheksajalad ei ole samad
  - h2: Kasvukeskkond määrab kvaliteedi
  - h2: Tekstuur: mis vahe on heal ja kehval kaheksajalal
  - h3: Töötlemine, millest poeriiulil ei räägita
  - h2: Mida tähendab naturaalselt küpsetatud kaheksajalg
  - h2: Miks valmis küpsetatud kaheksajalg võib olla parem kui toores
  - h2: Kuidas tunda ära õige kaheksajalg
  - h2: Soovid rohkem teada saada?
  - h3: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi
  - h3: 20 punkti, kuidas eristada kvaliteetset kaaviari
  - h3: Ahven ja koha – kaks Balti järvede kala, mille väärtus vajab uuesti mõtestamist
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| p-content/uploads/2026/01/Kawiare_kaheksajalg_header-1-1.png | Kuidas ära tunda tõeliselt head kaheksaj | 2000×560 | eager | ✗ |
| content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| t/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| e/wp-content/uploads/2026/01/Kawiare_ahven-ja-koha_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0`
- Hero image eagerly loaded:
  - `hero: https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_kaheksajalg_header-1-1.png`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_kaheksajalg_header-1-1.png`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 6 of 10 — https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari

Run: 2026-07-07T06:15:49.639Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 20751 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **68** | 93 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **8.7 s** | 1.6 s |
| CLS | 0.000 | **0.000** |
| TBT | **94 ms** | 26 ms |
| FCP | **2.63 s** | 627 ms |
| Speed Index | **4.37 s** | 997 ms |
| TTFB | 4 ms | 4 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 8.7 s
2. **first-contentful-paint** (medium) — 2.6 s
3. **speed-index** (medium) — 4.4 s
4. **document-latency-insight** (high) — Est savings of 240 ms
5. **image-delivery-insight** (high) — Est savings of 195 KiB

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 152 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 93 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.01, weight 25) — Largest Contentful Paint — 8.7 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.62, weight 10) — First Contentful Paint — 2.6 s
- `speed-index` (performance, score 0.74, weight 10) — Speed Index — 4.4 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.36, weight 0) — Time to Interactive — 8.7 s
- `max-potential-fid` (performance, score 0.83, weight 0) — Max Potential First Input Delay — 150 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 462 ms._

**Transport:**
- Final URL: https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari does not redirect to HTTPS (target: http://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 06 Jul 2026 22:26:42 GMT
- expires: Tue, 07 Jul 2026 06:15:49 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 31618
- Decoded body: 129.8 KB
- Compression ratio: 0.238

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 31618
content-type: text/html; charset=UTF-8
date: Tue, 07 Jul 2026 06:15:49 GMT
expires: Tue, 07 Jul 2026 06:15:49 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 06 Jul 2026 22:26:42 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 819 ms._

**Scoring:** 2 errors · 6 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`
- (×1) [warning] Text run is not in Unicode Normalization Form C. Should instead be “
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta           ”. (Copy and paste that into your source document to replace the un-normalized text.) — first at line 494 `px] mt-8">
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma mu`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2520 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 91 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2530 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 937.1 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 548.5 KB |
| script | 19 | 251.6 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 30.9 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 161.2 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 428 ms, 215 B
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 410 ms, 161.2 KB
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 341 ms, 22 B
- https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari (document) — 216 ms, 0 B
- https://kawiare.ee/wp-content/themes/kawiare/assets/Josefin_Sans/static/JosefinSans-Regular.ttf (font) — 94 ms, 29.5 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783404949922&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=673641945.1783404951&frm=0&pscdl=denied&rcb=0&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616985~115938466~115938469~118012009~119027224~119381663~119576881~119576885~119576891~119576895&sid=1783404950&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkuidas-eristada-kvaliteetset-kaaviari%2F&dt=20%20punkti%2C%20kuidas%20eristada%20kvaliteetset%20kaaviari%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.plf=4.5.3&tfd=1185 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783404949922&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=673641945.1783404951&frm=0&pscdl=denied&rcb=0&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616985~115938466~115938469~118012009~119027224~119381663~119576881~119576885~119576891~119576895&sid=1783404950&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkuidas-eristada-kvaliteetset-kaaviari%2F&dt=20%20punkti%2C%20kuidas%20eristada%20kvaliteetset%20kaaviari%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.plf=4.5.3&tfd=1185 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2530 ms._

**Document:**
- Lang: et
- Title: 20 punkti, kuidas eristada kvaliteetset kaaviari - Kawiare
- Canonical: https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 236383

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/20-points-on-how-to-identify-high-quality-caviar/
  - et → https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari/
  - lv → https://kawiare.lv/20-punkti-ka-atskirt-kvalitativu-kaviaru/
  - x-default → https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×2, h3 ×7, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: 20 punkti, kuidas eristada kvaliteetset kaaviari
  - h2: Soovid rohkem teada saada?
  - h3: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid
  - h3: Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta
  - h3: Kuidas eristada kvaliteetset punast kalamarja
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| s/2026/01/Kawiare_kuidas-eristada-kaaviari_header-scaled.jpg | 20 punkti, kuidas eristada kvaliteetset  | 2560×717 | eager | ✗ |
| are.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| oads/2026/01/Kawiare_kaaviar-looduslik-toidulisand_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| wp-content/uploads/2026/01/Kawiare_punane-kalamari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0`
- Hero image eagerly loaded:
  - `hero: …wp-content/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `…wp-content/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 7 of 10 — https://kawiare.ee/kammkarp

Run: 2026-07-07T06:16:16.473Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 15631 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **71** | 95 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **7.2 s** | 1.5 s |
| CLS | 0.000 | **0.000** |
| TBT | **92 ms** | 59 ms |
| FCP | **2.66 s** | 631 ms |
| Speed Index | **3.31 s** | 953 ms |
| TTFB | 4 ms | 4 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 7.2 s
2. **first-contentful-paint** (medium) — 2.7 s
3. **document-latency-insight** (high) — Est savings of 350 ms
4. **image-delivery-insight** (high) — Est savings of 195 KiB
5. **legacy-javascript-insight** (medium) — Est savings of 5 KiB

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 65 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 161 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 86 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.05, weight 25) — Largest Contentful Paint — 7.2 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.61, weight 10) — First Contentful Paint — 2.7 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.45, weight 0) — Time to Interactive — 7.7 s
- `max-potential-fid` (performance, score 0.80, weight 0) — Max Potential First Input Delay — 160 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 451 ms._

**Transport:**
- Final URL: https://kawiare.ee/kammkarp/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/kammkarp does not redirect to HTTPS (target: http://kawiare.ee/kammkarp/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 06 Jul 2026 22:27:36 GMT
- expires: Tue, 07 Jul 2026 06:16:16 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 31802
- Decoded body: 129.6 KB
- Compression ratio: 0.24

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/kammkarp does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 31802
content-type: text/html; charset=UTF-8
date: Tue, 07 Jul 2026 06:16:16 GMT
expires: Tue, 07 Jul 2026 06:16:16 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 06 Jul 2026 22:27:36 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 821 ms._

**Scoring:** 2 errors · 6 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`
- (×1) [warning] Text run is not in Unicode Normalization Form C. Should instead be “
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta           ”. (Copy and paste that into your source document to replace the un-normalized text.) — first at line 484 `px] mt-8">
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma mu`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2538 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 90 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2549 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 974.9 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 586.2 KB |
| script | 19 | 251.6 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 31.1 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 161.2 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 378 ms, 161.2 KB
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 338 ms, 215 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 338 ms, 22 B
- https://kawiare.ee/kammkarp (document) — 221 ms, 0 B
- https://kawiare.ee/wp-content/themes/kawiare/assets/Josefin_Sans/static/JosefinSans-Regular.ttf (font) — 70 ms, 29.5 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711h1v9244324978za200zd9244324978&_p=1783404976767&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=186482162.1783404978&frm=0&pscdl=denied&rcb=7&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616985~115938465~115938469~119027224~119576881~119576885~119576891~119576895&sid=1783404977&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkammkarp%2F&dt=Kammkarp%20%E2%80%93%20lihtne%20fast%20food%2C%20mis%20ei%20vaja%20keerulisi%20tehnikaid%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.plf=4.5.3&tfd=1163 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711h1v9244324978za200zd9244324978&_p=1783404976767&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=186482162.1783404978&frm=0&pscdl=denied&rcb=7&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616985~115938465~115938469~119027224~119576881~119576885~119576891~119576895&sid=1783404977&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkammkarp%2F&dt=Kammkarp%20%E2%80%93%20lihtne%20fast%20food%2C%20mis%20ei%20vaja%20keerulisi%20tehnikaid%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.plf=4.5.3&tfd=1163 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2548 ms._

**Document:**
- Lang: et
- Title: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid - Kawiare
- Canonical: https://kawiare.ee/kammkarp/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 236115

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/scallop/
  - et → https://kawiare.ee/kammkarp/
  - lv → https://kawiare.lv/kemmisgliemene-vienkarss-fast-food-kam-nav-vajadzigas-sarezgitas-tehnikas/
  - x-default → https://kawiare.ee/kammkarp/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×8, h3 ×8, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Kammkarp
  - h2: Mis on kammkarp ja miks teda hinnatakse
  - h2: Päritolu ja hooajalisus
  - h2: Miks kammkarp on kiire ja lihtne toit
  - h3: Kammkarp koorel – miks see on praktiline
  - h2: Lihtsad serveerimisviisid
  - h2: Kammkarp ja tervislik toitumine
  - h2: Kammkarp igapäevases köögis
  - h2: Soovid rohkem teada saada?
  - h3: Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta
  - h3: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi
  - h3: Kuidas ära tunda tõeliselt head kaheksajalga
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| p-content/uploads/2026/01/Kawiare_kammkarp_header-scaled.jpg | Kammkarp – lihtne <em>fast food</em>, mi | 2560×717 | eager | ✗ |
| oads/2026/01/Kawiare_kaaviar-looduslik-toidulisand_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| .ee/wp-content/uploads/2026/01/Kawiare_kaheksajalg_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 0 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0`
- Hero image eagerly loaded:
  - `hero: https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: (not set)`
- Responsive images (srcset / <picture>):
  - `https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 8 of 10 — https://kawiare.ee/ahven-ja-koha

Run: 2026-07-07T06:16:23.826Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 14639 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **67** | 93 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **9.4 s** | 1.6 s |
| CLS | 0.000 | **0.000** |
| TBT | **153 ms** | 79 ms |
| FCP | **2.63 s** | 624 ms |
| Speed Index | **4.49 s** | 1.02 s |
| TTFB | 3 ms | **4 ms** |

### Priority fixes
1. **largest-contentful-paint** (high) — 9.4 s
2. **first-contentful-paint** (medium) — 2.6 s
3. **speed-index** (medium) — 4.5 s
4. **document-latency-insight** (high) — Est savings of 260 ms
5. **image-delivery-insight** (high) — Est savings of 335 KiB

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0 — 172 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 81 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 9.4 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.63, weight 10) — First Contentful Paint — 2.6 s
- `speed-index` (performance, score 0.72, weight 10) — Speed Index — 4.5 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.30, weight 0) — Time to Interactive — 9.4 s
- `max-potential-fid` (performance, score 0.76, weight 0) — Max Potential First Input Delay — 170 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 466 ms._

**Transport:**
- Final URL: https://kawiare.ee/ahven-ja-koha/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/ahven-ja-koha does not redirect to HTTPS (target: http://kawiare.ee/ahven-ja-koha/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 06 Jul 2026 22:27:38 GMT
- expires: Tue, 07 Jul 2026 06:16:24 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 31528
- Decoded body: 129.2 KB
- Compression ratio: 0.238

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/ahven-ja-koha does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 31528
content-type: text/html; charset=UTF-8
date: Tue, 07 Jul 2026 06:16:24 GMT
expires: Tue, 07 Jul 2026 06:16:24 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 06 Jul 2026 22:27:38 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 803 ms._

**Scoring:** 2 errors · 5 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2573 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 63 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2583 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 1.11 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 747.3 KB |
| script | 19 | 251.6 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 30.8 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 161.2 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 413 ms, 215 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 365 ms, 22 B
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 313 ms, 161.2 KB
- https://kawiare.ee/ahven-ja-koha (document) — 216 ms, 0 B
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 (script) — 59 ms, 0 B

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783404984107&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1983541243.1783404985&frm=0&pscdl=denied&rcb=8&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938465~115938469~119027224~119576881~119576885~119576891~119576895&sid=1783404984&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fahven-ja-koha%2F&dt=Ahven%20ja%20koha%20%E2%80%93%20kaks%20Balti%20j%C3%A4rvede%20kala%2C%20mille%20v%C3%A4%C3%A4rtus%20vajab%20uuesti%20m%C3%B5testamist%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1105 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783404984107&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1983541243.1783404985&frm=0&pscdl=denied&rcb=8&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938465~115938469~119027224~119576881~119576885~119576891~119576895&sid=1783404984&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fahven-ja-koha%2F&dt=Ahven%20ja%20koha%20%E2%80%93%20kaks%20Balti%20j%C3%A4rvede%20kala%2C%20mille%20v%C3%A4%C3%A4rtus%20vajab%20uuesti%20m%C3%B5testamist%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1105 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2583 ms._

**Document:**
- Lang: et
- Title: Ahven ja koha – kaks Balti järvede kala, mille väärtus vajab uuesti mõtestamist - Kawiare
- Canonical: https://kawiare.ee/ahven-ja-koha/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 235702

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/perch-and-pike-perch/
  - et → https://kawiare.ee/ahven-ja-koha/
  - lv → https://kawiare.lv/asaris-un-zandarts-divas-baltijas-ezeru-zivis/
  - x-default → https://kawiare.ee/ahven-ja-koha/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×6, h3 ×7, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Ahven ja koha
  - h2: Päritolu ja keskkond
  - h2: Ahven – delikaatne ja kiire
  - h2: Koha – kindel ja universaalne
  - h2: Miks need kalad on väärtuslikud täna
  - h2: Soovid rohkem teada saada?
  - h3: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi
  - h3: Kuidas eristada kvaliteetset punast kalamarja
  - h3: Kuidas ära tunda tõeliselt head kaheksajalga
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| tent/uploads/2026/01/Kawiare_ahven-ja-koha_header-scaled.jpg | Ahven ja koha – kaks Balti järvede kala, | 2560×717 | eager | ✗ |
| content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| wp-content/uploads/2026/01/Kawiare_punane-kalamari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| .ee/wp-content/uploads/2026/01/Kawiare_kaheksajalg_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 1 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0`
- Hero image eagerly loaded:
  - `hero: …kawiare.ee/wp-content/uploads/2026/01/Kawiare_ahven-ja-koha_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `…kawiare.ee/wp-content/uploads/2026/01/Kawiare_ahven-ja-koha_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 9 of 10 — https://kawiare.ee/lumekrabi

Run: 2026-07-07T06:16:47.427Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 18321 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **70** | 94 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **7.2 s** | 1.6 s |
| CLS | 0.000 | **0.000** |
| TBT | **111 ms** | 26 ms |
| FCP | **2.68 s** | 609 ms |
| Speed Index | **3.52 s** | 816 ms |
| TTFB | 3 ms | 3 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 7.2 s
2. **first-contentful-paint** (medium) — 2.7 s
3. **speed-index** (low) — 3.5 s
4. **document-latency-insight** (high) — Est savings of 330 ms
5. **image-delivery-insight** (high) — Est savings of 171 KiB

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 186 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 93 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.05, weight 25) — Largest Contentful Paint — 7.2 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.61, weight 10) — First Contentful Paint — 2.7 s
- `speed-index` (performance, score 0.88, weight 10) — Speed Index — 3.5 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.46, weight 0) — Time to Interactive — 7.7 s
- `max-potential-fid` (performance, score 0.71, weight 0) — Max Potential First Input Delay — 190 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 445 ms._

**Transport:**
- Final URL: https://kawiare.ee/lumekrabi/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/lumekrabi does not redirect to HTTPS (target: http://kawiare.ee/lumekrabi/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 06 Jul 2026 22:27:40 GMT
- expires: Tue, 07 Jul 2026 06:16:47 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 32464
- Decoded body: 130.9 KB
- Compression ratio: 0.242

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/lumekrabi does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 32464
content-type: text/html; charset=UTF-8
date: Tue, 07 Jul 2026 06:16:47 GMT
expires: Tue, 07 Jul 2026 06:16:47 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 06 Jul 2026 22:27:40 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 789 ms._

**Scoring:** 2 errors · 5 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2590 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 85 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2604 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 960.9 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 571.4 KB |
| script | 19 | 251.7 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 31.7 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 161.2 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 413 ms, 161.2 KB
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 408 ms, 215 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 378 ms, 22 B
- https://kawiare.ee/lumekrabi (document) — 220 ms, 0 B
- https://kawiare.ee/wp-content/themes/kawiare/assets/Josefin_Sans/static/JosefinSans-Regular.ttf (font) — 70 ms, 29.5 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783405007715&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=2056345280.1783405009&frm=0&pscdl=denied&rcb=11&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616985~115938466~115938469~118395333~118897920~118897930~119027224~119576881~119576885~119576891~119576895&sid=1783405008&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Flumekrabi%2F&dt=Lumekrabi%20on%20tervislik%2C%20j%C3%A4tkusuutlik%20ja%20peene%20maitsega%20delikatess%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.plf=4.5.3&tfd=1187 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783405007715&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=2056345280.1783405009&frm=0&pscdl=denied&rcb=11&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616985~115938466~115938469~118395333~118897920~118897930~119027224~119576881~119576885~119576891~119576895&sid=1783405008&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Flumekrabi%2F&dt=Lumekrabi%20on%20tervislik%2C%20j%C3%A4tkusuutlik%20ja%20peene%20maitsega%20delikatess%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.plf=4.5.3&tfd=1187 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2604 ms._

**Document:**
- Lang: et
- Title: Lumekrabi on tervislik, jätkusuutlik ja peene maitsega delikatess - Kawiare
- Canonical: https://kawiare.ee/lumekrabi/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 237386

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/snow-crab/
  - et → https://kawiare.ee/lumekrabi/
  - lv → https://kawiare.lv/sniega-krabis-veseliga-ilgtspejiga-un-izsmalcinatas-garsas-delikatese/
  - x-default → https://kawiare.ee/lumekrabi/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×7, h3 ×12, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Lumekrabi
  - h2: Mis on lumekrabi ja kust see pärineb?
  - h2: Kuidas eristada kvaliteetset lumekrabi?
  - h3: Külmutatud vs värske lumekrabi – mis vahe neil on?
  - h2: Kas lumekrabi on jätkusuutlik valik?
  - h3: Milliseid vastutustundlikke valikuid tarbijad saavad teha?
  - h2: Miks lumekrabi on ideaalne valik terviseteadlikule inimesele?
  - h3: Madala kalorsuse ja kõrge valgusisaldusega supertoit
  - h3: Omega-3 rasvhapped ja nende mõju ajule ja südamele
  - h3: Kuidas lumekrabi sobib fitness-toitumisega
  - h2: Lumekrabi igapäevases köögis
  - h2: Soovid rohkem teada saada?
  - h3: Ahven ja koha – kaks Balti järvede kala, mille väärtus vajab uuesti mõtestamist
  - h3: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi
  - h3: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| -content/uploads/2026/01/Kawiare_lumekrabi_header-scaled.jpg | Lumekrabi on tervislik, jätkusuutlik ja  | 2560×717 | eager | ✗ |
| e/wp-content/uploads/2026/01/Kawiare_ahven-ja-koha_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| are.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0`
- Hero image eagerly loaded:
  - `hero: …s://kawiare.ee/wp-content/uploads/2026/01/Kawiare_lumekrabi_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `…s://kawiare.ee/wp-content/uploads/2026/01/Kawiare_lumekrabi_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 10 of 10 — https://kawiare.ee/kaaviar-tanapaeval

Run: 2026-07-07T06:16:49.318Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 21222 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **61** | 99 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **8.4 s** | 0.9 s |
| CLS | 0.000 | **0.000** |
| TBT | **66 ms** | 23 ms |
| FCP | **4.58 s** | 614 ms |
| Speed Index | **6.43 s** | 985 ms |
| TTFB | 4 ms | **5 ms** |

### Priority fixes
1. **largest-contentful-paint** (high) — 8.4 s
2. **first-contentful-paint** (high) — 4.6 s
3. **speed-index** (high) — 6.4 s
4. **document-latency-insight** (high) — Est savings of 260 ms
5. **image-delivery-insight** (high) — Est savings of 186 KiB

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 65 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 113 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 53 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.02, weight 25) — Largest Contentful Paint — 8.4 s
- `first-contentful-paint` (performance, score 0.14, weight 10) — First Contentful Paint — 4.6 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `speed-index` (performance, score 0.40, weight 10) — Speed Index — 6.4 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.39, weight 0) — Time to Interactive — 8.4 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 425 ms._

**Transport:**
- Final URL: https://kawiare.ee/kaaviar-tanapaeval/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/kaaviar-tanapaeval does not redirect to HTTPS (target: http://kawiare.ee/kaaviar-tanapaeval/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 06 Jul 2026 22:27:42 GMT
- expires: Tue, 07 Jul 2026 06:16:49 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 32180
- Decoded body: 130.8 KB
- Compression ratio: 0.24

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/kaaviar-tanapaeval does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 32180
content-type: text/html; charset=UTF-8
date: Tue, 07 Jul 2026 06:16:49 GMT
expires: Tue, 07 Jul 2026 06:16:49 GMT
keep-alive: timeout=5, max=99
last-modified: Mon, 06 Jul 2026 22:27:42 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 861 ms._

**Scoring:** 2 errors · 6 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`
- (×1) [warning] Text run is not in Unicode Normalization Form C. Should instead be “
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta           ”. (Copy and paste that into your source document to replace the un-normalized text.) — first at line 497 `px] mt-8">
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma mu`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2362 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 81 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2373 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 944.1 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 555.0 KB |
| script | 19 | 251.7 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 31.4 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 161.2 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 341 ms, 22 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 338 ms, 215 B
- https://kawiare.ee/kaaviar-tanapaeval (document) — 327 ms, 0 B
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 151 ms, 161.2 KB
- https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783405009595&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=598249246.1783405010&frm=0&pscdl=denied&rcb=6&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938468~118395333~118897921~118897931~119027224~119576881~119576885~119576891~119576895&sid=1783405009&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkaaviar-tanapaeval%2F&dt=Kaaviar%20t%C3%A4nap%C3%A4eval%3A%20miks%20kasvukeskkond%20m%C3%A4%C3%A4rab%20kvaliteedi%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1012 (fetch) — 41 ms, 0 B

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783405009595&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=598249246.1783405010&frm=0&pscdl=denied&rcb=6&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938468~118395333~118897921~118897931~119027224~119576881~119576885~119576891~119576895&sid=1783405009&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkaaviar-tanapaeval%2F&dt=Kaaviar%20t%C3%A4nap%C3%A4eval%3A%20miks%20kasvukeskkond%20m%C3%A4%C3%A4rab%20kvaliteedi%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1012 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783405009595&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=598249246.1783405010&frm=0&pscdl=denied&rcb=6&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938468~118395333~118897921~118897931~119027224~119576881~119576885~119576891~119576895&sid=1783405009&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkaaviar-tanapaeval%2F&dt=Kaaviar%20t%C3%A4nap%C3%A4eval%3A%20miks%20kasvukeskkond%20m%C3%A4%C3%A4rab%20kvaliteedi%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1012 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2372 ms._

**Document:**
- Lang: et
- Title: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi - Kawiare
- Canonical: https://kawiare.ee/kaaviar-tanapaeval/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 237380

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/caviar-today/
  - et → https://kawiare.ee/kaaviar-tanapaeval/
  - lv → https://kawiare.lv/kaviars-musdienas-kapec-audzesanas-vide-nosaka-kvalitati/
  - x-default → https://kawiare.ee/kaaviar-tanapaeval/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×7, h3 ×8, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Kaaviar tänapäeval
  - h2: Miks kasvukeskkond on kaaviari kvaliteedi alus
  - h3: Itaalia kasvukeskkond ja vee loogika
  - h2: Traditsiooniline tootmisviis ja käsitöö
  - h2: Vastutus ja repopulatsioon
  - h2: Kaaviari tüübid ja nende iseloom
  - h2: Kuidas eristada kvaliteetset kaaviari
  - h2: Soovid rohkem teada saada?
  - h3: Lumekrabi on tervislik, jätkusuutlik ja peene maitsega delikatess
  - h3: Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta
  - h3: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| uploads/2026/01/Kawiare_kaaviar-tanapaeval_header-scaled.jpg | Kaaviar tänapäeval: miks kasvukeskkond m | 2560×717 | eager | ✗ |
| re.ee/wp-content/uploads/2026/01/Kawiare_lumekrabi_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| oads/2026/01/Kawiare_kaaviar-looduslik-toidulisand_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| are.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 43 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0`
- Hero image eagerly loaded:
  - `hero: …re.ee/wp-content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `…re.ee/wp-content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).