Audit

20260707T063401Z-1da2

← Back to kawiareee
Audited URL
https://kawiare.ee/
Timestamp
2026-07-07T06:46:56.860Z
Kind
site
Pages
10
Audit summary
https://kawiare.ee/
10 of 10 pages audited
Pagespeed scores
Other checks
LLM Report

Weighted audit summary

57
Overall site quality
Poorhigh confidence

Site overall 57 is the mean of 10 pages. Scores range 46 (https://kawiare.ee/ahven-ja-koha) → 62 (https://kawiare.ee/kammkarp). Weakest page: Mobile LCP of 9.6 s is a critical failure (>4 s threshold), dragging performance to 68 despite a 90 desktop score. Security is compromised by a missing HTTP-to-HTTPS redirect and a 40/100 header grade. Accessibility is strong (97 PSI) but has 1 serious contrast violation. W3C validation shows 2 errors. Confidence is high as all tools returned data.

Per-page scores
56
Home
high
55
/artiklid
high
62
…eetset-punast-kalamarja
high
62
…-kaaviar-ilma-muutideta
high
48
…iselt-head-kaheksajalga
high
62
…a-kvaliteetset-kaaviari
high
62
/kammkarp
high
46
/ahven-ja-koha
high
58
/lumekrabi
high
56
/kaaviar-tanapaeval
high

Audit Report: Kawiare - Experience of Taste

Website: https://kawiare.ee/
Date: 2026-07-07

Overall Score: 57 / 100
Status: 🟠 Poor
Confidence: high
Audit Coverage: 100% — all sources returned data

Pages Audited (10 of 10):

Summary

Site overall 57 is the mean of 10 pages. Scores range 46 (https://kawiare.ee/ahven-ja-koha) → 62 (https://kawiare.ee/kammkarp). Weakest page: Mobile LCP of 9.6 s is a critical failure (>4 s threshold), dragging performance to 68 despite a 90 desktop score. Security is compromised by a missing HTTP-to-HTTPS redirect and a 40/100 header grade. Accessibility is strong (97 PSI) but has 1 serious contrast violation. W3C validation shows 2 errors. Confidence is high as all tools returned data.

Per-Page Scores

Page Score Status Confidence
https://kawiare.ee/ 56 🟠 Poor high
https://kawiare.ee/artiklid 55 🟠 Poor high
https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja 62 🟡 Needs Improvement high
https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta 62 🟡 Needs Improvement high
https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga 48 🟠 Poor high
https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari 62 🟡 Needs Improvement high
https://kawiare.ee/kammkarp 62 🟡 Needs Improvement high
https://kawiare.ee/ahven-ja-koha 46 🟠 Poor high
https://kawiare.ee/lumekrabi 58 🟠 Poor high
https://kawiare.ee/kaaviar-tanapaeval 56 🟠 Poor high

PageSpeed Insights — Mobile vs Desktop

Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.

URL Performance (M / D) LCP (M / D) CLS (M / D)
https://kawiare.ee/ 49 / 69 9.19 s / 1.56 s 1.000 / 0.637
https://kawiare.ee/artiklid 67 / 91 9.46 s / 1.75 s 0.001 / 0.001
https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja 78 / 94 4.62 s / 1.50 s 0.000 / 0.000
https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta 69 / 92 8.51 s / 1.70 s 0.000 / 0.000
https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga 60 / 81 8.92 s / 1.89 s 0.000 / 0.000
https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari 69 / 95 8.76 s / 1.43 s 0.000 / 0.000
https://kawiare.ee/kammkarp 61 / 93 8.49 s / 1.67 s 0.000 / 0.000
https://kawiare.ee/ahven-ja-koha 68 / 90 9.58 s / 1.91 s 0.000 / 0.000
https://kawiare.ee/lumekrabi 62 / 94 8.49 s / 1.59 s 0.000 / 0.000
https://kawiare.ee/kaaviar-tanapaeval 61 / 95 8.18 s / 1.46 s 0.000 / 0.000

Optimization Checklist

4 of 7 passing — 4 pass · 2 warn · 1 fail

Item Status Detail
Page caching plugin / CDN active Pass Caching plugin detected (WP Rocket)
Images lazy-loaded Pass All raster images use loading="lazy".
Hero image eagerly loaded Pass Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable).
Hero is a real <img> (not a CSS background-image) Warn Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.
Responsive images (srcset / <picture>) Warn Only 15/22 raster images use srcset or <picture> (68%).
Reasonable number of image sizes Pass 17 distinct srcset widths.
JS scripts not blocking in <head> Fail 5 render-blocking scripts in <head>. Move to footer or add defer/async.

Fixes

Priority 1: Critical

Immediate action — impacts user experience, search rankings, or site safety.

1A. Optimize Largest Contentful Paint (LCP) Image

  • Impact: LCP, Performance Score
  • Problem: LCP is 9.2s on mobile (threshold ≤2.5s), caused by the hero image loading without priority.
  • Solution: Preload the LCP image and serve it in WebP/AVIF format:
    <link rel="preload" as="image" href="/img/hero.webp">
    <img src="/img/hero.webp" alt="..." fetchpriority="high">
    

1B. Fix Cumulative Layout Shift (CLS)

  • Impact: CLS, User Experience
  • Problem: CLS is 1.000 (threshold ≤0.1), caused by images and content shifting during load.
  • Solution: Reserve space for all images and dynamic content using explicit width and height attributes or aspect-ratio CSS:
    img { aspect-ratio: attr(width) / attr(height); }
    

1C. Force HTTPS redirect on HTTP requests

  • Impact: Security, Transport Layer
  • Problem: HTTP does not redirect to HTTPS (http://kawiare.ee/artiklid does not redirect), leaving users vulnerable to downgrade attacks.
  • Solution: Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic:
    RewriteEngine On
    RewriteCond %{HTTPS} off
    RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
    

1D. Fix Mobile LCP (9.5 s) by deferring JS and optimizing hero

  • Impact: Performance, Core Web Vitals
  • Problem: LCP is 9.5 s on mobile due to 16 render-blocking scripts and a hero image implemented as a CSS background (no srcset).
  • Solution:
    • Move non-critical scripts to footer or add defer/async.
    • Replace CSS background hero with a real <img> or <picture> element with fetchpriority="high".
    • Defer unused JavaScript (224 KB wasted).

1E. Enforce HTTPS Redirect

  • Impact: Security, Trust
  • Problem: HTTP requests to http://kawiare.ee do not redirect to HTTPS, exposing users to potential MITM attacks if they type the URL manually.
  • Solution: Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP traffic to HTTPS:
    RewriteEngine On
    RewriteCond %{HTTPS} off
    RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
    

1F. Eliminate Render-Blocking JavaScript

  • Impact: LCP, FCP, Performance
  • Problem: 11 render-blocking scripts delay FCP (2.65 s) and contribute to LCP (4.6 s); unused JS totals ~290 KB.
  • Solution: Add defer or async to non-critical scripts in <head>. Move critical CSS inline and defer remaining JS:
    <script src="main.js" defer></script>
    
    Consider code-splitting the 224 KB main.js bundle.

1G. Force HTTPS redirect for all HTTP traffic

  • Impact: Security, Data Integrity
  • Problem: Security audit shows 'http://kawiare.ee/... does not redirect to HTTPS', leaving users on unencrypted connections.
  • Solution: Configure the web server (Apache/Nginx) to return a 301 redirect from HTTP to HTTPS for all requests.
    RewriteEngine On
    RewriteCond %{HTTPS} off
    RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
    

1H. Optimize Largest Contentful Paint (LCP)

  • Impact: Performance, Mobile UX
  • Problem: Mobile LCP is 8.5 s (heavy penalty), driven by 11 render-blocking scripts and a large hero image (2560px).
  • Solution:
    • Defer non-critical JavaScript (11 render-blocking scripts found).
    • Preload the LCP image resource.
    • Compress the hero image to WebP/AVIF and reduce dimensions to viewport size.
    <link rel="preload" as="image" href="/path/to/hero.webp">
    

1I. Defer render-blocking JavaScript

  • Impact: LCP, FCP, Performance Score
  • Problem: 11 render-blocking scripts delay FCP to 4.6s and LCP to 8.9s on mobile.
  • Solution: Add defer or async to non-critical scripts in <head>. Move critical CSS inline and load JS at the bottom or via defer:
    <script src="..." defer></script>
    

1J. Eliminate render-blocking JavaScript to fix LCP

  • Impact: LCP (8.8s), FCP (2.6s), Mobile Performance (69)
  • Problem: 5 render-blocking scripts in <head> delay rendering; LCP is 8.8s on mobile, far above the 2.5s target.
  • Solution: Move non-critical scripts to the footer or add defer/async attributes. Prioritize deferring WooCommerce and Google Tag Manager scripts:
    <script src="..." defer></script>
    <script src="..." async></script>
    

Priority 2: Important

Essential for compliance, user reach, and search visibility.

2A. Defer Render-Blocking JavaScript

  • Impact: FCP, LCP, TBT
  • Problem: 11 render-blocking scripts (including jQuery and WooCommerce) delay first paint.
  • Solution: Add defer or async to non-critical scripts in <head>:
    <script src="..." defer></script>
    

2B. Strengthen Security Headers

  • Impact: Transport Security, Clickjacking
  • Problem: HSTS is missing the preload directive; CSP is absent (signals show no auth/payments, so P2/P3).
  • Solution: Update HSTS header and add CSP:
    Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
    Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com;
    

2C. Fix accessibility violations (Contrast & Headings)

  • Impact: WCAG Compliance, Usability
  • Problem: 1 serious color-contrast violation (#cookiescript_accept) and heading order skips (H1 → H3).
  • Solution:
    • Increase contrast ratio for .cookiescript_accept to ≥4.5:1.
    • Insert an H2 between the H1 and H3s, or change the H3s to H2s to maintain sequential order.

2D. Strengthen Security Headers (HSTS, COOP, CORP)

  • Impact: Transport Security, Context Isolation
  • Problem: HSTS missing preload directive; COOP and CORP missing (grade 40/100).
  • Solution: Add the following headers:
    Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
    Header always set Cross-Origin-Opener-Policy "same-origin"
    Header always set Cross-Origin-Resource-Policy "same-origin"
    

2E. Fix Accessibility Violations

  • Impact: WCAG 2.1 AA Compliance
  • Problem: One serious color-contrast violation on #cookiescript_accept and moderate landmark issues (duplicate main, main not top-level).
  • Solution:
    • Increase contrast ratio on #cookiescript_accept to ≥4.5:1.
    • Ensure <main> is a direct child of <body> and remove duplicate role="main" attributes.
    • Add a skip-to-content link at the top of the DOM.

2F. Add Content-Security-Policy (CSP) and HSTS Preload

  • Impact: XSS Defense, Transport Security
  • Problem: CSP is missing and HSTS lacks the preload directive; Security Headers grade is 40/100.
  • Solution:
    • Add CSP with nonce/hash strategy (even for brochure sites, it mitigates injection risks).
    • Add preload to HSTS header.
    Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'"
    Header set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
    

2G. Fix Accessibility Violations (Contrast & Landmarks)

  • Impact: WCAG Compliance, Screen Reader Support
  • Problem: axe-core reports 1 serious color-contrast violation (#cookiescript_accept) and missing skip-to-content link.
  • Solution:
    • Increase contrast ratio for .lead-text and cookie banner to ≥4.5:1.
    • Add a skip link at the top of the DOM:
    <a href="#main" class="skip-link">Otse sisule</a>
    

2H. Fix color contrast on cookie consent buttons

  • Impact: Accessibility (WCAG 1.4.3)
  • Problem: axe-core reports 1 serious violation: #cookiescript_accept and #cookiescript_reject fail contrast thresholds.
  • Solution: Increase text color contrast to at least 4.5:1 against the background. Use browser dev tools to test contrast ratios before deploying:
    #cookiescript_accept, #cookiescript_reject {
      color: #333333; /* Adjust to meet ratio */
      background: #ffffff;
    }
    

2I. Harden security headers

  • Impact: Transport security, Context isolation
  • Problem: HSTS missing preload directive; COOP, CORP, and Permissions-Policy are missing.
  • Solution: Update server headers to include preload and context isolation:
    Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
    Header always set Cross-Origin-Opener-Policy "same-origin"
    Header always set Cross-Origin-Resource-Policy "same-origin"
    

2J. Defer Render-Blocking Scripts

  • Impact: FCP, TBT, Performance
  • Problem: HTML Inventory reports 11 render-blocking external scripts, including WooCommerce and jQuery, delaying page interactivity.
  • Solution: Add defer or async attributes to non-critical scripts in <head>:
    <script src="/wp-content/plugins/woocommerce/..." defer></script>
    
    • Move critical CSS inline and defer the rest.
    • Remove unused JavaScript identified in PSI (224 KB wasted).

2K. Fix Color Contrast Violation

  • Impact: Accessibility, WCAG 1.4.3
  • Problem: axe-core reports 1 serious violation on #cookiescript_accept where foreground/background contrast is insufficient.
  • Solution: Increase text color contrast to at least 4.5:1 ratio for the cookie consent button text. Use a darker text color or lighter background in CSS.

Priority 3: Best Practice

Recommended for long-term maintainability.

3A. Correct HTML Structure and Accessibility

  • Impact: SEO, Screen Readers
  • Problem: Page has 3 <h1> elements and missing skip-to-content link; serious contrast violation on cookie button.
  • Solution: Ensure only one <h1> per page, add <a href="#main" class="skip-link">Skip to content</a>, and fix contrast on #cookiescript_accept.

3B. Implement Content Security Policy (CSP)

  • Impact: XSS Defense-in-Depth
  • Problem: CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower, but WP sites benefit from CSP.
  • Solution: Deploy a nonce-based CSP rather than a flat allowlist:
    Header always set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';"
    

3C. Improve SEO & HTML Validity

  • Impact: Search Visibility, Code Quality
  • Problem: Missing meta description affects SEO snippet; W3C reports 2 errors (invalid <style> in <div>, unescaped <).
  • Solution:
    • Add a <meta name="description" content="..."> tag.
    • Move inline <style> blocks to the <head> or external CSS.
    • Escape special characters in text content (e.g., &lt; instead of <).

3D. Add Meta Description and Fix W3C Errors

  • Impact: SEO, Code Quality
  • Problem: SEO audit flags missing meta description; W3C validator reports 2 errors (invalid style tag placement, unescaped character).
  • Solution:
    • Add <meta name="description" content="..."> summarizing the article.
    • Move <style> blocks to <head> or use inline styles correctly.
    • Escape < characters in text content as &lt;.

3E. Optimize image delivery

  • Impact: Page weight, LCP
  • Problem: 2 images missing loading="lazy", 2 missing srcset, and LCP image is a large PNG.
  • Solution:
    • Add loading="lazy" to below-fold images.
    • Generate WebP/AVIF versions and use <picture> or srcset.
    • Ensure LCP image has fetchpriority="high" and explicit dimensions.

3F. Implement Content-Security-Policy (CSP)

  • Impact: XSS defense-in-depth
  • Problem: CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower, but CSP remains a best practice.
  • Solution: Deploy a strict CSP with nonce/hash for scripts rather than a flat allowlist:
    Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';"
    

3G. Resolve HTML Validation & SEO Gaps

  • Impact: Maintainability, Search Visibility
  • Problem: W3C reported 2 errors (style in div, bad char) and SEO audit notes missing meta description.
  • Solution:
    • Move <style> blocks out of <div> containers.
    • Escape special characters (e.g., < to &lt;).
    • Add a meta description tag:
    <meta name="description" content="...">
    
▸Raw Markdown sent to the LLM
# Site Audit — https://kawiare.ee/
Run: 2026-07-07T06:34:02.036Z

Audited **10** of 10 discovered pages.
Average per-page audit coverage: **100%**

Pages audited:
- https://kawiare.ee/
- https://kawiare.ee/artiklid
- https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja
- https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta
- https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga
- https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari
- https://kawiare.ee/kammkarp
- https://kawiare.ee/ahven-ja-koha
- https://kawiare.ee/lumekrabi
- https://kawiare.ee/kaaviar-tanapaeval

---

# Page 1 of 10 — https://kawiare.ee/

Run: 2026-07-07T06:34:04.225Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 14532 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **49** | 69 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **9.2 s** | 1.6 s |
| CLS | **1.000** | 0.637 |
| TBT | 38 ms | **144 ms** |
| FCP | **1.98 s** | 438 ms |
| Speed Index | **3.10 s** | 1.06 s |
| TTFB | 4 ms | 4 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 9.2 s
2. **cumulative-layout-shift** (high) — 1
3. **first-contentful-paint** (low) — 2.0 s
4. **cls-culprits-insight** (high)
5. **image-delivery-insight** (high) — Est savings of 638 KiB

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 163 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Layout-shift sources
- body.home > div#page > main#primary > div.grid — shift 1.000
- main#primary > div.grid > section.larger-content > h2.text-center — shift 0.000

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 112 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 57 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.01, weight 25) — Largest Contentful Paint — 9.2 s
- `cumulative-layout-shift` (performance, score 0.02, weight 25) — Cumulative Layout Shift — 1
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.85, weight 10) — First Contentful Paint — 2.0 s
- `cls-culprits-insight` (performance, score 0.00, weight 0) — Layout shift culprits
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.31, weight 0) — Time to Interactive — 9.4 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 225 ms._

**Transport:**
- Final URL: https://kawiare.ee/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 07 Jul 2026 06:03:06 GMT
- expires: Tue, 07 Jul 2026 06:34:04 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 32486
- Decoded body: 148.1 KB
- Compression ratio: 0.214

### Priority fixes
1. **strict-transport-security weak** (high) — missing preload directive
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
4. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
5. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
6. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
7. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 32486
content-type: text/html; charset=UTF-8
date: Tue, 07 Jul 2026 06:34:04 GMT
expires: Tue, 07 Jul 2026 06:34:04 GMT
keep-alive: timeout=5, max=95
last-modified: Tue, 07 Jul 2026 06:03:06 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 529 ms._

**Scoring:** 1 errors · 6 warnings · 70 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 174

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 174 `te">

    <style>
    /`
- (×1) [warning] Section lacks heading. Consider using “h2”-“h6” elements to add identifying headings to all sections, or else use a “div” element instead for any cases where no heading is needed. — first at line 394 `</script>
<section  class="relative">
<div`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 401 `<h2 class="text-center">MAITSE`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2871 ms._

**Scoring:** 1 violations · 54 passes · critical 0 · serious 1 · moderate 0 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 74 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2888 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 53 network requests · 1.84 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 21 | 1.46 MB |
| script | 19 | 251.6 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 1 | 31.7 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 161.2 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 563 ms, 22 B
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 430 ms, 161.2 KB
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 360 ms, 215 B
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 (script) — 130 ms, 0 B
- https://kawiare.ee/wp-content/themes/kawiare/assets/Josefin_Sans/static/JosefinSans-Regular.ttf (font) — 92 ms, 29.5 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406044332&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1792356443.1783406045&frm=0&pscdl=denied&rcb=12&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938465~115938469~119027224~119527019~119576881~119576885~119576891~119576895&sid=1783406044&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2F&dt=Kawiare%20-%20Experience%20of%20Taste&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1101 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406044332&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1792356443.1783406045&frm=0&pscdl=denied&rcb=12&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938465~115938469~119027224~119527019~119576881~119576885~119576891~119576895&sid=1783406044&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2F&dt=Kawiare%20-%20Experience%20of%20Taste&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1101 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2888 ms._

**Document:**
- Lang: et
- Title: Kawiare - Experience of Taste
- Canonical: https://kawiare.ee/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 259279

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang:
  - en → https://kawiare.eu/
  - et → https://kawiare.ee/
  - lv → https://kawiare.lv/
  - x-default → https://kawiare.ee/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×3, h2 ×5, h3 ×15, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: MAITSE, MILLEL ON TÄHENDUS
  - h1: HEA MAITSE ALGAB PÄRITOLUST
  - h1: KUS MAITSE KOHTUB TEADMISEGA
  - h2: MAITSE SÜNNIBTEADLIKEST VALIKUTEST
  - h2: Tutvu valikuga
  - h3: Lumekrabi liha
  - h3: Siberian, 100g
  - h3: Forellimari, 100g
  - h3: Kohafilee
  - h2: TUTVU MEREANDIDE MAAILMAGA
  - h3: 20 punkti, kuidas eristada kvaliteetset kaaviari
  - h3: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi
  - h3: Kuidas ära tunda tõeliselt head kaheksajalga
  - h3: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid
  - h2: Kulinaarne inspiratsioon
  - h3: Krabiliha “Crab Roll”
  - h3: Külm roheline karri röstitud kammkarpidega
  - h3: Kammkarbi crudo kirevilja ponzuga
  - h2: Liitu meie kogukonnaga
  - h3: POOD

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 46 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 22 total — **0 without alt**, **0 without width/height**, 6 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| //kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-1.png | MAITSE, MILLEL ON TÄHENDUS | 2560×1900 | eager | ✗ |
| wp-content/uploads/2026/06/Kawiare-tooted-e1782658950478.png | MAITSE, MILLEL ON TÄHENDUS | 1900×2560 | eager | ✗ |
| tent/uploads/2026/02/Kawiare_paisepildid_mob_2_1900x2560.jpg | HEA MAITSE ALGAB PÄRITOLUST | 2560×1900 | lazy | ✗ |
| ee/wp-content/uploads/2026/02/pais2_uus_2595x1467-scaled.jpg | HEA MAITSE ALGAB PÄRITOLUST | 1900×2560 | lazy | ✗ |
| tent/uploads/2026/02/Kawiare_paisepildid_mob_3_1900x2560.jpg | KUS MAITSE KOHTUB TEADMISEGA | 2560×1900 | lazy | ✗ |
| are.ee/wp-content/uploads/2026/02/pais2_2595x1467-scaled.jpg | KUS MAITSE KOHTUB TEADMISEGA | 1900×2560 | lazy | ✗ |
| nt/uploads/2026/01/Kawiare_crab_legs_500g_2000px-300x300.png | _(empty)_ | 300×300 | _n/a_ | ✓ |
| 026/01/828829589-kawiare_crab_legs_hover1_2000px-300x300.jpg | Lumekrabi liha | 300×300 | lazy | ✓ |
| ads/2026/01/Kawiare_caviar_siberian_big_2000px_2-300x300.png | _(empty)_ | 300×300 | _n/a_ | ✓ |
| //kawiare.ee/wp-content/uploads/2026/01/Siberian-300x300.jpg | Siberian, 100g | 300×300 | lazy | ✓ |
| p-content/uploads/2026/01/Kawiare_trout_2000px_2-300x300.png | _(empty)_ | 300×300 | _n/a_ | ✓ |
| ds/2026/01/828829653-kawiare_trout_hover1_2000px-300x300.jpg | Forellimari, 100g | 300×300 | lazy | ✓ |
| t/uploads/2026/01/Kawiare_pike-uerch_500g_2000px-300x300.png | _(empty)_ | 300×300 | lazy | ✓ |
| 26/01/828829676-kawiare_pike-perch_hover1_2000px-300x300.jpg | Kohafilee | 300×300 | lazy | ✓ |
| t/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |

**Links:** 59 anchors — 5 external, 1 preconnect, 2 preload.

Vague repeated link text:
- "artiklid" ×6
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "meie valik" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Document has 3 <h1> elements** (medium) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 15/22 raster images use srcset or <picture> (68%). |
| Reasonable number of image sizes | ✓ pass | 17 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0`
- Hero image eagerly loaded:
  - `hero: https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-1.png`
  - `loading: eager`
  - `fetchpriority: (not set)`
- Responsive images (srcset / <picture>):
  - `https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-1.png`
  - `https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-e1782658950478.png`
  - `…kawiare.ee/wp-content/uploads/2026/02/Kawiare_paisepildid_mob_2_1900x2560.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/02/pais2_uus_2595x1467-scaled.jpg`
  - `…kawiare.ee/wp-content/uploads/2026/02/Kawiare_paisepildid_mob_3_1900x2560.jpg`
- Reasonable number of image sizes:
  - `widths: 100, 150, 200, 225, 300, 600, 683, 768, 800, 1024, 1080, 1152, 1365, 1536, 1707, 1920, 2000`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 15/22 raster images use srcset or <picture> (68%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 2 of 10 — https://kawiare.ee/artiklid

Run: 2026-07-07T06:34:04.227Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 19383 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **67** | 91 |
| Accessibility | 96 | 96 |
| Best Practices | 100 | 100 |
| SEO | 85 | 85 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **9.5 s** | 1.7 s |
| CLS | 0.001 | **0.001** |
| TBT | **165 ms** | 105 ms |
| FCP | **2.85 s** | 664 ms |
| Speed Index | **3.82 s** | 908 ms |
| TTFB | **5 ms** | 3 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 9.5 s
2. **first-contentful-paint** (medium) — 2.8 s
3. **speed-index** (low) — 3.8 s
4. **document-latency-insight** (high) — Est savings of 330 ms
5. **forced-reflow-insight** (high)

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Layout-shift sources
- section.relative > div.pt-24 > div.mx-auto > h1.mb-4 — shift 0.001

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 220 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 119 ms
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1 — 61 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 50 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 9.5 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.55, weight 10) — First Contentful Paint — 2.8 s
- `heading-order` (accessibility, score 0.00, weight 3) — Heading elements are not in a sequentially-descending order
- `speed-index` (performance, score 0.83, weight 10) — Speed Index — 3.8 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `crawlable-anchors` (seo, score 0.00, weight 1) — Links are not crawlable
- `interactive` (performance, score 0.28, weight 0) — Time to Interactive — 9.8 s
- `max-potential-fid` (performance, score 0.59, weight 0) — Max Potential First Input Delay — 220 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 449 ms._

**Transport:**
- Final URL: https://kawiare.ee/artiklid/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/artiklid does not redirect to HTTPS (target: http://kawiare.ee/artiklid/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 06 Jul 2026 22:26:35 GMT
- expires: Tue, 07 Jul 2026 06:34:04 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 31627
- Decoded body: 141.7 KB
- Compression ratio: 0.218

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/artiklid does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 31627
content-type: text/html; charset=UTF-8
date: Tue, 07 Jul 2026 06:34:04 GMT
expires: Tue, 07 Jul 2026 06:34:04 GMT
keep-alive: timeout=5, max=94
last-modified: Mon, 06 Jul 2026 22:26:35 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1027 ms._

**Scoring:** 2 errors · 5 warnings · 63 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 170
2. **The heading “h3” (with computed level 3) follows the heading “h1” (with computed level 1), skipping 1 heading level.** (medium) — x1, first at line 476

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 170 `te">

    <style>
    /`
- (×1) [warning] Text run is not in Unicode Normalization Form C. Should instead be “
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta           ”. (Copy and paste that into your source document to replace the un-normalized text.) — first at line 717 `px] mt-8">
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma mu`
- (×1) [error] The heading “h3” (with computed level 3) follows the heading “h1” (with computed level 1), skipping 1 heading level. — first at line 476 `<h3 class="text-[24px] leading-[100%] text-white mb-[20px] mt-8">`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2868 ms._

**Scoring:** 2 violations · 54 passes · critical 0 · serious 1 · moderate 1 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **heading-order** (medium) — Heading levels should only increase by one

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `heading-order` (moderate)
[Heading levels should only increase by one](https://dequeuniversity.com/rules/axe/4.11/heading-order?application=playwright)
- `.product__item.group.justify-between:nth-child(1) > div:nth-child(1) > .lg\:px-6.px-4 > .text-\[24px\].mb-\[20px\].mt-8`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 65 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2881 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 51 network requests · 1.26 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 11 | 867.2 KB |
| script | 24 | 272.2 KB |
| font | 2 | 58.9 KB |
| stylesheet | 9 | 58.6 KB |
| document | 2 | 30.9 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 161.2 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 341 ms, 22 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 333 ms, 215 B
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 250 ms, 161.2 KB
- https://kawiare.ee/artiklid (document) — 237 ms, 0 B
- https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406044557&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=2034623254.1783406045&frm=0&pscdl=denied&rcb=13&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616985~115938465~115938469~118897921~118897931~119027224~119576881~119576885~119576891~119576895&sid=1783406044&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fartiklid%2F&dt=Artiklid%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.plf=4.5.3&tfd=1037 (fetch) — 92 ms, 0 B

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406044557&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=2034623254.1783406045&frm=0&pscdl=denied&rcb=13&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616985~115938465~115938469~118897921~118897931~119027224~119576881~119576885~119576891~119576895&sid=1783406044&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fartiklid%2F&dt=Artiklid%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.plf=4.5.3&tfd=1037 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406044557&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=2034623254.1783406045&frm=0&pscdl=denied&rcb=13&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616985~115938465~115938469~118897921~118897931~119027224~119576881~119576885~119576891~119576895&sid=1783406044&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fartiklid%2F&dt=Artiklid%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.plf=4.5.3&tfd=1037 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2880 ms._

**Document:**
- Lang: et
- Title: Artiklid - Kawiare
- Canonical: https://kawiare.ee/artiklid/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 248645

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang:
  - en → https://kawiare.eu/insights/
  - et → https://kawiare.ee/artiklid/
  - lv → https://kawiare.lv/zurnals/
  - x-default → https://kawiare.ee/artiklid/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×12, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: MEREANDIDE MAAILM
  - h3: 20 punkti, kuidas eristada kvaliteetset kaaviari
  - h3: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi
  - h3: Kuidas ära tunda tõeliselt head kaheksajalga
  - h3: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid
  - h3: Ahven ja koha – kaks Balti järvede kala, mille väärtus vajab uuesti mõtestamist
  - h3: Kuidas eristada kvaliteetset punast kalamarja
  - h3: Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta
  - h3: Lumekrabi on tervislik, jätkusuutlik ja peene maitsega delikatess
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE
- Skips:
  - h1 → h3 after "MEREANDIDE MAAILM"

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 51 total — 6 defer, 2 async, 16 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/jquery/ui/core.min.js?ver=1.13.3

**Stylesheets:** 9 external, 17 inline (68.3 KB)

**Images:** 9 total — **0 without alt**, **0 without width/height**, 4 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| t/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_thumb.jpg | _(empty)_ | 800×450 | _n/a_ | ✓ |
| content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_thumb.jpg | _(empty)_ | 800×450 | _n/a_ | ✓ |
| .ee/wp-content/uploads/2026/01/Kawiare_kaheksajalg_thumb.jpg | _(empty)_ | 800×450 | _n/a_ | ✓ |
| are.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| e/wp-content/uploads/2026/01/Kawiare_ahven-ja-koha_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| wp-content/uploads/2026/01/Kawiare_punane-kalamari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| oads/2026/01/Kawiare_kaaviar-looduslik-toidulisand_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| re.ee/wp-content/uploads/2026/01/Kawiare_lumekrabi_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 54 anchors — 6 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Heading level skips** (medium) — h1→h3 after "MEREANDIDE MAAILM"
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **16 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 5 pass · 1 warn · 1 fail

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | ! warn | Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file. |
| Responsive images (srcset / <picture>) | ✓ pass | 8/9 raster images use srcset or <picture> (89%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0`
- Hero image eagerly loaded:
  - `hero: …iare.ee/wp-content/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_thumb.jpg`
  - `loading: (not set)`
  - `fetchpriority: high`
- Hero is a real <img> (not a CSS background-image):
  - `selector: div.pt-24.pb-16`
  - `url: …e.ee/wp-content/uploads/2026/01/823960696-teadmuskeskus_2592x726_b-scaled.jpg`
  - `box: 1280×464px`
- Responsive images (srcset / <picture>):
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Hero is a real <img> (not a CSS background-image)** (medium) — Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 3 of 10 — https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja

Run: 2026-07-07T06:34:23.943Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 17514 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **78** | 94 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **4.6 s** | 1.5 s |
| CLS | 0.000 | **0.000** |
| TBT | 75 ms | 75 ms |
| FCP | **2.65 s** | 647 ms |
| Speed Index | **3.52 s** | 911 ms |
| TTFB | 4 ms | **5 ms** |

### Priority fixes
1. **largest-contentful-paint** (high) — 4.6 s
2. **first-contentful-paint** (medium) — 2.6 s
3. **speed-index** (low) — 3.5 s
4. **document-latency-insight** (high) — Est savings of 360 ms
5. **image-delivery-insight** (high) — Est savings of 220 KiB

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 159 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 70 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.34, weight 25) — Largest Contentful Paint — 4.6 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.62, weight 10) — First Contentful Paint — 2.6 s
- `speed-index` (performance, score 0.88, weight 10) — Speed Index — 3.5 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.50, weight 0) — Time to Interactive — 7.3 s
- `max-potential-fid` (performance, score 0.81, weight 0) — Max Potential First Input Delay — 160 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 466 ms._

**Transport:**
- Final URL: https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja does not redirect to HTTPS (target: http://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 06 Jul 2026 22:26:37 GMT
- expires: Tue, 07 Jul 2026 06:34:24 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 32005
- Decoded body: 130.7 KB
- Compression ratio: 0.239

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 32005
content-type: text/html; charset=UTF-8
date: Tue, 07 Jul 2026 06:34:24 GMT
expires: Tue, 07 Jul 2026 06:34:24 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 06 Jul 2026 22:26:37 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 815 ms._

**Scoring:** 2 errors · 5 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2752 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 84 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2763 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 976.7 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 587.7 KB |
| script | 19 | 251.6 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 31.3 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 161.2 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 391 ms, 161.2 KB
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 338 ms, 22 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 337 ms, 215 B
- https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja (document) — 220 ms, 0 B
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 (script) — 58 ms, 0 B

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406064231&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1528092161.1783406065&frm=0&pscdl=denied&rcb=7&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616986~115938465~115938468~118395334~118826209~119027224~119576881~119576885~119576891~119576895&sid=1783406064&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkuidas-eristada-kvaliteetset-punast-kalamarja%2F&dt=Kuidas%20eristada%20kvaliteetset%20punast%20kalamarja%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1166 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406064231&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1528092161.1783406065&frm=0&pscdl=denied&rcb=7&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616986~115938465~115938468~118395334~118826209~119027224~119576881~119576885~119576891~119576895&sid=1783406064&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkuidas-eristada-kvaliteetset-punast-kalamarja%2F&dt=Kuidas%20eristada%20kvaliteetset%20punast%20kalamarja%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1166 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2763 ms._

**Document:**
- Lang: et
- Title: Kuidas eristada kvaliteetset punast kalamarja - Kawiare
- Canonical: https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 237289

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/how-to-identify-quality-red-fish-roe/
  - et → https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja/
  - lv → https://kawiare.lv/ka-atskirt-kvalitativus-sarkanos-zivju-ikrus/
  - x-default → https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×8, h3 ×7, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Kuidas eristada kvaliteetset punast kalamarja
  - h2: Välimus ja tera ühtlus
  - h2: Lõhn
  - h2: Maitse ja tekstuur
  - h2: Soolasus
  - h2: Koostis ja lisandid
  - h2: Päritolu ja jälgitavus
  - h2: Soovid rohkem teada saada?
  - h3: 20 punkti, kuidas eristada kvaliteetset kaaviari
  - h3: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi
  - h3: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| nt/uploads/2026/01/Kawiare_punane-kalamari_header-scaled.jpg | Kuidas eristada kvaliteetset punast kala | 2560×717 | eager | ✗ |
| t/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| are.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0`
- Hero image eagerly loaded:
  - `hero: …wiare.ee/wp-content/uploads/2026/01/Kawiare_punane-kalamari_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `…wiare.ee/wp-content/uploads/2026/01/Kawiare_punane-kalamari_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 4 of 10 — https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta

Run: 2026-07-07T06:34:29.336Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 17867 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **69** | 92 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **8.5 s** | 1.7 s |
| CLS | 0.000 | **0.000** |
| TBT | 49 ms | **99 ms** |
| FCP | **2.63 s** | 625 ms |
| Speed Index | **4.19 s** | 987 ms |
| TTFB | 3 ms | 3 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 8.5 s
2. **first-contentful-paint** (medium) — 2.6 s
3. **speed-index** (low) — 4.2 s
4. **document-latency-insight** (high) — Est savings of 260 ms
5. **image-delivery-insight** (high) — Est savings of 170 KiB

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 99 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.01, weight 25) — Largest Contentful Paint — 8.5 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.63, weight 10) — First Contentful Paint — 2.6 s
- `speed-index` (performance, score 0.77, weight 10) — Speed Index — 4.2 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.38, weight 0) — Time to Interactive — 8.5 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 462 ms._

**Transport:**
- Final URL: https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta does not redirect to HTTPS (target: http://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 06 Jul 2026 22:26:39 GMT
- expires: Tue, 07 Jul 2026 06:34:29 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 32617
- Decoded body: 132.5 KB
- Compression ratio: 0.24

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 32617
content-type: text/html; charset=UTF-8
date: Tue, 07 Jul 2026 06:34:29 GMT
expires: Tue, 07 Jul 2026 06:34:29 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 06 Jul 2026 22:26:39 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 597 ms._

**Scoring:** 2 errors · 10 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [warning] Text run is not in Unicode Normalization Form C. Should instead be “Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta - Kawiar”. (Copy and paste that into your source document to replace the un-normalized text.) — first at line 43 `>
	<title>Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta - Kawia`
- (×1) [warning] The value of attribute “content” on element “meta” from namespace “http://www.w3.org/1999/xhtml” is not in Unicode Normalization Form C. — first at line 47 `icle" />
	<meta property="og:title" content="Kaaviar kui looduslik toidulisand e`
- (×1) [warning] Text run is not in Unicode Normalization Form C. Should instead be “{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/kawiare.ee\/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta\/#article","isPartOf":{"@id":"https:\/\/kawiare.ee\/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta\/"},"author":{"name":"artur","@id":"https:\/\/kawiare.ee\/#\/schema\/person\/03967b4e81b1b99ca46d262a3463ac35"},"headline":"Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta","datePublished":"2026-01-14T12:37:14+00:00","dateModified":"2026-03-02T17:57:24+00:00","mainEntityOfPage":{"@id":"https:\/\/kawiare.ee\/kaaviar-kui-l”. (Copy and paste that into your source document to replace the un-normalized text.) — first at line 63 `ma-graph">{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":`
- (×1) [warning] The value of attribute “title” on element “link” from namespace “http://www.w3.org/1999/xhtml” is not in Unicode Normalization Form C. — first at line 69 `.com' />

<link rel="alternate" type="application/rss+xml" title="Kawiare &raquo`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`
- (×1) [warning] The value of attribute “alt” on element “img” from namespace “http://www.w3.org/1999/xhtml” is not in Unicode Normalization Form C. — first at line 418 `<img fetchpriority="high" width="2560" height="717" class="mb-8 w-full h-auto" s`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2758 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 80 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2768 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 959.8 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 570.2 KB |
| script | 19 | 251.6 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 31.9 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 161.2 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 588 ms, 161.2 KB
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 332 ms, 22 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 233 ms, 215 B
- https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta (document) — 216 ms, 0 B
- https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_kaheksajalg_thumb-600x338.jpg (image) — 69 ms, 33.8 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406069619&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=16112608.1783406071&frm=0&pscdl=denied&rcb=3&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938465~115938468~119027224~119576881~119576885~119576891~119576895&sid=1783406070&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta%2F&dt=Kaaviar%20kui%20looduslik%20toidulisand%20ehk%20kaaviar%20ilma%20mu%CC%88u%CC%88tideta%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1357 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406069619&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=16112608.1783406071&frm=0&pscdl=denied&rcb=3&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938465~115938468~119027224~119576881~119576885~119576891~119576895&sid=1783406070&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta%2F&dt=Kaaviar%20kui%20looduslik%20toidulisand%20ehk%20kaaviar%20ilma%20mu%CC%88u%CC%88tideta%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1357 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2768 ms._

**Document:**
- Lang: et
- Title: Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta - Kawiare
- Canonical: https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 239046

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/caviar-without-the-myths/
  - et → https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta/
  - lv → https://kawiare.lv/kaviars-ka-dabisks-uztura-bagatinatajs-jeb-kaviars-bez-mitiem/
  - x-default → https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×5, h3 ×11, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Kaaviar kui looduslik toidulisand
  - h2: Kaaviar enne pidulauda
  - h2: Kaaviar kui kontsentreeritud toit
  - h3: Väike kogus, reaalne mõju
  - h3: Omega-3 rasvhapped ilma kapslita
  - h3: Miks kaaviar ei ole “liiga rasvane”
  - h3: Kaaviar ja aju
  - h2: Lugu, mida kaaviar ei vaja
  - h2: Soovid rohkem teada saada?
  - h3: Kuidas eristada kvaliteetset punast kalamarja
  - h3: Kuidas ära tunda tõeliselt head kaheksajalga
  - h3: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| 6/01/Kawiare_kaaviar-looduslik-toidulisand_header-scaled.jpg | Kaaviar kui looduslik toidulisand ehk ka | 2560×717 | eager | ✗ |
| wp-content/uploads/2026/01/Kawiare_punane-kalamari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| .ee/wp-content/uploads/2026/01/Kawiare_kaheksajalg_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| are.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0`
- Hero image eagerly loaded:
  - `hero: …ntent/uploads/2026/01/Kawiare_kaaviar-looduslik-toidulisand_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `…ntent/uploads/2026/01/Kawiare_kaaviar-looduslik-toidulisand_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 5 of 10 — https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga

Run: 2026-07-07T06:34:57.523Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 20909 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **60** | 81 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **8.9 s** | 1.9 s |
| CLS | 0.000 | **0.000** |
| TBT | 59 ms | **152 ms** |
| FCP | **4.56 s** | 641 ms |
| Speed Index | **6.63 s** | 3.00 s |
| TTFB | 3 ms | **4 ms** |

### Priority fixes
1. **largest-contentful-paint** (high) — 8.9 s
2. **first-contentful-paint** (high) — 4.6 s
3. **speed-index** (high) — 6.6 s
4. **document-latency-insight** (high) — Est savings of 240 ms
5. **image-delivery-insight** (high) — Est savings of 264 KiB

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0 — 109 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.01, weight 25) — Largest Contentful Paint — 8.9 s
- `first-contentful-paint` (performance, score 0.14, weight 10) — First Contentful Paint — 4.6 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `speed-index` (performance, score 0.37, weight 10) — Speed Index — 6.6 s
- `lcp-breakdown-insight` (performance, score 0.00, weight 0) — LCP breakdown
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.34, weight 0) — Time to Interactive — 8.9 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 446 ms._

**Transport:**
- Final URL: https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga does not redirect to HTTPS (target: http://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 06 Jul 2026 22:26:41 GMT
- expires: Tue, 07 Jul 2026 06:34:57 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 31993
- Decoded body: 130.9 KB
- Compression ratio: 0.239

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 31993
content-type: text/html; charset=UTF-8
date: Tue, 07 Jul 2026 06:34:57 GMT
expires: Tue, 07 Jul 2026 06:34:57 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 06 Jul 2026 22:26:41 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 812 ms._

**Scoring:** 2 errors · 5 warnings · 66 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2519 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 77 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2529 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 1.04 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 675.8 KB |
| script | 19 | 251.6 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 31.2 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 161.2 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 355 ms, 161.2 KB
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 340 ms, 22 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 337 ms, 215 B
- https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_ahven-ja-koha_thumb-600x338.jpg (image) — 276 ms, 49.0 KB
- https://kawiare.ee/wp-content/themes/kawiare/assets/Josefin_Sans/static/JosefinSans-Regular.ttf (font) — 276 ms, 29.5 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406097807&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=820935301.1783406099&frm=0&pscdl=denied&rcb=1&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938468~118395334~119027224~119576881~119576885~119576891~119576895&sid=1783406098&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkuidas-ara-tunda-toeliselt-head-kaheksajalga%2F&dt=Kuidas%20%C3%A4ra%20tunda%20t%C3%B5eliselt%20head%20kaheksajalga%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1127 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406097807&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=820935301.1783406099&frm=0&pscdl=denied&rcb=1&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938468~118395334~119027224~119576881~119576885~119576891~119576895&sid=1783406098&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkuidas-ara-tunda-toeliselt-head-kaheksajalga%2F&dt=Kuidas%20%C3%A4ra%20tunda%20t%C3%B5eliselt%20head%20kaheksajalga%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1127 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2529 ms._

**Document:**
- Lang: et
- Title: Kuidas ära tunda tõeliselt head kaheksajalga - Kawiare
- Canonical: https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 237416

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/how-to-identify-high-quality-octopus/
  - et → https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga/
  - lv → https://kawiare.lv/ka-atpazit-patiesi-labu-astonkaji-astonkaja-kvalitates-anatomija/
  - x-default → https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×8, h3 ×8, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Kuidas ära tunda tõeliselt head kaheksajalga
  - h2: Miks kõik kaheksajalad ei ole samad
  - h2: Kasvukeskkond määrab kvaliteedi
  - h2: Tekstuur: mis vahe on heal ja kehval kaheksajalal
  - h3: Töötlemine, millest poeriiulil ei räägita
  - h2: Mida tähendab naturaalselt küpsetatud kaheksajalg
  - h2: Miks valmis küpsetatud kaheksajalg võib olla parem kui toores
  - h2: Kuidas tunda ära õige kaheksajalg
  - h2: Soovid rohkem teada saada?
  - h3: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi
  - h3: 20 punkti, kuidas eristada kvaliteetset kaaviari
  - h3: Ahven ja koha – kaks Balti järvede kala, mille väärtus vajab uuesti mõtestamist
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| p-content/uploads/2026/01/Kawiare_kaheksajalg_header-1-1.png | Kuidas ära tunda tõeliselt head kaheksaj | 2000×560 | eager | ✗ |
| content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| t/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| e/wp-content/uploads/2026/01/Kawiare_ahven-ja-koha_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0`
- Hero image eagerly loaded:
  - `hero: https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_kaheksajalg_header-1-1.png`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_kaheksajalg_header-1-1.png`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 6 of 10 — https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari

Run: 2026-07-07T06:35:04.055Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 17037 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **69** | 95 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **8.8 s** | 1.4 s |
| CLS | 0.000 | **0.000** |
| TBT | 58 ms | **68 ms** |
| FCP | **2.63 s** | 621 ms |
| Speed Index | **4.22 s** | 847 ms |
| TTFB | 3 ms | **4 ms** |

### Priority fixes
1. **largest-contentful-paint** (high) — 8.8 s
2. **first-contentful-paint** (medium) — 2.6 s
3. **speed-index** (low) — 4.2 s
4. **document-latency-insight** (high) — Est savings of 250 ms
5. **image-delivery-insight** (high) — Est savings of 195 KiB

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0 — 145 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 60 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.01, weight 25) — Largest Contentful Paint — 8.8 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.62, weight 10) — First Contentful Paint — 2.6 s
- `speed-index` (performance, score 0.77, weight 10) — Speed Index — 4.2 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.35, weight 0) — Time to Interactive — 8.8 s
- `max-potential-fid` (performance, score 0.85, weight 0) — Max Potential First Input Delay — 150 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 482 ms._

**Transport:**
- Final URL: https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari does not redirect to HTTPS (target: http://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 06 Jul 2026 22:26:42 GMT
- expires: Tue, 07 Jul 2026 06:35:04 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 31618
- Decoded body: 129.8 KB
- Compression ratio: 0.238

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 31618
content-type: text/html; charset=UTF-8
date: Tue, 07 Jul 2026 06:35:04 GMT
expires: Tue, 07 Jul 2026 06:35:04 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 06 Jul 2026 22:26:42 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 965 ms._

**Scoring:** 2 errors · 6 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`
- (×1) [warning] Text run is not in Unicode Normalization Form C. Should instead be “
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta           ”. (Copy and paste that into your source document to replace the un-normalized text.) — first at line 494 `px] mt-8">
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma mu`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2113 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`
- `#cookiescript_reject`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 91 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2124 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 937.1 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 548.5 KB |
| script | 19 | 251.6 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 30.9 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 161.2 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 509 ms, 161.2 KB
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 494 ms, 215 B
- https://kawiare.ee/wp-content/themes/kawiare/assets/Josefin_Sans/static/JosefinSans-Regular.ttf (font) — 451 ms, 29.5 KB
- https://kawiare.ee/wp-content/themes/kawiare/assets/Josefin_Sans/static/JosefinSans-SemiBold.ttf (font) — 451 ms, 29.3 KB
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 356 ms, 22 B

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406104344&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=322819711.1783406106&frm=0&pscdl=denied&rcb=5&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938469~118395333~119027224~119576881~119576885~119576891~119576895&sid=1783406105&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkuidas-eristada-kvaliteetset-kaaviari%2F&dt=20%20punkti%2C%20kuidas%20eristada%20kvaliteetset%20kaaviari%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1916 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406104344&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=322819711.1783406106&frm=0&pscdl=denied&rcb=5&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938469~118395333~119027224~119576881~119576885~119576891~119576895&sid=1783406105&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkuidas-eristada-kvaliteetset-kaaviari%2F&dt=20%20punkti%2C%20kuidas%20eristada%20kvaliteetset%20kaaviari%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1916 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2123 ms._

**Document:**
- Lang: et
- Title: 20 punkti, kuidas eristada kvaliteetset kaaviari - Kawiare
- Canonical: https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 236383

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/20-points-on-how-to-identify-high-quality-caviar/
  - et → https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari/
  - lv → https://kawiare.lv/20-punkti-ka-atskirt-kvalitativu-kaviaru/
  - x-default → https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×2, h3 ×7, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: 20 punkti, kuidas eristada kvaliteetset kaaviari
  - h2: Soovid rohkem teada saada?
  - h3: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid
  - h3: Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta
  - h3: Kuidas eristada kvaliteetset punast kalamarja
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| s/2026/01/Kawiare_kuidas-eristada-kaaviari_header-scaled.jpg | 20 punkti, kuidas eristada kvaliteetset  | 2560×717 | eager | ✗ |
| are.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| oads/2026/01/Kawiare_kaaviar-looduslik-toidulisand_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| wp-content/uploads/2026/01/Kawiare_punane-kalamari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0`
- Hero image eagerly loaded:
  - `hero: …wp-content/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `…wp-content/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 7 of 10 — https://kawiare.ee/kammkarp

Run: 2026-07-07T06:35:33.584Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 16277 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **61** | 93 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **8.5 s** | 1.7 s |
| CLS | 0.000 | **0.000** |
| TBT | 42 ms | **70 ms** |
| FCP | **4.57 s** | 622 ms |
| Speed Index | **6.42 s** | 961 ms |
| TTFB | 4 ms | 4 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 8.5 s
2. **first-contentful-paint** (high) — 4.6 s
3. **speed-index** (high) — 6.4 s
4. **document-latency-insight** (high) — Est savings of 310 ms
5. **image-delivery-insight** (high) — Est savings of 195 KiB

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 92 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.02, weight 25) — Largest Contentful Paint — 8.5 s
- `first-contentful-paint` (performance, score 0.14, weight 10) — First Contentful Paint — 4.6 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `speed-index` (performance, score 0.40, weight 10) — Speed Index — 6.4 s
- `lcp-breakdown-insight` (performance, score 0.00, weight 0) — LCP breakdown
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.38, weight 0) — Time to Interactive — 8.5 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 469 ms._

**Transport:**
- Final URL: https://kawiare.ee/kammkarp/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/kammkarp does not redirect to HTTPS (target: http://kawiare.ee/kammkarp/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 06 Jul 2026 22:27:36 GMT
- expires: Tue, 07 Jul 2026 06:35:33 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 31802
- Decoded body: 129.6 KB
- Compression ratio: 0.24

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/kammkarp does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 31802
content-type: text/html; charset=UTF-8
date: Tue, 07 Jul 2026 06:35:33 GMT
expires: Tue, 07 Jul 2026 06:35:33 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 06 Jul 2026 22:27:36 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 900 ms._

**Scoring:** 2 errors · 6 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`
- (×1) [warning] Text run is not in Unicode Normalization Form C. Should instead be “
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta           ”. (Copy and paste that into your source document to replace the un-normalized text.) — first at line 484 `px] mt-8">
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma mu`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2886 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 90 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2896 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 975.0 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 586.2 KB |
| script | 19 | 251.6 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 31.1 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 161.2 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 528 ms, 215 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 336 ms, 22 B
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 332 ms, 161.2 KB
- https://kawiare.ee/kammkarp (document) — 220 ms, 0 B
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 (script) — 67 ms, 0 B

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406133874&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1626624834.1783406135&frm=0&pscdl=denied&rcb=3&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938465~115938469~119027224~119576881~119576885~119576891~119576895&sid=1783406134&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkammkarp%2F&dt=Kammkarp%20%E2%80%93%20lihtne%20fast%20food%2C%20mis%20ei%20vaja%20keerulisi%20tehnikaid%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1365 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406133874&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1626624834.1783406135&frm=0&pscdl=denied&rcb=3&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938465~115938469~119027224~119576881~119576885~119576891~119576895&sid=1783406134&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkammkarp%2F&dt=Kammkarp%20%E2%80%93%20lihtne%20fast%20food%2C%20mis%20ei%20vaja%20keerulisi%20tehnikaid%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1365 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2896 ms._

**Document:**
- Lang: et
- Title: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid - Kawiare
- Canonical: https://kawiare.ee/kammkarp/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 236115

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/scallop/
  - et → https://kawiare.ee/kammkarp/
  - lv → https://kawiare.lv/kemmisgliemene-vienkarss-fast-food-kam-nav-vajadzigas-sarezgitas-tehnikas/
  - x-default → https://kawiare.ee/kammkarp/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×8, h3 ×8, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Kammkarp
  - h2: Mis on kammkarp ja miks teda hinnatakse
  - h2: Päritolu ja hooajalisus
  - h2: Miks kammkarp on kiire ja lihtne toit
  - h3: Kammkarp koorel – miks see on praktiline
  - h2: Lihtsad serveerimisviisid
  - h2: Kammkarp ja tervislik toitumine
  - h2: Kammkarp igapäevases köögis
  - h2: Soovid rohkem teada saada?
  - h3: Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta
  - h3: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi
  - h3: Kuidas ära tunda tõeliselt head kaheksajalga
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| p-content/uploads/2026/01/Kawiare_kammkarp_header-scaled.jpg | Kammkarp – lihtne <em>fast food</em>, mi | 2560×717 | eager | ✗ |
| oads/2026/01/Kawiare_kaaviar-looduslik-toidulisand_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| .ee/wp-content/uploads/2026/01/Kawiare_kaheksajalg_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 0 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0`
- Hero image eagerly loaded:
  - `hero: https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: (not set)`
- Responsive images (srcset / <picture>):
  - `https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 8 of 10 — https://kawiare.ee/ahven-ja-koha

Run: 2026-07-07T06:35:34.174Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 32038 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **68** | 90 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **9.6 s** | 1.9 s |
| CLS | 0.000 | **0.000** |
| TBT | 49 ms | **102 ms** |
| FCP | **2.61 s** | 634 ms |
| Speed Index | **4.61 s** | 1.11 s |
| TTFB | 3 ms | **5 ms** |

### Priority fixes
1. **largest-contentful-paint** (high) — 9.6 s
2. **first-contentful-paint** (medium) — 2.6 s
3. **speed-index** (medium) — 4.6 s
4. **document-latency-insight** (high) — Est savings of 310 ms
5. **image-delivery-insight** (high) — Est savings of 335 KiB

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 99 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 50 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 9.6 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.63, weight 10) — First Contentful Paint — 2.6 s
- `speed-index` (performance, score 0.70, weight 10) — Speed Index — 4.6 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.29, weight 0) — Time to Interactive — 9.6 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 451 ms._

**Transport:**
- Final URL: https://kawiare.ee/ahven-ja-koha/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/ahven-ja-koha does not redirect to HTTPS (target: http://kawiare.ee/ahven-ja-koha/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 06 Jul 2026 22:27:38 GMT
- expires: Tue, 07 Jul 2026 06:35:34 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 31528
- Decoded body: 129.2 KB
- Compression ratio: 0.238

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/ahven-ja-koha does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 31528
content-type: text/html; charset=UTF-8
date: Tue, 07 Jul 2026 06:35:34 GMT
expires: Tue, 07 Jul 2026 06:35:34 GMT
keep-alive: timeout=5, max=99
last-modified: Mon, 06 Jul 2026 22:27:38 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 820 ms._

**Scoring:** 2 errors · 5 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2587 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 63 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2596 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 1.11 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 747.3 KB |
| script | 19 | 251.6 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 30.8 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 161.2 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 422 ms, 161.2 KB
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 335 ms, 215 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 333 ms, 22 B
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 (script) — 319 ms, 0 B
- https://kawiare.ee/ahven-ja-koha (document) — 250 ms, 0 B

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406134492&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=587807786.1783406135&frm=0&pscdl=denied&rcb=19&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938469~119027224~119576881~119576885~119576891~119576895&sid=1783406134&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fahven-ja-koha%2F&dt=Ahven%20ja%20koha%20%E2%80%93%20kaks%20Balti%20j%C3%A4rvede%20kala%2C%20mille%20v%C3%A4%C3%A4rtus%20vajab%20uuesti%20m%C3%B5testamist%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1224 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406134492&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=587807786.1783406135&frm=0&pscdl=denied&rcb=19&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938469~119027224~119576881~119576885~119576891~119576895&sid=1783406134&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fahven-ja-koha%2F&dt=Ahven%20ja%20koha%20%E2%80%93%20kaks%20Balti%20j%C3%A4rvede%20kala%2C%20mille%20v%C3%A4%C3%A4rtus%20vajab%20uuesti%20m%C3%B5testamist%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1224 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2596 ms._

**Document:**
- Lang: et
- Title: Ahven ja koha – kaks Balti järvede kala, mille väärtus vajab uuesti mõtestamist - Kawiare
- Canonical: https://kawiare.ee/ahven-ja-koha/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 235702

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/perch-and-pike-perch/
  - et → https://kawiare.ee/ahven-ja-koha/
  - lv → https://kawiare.lv/asaris-un-zandarts-divas-baltijas-ezeru-zivis/
  - x-default → https://kawiare.ee/ahven-ja-koha/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×6, h3 ×7, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Ahven ja koha
  - h2: Päritolu ja keskkond
  - h2: Ahven – delikaatne ja kiire
  - h2: Koha – kindel ja universaalne
  - h2: Miks need kalad on väärtuslikud täna
  - h2: Soovid rohkem teada saada?
  - h3: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi
  - h3: Kuidas eristada kvaliteetset punast kalamarja
  - h3: Kuidas ära tunda tõeliselt head kaheksajalga
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| tent/uploads/2026/01/Kawiare_ahven-ja-koha_header-scaled.jpg | Ahven ja koha – kaks Balti järvede kala, | 2560×717 | eager | ✗ |
| content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| wp-content/uploads/2026/01/Kawiare_punane-kalamari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| .ee/wp-content/uploads/2026/01/Kawiare_kaheksajalg_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0`
- Hero image eagerly loaded:
  - `hero: …kawiare.ee/wp-content/uploads/2026/01/Kawiare_ahven-ja-koha_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `…kawiare.ee/wp-content/uploads/2026/01/Kawiare_ahven-ja-koha_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 9 of 10 — https://kawiare.ee/lumekrabi

Run: 2026-07-07T06:35:50.215Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 20799 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **62** | 94 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **8.5 s** | 1.6 s |
| CLS | 0.000 | **0.000** |
| TBT | **146 ms** | 35 ms |
| FCP | **3.63 s** | 617 ms |
| Speed Index | **6.11 s** | 865 ms |
| TTFB | 4 ms | 4 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 8.5 s
2. **first-contentful-paint** (high) — 3.6 s
3. **speed-index** (high) — 6.1 s
4. **document-latency-insight** (high) — Est savings of 270 ms
5. **forced-reflow-insight** (high)

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 161 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 85 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.02, weight 25) — Largest Contentful Paint — 8.5 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.31, weight 10) — First Contentful Paint — 3.6 s
- `speed-index` (performance, score 0.45, weight 10) — Speed Index — 6.1 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.38, weight 0) — Time to Interactive — 8.5 s
- `max-potential-fid` (performance, score 0.80, weight 0) — Max Potential First Input Delay — 160 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 444 ms._

**Transport:**
- Final URL: https://kawiare.ee/lumekrabi/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/lumekrabi does not redirect to HTTPS (target: http://kawiare.ee/lumekrabi/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 06 Jul 2026 22:27:40 GMT
- expires: Tue, 07 Jul 2026 06:35:50 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 32464
- Decoded body: 130.9 KB
- Compression ratio: 0.242

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/lumekrabi does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 32464
content-type: text/html; charset=UTF-8
date: Tue, 07 Jul 2026 06:35:50 GMT
expires: Tue, 07 Jul 2026 06:35:50 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 06 Jul 2026 22:27:40 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 838 ms._

**Scoring:** 2 errors · 5 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2439 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 85 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2449 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 960.9 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 571.4 KB |
| script | 19 | 251.7 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 31.7 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 161.2 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 384 ms, 161.2 KB
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 340 ms, 22 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 337 ms, 215 B
- https://kawiare.ee/lumekrabi (document) — 218 ms, 0 B
- https://kawiare.ee/wp-content/themes/kawiare/assets/Josefin_Sans/static/JosefinSans-Regular.ttf (font) — 73 ms, 29.5 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406150498&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=2099942408.1783406151&frm=0&pscdl=denied&rcb=6&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616986~115938466~115938469~118897920~118897930~119027224~119576881~119576885~119576891~119576895&sid=1783406150&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Flumekrabi%2F&dt=Lumekrabi%20on%20tervislik%2C%20j%C3%A4tkusuutlik%20ja%20peene%20maitsega%20delikatess%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1156 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406150498&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=2099942408.1783406151&frm=0&pscdl=denied&rcb=6&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616986~115938466~115938469~118897920~118897930~119027224~119576881~119576885~119576891~119576895&sid=1783406150&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Flumekrabi%2F&dt=Lumekrabi%20on%20tervislik%2C%20j%C3%A4tkusuutlik%20ja%20peene%20maitsega%20delikatess%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1156 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2449 ms._

**Document:**
- Lang: et
- Title: Lumekrabi on tervislik, jätkusuutlik ja peene maitsega delikatess - Kawiare
- Canonical: https://kawiare.ee/lumekrabi/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 237386

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/snow-crab/
  - et → https://kawiare.ee/lumekrabi/
  - lv → https://kawiare.lv/sniega-krabis-veseliga-ilgtspejiga-un-izsmalcinatas-garsas-delikatese/
  - x-default → https://kawiare.ee/lumekrabi/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×7, h3 ×12, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Lumekrabi
  - h2: Mis on lumekrabi ja kust see pärineb?
  - h2: Kuidas eristada kvaliteetset lumekrabi?
  - h3: Külmutatud vs värske lumekrabi – mis vahe neil on?
  - h2: Kas lumekrabi on jätkusuutlik valik?
  - h3: Milliseid vastutustundlikke valikuid tarbijad saavad teha?
  - h2: Miks lumekrabi on ideaalne valik terviseteadlikule inimesele?
  - h3: Madala kalorsuse ja kõrge valgusisaldusega supertoit
  - h3: Omega-3 rasvhapped ja nende mõju ajule ja südamele
  - h3: Kuidas lumekrabi sobib fitness-toitumisega
  - h2: Lumekrabi igapäevases köögis
  - h2: Soovid rohkem teada saada?
  - h3: Ahven ja koha – kaks Balti järvede kala, mille väärtus vajab uuesti mõtestamist
  - h3: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi
  - h3: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| -content/uploads/2026/01/Kawiare_lumekrabi_header-scaled.jpg | Lumekrabi on tervislik, jätkusuutlik ja  | 2560×717 | eager | ✗ |
| e/wp-content/uploads/2026/01/Kawiare_ahven-ja-koha_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| are.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0`
- Hero image eagerly loaded:
  - `hero: …s://kawiare.ee/wp-content/uploads/2026/01/Kawiare_lumekrabi_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `…s://kawiare.ee/wp-content/uploads/2026/01/Kawiare_lumekrabi_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 10 of 10 — https://kawiare.ee/kaaviar-tanapaeval

Run: 2026-07-07T06:36:16.838Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 16327 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **61** | 95 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **8.2 s** | 1.5 s |
| CLS | 0.000 | **0.000** |
| TBT | **164 ms** | 29 ms |
| FCP | **3.64 s** | 648 ms |
| Speed Index | **6.44 s** | 958 ms |
| TTFB | 4 ms | 4 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 8.2 s
2. **first-contentful-paint** (high) — 3.6 s
3. **speed-index** (high) — 6.4 s
4. **document-latency-insight** (high) — Est savings of 250 ms
5. **forced-reflow-insight** (high)

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 65 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0 — 182 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 82 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.02, weight 25) — Largest Contentful Paint — 8.2 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.31, weight 10) — First Contentful Paint — 3.6 s
- `speed-index` (performance, score 0.40, weight 10) — Speed Index — 6.4 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.41, weight 0) — Time to Interactive — 8.2 s
- `max-potential-fid` (performance, score 0.73, weight 0) — Max Potential First Input Delay — 180 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 461 ms._

**Transport:**
- Final URL: https://kawiare.ee/kaaviar-tanapaeval/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/kaaviar-tanapaeval does not redirect to HTTPS (target: http://kawiare.ee/kaaviar-tanapaeval/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 06 Jul 2026 22:27:42 GMT
- expires: Tue, 07 Jul 2026 06:36:17 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 32180
- Decoded body: 130.8 KB
- Compression ratio: 0.24

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/kaaviar-tanapaeval does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 32180
content-type: text/html; charset=UTF-8
date: Tue, 07 Jul 2026 06:36:17 GMT
expires: Tue, 07 Jul 2026 06:36:17 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 06 Jul 2026 22:27:42 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 827 ms._

**Scoring:** 2 errors · 6 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`
- (×1) [warning] Text run is not in Unicode Normalization Form C. Should instead be “
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta           ”. (Copy and paste that into your source document to replace the un-normalized text.) — first at line 497 `px] mt-8">
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma mu`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2459 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 81 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2469 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 944.1 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 555.0 KB |
| script | 19 | 251.6 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 31.4 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 161.2 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 348 ms, 161.2 KB
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 339 ms, 22 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 336 ms, 215 B
- https://kawiare.ee/kaaviar-tanapaeval (document) — 218 ms, 0 B
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 (script) — 62 ms, 0 B

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406177120&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=2086795289.1783406178&frm=0&pscdl=denied&rcb=14&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938468~118395335~119027224~119576881~119576885~119576891~119576895~119724320&sid=1783406177&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkaaviar-tanapaeval%2F&dt=Kaaviar%20t%C3%A4nap%C3%A4eval%3A%20miks%20kasvukeskkond%20m%C3%A4%C3%A4rab%20kvaliteedi%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1172 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6711v9244324978za200zd9244324978&_p=1783406177120&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=2086795289.1783406178&frm=0&pscdl=denied&rcb=14&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938468~118395335~119027224~119576881~119576885~119576891~119576895~119724320&sid=1783406177&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkaaviar-tanapaeval%2F&dt=Kaaviar%20t%C3%A4nap%C3%A4eval%3A%20miks%20kasvukeskkond%20m%C3%A4%C3%A4rab%20kvaliteedi%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1172 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2469 ms._

**Document:**
- Lang: et
- Title: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi - Kawiare
- Canonical: https://kawiare.ee/kaaviar-tanapaeval/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 237380

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/caviar-today/
  - et → https://kawiare.ee/kaaviar-tanapaeval/
  - lv → https://kawiare.lv/kaviars-musdienas-kapec-audzesanas-vide-nosaka-kvalitati/
  - x-default → https://kawiare.ee/kaaviar-tanapaeval/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×7, h3 ×8, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Kaaviar tänapäeval
  - h2: Miks kasvukeskkond on kaaviari kvaliteedi alus
  - h3: Itaalia kasvukeskkond ja vee loogika
  - h2: Traditsiooniline tootmisviis ja käsitöö
  - h2: Vastutus ja repopulatsioon
  - h2: Kaaviari tüübid ja nende iseloom
  - h2: Kuidas eristada kvaliteetset kaaviari
  - h2: Soovid rohkem teada saada?
  - h3: Lumekrabi on tervislik, jätkusuutlik ja peene maitsega delikatess
  - h3: Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta
  - h3: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| uploads/2026/01/Kawiare_kaaviar-tanapaeval_header-scaled.jpg | Kaaviar tänapäeval: miks kasvukeskkond m | 2560×717 | eager | ✗ |
| re.ee/wp-content/uploads/2026/01/Kawiare_lumekrabi_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| oads/2026/01/Kawiare_kaaviar-looduslik-toidulisand_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| are.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 43 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0`
- Hero image eagerly loaded:
  - `hero: …re.ee/wp-content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `…re.ee/wp-content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).