Audit

20260713T130140Z-31b6

← Back to kawiareee
Audited URL
https://kawiare.ee/
Timestamp
2026-07-13T13:11:48.993Z
Kind
site
Pages
10
Audit summary
https://kawiare.ee/
10 of 10 pages audited
Pagespeed scores
Other checks
LLM Report

Weighted audit summary

56
Overall site quality
Poorhigh confidence

Site overall 56 is the mean of 10 pages. Scores range 45 (https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja) → 62 (https://kawiare.ee/kaaviar-tanapaeval). Weakest page: Mobile performance is critically low (63/100) with an LCP of 8.6 s, far exceeding the 2.5 s threshold and dragging the overall score. A critical security configuration error exists where HTTP traffic does not redirect to HTTPS, exposing users to downgrade attacks. Accessibility has a serious contrast violation and missing skip-link, though desktop performance is strong (95/100). Security headers are weak (40/100) with missing CSP and preload, but the HTTP redirect failure is the most urgent security fix. The site functions but requires significant optimization for mobile users and security hardening.

Per-page scores
55
Home
high
48
/artiklid
high
45
…eetset-punast-kalamarja
high
58
…-kaaviar-ilma-muutideta
high
55
…iselt-head-kaheksajalga
high
62
…a-kvaliteetset-kaaviari
high
62
/kammkarp
high
55
/ahven-ja-koha
high
62
/lumekrabi
high
62
/kaaviar-tanapaeval
high

Audit Report: Kawiare - Experience of Taste

Website: https://kawiare.ee/
Date: 2026-07-13

Overall Score: 56 / 100
Status: 🟠 Poor
Confidence: high
Audit Coverage: 100% — all sources returned data

Pages Audited (10 of 10):

Summary

Site overall 56 is the mean of 10 pages. Scores range 45 (https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja) → 62 (https://kawiare.ee/kaaviar-tanapaeval). Weakest page: Mobile performance is critically low (63/100) with an LCP of 8.6 s, far exceeding the 2.5 s threshold and dragging the overall score. A critical security configuration error exists where HTTP traffic does not redirect to HTTPS, exposing users to downgrade attacks. Accessibility has a serious contrast violation and missing skip-link, though desktop performance is strong (95/100). Security headers are weak (40/100) with missing CSP and preload, but the HTTP redirect failure is the most urgent security fix. The site functions but requires significant optimization for mobile users and security hardening.

Per-Page Scores

Page Score Status Confidence
https://kawiare.ee/ 55 🟠 Poor high
https://kawiare.ee/artiklid 48 🟠 Poor high
https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja 45 🟠 Poor high
https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta 58 🟠 Poor high
https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga 55 🟠 Poor high
https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari 62 🟡 Needs Improvement high
https://kawiare.ee/kammkarp 62 🟡 Needs Improvement high
https://kawiare.ee/ahven-ja-koha 55 🟠 Poor high
https://kawiare.ee/lumekrabi 62 🟡 Needs Improvement high
https://kawiare.ee/kaaviar-tanapaeval 62 🟡 Needs Improvement high

PageSpeed Insights — Mobile vs Desktop

Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.

URL Performance (M / D) LCP (M / D) CLS (M / D)
https://kawiare.ee/ 49 / 71 9.27 s / 1.67 s 1.000 / 0.637
https://kawiare.ee/artiklid 61 / 89 7.82 s / 1.79 s 0.001 / 0.001
https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja 63 / 95 8.65 s / 1.51 s 0.000 / 0.000
https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta 60 / 72 8.49 s / 1.77 s 0.000 / 0.000
https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga 60 / 91 8.95 s / 1.61 s 0.000 / 0.000
https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari 60 / 94 8.56 s / 1.60 s 0.000 / 0.000
https://kawiare.ee/kammkarp 60 / 98 8.48 s / 1.01 s 0.000 / 0.000
https://kawiare.ee/ahven-ja-koha 68 / 94 8.39 s / 1.58 s 0.000 / 0.000
https://kawiare.ee/lumekrabi 65 / 94 7.28 s / 1.53 s 0.000 / 0.000
https://kawiare.ee/kaaviar-tanapaeval 56 / 95 8.34 s / 1.48 s 0.000 / 0.000

Optimization Checklist

4 of 7 passing — 4 pass · 2 warn · 1 fail

Item Status Detail
Page caching plugin / CDN active Pass Caching plugin detected (WP Rocket)
Images lazy-loaded Pass All raster images use loading="lazy".
Hero image eagerly loaded Pass Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable).
Hero is a real <img> (not a CSS background-image) Warn Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.
Responsive images (srcset / <picture>) Warn Only 15/22 raster images use srcset or <picture> (68%).
Reasonable number of image sizes Pass 17 distinct srcset widths.
JS scripts not blocking in <head> Fail 5 render-blocking scripts in <head>. Move to footer or add defer/async.

Fixes

Priority 1: Critical

Immediate action — impacts user experience, search rankings, or site safety.

1A. Optimize images for WebP and lazy loading

  • Impact: LCP, Page Weight, CLS
  • Problem: Images total 1.45 MB with no WebP format; 6 images missing loading='lazy' contribute to LCP 9.3 s.
  • Solution: Convert all PNG/JPEG to WebP/AVIF. Add loading="lazy" to non-hero images. Ensure hero image has fetchpriority="high".
    <img src="image.webp" alt="..." loading="lazy" width="1200" height="800">
    

1B. Defer non-critical JavaScript

  • Impact: LCP, TBT, FCP
  • Problem: 11 render-blocking scripts identified; main.js (163 KB) and GTM (64 KB) cause long tasks and delay rendering.
  • Solution: Add defer or async to all non-critical scripts in <head>. Move WooCommerce/Contact Form scripts to footer if not needed for initial paint.
    <script src="main.js" defer></script>
    

1C. Enforce HTTPS redirect for all HTTP traffic

  • Impact: Security, Data Integrity
  • Problem: Audit shows http://kawiare.ee/artiklid does not redirect to HTTPS, leaving users vulnerable to interception on unencrypted connections.
  • Solution: Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to the HTTPS equivalent:
    RewriteEngine On
    RewriteCond %{HTTPS} off
    RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
    

1D. Defer or async non-critical JavaScript to fix LCP

  • Impact: LCP, FCP, TBT
  • Problem: 16 render-blocking scripts and 224 KB unused JS delay first paint; LCP is 7.8 s on mobile.
  • Solution: Add defer or async to all non-critical scripts in <head>. For WordPress, use a plugin like 'WP Rocket' or 'Autoptimize' to defer JS, or manually update theme files:
    <script src="main.js" defer></script>
    

1E. Force HTTPS Redirect

  • Impact: Security, Transport Layer
  • Problem: HTTP traffic (http://kawiare.ee/...) does not redirect to HTTPS, leaving users vulnerable to downgrade attacks and mixed content warnings.
  • Solution: Configure the web server (Apache/Nginx) to redirect all HTTP requests to HTTPS:
    RewriteEngine On
    RewriteCond %{HTTPS} off
    RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
    

1F. Optimize Largest Contentful Paint (LCP)

  • Impact: Mobile Performance, LCP (8.6 s)
  • Problem: Mobile LCP is 8.6 s (threshold 2.5 s), driven by render-blocking scripts and heavy resource loading.
  • Solution:
    • Defer non-critical JavaScript (11 render-blocking scripts found).
    • Preload the LCP image (hero) with <link rel="preload" as="image">.
    • Optimize server response time (TTFB is 4 ms, so focus on resource delivery).

1G. Force HTTP to HTTPS Redirect

  • Impact: Security, Data Integrity

  • Problem: Security Headers audit confirms http://kawiare.ee/... does not redirect to HTTPS, allowing unencrypted traffic.

  • Solution: Configure the web server (Apache/Nginx) to return a 301/302 redirect for all HTTP requests to the HTTPS equivalent.

    Apache Example:

    RewriteEngine On
    RewriteCond %{HTTPS} off
    RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
    

1H. Defer Render-Blocking JavaScript

  • Impact: LCP, FCP, Performance

  • Problem: 11 render-blocking scripts in <head> cause LCP to reach 8.5s and FCP 4.6s on mobile.

  • Solution: Add defer or async attributes to non-critical scripts in the <head>. Move critical CSS inline and defer the rest.

    Example:

    <script src="/js/main.js" defer></script>
    

1I. Enforce HTTPS Redirect

  • Impact: Security, Transport Layer

  • Problem: Security Headers audit reports 'HTTPS redirect: ✗ http://kawiare.ee... does not redirect to HTTPS'.

  • Solution: Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS.

    Apache (.htaccess):

    RewriteEngine On
    RewriteCond %{HTTPS} off
    RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
    

1J. Optimize Mobile Largest Contentful Paint (LCP)

  • Impact: Performance, Mobile UX
  • Problem: Mobile LCP is 9.0s (threshold is 2.5s), driven by render-blocking scripts and heavy assets.
  • Solution:
    • Defer non-critical JavaScript (11 render-blocking scripts found).
    • Preload the LCP image (hero) with fetchpriority="high".
    • Compress images to WebP/AVIF.
    • Remove unused JavaScript (224KB wasted in main.js).

1K. Enforce HTTP to HTTPS redirect

  • Impact: Security, Transport Layer
  • Problem: Security Headers audit shows http://kawiare.ee... does not redirect to HTTPS, leaving users vulnerable on unencrypted connections.
  • Solution: Configure the web server (Apache/Nginx) to return a 301 redirect for all HTTP requests to HTTPS:
    RewriteEngine On
    RewriteCond %{HTTPS} off
    RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
    

1L. Eliminate render-blocking JavaScript

  • Impact: LCP, FCP, Performance Score
  • Problem: PSI mobile LCP is 8.6 s; HTML Inventory shows 11 render-blocking scripts including main.js and jQuery.
  • Solution: Add defer or async to non-critical scripts in <head>. Critical CSS should be inlined, and JS moved to footer or deferred:
    <script src="main.js" defer></script>
    

Priority 2: Important

Essential for compliance, user reach, and search visibility.

2A. Strengthen security headers

  • Impact: Security Grade, XSS/Clickjacking Defense
  • Problem: Security Headers grade 40/100; missing CSP, COOP, CORP. HSTS lacks preload directive.
  • Solution: Add missing headers via server config (Apache example):
    Header set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com"
    Header set Cross-Origin-Opener-Policy "same-origin"
    Header set Cross-Origin-Resource-Policy "same-origin"
    

2B. Fix HTML structure and navigation

  • Impact: SEO, Accessibility
  • Problem: Page contains 3 <h1> elements; missing skip-to-content link; W3C error on <style> inside <div>.
  • Solution: Ensure exactly one <h1> per page. Add skip link before main content. Move inline styles to external CSS or <style> block in <head>.
    <a href="#main-content" class="skip-link">Skip to content</a>
    

2C. Complete Security Header Hardening

  • Impact: XSS, Clickjacking, Transport Security
  • Problem: Security Headers grade is 40/100; HSTS lacks preload directive, and CSP is missing entirely.
  • Solution: Add HSTS preload and a strict CSP. Since signals indicate no auth/payments, a restrictive default-src is safe:
    Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
    Header always set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com;"
    

2D. Fix Heading Hierarchy and Color Contrast

  • Impact: WCAG 1.3.1, 1.4.3, SEO
  • Problem: W3C and axe report h1→h3 skip and serious contrast failure on #cookiescript_accept.
  • Solution:
    • Insert an h2 between h1 and h3, or change h3 to h2.
    • Increase contrast on .lead-text or #cookiescript_accept to meet 4.5:1 ratio (e.g., darken text or lighten background).

2E. Defer Render-Blocking Scripts

  • Impact: FCP, TBT, Mobile Performance
  • Problem: 11 render-blocking scripts in <head> delay First Contentful Paint (3.62 s) and contribute to long tasks.
  • Solution: Add defer or async attributes to non-critical scripts in <head>:
    <script src="..." defer></script>
    
    Move critical CSS inline and defer the rest.

2F. Fix Accessibility Violations

  • Impact: WCAG Compliance, Usability
  • Problem: 1 serious color-contrast violation (#cookiescript_accept) and 3 moderate landmark violations (duplicate main, missing skip-link).
  • Solution:
    • Increase contrast ratio for .cookiescript_accept to ≥4.5:1.
    • Add <a href="#main" class="skip-link">Skip to content</a>.
    • Ensure only one <main> or role="main" element exists.

2G. Fix Color Contrast on Cookie Buttons

  • Impact: Accessibility (WCAG 1.4.3)

  • Problem: axe-core reports 1 serious violation: background and foreground colors on #cookiescript_accept/reject do not meet contrast thresholds.

  • Solution: Increase contrast ratio to at least 4.5:1 for normal text. Adjust button text color or background color in CSS.

    CSS Example:

    #cookiescript_accept { color: #333333; background: #ffffff; }
    

2H. Correct Invalid HTML Structure

  • Impact: SEO, Rendering Consistency

  • Problem: W3C Validator reports 2 errors: <style> not allowed as child of <div> and unescaped < character.

  • Solution: Move <style> blocks to the <head> or use <template> if dynamic. Escape special characters like < as &lt; in text content.

    Fix:

    <!-- Move style to head -->
    <head>
      <style>...</style>
    </head>
    

2I. Fix Color Contrast Violation

  • Impact: Accessibility (WCAG 1.4.3)
  • Problem: axe-core reports 1 serious violation on #cookiescript_accept element.
  • Solution: Increase text contrast ratio to at least 4.5:1 for the cookie consent button text. Adjust CSS color values or background opacity.

2J. Fix accessibility contrast and landmarks

  • Impact: WCAG 1.4.3, 2.4.1
  • Problem: axe-core reports 1 serious color-contrast violation (#cookiescript_accept) and missing skip-to-content link.
  • Solution:
    • Increase contrast on .lead-text and cookie button to ≥4.5:1.
    • Add a skip link at the top of the DOM:
    <a href="#main" class="skip-link">Otse sisule</a>
    

2K. Strengthen HSTS configuration

  • Impact: Security Headers Grade
  • Problem: HSTS is present but missing the preload directive, preventing inclusion in browser preload lists.
  • Solution: Update the Strict-Transport-Security header to include preload:
    Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
    

2L. Implement Content Security Policy (CSP)

  • Impact: XSS Defense, Security Headers
  • Problem: CSP is missing (Security Headers grade 40/100). While site signals show no auth/payments, CSP mitigates XSS risks from third-party scripts (e.g., GTM).
  • Solution: Deploy a strict CSP with nonce/hash for scripts:
    Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; style-src 'self' 'unsafe-inline';"
    

2M. Fix Color Contrast and Landmarks

  • Impact: Accessibility (WCAG 1.4.3, 1.3.1)
  • Problem: axe-core found 1 serious color-contrast violation (#cookiescript_accept) and 3 moderate landmark issues (duplicate main).
  • Solution:
    • Increase contrast on #cookiescript_accept to ≥4.5:1.
    • Ensure only one <main> element exists; remove duplicate role="main".
    • Add aria-label to landmarks if roles are duplicated.

Priority 3: Best Practice

Recommended for long-term maintainability.

3A. Fix color contrast on cookie banner

  • Impact: WCAG 1.4.3
  • Problem: axe-core reports serious contrast violation on #cookiescript_accept.
  • Solution: Increase text color contrast ratio to ≥4.5:1 against the background. Verify with a contrast checker tool.

3B. Replace CSS Background Hero with Real Image

  • Impact: LCP, Image Optimization
  • Problem: Hero uses CSS background-image, preventing srcset usage and browser optimization; LCP element is heavy.
  • Solution: Move the hero image into an <img> tag with fetchpriority="high" and srcset:
    <img src="hero-800.jpg" srcset="hero-400.jpg 400w, hero-800.jpg 800w" fetchpriority="high" alt="...">
    

3C. Add Content Security Policy (CSP)

  • Impact: XSS Defense-in-Depth
  • Problem: CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower than P1, but still recommended for defense.
  • Solution: Implement a strict CSP with nonce/hash for scripts:
    Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';"
    
    Ensure all inline scripts use the nonce.

3D. Implement Content Security Policy (CSP)

  • Impact: XSS Defense-in-Depth

  • Problem: CSP is missing. Site signals indicate no auth/payments, so this is a best practice rather than critical, but recommended for hardening.

  • Solution: Deploy a strict CSP with nonces for scripts. Since this is a brochure/blog page, a strict allowlist is feasible.

    Header:

    Content-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';
    

3E. Resolve W3C Validation Errors

  • Impact: SEO, Rendering Consistency
  • Problem: 2 errors found: <style> not allowed in div context and unescaped < character in text content.
  • Solution:
    • Move inline <style> blocks to the <head> or external CSS file.
    • Escape special characters in text content (e.g., use &lt; instead of <).

3F. Add Meta Description

  • Impact: SEO, Click-Through Rate
  • Problem: W3C and SEO audits confirm the document lacks a meta description.
  • Solution: Add a concise description (150–160 chars) in the <head>:
    <meta name="description" content="Ahven ja koha – kaks Balti järvede kala, mille väärtus vajab uuesti mõtestamist.">```
    

3G. Add Security Headers (CSP, HSTS Preload)

  • Impact: Defense-in-depth, Security Score

  • Problem: CSP is missing; HSTS lacks preload directive. Site signals indicate low auth/payment risk, so this is P3.

  • Solution: Add CSP with nonce/hash strategy. Add preload to HSTS.

    Apache:

    Header set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
    Header set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'"
    

3H. Improve SEO and Validation

  • Impact: Search Visibility, Code Quality
  • Problem: Missing meta description; W3C validator reports 2 errors (invalid <style> in <div>, unescaped <).
  • Solution:
    • Add <meta name="description" content="...">.
    • Fix W3C errors: Move <style> blocks to <head> or use <div> correctly; escape < as &lt;.

3I. Improve SEO and HTML Validity

  • Impact: Search Visibility, Code Quality
  • Problem: PSI SEO audit fails metaDescription; W3C reports 2 errors (invalid <style> in div, unescaped < character).
  • Solution:
    • Add <meta name="description" content="...">.
    • Fix W3C errors: move <style> to <head> or use <div> correctly; escape < as &lt; in text content.
▸Raw Markdown sent to the LLM
# Site Audit — https://kawiare.ee/
Run: 2026-07-13T13:01:40.696Z

Audited **10** of 10 discovered pages.
Average per-page audit coverage: **100%**

Pages audited:
- https://kawiare.ee/
- https://kawiare.ee/artiklid
- https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja
- https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta
- https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga
- https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari
- https://kawiare.ee/kammkarp
- https://kawiare.ee/ahven-ja-koha
- https://kawiare.ee/lumekrabi
- https://kawiare.ee/kaaviar-tanapaeval

---

# Page 1 of 10 — https://kawiare.ee/

Run: 2026-07-13T13:01:41.758Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 18575 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **49** | 71 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **9.3 s** | 1.7 s |
| CLS | **1.000** | 0.637 |
| TBT | **104 ms** | 27 ms |
| FCP | **1.68 s** | 433 ms |
| Speed Index | **2.93 s** | 895 ms |
| TTFB | 5 ms | 5 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 9.3 s
2. **cumulative-layout-shift** (high) — 1
3. **cls-culprits-insight** (high)
4. **image-delivery-insight** (high) — Est savings of 596 KiB
5. **legacy-javascript-insight** (medium) — Est savings of 5 KiB

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 163 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 64 KB wasted

#### Layout-shift sources
- body.home > div#page > main#primary > div.grid — shift 1.000
- main#primary > div.grid > section.larger-content > h2.text-center — shift 0.000

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 173 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 92 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.01, weight 25) — Largest Contentful Paint — 9.3 s
- `cumulative-layout-shift` (performance, score 0.02, weight 25) — Cumulative Layout Shift — 1
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `cls-culprits-insight` (performance, score 0.00, weight 0) — Layout shift culprits
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.30, weight 0) — Time to Interactive — 9.5 s
- `max-potential-fid` (performance, score 0.76, weight 0) — Max Potential First Input Delay — 170 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 200 ms._

**Transport:**
- Final URL: https://kawiare.ee/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 13 Jul 2026 02:28:21 GMT
- expires: Mon, 13 Jul 2026 13:01:41 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 32492
- Decoded body: 147.6 KB
- Compression ratio: 0.215

### Priority fixes
1. **strict-transport-security weak** (high) — missing preload directive
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
4. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
5. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
6. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
7. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 32492
content-type: text/html; charset=UTF-8
date: Mon, 13 Jul 2026 13:01:41 GMT
expires: Mon, 13 Jul 2026 13:01:41 GMT
keep-alive: timeout=5, max=95
last-modified: Mon, 13 Jul 2026 02:28:21 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 763 ms._

**Scoring:** 1 errors · 6 warnings · 70 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 174

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 174 `te">

    <style>
    /`
- (×1) [warning] Section lacks heading. Consider using “h2”-“h6” elements to add identifying headings to all sections, or else use a “div” element instead for any cases where no heading is needed. — first at line 394 `</script>
<section  class="relative">
<div`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 401 `<h2 class="text-center">MAITSE`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2722 ms._

**Scoring:** 1 violations · 54 passes · critical 0 · serious 1 · moderate 0 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 74 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2739 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 53 network requests · 1.83 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 21 | 1.45 MB |
| script | 19 | 251.3 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 1 | 31.7 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 160.8 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 410 ms, 215 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 301 ms, 22 B
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 145 ms, 160.8 KB
- https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6781v9244324978za200zd9244324978&_p=1783947701870&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1255030990.1783947703&frm=0&pscdl=denied&rcb=13&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938469~118826209~118897920~118897930~119027224&sid=1783947702&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2F&dt=Kawiare%20-%20Experience%20of%20Taste&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1001 (fetch) — 84 ms, 0 B
- https://kawiare.ee/wp-content/themes/kawiare/assets/Josefin_Sans/static/JosefinSans-Regular.ttf (font) — 73 ms, 29.5 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6781v9244324978za200zd9244324978&_p=1783947701870&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1255030990.1783947703&frm=0&pscdl=denied&rcb=13&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938469~118826209~118897920~118897930~119027224&sid=1783947702&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2F&dt=Kawiare%20-%20Experience%20of%20Taste&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1001 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6781v9244324978za200zd9244324978&_p=1783947701870&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1255030990.1783947703&frm=0&pscdl=denied&rcb=13&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938469~118826209~118897920~118897930~119027224&sid=1783947702&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2F&dt=Kawiare%20-%20Experience%20of%20Taste&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1001 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2739 ms._

**Document:**
- Lang: et
- Title: Kawiare - Experience of Taste
- Canonical: https://kawiare.ee/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 258731

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang:
  - en → https://kawiare.eu/
  - et → https://kawiare.ee/
  - lv → https://kawiare.lv/
  - x-default → https://kawiare.ee/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×3, h2 ×5, h3 ×15, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: MAITSE, MILLEL ON TÄHENDUS
  - h1: HEA MAITSE ALGAB PÄRITOLUST
  - h1: KUS MAITSE KOHTUB TEADMISEGA
  - h2: MAITSE SÜNNIBTEADLIKEST VALIKUTEST
  - h2: Tutvu valikuga
  - h3: Lumekrabi liha
  - h3: Siberian, 100g
  - h3: Forellimari, 100g
  - h3: Kohafilee
  - h2: TUTVU MEREANDIDE MAAILMAGA
  - h3: 20 punkti, kuidas eristada kvaliteetset kaaviari
  - h3: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi
  - h3: Kuidas ära tunda tõeliselt head kaheksajalga
  - h3: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid
  - h2: Kulinaarne inspiratsioon
  - h3: Krabiliha “Crab Roll”
  - h3: Külm roheline karri röstitud kammkarpidega
  - h3: Kammkarbi crudo kirevilja ponzuga
  - h2: Liitu meie kogukonnaga
  - h3: POOD

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 46 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 22 total — **0 without alt**, **0 without width/height**, 6 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| //kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-1.png | MAITSE, MILLEL ON TÄHENDUS | 2560×1900 | eager | ✗ |
| wp-content/uploads/2026/06/Kawiare-tooted-e1782658950478.png | MAITSE, MILLEL ON TÄHENDUS | 1900×2560 | eager | ✗ |
| tent/uploads/2026/02/Kawiare_paisepildid_mob_2_1900x2560.jpg | HEA MAITSE ALGAB PÄRITOLUST | 2560×1900 | lazy | ✗ |
| ee/wp-content/uploads/2026/02/pais2_uus_2595x1467-scaled.jpg | HEA MAITSE ALGAB PÄRITOLUST | 1900×2560 | lazy | ✗ |
| tent/uploads/2026/02/Kawiare_paisepildid_mob_3_1900x2560.jpg | KUS MAITSE KOHTUB TEADMISEGA | 2560×1900 | lazy | ✗ |
| are.ee/wp-content/uploads/2026/02/pais2_2595x1467-scaled.jpg | KUS MAITSE KOHTUB TEADMISEGA | 1900×2560 | lazy | ✗ |
| nt/uploads/2026/01/Kawiare_crab_legs_500g_2000px-300x300.png | _(empty)_ | 300×300 | _n/a_ | ✓ |
| 026/01/828829589-kawiare_crab_legs_hover1_2000px-300x300.jpg | Lumekrabi liha | 300×300 | lazy | ✓ |
| ads/2026/01/Kawiare_caviar_siberian_big_2000px_2-300x300.png | _(empty)_ | 300×300 | _n/a_ | ✓ |
| //kawiare.ee/wp-content/uploads/2026/01/Siberian-300x300.jpg | Siberian, 100g | 300×300 | lazy | ✓ |
| p-content/uploads/2026/01/Kawiare_trout_2000px_2-300x300.png | _(empty)_ | 300×300 | _n/a_ | ✓ |
| ds/2026/01/828829653-kawiare_trout_hover1_2000px-300x300.jpg | Forellimari, 100g | 300×300 | lazy | ✓ |
| t/uploads/2026/01/Kawiare_pike-uerch_500g_2000px-300x300.png | _(empty)_ | 300×300 | lazy | ✓ |
| s/2026/01/WhatsApp-Image-2026-07-10-at-06.09.48-300x300.jpeg | Kohafilee | 300×300 | lazy | ✓ |
| t/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |

**Links:** 59 anchors — 5 external, 1 preconnect, 2 preload.

Vague repeated link text:
- "artiklid" ×6
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "meie valik" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Document has 3 <h1> elements** (medium) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 15/22 raster images use srcset or <picture> (68%). |
| Reasonable number of image sizes | ✓ pass | 17 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0.1`
- Hero image eagerly loaded:
  - `hero: https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-1.png`
  - `loading: eager`
  - `fetchpriority: (not set)`
- Responsive images (srcset / <picture>):
  - `https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-1.png`
  - `https://kawiare.ee/wp-content/uploads/2026/06/Kawiare-tooted-e1782658950478.png`
  - `…kawiare.ee/wp-content/uploads/2026/02/Kawiare_paisepildid_mob_2_1900x2560.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/02/pais2_uus_2595x1467-scaled.jpg`
  - `…kawiare.ee/wp-content/uploads/2026/02/Kawiare_paisepildid_mob_3_1900x2560.jpg`
- Reasonable number of image sizes:
  - `widths: 100, 150, 200, 225, 300, 600, 683, 768, 800, 1024, 1080, 1152, 1365, 1536, 1707, 1920, 2000`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 15/22 raster images use srcset or <picture> (68%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 2 of 10 — https://kawiare.ee/artiklid

Run: 2026-07-13T13:01:41.761Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 22836 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **61** | 89 |
| Accessibility | 96 | 96 |
| Best Practices | 100 | 100 |
| SEO | 85 | 85 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **7.8 s** | 1.8 s |
| CLS | 0.001 | **0.001** |
| TBT | 94 ms | **141 ms** |
| FCP | **2.88 s** | 668 ms |
| Speed Index | **12.64 s** | 969 ms |
| TTFB | **4 ms** | 3 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 7.8 s
2. **speed-index** (high) — 12.6 s
3. **first-contentful-paint** (medium) — 2.9 s
4. **document-latency-insight** (high) — Est savings of 1,940 ms
5. **image-delivery-insight** (high) — Est savings of 158 KiB

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Layout-shift sources
- section.relative > div.pt-24 > div.mx-auto > h1.mb-4 — shift 0.001

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 191 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 92 ms
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1 — 52 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.03, weight 25) — Largest Contentful Paint — 7.8 s
- `speed-index` (performance, score 0.03, weight 10) — Speed Index — 12.6 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.53, weight 10) — First Contentful Paint — 2.9 s
- `heading-order` (accessibility, score 0.00, weight 3) — Heading elements are not in a sequentially-descending order
- `lcp-breakdown-insight` (performance, score 0.00, weight 0) — LCP breakdown
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `crawlable-anchors` (seo, score 0.00, weight 1) — Links are not crawlable
- `interactive` (performance, score 0.33, weight 0) — Time to Interactive — 9.1 s
- `max-potential-fid` (performance, score 0.70, weight 0) — Max Potential First Input Delay — 190 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 387 ms._

**Transport:**
- Final URL: https://kawiare.ee/artiklid/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/artiklid does not redirect to HTTPS (target: http://kawiare.ee/artiklid/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 13 Jul 2026 08:27:07 GMT
- expires: Mon, 13 Jul 2026 13:01:41 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 31629
- Decoded body: 141.7 KB
- Compression ratio: 0.218

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/artiklid does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 31629
content-type: text/html; charset=UTF-8
date: Mon, 13 Jul 2026 13:01:41 GMT
expires: Mon, 13 Jul 2026 13:01:41 GMT
keep-alive: timeout=5, max=94
last-modified: Mon, 13 Jul 2026 08:27:07 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 963 ms._

**Scoring:** 2 errors · 5 warnings · 63 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 170
2. **The heading “h3” (with computed level 3) follows the heading “h1” (with computed level 1), skipping 1 heading level.** (medium) — x1, first at line 476

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 170 `te">

    <style>
    /`
- (×1) [warning] Text run is not in Unicode Normalization Form C. Should instead be “
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta           ”. (Copy and paste that into your source document to replace the un-normalized text.) — first at line 717 `px] mt-8">
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma mu`
- (×1) [error] The heading “h3” (with computed level 3) follows the heading “h1” (with computed level 1), skipping 1 heading level. — first at line 476 `<h3 class="text-[24px] leading-[100%] text-white mb-[20px] mt-8">`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3040 ms._

**Scoring:** 2 violations · 54 passes · critical 0 · serious 1 · moderate 1 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **heading-order** (medium) — Heading levels should only increase by one

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `heading-order` (moderate)
[Heading levels should only increase by one](https://dequeuniversity.com/rules/axe/4.11/heading-order?application=playwright)
- `.product__item.group.justify-between:nth-child(1) > div:nth-child(1) > .lg\:px-6.px-4 > .text-\[24px\].mb-\[20px\].mt-8`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 65 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3051 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 52 network requests · 1.26 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 12 | 867.2 KB |
| script | 24 | 271.8 KB |
| font | 2 | 58.9 KB |
| stylesheet | 9 | 58.6 KB |
| document | 2 | 30.9 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 2 requests, 160.8 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 567 ms, 160.8 KB
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 (script) — 539 ms, 0 B
- https://kawiare.ee/wp-content/themes/kawiare/assets/Josefin_Sans/static/JosefinSans-SemiBold.ttf (font) — 485 ms, 29.3 KB
- https://kawiare.ee/wp-content/themes/kawiare/assets/Josefin_Sans/static/JosefinSans-Regular.ttf (font) — 485 ms, 29.5 KB
- https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_punane-kalamari_thumb-600x338.jpg (image) — 484 ms, 29.7 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6781v9244324978za200zd9244324978&_p=1783947702061&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1316252737.1783947703&frm=0&ngs=1&pscdl=denied&rcb=10&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938469~118395335~118826210~118897920~118897930~119027224~119724320&sid=1783947702&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fartiklid%2F&dt=Artiklid%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1314 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6781v9244324978za200zd9244324978&_p=1783947702061&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1316252737.1783947703&frm=0&ngs=1&pscdl=denied&rcb=10&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938469~118395335~118826210~118897920~118897930~119027224~119724320&sid=1783947702&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fartiklid%2F&dt=Artiklid%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1314 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3050 ms._

**Document:**
- Lang: et
- Title: Artiklid - Kawiare
- Canonical: https://kawiare.ee/artiklid/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 248647

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang:
  - en → https://kawiare.eu/insights/
  - et → https://kawiare.ee/artiklid/
  - lv → https://kawiare.lv/zurnals/
  - x-default → https://kawiare.ee/artiklid/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×12, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: MEREANDIDE MAAILM
  - h3: 20 punkti, kuidas eristada kvaliteetset kaaviari
  - h3: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi
  - h3: Kuidas ära tunda tõeliselt head kaheksajalga
  - h3: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid
  - h3: Ahven ja koha – kaks Balti järvede kala, mille väärtus vajab uuesti mõtestamist
  - h3: Kuidas eristada kvaliteetset punast kalamarja
  - h3: Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta
  - h3: Lumekrabi on tervislik, jätkusuutlik ja peene maitsega delikatess
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE
- Skips:
  - h1 → h3 after "MEREANDIDE MAAILM"

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 51 total — 6 defer, 2 async, 16 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/jquery/ui/core.min.js?ver=1.13.3

**Stylesheets:** 9 external, 17 inline (68.3 KB)

**Images:** 9 total — **0 without alt**, **0 without width/height**, 4 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| t/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_thumb.jpg | _(empty)_ | 800×450 | _n/a_ | ✓ |
| content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_thumb.jpg | _(empty)_ | 800×450 | _n/a_ | ✓ |
| .ee/wp-content/uploads/2026/01/Kawiare_kaheksajalg_thumb.jpg | _(empty)_ | 800×450 | _n/a_ | ✓ |
| are.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| e/wp-content/uploads/2026/01/Kawiare_ahven-ja-koha_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| wp-content/uploads/2026/01/Kawiare_punane-kalamari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| oads/2026/01/Kawiare_kaaviar-looduslik-toidulisand_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| re.ee/wp-content/uploads/2026/01/Kawiare_lumekrabi_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 54 anchors — 6 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Heading level skips** (medium) — h1→h3 after "MEREANDIDE MAAILM"
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **16 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 5 pass · 1 warn · 1 fail

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | ! warn | Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file. |
| Responsive images (srcset / <picture>) | ✓ pass | 8/9 raster images use srcset or <picture> (89%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0.1`
- Hero image eagerly loaded:
  - `hero: …iare.ee/wp-content/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_thumb.jpg`
  - `loading: (not set)`
  - `fetchpriority: high`
- Hero is a real <img> (not a CSS background-image):
  - `selector: div.pt-24.pb-16`
  - `url: …e.ee/wp-content/uploads/2026/01/823960696-teadmuskeskus_2592x726_b-scaled.jpg`
  - `box: 1280×464px`
- Responsive images (srcset / <picture>):
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Hero is a real <img> (not a CSS background-image)** (medium) — Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 3 of 10 — https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja

Run: 2026-07-13T13:02:14.464Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 13527 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **63** | 95 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **8.6 s** | 1.5 s |
| CLS | 0.000 | **0.000** |
| TBT | 53 ms | **54 ms** |
| FCP | **3.62 s** | 622 ms |
| Speed Index | **6.27 s** | 910 ms |
| TTFB | 4 ms | 4 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 8.6 s
2. **first-contentful-paint** (high) — 3.6 s
3. **speed-index** (high) — 6.3 s
4. **document-latency-insight** (high) — Est savings of 230 ms
5. **forced-reflow-insight** (high)

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 101 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 52 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.01, weight 25) — Largest Contentful Paint — 8.6 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.31, weight 10) — First Contentful Paint — 3.6 s
- `speed-index` (performance, score 0.42, weight 10) — Speed Index — 6.3 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.37, weight 0) — Time to Interactive — 8.6 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 410 ms._

**Transport:**
- Final URL: https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja does not redirect to HTTPS (target: http://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 13 Jul 2026 08:27:09 GMT
- expires: Mon, 13 Jul 2026 13:02:14 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 32042
- Decoded body: 130.7 KB
- Compression ratio: 0.239

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 32042
content-type: text/html; charset=UTF-8
date: Mon, 13 Jul 2026 13:02:14 GMT
expires: Mon, 13 Jul 2026 13:02:14 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 13 Jul 2026 08:27:09 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 809 ms._

**Scoring:** 2 errors · 5 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2699 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 84 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2709 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 1012.4 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 623.7 KB |
| script | 19 | 251.3 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 31.3 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 160.8 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 296 ms, 215 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 296 ms, 22 B
- https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja (document) — 190 ms, 0 B
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 132 ms, 160.8 KB
- https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_ahven-ja-koha_thumb-600x338.jpg (image) — 69 ms, 49.0 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6781v9244324978za200zd9244324978&_p=1783947734720&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=361583900.1783947736&frm=0&ngs=1&pscdl=denied&rcb=18&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938468~118826210~118897920~118897930~119027224~119527019&sid=1783947735&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkuidas-eristada-kvaliteetset-punast-kalamarja%2F&dt=Kuidas%20eristada%20kvaliteetset%20punast%20kalamarja%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1352 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6781v9244324978za200zd9244324978&_p=1783947734720&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=361583900.1783947736&frm=0&ngs=1&pscdl=denied&rcb=18&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938468~118826210~118897920~118897930~119027224~119527019&sid=1783947735&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkuidas-eristada-kvaliteetset-punast-kalamarja%2F&dt=Kuidas%20eristada%20kvaliteetset%20punast%20kalamarja%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1352 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2709 ms._

**Document:**
- Lang: et
- Title: Kuidas eristada kvaliteetset punast kalamarja - Kawiare
- Canonical: https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 237227

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/how-to-identify-quality-red-fish-roe/
  - et → https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja/
  - lv → https://kawiare.lv/ka-atskirt-kvalitativus-sarkanos-zivju-ikrus/
  - x-default → https://kawiare.ee/kuidas-eristada-kvaliteetset-punast-kalamarja/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×8, h3 ×7, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Kuidas eristada kvaliteetset punast kalamarja
  - h2: Välimus ja tera ühtlus
  - h2: Lõhn
  - h2: Maitse ja tekstuur
  - h2: Soolasus
  - h2: Koostis ja lisandid
  - h2: Päritolu ja jälgitavus
  - h2: Soovid rohkem teada saada?
  - h3: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid
  - h3: Ahven ja koha – kaks Balti järvede kala, mille väärtus vajab uuesti mõtestamist
  - h3: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| nt/uploads/2026/01/Kawiare_punane-kalamari_header-scaled.jpg | Kuidas eristada kvaliteetset punast kala | 2560×717 | eager | ✗ |
| are.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| e/wp-content/uploads/2026/01/Kawiare_ahven-ja-koha_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0.1`
- Hero image eagerly loaded:
  - `hero: …wiare.ee/wp-content/uploads/2026/01/Kawiare_punane-kalamari_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `…wiare.ee/wp-content/uploads/2026/01/Kawiare_punane-kalamari_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 4 of 10 — https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta

Run: 2026-07-13T13:02:20.602Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 23819 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **60** | 72 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **8.5 s** | 1.8 s |
| CLS | 0.000 | **0.000** |
| TBT | 135 ms | **417 ms** |
| FCP | **4.58 s** | 738 ms |
| Speed Index | **6.38 s** | 1.49 s |
| TTFB | 4 ms | **5 ms** |

### Priority fixes
1. **largest-contentful-paint** (high) — 8.5 s
2. **first-contentful-paint** (high) — 4.6 s
3. **speed-index** (high) — 6.4 s
4. **document-latency-insight** (high) — Est savings of 210 ms
5. **forced-reflow-insight** (high)

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 64 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 157 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 78 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.02, weight 25) — Largest Contentful Paint — 8.5 s
- `first-contentful-paint` (performance, score 0.14, weight 10) — First Contentful Paint — 4.6 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `speed-index` (performance, score 0.41, weight 10) — Speed Index — 6.4 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.38, weight 0) — Time to Interactive — 8.5 s
- `max-potential-fid` (performance, score 0.81, weight 0) — Max Potential First Input Delay — 160 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 398 ms._

**Transport:**
- Final URL: https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta does not redirect to HTTPS (target: http://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 13 Jul 2026 08:27:11 GMT
- expires: Mon, 13 Jul 2026 13:02:20 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 32622
- Decoded body: 132.5 KB
- Compression ratio: 0.24

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 32622
content-type: text/html; charset=UTF-8
date: Mon, 13 Jul 2026 13:02:20 GMT
expires: Mon, 13 Jul 2026 13:02:20 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 13 Jul 2026 08:27:11 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 832 ms._

**Scoring:** 2 errors · 10 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [warning] Text run is not in Unicode Normalization Form C. Should instead be “Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta - Kawiar”. (Copy and paste that into your source document to replace the un-normalized text.) — first at line 43 `>
	<title>Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta - Kawia`
- (×1) [warning] The value of attribute “content” on element “meta” from namespace “http://www.w3.org/1999/xhtml” is not in Unicode Normalization Form C. — first at line 47 `icle" />
	<meta property="og:title" content="Kaaviar kui looduslik toidulisand e`
- (×1) [warning] Text run is not in Unicode Normalization Form C. Should instead be “{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/kawiare.ee\/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta\/#article","isPartOf":{"@id":"https:\/\/kawiare.ee\/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta\/"},"author":{"name":"artur","@id":"https:\/\/kawiare.ee\/#\/schema\/person\/03967b4e81b1b99ca46d262a3463ac35"},"headline":"Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta","datePublished":"2026-01-14T12:37:14+00:00","dateModified":"2026-03-02T17:57:24+00:00","mainEntityOfPage":{"@id":"https:\/\/kawiare.ee\/kaaviar-kui-l”. (Copy and paste that into your source document to replace the un-normalized text.) — first at line 63 `ma-graph">{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":`
- (×1) [warning] The value of attribute “title” on element “link” from namespace “http://www.w3.org/1999/xhtml” is not in Unicode Normalization Form C. — first at line 69 `.com' />

<link rel="alternate" type="application/rss+xml" title="Kawiare &raquo`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`
- (×1) [warning] The value of attribute “alt” on element “img” from namespace “http://www.w3.org/1999/xhtml” is not in Unicode Normalization Form C. — first at line 418 `<img fetchpriority="high" width="2560" height="717" class="mb-8 w-full h-auto" s`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 1841 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`
- `#cookiescript_reject`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 79 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 1851 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 974.1 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 586.8 KB |
| script | 19 | 249.4 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 31.9 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 158.9 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 315 ms, 22 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 287 ms, 215 B
- https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta (document) — 187 ms, 0 B
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 143 ms, 158.9 KB
- https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_lumekrabi_thumb-600x338.jpg (image) — 85 ms, 13.9 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6790h2v9244324978za200zd9244324978&_p=1783947740856&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=682404623.1783947742&frm=0&pscdl=denied&rcb=19&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616986~115938465~115938469~118395333~118826209~118897920~118897930~119027224&sid=1783947741&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta%2F&dt=Kaaviar%20kui%20looduslik%20toidulisand%20ehk%20kaaviar%20ilma%20mu%CC%88u%CC%88tideta%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1681 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6790h2v9244324978za200zd9244324978&_p=1783947740856&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=682404623.1783947742&frm=0&pscdl=denied&rcb=19&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616986~115938465~115938469~118395333~118826209~118897920~118897930~119027224&sid=1783947741&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta%2F&dt=Kaaviar%20kui%20looduslik%20toidulisand%20ehk%20kaaviar%20ilma%20mu%CC%88u%CC%88tideta%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1681 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 1851 ms._

**Document:**
- Lang: et
- Title: Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta - Kawiare
- Canonical: https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 239068

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/caviar-without-the-myths/
  - et → https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta/
  - lv → https://kawiare.lv/kaviars-ka-dabisks-uztura-bagatinatajs-jeb-kaviars-bez-mitiem/
  - x-default → https://kawiare.ee/kaaviar-kui-looduslik-toidulisand-ehk-kaaviar-ilma-muutideta/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×5, h3 ×11, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Kaaviar kui looduslik toidulisand
  - h2: Kaaviar enne pidulauda
  - h2: Kaaviar kui kontsentreeritud toit
  - h3: Väike kogus, reaalne mõju
  - h3: Omega-3 rasvhapped ilma kapslita
  - h3: Miks kaaviar ei ole “liiga rasvane”
  - h3: Kaaviar ja aju
  - h2: Lugu, mida kaaviar ei vaja
  - h2: Soovid rohkem teada saada?
  - h3: Kuidas eristada kvaliteetset punast kalamarja
  - h3: Lumekrabi on tervislik, jätkusuutlik ja peene maitsega delikatess
  - h3: Ahven ja koha – kaks Balti järvede kala, mille väärtus vajab uuesti mõtestamist
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| 6/01/Kawiare_kaaviar-looduslik-toidulisand_header-scaled.jpg | Kaaviar kui looduslik toidulisand ehk ka | 2560×717 | eager | ✗ |
| wp-content/uploads/2026/01/Kawiare_punane-kalamari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| re.ee/wp-content/uploads/2026/01/Kawiare_lumekrabi_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| e/wp-content/uploads/2026/01/Kawiare_ahven-ja-koha_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0.1`
- Hero image eagerly loaded:
  - `hero: …ntent/uploads/2026/01/Kawiare_kaaviar-looduslik-toidulisand_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `…ntent/uploads/2026/01/Kawiare_kaaviar-looduslik-toidulisand_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 5 of 10 — https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga

Run: 2026-07-13T13:02:38.967Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 19919 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **60** | 91 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **9.0 s** | 1.6 s |
| CLS | 0.000 | **0.000** |
| TBT | 74 ms | **135 ms** |
| FCP | **4.58 s** | 648 ms |
| Speed Index | **6.73 s** | 1.13 s |
| TTFB | 4 ms | 4 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 9.0 s
2. **first-contentful-paint** (high) — 4.6 s
3. **speed-index** (high) — 6.7 s
4. **document-latency-insight** (high) — Est savings of 320 ms
5. **forced-reflow-insight** (high)

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0 — 114 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 60 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.01, weight 25) — Largest Contentful Paint — 9.0 s
- `first-contentful-paint` (performance, score 0.14, weight 10) — First Contentful Paint — 4.6 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `speed-index` (performance, score 0.36, weight 10) — Speed Index — 6.7 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `lcp-breakdown-insight` (performance, score 0.00, weight 0) — LCP breakdown
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.34, weight 0) — Time to Interactive — 9.0 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 405 ms._

**Transport:**
- Final URL: https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga does not redirect to HTTPS (target: http://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 13 Jul 2026 08:28:04 GMT
- expires: Mon, 13 Jul 2026 13:02:39 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 31960
- Decoded body: 130.9 KB
- Compression ratio: 0.238

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 31960
content-type: text/html; charset=UTF-8
date: Mon, 13 Jul 2026 13:02:39 GMT
expires: Mon, 13 Jul 2026 13:02:39 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 13 Jul 2026 08:28:04 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 770 ms._

**Scoring:** 2 errors · 5 warnings · 66 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2267 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 77 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2278 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 1.02 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 656.4 KB |
| script | 19 | 251.3 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 31.2 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 160.8 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 301 ms, 215 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 290 ms, 22 B
- https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga (document) — 189 ms, 0 B
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 137 ms, 160.8 KB
- https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_punane-kalamari_thumb-600x338.jpg (image) — 72 ms, 29.7 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6781v9244324978za200zd9244324978&_p=1783947759229&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=950225928.1783947760&frm=0&ngs=1&pscdl=denied&rcb=15&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616985~115938465~115938468~118826210~118897920~118897930~119027224&sid=1783947759&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkuidas-ara-tunda-toeliselt-head-kaheksajalga%2F&dt=Kuidas%20%C3%A4ra%20tunda%20t%C3%B5eliselt%20head%20kaheksajalga%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.plf=4.5.3&tfd=949 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6781v9244324978za200zd9244324978&_p=1783947759229&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=950225928.1783947760&frm=0&ngs=1&pscdl=denied&rcb=15&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616985~115938465~115938468~118826210~118897920~118897930~119027224&sid=1783947759&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkuidas-ara-tunda-toeliselt-head-kaheksajalga%2F&dt=Kuidas%20%C3%A4ra%20tunda%20t%C3%B5eliselt%20head%20kaheksajalga%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.plf=4.5.3&tfd=949 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2278 ms._

**Document:**
- Lang: et
- Title: Kuidas ära tunda tõeliselt head kaheksajalga - Kawiare
- Canonical: https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 237445

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/how-to-identify-high-quality-octopus/
  - et → https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga/
  - lv → https://kawiare.lv/ka-atpazit-patiesi-labu-astonkaji-astonkaja-kvalitates-anatomija/
  - x-default → https://kawiare.ee/kuidas-ara-tunda-toeliselt-head-kaheksajalga/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×8, h3 ×8, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Kuidas ära tunda tõeliselt head kaheksajalga
  - h2: Miks kõik kaheksajalad ei ole samad
  - h2: Kasvukeskkond määrab kvaliteedi
  - h2: Tekstuur: mis vahe on heal ja kehval kaheksajalal
  - h3: Töötlemine, millest poeriiulil ei räägita
  - h2: Mida tähendab naturaalselt küpsetatud kaheksajalg
  - h2: Miks valmis küpsetatud kaheksajalg võib olla parem kui toores
  - h2: Kuidas tunda ära õige kaheksajalg
  - h2: Soovid rohkem teada saada?
  - h3: Kuidas eristada kvaliteetset punast kalamarja
  - h3: 20 punkti, kuidas eristada kvaliteetset kaaviari
  - h3: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| p-content/uploads/2026/01/Kawiare_kaheksajalg_header-1-1.png | Kuidas ära tunda tõeliselt head kaheksaj | 2000×560 | eager | ✗ |
| wp-content/uploads/2026/01/Kawiare_punane-kalamari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| t/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0.1`
- Hero image eagerly loaded:
  - `hero: https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_kaheksajalg_header-1-1.png`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_kaheksajalg_header-1-1.png`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 6 of 10 — https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari

Run: 2026-07-13T13:02:56.538Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 20802 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **60** | 94 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **8.6 s** | 1.6 s |
| CLS | 0.000 | **0.000** |
| TBT | 52 ms | **64 ms** |
| FCP | **4.57 s** | 625 ms |
| Speed Index | **6.56 s** | 864 ms |
| TTFB | 3 ms | 3 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 8.6 s
2. **first-contentful-paint** (high) — 4.6 s
3. **speed-index** (high) — 6.6 s
4. **document-latency-insight** (high) — Est savings of 220 ms
5. **image-delivery-insight** (high) — Est savings of 195 KiB

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 114 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 70 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.01, weight 25) — Largest Contentful Paint — 8.6 s
- `first-contentful-paint` (performance, score 0.14, weight 10) — First Contentful Paint — 4.6 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `speed-index` (performance, score 0.38, weight 10) — Speed Index — 6.6 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.37, weight 0) — Time to Interactive — 8.6 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 381 ms._

**Transport:**
- Final URL: https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari does not redirect to HTTPS (target: http://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 13 Jul 2026 08:28:05 GMT
- expires: Mon, 13 Jul 2026 13:02:56 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 31618
- Decoded body: 129.8 KB
- Compression ratio: 0.238

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 31618
content-type: text/html; charset=UTF-8
date: Mon, 13 Jul 2026 13:02:56 GMT
expires: Mon, 13 Jul 2026 13:02:56 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 13 Jul 2026 08:28:05 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 969 ms._

**Scoring:** 2 errors · 6 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`
- (×1) [warning] Text run is not in Unicode Normalization Form C. Should instead be “
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta           ”. (Copy and paste that into your source document to replace the un-normalized text.) — first at line 523 `px] mt-8">
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma mu`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2542 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 91 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2552 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 936.8 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 548.5 KB |
| script | 19 | 251.3 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 30.9 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 160.8 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 478 ms, 160.8 KB
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 (script) — 404 ms, 0 B
- https://kawiare.ee/wp-content/themes/kawiare/assets/Josefin_Sans/static/JosefinSans-SemiBold.ttf (font) — 351 ms, 29.3 KB
- https://kawiare.ee/wp-content/themes/kawiare/assets/Josefin_Sans/static/JosefinSans-Regular.ttf (font) — 350 ms, 29.5 KB
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 298 ms, 22 B

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6781v9244324978za200zd9244324978&_p=1783947776788&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=440709523.1783947778&frm=0&pscdl=denied&rcb=12&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616985~115938466~115938468~118826209~118897920~118897930~119027224&sid=1783947777&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkuidas-eristada-kvaliteetset-kaaviari%2F&dt=20%20punkti%2C%20kuidas%20eristada%20kvaliteetset%20kaaviari%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.plf=4.5.3&tfd=1235 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6781v9244324978za200zd9244324978&_p=1783947776788&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=440709523.1783947778&frm=0&pscdl=denied&rcb=12&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616985~115938466~115938468~118826209~118897920~118897930~119027224&sid=1783947777&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkuidas-eristada-kvaliteetset-kaaviari%2F&dt=20%20punkti%2C%20kuidas%20eristada%20kvaliteetset%20kaaviari%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.plf=4.5.3&tfd=1235 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2552 ms._

**Document:**
- Lang: et
- Title: 20 punkti, kuidas eristada kvaliteetset kaaviari - Kawiare
- Canonical: https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 236385

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/20-points-on-how-to-identify-high-quality-caviar/
  - et → https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari/
  - lv → https://kawiare.lv/20-punkti-ka-atskirt-kvalitativu-kaviaru/
  - x-default → https://kawiare.ee/kuidas-eristada-kvaliteetset-kaaviari/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×2, h3 ×7, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: 20 punkti, kuidas eristada kvaliteetset kaaviari
  - h2: Soovid rohkem teada saada?
  - h3: Kuidas eristada kvaliteetset punast kalamarja
  - h3: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid
  - h3: Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| s/2026/01/Kawiare_kuidas-eristada-kaaviari_header-scaled.jpg | 20 punkti, kuidas eristada kvaliteetset  | 2560×717 | eager | ✗ |
| wp-content/uploads/2026/01/Kawiare_punane-kalamari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| are.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| oads/2026/01/Kawiare_kaaviar-looduslik-toidulisand_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0.1`
- Hero image eagerly loaded:
  - `hero: …wp-content/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `…wp-content/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 7 of 10 — https://kawiare.ee/kammkarp

Run: 2026-07-13T13:03:11.272Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 15678 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **60** | 98 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **8.5 s** | 1.0 s |
| CLS | 0.000 | **0.000** |
| TBT | **103 ms** | 87 ms |
| FCP | **4.58 s** | 628 ms |
| Speed Index | **6.56 s** | 994 ms |
| TTFB | 4 ms | 4 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 8.5 s
2. **first-contentful-paint** (high) — 4.6 s
3. **speed-index** (high) — 6.6 s
4. **document-latency-insight** (high) — Est savings of 240 ms
5. **forced-reflow-insight** (high)

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 133 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 70 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.02, weight 25) — Largest Contentful Paint — 8.5 s
- `first-contentful-paint` (performance, score 0.14, weight 10) — First Contentful Paint — 4.6 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `speed-index` (performance, score 0.38, weight 10) — Speed Index — 6.6 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.38, weight 0) — Time to Interactive — 8.5 s
- `max-potential-fid` (performance, score 0.89, weight 0) — Max Potential First Input Delay — 130 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 387 ms._

**Transport:**
- Final URL: https://kawiare.ee/kammkarp/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/kammkarp does not redirect to HTTPS (target: http://kawiare.ee/kammkarp/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 13 Jul 2026 08:28:07 GMT
- expires: Mon, 13 Jul 2026 13:03:11 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 31751
- Decoded body: 129.5 KB
- Compression ratio: 0.239

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/kammkarp does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 31751
content-type: text/html; charset=UTF-8
date: Mon, 13 Jul 2026 13:03:11 GMT
expires: Mon, 13 Jul 2026 13:03:11 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 13 Jul 2026 08:28:07 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 804 ms._

**Scoring:** 2 errors · 5 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2512 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 90 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2523 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 970.4 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 582.0 KB |
| script | 19 | 251.3 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 31.0 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 160.8 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 301 ms, 22 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 300 ms, 215 B
- https://kawiare.ee/kammkarp (document) — 179 ms, 0 B
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 129 ms, 160.8 KB
- https://kawiare.ee/wp-content/themes/kawiare/assets/Josefin_Sans/static/JosefinSans-SemiBold.ttf (font) — 70 ms, 29.3 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6781h1v9244324978za200zd9244324978&_p=1783947791516&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=229759549.1783947792&frm=0&ngs=1&pscdl=denied&rcb=1&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616985~115938465~115938468~118395335~118826210~118897920~118897930~119027224&sid=1783947791&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkammkarp%2F&dt=Kammkarp%20%E2%80%93%20lihtne%20fast%20food%2C%20mis%20ei%20vaja%20keerulisi%20tehnikaid%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.plf=4.5.3&tfd=1178 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6781h1v9244324978za200zd9244324978&_p=1783947791516&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=229759549.1783947792&frm=0&ngs=1&pscdl=denied&rcb=1&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616985~115938465~115938468~118395335~118826210~118897920~118897930~119027224&sid=1783947791&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkammkarp%2F&dt=Kammkarp%20%E2%80%93%20lihtne%20fast%20food%2C%20mis%20ei%20vaja%20keerulisi%20tehnikaid%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&gap.plf=4.5.3&tfd=1178 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2523 ms._

**Document:**
- Lang: et
- Title: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid - Kawiare
- Canonical: https://kawiare.ee/kammkarp/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 236035

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/scallop/
  - et → https://kawiare.ee/kammkarp/
  - lv → https://kawiare.lv/kemmisgliemene-vienkarss-fast-food-kam-nav-vajadzigas-sarezgitas-tehnikas/
  - x-default → https://kawiare.ee/kammkarp/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×8, h3 ×8, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Kammkarp
  - h2: Mis on kammkarp ja miks teda hinnatakse
  - h2: Päritolu ja hooajalisus
  - h2: Miks kammkarp on kiire ja lihtne toit
  - h3: Kammkarp koorel – miks see on praktiline
  - h2: Lihtsad serveerimisviisid
  - h2: Kammkarp ja tervislik toitumine
  - h2: Kammkarp igapäevases köögis
  - h2: Soovid rohkem teada saada?
  - h3: Kuidas ära tunda tõeliselt head kaheksajalga
  - h3: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi
  - h3: 20 punkti, kuidas eristada kvaliteetset kaaviari
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| p-content/uploads/2026/01/Kawiare_kammkarp_header-scaled.jpg | Kammkarp – lihtne <em>fast food</em>, mi | 2560×717 | eager | ✗ |
| .ee/wp-content/uploads/2026/01/Kawiare_kaheksajalg_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| t/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 0 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0.1`
- Hero image eagerly loaded:
  - `hero: https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: (not set)`
- Responsive images (srcset / <picture>):
  - `https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 8 of 10 — https://kawiare.ee/ahven-ja-koha

Run: 2026-07-13T13:03:30.086Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 16996 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **68** | 94 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **8.4 s** | 1.6 s |
| CLS | 0.000 | **0.000** |
| TBT | **180 ms** | 56 ms |
| FCP | **2.65 s** | 630 ms |
| Speed Index | **3.35 s** | 971 ms |
| TTFB | 3 ms | 3 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 8.4 s
2. **first-contentful-paint** (medium) — 2.6 s
3. **document-latency-insight** (high) — Est savings of 200 ms
4. **forced-reflow-insight** (high)
5. **image-delivery-insight** (high) — Est savings of 335 KiB

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 278 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 115 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 51 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.02, weight 25) — Largest Contentful Paint — 8.4 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.62, weight 10) — First Contentful Paint — 2.6 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.35, weight 0) — Time to Interactive — 8.8 s
- `max-potential-fid` (performance, score 0.41, weight 0) — Max Potential First Input Delay — 280 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 376 ms._

**Transport:**
- Final URL: https://kawiare.ee/ahven-ja-koha/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/ahven-ja-koha does not redirect to HTTPS (target: http://kawiare.ee/ahven-ja-koha/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 13 Jul 2026 08:28:09 GMT
- expires: Mon, 13 Jul 2026 13:03:30 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 31535
- Decoded body: 129.2 KB
- Compression ratio: 0.238

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/ahven-ja-koha does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 31535
content-type: text/html; charset=UTF-8
date: Mon, 13 Jul 2026 13:03:30 GMT
expires: Mon, 13 Jul 2026 13:03:30 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 13 Jul 2026 08:28:09 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 832 ms._

**Scoring:** 2 errors · 5 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 1858 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`
- `#cookiescript_reject`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 64 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 1870 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 1.07 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 709.5 KB |
| script | 19 | 251.3 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 30.8 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 160.8 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 485 ms, 22 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 300 ms, 215 B
- https://kawiare.ee/ahven-ja-koha (document) — 219 ms, 0 B
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 140 ms, 160.8 KB
- https://kawiare.ee/wp-content/themes/kawiare/assets/Josefin_Sans/static/JosefinSans-Regular.ttf (font) — 68 ms, 29.5 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6781v9244324978za200zd9244324978&_p=1783947810381&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=600364304.1783947812&frm=0&ngs=1&pscdl=denied&rcb=2&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616986~115938466~115938469~118826210~118897920~118897930~119027224&sid=1783947811&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fahven-ja-koha%2F&dt=Ahven%20ja%20koha%20%E2%80%93%20kaks%20Balti%20j%C3%A4rvede%20kala%2C%20mille%20v%C3%A4%C3%A4rtus%20vajab%20uuesti%20m%C3%B5testamist%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1550 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6781v9244324978za200zd9244324978&_p=1783947810381&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=600364304.1783947812&frm=0&ngs=1&pscdl=denied&rcb=2&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115616986~115938466~115938469~118826210~118897920~118897930~119027224&sid=1783947811&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fahven-ja-koha%2F&dt=Ahven%20ja%20koha%20%E2%80%93%20kaks%20Balti%20j%C3%A4rvede%20kala%2C%20mille%20v%C3%A4%C3%A4rtus%20vajab%20uuesti%20m%C3%B5testamist%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=1550 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 1870 ms._

**Document:**
- Lang: et
- Title: Ahven ja koha – kaks Balti järvede kala, mille väärtus vajab uuesti mõtestamist - Kawiare
- Canonical: https://kawiare.ee/ahven-ja-koha/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 235718

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/perch-and-pike-perch/
  - et → https://kawiare.ee/ahven-ja-koha/
  - lv → https://kawiare.lv/asaris-un-zandarts-divas-baltijas-ezeru-zivis/
  - x-default → https://kawiare.ee/ahven-ja-koha/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×6, h3 ×7, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Ahven ja koha
  - h2: Päritolu ja keskkond
  - h2: Ahven – delikaatne ja kiire
  - h2: Koha – kindel ja universaalne
  - h2: Miks need kalad on väärtuslikud täna
  - h2: Soovid rohkem teada saada?
  - h3: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid
  - h3: 20 punkti, kuidas eristada kvaliteetset kaaviari
  - h3: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| tent/uploads/2026/01/Kawiare_ahven-ja-koha_header-scaled.jpg | Ahven ja koha – kaks Balti järvede kala, | 2560×717 | eager | ✗ |
| are.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| t/uploads/2026/01/Kawiare_kuidas-eristada-kaaviari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0.1`
- Hero image eagerly loaded:
  - `hero: …kawiare.ee/wp-content/uploads/2026/01/Kawiare_ahven-ja-koha_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `…kawiare.ee/wp-content/uploads/2026/01/Kawiare_ahven-ja-koha_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 9 of 10 — https://kawiare.ee/lumekrabi

Run: 2026-07-13T13:03:38.486Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 19837 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **65** | 94 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **7.3 s** | 1.5 s |
| CLS | 0.000 | **0.000** |
| TBT | **190 ms** | 59 ms |
| FCP | **2.65 s** | 665 ms |
| Speed Index | **5.80 s** | 1.13 s |
| TTFB | 4 ms | 4 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 7.3 s
2. **speed-index** (high) — 5.8 s
3. **first-contentful-paint** (medium) — 2.6 s
4. **document-latency-insight** (high) — Est savings of 2,050 ms
5. **forced-reflow-insight** (high)

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 279 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 123 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 53 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.05, weight 25) — Largest Contentful Paint — 7.3 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `speed-index` (performance, score 0.49, weight 10) — Speed Index — 5.8 s
- `first-contentful-paint` (performance, score 0.62, weight 10) — First Contentful Paint — 2.6 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `max-potential-fid` (performance, score 0.41, weight 0) — Max Potential First Input Delay — 280 ms
- `interactive` (performance, score 0.44, weight 0) — Time to Interactive — 7.8 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 403 ms._

**Transport:**
- Final URL: https://kawiare.ee/lumekrabi/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/lumekrabi does not redirect to HTTPS (target: http://kawiare.ee/lumekrabi/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 13 Jul 2026 08:28:10 GMT
- expires: Mon, 13 Jul 2026 13:03:38 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 32461
- Decoded body: 130.9 KB
- Compression ratio: 0.242

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/lumekrabi does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 32461
content-type: text/html; charset=UTF-8
date: Mon, 13 Jul 2026 13:03:38 GMT
expires: Mon, 13 Jul 2026 13:03:38 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 13 Jul 2026 08:28:10 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 756 ms._

**Scoring:** 2 errors · 5 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2180 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 85 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2190 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 960.5 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 571.4 KB |
| script | 19 | 251.3 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 31.7 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 160.8 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 465 ms, 215 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 424 ms, 22 B
- https://kawiare.ee/lumekrabi (document) — 190 ms, 0 B
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 131 ms, 160.8 KB
- https://kawiare.ee/wp-content/themes/kawiare/assets/Josefin_Sans/static/JosefinSans-Regular.ttf (font) — 74 ms, 29.5 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6781h1v9244324978za200zd9244324978&_p=1783947818743&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=240119043.1783947819&frm=0&pscdl=denied&rcb=1&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938469~118826209~118897920~118897930~119027224&sid=1783947818&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Flumekrabi%2F&dt=Lumekrabi%20on%20tervislik%2C%20j%C3%A4tkusuutlik%20ja%20peene%20maitsega%20delikatess%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=878 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6781h1v9244324978za200zd9244324978&_p=1783947818743&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=240119043.1783947819&frm=0&pscdl=denied&rcb=1&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938469~118826209~118897920~118897930~119027224&sid=1783947818&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Flumekrabi%2F&dt=Lumekrabi%20on%20tervislik%2C%20j%C3%A4tkusuutlik%20ja%20peene%20maitsega%20delikatess%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=878 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2190 ms._

**Document:**
- Lang: et
- Title: Lumekrabi on tervislik, jätkusuutlik ja peene maitsega delikatess - Kawiare
- Canonical: https://kawiare.ee/lumekrabi/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 237399

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/snow-crab/
  - et → https://kawiare.ee/lumekrabi/
  - lv → https://kawiare.lv/sniega-krabis-veseliga-ilgtspejiga-un-izsmalcinatas-garsas-delikatese/
  - x-default → https://kawiare.ee/lumekrabi/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×7, h3 ×12, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Lumekrabi
  - h2: Mis on lumekrabi ja kust see pärineb?
  - h2: Kuidas eristada kvaliteetset lumekrabi?
  - h3: Külmutatud vs värske lumekrabi – mis vahe neil on?
  - h2: Kas lumekrabi on jätkusuutlik valik?
  - h3: Milliseid vastutustundlikke valikuid tarbijad saavad teha?
  - h2: Miks lumekrabi on ideaalne valik terviseteadlikule inimesele?
  - h3: Madala kalorsuse ja kõrge valgusisaldusega supertoit
  - h3: Omega-3 rasvhapped ja nende mõju ajule ja südamele
  - h3: Kuidas lumekrabi sobib fitness-toitumisega
  - h2: Lumekrabi igapäevases köögis
  - h2: Soovid rohkem teada saada?
  - h3: Kuidas ära tunda tõeliselt head kaheksajalga
  - h3: Kuidas eristada kvaliteetset punast kalamarja
  - h3: Kammkarp – lihtne fast food, mis ei vaja keerulisi tehnikaid
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| -content/uploads/2026/01/Kawiare_lumekrabi_header-scaled.jpg | Lumekrabi on tervislik, jätkusuutlik ja  | 2560×717 | eager | ✗ |
| .ee/wp-content/uploads/2026/01/Kawiare_kaheksajalg_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| wp-content/uploads/2026/01/Kawiare_punane-kalamari_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| are.ee/wp-content/uploads/2026/01/Kawiare_kammkarp_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 42 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0.1`
- Hero image eagerly loaded:
  - `hero: …s://kawiare.ee/wp-content/uploads/2026/01/Kawiare_lumekrabi_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `…s://kawiare.ee/wp-content/uploads/2026/01/Kawiare_lumekrabi_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 10 of 10 — https://kawiare.ee/kaaviar-tanapaeval

Run: 2026-07-13T13:04:01.610Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 17793 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **56** | 95 |
| Accessibility | 97 | 97 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **8.3 s** | 1.5 s |
| CLS | 0.000 | **0.000** |
| TBT | **238 ms** | 50 ms |
| FCP | **4.59 s** | 617 ms |
| Speed Index | **6.42 s** | 985 ms |
| TTFB | 4 ms | 4 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 8.3 s
2. **first-contentful-paint** (high) — 4.6 s
3. **speed-index** (high) — 6.4 s
4. **total-blocking-time** (low) — 240 ms
5. **document-latency-insight** (high) — Est savings of 220 ms

### Findings (mobile)

#### Unused JavaScript
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638 — 224 KB wasted
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 66 KB wasted

#### Long tasks
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0 — 228 ms
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL — 110 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.02, weight 25) — Largest Contentful Paint — 8.3 s
- `first-contentful-paint` (performance, score 0.14, weight 10) — First Contentful Paint — 4.6 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `speed-index` (performance, score 0.40, weight 10) — Speed Index — 6.4 s
- `total-blocking-time` (performance, score 0.85, weight 30) — Total Blocking Time — 240 ms
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `valid-source-maps` (best-practices, score 0.00, weight 0) — Missing source maps for large first-party JavaScript
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.39, weight 0) — Time to Interactive — 8.3 s
- `max-potential-fid` (performance, score 0.57, weight 0) — Max Potential First Input Delay — 230 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 1902 ms._

**Transport:**
- Final URL: https://kawiare.ee/kaaviar-tanapaeval/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://kawiare.ee/kaaviar-tanapaeval does not redirect to HTTPS (target: http://kawiare.ee/kaaviar-tanapaeval/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 13 Jul 2026 08:28:12 GMT
- expires: Mon, 13 Jul 2026 13:04:03 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 32164
- Decoded body: 130.9 KB
- Compression ratio: 0.24

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://kawiare.ee/kaaviar-tanapaeval does not redirect to HTTPS
2. **strict-transport-security weak** (high) — missing preload directive
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000; includeSubDomains` — missing preload directive
- **content-security-policy** (missing, high)
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (present, low) `strict-origin-when-cross-origin`
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 32164
content-type: text/html; charset=UTF-8
date: Mon, 13 Jul 2026 13:04:03 GMT
expires: Mon, 13 Jul 2026 13:04:03 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 13 Jul 2026 08:28:12 GMT
referrer-policy: strict-origin-when-cross-origin
server: Apache
strict-transport-security: max-age=31536000; includeSubDomains
upgrade: h2,h2c
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 2126 ms._

**Scoring:** 2 errors · 6 warnings · 64 cosmetic (suppressed)

### Priority fixes
1. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 180
2. **Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”.** (medium) — x1, first at line 401

### Issue groups
- (×1) [warning] The document is not mappable to XML 1.0 due to two consecutive hyphens in a comment. — first at line 8 `stylesheet"> --->

    <style>`
- (×1) [warning] The “charset” attribute on the “script” element is obsolete. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 41 `</script>
<script data-minify="1" type="text/javascript" charset="UTF-8" data-cs`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 180 `te">

    <style>
    /`
- (×1) [error] Bad character “ ” after “<”. Probable cause: Unescaped “<”. Try escaping it as “&lt;”. — first at line 401 `< Tagasi artikli`
- (×1) [warning] A document should not include more than one visible element with “role=main”. — first at line 404 `<div  id="primary" class="site-main  relative" role="main">`
- (×1) [warning] Text run is not in Unicode Normalization Form C. Should instead be “
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta           ”. (Copy and paste that into your source document to replace the un-normalized text.) — first at line 497 `px] mt-8">
                Kaaviar kui looduslik toidulisand ehk kaaviar ilma mu`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3868 ms._

**Scoring:** 4 violations · 53 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-main-is-top-level** (medium) — Main landmark should not be contained in another landmark
3. **landmark-no-duplicate-main** (medium) — Document should not have more than one main landmark
4. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#cookiescript_accept`

#### `landmark-main-is-top-level` (moderate)
[Main landmark should not be contained in another landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-main-is-top-level?application=playwright)
- `#primary`

#### `landmark-no-duplicate-main` (moderate)
[Document should not have more than one main landmark](https://dequeuniversity.com/rules/axe/4.11/landmark-no-duplicate-main?application=playwright)
- `#main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `#main`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 80 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3880 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 39 network requests · 980.2 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 591.4 KB |
| script | 19 | 251.3 KB |
| font | 2 | 58.9 KB |
| stylesheet | 7 | 47.0 KB |
| document | 2 | 31.4 KB |
| fetch | 3 | 237 B |

**Third-party origins (by bytes):**
- https://www.googletagmanager.com — 1 request, 160.8 KB
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://kawiare.ee/kaaviar-tanapaeval (document) — 1.68 s, 0 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/feedback/schema (fetch) — 307 ms, 215 B
- https://kawiare.ee/wp-json/contact-form-7/v1/contact-forms/208/refill (fetch) — 298 ms, 22 B
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (script) — 139 ms, 160.8 KB
- https://kawiare.ee/wp-content/uploads/2026/01/Kawiare_lumekrabi_thumb-600x338.jpg (image) — 74 ms, 13.9 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6781v9244324978za200zd9244324978&_p=1783947843365&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1602917710.1783947844&frm=0&pscdl=denied&rcb=8&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938468~118826209~118897920~118897930~119027224&sid=1783947843&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkaaviar-tanapaeval%2F&dt=Kaaviar%20t%C3%A4nap%C3%A4eval%3A%20miks%20kasvukeskkond%20m%C3%A4%C3%A4rab%20kvaliteedi%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=2540 — net::ERR_ABORTED

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-KXTV1DHQZ6&gtm=45Pe6781v9244324978za200zd9244324978&_p=1783947843365&gcs=G100&gcd=13p3p3p2p5l1&npa=1&dma_cps=-&dma=1&gdid=dMmY1Mm.dZTNiMT&are=1&cid=1602917710.1783947844&frm=0&pscdl=denied&rcb=8&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&_s=1&tag_exp=115938466~115938468~118826209~118897920~118897930~119027224&sid=1783947843&sct=1&seg=0&dl=https%3A%2F%2Fkawiare.ee%2Fkaaviar-tanapaeval%2F&dt=Kaaviar%20t%C3%A4nap%C3%A4eval%3A%20miks%20kasvukeskkond%20m%C3%A4%C3%A4rab%20kvaliteedi%20-%20Kawiare&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&_ee=1&tfd=2540 — net::ERR_ABORTED

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3880 ms._

**Document:**
- Lang: et
- Title: Kaaviar tänapäeval: miks kasvukeskkond määrab kvaliteedi - Kawiare
- Canonical: https://kawiare.ee/kaaviar-tanapaeval/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 237401

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: not set
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang:
  - en → https://kawiare.eu/caviar-today/
  - et → https://kawiare.ee/kaaviar-tanapaeval/
  - lv → https://kawiare.lv/kaviars-musdienas-kapec-audzesanas-vide-nosaka-kvalitati/
  - x-default → https://kawiare.ee/kaaviar-tanapaeval/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×7, h3 ×8, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Kaaviar tänapäeval
  - h2: Miks kasvukeskkond on kaaviari kvaliteedi alus
  - h3: Itaalia kasvukeskkond ja vee loogika
  - h2: Traditsiooniline tootmisviis ja käsitöö
  - h2: Vastutus ja repopulatsioon
  - h2: Kaaviari tüübid ja nende iseloom
  - h2: Kuidas eristada kvaliteetset kaaviari
  - h2: Soovid rohkem teada saada?
  - h3: Lumekrabi on tervislik, jätkusuutlik ja peene maitsega delikatess
  - h3: Kaaviar kui looduslik toidulisand ehk kaaviar ilma müütideta
  - h3: Ahven ja koha – kaks Balti järvede kala, mille väärtus vajab uuesti mõtestamist
  - h2: Liitu meie kogukonnaga
  - h3: POOD
  - h3: LOE
  - h3: TUGI
  - h3: KAWIARE

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 6 defer, 2 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://kawiare.ee/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=10.7.0 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0
- https://www.googletagmanager.com/gtag/js?id=GT-TBZJWDHL (async)
- https://kawiare.ee/wp-content/cache/min/1/wp-content/plugins/sitepress-multilingual-cms/res/js/xdomain-data.js?ver=1783022638 (defer)
- https://kawiare.ee/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=10.7.0
- https://kawiare.ee/wp-content/cache/min/1/wp-content/themes/kawiare/assets/dist/js/main.js?ver=1783022638
- https://kawiare.ee/wp-content/plugins/woocommerce-multilingual/res/js/cart_widget.min.js?ver=5.5.5 (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-contact-form-7-08e8756782316cb65854.js (defer)
- https://kawiare.ee/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-a5f72561d6cdf416147d.js (defer)
- https://kawiare.ee/wp-includes/js/dist/hooks.min.js?ver=7496969728ca0f95732d

**Stylesheets:** 7 external, 18 inline (68.4 KB)

**Images:** 5 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| uploads/2026/01/Kawiare_kaaviar-tanapaeval_header-scaled.jpg | Kaaviar tänapäeval: miks kasvukeskkond m | 2560×717 | eager | ✗ |
| re.ee/wp-content/uploads/2026/01/Kawiare_lumekrabi_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| oads/2026/01/Kawiare_kaaviar-looduslik-toidulisand_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| e/wp-content/uploads/2026/01/Kawiare_ahven-ja-koha_thumb.jpg | _(empty)_ | 800×450 | lazy | ✓ |
| s://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png | Kawiare | 1428×244 | _n/a_ | ✗ |

**Links:** 43 anchors — 5 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "artiklid" ×3
- "retseptid" ×3
- "meie lugu" ×3
- "võta ühendust" ×3
- "avaleht" ×2
- "tooted" ×2
- "privaatsuspoliitika" ×2

**Forms:**
Form 1:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- email — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **11 render-blocking external scripts** (medium) — Only 6 defer, 2 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 3/5 raster images use srcset or <picture> (60%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 5 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WordPress 7.0.1`
- Hero image eagerly loaded:
  - `hero: …re.ee/wp-content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_header-scaled.jpg`
  - `loading: eager`
  - `fetchpriority: high`
- Responsive images (srcset / <picture>):
  - `…re.ee/wp-content/uploads/2026/01/Kawiare_kaaviar-tanapaeval_header-scaled.jpg`
  - `https://kawiare.ee/wp-content/uploads/2026/01/kawiare-footer.png`
- Reasonable number of image sizes:
  - `widths: 300, 600, 768, 800`
- JS scripts not blocking in <head>:
  - `…e/wp-content/cache/min/1/s/5a3a40d9610db7fdf5d70791b1214ed3.js?ver=1783022638`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://kawiare.ee/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1`
  - `…oocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.10.7.0`
  - `…/plugins/woocommerce/assets/js/js-cookie/js.cookie.min.js?ver=2.1.4-wc.10.7.0`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 5 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Responsive images (srcset / <picture>)** (medium) — Only 3/5 raster images use srcset or <picture> (60%).

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).