Audit

20260814T125320Z-59bb

← Back to lootsaee
Audited URL
https://lootsa.ee/
Timestamp
2026-08-14T12:55:01.113Z
Kind
single
Pages
1
Audit summary
https://lootsa.ee/
Pagespeed scores
Other checks
LLM Report

Weighted audit summary

55
Overall site quality
Poorhigh confidence

PSI mobile performance is 72, but LCP 5.1 s and FCP 4.05 s indicate critical rendering delays that heavily penalize user experience. Security Headers score is 0/100; with User-Generated Content present, missing CSP and HSTS create significant vulnerability. Accessibility has 3 serious axe violations (aria-hidden-focus, link-name, contrast) despite a 93 category score. Image payload is 1.77 MB with the hero image incorrectly lazy-loaded, driving the performance debt. Confidence is high as all audit tools returned complete data.

Audit Report: lootsa

Website: https://lootsa.ee/
Date: 14.08.2026
Audit Coverage: 100% — all sources returned data
Confidence: high

Pages Audited (1 of 1):

Summary of results

Overall Score: 55 / 100
Status: 🟠 Poor

PSI mobile performance is 72, but LCP 5.1 s and FCP 4.05 s indicate critical rendering delays that heavily penalize user experience. Security Headers score is 0/100; with User-Generated Content present, missing CSP and HSTS create significant vulnerability. Accessibility has 3 serious axe violations (aria-hidden-focus, link-name, contrast) despite a 93 category score. Image payload is 1.77 MB with the hero image incorrectly lazy-loaded, driving the performance debt. Confidence is high as all audit tools returned complete data.

Per-page scores

🟠 Poor · https://lootsa.ee/

Score Performance Accessibility Best Practices SEO Security
55 72 93 100 92 0

PageSpeed Insights — Mobile vs Desktop

Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.

Strategy Performance (M / D) LCP (M / D) CLS (M / D)
Mobile vs Desktop 72 / 98 5.06 s / 1.03 s 0.011 / 0.000

Optimization Checklist

3 of 6 passing — 3 pass · 1 warn · 2 fail · 1 n/a

Item Status Detail
Page caching plugin / CDN active Pass Caching plugin detected (WP Rocket)
Images lazy-loaded Fail 66 of 73 non-hero raster images are not lazy-loaded (threshold: 14) (3 SVGs excluded).
Hero image eagerly loaded Fail Hero image has loading="lazy", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading="eager" (or omit loading) and add fetchpriority="high".
Hero is a real <img> (not a CSS background-image) N/A No CSS background-images detected on raster-image-eligible elements.
Responsive images (srcset / <picture>) Pass 67/74 raster images use srcset or <picture> (91%) (3 SVGs excluded).
Reasonable number of image sizes Pass 25 distinct srcset widths.
JS scripts not blocking in <head> Warn 1 render-blocking script in <head>. Move to footer or add defer/async.

Fixes

Priority 1: Critical

Immediate action — impacts user experience, search rankings, or site safety.

1A. Fix Hero Image Loading Strategy Performance

  • Impact: LCP, FCP, Speed Index
  • Problem: LCP is 5.1 s; the hero image (lootsa_hero-320x180.jpg) has loading="lazy" which delays rendering.
  • Solution: Remove loading="lazy" from the hero image and add fetchpriority="high":
    <img src="/wp-content/uploads/.../lootsa_hero.jpg" fetchpriority="high" alt="...">
    

1B. Implement HSTS and CSP Security

  • Impact: Transport security, XSS protection
  • Problem: Security Headers grade 0/100; HSTS and CSP are missing. Site has User-Generated Content (textarea/upload), elevating CSP to Priority 1.
  • Solution: Add HSTS and a strict CSP via server config (Apache example):
    Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
    Header always set Content-Security-Policy "default-src 'self'; script-src 'self' 'nonce-{random}' 'strict-dynamic'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; form-action 'self';"
    

1C. Fix Serious Axe Violations Accessibility

  • Impact: WCAG 2.1 AA compliance, Screen Reader usability
  • Problem: 3 serious violations: aria-hidden-focus (FAQ slides), link-name (gallery images), color-contrast (.tag--brand).
  • Solution:
    • Remove aria-hidden="true" from elements containing focusable children or ensure focus is managed.
    • Add aria-label or visible text to gallery image links.
    • Increase contrast ratio for .tag--brand to ≥4.5:1.

Priority 2: Important

Essential for compliance, user reach, and search visibility.

2A. Lazy Load Below-Fold Images Performance

  • Impact: Page Weight, Initial Load Time
  • Problem: 69 of 77 images lack loading="lazy"; total image weight is 1.77 MB.
  • Solution: Add loading="lazy" to all images below the fold. Ensure hero image remains eager.
    <img src="..." loading="lazy" alt="...">
    

2B. Add Meta Description and Correct Language SEO

  • Impact: Search snippet, Accessibility
  • Problem: Missing meta description; HTML lang is "en" but content is Estonian.
  • Solution:
    • Add <meta name="description" content="...">.
    • Change <html lang="en"> to <html lang="et">.

2C. Add X-Content-Type-Options and X-Frame-Options Security

  • Impact: MIME sniffing, Clickjacking
  • Problem: Missing X-Content-Type-Options and X-Frame-Options headers.
  • Solution: Add headers via server config:
    Header always set X-Content-Type-Options "nosniff"
    Header always set X-Frame-Options "SAMEORIGIN"
    

Priority 3: Best Practice

Recommended for long-term maintainability.

No items.

▸Raw Markdown sent to the LLM
# Audit — https://lootsa.ee/

Run: 2026-08-14T12:53:20.526Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — <textarea> in a form; anchor href contains "upload"
- E-commerce: no

## PageSpeed Insights
_Captured in 23017 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **72** | 98 |
| Accessibility | 93 | **89** |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **5.1 s** | 1.0 s |
| CLS | **0.011** | 0.000 |
| TBT | 0 ms | **42 ms** |
| FCP | **4.05 s** | 521 ms |
| Speed Index | **4.05 s** | 814 ms |
| TTFB | 4 ms | 4 ms |

### Priority fixes
1. **largest-contentful-paint** (high) — 5.1 s
2. **first-contentful-paint** (high) — 4.1 s
3. **speed-index** (low) — 4.1 s
4. **cache-insight** (high) — Est savings of 2,235 KiB
5. **image-delivery-insight** (medium) — Est savings of 91 KiB

### Findings (mobile)

#### Unused JavaScript
- https://lootsa.ee/wp-content/themes/lootsa-arikvartal/inc/theme/js/global.1c4ff9002c5bb70b.js — 107 KB wasted

#### Layout-shift sources
- main#main > div#lootsa-arikvartal > div.h-container > div.hero-front__map — shift 0.011

#### Long tasks
- https://cdn-cookieyes.com/client_data/6d4d733d03db47c5aecbf6c09eac2e0b/script.js — 79 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.26, weight 25) — Largest Contentful Paint — 5.1 s
- `first-contentful-paint` (performance, score 0.22, weight 10) — First Contentful Paint — 4.1 s
- `aria-hidden-focus` (accessibility, score 0.00, weight 7) — `[aria-hidden="true"]` elements contain focusable descendents
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `speed-index` (performance, score 0.80, weight 10) — Speed Index — 4.1 s
- `lcp-discovery-insight` (performance, score 0.00, weight 0) — LCP request discovery
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.76, weight 0) — Time to Interactive — 5.1 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 398 ms._

**Transport:**
- Final URL: https://lootsa.ee/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: not set
- etag: n/a
- last-modified: n/a
- expires: n/a
- pragma: n/a
- vary: Accept-Encoding
- Issues:
  - no cache-control header — caching behavior is unpredictable

**Compression:**
- content-encoding: gzip
- content-length: 36014
- Decoded body: 227.9 KB
- Compression ratio: 0.154

### Priority fixes
1. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **weak caching policy** (medium) — no cache-control header — caching behavior is unpredictable
6. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
7. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
8. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
9. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
10. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests

### Findings

#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 36014
content-type: text/html; charset=UTF-8
date: Fri, 14 Aug 2026 12:53:20 GMT
keep-alive: timeout=5, max=100
link: <https://lootsa.ee/wp-json/>; rel="https://api.w.org/", <https://lootsa.ee/wp-json/wp/v2/pages/27>; rel="alternate"; title="JSON"; type="application/json", <https://lootsa.ee/>; rel=shortlink
server: Apache / ZoneOS
vary: Accept-Encoding
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1062 ms._

**Scoring:** 4 errors · 4 warnings · 19 cosmetic (suppressed)

### Priority fixes
1. **An “input” element with a “type” attribute whose value is “hidden” must not have an “autocomplete” attribute whose value is “on” or “off”.** (medium) — x2, first at line 2234
2. **A “charset” attribute on a “meta” element found after the first 1024 bytes.** (medium) — x1, first at line 7
3. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 2122

### Issue groups
- (×1) [error] A “charset” attribute on a “meta” element found after the first 1024 bytes. — first at line 7 `charset="utf-8">
    <meta na`
- (×3) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 38 `banner --><script id="cookieyes" type="text/javascript" src="https://cdn-cookiey`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 2122 `apper_1' ><style>#gform`
- (×2) [error] An “input” element with a “type” attribute whose value is “hidden” must not have an “autocomplete” attribute whose value is “on” or “off”. — first at line 2234 `<input type='hidden' autocomplete='off' class='gform_hidden h-hidden' name='gfor`
- (×1) [warning] This document appears to be written in Estonian but the “html” start tag has “lang="en"”. Consider using “lang="et"” (or variant) instead. — first at line 2 `TYPE html>
<html class="no-js" lang="en">
<head`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2866 ms._

**Scoring:** 3 violations · 45 passes · critical 0 · serious 3 · moderate 0 · minor 0

### Priority fixes
1. **aria-hidden-focus** (high) — ARIA hidden element must not be focusable or contain focusable elements
2. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
3. **link-name** (high) — Links must have discernible text

### Findings

#### `aria-hidden-focus` (serious) — WCAG: wcag2a, wcag412
[ARIA hidden element must not be focusable or contain focusable elements](https://dequeuniversity.com/rules/axe/4.11/aria-hidden-focus?application=playwright)
- `.faq__slide.f-carousel__slide[data-index="0"]`
- `.faq__slide.f-carousel__slide[data-index="2"]`
- `.faq__slide.f-carousel__slide[data-index="3"]`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `.tag--brand`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.gallery-slider__item:nth-child(4) > .gallery-slider__image > .image__link[data-fancybox="gallery-carousel-6a7f0fc0db450"]`
- `.gallery-slider__item:nth-child(5) > .gallery-slider__image > .image__link[data-fancybox="gallery-carousel-6a7f0fc0db450"]`
- `.gallery-slider__item:nth-child(6) > .gallery-slider__image > .image__link[data-fancybox="gallery-carousel-6a7f0fc0db450"]`
- `.gallery-slider__item:nth-child(7) > .gallery-slider__image > .image__link[data-fancybox="gallery-carousel-6a7f0fc0db450"]`
- `.gallery-slider__item:nth-child(8) > .gallery-slider__image > .image__link[data-fancybox="gallery-carousel-6a7f0fc0db450"]`
- … and 14 more nodes

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 13 nodes

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2890 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 56 network requests · 2.23 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 28 | 1.77 MB |
| font | 4 | 284.3 KB |
| script | 15 | 116.0 KB |
| document | 1 | 35.2 KB |
| stylesheet | 2 | 27.7 KB |
| other | 1 | 4.5 KB |
| fetch | 4 | 44 B |
| ping | 1 | 0 B |

**Third-party origins (by bytes):**
- https://cdn-cookieyes.com — 9 requests, 44 B
- https://log.cookieyes.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://lootsa.ee/ (document) — 172 ms, 35.2 KB
- https://log.cookieyes.com/api/v1/log (ping) — 122 ms, 0 B
- https://cdn-cookieyes.com/client_data/6d4d733d03db47c5aecbf6c09eac2e0b/translations/gBap1QLC.json (fetch) — 62 ms, 0 B
- https://cdn-cookieyes.com/client_data/6d4d733d03db47c5aecbf6c09eac2e0b/audit-table/Jyy3AUGa.json (fetch) — 60 ms, 0 B
- https://cdn-cookieyes.com/assets/images/close.svg (image) — 54 ms, 0 B

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2889 ms._

**Document:**
- Lang: en
- Title: lootsa
- Canonical: https://lootsa.ee/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 354142

**Meta tags:**
- Description: not set
- Robots: max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 0 (none)
- Twitter tags: 0
- hreflang:
  - en → https://lootsa.ee
- JSON-LD: none

**Heading outline:**
- Counts: h1 ×1, h2 ×4, h3 ×12, h4 ×10, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Lõõtsa ärikvartal
                                                    Tartu tuik
  - h2: Miks valida
                            Lõõtsa ärikvartal?
  - h3: Roheline energia
  - h3: Parim sisekliima
  - h3: Turvaline keskkond
  - h3: Mugav ligipääs ja parkimine
  - h3: Elav ärikogukond
  - h2: Hooned ja vabad äripinnad
  - h3: Lõõtsa 4
  - h4: 1. korrus
  - h4: Sellel korrusel vabu pindu hetkel pole
  - h3: Lõõtsa 5
  - h4: 1. korrus
  - h4: 2. korrus
  - h4: 3. korrus
  - h4: Sellel korrusel vabu pindu hetkel pole
  - h3: Lõõtsa 6
  - h4: 1. korrus
  - h4: 2. korrus
  - h4: 3. korrus

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 27 total — 5 defer, 1 async, 9 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://cdn-cookieyes.com/client_data/6d4d733d03db47c5aecbf6c09eac2e0b/script.js
- https://cdn-cookieyes.com/client_data/6d4d733d03db47c5aecbf6c09eac2e0b/banner.js (async)
- https://lootsa.ee/wp-includes/js/dist/dom-ready.min.js
- https://lootsa.ee/wp-includes/js/dist/hooks.min.js
- https://lootsa.ee/wp-includes/js/dist/i18n.min.js
- https://lootsa.ee/wp-includes/js/dist/a11y.min.js
- https://lootsa.ee/wp-content/themes/lootsa-arikvartal/inc/theme/js/jquery.d34d86e241c9422e.js
- https://lootsa.ee/wp-content/themes/lootsa-arikvartal/inc/theme/js/core.e77acb129c76c92a.js
- https://lootsa.ee/wp-content/themes/lootsa-arikvartal/inc/theme/js/global.1c4ff9002c5bb70b.js
- https://lootsa.ee/wp-content/plugins/gravityforms/js/jquery.json.min.js (defer)
- https://lootsa.ee/wp-content/plugins/gravityforms/js/gravityforms.min.js (defer)
- https://lootsa.ee/wp-content/plugins/gravityforms/assets/js/dist/utils.min.js (defer)
- https://lootsa.ee/wp-content/plugins/gravityforms/assets/js/dist/vendor-theme.min.js (defer)
- https://lootsa.ee/wp-content/plugins/gravityforms/assets/js/dist/scripts-theme.min.js (defer)
- https://lootsa.ee/wp-includes/js/jquery/jquery-migrate.min.js

**Stylesheets:** 2 external, 5 inline (34.9 KB)

**Images:** 77 total — **0 without alt**, **10 without width/height**, 69 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/revisit.svg | Revisit consent button | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/close.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| lootsa.ee/wp-content/uploads/2026/08/lootsa_hero-320x180.jpg | _(empty)_ | 320×180 | lazy | ✓ |
| //lootsa.ee/wp-content/uploads/2026/07/galerii-1-360x240.jpg | Lõõtsa ärikvartali hoone välisvaade | 360×240 | eager | ✓ |
| //lootsa.ee/wp-content/uploads/2026/07/galerii-2-360x240.jpg | Lõõtsa ärikvartali klaasfassaad | 360×240 | eager | ✓ |
| otsa.ee/wp-content/uploads/2026/07/galerii-brand-360x240.jpg | Lõõtsa ärikvartali ärihoone | 360×240 | eager | ✓ |
| s://lootsa.ee/wp-content/uploads/2026/08/23a0249-360x240.jpg | _(empty)_ | 360×240 | eager | ✓ |
| s://lootsa.ee/wp-content/uploads/2026/08/23a0238-360x240.jpg | _(empty)_ | 360×240 | eager | ✓ |
| ent/uploads/2026/08/lootsa-arikvartal-gallerii-1-360x203.jpg | _(empty)_ | 360×203 | eager | ✓ |
| ent/uploads/2026/08/lootsa-arikvartal-gallerii-2-360x203.jpg | _(empty)_ | 360×203 | eager | ✓ |
| ent/uploads/2026/08/lootsa-arikvartal-gallerii-3-360x203.jpg | _(empty)_ | 360×203 | eager | ✓ |
| ent/uploads/2026/08/lootsa-arikvartal-gallerii-4-360x203.jpg | _(empty)_ | 360×203 | eager | ✓ |
| ent/uploads/2026/08/lootsa-arikvartal-gallerii-5-360x203.jpg | _(empty)_ | 360×203 | eager | ✓ |
| ent/uploads/2026/08/lootsa-arikvartal-gallerii-6-360x203.jpg | _(empty)_ | 360×203 | eager | ✓ |

**Links:** 103 anchors — 6 external, 0 preconnect, 0 preload.

Vague repeated link text:
- "ava korruseplaan suurelt" ×7
- "tutvu pindadega" ×3
- "anna mulle teada" ×3
- "küsi pakkumist" ×3
- "lõõtsa 4" ×2
- "lõõtsa 6" ×2
- "lõõtsa 5" ×2
- "lootsa@giga.ee" ×2

**Forms:**
Form 1:
- email — labeled
- tel — labeled
- text — labeled
- textarea — labeled
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **10 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **9 render-blocking external scripts** (medium) — Only 5 defer, 1 async; add defer/async to non-critical scripts
4. **Vague link text repeated** (medium) — "tutvu pindadega" ×3

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 3 pass · 1 warn · 2 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✗ fail | 66 of 73 non-hero raster images are not lazy-loaded (threshold: 14) (3 SVGs excluded). |
| Hero image eagerly loaded | ✗ fail | Hero image has loading="lazy", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading="eager" (or omit loading) and add fetchpriority="high". |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ✓ pass | 67/74 raster images use srcset or <picture> (91%) (3 SVGs excluded). |
| Reasonable number of image sizes | ✓ pass | 25 distinct srcset widths. |
| JS scripts not blocking in <head> | ! warn | 1 render-blocking script in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
- Images lazy-loaded:
  - `https://lootsa.ee/wp-content/uploads/2026/07/galerii-1-360x240.jpg`
  - `https://lootsa.ee/wp-content/uploads/2026/07/galerii-2-360x240.jpg`
  - `https://lootsa.ee/wp-content/uploads/2026/07/galerii-brand-360x240.jpg`
  - `https://lootsa.ee/wp-content/uploads/2026/08/23a0249-360x240.jpg`
  - `https://lootsa.ee/wp-content/uploads/2026/08/23a0238-360x240.jpg`
- Hero image eagerly loaded:
  - `hero: https://lootsa.ee/wp-content/uploads/2026/08/lootsa_hero-320x180.jpg`
  - `loading: lazy`
  - `fetchpriority: (not set)`
- Responsive images (srcset / <picture>):
  - `…a.ee/wp-content/themes/lootsa-arikvartal/inc/theme/img/lootsa4-plaan.jpg?v=58`
  - `…ee/wp-content/themes/lootsa-arikvartal/inc/theme/img/lootsa5-korrus1.jpg?v=58`
  - `…ee/wp-content/themes/lootsa-arikvartal/inc/theme/img/lootsa5-korrus2.jpg?v=58`
  - `…ee/wp-content/themes/lootsa-arikvartal/inc/theme/img/lootsa5-korrus3.jpg?v=58`
  - `…ee/wp-content/themes/lootsa-arikvartal/inc/theme/img/lootsa6-korrus1.jpg?v=58`
- Reasonable number of image sizes:
  - `widths: 233, 276, 278, 300, 320, 360, 420, 465, 498, 551, 555, 640, 720, 768, 840, 996, 1003, 1024, 1080, 1360, 1536, 1600, 1920, 2048, 2560`
- JS scripts not blocking in <head>:
  - `https://cdn-cookieyes.com/client_data/6d4d733d03db47c5aecbf6c09eac2e0b/script.js`

### Priority fixes
1. **Images lazy-loaded** (high) — 66 of 73 non-hero raster images are not lazy-loaded (threshold: 14) (3 SVGs excluded).
2. **Hero image eagerly loaded** (high) — Hero image has loading="lazy", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading="eager" (or omit loading) and add fetchpriority="high".
3. **JS scripts not blocking in <head>** (medium) — 1 render-blocking script in <head>. Move to footer or add defer/async.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).