20260817T064352Z-a8e5
- Audited URL
- https://lootsa.ee/
- Timestamp
- 2026-08-17T06:51:14.919Z
- Kind
- single
- Pages
- 1
Weighted audit summary
PSI mobile performance is excellent at 97 with LCP 2.0 s, but security headers score 0/100 and W3C validation has 15 errors. Two serious accessibility violations (link names, contrast) impact usability despite a 96 PSI accessibility score. The site signals indicate user-generated content (textarea, upload), elevating CSP to Priority 1. Mobile FCP is 1.97 s, slightly above the 1.8 s threshold, partly due to the hero image being lazy-loaded. Confidence is high as all audit tools returned complete data.
Audit Report: lootsa
Website: https://lootsa.ee/
Date: 17.08.2026
Audit Coverage: 100% — all sources returned data
Confidence: high
Pages Audited (1 of 1):
Summary of results
Overall Score: 73 / 100
Status: 🟡 Needs Improvement
PSI mobile performance is excellent at 97 with LCP 2.0 s, but security headers score 0/100 and W3C validation has 15 errors. Two serious accessibility violations (link names, contrast) impact usability despite a 96 PSI accessibility score. The site signals indicate user-generated content (textarea, upload), elevating CSP to Priority 1. Mobile FCP is 1.97 s, slightly above the 1.8 s threshold, partly due to the hero image being lazy-loaded. Confidence is high as all audit tools returned complete data.
Per-page scores
🟡 Needs Improvement · https://lootsa.ee/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 73 | 97 | 96 | 100 | 92 | 0 |
PageSpeed Insights — Mobile vs Desktop
Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.
| Strategy | Performance (M / D) | LCP (M / D) | CLS (M / D) |
|---|---|---|---|
| Mobile vs Desktop | 97 / 100 | 1.97 s / 641 ms | 0.000 / 0.028 |
Optimization Checklist
4 of 6 passing — 4 pass · 1 warn · 1 fail · 1 n/a
| Item | Status | Detail |
|---|---|---|
| Page caching plugin / CDN active | Pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | Pass | All non-hero raster images use loading="lazy". |
| Hero image eagerly loaded | Fail | Hero image has loading="lazy", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading="eager" (or omit loading) and add fetchpriority="high". |
| Hero is a real <img> (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | Warn | Only 23/30 raster images use srcset or <picture> (77%). |
| Reasonable number of image sizes | Pass | 25 distinct srcset widths. |
| JS scripts not blocking in <head> | Pass | No render-blocking scripts in <head>. |
Fixes
Priority 1: Critical
Immediate action — impacts user experience, search rankings, or site safety.
1A. Add baseline security headers (HSTS, X-Frame-Options, X-Content-Type-Options) Security
- Impact: Transport security, clickjacking, MIME sniffing
- Problem: Security Headers grade is 0/100; HSTS, X-Frame-Options, and X-Content-Type-Options are missing.
- Solution:
Add these headers to your server configuration (e.g., Apache .htaccess or Nginx config):
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" Header always set X-Frame-Options "SAMEORIGIN" Header always set X-Content-Type-Options "nosniff"
1B. Implement Content-Security-Policy (CSP) Security
- Impact: XSS defense-in-depth
- Problem: CSP is missing. Site signals indicate user-generated content (textarea, upload link), making XSS a higher risk (Priority 1 per rubric).
- Solution:
Deploy a strict CSP using nonces or hashes rather than a flat allowlist:
Ensure your server injects the nonce intoHeader always set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';"<script>tags.
1C. Fix hero image loading strategy Performance
- Impact: LCP, FCP
- Problem: Hero image
lootsa_hero-320x180.jpghasloading="lazy", which delays LCP (Mobile FCP 1.97 s). - Solution:
Remove
loading="lazy"from the hero image and addfetchpriority="high":<img src="/wp-content/uploads/.../lootsa_hero-320x180.jpg" fetchpriority="high" alt="...">
1D. Add accessible names to gallery image links Accessibility
- Impact: WCAG 2.4.4 (Link Purpose)
- Problem: Axe reports serious violations for 14+ gallery image links (
.gallery-slider__item > .image__link) lacking discernible text. - Solution:
Add
aria-labelor visible text to each link:<a href="..." aria-label="View image 1 of gallery"> <img src="..." alt="..."> </a>
Priority 2: Important
Essential for compliance, user reach, and search visibility.
2A. Fix color contrast on brand tags Accessibility
- Impact: WCAG 1.4.3 (Contrast)
- Problem: Axe reports serious contrast violation on
.tag--brandelements. - Solution: Increase contrast ratio to at least 4.5:1 for text against background. Suggest darkening text color or lightening background.
2B. Add meta description and correct language tag SEO
- Impact: Search visibility, screen reader language detection
- Problem: Meta description is missing; HTML
lang="en"but content is Estonian. - Solution:
Add a unique meta description:
Change HTML tag to:<meta name="description" content="Lõõtsa ärikvartal - äripinnad Tallinnas"><html lang="et">
2C. Fix W3C validation errors (script types, hidden inputs) Best Practices
- Impact: Code quality, potential rendering issues
- Problem: 15 W3C errors including
script type="text/rocketlazyloadscript"withdeferandinput type="hidden"withautocomplete. - Solution:
Update WP Rocket settings or custom scripts to use valid MIME types (e.g.,
application/javascript) or removedeferfrom non-JS types. Removeautocompletefrom hidden inputs.
Priority 3: Best Practice
Recommended for long-term maintainability.
No items.
▸Raw Markdown sent to the LLM
# Audit — https://lootsa.ee/
Run: 2026-08-17T06:43:52.305Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: **yes** — <textarea> in a form; anchor href contains "upload"
- E-commerce: no
## PageSpeed Insights
_Captured in 17134 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **97** | 100 |
| Accessibility | 96 | **92** |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **2.0 s** | 0.6 s |
| CLS | 0.000 | **0.028** |
| TBT | 0 ms | 0 ms |
| FCP | **1.97 s** | 441 ms |
| Speed Index | **2.84 s** | 910 ms |
| TTFB | **44 ms** | 17 ms |
### Priority fixes
1. **first-contentful-paint** (low) — 2.0 s
2. **image-delivery-insight** (medium) — Est savings of 91 KiB
3. **lcp-discovery-insight** (high)
4. **network-dependency-tree-insight** (high)
5. **render-blocking-insight** (high) — Est savings of 1,770 ms
### Findings (mobile)
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.85, weight 10) — First Contentful Paint — 2.0 s
- `lcp-discovery-insight` (performance, score 0.00, weight 0) — LCP request discovery
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 31 ms._
**Transport:**
- Final URL: https://lootsa.ee/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 17 Aug 2026 06:43:16 GMT
- expires: Mon, 17 Aug 2026 06:43:52 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 43324
- Decoded body: 243.8 KB
- Compression ratio: 0.174
### Priority fixes
1. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 43324
content-type: text/html; charset=UTF-8
date: Mon, 17 Aug 2026 06:43:52 GMT
expires: Mon, 17 Aug 2026 06:43:52 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 17 Aug 2026 06:43:16 GMT
server: Apache / ZoneOS
vary: Accept-Encoding
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1112 ms._
**Scoring:** 15 errors · 3 warnings · 20 cosmetic (suppressed)
### Priority fixes
1. **A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute.** (high) — x11, first at line 39
2. **An “input” element with a “type” attribute whose value is “hidden” must not have an “autocomplete” attribute whose value is “on” or “off”.** (medium) — x2, first at line 2175
3. **A “charset” attribute on a “meta” element found after the first 1024 bytes.** (medium) — x1, first at line 6
4. **Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.)** (medium) — x1, first at line 2063
### Issue groups
- (×1) [error] A “charset” attribute on a “meta” element found after the first 1024 bytes. — first at line 6 `charset="utf-8"><script>if(na`
- (×11) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 39 `banner --><script type="text/rocketlazyloadscript" id="cookieyes" data-rocket-ty`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 2052 `/noscript><script nowprocket type="text/javascript">var el`
- (×1) [error] Element “style” not allowed as child of element “div” in this context. (Suppressing further errors from this subtree.) — first at line 2063 `apper_1' ><style>#gform`
- (×2) [error] An “input” element with a “type” attribute whose value is “hidden” must not have an “autocomplete” attribute whose value is “on” or “off”. — first at line 2175 `<input type='hidden' autocomplete='off' class='gform_hidden h-hidden' name='gfor`
- (×1) [warning] This document appears to be written in Estonian but the “html” start tag has “lang="en"”. Consider using “lang="et"” (or variant) instead. — first at line 2 `TYPE html>
<html class="no-js" lang="en">
<head`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 1801 ms._
**Scoring:** 2 violations · 43 passes · critical 0 · serious 2 · moderate 0 · minor 0
### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **link-name** (high) — Links must have discernible text
### Findings
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `.tag--brand`
#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.gallery-slider__item:nth-child(4) > .gallery-slider__image > .image__link[data-fancybox="gallery-carousel-6a82ad8435613"]`
- `.gallery-slider__item:nth-child(5) > .gallery-slider__image > .image__link[data-fancybox="gallery-carousel-6a82ad8435613"]`
- `.gallery-slider__item:nth-child(6) > .gallery-slider__image > .image__link[data-fancybox="gallery-carousel-6a82ad8435613"]`
- `.gallery-slider__item:nth-child(7) > .gallery-slider__image > .image__link[data-fancybox="gallery-carousel-6a82ad8435613"]`
- `.gallery-slider__item:nth-child(8) > .gallery-slider__image > .image__link[data-fancybox="gallery-carousel-6a82ad8435613"]`
- … and 14 more nodes
### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 13 nodes
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 1819 ms._
**Capture summary:** 0 console events · 0 mixed-content requests · 14 network requests · 657.9 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 548.3 KB |
| document | 1 | 42.3 KB |
| font | 3 | 32.5 KB |
| stylesheet | 2 | 27.7 KB |
| other | 1 | 4.5 KB |
| script | 1 | 2.6 KB |
**Slowest requests (top 5):**
- https://lootsa.ee/wp-content/themes/lootsa-arikvartal/inc/theme/fonts/Raleway-Variable.woff2 (font) — 29 ms, 0 B
- https://lootsa.ee/ (document) — 26 ms, 42.3 KB
- https://lootsa.ee/wp-content/themes/lootsa-arikvartal/inc/theme/fonts/ClashDisplay-Medium.woff2 (font) — 21 ms, 16.3 KB
- https://lootsa.ee/wp-content/themes/lootsa-arikvartal/inc/theme/fonts/ClashDisplay-Regular.woff2 (font) — 21 ms, 16.2 KB
- https://lootsa.ee/wp-content/uploads/2026/07/galerii-1-840x560.jpg (image) — 19 ms, 52.2 KB
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 1819 ms._
**Document:**
- Lang: en
- Title: lootsa
- Canonical: https://lootsa.ee/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 242068
**Meta tags:**
- Description: not set
- Robots: max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 0 (none)
- Twitter tags: 0
- hreflang:
- en → https://lootsa.ee
- JSON-LD: none
**Heading outline:**
- Counts: h1 ×1, h2 ×4, h3 ×12, h4 ×8, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Lõõtsa ärikvartal
Aadress, m
- h2: Miks valida
Lõõtsa ärikvartal?
- h3: Roheline energia
- h3: Parim sisekliima
- h3: Turvaline keskkond
- h3: Mugav ligipääs ja parkimine
- h3: Elav ärikogukond
- h2: Hooned ja vabad äripinnad
- h3: Lõõtsa 4
- h4: 1. korrus
- h4: Sellel korrusel vabu pindu hetkel pole
- h3: Lõõtsa 5
- h4: 2. korrus
- h4: Sellel korrusel vabu pindu hetkel pole
- h3: Lõõtsa 6
- h4: 1. korrus
- h4: 2. korrus
- h4: 3. korrus
- h4: Sellel korrusel vabu pindu hetkel pole
- h2: Korduma kippuvad
küsimused
**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: **missing**
**Scripts:** 32 total — 0 defer, 0 async, 1 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://lootsa.ee/wp-content/themes/lootsa-arikvartal/inc/theme/js/core.e77acb129c76c92a.js
**Stylesheets:** 2 external, 4 inline (14.2 KB)
**Images:** 30 total — **0 without alt**, **7 without width/height**, 0 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| lootsa.ee/wp-content/uploads/2026/08/lootsa_hero-320x180.jpg | _(empty)_ | 320×180 | lazy | ✓ |
| //lootsa.ee/wp-content/uploads/2026/07/galerii-1-360x240.jpg | Lõõtsa ärikvartali hoone välisvaade | 360×240 | lazy | ✓ |
| //lootsa.ee/wp-content/uploads/2026/07/galerii-2-360x240.jpg | Lõõtsa ärikvartali klaasfassaad | 360×240 | lazy | ✓ |
| otsa.ee/wp-content/uploads/2026/07/galerii-brand-360x240.jpg | Lõõtsa ärikvartali ärihoone | 360×240 | lazy | ✓ |
| s://lootsa.ee/wp-content/uploads/2026/08/23a0249-360x240.jpg | _(empty)_ | 360×240 | lazy | ✓ |
| s://lootsa.ee/wp-content/uploads/2026/08/23a0238-360x240.jpg | _(empty)_ | 360×240 | lazy | ✓ |
| ent/uploads/2026/08/lootsa-arikvartal-gallerii-1-360x203.jpg | _(empty)_ | 360×203 | lazy | ✓ |
| ent/uploads/2026/08/lootsa-arikvartal-gallerii-2-360x203.jpg | _(empty)_ | 360×203 | lazy | ✓ |
| ent/uploads/2026/08/lootsa-arikvartal-gallerii-3-360x203.jpg | _(empty)_ | 360×203 | lazy | ✓ |
| ent/uploads/2026/08/lootsa-arikvartal-gallerii-4-360x203.jpg | _(empty)_ | 360×203 | lazy | ✓ |
| ent/uploads/2026/08/lootsa-arikvartal-gallerii-5-360x203.jpg | _(empty)_ | 360×203 | lazy | ✓ |
| ent/uploads/2026/08/lootsa-arikvartal-gallerii-6-360x203.jpg | _(empty)_ | 360×203 | lazy | ✓ |
| ent/uploads/2026/08/lootsa-arikvartal-gallerii-7-360x203.jpg | _(empty)_ | 360×203 | lazy | ✓ |
| ent/uploads/2026/08/lootsa-arikvartal-gallerii-8-360x203.jpg | _(empty)_ | 360×203 | lazy | ✓ |
| ent/uploads/2026/08/lootsa-arikvartal-gallerii-9-360x203.jpg | _(empty)_ | 360×203 | lazy | ✓ |
**Links:** 58 anchors — 5 external, 1 preconnect, 0 preload.
Vague repeated link text:
- "ava korruseplaan suurelt" ×7
- "tutvu pindadega" ×3
- "anna mulle teada" ×3
- "küsi pakkumist" ×3
- "lõõtsa 4" ×2
- "lõõtsa 6" ×2
- "lõõtsa 5" ×2
- "lootsa@giga.ee" ×2
**Forms:**
Form 1:
- email — labeled
- tel — labeled
- text — labeled
- textarea — labeled
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **7 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **Vague link text repeated** (medium) — "tutvu pindadega" ×3
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 4 pass · 1 warn · 1 fail · 1 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All non-hero raster images use loading="lazy". |
| Hero image eagerly loaded | ✗ fail | Hero image has loading="lazy", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading="eager" (or omit loading) and add fetchpriority="high". |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ! warn | Only 23/30 raster images use srcset or <picture> (77%). |
| Reasonable number of image sizes | ✓ pass | 25 distinct srcset widths. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.23.2.1`
- Hero image eagerly loaded:
- `hero: https://lootsa.ee/wp-content/uploads/2026/08/lootsa_hero-320x180.jpg`
- `loading: lazy`
- `fetchpriority: (not set)`
- Responsive images (srcset / <picture>):
- `…a.ee/wp-content/themes/lootsa-arikvartal/inc/theme/img/lootsa4-plaan.jpg?v=58`
- `…ee/wp-content/themes/lootsa-arikvartal/inc/theme/img/lootsa5-korrus1.jpg?v=58`
- `…ee/wp-content/themes/lootsa-arikvartal/inc/theme/img/lootsa5-korrus2.jpg?v=58`
- `…ee/wp-content/themes/lootsa-arikvartal/inc/theme/img/lootsa5-korrus3.jpg?v=58`
- `…ee/wp-content/themes/lootsa-arikvartal/inc/theme/img/lootsa6-korrus1.jpg?v=58`
- Reasonable number of image sizes:
- `widths: 233, 276, 278, 300, 320, 360, 420, 465, 498, 551, 555, 640, 720, 768, 840, 996, 1003, 1024, 1080, 1360, 1536, 1600, 1920, 2048, 2560`
### Priority fixes
1. **Hero image eagerly loaded** (high) — Hero image has loading="lazy", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading="eager" (or omit loading) and add fetchpriority="high".
2. **Responsive images (srcset / <picture>)** (medium) — Only 23/30 raster images use srcset or <picture> (77%).
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).