Audit

20260924T095417Z-a917

← Back to playee
Audited URL
https://play.ee/
Timestamp
2026-09-24T09:58:42.500Z
Kind
site
Pages
5
Audit summary
https://play.ee/
5 of 5 pages audited
Pagespeed scores
Other checks
LLM Report

Weighted audit summary

76
Overall site quality
Needs Improvementlow confidence

Site overall 76 is the mean of 4 pages. Scores range 73 (https://play.ee/team) → 78 (https://play.ee/privacy-policy). Weakest page: PSI mobile performance is strong at 94 with excellent TTFB and CLS, though LCP sits at 2.8 s in the warning range. However, the Security basics verdict is FAILED due to missing HTTP-to-HTTPS redirects and HSTS, which caps the overall score below 90 per the rubric. Accessibility has a serious color-contrast violation and missing landmarks despite a 94 score. W3C validation reports 7 errors including parser recovery failure, indicating broken HTML structure. Confidence is high as all audit tools returned complete data.

Per-page scores
78
Home
high
73
/team
high
78
/privacy-policy
medium
74
/et/meeskond
medium
—
…rdpress-support-service
low

Audit Report: Perfectly formed web development team - gotoAndPlay

Website: https://play.ee/
Date: 24.09.2026
Audit Coverage: 95% — PageSpeed Insights (desktop): PSI HTTP 429; PageSpeed Insights (mobile): PSI HTTP 429; PageSpeed Insights: mobile: PSI HTTP 429; desktop: PSI HTTP 429
Confidence: low

Pages Audited (5 of 5):

Summary of results

Overall Score: 76 / 100
Status: ⚠ 🟡 Needs Improvement

Site overall 76 is the mean of 4 pages. Scores range 73 (https://play.ee/team) → 78 (https://play.ee/privacy-policy). Weakest page: PSI mobile performance is strong at 94 with excellent TTFB and CLS, though LCP sits at 2.8 s in the warning range. However, the Security basics verdict is FAILED due to missing HTTP-to-HTTPS redirects and HSTS, which caps the overall score below 90 per the rubric. Accessibility has a serious color-contrast violation and missing landmarks despite a 94 score. W3C validation reports 7 errors including parser recovery failure, indicating broken HTML structure. Confidence is high as all audit tools returned complete data.

Per-page scores

🟡 Needs Improvement · https://play.ee/

Score Performance Accessibility Best Practices SEO Security
78 96 94 100 92 FAILED

🟡 Needs Improvement · https://play.ee/team

Score Performance Accessibility Best Practices SEO Security
73 94 94 100 100 FAILED

🟡 Needs Improvement · https://play.ee/privacy-policy

Score Performance Accessibility Best Practices SEO Security
78 93 87 100 100 FAILED

🟡 Needs Improvement · https://play.ee/et/meeskond

Score Performance Accessibility Best Practices SEO Security
74 100 93 100 100 FAILED

— · https://play.ee/wordpress-support-service

Score Performance Accessibility Best Practices SEO Security
— — — — — FAILED

PageSpeed Insights — Mobile vs Desktop

Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.

URL Performance (M / D) LCP (M / D) CLS (M / D)
https://play.ee/ 96 / 100 2.48 s / 546 ms 0.001 / 0.005
https://play.ee/team 94 / 100 2.78 s / 633 ms 0.037 / 0.003
https://play.ee/privacy-policy 93 / — 2.80 s / — 0.002 / —
https://play.ee/et/meeskond — / 100 — / 629 ms — / 0.003

Optimization Checklist

3 of 3 passing — 3 pass · 0 warn · 0 fail · 5 n/a

Item Status Detail
Page caching plugin / CDN active Pass Caching plugin detected (WP Rocket)
Response compressed (gzip / brotli) Pass Document response is compressed with gzip.
Images lazy-loaded N/A No raster <img> elements found (37 SVGs, 13 placeholders excluded).
Hero image eagerly loaded N/A No raster <img> elements found (37 SVGs, 13 placeholders excluded).
Hero is a real <img> (not a CSS background-image) N/A No CSS background-images detected on raster-image-eligible elements.
Responsive images (srcset / <picture>) N/A Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply.
Reasonable number of image sizes N/A Too few raster images to evaluate srcset width variety.
JS scripts not blocking in <head> Pass No render-blocking scripts in <head>.

Fixes

Priority 1: Critical

Immediate action — impacts user experience, search rankings, or site safety.

1A. Enforce HTTPS redirect and add HSTS Security

  • Impact: Transport security, trust, security basics score
  • Problem: Security basics verdict is FAILED; HTTP does not redirect to HTTPS and Strict-Transport-Security header is missing.
  • Solution: Configure the web server to redirect all HTTP traffic to HTTPS (301) and send the HSTS header:
    Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
    RewriteEngine On
    RewriteCond %{HTTPS} off
    RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
    

1B. Fix W3C HTML validation errors Best Practices

  • Impact: Rendering stability, SEO indexing
  • Problem: W3C validator reports 7 errors including parser recovery failure at line 101 (bad start tag in iframe/noscript in head).
  • Solution: Move the Google Tag Manager iframe snippet out of the <head> or ensure it is properly closed within <noscript> without breaking the <head> structure. Remove invalid name attributes on <meta> tags inside the <head>.

1C. Fix HTTP redirect and add baseline security headers Security

  • Impact: Transport security, clickjacking, MIME sniffing
  • Problem: Security basics verdict is FAILED: HTTP does not redirect to HTTPS, HSTS is missing, and X-Content-Type-Options is missing.
  • Solution: Configure server to redirect HTTP to HTTPS and add headers:
    Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
    Header always set X-Content-Type-Options "nosniff"
    RewriteEngine On
    RewriteCond %{HTTPS} off
    RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
    

1D. Enforce HTTPS and add baseline security headers Security

  • Impact: Transport security, clickjacking, MIME sniffing
  • Problem: Security basics verdict is FAILED: HTTP does not redirect to HTTPS, HSTS is missing, and X-Content-Type-Options is missing.
  • Solution: Configure the web server to redirect all HTTP traffic to HTTPS and send these headers:
    Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
    Header always set X-Content-Type-Options "nosniff"
    

1E. Disable WordPress xmlrpc.php POST requests Security

  • Impact: Brute-force protection, pingback vector
  • Problem: Security basics report shows xmlrpc.php accepts POST requests, a known brute-force vector.
  • Solution: Block POST requests to xmlrpc.php in .htaccess or via a security plugin:
    <Files xmlrpc.php>
      <Limit POST>
        deny from all
      </Limit>
    </Files>
    

1F. Fix HTTP to HTTPS redirect and add HSTS Security

  • Impact: Transport security, Security Basics verdict

  • Problem: Security Basics FAILED: HTTP does not redirect to HTTPS and Strict-Transport-Security header is missing.

  • Solution: Configure server to redirect all HTTP traffic to HTTPS immediately.

    Add HSTS header:

    Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
    

1G. Add X-Content-Type-Options header Security

  • Impact: MIME sniffing protection
  • Problem: Security Basics FAILED: X-Content-Type-Options header is missing.
  • Solution: Add the following header to prevent MIME type sniffing:
    Header always set X-Content-Type-Options "nosniff"
    

Priority 2: Important

Essential for compliance, user reach, and search visibility.

2A. Add explicit width and height to images Performance

  • Impact: CLS (Cumulative Layout Shift)
  • Problem: 50 images lack explicit width/height attributes, creating a high risk for layout shifts even though current CLS is 0.001.
  • Solution: Add width and height attributes to all <img> tags matching the intrinsic aspect ratio:
    <img src="image.jpg" width="800" height="600" alt="...">
    

2B. Add skip-to-content link and main landmark Accessibility

  • Impact: Keyboard navigation, screen reader usability
  • Problem: HTML inventory shows missing main landmark and no skip-to-content link; axe reports region and landmark-unique violations.
  • Solution: Add a skip link at the top of the body:
    <a href="#main-content" class="skip-link">Skip to content</a>
    
    Wrap the primary content in <main id="main-content">.

2C. Disable WordPress xmlrpc.php POST requests Security

  • Impact: Brute-force protection, server load
  • Problem: Security basics report indicates xmlrpc.php accepts POST requests, a known brute-force vector.
  • Solution: Block POST requests to xmlrpc.php in .htaccess:
    <Files xmlrpc.php>
      <Limit POST>
        deny from all
      </Limit>
    </Files>
    

2D. Fix color contrast and add main landmark Accessibility

  • Impact: WCAG 1.4.3 contrast, 1.3.1 info and relationships
  • Problem: axe-core reports 1 serious violation on .heading__main contrast; document lacks a main landmark and skip-to-content link.
  • Solution:
    • Increase contrast on .heading__main to ≥4.5:1.
    • Add <main id="main-content"> wrapper around primary content.
    • Add skip link at top: <a href="#main-content" class="skip-link">Skip to content</a>.

2E. Resolve W3C HTML validation errors Best Practices

  • Impact: Parser compatibility, SEO rendering
  • Problem: W3C Validator reports 7 errors including parser recovery failure at line 105 and invalid iframe/noscript placement in head.
  • Solution:
    • Move <noscript><iframe>...</iframe></noscript> out of <head> (likely GTM snippet).
    • Fix stray end tags and meta attributes.
    • Ensure <body> opens correctly after </head>.

2F. Fix color contrast and heading hierarchy Accessibility

  • Impact: WCAG 1.4.3 contrast, 1.3.1 heading order
  • Problem: axe-core found 1 serious color-contrast violation on h1 and .button, plus heading order skips (h1→h4).
  • Solution:
    • Adjust text colors to meet 4.5:1 contrast ratio.
    • Ensure headings follow sequential order (h1 → h2 → h3) without skipping levels.

2G. Fix W3C HTML validation errors SEO

  • Impact: Parser recovery, rendering consistency
  • Problem: W3C validator reported 7 errors including parser recovery failure at line 100 and invalid iframe/noscript placement in head.
  • Solution:
    • Move <noscript><iframe>...</iframe></noscript> out of <head>.
    • Ensure <meta> tags are placed correctly within <head>.
    • Validate HTML structure to prevent parser recovery mode.

2H. Fix HTML validation errors SEO

  • Impact: Parsing, SEO, Accessibility
  • Problem: W3C Validator reported 8 errors including parser recovery failure at line 102 and bad href attributes.
  • Solution:
    • Remove empty href attributes on <link> tags.
    • Fix <noscript> placement (not allowed in <head>).
    • Ensure <meta> tags are correctly placed within <head>.

Priority 3: Best Practice

Recommended for long-term maintainability.

3A. Strengthen Content-Security-Policy Security

  • Impact: XSS defense-in-depth
  • Problem: CSP is present but weak (missing default-src, object-src not 'none'). Site signals show no auth/payments/UGC, lowering priority.
  • Solution: Add default-src 'self' and object-src 'none' to the CSP header. Since this is a brochure site, a strict allowlist is less critical than basic headers, but improves defense-in-depth.

3B. Add explicit width and height to images Performance

  • Impact: CLS (Cumulative Layout Shift)
  • Problem: 45 images lack width/height attributes, risking layout shifts despite current CLS of 0.037.
  • Solution: Add width and height attributes to all <img> tags:
    <img src="..." alt="..." width="300" height="200">
    

3C. Harden WordPress configuration Security

  • Impact: Brute-force protection, attack surface
  • Problem: xmlrpc.php accepts POST requests and /wp-admin/install.php is reachable.
  • Solution:
    • Disable xmlrpc.php in .htaccess or via plugin.
    • Block /wp-admin/install.php access after installation.
    • Consider changing default login path.

3D. Eliminate render-blocking JavaScript Performance

  • Impact: FCP, LCP, TBT
  • Problem: PSI findings estimate 1,230 ms savings from render-blocking insights; unused JS detected (23 KB).
  • Solution:
    • Add defer or async to non-critical scripts.
    • Inline critical CSS and defer non-critical JS.
    • Remove or tree-shake the 23 KB of unused jQuery code.

3E. Harden Content-Security-Policy (CSP) Security

  • Impact: XSS defense-in-depth
  • Problem: Current CSP only sets frame-ancestors 'self'; missing default-src and object-src 'none'.
  • Solution: Since the site has no auth/payments (signals: no), a strict CSP is P3. If implemented later, use nonce-based CSP:
    Header always set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none';"
    

3F. Add image dimensions and lazy loading Performance

  • Impact: CLS, Layout stability
  • Problem: HTML Inventory shows 45 images without explicit width/height and 45 without loading="lazy".
  • Solution: Add width and height attributes to all <img> tags to reserve space. Add loading="lazy" to images below the fold:
    <img src="..." alt="..." width="300" height="200" loading="lazy">
    

3G. Harden WordPress security endpoints Security

  • Impact: Brute-force protection, Attack surface
  • Problem: Security basics warn: xmlrpc.php accepts POST requests and /wp-admin/install.php is reachable.
  • Solution:
    • Disable xmlrpc.php in .htaccess or via plugin.
    • Block access to /wp-admin/install.php after installation:
    <Files "install.php">
      Require all denied
    </Files>
    
▸Raw Markdown sent to the LLM
# Site Audit — https://play.ee/
Run: 2026-09-24T09:54:38.817Z

Audited **5** of 5 discovered pages.
Average per-page audit coverage: **95%**

Aggregate missing or failed sources (deduped across pages):
- PageSpeed Insights (desktop): PSI HTTP 429
- PageSpeed Insights (mobile): PSI HTTP 429
- PageSpeed Insights: mobile: PSI HTTP 429; desktop: PSI HTTP 429

Pages audited:
- https://play.ee/
- https://play.ee/team
- https://play.ee/privacy-policy
- https://play.ee/et/meeskond
- https://play.ee/wordpress-support-service

---

# Page 1 of 5 — https://play.ee/

Run: 2026-09-24T09:54:40.828Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 18129 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **96** | 100 |
| Accessibility | **94** | 95 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **2.6 s** | 0.5 s |
| CLS | 0.001 | **0.005** |
| TBT | **20 ms** | 0 ms |
| FCP | **1.97 s** | 486 ms |
| Speed Index | **2.90 s** | 513 ms |
| TTFB | 7 ms | **40 ms** |

### Priority fixes
1. **largest-contentful-paint** (low) — 2.6 s
2. **speed-index** (low) — 3.8 s
3. **first-contentful-paint** (low) — 2.0 s
4. **network-dependency-tree-insight** (high)
5. **render-blocking-insight** (high) — Est savings of 1,060 ms

### Findings (mobile)

#### Unused JavaScript
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js — 23 KB wasted

#### Long tasks
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js — 89 ms
- https://play.ee/ — 51 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `largest-contentful-paint` (performance, score 0.87, weight 25) — Largest Contentful Paint — 2.6 s
- `speed-index` (performance, score 0.83, weight 10) — Speed Index — 3.8 s
- `first-contentful-paint` (performance, score 0.85, weight 10) — First Contentful Paint — 2.0 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 9 links found

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 1255 ms._

**Transport:**
- Final URL: https://play.ee/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://play.ee/ does not redirect to HTTPS (target: none)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 15 Sep 2026 08:38:43 GMT
- expires: Thu, 24 Sep 2026 09:54:40 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 35451
- Decoded body: 216.5 KB
- Compression ratio: 0.16

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://play.ee/ does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy weak** (high) — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (weak, high) `frame-ancestors 'self';` — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`
- X-Powered-By: `PHP/8.3.33`

#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 35451
content-security-policy: frame-ancestors 'self';
content-type: text/html; charset=UTF-8
date: Thu, 24 Sep 2026 09:54:40 GMT
expires: Thu, 24 Sep 2026 09:54:40 GMT
keep-alive: timeout=5, max=100
last-modified: Tue, 15 Sep 2026 08:38:43 GMT
server: Apache
upgrade: h2,h2c
vary: Accept-Encoding
x-frame-options: SAMEORIGIN
x-powered-by: PHP/8.3.33
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 773 ms._

**Scoring:** 7 errors · 0 warnings · 23 cosmetic (suppressed)

> **Validator truncated at line 101** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.

### Priority fixes
1. **Parser recovery at line 101** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad start tag in “iframe” in “noscript” in “head”.** (medium) — x1, first at line 98
3. **Stray end tag “noscript”.** (medium) — x1, first at line 98
4. **Attribute “name” not allowed on element “meta” at this point.** (medium) — x1, first at line 100
5. **Element “meta” is missing one or more of the following attributes: “itemprop”, “property”.** (medium) — x1, first at line 100

### Issue groups
- (×1) [error] Bad start tag in “iframe” in “noscript” in “head”. — first at line 98 `<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-K3P64XMJ"`
- (×1) [error] Stray end tag “noscript”. — first at line 98 `></iframe></noscript><!-- E`
- (×1) [error] Attribute “name” not allowed on element “meta” at this point. — first at line 100 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Element “meta” is missing one or more of the following attributes: “itemprop”, “property”. — first at line 100 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Stray end tag “head”. — first at line 100 `esktop" /></head>
<body`
- (×1) [error] Start tag “body” seen but an element of the same type was already open. — first at line 101 `/></head>
<body class="home wp-singular page-template page-template-template-dyn`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 101 `/></head>
<body class="home wp-singular page-template page-template-template-dyn`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2287 ms._

**Scoring:** 2 violations · 32 passes · critical 0 · serious 0 · moderate 2 · minor 0

### Priority fixes
1. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
2. **region** (medium) — All page content should be contained by landmarks

### Findings

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.header__nav`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.home-hero__main`
- `.home-hero__bottom`
- `canvas`
- `.keywords__mouse`
- `.keywords__intro`
- … and 31 more nodes

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 38 nodes

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2303 ms._

**Capture summary:** 1 console events · 0 mixed-content requests · 13 network requests · 178.1 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| font | 3 | 57.6 KB |
| script | 4 | 45.6 KB |
| document | 1 | 34.6 KB |
| stylesheet | 2 | 34.2 KB |
| other | 1 | 5.5 KB |
| image | 1 | 576 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 2 requests, 13.2 KB
- https://fast.fonts.net — 2 requests, 0 B

**Slowest requests (top 5):**
- https://play.ee/ (document) — 460 ms, 34.6 KB
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/fonts/1c0243aa-c535-4d42-ac53-d6f0f74a1412.bd94708352cbb3b4863c.woff2 (font) — 208 ms, 19.3 KB
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/fonts/fc2fa85e-cd2d-4004-930a-8adad6c60317.3bd2a5f3705d9fb438c5.woff2 (font) — 208 ms, 19.3 KB
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/fonts/f389f79b-6013-4448-aa6a-b6fd235eab80.b91a05bafb09e626383a.woff2 (font) — 208 ms, 19.0 KB
- https://fast.fonts.net/t/1.css?apiType=css&projectid=d924b670-8ecc-46fd-9fff-80fd9989d037 (stylesheet) — 33 ms, 0 B

### Findings

#### Console events
- [warning] Couldn't load preload assets:  

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2303 ms._

**Document:**
- Lang: en
- Title: Perfectly formed web development team - gotoAndPlay
- Canonical: https://play.ee/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 217719

**Meta tags:**
- Description: Small, agile web development team working on big ideas in close collaboration with our clients. Result driven from day one!
- Robots: follow, index, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time)
- Twitter tags: 3
- hreflang:
  - en → http://play.ee/
  - et → http://play.ee/et/
  - x-default → http://play.ee/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×6, h3 ×5, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: we create memorable experiences with
        
                    web technologi
  - h2: Your result
  - h2: we offer
        
                    more than expected
  - h2: Üks
  - h2: meet the team of
        
                    uncommon talent
  - h2: proof to our approach are
        
                    happy clients
  - h3: Deliverables with high quality standards
  - h3: Working with gotoAndPlay is a great experience
  - h3: Speed, attitude, skills!
  - h3: Hardworking, fun & ready to adopt new technologies
  - h3: The sky is the limit
  - h2: take a look at our
        
                    
    case studies

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 23 total — 3 defer, 0 async, 1 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/runtime.30d3b226dcf211e512b1.min.js
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js (defer)

**Stylesheets:** 1 external, 3 inline (9.6 KB)

**Images:** 50 total — **0 without alt**, **50 without width/height**, 50 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| ee/wp-content/themes/gotoandplay/inc/theme/img/landscape.svg | Please turn your device sideways | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 46 anchors — 34 external, 1 preconnect, 0 preload.

Vague repeated link text:
- "read more" ×9
- "view our instagram feed" ×3
- "visit our facebook page" ×3
- "visit our linkedin page" ×3
- "eng" ×3
- "est" ×3
- "case studies" ×2
- "styleguide" ×2
- "privacy policy" ×2

**Forms:**
Form 1:
- text — labeled

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **50 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **Vague link text repeated** (medium) — "read more" ×9

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 3 pass · 0 warn · 0 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Response compressed (gzip / brotli) | ✓ pass | Document response is compressed with gzip. |
| Images lazy-loaded | – n/a | No raster <img> elements found (37 SVGs, 13 placeholders excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (37 SVGs, 13 placeholders excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WP Rocket 3.23.3.3`
- Response compressed (gzip / brotli):
  - `content-encoding: gzip`
  - `decoded body: 221727 bytes`
  - `ratio: 0.16`

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

## Security basics
_Captured in 0 ms._

**Verdict: FAILED**

> These are high-level hygiene checks on HTTP headers, TLS, cookies and a few well-known exposed paths. PASS means the basics are in place. It does **not** mean the site is secure: application logic, authentication, plugins, server configuration and dependencies are not tested here. Treat FAILED as a must-fix and PASS as a starting point, not a certificate.

| Check | Tier | Status | Detail |
| --- | --- | --- | --- |
| HTTP redirects to HTTPS | basic | fail | Plain HTTP does not redirect to HTTPS. |
| Strict-Transport-Security | basic | fail | Strict-Transport-Security header is missing. |
| Clickjacking protection | basic | pass | Framing is restricted. |
| X-Content-Type-Options | basic | fail | X-Content-Type-Options header is missing. |
| Cookies Secure + HttpOnly | basic | n/a | The document response sets no cookies. |
| No mixed content | basic | pass | No http:// subresources were loaded. |
| CORS | basic | pass | No wildcard CORS origin. |
| Technology disclosure | basic | warn | Response headers disclose server technology. |
| TLS certificate and protocol | basic | pass | Valid certificate and modern TLS protocol. |
| No exposed sensitive files | basic | pass | None of 6 probed sensitive paths returned real content. |
| Forms do not post to HTTP | basic | pass | No form action uses http://. |
| Content-Security-Policy present | advanced | pass | Content-Security-Policy header is set. |
| CSP is strict | advanced | fail | CSP has 2 issues: default-src missing; object-src is not 'none'. |
| HSTS preload | advanced | fail | Strict-Transport-Security header is missing. |
| Referrer-Policy | advanced | fail | Referrer-Policy header is missing. |
| Permissions-Policy | advanced | fail | Permissions-Policy header is missing. |
| Cross-Origin-Opener-Policy | advanced | fail | Cross-Origin-Opener-Policy header is missing. |
| Cross-Origin-Resource-Policy | advanced | fail | Cross-Origin-Resource-Policy header is missing. |
| Cookies SameSite | advanced | n/a | The document response sets no cookies. |
| Subresource Integrity | advanced | warn | 2 of 2 cross-origin scripts lack an integrity attribute. |
| SPF + DMARC DNS records | advanced | pass | SPF and DMARC records are present. |
| WP version not disclosed | wordpress | pass | No WordPress version found in generator meta or core asset URLs. |
| xmlrpc.php disabled | wordpress | fail | xmlrpc.php accepts POST requests (brute-force / pingback vector). |
| User enumeration blocked | wordpress | pass | No username leak across 3 enumeration probes. |
| readme.html removed | wordpress | pass | readme.html is not served. |
| Directory listing off | wordpress | pass | Uploads directory does not return an index page. |
| debug.log not public | wordpress | pass | debug.log is not served. |
| No config backups or installer | wordpress | warn | Installer /wp-admin/install.php is reachable. Harmless while the site is installed, but it becomes an open takeover path if the database is ever unreachable — block it in .htaccess. |
| Login not on default path | wordpress | warn | Login form is served on the default /wp-login.php path. |

---

# Page 2 of 5 — https://play.ee/team

Run: 2026-09-24T09:54:40.828Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 19100 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **94** | 100 |
| Accessibility | 94 | **93** |
| Best Practices | 100 | 100 |
| SEO | 100 | 100 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **2.8 s** | 0.6 s |
| CLS | **0.037** | 0.003 |
| TBT | 0 ms | 0 ms |
| FCP | **2.13 s** | 573 ms |
| Speed Index | **2.13 s** | 685 ms |
| TTFB | 4 ms | **5 ms** |

### Priority fixes
1. **largest-contentful-paint** (low) — 2.8 s
2. **first-contentful-paint** (low) — 2.1 s
3. **document-latency-insight** (high) — Est savings of 380 ms
4. **network-dependency-tree-insight** (high)
5. **render-blocking-insight** (high) — Est savings of 990 ms

### Findings (mobile)

#### Unused JavaScript
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js — 23 KB wasted

#### Layout-shift sources
- div.team-grid > div.team-grid__inner > div.intro > div.intro__content — shift 0.037

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `largest-contentful-paint` (performance, score 0.83, weight 25) — Largest Contentful Paint — 2.8 s
- `landmark-one-main` (accessibility, score 0.00, weight 3) — Document does not have a main landmark.
- `first-contentful-paint` (performance, score 0.80, weight 10) — First Contentful Paint — 2.1 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 1648 ms._

**Transport:**
- Final URL: https://play.ee/team/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://play.ee/team does not redirect to HTTPS (target: http://play.ee/team/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 15 Sep 2026 11:35:03 GMT
- expires: Thu, 24 Sep 2026 09:54:41 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 28364
- Decoded body: 169.4 KB
- Compression ratio: 0.163

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://play.ee/team does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy weak** (high) — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (weak, high) `frame-ancestors 'self';` — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`
- X-Powered-By: `PHP/8.3.33`

#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 28364
content-security-policy: frame-ancestors 'self';
content-type: text/html; charset=UTF-8
date: Thu, 24 Sep 2026 09:54:41 GMT
expires: Thu, 24 Sep 2026 09:54:41 GMT
keep-alive: timeout=5, max=99
last-modified: Tue, 15 Sep 2026 11:35:03 GMT
server: Apache
vary: Accept-Encoding
x-frame-options: SAMEORIGIN
x-powered-by: PHP/8.3.33
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1557 ms._

**Scoring:** 7 errors · 0 warnings · 23 cosmetic (suppressed)

> **Validator truncated at line 105** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.

### Priority fixes
1. **Parser recovery at line 105** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad start tag in “iframe” in “noscript” in “head”.** (medium) — x1, first at line 102
3. **Stray end tag “noscript”.** (medium) — x1, first at line 102
4. **Attribute “name” not allowed on element “meta” at this point.** (medium) — x1, first at line 104
5. **Element “meta” is missing one or more of the following attributes: “itemprop”, “property”.** (medium) — x1, first at line 104

### Issue groups
- (×1) [error] Bad start tag in “iframe” in “noscript” in “head”. — first at line 102 `<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-K3P64XMJ"`
- (×1) [error] Stray end tag “noscript”. — first at line 102 `></iframe></noscript><!-- E`
- (×1) [error] Attribute “name” not allowed on element “meta” at this point. — first at line 104 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Element “meta” is missing one or more of the following attributes: “itemprop”, “property”. — first at line 104 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Stray end tag “head”. — first at line 104 `esktop" /></head>
<body`
- (×1) [error] Start tag “body” seen but an element of the same type was already open. — first at line 105 `/></head>
<body class="wp-singular page-template page-template-template-dynamic `
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 105 `/></head>
<body class="wp-singular page-template page-template-template-dynamic `

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2415 ms._

**Scoring:** 3 violations · 32 passes · critical 0 · serious 1 · moderate 2 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
3. **region** (medium) — All page content should be contained by landmarks

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `h1 > .heading__main`
- `.how-we-do__intro > .heading--primary.heading > .heading__main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.header__nav`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.team-grid__intro`
- `.is-active`
- `.grid__col--sm-6.grid__col--md-4.team-grid__member:nth-child(1) > .person-card.team-grid__member-card > .person-card__content`
- `.grid__col--sm-6.grid__col--md-4.team-grid__member:nth-child(2) > .person-card.team-grid__member-card > .person-card__content`
- `.grid__col--sm-6.grid__col--md-4.team-grid__member:nth-child(3) > .person-card.team-grid__member-card > .person-card__figure > .person-card__image--workmode.person-card__image.image--background > .image__inner > img`
- … and 35 more nodes

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 10 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 7 nodes

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2426 ms._

**Capture summary:** 1 console events · 0 mixed-content requests · 14 network requests · 188.7 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| font | 3 | 57.6 KB |
| script | 4 | 45.6 KB |
| stylesheet | 2 | 34.2 KB |
| document | 2 | 27.7 KB |
| image | 1 | 18.1 KB |
| other | 1 | 5.5 KB |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 2 requests, 13.2 KB
- https://fast.fonts.net — 2 requests, 0 B

**Slowest requests (top 5):**
- https://play.ee/team (document) — 399 ms, 0 B
- https://play.ee/team/ (document) — 357 ms, 27.7 KB
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/fonts/1c0243aa-c535-4d42-ac53-d6f0f74a1412.bd94708352cbb3b4863c.woff2 (font) — 139 ms, 19.3 KB
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/fonts/fc2fa85e-cd2d-4004-930a-8adad6c60317.3bd2a5f3705d9fb438c5.woff2 (font) — 139 ms, 19.3 KB
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/fonts/f389f79b-6013-4448-aa6a-b6fd235eab80.b91a05bafb09e626383a.woff2 (font) — 138 ms, 19.0 KB

### Findings

#### Console events
- [warning] Couldn't load preload assets:  

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2426 ms._

**Document:**
- Lang: en
- Title: Expert full-stack development & technical support
- Canonical: https://play.ee/team/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 171666

**Meta tags:**
- Description: Meet our team of amazing people! At your service is our expert full-stack development team and an ever-ready technical support.
- Robots: follow, index, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time)
- Twitter tags: 3
- hreflang:
  - en → https://play.ee/team/
  - et → https://play.ee/et/meeskond/
  - x-default → https://play.ee/team/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×21, h3 ×8, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: meet our team of
        
                    individual masters
  - h2: Siim Sups
  - h2: Hiie-Helen Raju
  - h2: Ardo Gärtner
  - h2: Pärt Erikson
  - h2: Juhan Valge
  - h2: Vladislav Stafinjak
  - h2: Lauri Uue
  - h2: Kuldar Jürma
  - h2: Raiko Raidma
  - h2: Sander Orav
  - h2: Andres Kalle
  - h2: Ivo Klaas
  - h2: Timo Soiunen
  - h2: Tanel Marran
  - h2: Hannes Juurma
  - h2: Raimond Kurm
  - h2: Janeli Kurvits
  - h2: Marianne Võime
  - h2: we are part of
        
                    play & nope alliance

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 30 total — 3 defer, 0 async, 1 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/runtime.30d3b226dcf211e512b1.min.js
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js (defer)

**Stylesheets:** 1 external, 3 inline (9.6 KB)

**Images:** 45 total — **0 without alt**, **45 without width/height**, 45 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | wordpress support service / wordpress tu | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | vladislav | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 40 anchors — 23 external, 1 preconnect, 0 preload.

Vague repeated link text:
- "view our instagram feed" ×3
- "visit our facebook page" ×3
- "visit our linkedin page" ×3
- "eng" ×3
- "est" ×3
- "styleguide" ×2
- "privacy policy" ×2
- "nope design agency" ×2

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **45 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 3 pass · 0 warn · 0 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Response compressed (gzip / brotli) | ✓ pass | Document response is compressed with gzip. |
| Images lazy-loaded | – n/a | No raster <img> elements found (30 SVGs, 15 placeholders excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (30 SVGs, 15 placeholders excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (30 SVGs, 15 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WP Rocket 3.23.3.3`
- Response compressed (gzip / brotli):
  - `content-encoding: gzip`
  - `decoded body: 173514 bytes`
  - `ratio: 0.163`

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

## Security basics
_Captured in 0 ms._

**Verdict: FAILED**

> These are high-level hygiene checks on HTTP headers, TLS, cookies and a few well-known exposed paths. PASS means the basics are in place. It does **not** mean the site is secure: application logic, authentication, plugins, server configuration and dependencies are not tested here. Treat FAILED as a must-fix and PASS as a starting point, not a certificate.

| Check | Tier | Status | Detail |
| --- | --- | --- | --- |
| HTTP redirects to HTTPS | basic | fail | Plain HTTP does not redirect to HTTPS. |
| Strict-Transport-Security | basic | fail | Strict-Transport-Security header is missing. |
| Clickjacking protection | basic | pass | Framing is restricted. |
| X-Content-Type-Options | basic | fail | X-Content-Type-Options header is missing. |
| Cookies Secure + HttpOnly | basic | n/a | The document response sets no cookies. |
| No mixed content | basic | pass | No http:// subresources were loaded. |
| CORS | basic | pass | No wildcard CORS origin. |
| Technology disclosure | basic | warn | Response headers disclose server technology. |
| TLS certificate and protocol | basic | pass | Valid certificate and modern TLS protocol. |
| No exposed sensitive files | basic | pass | None of 6 probed sensitive paths returned real content. |
| Forms do not post to HTTP | basic | n/a | No forms on the page. |
| Content-Security-Policy present | advanced | pass | Content-Security-Policy header is set. |
| CSP is strict | advanced | fail | CSP has 2 issues: default-src missing; object-src is not 'none'. |
| HSTS preload | advanced | fail | Strict-Transport-Security header is missing. |
| Referrer-Policy | advanced | fail | Referrer-Policy header is missing. |
| Permissions-Policy | advanced | fail | Permissions-Policy header is missing. |
| Cross-Origin-Opener-Policy | advanced | fail | Cross-Origin-Opener-Policy header is missing. |
| Cross-Origin-Resource-Policy | advanced | fail | Cross-Origin-Resource-Policy header is missing. |
| Cookies SameSite | advanced | n/a | The document response sets no cookies. |
| Subresource Integrity | advanced | warn | 2 of 2 cross-origin scripts lack an integrity attribute. |
| SPF + DMARC DNS records | advanced | pass | SPF and DMARC records are present. |
| WP version not disclosed | wordpress | pass | No WordPress version found in generator meta or core asset URLs. |
| xmlrpc.php disabled | wordpress | fail | xmlrpc.php accepts POST requests (brute-force / pingback vector). |
| User enumeration blocked | wordpress | pass | No username leak across 3 enumeration probes. |
| readme.html removed | wordpress | pass | readme.html is not served. |
| Directory listing off | wordpress | pass | Uploads directory does not return an index page. |
| debug.log not public | wordpress | pass | debug.log is not served. |
| No config backups or installer | wordpress | warn | Installer /wp-admin/install.php is reachable. Harmless while the site is installed, but it becomes an open takeover path if the database is ever unreachable — block it in .htaccess. |
| Login not on default path | wordpress | warn | Login form is served on the default /wp-login.php path. |

---

# Page 3 of 5 — https://play.ee/privacy-policy

Run: 2026-09-24T09:54:59.202Z

## Audit Coverage
**94%** of audit sources returned data.

Missing or failed sources:
- PageSpeed Insights (desktop): PSI HTTP 429

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 10920 ms (mobile + desktop in parallel)._
_Desktop strategy errored (PSI HTTP 429); mobile data duplicated for both._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | 93 | 93 |
| Accessibility | 87 | 87 |
| Best Practices | 100 | 100 |
| SEO | 100 | 100 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | 2.8 s | 2.8 s |
| CLS | 0.002 | 0.002 |
| TBT | 0 ms | 0 ms |
| FCP | 2.33 s | 2.33 s |
| Speed Index | 2.96 s | 2.96 s |
| TTFB | 3 ms | 3 ms |

### Priority fixes
1. **largest-contentful-paint** (low) — 2.8 s
2. **first-contentful-paint** (medium) — 2.3 s
3. **document-latency-insight** (high) — Est savings of 690 ms
4. **network-dependency-tree-insight** (high)
5. **render-blocking-insight** (high) — Est savings of 1,230 ms

### Findings (mobile)

#### Unused JavaScript
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js — 23 KB wasted

#### Layout-shift sources
- div.main > footer.footer > h2.heading > span.heading__main — shift 0.001
- div.main > footer.footer > div.footer__bottom > ul.list — shift 0.001

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `largest-contentful-paint` (performance, score 0.83, weight 25) — Largest Contentful Paint — 2.8 s
- `heading-order` (accessibility, score 0.00, weight 3) — Heading elements are not in a sequentially-descending order
- `landmark-one-main` (accessibility, score 0.00, weight 3) — Document does not have a main landmark.
- `first-contentful-paint` (performance, score 0.73, weight 10) — First Contentful Paint — 2.3 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 2093 ms._

**Transport:**
- Final URL: https://play.ee/privacy-policy/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://play.ee/privacy-policy does not redirect to HTTPS (target: http://play.ee/privacy-policy/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 15 Sep 2026 08:38:51 GMT
- expires: Thu, 24 Sep 2026 09:54:59 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 21747
- Decoded body: 78.9 KB
- Compression ratio: 0.269

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://play.ee/privacy-policy does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy weak** (high) — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (weak, high) `frame-ancestors 'self';` — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`
- X-Powered-By: `PHP/8.3.33`

#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 21747
content-security-policy: frame-ancestors 'self';
content-type: text/html; charset=UTF-8
date: Thu, 24 Sep 2026 09:54:59 GMT
expires: Thu, 24 Sep 2026 09:54:59 GMT
keep-alive: timeout=5, max=98
last-modified: Tue, 15 Sep 2026 08:38:51 GMT
server: Apache
vary: Accept-Encoding
x-frame-options: SAMEORIGIN
x-powered-by: PHP/8.3.33
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1307 ms._

**Scoring:** 7 errors · 0 warnings · 23 cosmetic (suppressed)

> **Validator truncated at line 100** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.

### Priority fixes
1. **Parser recovery at line 100** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad start tag in “iframe” in “noscript” in “head”.** (medium) — x1, first at line 97
3. **Stray end tag “noscript”.** (medium) — x1, first at line 97
4. **Attribute “name” not allowed on element “meta” at this point.** (medium) — x1, first at line 99
5. **Element “meta” is missing one or more of the following attributes: “itemprop”, “property”.** (medium) — x1, first at line 99

### Issue groups
- (×1) [error] Bad start tag in “iframe” in “noscript” in “head”. — first at line 97 `<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-K3P64XMJ"`
- (×1) [error] Stray end tag “noscript”. — first at line 97 `></iframe></noscript><!-- E`
- (×1) [error] Attribute “name” not allowed on element “meta” at this point. — first at line 99 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Element “meta” is missing one or more of the following attributes: “itemprop”, “property”. — first at line 99 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Stray end tag “head”. — first at line 99 `esktop" /></head>
<body`
- (×1) [error] Start tag “body” seen but an element of the same type was already open. — first at line 100 `/></head>
<body class="privacy-policy wp-singular page-template-default page pag`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 100 `/></head>
<body class="privacy-policy wp-singular page-template-default page pag`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2069 ms._

**Scoring:** 4 violations · 25 passes · critical 0 · serious 1 · moderate 3 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **heading-order** (medium) — Heading levels should only increase by one
3. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
4. **region** (medium) — All page content should be contained by landmarks

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `h1 > .heading__main`
- `.button`

#### `heading-order` (moderate)
[Heading levels should only increase by one](https://dequeuniversity.com/rules/axe/4.11/heading-order?application=playwright)
- `h4:nth-child(9)`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.header__nav`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `h1`
- `.content__body`
- `.sticky-footer__social > .list__item:nth-child(1) > .social__link > .social__label`
- `.sticky-footer__social > .list__item:nth-child(2) > .social__link > .social__label`
- `.sticky-footer__social > .list__item:nth-child(3) > .social__link > .social__label`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 8 nodes

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2079 ms._

**Capture summary:** 1 console events · 0 mixed-content requests · 15 network requests · 172.4 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| font | 3 | 57.6 KB |
| script | 5 | 53.5 KB |
| stylesheet | 2 | 34.2 KB |
| document | 2 | 21.2 KB |
| other | 1 | 5.5 KB |
| image | 1 | 338 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 2 requests, 13.2 KB
- https://fast.fonts.net — 2 requests, 0 B

**Slowest requests (top 5):**
- https://play.ee/privacy-policy/ (document) — 465 ms, 21.2 KB
- https://play.ee/privacy-policy (document) — 407 ms, 0 B
- https://fast.fonts.net/t/1.css?apiType=css&projectid=d924b670-8ecc-46fd-9fff-80fd9989d037 (stylesheet) — 28 ms, 0 B
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (script) — 27 ms, 3.0 KB
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (script) — 26 ms, 10.1 KB

### Findings

#### Console events
- [warning] Couldn't load preload assets:  

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2079 ms._

**Document:**
- Lang: en
- Title: Privacy Policy - gotoAndPlay
- Canonical: https://play.ee/privacy-policy/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 80901

**Meta tags:**
- Description: At gotoAndPlay, we take information security seriously. From our privacy policy you can learn about the data we gather at gotoAndPlay regarding personal data,
- Robots: follow, index, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time)
- Twitter tags: 3
- hreflang:
  - en → https://play.ee/privacy-policy/
  - et → https://play.ee/et/privaatsustingimused/
  - x-default → https://play.ee/privacy-policy/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×0, h4 ×3, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: about our
        
                    privacy policy
  - h4: About the cookies used on our website
  - h4: Manage cookie preferences
  - h4: Server logs
  - h2: ready when you are
            
            <span style="unicode-bidi:bidi-overr
- Skips:
  - h1 → h4 after "about our
        
                    privacy policy"

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 28 total — 3 defer, 1 async, 1 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/runtime.30d3b226dcf211e512b1.min.js
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js (defer)
- https://play.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)

**Stylesheets:** 1 external, 3 inline (9.6 KB)

**Images:** 1 total — **0 without alt**, **1 without width/height**, 1 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 29 anchors — 14 external, 1 preconnect, 0 preload.

Vague repeated link text:
- "view our instagram feed" ×3
- "visit our facebook page" ×3
- "visit our linkedin page" ×3
- "eng" ×3
- "est" ×3
- "styleguide" ×2
- "privacy policy" ×2
- "http://play.ee" ×2

### Priority fixes
1. **Heading level skips** (medium) — h1→h4 after "about our
        
                    p"
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **1 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 3 pass · 0 warn · 0 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Response compressed (gzip / brotli) | ✓ pass | Document response is compressed with gzip. |
| Images lazy-loaded | – n/a | No raster <img> elements found (1 placeholder excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (1 placeholder excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (1 placeholder excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WP Rocket 3.23.3.3`
- Response compressed (gzip / brotli):
  - `content-encoding: gzip`
  - `decoded body: 80767 bytes`
  - `ratio: 0.269`

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

## Security basics
_Captured in 0 ms._

**Verdict: FAILED**

> These are high-level hygiene checks on HTTP headers, TLS, cookies and a few well-known exposed paths. PASS means the basics are in place. It does **not** mean the site is secure: application logic, authentication, plugins, server configuration and dependencies are not tested here. Treat FAILED as a must-fix and PASS as a starting point, not a certificate.

| Check | Tier | Status | Detail |
| --- | --- | --- | --- |
| HTTP redirects to HTTPS | basic | fail | Plain HTTP does not redirect to HTTPS. |
| Strict-Transport-Security | basic | fail | Strict-Transport-Security header is missing. |
| Clickjacking protection | basic | pass | Framing is restricted. |
| X-Content-Type-Options | basic | fail | X-Content-Type-Options header is missing. |
| Cookies Secure + HttpOnly | basic | n/a | The document response sets no cookies. |
| No mixed content | basic | pass | No http:// subresources were loaded. |
| CORS | basic | pass | No wildcard CORS origin. |
| Technology disclosure | basic | warn | Response headers disclose server technology. |
| TLS certificate and protocol | basic | pass | Valid certificate and modern TLS protocol. |
| No exposed sensitive files | basic | pass | None of 6 probed sensitive paths returned real content. |
| Forms do not post to HTTP | basic | n/a | No forms on the page. |
| Content-Security-Policy present | advanced | pass | Content-Security-Policy header is set. |
| CSP is strict | advanced | fail | CSP has 2 issues: default-src missing; object-src is not 'none'. |
| HSTS preload | advanced | fail | Strict-Transport-Security header is missing. |
| Referrer-Policy | advanced | fail | Referrer-Policy header is missing. |
| Permissions-Policy | advanced | fail | Permissions-Policy header is missing. |
| Cross-Origin-Opener-Policy | advanced | fail | Cross-Origin-Opener-Policy header is missing. |
| Cross-Origin-Resource-Policy | advanced | fail | Cross-Origin-Resource-Policy header is missing. |
| Cookies SameSite | advanced | n/a | The document response sets no cookies. |
| Subresource Integrity | advanced | warn | 2 of 2 cross-origin scripts lack an integrity attribute. |
| SPF + DMARC DNS records | advanced | pass | SPF and DMARC records are present. |
| WP version not disclosed | wordpress | pass | No WordPress version found in generator meta or core asset URLs. |
| xmlrpc.php disabled | wordpress | fail | xmlrpc.php accepts POST requests (brute-force / pingback vector). |
| User enumeration blocked | wordpress | pass | No username leak across 3 enumeration probes. |
| readme.html removed | wordpress | pass | readme.html is not served. |
| Directory listing off | wordpress | pass | Uploads directory does not return an index page. |
| debug.log not public | wordpress | pass | debug.log is not served. |
| No config backups or installer | wordpress | warn | Installer /wp-admin/install.php is reachable. Harmless while the site is installed, but it becomes an open takeover path if the database is ever unreachable — block it in .htaccess. |
| Login not on default path | wordpress | warn | Login form is served on the default /wp-login.php path. |

---

# Page 4 of 5 — https://play.ee/et/meeskond

Run: 2026-09-24T09:55:00.892Z

## Audit Coverage
**94%** of audit sources returned data.

Missing or failed sources:
- PageSpeed Insights (mobile): PSI HTTP 429

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 14669 ms (mobile + desktop in parallel)._
_Mobile strategy errored (PSI HTTP 429); desktop data duplicated for both._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | 100 | 100 |
| Accessibility | 93 | 93 |
| Best Practices | 100 | 100 |
| SEO | 100 | 100 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | 0.6 s | 0.6 s |
| CLS | 0.003 | 0.003 |
| TBT | 0 ms | 0 ms |
| FCP | 586 ms | 586 ms |
| Speed Index | 748 ms | 748 ms |
| TTFB | 37 ms | 37 ms |

### Priority fixes
1. **document-latency-insight** (high) — Est savings of 440 ms
2. **network-dependency-tree-insight** (high)
3. **render-blocking-insight** (high) — Est savings of 250 ms
4. **unused-css-rules** (high) — Est savings of 30 KiB
5. **unused-javascript** (medium) — Est savings of 23 KiB

### Findings (mobile)

#### Unused JavaScript
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js — 23 KB wasted

#### Layout-shift sources
- div.main > footer.footer > h2.heading > span.heading__main — shift 0.003
- div.main > footer.footer > div.footer__bottom > ul.list — shift 0.000
- div.main > footer.footer > div.footer__bottom > ul.list — shift 0.000

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `landmark-one-main` (accessibility, score 0.00, weight 3) — Document does not have a main landmark.
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 2072 ms._

**Transport:**
- Final URL: https://play.ee/et/meeskond/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://play.ee/et/meeskond does not redirect to HTTPS (target: http://play.ee/et/meeskond/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 15 Sep 2026 08:42:10 GMT
- expires: Thu, 24 Sep 2026 09:55:02 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 28109
- Decoded body: 158.6 KB
- Compression ratio: 0.173

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://play.ee/et/meeskond does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy weak** (high) — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (weak, high) `frame-ancestors 'self';` — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`
- X-Powered-By: `PHP/8.3.33`

#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 28109
content-security-policy: frame-ancestors 'self';
content-type: text/html; charset=UTF-8
date: Thu, 24 Sep 2026 09:55:02 GMT
expires: Thu, 24 Sep 2026 09:55:02 GMT
keep-alive: timeout=5, max=100
last-modified: Tue, 15 Sep 2026 08:42:10 GMT
server: Apache
upgrade: h2,h2c
vary: Accept-Encoding
x-frame-options: SAMEORIGIN
x-powered-by: PHP/8.3.33
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1513 ms._

**Scoring:** 8 errors · 0 warnings · 23 cosmetic (suppressed)

> **Validator truncated at line 102** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.

### Priority fixes
1. **Parser recovery at line 102** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad value “” for attribute “href” on element “link”: Must be non-empty.** (medium) — x1, first at line 51
3. **Bad start tag in “iframe” in “noscript” in “head”.** (medium) — x1, first at line 99
4. **Stray end tag “noscript”.** (medium) — x1, first at line 99
5. **Attribute “name” not allowed on element “meta” at this point.** (medium) — x1, first at line 101

### Issue groups
- (×1) [error] Bad value “” for attribute “href” on element “link”: Must be non-empty. — first at line 51 `refetch">
<link data-rocket-prefetch href="" rel="dns-prefetch">
<meta`
- (×1) [error] Bad start tag in “iframe” in “noscript” in “head”. — first at line 99 `<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-K3P64XMJ"`
- (×1) [error] Stray end tag “noscript”. — first at line 99 `></iframe></noscript><!-- E`
- (×1) [error] Attribute “name” not allowed on element “meta” at this point. — first at line 101 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Element “meta” is missing one or more of the following attributes: “itemprop”, “property”. — first at line 101 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Stray end tag “head”. — first at line 101 `esktop" /></head>
<body`
- (×1) [error] Start tag “body” seen but an element of the same type was already open. — first at line 102 `/></head>
<body class="wp-singular page-template page-template-template-dynamic `
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 102 `/></head>
<body class="wp-singular page-template page-template-template-dynamic `

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2167 ms._

**Scoring:** 3 violations · 32 passes · critical 0 · serious 1 · moderate 2 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
3. **region** (medium) — All page content should be contained by landmarks

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `h1 > .heading__main`
- `.how-we-do__intro > .heading--primary.heading > .heading__main`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.header__nav`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.team-grid__intro`
- `.is-active`
- `.grid__col--sm-6.grid__col--md-4.team-grid__member:nth-child(1) > .person-card.team-grid__member-card > .person-card__content`
- `.grid__col--sm-6.grid__col--md-4.team-grid__member:nth-child(2) > .person-card.team-grid__member-card > .person-card__content`
- `.grid__col--sm-6.grid__col--md-4.team-grid__member:nth-child(3) > .person-card.team-grid__member-card > .person-card__figure > .person-card__image--workmode.person-card__image.image--background > .image__inner > img`
- … and 28 more nodes

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 12 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2179 ms._

**Capture summary:** 1 console events · 0 mixed-content requests · 14 network requests · 188.4 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| font | 3 | 57.6 KB |
| script | 4 | 45.6 KB |
| stylesheet | 2 | 34.2 KB |
| document | 2 | 27.5 KB |
| image | 1 | 18.1 KB |
| other | 1 | 5.5 KB |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 2 requests, 13.2 KB
- https://fast.fonts.net — 2 requests, 0 B

**Slowest requests (top 5):**
- https://play.ee/et/meeskond (document) — 528 ms, 0 B
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (script) — 41 ms, 3.0 KB
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (script) — 41 ms, 10.1 KB
- https://fast.fonts.net/t/1.css?apiType=css&projectid=d924b670-8ecc-46fd-9fff-80fd9989d037 (stylesheet) — 32 ms, 0 B
- https://fast.fonts.net/t/1.css?apiType=css&projectid=d924b670-8ecc-46fd-9fff-80fd9989d037 (xhr) — 24 ms, 0 B

### Findings

#### Console events
- [warning] Couldn't load preload assets:  

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2179 ms._

**Document:**
- Lang: et
- Title: Usaldusväärne full-stack arendus ja tehniline tugi
- Canonical: https://play.ee/et/meeskond/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 160414

**Meta tags:**
- Description: Siin on meie tragi punt ägedaid inimesi. Sinu päralt on full-stack arendus (nii front-end kui back-end arendus) ning alati valvel tehniline tugi.
- Robots: follow, index, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time)
- Twitter tags: 3
- hreflang:
  - en → https://play.ee/team/
  - et → https://play.ee/et/meeskond/
  - x-default → https://play.ee/team/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×21, h3 ×8, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: meie meeskonna
        
                    individuaalsed meistrid
  - h2: Siim Sups
  - h2: Hiie-Helen Raju
  - h2: Ardo Gärtner
  - h2: Pärt Erikson
  - h2: Juhan Valge
  - h2: Vladislav Stafinjak
  - h2: Lauri Uue
  - h2: Kuldar Jürma
  - h2: Raiko Raidma
  - h2: Sander Orav
  - h2: Andres Kalle
  - h2: Ivo Klaas
  - h2: Timo Soiunen
  - h2: Tanel Marran
  - h2: Hannes Juurma
  - h2: Raimond Kurm
  - h2: Marianne Võime
  - h2: Janeli Kurvits
  - h2: Me oleme osa
        
                    play & nope alliance'st

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 30 total — 3 defer, 0 async, 1 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/runtime.30d3b226dcf211e512b1.min.js
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js (defer)

**Stylesheets:** 1 external, 3 inline (9.6 KB)

**Images:** 45 total — **0 without alt**, **45 without width/height**, 45 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | wordpress support service / wordpress tu | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | vladislav | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 40 anchors — 23 external, 1 preconnect, 0 preload.

Vague repeated link text:
- "vaata meie instagrami" ×3
- "külasta meie facebooki lehte" ×3
- "külasta meie linkedin lehte" ×3
- "eng" ×3
- "est" ×3
- "styleguide" ×2
- "privaatsustingimused" ×2
- "osa play & nope alliance'st" ×2

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **45 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **Vague link text repeated** (medium) — "vaata meie instagrami" ×3

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 3 pass · 0 warn · 0 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Response compressed (gzip / brotli) | ✓ pass | Document response is compressed with gzip. |
| Images lazy-loaded | – n/a | No raster <img> elements found (26 SVGs, 19 placeholders excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (26 SVGs, 19 placeholders excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (26 SVGs, 19 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WP Rocket 3.23.3.3`
- Response compressed (gzip / brotli):
  - `content-encoding: gzip`
  - `decoded body: 162442 bytes`
  - `ratio: 0.173`

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

## Security basics
_Captured in 0 ms._

**Verdict: FAILED**

> These are high-level hygiene checks on HTTP headers, TLS, cookies and a few well-known exposed paths. PASS means the basics are in place. It does **not** mean the site is secure: application logic, authentication, plugins, server configuration and dependencies are not tested here. Treat FAILED as a must-fix and PASS as a starting point, not a certificate.

| Check | Tier | Status | Detail |
| --- | --- | --- | --- |
| HTTP redirects to HTTPS | basic | fail | Plain HTTP does not redirect to HTTPS. |
| Strict-Transport-Security | basic | fail | Strict-Transport-Security header is missing. |
| Clickjacking protection | basic | pass | Framing is restricted. |
| X-Content-Type-Options | basic | fail | X-Content-Type-Options header is missing. |
| Cookies Secure + HttpOnly | basic | n/a | The document response sets no cookies. |
| No mixed content | basic | pass | No http:// subresources were loaded. |
| CORS | basic | pass | No wildcard CORS origin. |
| Technology disclosure | basic | warn | Response headers disclose server technology. |
| TLS certificate and protocol | basic | pass | Valid certificate and modern TLS protocol. |
| No exposed sensitive files | basic | pass | None of 6 probed sensitive paths returned real content. |
| Forms do not post to HTTP | basic | n/a | No forms on the page. |
| Content-Security-Policy present | advanced | pass | Content-Security-Policy header is set. |
| CSP is strict | advanced | fail | CSP has 2 issues: default-src missing; object-src is not 'none'. |
| HSTS preload | advanced | fail | Strict-Transport-Security header is missing. |
| Referrer-Policy | advanced | fail | Referrer-Policy header is missing. |
| Permissions-Policy | advanced | fail | Permissions-Policy header is missing. |
| Cross-Origin-Opener-Policy | advanced | fail | Cross-Origin-Opener-Policy header is missing. |
| Cross-Origin-Resource-Policy | advanced | fail | Cross-Origin-Resource-Policy header is missing. |
| Cookies SameSite | advanced | n/a | The document response sets no cookies. |
| Subresource Integrity | advanced | warn | 2 of 2 cross-origin scripts lack an integrity attribute. |
| SPF + DMARC DNS records | advanced | pass | SPF and DMARC records are present. |
| WP version not disclosed | wordpress | pass | No WordPress version found in generator meta or core asset URLs. |
| xmlrpc.php disabled | wordpress | fail | xmlrpc.php accepts POST requests (brute-force / pingback vector). |
| User enumeration blocked | wordpress | pass | No username leak across 3 enumeration probes. |
| readme.html removed | wordpress | pass | readme.html is not served. |
| Directory listing off | wordpress | pass | Uploads directory does not return an index page. |
| debug.log not public | wordpress | pass | debug.log is not served. |
| No config backups or installer | wordpress | warn | Installer /wp-admin/install.php is reachable. Harmless while the site is installed, but it becomes an open takeover path if the database is ever unreachable — block it in .htaccess. |
| Login not on default path | wordpress | warn | Login form is served on the default /wp-login.php path. |

---

# Page 5 of 5 — https://play.ee/wordpress-support-service

Run: 2026-09-24T09:55:16.366Z

## Audit Coverage
**88%** of audit sources returned data.

Missing or failed sources:
- PageSpeed Insights: mobile: PSI HTTP 429; desktop: PSI HTTP 429

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights

_Error after 226 ms: mobile: PSI HTTP 429; desktop: PSI HTTP 429_

## Security Headers & HTTP
_Captured in 1719 ms._

**Transport:**
- Final URL: https://play.ee/wordpress-support-service/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://play.ee/wordpress-support-service does not redirect to HTTPS (target: http://play.ee/wordpress-support-service/)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 15 Sep 2026 08:37:43 GMT
- expires: Thu, 24 Sep 2026 09:55:17 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 31016
- Decoded body: 184.1 KB
- Compression ratio: 0.165

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://play.ee/wordpress-support-service does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy weak** (high) — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (weak, high) `frame-ancestors 'self';` — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`
- X-Powered-By: `PHP/8.3.33`

#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 31016
content-security-policy: frame-ancestors 'self';
content-type: text/html; charset=UTF-8
date: Thu, 24 Sep 2026 09:55:17 GMT
expires: Thu, 24 Sep 2026 09:55:17 GMT
keep-alive: timeout=5, max=99
last-modified: Tue, 15 Sep 2026 08:37:43 GMT
server: Apache
vary: Accept-Encoding
x-frame-options: SAMEORIGIN
x-powered-by: PHP/8.3.33
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1221 ms._

**Scoring:** 7 errors · 0 warnings · 30 cosmetic (suppressed)

> **Validator truncated at line 107** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.

### Priority fixes
1. **Parser recovery at line 107** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad start tag in “iframe” in “noscript” in “head”.** (medium) — x1, first at line 104
3. **Stray end tag “noscript”.** (medium) — x1, first at line 104
4. **Attribute “name” not allowed on element “meta” at this point.** (medium) — x1, first at line 106
5. **Element “meta” is missing one or more of the following attributes: “itemprop”, “property”.** (medium) — x1, first at line 106

### Issue groups
- (×1) [error] Bad start tag in “iframe” in “noscript” in “head”. — first at line 104 `<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-K3P64XMJ"`
- (×1) [error] Stray end tag “noscript”. — first at line 104 `></iframe></noscript><!-- E`
- (×1) [error] Attribute “name” not allowed on element “meta” at this point. — first at line 106 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Element “meta” is missing one or more of the following attributes: “itemprop”, “property”. — first at line 106 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Stray end tag “head”. — first at line 106 `esktop" /></head>
<body`
- (×1) [error] Start tag “body” seen but an element of the same type was already open. — first at line 107 `/></head>
<body class="wp-singular page-template page-template-template-dynamic `
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 107 `/></head>
<body class="wp-singular page-template page-template-template-dynamic `

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2473 ms._

**Scoring:** 4 violations · 32 passes · critical 0 · serious 2 · moderate 2 · minor 0

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **link-name** (high) — Links must have discernible text
3. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
4. **region** (medium) — All page content should be contained by landmarks

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `.button--tertiary > .button__inner > .button__text`
- `.grid__col--md-4.capabilities__grid-col.grid__col--sm-6:nth-child(1) > .heading--h5.capabilities__heading.h5 > .heading__small`
- `.grid__col--md-4.capabilities__grid-col.grid__col--sm-6:nth-child(2) > .heading--h5.capabilities__heading.h5 > .heading__small`
- `.grid__col--md-4.capabilities__grid-col.grid__col--sm-6:nth-child(3) > .heading--h5.capabilities__heading.h5 > .heading__small`
- `.grid__col--md-4.capabilities__grid-col.grid__col--sm-6:nth-child(4) > .heading--h5.capabilities__heading.h5 > .heading__small`
- … and 10 more nodes

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.header__nav`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.logo-grid__row.js-in-viewport:nth-child(1) > .logo-grid__item:nth-child(1) > .logo-grid__link[href=""][rel="noopener"]`
- `.logo-grid__row.js-in-viewport:nth-child(1) > .logo-grid__item:nth-child(2) > .logo-grid__link[href=""][rel="noopener"]`
- `.logo-grid__row.js-in-viewport:nth-child(1) > .logo-grid__item:nth-child(3) > .logo-grid__link[href=""][rel="noopener"]`
- `.logo-grid__row.js-in-viewport:nth-child(2) > .logo-grid__item:nth-child(1) > .logo-grid__link[href=""][rel="noopener"]`
- `.logo-grid__row.js-in-viewport:nth-child(2) > .logo-grid__item:nth-child(2) > .logo-grid__link[href=""][rel="noopener"]`
- … and 4 more nodes

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.contact-hero__intro > h1`
- `.intro__content > p:nth-child(2)`
- `p:nth-child(3)`
- `.button--tertiary`
- `canvas`
- … and 95 more nodes

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 15 nodes

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2489 ms._

**Capture summary:** 1 console events · 0 mixed-content requests · 25 network requests · 201.9 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| font | 3 | 57.6 KB |
| script | 5 | 53.5 KB |
| stylesheet | 2 | 34.2 KB |
| document | 2 | 30.3 KB |
| image | 11 | 20.8 KB |
| other | 1 | 5.5 KB |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 2 requests, 13.2 KB
- https://fast.fonts.net — 2 requests, 0 B

**Slowest requests (top 5):**
- https://play.ee/wordpress-support-service (document) — 411 ms, 0 B
- https://play.ee/wordpress-support-service/ (document) — 81 ms, 30.3 KB
- https://fast.fonts.net/t/1.css?apiType=css&projectid=d924b670-8ecc-46fd-9fff-80fd9989d037 (stylesheet) — 38 ms, 0 B
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (script) — 29 ms, 3.0 KB
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (script) — 28 ms, 10.1 KB

### Findings

#### Console events
- [warning] Couldn't load preload assets:  

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2489 ms._

**Document:**
- Lang: en
- Title: WordPress support service
- Canonical: https://play.ee/wordpress-support-service/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 187229

**Meta tags:**
- Description: From ongoing WordPress support to health monitoring and expert fixes, we take care of your website so you can spend more time building your business.
- Robots: follow, index, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 13 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time, og:image, og:image:secure_url, og:image:width, og:image:height, og:image:alt, og:image:type)
- Twitter tags: 4
- hreflang:
  - en → https://play.ee/wordpress-support-service/
  - et → https://play.ee/et/tugiteenus/
  - x-default → https://play.ee/wordpress-support-service/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×2, h2 ×16, h3 ×14, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Your worry-free
        
                    WordPress website
  - h2: Why choose our
        
                    WordPress support service
  - h3: #1
        
                    peace of mind
  - h3: #2
        
                    security first
  - h3: #3
        
                    expert team on-call
  - h3: #4
        
                    performance wins
  - h3: #5
        
                    save money
  - h3: #6
        
                    monthly health reports
  - h3: #7
        
                    collaboration
  - h3: #8
        
                    extensive network
  - h3: #9
        
                    top notch tools
  - h2: service by professionals who
        
                    build websites for a l
  - h2: customizable & transparent
        
                    Pricing
  - h2: <Basic/>
  - h2: <Advanced/>
  - h2: <Pro/>
  - h2: five-step
        
                    onboarding process
  - h1: additional services
        
                    to upgrade your online presence
  - h2: UX/UI audit
  - h2: WCAG audit

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 27 total — 3 defer, 1 async, 1 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/runtime.30d3b226dcf211e512b1.min.js
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js (defer)
- https://play.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)

**Stylesheets:** 1 external, 3 inline (9.6 KB)

**Images:** 31 total — **0 without alt**, **31 without width/height**, 31 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | Expert WordPress support service | _n/a_ | _n/a_ | ✗ |
| p-content/themes/gotoandplay/inc/theme/img/line-1-mobile.svg | line-1 | _n/a_ | _n/a_ | ✗ |
| ay.ee/wp-content/themes/gotoandplay/inc/theme/img/line-1.svg | line-1 | _n/a_ | _n/a_ | ✗ |
| p-content/themes/gotoandplay/inc/theme/img/line-2-mobile.svg | line-2 | _n/a_ | _n/a_ | ✗ |
| ay.ee/wp-content/themes/gotoandplay/inc/theme/img/line-2.svg | line-2 | _n/a_ | _n/a_ | ✗ |
| p-content/themes/gotoandplay/inc/theme/img/line-3-mobile.svg | line-3 | _n/a_ | _n/a_ | ✗ |
| ay.ee/wp-content/themes/gotoandplay/inc/theme/img/line-3.svg | line-3 | _n/a_ | _n/a_ | ✗ |
| p-content/themes/gotoandplay/inc/theme/img/line-4-mobile.svg | line-4 | _n/a_ | _n/a_ | ✗ |
| ay.ee/wp-content/themes/gotoandplay/inc/theme/img/line-4.svg | line-4 | _n/a_ | _n/a_ | ✗ |
| p-content/themes/gotoandplay/inc/theme/img/line-5-mobile.svg | line-5 | _n/a_ | _n/a_ | ✗ |
| ay.ee/wp-content/themes/gotoandplay/inc/theme/img/line-5.svg | line-5 | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 57 anchors — 17 external, 2 preconnect, 0 preload.

Vague repeated link text:
- "get in touch" ×14
- "view our instagram feed" ×3
- "visit our facebook page" ×3
- "visit our linkedin page" ×3
- "eng" ×3
- "est" ×3
- "styleguide" ×2
- "privacy policy" ×2

### Priority fixes
1. **Document has 2 <h1> elements** (medium) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **31 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 3 pass · 0 warn · 0 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Response compressed (gzip / brotli) | ✓ pass | Document response is compressed with gzip. |
| Images lazy-loaded | – n/a | No raster <img> elements found (24 SVGs, 7 placeholders excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (24 SVGs, 7 placeholders excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (24 SVGs, 7 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WP Rocket 3.23.3.3`
- Response compressed (gzip / brotli):
  - `content-encoding: gzip`
  - `decoded body: 188490 bytes`
  - `ratio: 0.165`

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

## Security basics
_Captured in 0 ms._

**Verdict: FAILED**

> These are high-level hygiene checks on HTTP headers, TLS, cookies and a few well-known exposed paths. PASS means the basics are in place. It does **not** mean the site is secure: application logic, authentication, plugins, server configuration and dependencies are not tested here. Treat FAILED as a must-fix and PASS as a starting point, not a certificate.

| Check | Tier | Status | Detail |
| --- | --- | --- | --- |
| HTTP redirects to HTTPS | basic | fail | Plain HTTP does not redirect to HTTPS. |
| Strict-Transport-Security | basic | fail | Strict-Transport-Security header is missing. |
| Clickjacking protection | basic | pass | Framing is restricted. |
| X-Content-Type-Options | basic | fail | X-Content-Type-Options header is missing. |
| Cookies Secure + HttpOnly | basic | n/a | The document response sets no cookies. |
| No mixed content | basic | pass | No http:// subresources were loaded. |
| CORS | basic | pass | No wildcard CORS origin. |
| Technology disclosure | basic | warn | Response headers disclose server technology. |
| TLS certificate and protocol | basic | pass | Valid certificate and modern TLS protocol. |
| No exposed sensitive files | basic | pass | None of 6 probed sensitive paths returned real content. |
| Forms do not post to HTTP | basic | n/a | No forms on the page. |
| Content-Security-Policy present | advanced | pass | Content-Security-Policy header is set. |
| CSP is strict | advanced | fail | CSP has 2 issues: default-src missing; object-src is not 'none'. |
| HSTS preload | advanced | fail | Strict-Transport-Security header is missing. |
| Referrer-Policy | advanced | fail | Referrer-Policy header is missing. |
| Permissions-Policy | advanced | fail | Permissions-Policy header is missing. |
| Cross-Origin-Opener-Policy | advanced | fail | Cross-Origin-Opener-Policy header is missing. |
| Cross-Origin-Resource-Policy | advanced | fail | Cross-Origin-Resource-Policy header is missing. |
| Cookies SameSite | advanced | n/a | The document response sets no cookies. |
| Subresource Integrity | advanced | warn | 2 of 2 cross-origin scripts lack an integrity attribute. |
| SPF + DMARC DNS records | advanced | pass | SPF and DMARC records are present. |
| WP version not disclosed | wordpress | pass | No WordPress version found in generator meta or core asset URLs. |
| xmlrpc.php disabled | wordpress | fail | xmlrpc.php accepts POST requests (brute-force / pingback vector). |
| User enumeration blocked | wordpress | pass | No username leak across 3 enumeration probes. |
| readme.html removed | wordpress | pass | readme.html is not served. |
| Directory listing off | wordpress | pass | Uploads directory does not return an index page. |
| debug.log not public | wordpress | pass | debug.log is not served. |
| No config backups or installer | wordpress | warn | Installer /wp-admin/install.php is reachable. Harmless while the site is installed, but it becomes an open takeover path if the database is ever unreachable — block it in .htaccess. |
| Login not on default path | wordpress | warn | Login form is served on the default /wp-login.php path. |