20260924T095417Z-a917
- Audited URL
- https://play.ee/
- Timestamp
- 2026-09-24T09:58:42.500Z
- Kind
- site
- Pages
- 5
Weighted audit summary
Site overall 76 is the mean of 4 pages. Scores range 73 (https://play.ee/team) → 78 (https://play.ee/privacy-policy). Weakest page: PSI mobile performance is strong at 94 with excellent TTFB and CLS, though LCP sits at 2.8 s in the warning range. However, the Security basics verdict is FAILED due to missing HTTP-to-HTTPS redirects and HSTS, which caps the overall score below 90 per the rubric. Accessibility has a serious color-contrast violation and missing landmarks despite a 94 score. W3C validation reports 7 errors including parser recovery failure, indicating broken HTML structure. Confidence is high as all audit tools returned complete data.
Audit Report: Perfectly formed web development team - gotoAndPlay
Website: https://play.ee/
Date: 24.09.2026
Audit Coverage: 95% — PageSpeed Insights (desktop): PSI HTTP 429; PageSpeed Insights (mobile): PSI HTTP 429; PageSpeed Insights: mobile: PSI HTTP 429; desktop: PSI HTTP 429
Confidence: low
Pages Audited (5 of 5):
- https://play.ee/
- https://play.ee/team
- https://play.ee/privacy-policy
- https://play.ee/et/meeskond
- https://play.ee/wordpress-support-service
Summary of results
Overall Score: 76 / 100
Status: ⚠ 🟡 Needs Improvement
Site overall 76 is the mean of 4 pages. Scores range 73 (https://play.ee/team) → 78 (https://play.ee/privacy-policy). Weakest page: PSI mobile performance is strong at 94 with excellent TTFB and CLS, though LCP sits at 2.8 s in the warning range. However, the Security basics verdict is FAILED due to missing HTTP-to-HTTPS redirects and HSTS, which caps the overall score below 90 per the rubric. Accessibility has a serious color-contrast violation and missing landmarks despite a 94 score. W3C validation reports 7 errors including parser recovery failure, indicating broken HTML structure. Confidence is high as all audit tools returned complete data.
Per-page scores
🟡 Needs Improvement · https://play.ee/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 78 | 96 | 94 | 100 | 92 | FAILED |
🟡 Needs Improvement · https://play.ee/team
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 73 | 94 | 94 | 100 | 100 | FAILED |
🟡 Needs Improvement · https://play.ee/privacy-policy
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 78 | 93 | 87 | 100 | 100 | FAILED |
🟡 Needs Improvement · https://play.ee/et/meeskond
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 74 | 100 | 93 | 100 | 100 | FAILED |
— · https://play.ee/wordpress-support-service
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| — | — | — | — | — | FAILED |
PageSpeed Insights — Mobile vs Desktop
Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.
| URL | Performance (M / D) | LCP (M / D) | CLS (M / D) |
|---|---|---|---|
| https://play.ee/ | 96 / 100 | 2.48 s / 546 ms | 0.001 / 0.005 |
| https://play.ee/team | 94 / 100 | 2.78 s / 633 ms | 0.037 / 0.003 |
| https://play.ee/privacy-policy | 93 / — | 2.80 s / — | 0.002 / — |
| https://play.ee/et/meeskond | — / 100 | — / 629 ms | — / 0.003 |
Optimization Checklist
3 of 3 passing — 3 pass · 0 warn · 0 fail · 5 n/a
| Item | Status | Detail |
|---|---|---|
| Page caching plugin / CDN active | Pass | Caching plugin detected (WP Rocket) |
| Response compressed (gzip / brotli) | Pass | Document response is compressed with gzip. |
| Images lazy-loaded | N/A | No raster <img> elements found (37 SVGs, 13 placeholders excluded). |
| Hero image eagerly loaded | N/A | No raster <img> elements found (37 SVGs, 13 placeholders excluded). |
| Hero is a real <img> (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | N/A | Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | Pass | No render-blocking scripts in <head>. |
Fixes
Priority 1: Critical
Immediate action — impacts user experience, search rankings, or site safety.
1A. Enforce HTTPS redirect and add HSTS Security
- Impact: Transport security, trust, security basics score
- Problem: Security basics verdict is FAILED; HTTP does not redirect to HTTPS and Strict-Transport-Security header is missing.
- Solution:
Configure the web server to redirect all HTTP traffic to HTTPS (301) and send the HSTS header:
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
1B. Fix W3C HTML validation errors Best Practices
- Impact: Rendering stability, SEO indexing
- Problem: W3C validator reports 7 errors including parser recovery failure at line 101 (bad start tag in iframe/noscript in head).
- Solution:
Move the Google Tag Manager iframe snippet out of the
<head>or ensure it is properly closed within<noscript>without breaking the<head>structure. Remove invalidnameattributes on<meta>tags inside the<head>.
1C. Fix HTTP redirect and add baseline security headers Security
- Impact: Transport security, clickjacking, MIME sniffing
- Problem: Security basics verdict is FAILED: HTTP does not redirect to HTTPS, HSTS is missing, and X-Content-Type-Options is missing.
- Solution:
Configure server to redirect HTTP to HTTPS and add headers:
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" Header always set X-Content-Type-Options "nosniff" RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
1D. Enforce HTTPS and add baseline security headers Security
- Impact: Transport security, clickjacking, MIME sniffing
- Problem: Security basics verdict is FAILED: HTTP does not redirect to HTTPS, HSTS is missing, and X-Content-Type-Options is missing.
- Solution:
Configure the web server to redirect all HTTP traffic to HTTPS and send these headers:
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" Header always set X-Content-Type-Options "nosniff"
1E. Disable WordPress xmlrpc.php POST requests Security
- Impact: Brute-force protection, pingback vector
- Problem: Security basics report shows xmlrpc.php accepts POST requests, a known brute-force vector.
- Solution:
Block POST requests to xmlrpc.php in .htaccess or via a security plugin:
<Files xmlrpc.php> <Limit POST> deny from all </Limit> </Files>
1F. Fix HTTP to HTTPS redirect and add HSTS Security
Impact: Transport security, Security Basics verdict
Problem: Security Basics FAILED: HTTP does not redirect to HTTPS and Strict-Transport-Security header is missing.
Solution: Configure server to redirect all HTTP traffic to HTTPS immediately.
Add HSTS header:
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
1G. Add X-Content-Type-Options header Security
- Impact: MIME sniffing protection
- Problem: Security Basics FAILED: X-Content-Type-Options header is missing.
- Solution:
Add the following header to prevent MIME type sniffing:
Header always set X-Content-Type-Options "nosniff"
Priority 2: Important
Essential for compliance, user reach, and search visibility.
2A. Add explicit width and height to images Performance
- Impact: CLS (Cumulative Layout Shift)
- Problem: 50 images lack explicit width/height attributes, creating a high risk for layout shifts even though current CLS is 0.001.
- Solution:
Add
widthandheightattributes to all<img>tags matching the intrinsic aspect ratio:<img src="image.jpg" width="800" height="600" alt="...">
2B. Add skip-to-content link and main landmark Accessibility
- Impact: Keyboard navigation, screen reader usability
- Problem: HTML inventory shows missing
mainlandmark and no skip-to-content link; axe reportsregionandlandmark-uniqueviolations. - Solution:
Add a skip link at the top of the body:
Wrap the primary content in<a href="#main-content" class="skip-link">Skip to content</a><main id="main-content">.
2C. Disable WordPress xmlrpc.php POST requests Security
- Impact: Brute-force protection, server load
- Problem: Security basics report indicates xmlrpc.php accepts POST requests, a known brute-force vector.
- Solution:
Block POST requests to xmlrpc.php in
.htaccess:<Files xmlrpc.php> <Limit POST> deny from all </Limit> </Files>
2D. Fix color contrast and add main landmark Accessibility
- Impact: WCAG 1.4.3 contrast, 1.3.1 info and relationships
- Problem: axe-core reports 1 serious violation on .heading__main contrast; document lacks a main landmark and skip-to-content link.
- Solution:
- Increase contrast on
.heading__mainto ≥4.5:1. - Add
<main id="main-content">wrapper around primary content. - Add skip link at top:
<a href="#main-content" class="skip-link">Skip to content</a>.
- Increase contrast on
2E. Resolve W3C HTML validation errors Best Practices
- Impact: Parser compatibility, SEO rendering
- Problem: W3C Validator reports 7 errors including parser recovery failure at line 105 and invalid iframe/noscript placement in head.
- Solution:
- Move
<noscript><iframe>...</iframe></noscript>out of<head>(likely GTM snippet). - Fix stray end tags and meta attributes.
- Ensure
<body>opens correctly after</head>.
- Move
2F. Fix color contrast and heading hierarchy Accessibility
- Impact: WCAG 1.4.3 contrast, 1.3.1 heading order
- Problem: axe-core found 1 serious color-contrast violation on h1 and .button, plus heading order skips (h1→h4).
- Solution:
- Adjust text colors to meet 4.5:1 contrast ratio.
- Ensure headings follow sequential order (h1 → h2 → h3) without skipping levels.
2G. Fix W3C HTML validation errors SEO
- Impact: Parser recovery, rendering consistency
- Problem: W3C validator reported 7 errors including parser recovery failure at line 100 and invalid iframe/noscript placement in head.
- Solution:
- Move
<noscript><iframe>...</iframe></noscript>out of<head>. - Ensure
<meta>tags are placed correctly within<head>. - Validate HTML structure to prevent parser recovery mode.
- Move
2H. Fix HTML validation errors SEO
- Impact: Parsing, SEO, Accessibility
- Problem: W3C Validator reported 8 errors including parser recovery failure at line 102 and bad href attributes.
- Solution:
- Remove empty
hrefattributes on<link>tags. - Fix
<noscript>placement (not allowed in<head>). - Ensure
<meta>tags are correctly placed within<head>.
- Remove empty
Priority 3: Best Practice
Recommended for long-term maintainability.
3A. Strengthen Content-Security-Policy Security
- Impact: XSS defense-in-depth
- Problem: CSP is present but weak (missing default-src, object-src not 'none'). Site signals show no auth/payments/UGC, lowering priority.
- Solution:
Add
default-src 'self'andobject-src 'none'to the CSP header. Since this is a brochure site, a strict allowlist is less critical than basic headers, but improves defense-in-depth.
3B. Add explicit width and height to images Performance
- Impact: CLS (Cumulative Layout Shift)
- Problem: 45 images lack width/height attributes, risking layout shifts despite current CLS of 0.037.
- Solution:
Add
widthandheightattributes to all<img>tags:<img src="..." alt="..." width="300" height="200">
3C. Harden WordPress configuration Security
- Impact: Brute-force protection, attack surface
- Problem: xmlrpc.php accepts POST requests and /wp-admin/install.php is reachable.
- Solution:
- Disable xmlrpc.php in .htaccess or via plugin.
- Block /wp-admin/install.php access after installation.
- Consider changing default login path.
3D. Eliminate render-blocking JavaScript Performance
- Impact: FCP, LCP, TBT
- Problem: PSI findings estimate 1,230 ms savings from render-blocking insights; unused JS detected (23 KB).
- Solution:
- Add
deferorasyncto non-critical scripts. - Inline critical CSS and defer non-critical JS.
- Remove or tree-shake the 23 KB of unused jQuery code.
- Add
3E. Harden Content-Security-Policy (CSP) Security
- Impact: XSS defense-in-depth
- Problem: Current CSP only sets
frame-ancestors 'self'; missingdefault-srcandobject-src 'none'. - Solution:
Since the site has no auth/payments (signals: no), a strict CSP is P3. If implemented later, use nonce-based CSP:
Header always set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none';"
3F. Add image dimensions and lazy loading Performance
- Impact: CLS, Layout stability
- Problem: HTML Inventory shows 45 images without explicit width/height and 45 without loading="lazy".
- Solution:
Add
widthandheightattributes to all<img>tags to reserve space. Addloading="lazy"to images below the fold:<img src="..." alt="..." width="300" height="200" loading="lazy">
3G. Harden WordPress security endpoints Security
- Impact: Brute-force protection, Attack surface
- Problem: Security basics warn: xmlrpc.php accepts POST requests and /wp-admin/install.php is reachable.
- Solution:
- Disable xmlrpc.php in .htaccess or via plugin.
- Block access to /wp-admin/install.php after installation:
<Files "install.php"> Require all denied </Files>
▸Raw Markdown sent to the LLM
# Site Audit — https://play.ee/
Run: 2026-09-24T09:54:38.817Z
Audited **5** of 5 discovered pages.
Average per-page audit coverage: **95%**
Aggregate missing or failed sources (deduped across pages):
- PageSpeed Insights (desktop): PSI HTTP 429
- PageSpeed Insights (mobile): PSI HTTP 429
- PageSpeed Insights: mobile: PSI HTTP 429; desktop: PSI HTTP 429
Pages audited:
- https://play.ee/
- https://play.ee/team
- https://play.ee/privacy-policy
- https://play.ee/et/meeskond
- https://play.ee/wordpress-support-service
---
# Page 1 of 5 — https://play.ee/
Run: 2026-09-24T09:54:40.828Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 18129 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **96** | 100 |
| Accessibility | **94** | 95 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **2.6 s** | 0.5 s |
| CLS | 0.001 | **0.005** |
| TBT | **20 ms** | 0 ms |
| FCP | **1.97 s** | 486 ms |
| Speed Index | **2.90 s** | 513 ms |
| TTFB | 7 ms | **40 ms** |
### Priority fixes
1. **largest-contentful-paint** (low) — 2.6 s
2. **speed-index** (low) — 3.8 s
3. **first-contentful-paint** (low) — 2.0 s
4. **network-dependency-tree-insight** (high)
5. **render-blocking-insight** (high) — Est savings of 1,060 ms
### Findings (mobile)
#### Unused JavaScript
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js — 23 KB wasted
#### Long tasks
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js — 89 ms
- https://play.ee/ — 51 ms
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `largest-contentful-paint` (performance, score 0.87, weight 25) — Largest Contentful Paint — 2.6 s
- `speed-index` (performance, score 0.83, weight 10) — Speed Index — 3.8 s
- `first-contentful-paint` (performance, score 0.85, weight 10) — First Contentful Paint — 2.0 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 9 links found
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 1255 ms._
**Transport:**
- Final URL: https://play.ee/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://play.ee/ does not redirect to HTTPS (target: none)
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 15 Sep 2026 08:38:43 GMT
- expires: Thu, 24 Sep 2026 09:54:40 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 35451
- Decoded body: 216.5 KB
- Compression ratio: 0.16
### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://play.ee/ does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy weak** (high) — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (weak, high) `frame-ancestors 'self';` — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache`
- X-Powered-By: `PHP/8.3.33`
#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 35451
content-security-policy: frame-ancestors 'self';
content-type: text/html; charset=UTF-8
date: Thu, 24 Sep 2026 09:54:40 GMT
expires: Thu, 24 Sep 2026 09:54:40 GMT
keep-alive: timeout=5, max=100
last-modified: Tue, 15 Sep 2026 08:38:43 GMT
server: Apache
upgrade: h2,h2c
vary: Accept-Encoding
x-frame-options: SAMEORIGIN
x-powered-by: PHP/8.3.33
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 773 ms._
**Scoring:** 7 errors · 0 warnings · 23 cosmetic (suppressed)
> **Validator truncated at line 101** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.
### Priority fixes
1. **Parser recovery at line 101** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad start tag in “iframe” in “noscript” in “head”.** (medium) — x1, first at line 98
3. **Stray end tag “noscript”.** (medium) — x1, first at line 98
4. **Attribute “name” not allowed on element “meta” at this point.** (medium) — x1, first at line 100
5. **Element “meta” is missing one or more of the following attributes: “itemprop”, “property”.** (medium) — x1, first at line 100
### Issue groups
- (×1) [error] Bad start tag in “iframe” in “noscript” in “head”. — first at line 98 `<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-K3P64XMJ"`
- (×1) [error] Stray end tag “noscript”. — first at line 98 `></iframe></noscript><!-- E`
- (×1) [error] Attribute “name” not allowed on element “meta” at this point. — first at line 100 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Element “meta” is missing one or more of the following attributes: “itemprop”, “property”. — first at line 100 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Stray end tag “head”. — first at line 100 `esktop" /></head>
<body`
- (×1) [error] Start tag “body” seen but an element of the same type was already open. — first at line 101 `/></head>
<body class="home wp-singular page-template page-template-template-dyn`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 101 `/></head>
<body class="home wp-singular page-template page-template-template-dyn`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 2287 ms._
**Scoring:** 2 violations · 32 passes · critical 0 · serious 0 · moderate 2 · minor 0
### Priority fixes
1. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
2. **region** (medium) — All page content should be contained by landmarks
### Findings
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.header__nav`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.home-hero__main`
- `.home-hero__bottom`
- `canvas`
- `.keywords__mouse`
- `.keywords__intro`
- … and 31 more nodes
### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 38 nodes
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 2303 ms._
**Capture summary:** 1 console events · 0 mixed-content requests · 13 network requests · 178.1 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| font | 3 | 57.6 KB |
| script | 4 | 45.6 KB |
| document | 1 | 34.6 KB |
| stylesheet | 2 | 34.2 KB |
| other | 1 | 5.5 KB |
| image | 1 | 576 B |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 2 requests, 13.2 KB
- https://fast.fonts.net — 2 requests, 0 B
**Slowest requests (top 5):**
- https://play.ee/ (document) — 460 ms, 34.6 KB
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/fonts/1c0243aa-c535-4d42-ac53-d6f0f74a1412.bd94708352cbb3b4863c.woff2 (font) — 208 ms, 19.3 KB
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/fonts/fc2fa85e-cd2d-4004-930a-8adad6c60317.3bd2a5f3705d9fb438c5.woff2 (font) — 208 ms, 19.3 KB
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/fonts/f389f79b-6013-4448-aa6a-b6fd235eab80.b91a05bafb09e626383a.woff2 (font) — 208 ms, 19.0 KB
- https://fast.fonts.net/t/1.css?apiType=css&projectid=d924b670-8ecc-46fd-9fff-80fd9989d037 (stylesheet) — 33 ms, 0 B
### Findings
#### Console events
- [warning] Couldn't load preload assets:
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 2303 ms._
**Document:**
- Lang: en
- Title: Perfectly formed web development team - gotoAndPlay
- Canonical: https://play.ee/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 217719
**Meta tags:**
- Description: Small, agile web development team working on big ideas in close collaboration with our clients. Result driven from day one!
- Robots: follow, index, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time)
- Twitter tags: 3
- hreflang:
- en → http://play.ee/
- et → http://play.ee/et/
- x-default → http://play.ee/
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×6, h3 ×5, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: we create memorable experiences with
web technologi
- h2: Your result
- h2: we offer
more than expected
- h2: Üks
- h2: meet the team of
uncommon talent
- h2: proof to our approach are
happy clients
- h3: Deliverables with high quality standards
- h3: Working with gotoAndPlay is a great experience
- h3: Speed, attitude, skills!
- h3: Hardworking, fun & ready to adopt new technologies
- h3: The sky is the limit
- h2: take a look at our
case studies
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**
**Scripts:** 23 total — 3 defer, 0 async, 1 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/runtime.30d3b226dcf211e512b1.min.js
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js (defer)
**Stylesheets:** 1 external, 3 inline (9.6 KB)
**Images:** 50 total — **0 without alt**, **50 without width/height**, 50 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| ee/wp-content/themes/gotoandplay/inc/theme/img/landscape.svg | Please turn your device sideways | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 46 anchors — 34 external, 1 preconnect, 0 preload.
Vague repeated link text:
- "read more" ×9
- "view our instagram feed" ×3
- "visit our facebook page" ×3
- "visit our linkedin page" ×3
- "eng" ×3
- "est" ×3
- "case studies" ×2
- "styleguide" ×2
- "privacy policy" ×2
**Forms:**
Form 1:
- text — labeled
### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **50 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **Vague link text repeated** (medium) — "read more" ×9
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 3 pass · 0 warn · 0 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Response compressed (gzip / brotli) | ✓ pass | Document response is compressed with gzip. |
| Images lazy-loaded | – n/a | No raster <img> elements found (37 SVGs, 13 placeholders excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (37 SVGs, 13 placeholders excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.23.3.3`
- Response compressed (gzip / brotli):
- `content-encoding: gzip`
- `decoded body: 221727 bytes`
- `ratio: 0.16`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
## Security basics
_Captured in 0 ms._
**Verdict: FAILED**
> These are high-level hygiene checks on HTTP headers, TLS, cookies and a few well-known exposed paths. PASS means the basics are in place. It does **not** mean the site is secure: application logic, authentication, plugins, server configuration and dependencies are not tested here. Treat FAILED as a must-fix and PASS as a starting point, not a certificate.
| Check | Tier | Status | Detail |
| --- | --- | --- | --- |
| HTTP redirects to HTTPS | basic | fail | Plain HTTP does not redirect to HTTPS. |
| Strict-Transport-Security | basic | fail | Strict-Transport-Security header is missing. |
| Clickjacking protection | basic | pass | Framing is restricted. |
| X-Content-Type-Options | basic | fail | X-Content-Type-Options header is missing. |
| Cookies Secure + HttpOnly | basic | n/a | The document response sets no cookies. |
| No mixed content | basic | pass | No http:// subresources were loaded. |
| CORS | basic | pass | No wildcard CORS origin. |
| Technology disclosure | basic | warn | Response headers disclose server technology. |
| TLS certificate and protocol | basic | pass | Valid certificate and modern TLS protocol. |
| No exposed sensitive files | basic | pass | None of 6 probed sensitive paths returned real content. |
| Forms do not post to HTTP | basic | pass | No form action uses http://. |
| Content-Security-Policy present | advanced | pass | Content-Security-Policy header is set. |
| CSP is strict | advanced | fail | CSP has 2 issues: default-src missing; object-src is not 'none'. |
| HSTS preload | advanced | fail | Strict-Transport-Security header is missing. |
| Referrer-Policy | advanced | fail | Referrer-Policy header is missing. |
| Permissions-Policy | advanced | fail | Permissions-Policy header is missing. |
| Cross-Origin-Opener-Policy | advanced | fail | Cross-Origin-Opener-Policy header is missing. |
| Cross-Origin-Resource-Policy | advanced | fail | Cross-Origin-Resource-Policy header is missing. |
| Cookies SameSite | advanced | n/a | The document response sets no cookies. |
| Subresource Integrity | advanced | warn | 2 of 2 cross-origin scripts lack an integrity attribute. |
| SPF + DMARC DNS records | advanced | pass | SPF and DMARC records are present. |
| WP version not disclosed | wordpress | pass | No WordPress version found in generator meta or core asset URLs. |
| xmlrpc.php disabled | wordpress | fail | xmlrpc.php accepts POST requests (brute-force / pingback vector). |
| User enumeration blocked | wordpress | pass | No username leak across 3 enumeration probes. |
| readme.html removed | wordpress | pass | readme.html is not served. |
| Directory listing off | wordpress | pass | Uploads directory does not return an index page. |
| debug.log not public | wordpress | pass | debug.log is not served. |
| No config backups or installer | wordpress | warn | Installer /wp-admin/install.php is reachable. Harmless while the site is installed, but it becomes an open takeover path if the database is ever unreachable — block it in .htaccess. |
| Login not on default path | wordpress | warn | Login form is served on the default /wp-login.php path. |
---
# Page 2 of 5 — https://play.ee/team
Run: 2026-09-24T09:54:40.828Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 19100 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **94** | 100 |
| Accessibility | 94 | **93** |
| Best Practices | 100 | 100 |
| SEO | 100 | 100 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **2.8 s** | 0.6 s |
| CLS | **0.037** | 0.003 |
| TBT | 0 ms | 0 ms |
| FCP | **2.13 s** | 573 ms |
| Speed Index | **2.13 s** | 685 ms |
| TTFB | 4 ms | **5 ms** |
### Priority fixes
1. **largest-contentful-paint** (low) — 2.8 s
2. **first-contentful-paint** (low) — 2.1 s
3. **document-latency-insight** (high) — Est savings of 380 ms
4. **network-dependency-tree-insight** (high)
5. **render-blocking-insight** (high) — Est savings of 990 ms
### Findings (mobile)
#### Unused JavaScript
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js — 23 KB wasted
#### Layout-shift sources
- div.team-grid > div.team-grid__inner > div.intro > div.intro__content — shift 0.037
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `largest-contentful-paint` (performance, score 0.83, weight 25) — Largest Contentful Paint — 2.8 s
- `landmark-one-main` (accessibility, score 0.00, weight 3) — Document does not have a main landmark.
- `first-contentful-paint` (performance, score 0.80, weight 10) — First Contentful Paint — 2.1 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 1648 ms._
**Transport:**
- Final URL: https://play.ee/team/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://play.ee/team does not redirect to HTTPS (target: http://play.ee/team/)
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 15 Sep 2026 11:35:03 GMT
- expires: Thu, 24 Sep 2026 09:54:41 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 28364
- Decoded body: 169.4 KB
- Compression ratio: 0.163
### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://play.ee/team does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy weak** (high) — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (weak, high) `frame-ancestors 'self';` — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache`
- X-Powered-By: `PHP/8.3.33`
#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 28364
content-security-policy: frame-ancestors 'self';
content-type: text/html; charset=UTF-8
date: Thu, 24 Sep 2026 09:54:41 GMT
expires: Thu, 24 Sep 2026 09:54:41 GMT
keep-alive: timeout=5, max=99
last-modified: Tue, 15 Sep 2026 11:35:03 GMT
server: Apache
vary: Accept-Encoding
x-frame-options: SAMEORIGIN
x-powered-by: PHP/8.3.33
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1557 ms._
**Scoring:** 7 errors · 0 warnings · 23 cosmetic (suppressed)
> **Validator truncated at line 105** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.
### Priority fixes
1. **Parser recovery at line 105** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad start tag in “iframe” in “noscript” in “head”.** (medium) — x1, first at line 102
3. **Stray end tag “noscript”.** (medium) — x1, first at line 102
4. **Attribute “name” not allowed on element “meta” at this point.** (medium) — x1, first at line 104
5. **Element “meta” is missing one or more of the following attributes: “itemprop”, “property”.** (medium) — x1, first at line 104
### Issue groups
- (×1) [error] Bad start tag in “iframe” in “noscript” in “head”. — first at line 102 `<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-K3P64XMJ"`
- (×1) [error] Stray end tag “noscript”. — first at line 102 `></iframe></noscript><!-- E`
- (×1) [error] Attribute “name” not allowed on element “meta” at this point. — first at line 104 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Element “meta” is missing one or more of the following attributes: “itemprop”, “property”. — first at line 104 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Stray end tag “head”. — first at line 104 `esktop" /></head>
<body`
- (×1) [error] Start tag “body” seen but an element of the same type was already open. — first at line 105 `/></head>
<body class="wp-singular page-template page-template-template-dynamic `
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 105 `/></head>
<body class="wp-singular page-template page-template-template-dynamic `
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 2415 ms._
**Scoring:** 3 violations · 32 passes · critical 0 · serious 1 · moderate 2 · minor 0
### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
3. **region** (medium) — All page content should be contained by landmarks
### Findings
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `h1 > .heading__main`
- `.how-we-do__intro > .heading--primary.heading > .heading__main`
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.header__nav`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.team-grid__intro`
- `.is-active`
- `.grid__col--sm-6.grid__col--md-4.team-grid__member:nth-child(1) > .person-card.team-grid__member-card > .person-card__content`
- `.grid__col--sm-6.grid__col--md-4.team-grid__member:nth-child(2) > .person-card.team-grid__member-card > .person-card__content`
- `.grid__col--sm-6.grid__col--md-4.team-grid__member:nth-child(3) > .person-card.team-grid__member-card > .person-card__figure > .person-card__image--workmode.person-card__image.image--background > .image__inner > img`
- … and 35 more nodes
### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 10 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 7 nodes
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 2426 ms._
**Capture summary:** 1 console events · 0 mixed-content requests · 14 network requests · 188.7 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| font | 3 | 57.6 KB |
| script | 4 | 45.6 KB |
| stylesheet | 2 | 34.2 KB |
| document | 2 | 27.7 KB |
| image | 1 | 18.1 KB |
| other | 1 | 5.5 KB |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 2 requests, 13.2 KB
- https://fast.fonts.net — 2 requests, 0 B
**Slowest requests (top 5):**
- https://play.ee/team (document) — 399 ms, 0 B
- https://play.ee/team/ (document) — 357 ms, 27.7 KB
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/fonts/1c0243aa-c535-4d42-ac53-d6f0f74a1412.bd94708352cbb3b4863c.woff2 (font) — 139 ms, 19.3 KB
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/fonts/fc2fa85e-cd2d-4004-930a-8adad6c60317.3bd2a5f3705d9fb438c5.woff2 (font) — 139 ms, 19.3 KB
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/fonts/f389f79b-6013-4448-aa6a-b6fd235eab80.b91a05bafb09e626383a.woff2 (font) — 138 ms, 19.0 KB
### Findings
#### Console events
- [warning] Couldn't load preload assets:
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 2426 ms._
**Document:**
- Lang: en
- Title: Expert full-stack development & technical support
- Canonical: https://play.ee/team/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 171666
**Meta tags:**
- Description: Meet our team of amazing people! At your service is our expert full-stack development team and an ever-ready technical support.
- Robots: follow, index, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time)
- Twitter tags: 3
- hreflang:
- en → https://play.ee/team/
- et → https://play.ee/et/meeskond/
- x-default → https://play.ee/team/
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×21, h3 ×8, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: meet our team of
individual masters
- h2: Siim Sups
- h2: Hiie-Helen Raju
- h2: Ardo Gärtner
- h2: Pärt Erikson
- h2: Juhan Valge
- h2: Vladislav Stafinjak
- h2: Lauri Uue
- h2: Kuldar Jürma
- h2: Raiko Raidma
- h2: Sander Orav
- h2: Andres Kalle
- h2: Ivo Klaas
- h2: Timo Soiunen
- h2: Tanel Marran
- h2: Hannes Juurma
- h2: Raimond Kurm
- h2: Janeli Kurvits
- h2: Marianne Võime
- h2: we are part of
play & nope alliance
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**
**Scripts:** 30 total — 3 defer, 0 async, 1 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/runtime.30d3b226dcf211e512b1.min.js
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js (defer)
**Stylesheets:** 1 external, 3 inline (9.6 KB)
**Images:** 45 total — **0 without alt**, **45 without width/height**, 45 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | wordpress support service / wordpress tu | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | vladislav | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 40 anchors — 23 external, 1 preconnect, 0 preload.
Vague repeated link text:
- "view our instagram feed" ×3
- "visit our facebook page" ×3
- "visit our linkedin page" ×3
- "eng" ×3
- "est" ×3
- "styleguide" ×2
- "privacy policy" ×2
- "nope design agency" ×2
### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **45 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 3 pass · 0 warn · 0 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Response compressed (gzip / brotli) | ✓ pass | Document response is compressed with gzip. |
| Images lazy-loaded | – n/a | No raster <img> elements found (30 SVGs, 15 placeholders excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (30 SVGs, 15 placeholders excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (30 SVGs, 15 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.23.3.3`
- Response compressed (gzip / brotli):
- `content-encoding: gzip`
- `decoded body: 173514 bytes`
- `ratio: 0.163`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
## Security basics
_Captured in 0 ms._
**Verdict: FAILED**
> These are high-level hygiene checks on HTTP headers, TLS, cookies and a few well-known exposed paths. PASS means the basics are in place. It does **not** mean the site is secure: application logic, authentication, plugins, server configuration and dependencies are not tested here. Treat FAILED as a must-fix and PASS as a starting point, not a certificate.
| Check | Tier | Status | Detail |
| --- | --- | --- | --- |
| HTTP redirects to HTTPS | basic | fail | Plain HTTP does not redirect to HTTPS. |
| Strict-Transport-Security | basic | fail | Strict-Transport-Security header is missing. |
| Clickjacking protection | basic | pass | Framing is restricted. |
| X-Content-Type-Options | basic | fail | X-Content-Type-Options header is missing. |
| Cookies Secure + HttpOnly | basic | n/a | The document response sets no cookies. |
| No mixed content | basic | pass | No http:// subresources were loaded. |
| CORS | basic | pass | No wildcard CORS origin. |
| Technology disclosure | basic | warn | Response headers disclose server technology. |
| TLS certificate and protocol | basic | pass | Valid certificate and modern TLS protocol. |
| No exposed sensitive files | basic | pass | None of 6 probed sensitive paths returned real content. |
| Forms do not post to HTTP | basic | n/a | No forms on the page. |
| Content-Security-Policy present | advanced | pass | Content-Security-Policy header is set. |
| CSP is strict | advanced | fail | CSP has 2 issues: default-src missing; object-src is not 'none'. |
| HSTS preload | advanced | fail | Strict-Transport-Security header is missing. |
| Referrer-Policy | advanced | fail | Referrer-Policy header is missing. |
| Permissions-Policy | advanced | fail | Permissions-Policy header is missing. |
| Cross-Origin-Opener-Policy | advanced | fail | Cross-Origin-Opener-Policy header is missing. |
| Cross-Origin-Resource-Policy | advanced | fail | Cross-Origin-Resource-Policy header is missing. |
| Cookies SameSite | advanced | n/a | The document response sets no cookies. |
| Subresource Integrity | advanced | warn | 2 of 2 cross-origin scripts lack an integrity attribute. |
| SPF + DMARC DNS records | advanced | pass | SPF and DMARC records are present. |
| WP version not disclosed | wordpress | pass | No WordPress version found in generator meta or core asset URLs. |
| xmlrpc.php disabled | wordpress | fail | xmlrpc.php accepts POST requests (brute-force / pingback vector). |
| User enumeration blocked | wordpress | pass | No username leak across 3 enumeration probes. |
| readme.html removed | wordpress | pass | readme.html is not served. |
| Directory listing off | wordpress | pass | Uploads directory does not return an index page. |
| debug.log not public | wordpress | pass | debug.log is not served. |
| No config backups or installer | wordpress | warn | Installer /wp-admin/install.php is reachable. Harmless while the site is installed, but it becomes an open takeover path if the database is ever unreachable — block it in .htaccess. |
| Login not on default path | wordpress | warn | Login form is served on the default /wp-login.php path. |
---
# Page 3 of 5 — https://play.ee/privacy-policy
Run: 2026-09-24T09:54:59.202Z
## Audit Coverage
**94%** of audit sources returned data.
Missing or failed sources:
- PageSpeed Insights (desktop): PSI HTTP 429
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 10920 ms (mobile + desktop in parallel)._
_Desktop strategy errored (PSI HTTP 429); mobile data duplicated for both._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | 93 | 93 |
| Accessibility | 87 | 87 |
| Best Practices | 100 | 100 |
| SEO | 100 | 100 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | 2.8 s | 2.8 s |
| CLS | 0.002 | 0.002 |
| TBT | 0 ms | 0 ms |
| FCP | 2.33 s | 2.33 s |
| Speed Index | 2.96 s | 2.96 s |
| TTFB | 3 ms | 3 ms |
### Priority fixes
1. **largest-contentful-paint** (low) — 2.8 s
2. **first-contentful-paint** (medium) — 2.3 s
3. **document-latency-insight** (high) — Est savings of 690 ms
4. **network-dependency-tree-insight** (high)
5. **render-blocking-insight** (high) — Est savings of 1,230 ms
### Findings (mobile)
#### Unused JavaScript
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js — 23 KB wasted
#### Layout-shift sources
- div.main > footer.footer > h2.heading > span.heading__main — shift 0.001
- div.main > footer.footer > div.footer__bottom > ul.list — shift 0.001
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `largest-contentful-paint` (performance, score 0.83, weight 25) — Largest Contentful Paint — 2.8 s
- `heading-order` (accessibility, score 0.00, weight 3) — Heading elements are not in a sequentially-descending order
- `landmark-one-main` (accessibility, score 0.00, weight 3) — Document does not have a main landmark.
- `first-contentful-paint` (performance, score 0.73, weight 10) — First Contentful Paint — 2.3 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 2093 ms._
**Transport:**
- Final URL: https://play.ee/privacy-policy/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://play.ee/privacy-policy does not redirect to HTTPS (target: http://play.ee/privacy-policy/)
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 15 Sep 2026 08:38:51 GMT
- expires: Thu, 24 Sep 2026 09:54:59 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 21747
- Decoded body: 78.9 KB
- Compression ratio: 0.269
### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://play.ee/privacy-policy does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy weak** (high) — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (weak, high) `frame-ancestors 'self';` — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache`
- X-Powered-By: `PHP/8.3.33`
#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 21747
content-security-policy: frame-ancestors 'self';
content-type: text/html; charset=UTF-8
date: Thu, 24 Sep 2026 09:54:59 GMT
expires: Thu, 24 Sep 2026 09:54:59 GMT
keep-alive: timeout=5, max=98
last-modified: Tue, 15 Sep 2026 08:38:51 GMT
server: Apache
vary: Accept-Encoding
x-frame-options: SAMEORIGIN
x-powered-by: PHP/8.3.33
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1307 ms._
**Scoring:** 7 errors · 0 warnings · 23 cosmetic (suppressed)
> **Validator truncated at line 100** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.
### Priority fixes
1. **Parser recovery at line 100** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad start tag in “iframe” in “noscript” in “head”.** (medium) — x1, first at line 97
3. **Stray end tag “noscript”.** (medium) — x1, first at line 97
4. **Attribute “name” not allowed on element “meta” at this point.** (medium) — x1, first at line 99
5. **Element “meta” is missing one or more of the following attributes: “itemprop”, “property”.** (medium) — x1, first at line 99
### Issue groups
- (×1) [error] Bad start tag in “iframe” in “noscript” in “head”. — first at line 97 `<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-K3P64XMJ"`
- (×1) [error] Stray end tag “noscript”. — first at line 97 `></iframe></noscript><!-- E`
- (×1) [error] Attribute “name” not allowed on element “meta” at this point. — first at line 99 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Element “meta” is missing one or more of the following attributes: “itemprop”, “property”. — first at line 99 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Stray end tag “head”. — first at line 99 `esktop" /></head>
<body`
- (×1) [error] Start tag “body” seen but an element of the same type was already open. — first at line 100 `/></head>
<body class="privacy-policy wp-singular page-template-default page pag`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 100 `/></head>
<body class="privacy-policy wp-singular page-template-default page pag`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 2069 ms._
**Scoring:** 4 violations · 25 passes · critical 0 · serious 1 · moderate 3 · minor 0
### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **heading-order** (medium) — Heading levels should only increase by one
3. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
4. **region** (medium) — All page content should be contained by landmarks
### Findings
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `h1 > .heading__main`
- `.button`
#### `heading-order` (moderate)
[Heading levels should only increase by one](https://dequeuniversity.com/rules/axe/4.11/heading-order?application=playwright)
- `h4:nth-child(9)`
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.header__nav`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `h1`
- `.content__body`
- `.sticky-footer__social > .list__item:nth-child(1) > .social__link > .social__label`
- `.sticky-footer__social > .list__item:nth-child(2) > .social__link > .social__label`
- `.sticky-footer__social > .list__item:nth-child(3) > .social__link > .social__label`
### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 8 nodes
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 2079 ms._
**Capture summary:** 1 console events · 0 mixed-content requests · 15 network requests · 172.4 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| font | 3 | 57.6 KB |
| script | 5 | 53.5 KB |
| stylesheet | 2 | 34.2 KB |
| document | 2 | 21.2 KB |
| other | 1 | 5.5 KB |
| image | 1 | 338 B |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 2 requests, 13.2 KB
- https://fast.fonts.net — 2 requests, 0 B
**Slowest requests (top 5):**
- https://play.ee/privacy-policy/ (document) — 465 ms, 21.2 KB
- https://play.ee/privacy-policy (document) — 407 ms, 0 B
- https://fast.fonts.net/t/1.css?apiType=css&projectid=d924b670-8ecc-46fd-9fff-80fd9989d037 (stylesheet) — 28 ms, 0 B
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (script) — 27 ms, 3.0 KB
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (script) — 26 ms, 10.1 KB
### Findings
#### Console events
- [warning] Couldn't load preload assets:
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 2079 ms._
**Document:**
- Lang: en
- Title: Privacy Policy - gotoAndPlay
- Canonical: https://play.ee/privacy-policy/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 80901
**Meta tags:**
- Description: At gotoAndPlay, we take information security seriously. From our privacy policy you can learn about the data we gather at gotoAndPlay regarding personal data,
- Robots: follow, index, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time)
- Twitter tags: 3
- hreflang:
- en → https://play.ee/privacy-policy/
- et → https://play.ee/et/privaatsustingimused/
- x-default → https://play.ee/privacy-policy/
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×0, h4 ×3, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: about our
privacy policy
- h4: About the cookies used on our website
- h4: Manage cookie preferences
- h4: Server logs
- h2: ready when you are
<span style="unicode-bidi:bidi-overr
- Skips:
- h1 → h4 after "about our
privacy policy"
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**
**Scripts:** 28 total — 3 defer, 1 async, 1 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/runtime.30d3b226dcf211e512b1.min.js
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js (defer)
- https://play.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)
**Stylesheets:** 1 external, 3 inline (9.6 KB)
**Images:** 1 total — **0 without alt**, **1 without width/height**, 1 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 29 anchors — 14 external, 1 preconnect, 0 preload.
Vague repeated link text:
- "view our instagram feed" ×3
- "visit our facebook page" ×3
- "visit our linkedin page" ×3
- "eng" ×3
- "est" ×3
- "styleguide" ×2
- "privacy policy" ×2
- "http://play.ee" ×2
### Priority fixes
1. **Heading level skips** (medium) — h1→h4 after "about our
p"
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **1 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 3 pass · 0 warn · 0 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Response compressed (gzip / brotli) | ✓ pass | Document response is compressed with gzip. |
| Images lazy-loaded | – n/a | No raster <img> elements found (1 placeholder excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (1 placeholder excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (1 placeholder excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.23.3.3`
- Response compressed (gzip / brotli):
- `content-encoding: gzip`
- `decoded body: 80767 bytes`
- `ratio: 0.269`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
## Security basics
_Captured in 0 ms._
**Verdict: FAILED**
> These are high-level hygiene checks on HTTP headers, TLS, cookies and a few well-known exposed paths. PASS means the basics are in place. It does **not** mean the site is secure: application logic, authentication, plugins, server configuration and dependencies are not tested here. Treat FAILED as a must-fix and PASS as a starting point, not a certificate.
| Check | Tier | Status | Detail |
| --- | --- | --- | --- |
| HTTP redirects to HTTPS | basic | fail | Plain HTTP does not redirect to HTTPS. |
| Strict-Transport-Security | basic | fail | Strict-Transport-Security header is missing. |
| Clickjacking protection | basic | pass | Framing is restricted. |
| X-Content-Type-Options | basic | fail | X-Content-Type-Options header is missing. |
| Cookies Secure + HttpOnly | basic | n/a | The document response sets no cookies. |
| No mixed content | basic | pass | No http:// subresources were loaded. |
| CORS | basic | pass | No wildcard CORS origin. |
| Technology disclosure | basic | warn | Response headers disclose server technology. |
| TLS certificate and protocol | basic | pass | Valid certificate and modern TLS protocol. |
| No exposed sensitive files | basic | pass | None of 6 probed sensitive paths returned real content. |
| Forms do not post to HTTP | basic | n/a | No forms on the page. |
| Content-Security-Policy present | advanced | pass | Content-Security-Policy header is set. |
| CSP is strict | advanced | fail | CSP has 2 issues: default-src missing; object-src is not 'none'. |
| HSTS preload | advanced | fail | Strict-Transport-Security header is missing. |
| Referrer-Policy | advanced | fail | Referrer-Policy header is missing. |
| Permissions-Policy | advanced | fail | Permissions-Policy header is missing. |
| Cross-Origin-Opener-Policy | advanced | fail | Cross-Origin-Opener-Policy header is missing. |
| Cross-Origin-Resource-Policy | advanced | fail | Cross-Origin-Resource-Policy header is missing. |
| Cookies SameSite | advanced | n/a | The document response sets no cookies. |
| Subresource Integrity | advanced | warn | 2 of 2 cross-origin scripts lack an integrity attribute. |
| SPF + DMARC DNS records | advanced | pass | SPF and DMARC records are present. |
| WP version not disclosed | wordpress | pass | No WordPress version found in generator meta or core asset URLs. |
| xmlrpc.php disabled | wordpress | fail | xmlrpc.php accepts POST requests (brute-force / pingback vector). |
| User enumeration blocked | wordpress | pass | No username leak across 3 enumeration probes. |
| readme.html removed | wordpress | pass | readme.html is not served. |
| Directory listing off | wordpress | pass | Uploads directory does not return an index page. |
| debug.log not public | wordpress | pass | debug.log is not served. |
| No config backups or installer | wordpress | warn | Installer /wp-admin/install.php is reachable. Harmless while the site is installed, but it becomes an open takeover path if the database is ever unreachable — block it in .htaccess. |
| Login not on default path | wordpress | warn | Login form is served on the default /wp-login.php path. |
---
# Page 4 of 5 — https://play.ee/et/meeskond
Run: 2026-09-24T09:55:00.892Z
## Audit Coverage
**94%** of audit sources returned data.
Missing or failed sources:
- PageSpeed Insights (mobile): PSI HTTP 429
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 14669 ms (mobile + desktop in parallel)._
_Mobile strategy errored (PSI HTTP 429); desktop data duplicated for both._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | 100 | 100 |
| Accessibility | 93 | 93 |
| Best Practices | 100 | 100 |
| SEO | 100 | 100 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | 0.6 s | 0.6 s |
| CLS | 0.003 | 0.003 |
| TBT | 0 ms | 0 ms |
| FCP | 586 ms | 586 ms |
| Speed Index | 748 ms | 748 ms |
| TTFB | 37 ms | 37 ms |
### Priority fixes
1. **document-latency-insight** (high) — Est savings of 440 ms
2. **network-dependency-tree-insight** (high)
3. **render-blocking-insight** (high) — Est savings of 250 ms
4. **unused-css-rules** (high) — Est savings of 30 KiB
5. **unused-javascript** (medium) — Est savings of 23 KiB
### Findings (mobile)
#### Unused JavaScript
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js — 23 KB wasted
#### Layout-shift sources
- div.main > footer.footer > h2.heading > span.heading__main — shift 0.003
- div.main > footer.footer > div.footer__bottom > ul.list — shift 0.000
- div.main > footer.footer > div.footer__bottom > ul.list — shift 0.000
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `landmark-one-main` (accessibility, score 0.00, weight 3) — Document does not have a main landmark.
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 2072 ms._
**Transport:**
- Final URL: https://play.ee/et/meeskond/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://play.ee/et/meeskond does not redirect to HTTPS (target: http://play.ee/et/meeskond/)
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 15 Sep 2026 08:42:10 GMT
- expires: Thu, 24 Sep 2026 09:55:02 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 28109
- Decoded body: 158.6 KB
- Compression ratio: 0.173
### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://play.ee/et/meeskond does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy weak** (high) — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (weak, high) `frame-ancestors 'self';` — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache`
- X-Powered-By: `PHP/8.3.33`
#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 28109
content-security-policy: frame-ancestors 'self';
content-type: text/html; charset=UTF-8
date: Thu, 24 Sep 2026 09:55:02 GMT
expires: Thu, 24 Sep 2026 09:55:02 GMT
keep-alive: timeout=5, max=100
last-modified: Tue, 15 Sep 2026 08:42:10 GMT
server: Apache
upgrade: h2,h2c
vary: Accept-Encoding
x-frame-options: SAMEORIGIN
x-powered-by: PHP/8.3.33
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1513 ms._
**Scoring:** 8 errors · 0 warnings · 23 cosmetic (suppressed)
> **Validator truncated at line 102** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.
### Priority fixes
1. **Parser recovery at line 102** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad value “” for attribute “href” on element “link”: Must be non-empty.** (medium) — x1, first at line 51
3. **Bad start tag in “iframe” in “noscript” in “head”.** (medium) — x1, first at line 99
4. **Stray end tag “noscript”.** (medium) — x1, first at line 99
5. **Attribute “name” not allowed on element “meta” at this point.** (medium) — x1, first at line 101
### Issue groups
- (×1) [error] Bad value “” for attribute “href” on element “link”: Must be non-empty. — first at line 51 `refetch">
<link data-rocket-prefetch href="" rel="dns-prefetch">
<meta`
- (×1) [error] Bad start tag in “iframe” in “noscript” in “head”. — first at line 99 `<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-K3P64XMJ"`
- (×1) [error] Stray end tag “noscript”. — first at line 99 `></iframe></noscript><!-- E`
- (×1) [error] Attribute “name” not allowed on element “meta” at this point. — first at line 101 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Element “meta” is missing one or more of the following attributes: “itemprop”, “property”. — first at line 101 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Stray end tag “head”. — first at line 101 `esktop" /></head>
<body`
- (×1) [error] Start tag “body” seen but an element of the same type was already open. — first at line 102 `/></head>
<body class="wp-singular page-template page-template-template-dynamic `
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 102 `/></head>
<body class="wp-singular page-template page-template-template-dynamic `
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 2167 ms._
**Scoring:** 3 violations · 32 passes · critical 0 · serious 1 · moderate 2 · minor 0
### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
3. **region** (medium) — All page content should be contained by landmarks
### Findings
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `h1 > .heading__main`
- `.how-we-do__intro > .heading--primary.heading > .heading__main`
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.header__nav`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.team-grid__intro`
- `.is-active`
- `.grid__col--sm-6.grid__col--md-4.team-grid__member:nth-child(1) > .person-card.team-grid__member-card > .person-card__content`
- `.grid__col--sm-6.grid__col--md-4.team-grid__member:nth-child(2) > .person-card.team-grid__member-card > .person-card__content`
- `.grid__col--sm-6.grid__col--md-4.team-grid__member:nth-child(3) > .person-card.team-grid__member-card > .person-card__figure > .person-card__image--workmode.person-card__image.image--background > .image__inner > img`
- … and 28 more nodes
### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 12 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 2179 ms._
**Capture summary:** 1 console events · 0 mixed-content requests · 14 network requests · 188.4 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| font | 3 | 57.6 KB |
| script | 4 | 45.6 KB |
| stylesheet | 2 | 34.2 KB |
| document | 2 | 27.5 KB |
| image | 1 | 18.1 KB |
| other | 1 | 5.5 KB |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 2 requests, 13.2 KB
- https://fast.fonts.net — 2 requests, 0 B
**Slowest requests (top 5):**
- https://play.ee/et/meeskond (document) — 528 ms, 0 B
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (script) — 41 ms, 3.0 KB
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (script) — 41 ms, 10.1 KB
- https://fast.fonts.net/t/1.css?apiType=css&projectid=d924b670-8ecc-46fd-9fff-80fd9989d037 (stylesheet) — 32 ms, 0 B
- https://fast.fonts.net/t/1.css?apiType=css&projectid=d924b670-8ecc-46fd-9fff-80fd9989d037 (xhr) — 24 ms, 0 B
### Findings
#### Console events
- [warning] Couldn't load preload assets:
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 2179 ms._
**Document:**
- Lang: et
- Title: Usaldusväärne full-stack arendus ja tehniline tugi
- Canonical: https://play.ee/et/meeskond/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 160414
**Meta tags:**
- Description: Siin on meie tragi punt ägedaid inimesi. Sinu päralt on full-stack arendus (nii front-end kui back-end arendus) ning alati valvel tehniline tugi.
- Robots: follow, index, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time)
- Twitter tags: 3
- hreflang:
- en → https://play.ee/team/
- et → https://play.ee/et/meeskond/
- x-default → https://play.ee/team/
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×21, h3 ×8, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: meie meeskonna
individuaalsed meistrid
- h2: Siim Sups
- h2: Hiie-Helen Raju
- h2: Ardo Gärtner
- h2: Pärt Erikson
- h2: Juhan Valge
- h2: Vladislav Stafinjak
- h2: Lauri Uue
- h2: Kuldar Jürma
- h2: Raiko Raidma
- h2: Sander Orav
- h2: Andres Kalle
- h2: Ivo Klaas
- h2: Timo Soiunen
- h2: Tanel Marran
- h2: Hannes Juurma
- h2: Raimond Kurm
- h2: Marianne Võime
- h2: Janeli Kurvits
- h2: Me oleme osa
play & nope alliance'st
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**
**Scripts:** 30 total — 3 defer, 0 async, 1 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/runtime.30d3b226dcf211e512b1.min.js
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js (defer)
**Stylesheets:** 1 external, 3 inline (9.6 KB)
**Images:** 45 total — **0 without alt**, **45 without width/height**, 45 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | wordpress support service / wordpress tu | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | vladislav | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 40 anchors — 23 external, 1 preconnect, 0 preload.
Vague repeated link text:
- "vaata meie instagrami" ×3
- "külasta meie facebooki lehte" ×3
- "külasta meie linkedin lehte" ×3
- "eng" ×3
- "est" ×3
- "styleguide" ×2
- "privaatsustingimused" ×2
- "osa play & nope alliance'st" ×2
### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **45 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **Vague link text repeated** (medium) — "vaata meie instagrami" ×3
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 3 pass · 0 warn · 0 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Response compressed (gzip / brotli) | ✓ pass | Document response is compressed with gzip. |
| Images lazy-loaded | – n/a | No raster <img> elements found (26 SVGs, 19 placeholders excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (26 SVGs, 19 placeholders excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (26 SVGs, 19 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.23.3.3`
- Response compressed (gzip / brotli):
- `content-encoding: gzip`
- `decoded body: 162442 bytes`
- `ratio: 0.173`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
## Security basics
_Captured in 0 ms._
**Verdict: FAILED**
> These are high-level hygiene checks on HTTP headers, TLS, cookies and a few well-known exposed paths. PASS means the basics are in place. It does **not** mean the site is secure: application logic, authentication, plugins, server configuration and dependencies are not tested here. Treat FAILED as a must-fix and PASS as a starting point, not a certificate.
| Check | Tier | Status | Detail |
| --- | --- | --- | --- |
| HTTP redirects to HTTPS | basic | fail | Plain HTTP does not redirect to HTTPS. |
| Strict-Transport-Security | basic | fail | Strict-Transport-Security header is missing. |
| Clickjacking protection | basic | pass | Framing is restricted. |
| X-Content-Type-Options | basic | fail | X-Content-Type-Options header is missing. |
| Cookies Secure + HttpOnly | basic | n/a | The document response sets no cookies. |
| No mixed content | basic | pass | No http:// subresources were loaded. |
| CORS | basic | pass | No wildcard CORS origin. |
| Technology disclosure | basic | warn | Response headers disclose server technology. |
| TLS certificate and protocol | basic | pass | Valid certificate and modern TLS protocol. |
| No exposed sensitive files | basic | pass | None of 6 probed sensitive paths returned real content. |
| Forms do not post to HTTP | basic | n/a | No forms on the page. |
| Content-Security-Policy present | advanced | pass | Content-Security-Policy header is set. |
| CSP is strict | advanced | fail | CSP has 2 issues: default-src missing; object-src is not 'none'. |
| HSTS preload | advanced | fail | Strict-Transport-Security header is missing. |
| Referrer-Policy | advanced | fail | Referrer-Policy header is missing. |
| Permissions-Policy | advanced | fail | Permissions-Policy header is missing. |
| Cross-Origin-Opener-Policy | advanced | fail | Cross-Origin-Opener-Policy header is missing. |
| Cross-Origin-Resource-Policy | advanced | fail | Cross-Origin-Resource-Policy header is missing. |
| Cookies SameSite | advanced | n/a | The document response sets no cookies. |
| Subresource Integrity | advanced | warn | 2 of 2 cross-origin scripts lack an integrity attribute. |
| SPF + DMARC DNS records | advanced | pass | SPF and DMARC records are present. |
| WP version not disclosed | wordpress | pass | No WordPress version found in generator meta or core asset URLs. |
| xmlrpc.php disabled | wordpress | fail | xmlrpc.php accepts POST requests (brute-force / pingback vector). |
| User enumeration blocked | wordpress | pass | No username leak across 3 enumeration probes. |
| readme.html removed | wordpress | pass | readme.html is not served. |
| Directory listing off | wordpress | pass | Uploads directory does not return an index page. |
| debug.log not public | wordpress | pass | debug.log is not served. |
| No config backups or installer | wordpress | warn | Installer /wp-admin/install.php is reachable. Harmless while the site is installed, but it becomes an open takeover path if the database is ever unreachable — block it in .htaccess. |
| Login not on default path | wordpress | warn | Login form is served on the default /wp-login.php path. |
---
# Page 5 of 5 — https://play.ee/wordpress-support-service
Run: 2026-09-24T09:55:16.366Z
## Audit Coverage
**88%** of audit sources returned data.
Missing or failed sources:
- PageSpeed Insights: mobile: PSI HTTP 429; desktop: PSI HTTP 429
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Error after 226 ms: mobile: PSI HTTP 429; desktop: PSI HTTP 429_
## Security Headers & HTTP
_Captured in 1719 ms._
**Transport:**
- Final URL: https://play.ee/wordpress-support-service/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://play.ee/wordpress-support-service does not redirect to HTTPS (target: http://play.ee/wordpress-support-service/)
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 15 Sep 2026 08:37:43 GMT
- expires: Thu, 24 Sep 2026 09:55:17 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 31016
- Decoded body: 184.1 KB
- Compression ratio: 0.165
### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://play.ee/wordpress-support-service does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy weak** (high) — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (weak, high) `frame-ancestors 'self';` — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache`
- X-Powered-By: `PHP/8.3.33`
#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 31016
content-security-policy: frame-ancestors 'self';
content-type: text/html; charset=UTF-8
date: Thu, 24 Sep 2026 09:55:17 GMT
expires: Thu, 24 Sep 2026 09:55:17 GMT
keep-alive: timeout=5, max=99
last-modified: Tue, 15 Sep 2026 08:37:43 GMT
server: Apache
vary: Accept-Encoding
x-frame-options: SAMEORIGIN
x-powered-by: PHP/8.3.33
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1221 ms._
**Scoring:** 7 errors · 0 warnings · 30 cosmetic (suppressed)
> **Validator truncated at line 107** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.
### Priority fixes
1. **Parser recovery at line 107** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad start tag in “iframe” in “noscript” in “head”.** (medium) — x1, first at line 104
3. **Stray end tag “noscript”.** (medium) — x1, first at line 104
4. **Attribute “name” not allowed on element “meta” at this point.** (medium) — x1, first at line 106
5. **Element “meta” is missing one or more of the following attributes: “itemprop”, “property”.** (medium) — x1, first at line 106
### Issue groups
- (×1) [error] Bad start tag in “iframe” in “noscript” in “head”. — first at line 104 `<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-K3P64XMJ"`
- (×1) [error] Stray end tag “noscript”. — first at line 104 `></iframe></noscript><!-- E`
- (×1) [error] Attribute “name” not allowed on element “meta” at this point. — first at line 106 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Element “meta” is missing one or more of the following attributes: “itemprop”, “property”. — first at line 106 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Stray end tag “head”. — first at line 106 `esktop" /></head>
<body`
- (×1) [error] Start tag “body” seen but an element of the same type was already open. — first at line 107 `/></head>
<body class="wp-singular page-template page-template-template-dynamic `
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 107 `/></head>
<body class="wp-singular page-template page-template-template-dynamic `
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 2473 ms._
**Scoring:** 4 violations · 32 passes · critical 0 · serious 2 · moderate 2 · minor 0
### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **link-name** (high) — Links must have discernible text
3. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
4. **region** (medium) — All page content should be contained by landmarks
### Findings
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `.button--tertiary > .button__inner > .button__text`
- `.grid__col--md-4.capabilities__grid-col.grid__col--sm-6:nth-child(1) > .heading--h5.capabilities__heading.h5 > .heading__small`
- `.grid__col--md-4.capabilities__grid-col.grid__col--sm-6:nth-child(2) > .heading--h5.capabilities__heading.h5 > .heading__small`
- `.grid__col--md-4.capabilities__grid-col.grid__col--sm-6:nth-child(3) > .heading--h5.capabilities__heading.h5 > .heading__small`
- `.grid__col--md-4.capabilities__grid-col.grid__col--sm-6:nth-child(4) > .heading--h5.capabilities__heading.h5 > .heading__small`
- … and 10 more nodes
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.header__nav`
#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.logo-grid__row.js-in-viewport:nth-child(1) > .logo-grid__item:nth-child(1) > .logo-grid__link[href=""][rel="noopener"]`
- `.logo-grid__row.js-in-viewport:nth-child(1) > .logo-grid__item:nth-child(2) > .logo-grid__link[href=""][rel="noopener"]`
- `.logo-grid__row.js-in-viewport:nth-child(1) > .logo-grid__item:nth-child(3) > .logo-grid__link[href=""][rel="noopener"]`
- `.logo-grid__row.js-in-viewport:nth-child(2) > .logo-grid__item:nth-child(1) > .logo-grid__link[href=""][rel="noopener"]`
- `.logo-grid__row.js-in-viewport:nth-child(2) > .logo-grid__item:nth-child(2) > .logo-grid__link[href=""][rel="noopener"]`
- … and 4 more nodes
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.contact-hero__intro > h1`
- `.intro__content > p:nth-child(2)`
- `p:nth-child(3)`
- `.button--tertiary`
- `canvas`
- … and 95 more nodes
### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 15 nodes
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 2489 ms._
**Capture summary:** 1 console events · 0 mixed-content requests · 25 network requests · 201.9 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| font | 3 | 57.6 KB |
| script | 5 | 53.5 KB |
| stylesheet | 2 | 34.2 KB |
| document | 2 | 30.3 KB |
| image | 11 | 20.8 KB |
| other | 1 | 5.5 KB |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 2 requests, 13.2 KB
- https://fast.fonts.net — 2 requests, 0 B
**Slowest requests (top 5):**
- https://play.ee/wordpress-support-service (document) — 411 ms, 0 B
- https://play.ee/wordpress-support-service/ (document) — 81 ms, 30.3 KB
- https://fast.fonts.net/t/1.css?apiType=css&projectid=d924b670-8ecc-46fd-9fff-80fd9989d037 (stylesheet) — 38 ms, 0 B
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (script) — 29 ms, 3.0 KB
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (script) — 28 ms, 10.1 KB
### Findings
#### Console events
- [warning] Couldn't load preload assets:
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 2489 ms._
**Document:**
- Lang: en
- Title: WordPress support service
- Canonical: https://play.ee/wordpress-support-service/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 187229
**Meta tags:**
- Description: From ongoing WordPress support to health monitoring and expert fixes, we take care of your website so you can spend more time building your business.
- Robots: follow, index, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 13 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time, og:image, og:image:secure_url, og:image:width, og:image:height, og:image:alt, og:image:type)
- Twitter tags: 4
- hreflang:
- en → https://play.ee/wordpress-support-service/
- et → https://play.ee/et/tugiteenus/
- x-default → https://play.ee/wordpress-support-service/
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×2, h2 ×16, h3 ×14, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Your worry-free
WordPress website
- h2: Why choose our
WordPress support service
- h3: #1
peace of mind
- h3: #2
security first
- h3: #3
expert team on-call
- h3: #4
performance wins
- h3: #5
save money
- h3: #6
monthly health reports
- h3: #7
collaboration
- h3: #8
extensive network
- h3: #9
top notch tools
- h2: service by professionals who
build websites for a l
- h2: customizable & transparent
Pricing
- h2: <Basic/>
- h2: <Advanced/>
- h2: <Pro/>
- h2: five-step
onboarding process
- h1: additional services
to upgrade your online presence
- h2: UX/UI audit
- h2: WCAG audit
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**
**Scripts:** 27 total — 3 defer, 1 async, 1 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/runtime.30d3b226dcf211e512b1.min.js
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js (defer)
- https://play.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)
**Stylesheets:** 1 external, 3 inline (9.6 KB)
**Images:** 31 total — **0 without alt**, **31 without width/height**, 31 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | Expert WordPress support service | _n/a_ | _n/a_ | ✗ |
| p-content/themes/gotoandplay/inc/theme/img/line-1-mobile.svg | line-1 | _n/a_ | _n/a_ | ✗ |
| ay.ee/wp-content/themes/gotoandplay/inc/theme/img/line-1.svg | line-1 | _n/a_ | _n/a_ | ✗ |
| p-content/themes/gotoandplay/inc/theme/img/line-2-mobile.svg | line-2 | _n/a_ | _n/a_ | ✗ |
| ay.ee/wp-content/themes/gotoandplay/inc/theme/img/line-2.svg | line-2 | _n/a_ | _n/a_ | ✗ |
| p-content/themes/gotoandplay/inc/theme/img/line-3-mobile.svg | line-3 | _n/a_ | _n/a_ | ✗ |
| ay.ee/wp-content/themes/gotoandplay/inc/theme/img/line-3.svg | line-3 | _n/a_ | _n/a_ | ✗ |
| p-content/themes/gotoandplay/inc/theme/img/line-4-mobile.svg | line-4 | _n/a_ | _n/a_ | ✗ |
| ay.ee/wp-content/themes/gotoandplay/inc/theme/img/line-4.svg | line-4 | _n/a_ | _n/a_ | ✗ |
| p-content/themes/gotoandplay/inc/theme/img/line-5-mobile.svg | line-5 | _n/a_ | _n/a_ | ✗ |
| ay.ee/wp-content/themes/gotoandplay/inc/theme/img/line-5.svg | line-5 | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 57 anchors — 17 external, 2 preconnect, 0 preload.
Vague repeated link text:
- "get in touch" ×14
- "view our instagram feed" ×3
- "visit our facebook page" ×3
- "visit our linkedin page" ×3
- "eng" ×3
- "est" ×3
- "styleguide" ×2
- "privacy policy" ×2
### Priority fixes
1. **Document has 2 <h1> elements** (medium) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **31 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 3 pass · 0 warn · 0 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Response compressed (gzip / brotli) | ✓ pass | Document response is compressed with gzip. |
| Images lazy-loaded | – n/a | No raster <img> elements found (24 SVGs, 7 placeholders excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (24 SVGs, 7 placeholders excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (24 SVGs, 7 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.23.3.3`
- Response compressed (gzip / brotli):
- `content-encoding: gzip`
- `decoded body: 188490 bytes`
- `ratio: 0.165`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
## Security basics
_Captured in 0 ms._
**Verdict: FAILED**
> These are high-level hygiene checks on HTTP headers, TLS, cookies and a few well-known exposed paths. PASS means the basics are in place. It does **not** mean the site is secure: application logic, authentication, plugins, server configuration and dependencies are not tested here. Treat FAILED as a must-fix and PASS as a starting point, not a certificate.
| Check | Tier | Status | Detail |
| --- | --- | --- | --- |
| HTTP redirects to HTTPS | basic | fail | Plain HTTP does not redirect to HTTPS. |
| Strict-Transport-Security | basic | fail | Strict-Transport-Security header is missing. |
| Clickjacking protection | basic | pass | Framing is restricted. |
| X-Content-Type-Options | basic | fail | X-Content-Type-Options header is missing. |
| Cookies Secure + HttpOnly | basic | n/a | The document response sets no cookies. |
| No mixed content | basic | pass | No http:// subresources were loaded. |
| CORS | basic | pass | No wildcard CORS origin. |
| Technology disclosure | basic | warn | Response headers disclose server technology. |
| TLS certificate and protocol | basic | pass | Valid certificate and modern TLS protocol. |
| No exposed sensitive files | basic | pass | None of 6 probed sensitive paths returned real content. |
| Forms do not post to HTTP | basic | n/a | No forms on the page. |
| Content-Security-Policy present | advanced | pass | Content-Security-Policy header is set. |
| CSP is strict | advanced | fail | CSP has 2 issues: default-src missing; object-src is not 'none'. |
| HSTS preload | advanced | fail | Strict-Transport-Security header is missing. |
| Referrer-Policy | advanced | fail | Referrer-Policy header is missing. |
| Permissions-Policy | advanced | fail | Permissions-Policy header is missing. |
| Cross-Origin-Opener-Policy | advanced | fail | Cross-Origin-Opener-Policy header is missing. |
| Cross-Origin-Resource-Policy | advanced | fail | Cross-Origin-Resource-Policy header is missing. |
| Cookies SameSite | advanced | n/a | The document response sets no cookies. |
| Subresource Integrity | advanced | warn | 2 of 2 cross-origin scripts lack an integrity attribute. |
| SPF + DMARC DNS records | advanced | pass | SPF and DMARC records are present. |
| WP version not disclosed | wordpress | pass | No WordPress version found in generator meta or core asset URLs. |
| xmlrpc.php disabled | wordpress | fail | xmlrpc.php accepts POST requests (brute-force / pingback vector). |
| User enumeration blocked | wordpress | pass | No username leak across 3 enumeration probes. |
| readme.html removed | wordpress | pass | readme.html is not served. |
| Directory listing off | wordpress | pass | Uploads directory does not return an index page. |
| debug.log not public | wordpress | pass | debug.log is not served. |
| No config backups or installer | wordpress | warn | Installer /wp-admin/install.php is reachable. Harmless while the site is installed, but it becomes an open takeover path if the database is ever unreachable — block it in .htaccess. |
| Login not on default path | wordpress | warn | Login form is served on the default /wp-login.php path. |