20260924T101051Z-44da
- Audited URL
- https://play.ee/
- Timestamp
- 2026-09-24T10:14:51.854Z
- Kind
- site
- Pages
- 5
Weighted audit summary
Site overall 75 is the mean of 4 pages. Scores range 72 (https://play.ee/et/meeskond) → 78 (https://play.ee/team). Weakest page: Mobile PSI 83 with CLS 0.23 and LCP 2.6s indicates moderate performance issues. Security Basics FAILED due to missing HSTS and HTTP redirect, capping the score below 90. One serious accessibility violation on color contrast and 45 images missing dimensions further reduce quality. W3C validation shows 8 errors including parser recovery failure. Confidence is high as all audit tools returned data.
Audit Report: Perfectly formed web development team - gotoAndPlay
Website: https://play.ee/
Date: 24.09.2026
Audit Coverage: 98% — PageSpeed Insights: mobile: PSI HTTP 429; desktop: PSI HTTP 429
Confidence: low
Pages Audited (5 of 5):
- https://play.ee/
- https://play.ee/team
- https://play.ee/privacy-policy
- https://play.ee/et/meeskond
- https://play.ee/wordpress-support-service
Summary of results
Overall Score: 75 / 100
Status: ⚠ 🟡 Needs Improvement
Site overall 75 is the mean of 4 pages. Scores range 72 (https://play.ee/et/meeskond) → 78 (https://play.ee/team). Weakest page: Mobile PSI 83 with CLS 0.23 and LCP 2.6s indicates moderate performance issues. Security Basics FAILED due to missing HSTS and HTTP redirect, capping the score below 90. One serious accessibility violation on color contrast and 45 images missing dimensions further reduce quality. W3C validation shows 8 errors including parser recovery failure. Confidence is high as all audit tools returned data.
Per-page scores
🟡 Needs Improvement · https://play.ee/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 76 | 97 | 94 | 100 | 92 | FAILED |
🟡 Needs Improvement · https://play.ee/team
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 78 | 95 | 94 | 100 | 100 | FAILED |
🟡 Needs Improvement · https://play.ee/privacy-policy
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 74 | 94 | 87 | 100 | 100 | FAILED |
🟡 Needs Improvement · https://play.ee/et/meeskond
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 72 | 83 | 94 | 100 | 100 | FAILED |
— · https://play.ee/wordpress-support-service
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| — | — | — | — | — | FAILED |
PageSpeed Insights — Mobile vs Desktop
Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.
| URL | Performance (M / D) | LCP (M / D) | CLS (M / D) |
|---|---|---|---|
| https://play.ee/ | 97 / 100 | 2.33 s / 548 ms | 0.001 / 0.006 |
| https://play.ee/team | 95 / 99 | 2.58 s / 645 ms | 0.036 / 0.003 |
| https://play.ee/privacy-policy | 94 / 99 | 2.73 s / 788 ms | 0.002 / 0.003 |
| https://play.ee/et/meeskond | 83 / 100 | 2.63 s / 704 ms | 0.230 / 0.004 |
Optimization Checklist
3 of 3 passing — 3 pass · 0 warn · 0 fail · 5 n/a
| Item | Status | Detail |
|---|---|---|
| Page caching plugin / CDN active | Pass | Caching plugin detected (WP Rocket) |
| Response compressed (gzip / brotli) | Pass | Document response is compressed with gzip. |
| Images lazy-loaded | N/A | No raster <img> elements found (37 SVGs, 13 placeholders excluded). |
| Hero image eagerly loaded | N/A | No raster <img> elements found (37 SVGs, 13 placeholders excluded). |
| Hero is a real <img> (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | N/A | Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | Pass | No render-blocking scripts in <head>. |
Fixes
Priority 1: Critical
Immediate action — impacts user experience, search rankings, or site safety.
1A. Fix HTTP redirect and add baseline security headers Security
- Impact: Transport security, clickjacking, MIME sniffing
- Problem: Security Basics FAILED: http://play.ee/ does not redirect to HTTPS, HSTS is missing, and X-Content-Type-Options is missing.
- Solution:
Configure server to redirect HTTP to HTTPS and send these headers:
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" Header always set X-Content-Type-Options "nosniff" RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
1B. Fix color contrast failures Accessibility
- Impact: WCAG 1.4.3 Contrast
- Problem: PSI Accessibility audit
color-contrastfailed with score 0.00, indicating insufficient contrast on foreground/background elements. - Solution: Audit all text elements against WCAG 2.1 AA (4.5:1 for normal text). Increase contrast ratios on low-contrast text blocks identified in the PSI report.
1C. Fix color contrast on headings and buttons Accessibility
- Impact: WCAG 1.4.3 Contrast, Screen Reader usability
- Problem: axe-core reports 1 serious violation: color-contrast on h1 > .heading__main and .button elements.
- Solution:
Increase contrast ratio to at least 4.5:1 for normal text.
- Adjust
.heading__maincolor to darker shade (e.g., #333 on #fff). - Adjust
.buttontext/background colors to meet AA standards.
- Adjust
1D. Add baseline security headers and enforce HTTPS Security
- Impact: Transport security, clickjacking, MIME sniffing
- Problem: Security basics verdict FAILED: HTTP does not redirect to HTTPS, HSTS missing, X-Content-Type-Options missing.
- Solution: Configure server to redirect HTTP to HTTPS, add HSTS (max-age=31536000; includeSubDomains), and X-Content-Type-Options: nosniff.
1E. Add explicit width and height to images Performance
- Impact: CLS, LCP
- Problem: CLS 0.23 (warning) and 45 images missing width/height attributes in HTML inventory.
- Solution:
Add
widthandheightattributes to all<img>tags or use CSS aspect-ratio to reserve space.
Priority 2: Important
Essential for compliance, user reach, and search visibility.
2A. Fix W3C HTML validation errors SEO
- Impact: Rendering, SEO, Maintainability
- Problem: W3C Validator reported 7 errors including parser recovery failure at line 101 and invalid iframe placement in noscript within head.
- Solution:
Move
<noscript><iframe>...</iframe></noscript>out of<head>and into<body>. Ensure<meta>tags in head do not use invalid attributes likenamewherepropertyis required.
2B. Harden WordPress installation Security
- Impact: Brute-force protection, Attack surface
- Problem: xmlrpc.php accepts POST requests (brute-force vector) and /wp-admin/install.php is reachable.
- Solution:
Disable xmlrpc.php via .htaccess or plugin. Block access to /wp-admin/install.php after installation:
<Files "install.php"> Require all denied </Files>
2C. Fix color contrast and add main landmark Accessibility
- Impact: WCAG 1.4.3 contrast, 1.3.1 info and relationships
- Problem: axe-core found 1 serious color-contrast violation on headings and missing
mainlandmark (PSI Accessibility 94 but axe found issues). - Solution:
- Increase contrast on
.heading__mainto ≥4.5:1. - Wrap primary content in
<main>tag. - Add
<a href="#content" class="skip-link">Skip to content</a>before navigation.
- Increase contrast on
2D. Resolve W3C HTML validation errors Best Practices
- Impact: SEO indexing, rendering stability
- Problem: W3C validator reported 7 errors including parser recovery failure at line 105 (iframe/noscript in head).
- Solution:
- Move
<noscript><iframe>...</iframe></noscript>out of<head>(allowed in<body>). - Fix stray
</noscript>and</head>tags. - Ensure
<meta>tags use valid attributes (propertyoritempropinstead ofnamewhere required).
- Move
2E. Add baseline security headers (HSTS, HTTP redirect, X-Content-Type-Options) Security
- Impact: Transport security, Clickjacking, MIME sniffing
- Problem: Security Basics verdict is FAILED: HTTP does not redirect to HTTPS, HSTS missing, X-Content-Type-Options missing.
- Solution:
Configure server to enforce HTTPS and send headers:
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" Header always set X-Content-Type-Options "nosniff" RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
2F. Fix HTML validation errors (Parser recovery, iframe in noscript) Best Practices
- Impact: SEO, Rendering consistency
- Problem: W3C Validator reports 7 errors including parser recovery failure at line 100 and bad start tag in iframe in noscript in head.
- Solution:
Move Google Tag Manager iframe out of
<head>or ensure proper<noscript>nesting.- Remove
<meta name="generator">or ensure it complies with HTML5 spec. - Validate HTML structure to prevent parser recovery mode.
- Remove
2G. Fix color contrast on headings Accessibility
- Impact: WCAG 1.4.3
- Problem: axe-core reports 1 serious violation: color-contrast on h1 and .heading__main.
- Solution: Increase contrast ratio to ≥4.5:1 for text against background (e.g., darken text or lighten background).
2H. Harden WordPress security endpoints Security
- Impact: Brute-force protection
- Problem: xmlrpc.php accepts POST requests and /wp-admin/install.php is reachable.
- Solution: Disable xmlrpc.php via .htaccess or plugin, and block access to /wp-admin/install.php after installation.
Priority 3: Best Practice
Recommended for long-term maintainability.
3A. Add explicit width and height to images Performance
- Impact: CLS, Layout stability
- Problem: HTML Inventory shows 50 images without width/height attributes, risking layout shifts on load.
- Solution:
Add
widthandheightattributes to all<img>tags matching their intrinsic dimensions. For responsive images, usewidthandheighton the<img>tag andsrcseton the source.
3B. Harden Content-Security-Policy (CSP) Security
- Impact: XSS defense-in-depth
- Problem: CSP is present but weak (missing
default-src,object-src 'none'). Site signals show no auth/payments, so this is lower priority. - Solution:
Update CSP to include restrictive defaults:
Header always set Content-Security-Policy "default-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self';"
3C. Optimize Largest Contentful Paint (LCP) Performance
- Impact: LCP, FCP, Perceived load speed
- Problem: Mobile LCP is 2.7s (warning range) with render-blocking insights estimating 1,030ms savings.
- Solution:
- Preload critical fonts and LCP image.
- Defer non-critical JavaScript.
- Ensure server response time (TTFB 34ms is good) remains low under load.
▸Raw Markdown sent to the LLM
# Site Audit — https://play.ee/
Run: 2026-09-24T10:10:51.767Z
Audited **5** of 5 discovered pages.
Average per-page audit coverage: **98%**
Aggregate missing or failed sources (deduped across pages):
- PageSpeed Insights: mobile: PSI HTTP 429; desktop: PSI HTTP 429
Pages audited:
- https://play.ee/
- https://play.ee/team
- https://play.ee/privacy-policy
- https://play.ee/et/meeskond
- https://play.ee/wordpress-support-service
---
# Page 1 of 5 — https://play.ee/
Run: 2026-09-24T10:10:53.795Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 18641 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **97** | 100 |
| Accessibility | **94** | 95 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **2.3 s** | 0.5 s |
| CLS | 0.001 | **0.006** |
| TBT | 0 ms | 0 ms |
| FCP | **1.96 s** | 487 ms |
| Speed Index | **1.96 s** | 705 ms |
| TTFB | 8 ms | **42 ms** |
### Priority fixes
1. **first-contentful-paint** (low) — 2.0 s
2. **network-dependency-tree-insight** (high)
3. **render-blocking-insight** (high) — Est savings of 1,050 ms
4. **unused-css-rules** (high) — Est savings of 30 KiB
5. **unused-javascript** (medium) — Est savings of 23 KiB
### Findings (mobile)
#### Unused JavaScript
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js — 23 KB wasted
#### Layout-shift sources
- footer.footer > h2.heading > span.heading__main > a.link — shift 0.001
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.85, weight 10) — First Contentful Paint — 2.0 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 9 links found
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 1337 ms._
**Transport:**
- Final URL: https://play.ee/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://play.ee/ does not redirect to HTTPS (target: none)
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 15 Sep 2026 08:38:43 GMT
- expires: Thu, 24 Sep 2026 10:10:53 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 35451
- Decoded body: 216.5 KB
- Compression ratio: 0.16
### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://play.ee/ does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy weak** (high) — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (weak, high) `frame-ancestors 'self';` — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache`
- X-Powered-By: `PHP/8.3.33`
#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 35451
content-security-policy: frame-ancestors 'self';
content-type: text/html; charset=UTF-8
date: Thu, 24 Sep 2026 10:10:53 GMT
expires: Thu, 24 Sep 2026 10:10:53 GMT
keep-alive: timeout=5, max=100
last-modified: Tue, 15 Sep 2026 08:38:43 GMT
server: Apache
upgrade: h2,h2c
vary: Accept-Encoding
x-frame-options: SAMEORIGIN
x-powered-by: PHP/8.3.33
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 807 ms._
**Scoring:** 7 errors · 0 warnings · 23 cosmetic (suppressed)
> **Validator truncated at line 101** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.
### Priority fixes
1. **Parser recovery at line 101** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad start tag in “iframe” in “noscript” in “head”.** (medium) — x1, first at line 98
3. **Stray end tag “noscript”.** (medium) — x1, first at line 98
4. **Attribute “name” not allowed on element “meta” at this point.** (medium) — x1, first at line 100
5. **Element “meta” is missing one or more of the following attributes: “itemprop”, “property”.** (medium) — x1, first at line 100
### Issue groups
- (×1) [error] Bad start tag in “iframe” in “noscript” in “head”. — first at line 98 `<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-K3P64XMJ"`
- (×1) [error] Stray end tag “noscript”. — first at line 98 `></iframe></noscript><!-- E`
- (×1) [error] Attribute “name” not allowed on element “meta” at this point. — first at line 100 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Element “meta” is missing one or more of the following attributes: “itemprop”, “property”. — first at line 100 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Stray end tag “head”. — first at line 100 `esktop" /></head>
<body`
- (×1) [error] Start tag “body” seen but an element of the same type was already open. — first at line 101 `/></head>
<body class="home wp-singular page-template page-template-template-dyn`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 101 `/></head>
<body class="home wp-singular page-template page-template-template-dyn`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 2234 ms._
**Scoring:** 2 violations · 32 passes · critical 0 · serious 0 · moderate 2 · minor 0
### Priority fixes
1. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
2. **region** (medium) — All page content should be contained by landmarks
### Findings
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.header__nav`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.home-hero__main`
- `.home-hero__bottom`
- `canvas`
- `.keywords__mouse`
- `.keywords__intro`
- … and 31 more nodes
### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 38 nodes
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 2248 ms._
**Capture summary:** 1 console events · 0 mixed-content requests · 13 network requests · 178.1 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| font | 3 | 57.6 KB |
| script | 4 | 45.6 KB |
| document | 1 | 34.6 KB |
| stylesheet | 2 | 34.2 KB |
| other | 1 | 5.5 KB |
| image | 1 | 576 B |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 2 requests, 13.2 KB
- https://fast.fonts.net — 2 requests, 0 B
**Slowest requests (top 5):**
- https://play.ee/ (document) — 530 ms, 34.6 KB
- https://fast.fonts.net/t/1.css?apiType=css&projectid=d924b670-8ecc-46fd-9fff-80fd9989d037 (stylesheet) — 54 ms, 0 B
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (script) — 25 ms, 3.0 KB
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (script) — 24 ms, 10.1 KB
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/runtime.30d3b226dcf211e512b1.min.js (script) — 19 ms, 1.0 KB
### Findings
#### Console events
- [warning] Couldn't load preload assets:
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 2248 ms._
**Document:**
- Lang: en
- Title: Perfectly formed web development team - gotoAndPlay
- Canonical: https://play.ee/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 217719
**Meta tags:**
- Description: Small, agile web development team working on big ideas in close collaboration with our clients. Result driven from day one!
- Robots: follow, index, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time)
- Twitter tags: 3
- hreflang:
- en → http://play.ee/
- et → http://play.ee/et/
- x-default → http://play.ee/
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×6, h3 ×5, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: we create memorable experiences with
web technologi
- h2: Your result
- h2: we offer
more than expected
- h2: Üks
- h2: meet the team of
uncommon talent
- h2: proof to our approach are
happy clients
- h3: Deliverables with high quality standards
- h3: Working with gotoAndPlay is a great experience
- h3: Speed, attitude, skills!
- h3: Hardworking, fun & ready to adopt new technologies
- h3: The sky is the limit
- h2: take a look at our
case studies
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**
**Scripts:** 23 total — 3 defer, 0 async, 1 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/runtime.30d3b226dcf211e512b1.min.js
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js (defer)
**Stylesheets:** 1 external, 3 inline (9.6 KB)
**Images:** 50 total — **0 without alt**, **50 without width/height**, 50 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| ee/wp-content/themes/gotoandplay/inc/theme/img/landscape.svg | Please turn your device sideways | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 46 anchors — 34 external, 1 preconnect, 0 preload.
Vague repeated link text:
- "read more" ×9
- "view our instagram feed" ×3
- "visit our facebook page" ×3
- "visit our linkedin page" ×3
- "eng" ×3
- "est" ×3
- "case studies" ×2
- "styleguide" ×2
- "privacy policy" ×2
**Forms:**
Form 1:
- text — labeled
### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **50 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **Vague link text repeated** (medium) — "read more" ×9
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 3 pass · 0 warn · 0 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Response compressed (gzip / brotli) | ✓ pass | Document response is compressed with gzip. |
| Images lazy-loaded | – n/a | No raster <img> elements found (37 SVGs, 13 placeholders excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (37 SVGs, 13 placeholders excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.23.3.3`
- Response compressed (gzip / brotli):
- `content-encoding: gzip`
- `decoded body: 221727 bytes`
- `ratio: 0.16`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
## Security basics
_Captured in 0 ms._
**Verdict: FAILED**
> These are high-level hygiene checks on HTTP headers, TLS, cookies and a few well-known exposed paths. PASS means the basics are in place. It does **not** mean the site is secure: application logic, authentication, plugins, server configuration and dependencies are not tested here. Treat FAILED as a must-fix and PASS as a starting point, not a certificate.
| Check | Tier | Status | Detail |
| --- | --- | --- | --- |
| HTTP redirects to HTTPS | basic | fail | Plain HTTP does not redirect to HTTPS. |
| Strict-Transport-Security | basic | fail | Strict-Transport-Security header is missing. |
| Clickjacking protection | basic | pass | Framing is restricted. |
| X-Content-Type-Options | basic | fail | X-Content-Type-Options header is missing. |
| Cookies Secure + HttpOnly | basic | n/a | The document response sets no cookies. |
| No mixed content | basic | pass | No http:// subresources were loaded. |
| CORS | basic | pass | No wildcard CORS origin. |
| Technology disclosure | basic | warn | Response headers disclose server technology. |
| TLS certificate and protocol | basic | pass | Valid certificate and modern TLS protocol. |
| No exposed sensitive files | basic | pass | None of 6 probed sensitive paths returned real content. |
| Forms do not post to HTTP | basic | pass | No form action uses http://. |
| Content-Security-Policy present | advanced | pass | Content-Security-Policy header is set. |
| CSP is strict | advanced | fail | CSP has 2 issues: default-src missing; object-src is not 'none'. |
| HSTS preload | advanced | fail | Strict-Transport-Security header is missing. |
| Referrer-Policy | advanced | fail | Referrer-Policy header is missing. |
| Permissions-Policy | advanced | fail | Permissions-Policy header is missing. |
| Cross-Origin-Opener-Policy | advanced | fail | Cross-Origin-Opener-Policy header is missing. |
| Cross-Origin-Resource-Policy | advanced | fail | Cross-Origin-Resource-Policy header is missing. |
| Cookies SameSite | advanced | n/a | The document response sets no cookies. |
| Subresource Integrity | advanced | warn | 2 of 2 cross-origin scripts lack an integrity attribute. |
| SPF + DMARC DNS records | advanced | pass | SPF and DMARC records are present. |
| WP version not disclosed | wordpress | pass | No WordPress version found in generator meta or core asset URLs. |
| xmlrpc.php disabled | wordpress | fail | xmlrpc.php accepts POST requests (brute-force / pingback vector). |
| User enumeration blocked | wordpress | pass | No username leak across 3 enumeration probes. |
| readme.html removed | wordpress | pass | readme.html is not served. |
| Directory listing off | wordpress | pass | Uploads directory does not return an index page. |
| debug.log not public | wordpress | pass | debug.log is not served. |
| No config backups or installer | wordpress | warn | Installer /wp-admin/install.php is reachable. Harmless while the site is installed, but it becomes an open takeover path if the database is ever unreachable — block it in .htaccess. |
| Login not on default path | wordpress | warn | Login form is served on the default /wp-login.php path. |
---
# Page 2 of 5 — https://play.ee/team
Run: 2026-09-24T10:10:53.795Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 19117 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **95** | 99 |
| Accessibility | 94 | **93** |
| Best Practices | 100 | 100 |
| SEO | 100 | 100 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **2.6 s** | 0.6 s |
| CLS | **0.036** | 0.003 |
| TBT | 0 ms | 0 ms |
| FCP | **2.20 s** | 588 ms |
| Speed Index | **2.30 s** | 934 ms |
| TTFB | **43 ms** | 3 ms |
### Priority fixes
1. **largest-contentful-paint** (low) — 2.6 s
2. **first-contentful-paint** (low) — 2.2 s
3. **document-latency-insight** (high) — Est savings of 610 ms
4. **network-dependency-tree-insight** (high)
5. **render-blocking-insight** (high) — Est savings of 1,070 ms
### Findings (mobile)
#### Unused JavaScript
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js — 23 KB wasted
#### Layout-shift sources
- div.team-grid > div.team-grid__inner > div.intro > div.intro__content — shift 0.036
- div.main > footer.footer > div.footer__bottom > ul.list — shift 0.000
- footer.footer > div.footer__bottom > a.footer__copyright > b — shift 0.000
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `largest-contentful-paint` (performance, score 0.88, weight 25) — Largest Contentful Paint — 2.6 s
- `landmark-one-main` (accessibility, score 0.00, weight 3) — Document does not have a main landmark.
- `first-contentful-paint` (performance, score 0.78, weight 10) — First Contentful Paint — 2.2 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 1400 ms._
**Transport:**
- Final URL: https://play.ee/team/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://play.ee/team does not redirect to HTTPS (target: http://play.ee/team/)
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 15 Sep 2026 11:35:03 GMT
- expires: Thu, 24 Sep 2026 10:10:54 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 28364
- Decoded body: 169.4 KB
- Compression ratio: 0.163
### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://play.ee/team does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy weak** (high) — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (weak, high) `frame-ancestors 'self';` — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache`
- X-Powered-By: `PHP/8.3.33`
#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 28364
content-security-policy: frame-ancestors 'self';
content-type: text/html; charset=UTF-8
date: Thu, 24 Sep 2026 10:10:54 GMT
expires: Thu, 24 Sep 2026 10:10:54 GMT
keep-alive: timeout=5, max=99
last-modified: Tue, 15 Sep 2026 11:35:03 GMT
server: Apache
vary: Accept-Encoding
x-frame-options: SAMEORIGIN
x-powered-by: PHP/8.3.33
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1652 ms._
**Scoring:** 7 errors · 0 warnings · 23 cosmetic (suppressed)
> **Validator truncated at line 105** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.
### Priority fixes
1. **Parser recovery at line 105** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad start tag in “iframe” in “noscript” in “head”.** (medium) — x1, first at line 102
3. **Stray end tag “noscript”.** (medium) — x1, first at line 102
4. **Attribute “name” not allowed on element “meta” at this point.** (medium) — x1, first at line 104
5. **Element “meta” is missing one or more of the following attributes: “itemprop”, “property”.** (medium) — x1, first at line 104
### Issue groups
- (×1) [error] Bad start tag in “iframe” in “noscript” in “head”. — first at line 102 `<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-K3P64XMJ"`
- (×1) [error] Stray end tag “noscript”. — first at line 102 `></iframe></noscript><!-- E`
- (×1) [error] Attribute “name” not allowed on element “meta” at this point. — first at line 104 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Element “meta” is missing one or more of the following attributes: “itemprop”, “property”. — first at line 104 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Stray end tag “head”. — first at line 104 `esktop" /></head>
<body`
- (×1) [error] Start tag “body” seen but an element of the same type was already open. — first at line 105 `/></head>
<body class="wp-singular page-template page-template-template-dynamic `
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 105 `/></head>
<body class="wp-singular page-template page-template-template-dynamic `
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 2712 ms._
**Scoring:** 3 violations · 32 passes · critical 0 · serious 1 · moderate 2 · minor 0
### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
3. **region** (medium) — All page content should be contained by landmarks
### Findings
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `h1 > .heading__main`
- `.how-we-do__intro > .heading--primary.heading > .heading__main`
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.header__nav`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.team-grid__intro`
- `.is-active`
- `.grid__col--sm-6.grid__col--md-4.team-grid__member:nth-child(1) > .person-card.team-grid__member-card > .person-card__content`
- `.grid__col--sm-6.grid__col--md-4.team-grid__member:nth-child(2) > .person-card.team-grid__member-card > .person-card__content`
- `.grid__col--sm-6.grid__col--md-4.team-grid__member:nth-child(3) > .person-card.team-grid__member-card > .person-card__figure > .person-card__image--workmode.person-card__image.image--background > .image__inner > img`
- … and 35 more nodes
### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 10 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 7 nodes
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 2724 ms._
**Capture summary:** 1 console events · 0 mixed-content requests · 14 network requests · 188.7 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| font | 3 | 57.6 KB |
| script | 4 | 45.6 KB |
| stylesheet | 2 | 34.2 KB |
| document | 2 | 27.7 KB |
| image | 1 | 18.1 KB |
| other | 1 | 5.5 KB |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 2 requests, 13.2 KB
- https://fast.fonts.net — 2 requests, 0 B
**Slowest requests (top 5):**
- https://play.ee/team/ (document) — 464 ms, 27.7 KB
- https://play.ee/team (document) — 406 ms, 0 B
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/fonts/1c0243aa-c535-4d42-ac53-d6f0f74a1412.bd94708352cbb3b4863c.woff2 (font) — 309 ms, 19.3 KB
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/fonts/fc2fa85e-cd2d-4004-930a-8adad6c60317.3bd2a5f3705d9fb438c5.woff2 (font) — 309 ms, 19.3 KB
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/fonts/f389f79b-6013-4448-aa6a-b6fd235eab80.b91a05bafb09e626383a.woff2 (font) — 309 ms, 19.0 KB
### Findings
#### Console events
- [warning] Couldn't load preload assets:
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 2724 ms._
**Document:**
- Lang: en
- Title: Expert full-stack development & technical support
- Canonical: https://play.ee/team/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 171666
**Meta tags:**
- Description: Meet our team of amazing people! At your service is our expert full-stack development team and an ever-ready technical support.
- Robots: follow, index, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time)
- Twitter tags: 3
- hreflang:
- en → https://play.ee/team/
- et → https://play.ee/et/meeskond/
- x-default → https://play.ee/team/
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×21, h3 ×8, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: meet our team of
individual masters
- h2: Siim Sups
- h2: Hiie-Helen Raju
- h2: Ardo Gärtner
- h2: Pärt Erikson
- h2: Juhan Valge
- h2: Vladislav Stafinjak
- h2: Lauri Uue
- h2: Kuldar Jürma
- h2: Raiko Raidma
- h2: Sander Orav
- h2: Andres Kalle
- h2: Ivo Klaas
- h2: Timo Soiunen
- h2: Tanel Marran
- h2: Hannes Juurma
- h2: Raimond Kurm
- h2: Janeli Kurvits
- h2: Marianne Võime
- h2: we are part of
play & nope alliance
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**
**Scripts:** 30 total — 3 defer, 0 async, 1 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/runtime.30d3b226dcf211e512b1.min.js
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js (defer)
**Stylesheets:** 1 external, 3 inline (9.6 KB)
**Images:** 45 total — **0 without alt**, **45 without width/height**, 45 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | wordpress support service / wordpress tu | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | vladislav | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 40 anchors — 23 external, 1 preconnect, 0 preload.
Vague repeated link text:
- "view our instagram feed" ×3
- "visit our facebook page" ×3
- "visit our linkedin page" ×3
- "eng" ×3
- "est" ×3
- "styleguide" ×2
- "privacy policy" ×2
- "nope design agency" ×2
### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **45 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 3 pass · 0 warn · 0 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Response compressed (gzip / brotli) | ✓ pass | Document response is compressed with gzip. |
| Images lazy-loaded | – n/a | No raster <img> elements found (30 SVGs, 15 placeholders excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (30 SVGs, 15 placeholders excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (30 SVGs, 15 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.23.3.3`
- Response compressed (gzip / brotli):
- `content-encoding: gzip`
- `decoded body: 173514 bytes`
- `ratio: 0.163`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
## Security basics
_Captured in 0 ms._
**Verdict: FAILED**
> These are high-level hygiene checks on HTTP headers, TLS, cookies and a few well-known exposed paths. PASS means the basics are in place. It does **not** mean the site is secure: application logic, authentication, plugins, server configuration and dependencies are not tested here. Treat FAILED as a must-fix and PASS as a starting point, not a certificate.
| Check | Tier | Status | Detail |
| --- | --- | --- | --- |
| HTTP redirects to HTTPS | basic | fail | Plain HTTP does not redirect to HTTPS. |
| Strict-Transport-Security | basic | fail | Strict-Transport-Security header is missing. |
| Clickjacking protection | basic | pass | Framing is restricted. |
| X-Content-Type-Options | basic | fail | X-Content-Type-Options header is missing. |
| Cookies Secure + HttpOnly | basic | n/a | The document response sets no cookies. |
| No mixed content | basic | pass | No http:// subresources were loaded. |
| CORS | basic | pass | No wildcard CORS origin. |
| Technology disclosure | basic | warn | Response headers disclose server technology. |
| TLS certificate and protocol | basic | pass | Valid certificate and modern TLS protocol. |
| No exposed sensitive files | basic | pass | None of 6 probed sensitive paths returned real content. |
| Forms do not post to HTTP | basic | n/a | No forms on the page. |
| Content-Security-Policy present | advanced | pass | Content-Security-Policy header is set. |
| CSP is strict | advanced | fail | CSP has 2 issues: default-src missing; object-src is not 'none'. |
| HSTS preload | advanced | fail | Strict-Transport-Security header is missing. |
| Referrer-Policy | advanced | fail | Referrer-Policy header is missing. |
| Permissions-Policy | advanced | fail | Permissions-Policy header is missing. |
| Cross-Origin-Opener-Policy | advanced | fail | Cross-Origin-Opener-Policy header is missing. |
| Cross-Origin-Resource-Policy | advanced | fail | Cross-Origin-Resource-Policy header is missing. |
| Cookies SameSite | advanced | n/a | The document response sets no cookies. |
| Subresource Integrity | advanced | warn | 2 of 2 cross-origin scripts lack an integrity attribute. |
| SPF + DMARC DNS records | advanced | pass | SPF and DMARC records are present. |
| WP version not disclosed | wordpress | pass | No WordPress version found in generator meta or core asset URLs. |
| xmlrpc.php disabled | wordpress | fail | xmlrpc.php accepts POST requests (brute-force / pingback vector). |
| User enumeration blocked | wordpress | pass | No username leak across 3 enumeration probes. |
| readme.html removed | wordpress | pass | readme.html is not served. |
| Directory listing off | wordpress | pass | Uploads directory does not return an index page. |
| debug.log not public | wordpress | pass | debug.log is not served. |
| No config backups or installer | wordpress | warn | Installer /wp-admin/install.php is reachable. Harmless while the site is installed, but it becomes an open takeover path if the database is ever unreachable — block it in .htaccess. |
| Login not on default path | wordpress | warn | Login form is served on the default /wp-login.php path. |
---
# Page 3 of 5 — https://play.ee/privacy-policy
Run: 2026-09-24T10:11:25.828Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 15056 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **94** | 99 |
| Accessibility | 87 | 87 |
| Best Practices | 100 | 100 |
| SEO | 100 | 100 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **2.7 s** | 0.8 s |
| CLS | 0.002 | **0.003** |
| TBT | 0 ms | 0 ms |
| FCP | **2.15 s** | 702 ms |
| Speed Index | **2.15 s** | 840 ms |
| TTFB | **34 ms** | 3 ms |
### Priority fixes
1. **largest-contentful-paint** (low) — 2.7 s
2. **first-contentful-paint** (low) — 2.1 s
3. **document-latency-insight** (high) — Est savings of 430 ms
4. **network-dependency-tree-insight** (high)
5. **render-blocking-insight** (high) — Est savings of 1,030 ms
### Findings (mobile)
#### Unused JavaScript
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js — 23 KB wasted
#### Layout-shift sources
- div.main > footer.footer > h2.heading > span.heading__main — shift 0.002
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `largest-contentful-paint` (performance, score 0.85, weight 25) — Largest Contentful Paint — 2.7 s
- `heading-order` (accessibility, score 0.00, weight 3) — Heading elements are not in a sequentially-descending order
- `landmark-one-main` (accessibility, score 0.00, weight 3) — Document does not have a main landmark.
- `first-contentful-paint` (performance, score 0.79, weight 10) — First Contentful Paint — 2.1 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 1592 ms._
**Transport:**
- Final URL: https://play.ee/privacy-policy/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://play.ee/privacy-policy does not redirect to HTTPS (target: http://play.ee/privacy-policy/)
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 15 Sep 2026 08:38:51 GMT
- expires: Thu, 24 Sep 2026 10:11:26 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 21747
- Decoded body: 78.9 KB
- Compression ratio: 0.269
### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://play.ee/privacy-policy does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy weak** (high) — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (weak, high) `frame-ancestors 'self';` — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache`
- X-Powered-By: `PHP/8.3.33`
#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 21747
content-security-policy: frame-ancestors 'self';
content-type: text/html; charset=UTF-8
date: Thu, 24 Sep 2026 10:11:26 GMT
expires: Thu, 24 Sep 2026 10:11:26 GMT
keep-alive: timeout=5, max=99
last-modified: Tue, 15 Sep 2026 08:38:51 GMT
server: Apache
vary: Accept-Encoding
x-frame-options: SAMEORIGIN
x-powered-by: PHP/8.3.33
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1285 ms._
**Scoring:** 7 errors · 0 warnings · 23 cosmetic (suppressed)
> **Validator truncated at line 100** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.
### Priority fixes
1. **Parser recovery at line 100** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad start tag in “iframe” in “noscript” in “head”.** (medium) — x1, first at line 97
3. **Stray end tag “noscript”.** (medium) — x1, first at line 97
4. **Attribute “name” not allowed on element “meta” at this point.** (medium) — x1, first at line 99
5. **Element “meta” is missing one or more of the following attributes: “itemprop”, “property”.** (medium) — x1, first at line 99
### Issue groups
- (×1) [error] Bad start tag in “iframe” in “noscript” in “head”. — first at line 97 `<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-K3P64XMJ"`
- (×1) [error] Stray end tag “noscript”. — first at line 97 `></iframe></noscript><!-- E`
- (×1) [error] Attribute “name” not allowed on element “meta” at this point. — first at line 99 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Element “meta” is missing one or more of the following attributes: “itemprop”, “property”. — first at line 99 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Stray end tag “head”. — first at line 99 `esktop" /></head>
<body`
- (×1) [error] Start tag “body” seen but an element of the same type was already open. — first at line 100 `/></head>
<body class="privacy-policy wp-singular page-template-default page pag`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 100 `/></head>
<body class="privacy-policy wp-singular page-template-default page pag`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 2052 ms._
**Scoring:** 4 violations · 25 passes · critical 0 · serious 1 · moderate 3 · minor 0
### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **heading-order** (medium) — Heading levels should only increase by one
3. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
4. **region** (medium) — All page content should be contained by landmarks
### Findings
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `h1 > .heading__main`
- `.button`
#### `heading-order` (moderate)
[Heading levels should only increase by one](https://dequeuniversity.com/rules/axe/4.11/heading-order?application=playwright)
- `h4:nth-child(9)`
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.header__nav`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `h1`
- `.content__body`
- `.sticky-footer__social > .list__item:nth-child(1) > .social__link > .social__label`
- `.sticky-footer__social > .list__item:nth-child(2) > .social__link > .social__label`
- `.sticky-footer__social > .list__item:nth-child(3) > .social__link > .social__label`
### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 8 nodes
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 2058 ms._
**Capture summary:** 1 console events · 0 mixed-content requests · 15 network requests · 172.4 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| font | 3 | 57.6 KB |
| script | 5 | 53.5 KB |
| stylesheet | 2 | 34.2 KB |
| document | 2 | 21.2 KB |
| other | 1 | 5.5 KB |
| image | 1 | 338 B |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 2 requests, 13.2 KB
- https://fast.fonts.net — 2 requests, 0 B
**Slowest requests (top 5):**
- https://play.ee/privacy-policy/ (document) — 526 ms, 21.2 KB
- https://play.ee/privacy-policy (document) — 402 ms, 0 B
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (script) — 26 ms, 3.0 KB
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (script) — 26 ms, 10.1 KB
- https://fast.fonts.net/t/1.css?apiType=css&projectid=d924b670-8ecc-46fd-9fff-80fd9989d037 (stylesheet) — 23 ms, 0 B
### Findings
#### Console events
- [warning] Couldn't load preload assets:
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 2058 ms._
**Document:**
- Lang: en
- Title: Privacy Policy - gotoAndPlay
- Canonical: https://play.ee/privacy-policy/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 80901
**Meta tags:**
- Description: At gotoAndPlay, we take information security seriously. From our privacy policy you can learn about the data we gather at gotoAndPlay regarding personal data,
- Robots: follow, index, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time)
- Twitter tags: 3
- hreflang:
- en → https://play.ee/privacy-policy/
- et → https://play.ee/et/privaatsustingimused/
- x-default → https://play.ee/privacy-policy/
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×0, h4 ×3, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: about our
privacy policy
- h4: About the cookies used on our website
- h4: Manage cookie preferences
- h4: Server logs
- h2: ready when you are
<span style="unicode-bidi:bidi-overr
- Skips:
- h1 → h4 after "about our
privacy policy"
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**
**Scripts:** 28 total — 3 defer, 1 async, 1 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/runtime.30d3b226dcf211e512b1.min.js
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js (defer)
- https://play.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)
**Stylesheets:** 1 external, 3 inline (9.6 KB)
**Images:** 1 total — **0 without alt**, **1 without width/height**, 1 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 29 anchors — 14 external, 1 preconnect, 0 preload.
Vague repeated link text:
- "view our instagram feed" ×3
- "visit our facebook page" ×3
- "visit our linkedin page" ×3
- "eng" ×3
- "est" ×3
- "styleguide" ×2
- "privacy policy" ×2
- "http://play.ee" ×2
### Priority fixes
1. **Heading level skips** (medium) — h1→h4 after "about our
p"
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **1 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 3 pass · 0 warn · 0 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Response compressed (gzip / brotli) | ✓ pass | Document response is compressed with gzip. |
| Images lazy-loaded | – n/a | No raster <img> elements found (1 placeholder excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (1 placeholder excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (1 placeholder excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.23.3.3`
- Response compressed (gzip / brotli):
- `content-encoding: gzip`
- `decoded body: 80767 bytes`
- `ratio: 0.269`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
## Security basics
_Captured in 0 ms._
**Verdict: FAILED**
> These are high-level hygiene checks on HTTP headers, TLS, cookies and a few well-known exposed paths. PASS means the basics are in place. It does **not** mean the site is secure: application logic, authentication, plugins, server configuration and dependencies are not tested here. Treat FAILED as a must-fix and PASS as a starting point, not a certificate.
| Check | Tier | Status | Detail |
| --- | --- | --- | --- |
| HTTP redirects to HTTPS | basic | fail | Plain HTTP does not redirect to HTTPS. |
| Strict-Transport-Security | basic | fail | Strict-Transport-Security header is missing. |
| Clickjacking protection | basic | pass | Framing is restricted. |
| X-Content-Type-Options | basic | fail | X-Content-Type-Options header is missing. |
| Cookies Secure + HttpOnly | basic | n/a | The document response sets no cookies. |
| No mixed content | basic | pass | No http:// subresources were loaded. |
| CORS | basic | pass | No wildcard CORS origin. |
| Technology disclosure | basic | warn | Response headers disclose server technology. |
| TLS certificate and protocol | basic | pass | Valid certificate and modern TLS protocol. |
| No exposed sensitive files | basic | pass | None of 6 probed sensitive paths returned real content. |
| Forms do not post to HTTP | basic | n/a | No forms on the page. |
| Content-Security-Policy present | advanced | pass | Content-Security-Policy header is set. |
| CSP is strict | advanced | fail | CSP has 2 issues: default-src missing; object-src is not 'none'. |
| HSTS preload | advanced | fail | Strict-Transport-Security header is missing. |
| Referrer-Policy | advanced | fail | Referrer-Policy header is missing. |
| Permissions-Policy | advanced | fail | Permissions-Policy header is missing. |
| Cross-Origin-Opener-Policy | advanced | fail | Cross-Origin-Opener-Policy header is missing. |
| Cross-Origin-Resource-Policy | advanced | fail | Cross-Origin-Resource-Policy header is missing. |
| Cookies SameSite | advanced | n/a | The document response sets no cookies. |
| Subresource Integrity | advanced | warn | 2 of 2 cross-origin scripts lack an integrity attribute. |
| SPF + DMARC DNS records | advanced | pass | SPF and DMARC records are present. |
| WP version not disclosed | wordpress | pass | No WordPress version found in generator meta or core asset URLs. |
| xmlrpc.php disabled | wordpress | fail | xmlrpc.php accepts POST requests (brute-force / pingback vector). |
| User enumeration blocked | wordpress | pass | No username leak across 3 enumeration probes. |
| readme.html removed | wordpress | pass | readme.html is not served. |
| Directory listing off | wordpress | pass | Uploads directory does not return an index page. |
| debug.log not public | wordpress | pass | debug.log is not served. |
| No config backups or installer | wordpress | warn | Installer /wp-admin/install.php is reachable. Harmless while the site is installed, but it becomes an open takeover path if the database is ever unreachable — block it in .htaccess. |
| Login not on default path | wordpress | warn | Login form is served on the default /wp-login.php path. |
---
# Page 4 of 5 — https://play.ee/et/meeskond
Run: 2026-09-24T10:11:30.912Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 15617 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **83** | 100 |
| Accessibility | 94 | **93** |
| Best Practices | 100 | 100 |
| SEO | 100 | 100 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **2.6 s** | 0.7 s |
| CLS | **0.230** | 0.004 |
| TBT | 0 ms | 0 ms |
| FCP | **2.13 s** | 618 ms |
| Speed Index | **2.13 s** | 782 ms |
| TTFB | 7 ms | **35 ms** |
### Priority fixes
1. **cumulative-layout-shift** (medium) — 0.23
2. **largest-contentful-paint** (low) — 2.6 s
3. **first-contentful-paint** (low) — 2.1 s
4. **cls-culprits-insight** (high)
5. **document-latency-insight** (high) — Est savings of 420 ms
### Findings (mobile)
#### Unused JavaScript
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js — 23 KB wasted
#### Layout-shift sources
- body.wp-singular > div#page > div.main > footer.footer — shift 0.230
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `cumulative-layout-shift` (performance, score 0.54, weight 25) — Cumulative Layout Shift — 0.23
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `largest-contentful-paint` (performance, score 0.87, weight 25) — Largest Contentful Paint — 2.6 s
- `landmark-one-main` (accessibility, score 0.00, weight 3) — Document does not have a main landmark.
- `first-contentful-paint` (performance, score 0.80, weight 10) — First Contentful Paint — 2.1 s
- `cls-culprits-insight` (performance, score 0.00, weight 0) — Layout shift culprits
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 1962 ms._
**Transport:**
- Final URL: https://play.ee/et/meeskond/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://play.ee/et/meeskond does not redirect to HTTPS (target: http://play.ee/et/meeskond/)
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 15 Sep 2026 08:42:10 GMT
- expires: Thu, 24 Sep 2026 10:11:31 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 28109
- Decoded body: 158.6 KB
- Compression ratio: 0.173
### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://play.ee/et/meeskond does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy weak** (high) — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (weak, high) `frame-ancestors 'self';` — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache`
- X-Powered-By: `PHP/8.3.33`
#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 28109
content-security-policy: frame-ancestors 'self';
content-type: text/html; charset=UTF-8
date: Thu, 24 Sep 2026 10:11:31 GMT
expires: Thu, 24 Sep 2026 10:11:31 GMT
keep-alive: timeout=5, max=99
last-modified: Tue, 15 Sep 2026 08:42:10 GMT
server: Apache
vary: Accept-Encoding
x-frame-options: SAMEORIGIN
x-powered-by: PHP/8.3.33
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1391 ms._
**Scoring:** 8 errors · 0 warnings · 23 cosmetic (suppressed)
> **Validator truncated at line 102** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.
### Priority fixes
1. **Parser recovery at line 102** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad value “” for attribute “href” on element “link”: Must be non-empty.** (medium) — x1, first at line 51
3. **Bad start tag in “iframe” in “noscript” in “head”.** (medium) — x1, first at line 99
4. **Stray end tag “noscript”.** (medium) — x1, first at line 99
5. **Attribute “name” not allowed on element “meta” at this point.** (medium) — x1, first at line 101
### Issue groups
- (×1) [error] Bad value “” for attribute “href” on element “link”: Must be non-empty. — first at line 51 `refetch">
<link data-rocket-prefetch href="" rel="dns-prefetch">
<meta`
- (×1) [error] Bad start tag in “iframe” in “noscript” in “head”. — first at line 99 `<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-K3P64XMJ"`
- (×1) [error] Stray end tag “noscript”. — first at line 99 `></iframe></noscript><!-- E`
- (×1) [error] Attribute “name” not allowed on element “meta” at this point. — first at line 101 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Element “meta” is missing one or more of the following attributes: “itemprop”, “property”. — first at line 101 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Stray end tag “head”. — first at line 101 `esktop" /></head>
<body`
- (×1) [error] Start tag “body” seen but an element of the same type was already open. — first at line 102 `/></head>
<body class="wp-singular page-template page-template-template-dynamic `
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 102 `/></head>
<body class="wp-singular page-template page-template-template-dynamic `
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 2148 ms._
**Scoring:** 3 violations · 32 passes · critical 0 · serious 1 · moderate 2 · minor 0
### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
3. **region** (medium) — All page content should be contained by landmarks
### Findings
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `h1 > .heading__main`
- `.how-we-do__intro > .heading--primary.heading > .heading__main`
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.header__nav`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.team-grid__intro`
- `.is-active`
- `.grid__col--sm-6.grid__col--md-4.team-grid__member:nth-child(1) > .person-card.team-grid__member-card > .person-card__content`
- `.grid__col--sm-6.grid__col--md-4.team-grid__member:nth-child(2) > .person-card.team-grid__member-card > .person-card__content`
- `.grid__col--sm-6.grid__col--md-4.team-grid__member:nth-child(3) > .person-card.team-grid__member-card > .person-card__figure > .person-card__image--workmode.person-card__image.image--background > .image__inner > img`
- … and 28 more nodes
### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 12 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 2165 ms._
**Capture summary:** 1 console events · 0 mixed-content requests · 14 network requests · 188.4 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| font | 3 | 57.6 KB |
| script | 4 | 45.6 KB |
| stylesheet | 2 | 34.2 KB |
| document | 2 | 27.5 KB |
| image | 1 | 18.1 KB |
| other | 1 | 5.5 KB |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 2 requests, 13.2 KB
- https://fast.fonts.net — 2 requests, 0 B
**Slowest requests (top 5):**
- https://play.ee/et/meeskond (document) — 469 ms, 0 B
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/fonts/fc2fa85e-cd2d-4004-930a-8adad6c60317.3bd2a5f3705d9fb438c5.woff2 (font) — 132 ms, 19.3 KB
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/fonts/f389f79b-6013-4448-aa6a-b6fd235eab80.b91a05bafb09e626383a.woff2 (font) — 132 ms, 19.0 KB
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/fonts/1c0243aa-c535-4d42-ac53-d6f0f74a1412.bd94708352cbb3b4863c.woff2 (font) — 121 ms, 19.3 KB
- https://fast.fonts.net/t/1.css?apiType=css&projectid=d924b670-8ecc-46fd-9fff-80fd9989d037 (stylesheet) — 29 ms, 0 B
### Findings
#### Console events
- [warning] Couldn't load preload assets:
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 2165 ms._
**Document:**
- Lang: et
- Title: Usaldusväärne full-stack arendus ja tehniline tugi
- Canonical: https://play.ee/et/meeskond/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 160414
**Meta tags:**
- Description: Siin on meie tragi punt ägedaid inimesi. Sinu päralt on full-stack arendus (nii front-end kui back-end arendus) ning alati valvel tehniline tugi.
- Robots: follow, index, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time)
- Twitter tags: 3
- hreflang:
- en → https://play.ee/team/
- et → https://play.ee/et/meeskond/
- x-default → https://play.ee/team/
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×21, h3 ×8, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: meie meeskonna
individuaalsed meistrid
- h2: Siim Sups
- h2: Hiie-Helen Raju
- h2: Ardo Gärtner
- h2: Pärt Erikson
- h2: Juhan Valge
- h2: Vladislav Stafinjak
- h2: Lauri Uue
- h2: Kuldar Jürma
- h2: Raiko Raidma
- h2: Sander Orav
- h2: Andres Kalle
- h2: Ivo Klaas
- h2: Timo Soiunen
- h2: Tanel Marran
- h2: Hannes Juurma
- h2: Raimond Kurm
- h2: Marianne Võime
- h2: Janeli Kurvits
- h2: Me oleme osa
play & nope alliance'st
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**
**Scripts:** 30 total — 3 defer, 0 async, 1 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/runtime.30d3b226dcf211e512b1.min.js
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js (defer)
**Stylesheets:** 1 external, 3 inline (9.6 KB)
**Images:** 45 total — **0 without alt**, **45 without width/height**, 45 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | wordpress support service / wordpress tu | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | vladislav | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 40 anchors — 23 external, 1 preconnect, 0 preload.
Vague repeated link text:
- "vaata meie instagrami" ×3
- "külasta meie facebooki lehte" ×3
- "külasta meie linkedin lehte" ×3
- "eng" ×3
- "est" ×3
- "styleguide" ×2
- "privaatsustingimused" ×2
- "osa play & nope alliance'st" ×2
### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **45 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **Vague link text repeated** (medium) — "vaata meie instagrami" ×3
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 3 pass · 0 warn · 0 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Response compressed (gzip / brotli) | ✓ pass | Document response is compressed with gzip. |
| Images lazy-loaded | – n/a | No raster <img> elements found (26 SVGs, 19 placeholders excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (26 SVGs, 19 placeholders excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (26 SVGs, 19 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.23.3.3`
- Response compressed (gzip / brotli):
- `content-encoding: gzip`
- `decoded body: 162442 bytes`
- `ratio: 0.173`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
## Security basics
_Captured in 0 ms._
**Verdict: FAILED**
> These are high-level hygiene checks on HTTP headers, TLS, cookies and a few well-known exposed paths. PASS means the basics are in place. It does **not** mean the site is secure: application logic, authentication, plugins, server configuration and dependencies are not tested here. Treat FAILED as a must-fix and PASS as a starting point, not a certificate.
| Check | Tier | Status | Detail |
| --- | --- | --- | --- |
| HTTP redirects to HTTPS | basic | fail | Plain HTTP does not redirect to HTTPS. |
| Strict-Transport-Security | basic | fail | Strict-Transport-Security header is missing. |
| Clickjacking protection | basic | pass | Framing is restricted. |
| X-Content-Type-Options | basic | fail | X-Content-Type-Options header is missing. |
| Cookies Secure + HttpOnly | basic | n/a | The document response sets no cookies. |
| No mixed content | basic | pass | No http:// subresources were loaded. |
| CORS | basic | pass | No wildcard CORS origin. |
| Technology disclosure | basic | warn | Response headers disclose server technology. |
| TLS certificate and protocol | basic | pass | Valid certificate and modern TLS protocol. |
| No exposed sensitive files | basic | pass | None of 6 probed sensitive paths returned real content. |
| Forms do not post to HTTP | basic | n/a | No forms on the page. |
| Content-Security-Policy present | advanced | pass | Content-Security-Policy header is set. |
| CSP is strict | advanced | fail | CSP has 2 issues: default-src missing; object-src is not 'none'. |
| HSTS preload | advanced | fail | Strict-Transport-Security header is missing. |
| Referrer-Policy | advanced | fail | Referrer-Policy header is missing. |
| Permissions-Policy | advanced | fail | Permissions-Policy header is missing. |
| Cross-Origin-Opener-Policy | advanced | fail | Cross-Origin-Opener-Policy header is missing. |
| Cross-Origin-Resource-Policy | advanced | fail | Cross-Origin-Resource-Policy header is missing. |
| Cookies SameSite | advanced | n/a | The document response sets no cookies. |
| Subresource Integrity | advanced | warn | 2 of 2 cross-origin scripts lack an integrity attribute. |
| SPF + DMARC DNS records | advanced | pass | SPF and DMARC records are present. |
| WP version not disclosed | wordpress | pass | No WordPress version found in generator meta or core asset URLs. |
| xmlrpc.php disabled | wordpress | fail | xmlrpc.php accepts POST requests (brute-force / pingback vector). |
| User enumeration blocked | wordpress | pass | No username leak across 3 enumeration probes. |
| readme.html removed | wordpress | pass | readme.html is not served. |
| Directory listing off | wordpress | pass | Uploads directory does not return an index page. |
| debug.log not public | wordpress | pass | debug.log is not served. |
| No config backups or installer | wordpress | warn | Installer /wp-admin/install.php is reachable. Harmless while the site is installed, but it becomes an open takeover path if the database is ever unreachable — block it in .htaccess. |
| Login not on default path | wordpress | warn | Login form is served on the default /wp-login.php path. |
---
# Page 5 of 5 — https://play.ee/wordpress-support-service
Run: 2026-09-24T10:11:48.207Z
## Audit Coverage
**88%** of audit sources returned data.
Missing or failed sources:
- PageSpeed Insights: mobile: PSI HTTP 429; desktop: PSI HTTP 429
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Error after 71 ms: mobile: PSI HTTP 429; desktop: PSI HTTP 429_
## Security Headers & HTTP
_Captured in 1777 ms._
**Transport:**
- Final URL: https://play.ee/wordpress-support-service/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://play.ee/wordpress-support-service does not redirect to HTTPS (target: http://play.ee/wordpress-support-service/)
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 15 Sep 2026 08:37:43 GMT
- expires: Thu, 24 Sep 2026 10:11:49 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 31016
- Decoded body: 184.1 KB
- Compression ratio: 0.165
### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://play.ee/wordpress-support-service does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy weak** (high) — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (weak, high) `frame-ancestors 'self';` — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache`
- X-Powered-By: `PHP/8.3.33`
#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 31016
content-security-policy: frame-ancestors 'self';
content-type: text/html; charset=UTF-8
date: Thu, 24 Sep 2026 10:11:49 GMT
expires: Thu, 24 Sep 2026 10:11:49 GMT
keep-alive: timeout=5, max=99
last-modified: Tue, 15 Sep 2026 08:37:43 GMT
server: Apache
vary: Accept-Encoding
x-frame-options: SAMEORIGIN
x-powered-by: PHP/8.3.33
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1227 ms._
**Scoring:** 7 errors · 0 warnings · 30 cosmetic (suppressed)
> **Validator truncated at line 107** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.
### Priority fixes
1. **Parser recovery at line 107** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad start tag in “iframe” in “noscript” in “head”.** (medium) — x1, first at line 104
3. **Stray end tag “noscript”.** (medium) — x1, first at line 104
4. **Attribute “name” not allowed on element “meta” at this point.** (medium) — x1, first at line 106
5. **Element “meta” is missing one or more of the following attributes: “itemprop”, “property”.** (medium) — x1, first at line 106
### Issue groups
- (×1) [error] Bad start tag in “iframe” in “noscript” in “head”. — first at line 104 `<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-K3P64XMJ"`
- (×1) [error] Stray end tag “noscript”. — first at line 104 `></iframe></noscript><!-- E`
- (×1) [error] Attribute “name” not allowed on element “meta” at this point. — first at line 106 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Element “meta” is missing one or more of the following attributes: “itemprop”, “property”. — first at line 106 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Stray end tag “head”. — first at line 106 `esktop" /></head>
<body`
- (×1) [error] Start tag “body” seen but an element of the same type was already open. — first at line 107 `/></head>
<body class="wp-singular page-template page-template-template-dynamic `
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 107 `/></head>
<body class="wp-singular page-template page-template-template-dynamic `
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 3044 ms._
**Scoring:** 4 violations · 32 passes · critical 0 · serious 2 · moderate 2 · minor 0
### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **link-name** (high) — Links must have discernible text
3. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
4. **region** (medium) — All page content should be contained by landmarks
### Findings
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `.button--tertiary > .button__inner > .button__text`
- `.grid__col--md-4.capabilities__grid-col.grid__col--sm-6:nth-child(1) > .heading--h5.capabilities__heading.h5 > .heading__small`
- `.grid__col--md-4.capabilities__grid-col.grid__col--sm-6:nth-child(2) > .heading--h5.capabilities__heading.h5 > .heading__small`
- `.grid__col--md-4.capabilities__grid-col.grid__col--sm-6:nth-child(3) > .heading--h5.capabilities__heading.h5 > .heading__small`
- `.grid__col--md-4.capabilities__grid-col.grid__col--sm-6:nth-child(4) > .heading--h5.capabilities__heading.h5 > .heading__small`
- … and 10 more nodes
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.header__nav`
#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.logo-grid__row.js-in-viewport:nth-child(1) > .logo-grid__item:nth-child(1) > .logo-grid__link[href=""][rel="noopener"]`
- `.logo-grid__row.js-in-viewport:nth-child(1) > .logo-grid__item:nth-child(2) > .logo-grid__link[href=""][rel="noopener"]`
- `.logo-grid__row.js-in-viewport:nth-child(1) > .logo-grid__item:nth-child(3) > .logo-grid__link[href=""][rel="noopener"]`
- `.logo-grid__row.js-in-viewport:nth-child(2) > .logo-grid__item:nth-child(1) > .logo-grid__link[href=""][rel="noopener"]`
- `.logo-grid__row.js-in-viewport:nth-child(2) > .logo-grid__item:nth-child(2) > .logo-grid__link[href=""][rel="noopener"]`
- … and 4 more nodes
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.contact-hero__intro > h1`
- `.intro__content > p:nth-child(2)`
- `p:nth-child(3)`
- `.button--tertiary`
- `canvas`
- … and 95 more nodes
### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 15 nodes
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 3058 ms._
**Capture summary:** 1 console events · 0 mixed-content requests · 25 network requests · 201.9 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| font | 3 | 57.6 KB |
| script | 5 | 53.5 KB |
| stylesheet | 2 | 34.2 KB |
| document | 2 | 30.3 KB |
| image | 11 | 20.8 KB |
| other | 1 | 5.5 KB |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 2 requests, 13.2 KB
- https://fast.fonts.net — 2 requests, 0 B
**Slowest requests (top 5):**
- https://play.ee/wordpress-support-service (document) — 406 ms, 0 B
- https://play.ee/wordpress-support-service/ (document) — 384 ms, 30.3 KB
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/fonts/fc2fa85e-cd2d-4004-930a-8adad6c60317.3bd2a5f3705d9fb438c5.woff2 (font) — 219 ms, 19.3 KB
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (script) — 29 ms, 3.0 KB
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js (script) — 28 ms, 31.5 KB
### Findings
#### Console events
- [warning] Couldn't load preload assets:
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 3058 ms._
**Document:**
- Lang: en
- Title: WordPress support service
- Canonical: https://play.ee/wordpress-support-service/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 187229
**Meta tags:**
- Description: From ongoing WordPress support to health monitoring and expert fixes, we take care of your website so you can spend more time building your business.
- Robots: follow, index, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 13 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time, og:image, og:image:secure_url, og:image:width, og:image:height, og:image:alt, og:image:type)
- Twitter tags: 4
- hreflang:
- en → https://play.ee/wordpress-support-service/
- et → https://play.ee/et/tugiteenus/
- x-default → https://play.ee/wordpress-support-service/
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×2, h2 ×16, h3 ×14, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Your worry-free
WordPress website
- h2: Why choose our
WordPress support service
- h3: #1
peace of mind
- h3: #2
security first
- h3: #3
expert team on-call
- h3: #4
performance wins
- h3: #5
save money
- h3: #6
monthly health reports
- h3: #7
collaboration
- h3: #8
extensive network
- h3: #9
top notch tools
- h2: service by professionals who
build websites for a l
- h2: customizable & transparent
Pricing
- h2: <Basic/>
- h2: <Advanced/>
- h2: <Pro/>
- h2: five-step
onboarding process
- h1: additional services
to upgrade your online presence
- h2: UX/UI audit
- h2: WCAG audit
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**
**Scripts:** 27 total — 3 defer, 1 async, 1 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/runtime.30d3b226dcf211e512b1.min.js
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js (defer)
- https://play.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)
**Stylesheets:** 1 external, 3 inline (9.6 KB)
**Images:** 31 total — **0 without alt**, **31 without width/height**, 31 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | Expert WordPress support service | _n/a_ | _n/a_ | ✗ |
| p-content/themes/gotoandplay/inc/theme/img/line-1-mobile.svg | line-1 | _n/a_ | _n/a_ | ✗ |
| ay.ee/wp-content/themes/gotoandplay/inc/theme/img/line-1.svg | line-1 | _n/a_ | _n/a_ | ✗ |
| p-content/themes/gotoandplay/inc/theme/img/line-2-mobile.svg | line-2 | _n/a_ | _n/a_ | ✗ |
| ay.ee/wp-content/themes/gotoandplay/inc/theme/img/line-2.svg | line-2 | _n/a_ | _n/a_ | ✗ |
| p-content/themes/gotoandplay/inc/theme/img/line-3-mobile.svg | line-3 | _n/a_ | _n/a_ | ✗ |
| ay.ee/wp-content/themes/gotoandplay/inc/theme/img/line-3.svg | line-3 | _n/a_ | _n/a_ | ✗ |
| p-content/themes/gotoandplay/inc/theme/img/line-4-mobile.svg | line-4 | _n/a_ | _n/a_ | ✗ |
| ay.ee/wp-content/themes/gotoandplay/inc/theme/img/line-4.svg | line-4 | _n/a_ | _n/a_ | ✗ |
| p-content/themes/gotoandplay/inc/theme/img/line-5-mobile.svg | line-5 | _n/a_ | _n/a_ | ✗ |
| ay.ee/wp-content/themes/gotoandplay/inc/theme/img/line-5.svg | line-5 | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 57 anchors — 17 external, 2 preconnect, 0 preload.
Vague repeated link text:
- "get in touch" ×14
- "view our instagram feed" ×3
- "visit our facebook page" ×3
- "visit our linkedin page" ×3
- "eng" ×3
- "est" ×3
- "styleguide" ×2
- "privacy policy" ×2
### Priority fixes
1. **Document has 2 <h1> elements** (medium) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **31 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 3 pass · 0 warn · 0 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Response compressed (gzip / brotli) | ✓ pass | Document response is compressed with gzip. |
| Images lazy-loaded | – n/a | No raster <img> elements found (24 SVGs, 7 placeholders excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (24 SVGs, 7 placeholders excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (24 SVGs, 7 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.23.3.3`
- Response compressed (gzip / brotli):
- `content-encoding: gzip`
- `decoded body: 188490 bytes`
- `ratio: 0.165`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
## Security basics
_Captured in 0 ms._
**Verdict: FAILED**
> These are high-level hygiene checks on HTTP headers, TLS, cookies and a few well-known exposed paths. PASS means the basics are in place. It does **not** mean the site is secure: application logic, authentication, plugins, server configuration and dependencies are not tested here. Treat FAILED as a must-fix and PASS as a starting point, not a certificate.
| Check | Tier | Status | Detail |
| --- | --- | --- | --- |
| HTTP redirects to HTTPS | basic | fail | Plain HTTP does not redirect to HTTPS. |
| Strict-Transport-Security | basic | fail | Strict-Transport-Security header is missing. |
| Clickjacking protection | basic | pass | Framing is restricted. |
| X-Content-Type-Options | basic | fail | X-Content-Type-Options header is missing. |
| Cookies Secure + HttpOnly | basic | n/a | The document response sets no cookies. |
| No mixed content | basic | pass | No http:// subresources were loaded. |
| CORS | basic | pass | No wildcard CORS origin. |
| Technology disclosure | basic | warn | Response headers disclose server technology. |
| TLS certificate and protocol | basic | pass | Valid certificate and modern TLS protocol. |
| No exposed sensitive files | basic | pass | None of 6 probed sensitive paths returned real content. |
| Forms do not post to HTTP | basic | n/a | No forms on the page. |
| Content-Security-Policy present | advanced | pass | Content-Security-Policy header is set. |
| CSP is strict | advanced | fail | CSP has 2 issues: default-src missing; object-src is not 'none'. |
| HSTS preload | advanced | fail | Strict-Transport-Security header is missing. |
| Referrer-Policy | advanced | fail | Referrer-Policy header is missing. |
| Permissions-Policy | advanced | fail | Permissions-Policy header is missing. |
| Cross-Origin-Opener-Policy | advanced | fail | Cross-Origin-Opener-Policy header is missing. |
| Cross-Origin-Resource-Policy | advanced | fail | Cross-Origin-Resource-Policy header is missing. |
| Cookies SameSite | advanced | n/a | The document response sets no cookies. |
| Subresource Integrity | advanced | warn | 2 of 2 cross-origin scripts lack an integrity attribute. |
| SPF + DMARC DNS records | advanced | pass | SPF and DMARC records are present. |
| WP version not disclosed | wordpress | pass | No WordPress version found in generator meta or core asset URLs. |
| xmlrpc.php disabled | wordpress | fail | xmlrpc.php accepts POST requests (brute-force / pingback vector). |
| User enumeration blocked | wordpress | pass | No username leak across 3 enumeration probes. |
| readme.html removed | wordpress | pass | readme.html is not served. |
| Directory listing off | wordpress | pass | Uploads directory does not return an index page. |
| debug.log not public | wordpress | pass | debug.log is not served. |
| No config backups or installer | wordpress | warn | Installer /wp-admin/install.php is reachable. Harmless while the site is installed, but it becomes an open takeover path if the database is ever unreachable — block it in .htaccess. |
| Login not on default path | wordpress | warn | Login form is served on the default /wp-login.php path. |