Audit

20260924T111955Z-7771

← Back to playee
Audited URL
https://play.ee/
Timestamp
2026-09-24T11:21:21.681Z
Kind
single
Pages
1
Audit summary
https://play.ee/
Pagespeed scores
Other checks
LLM Report

Weighted audit summary

78
Overall site quality
Needs Improvementhigh confidence

PSI mobile 97 indicates excellent performance (LCP 2.3 s, CLS 0.001), but the Security basics verdict is FAILED. Per the audit protocol: 'Treat FAILED as a must-fix and PASS as a starting point, not a certificate.' W3C validation returned 7 errors including parser recovery failure, and accessibility has 2 moderate violations plus missing landmarks. Image assets lack width/height attributes on all 50 images, risking future CLS. These structural and security hygiene issues prevent a higher score despite the fast load times.

Audit Report: Perfectly formed web development team - gotoAndPlay

Website: https://play.ee/
Date: 24.09.2026
Audit Coverage: 100% — all sources returned data
Confidence: high

Pages Audited (1 of 1):

Summary of results

Overall Score: 78 / 100
Status: 🟡 Needs Improvement

PSI mobile 97 indicates excellent performance (LCP 2.3 s, CLS 0.001), but the Security basics verdict is FAILED. Per the audit protocol: 'Treat FAILED as a must-fix and PASS as a starting point, not a certificate.' W3C validation returned 7 errors including parser recovery failure, and accessibility has 2 moderate violations plus missing landmarks. Image assets lack width/height attributes on all 50 images, risking future CLS. These structural and security hygiene issues prevent a higher score despite the fast load times.

Per-page scores

🟡 Needs Improvement · https://play.ee/

Score Performance Accessibility Best Practices SEO Security
78 97 94 100 92 FAILED

PageSpeed Insights — Mobile vs Desktop

Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.

Strategy Performance (M / D) LCP (M / D) CLS (M / D)
Mobile vs Desktop 97 / 100 2.33 s / 588 ms 0.001 / 0.007

Optimization Checklist

3 of 3 passing — 3 pass · 0 warn · 0 fail · 5 n/a

Item Status Detail
Page caching plugin / CDN active Pass Caching plugin detected (WP Rocket)
Response compressed (gzip / brotli) Pass Document response is compressed with gzip.
Images lazy-loaded N/A No raster <img> elements found (37 SVGs, 13 placeholders excluded).
Hero image eagerly loaded N/A No raster <img> elements found (37 SVGs, 13 placeholders excluded).
Hero is a real <img> (not a CSS background-image) N/A No CSS background-images detected on raster-image-eligible elements.
Responsive images (srcset / <picture>) N/A Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply.
Reasonable number of image sizes N/A Too few raster images to evaluate srcset width variety.
JS scripts not blocking in <head> Pass No render-blocking scripts in <head>.

Fixes

Priority 1: Critical

Immediate action — impacts user experience, search rankings, or site safety.

1A. Fix HTTP redirect and add baseline security headers Security

  • Impact: Transport security, clickjacking, MIME sniffing
  • Problem: Security basics verdict is FAILED: http:// does not redirect to https, HSTS is missing, and X-Content-Type-Options is missing.
  • Solution: Configure server to redirect HTTP to HTTPS and send these headers:
    Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
    Header always set X-Content-Type-Options "nosniff"
    Redirect permanent / https://play.ee/
    

Priority 2: Important

Essential for compliance, user reach, and search visibility.

2A. Fix W3C HTML validation errors SEO

  • Impact: Parser recovery, document structure
  • Problem: W3C validator reported 7 errors including 'Cannot recover after last error' at line 101 and bad iframe/noscript nesting in head.
  • Solution: Move <noscript><iframe>...</iframe></noscript> out of <head> or ensure it is valid HTML5. Remove stray end tags and fix meta tag attributes (e.g., name vs property).

2B. Add skip-to-content link and fix landmarks Accessibility

  • Impact: Keyboard navigation, screen reader flow
  • Problem: axe-core found landmark-unique and region violations; HTML inventory confirms missing main landmark and skip link.
  • Solution: Add a skip link at the top of the body:
    <a href="#main-content" class="skip-link">Skip to content</a>
    
    Wrap main content in <main id="main-content"> and ensure nav/footer have unique labels.

2C. Add width and height to all images Performance

  • Impact: CLS (Cumulative Layout Shift)
  • Problem: HTML inventory shows 50 images without explicit width/height attributes, risking layout shifts despite current CLS of 0.001.
  • Solution: Add width and height attributes to all <img> tags matching their intrinsic dimensions. For responsive images, use srcset with corresponding sizes.

2D. Harden WordPress installation Security

  • Impact: Brute-force protection, attack surface
  • Problem: Security basics flagged xmlrpc.php accepts POST requests and /wp-admin/install.php is reachable.
  • Solution: Disable xmlrpc.php in .htaccess or via plugin. Block access to /wp-admin/install.php after installation:
    <Files install.php>
      Order Allow,Deny
      Deny from all
    </Files>
    

Priority 3: Best Practice

Recommended for long-term maintainability.

No items.

▸Raw Markdown sent to the LLM
# Audit — https://play.ee/

Run: 2026-09-24T11:19:55.690Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 17451 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **97** | 100 |
| Accessibility | **94** | 95 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **2.3 s** | 0.6 s |
| CLS | 0.001 | **0.007** |
| TBT | 0 ms | 0 ms |
| FCP | **1.96 s** | 490 ms |
| Speed Index | **1.96 s** | 490 ms |
| TTFB | **9 ms** | 6 ms |

### Priority fixes
1. **first-contentful-paint** (low) — 2.0 s
2. **network-dependency-tree-insight** (high)
3. **render-blocking-insight** (high) — Est savings of 1,080 ms
4. **unused-css-rules** (high) — Est savings of 30 KiB
5. **unused-javascript** (medium) — Est savings of 23 KiB

### Findings (mobile)

#### Unused JavaScript
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js — 23 KB wasted

#### Layout-shift sources
- footer.footer > h2.heading > span.heading__main > a.link — shift 0.001

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `first-contentful-paint` (performance, score 0.85, weight 10) — First Contentful Paint — 2.0 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 9 links found

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 1153 ms._

**Transport:**
- Final URL: https://play.ee/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://play.ee/ does not redirect to HTTPS (target: none)

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 15 Sep 2026 08:38:43 GMT
- expires: Thu, 24 Sep 2026 11:19:55 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 35451
- Decoded body: 216.5 KB
- Compression ratio: 0.16

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://play.ee/ does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy weak** (high) — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache

### Findings

#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (weak, high) `frame-ancestors 'self';` — missing default-src; missing object-src 'none'; only frame-ancestors set — no script/resource restrictions
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache`
- X-Powered-By: `PHP/8.3.33`

#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 35451
content-security-policy: frame-ancestors 'self';
content-type: text/html; charset=UTF-8
date: Thu, 24 Sep 2026 11:19:55 GMT
expires: Thu, 24 Sep 2026 11:19:55 GMT
keep-alive: timeout=5, max=100
last-modified: Tue, 15 Sep 2026 08:38:43 GMT
server: Apache
upgrade: h2,h2c
vary: Accept-Encoding
x-frame-options: SAMEORIGIN
x-powered-by: PHP/8.3.33
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 926 ms._

**Scoring:** 7 errors · 0 warnings · 23 cosmetic (suppressed)

> **Validator truncated at line 101** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.

### Priority fixes
1. **Parser recovery at line 101** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad start tag in “iframe” in “noscript” in “head”.** (medium) — x1, first at line 98
3. **Stray end tag “noscript”.** (medium) — x1, first at line 98
4. **Attribute “name” not allowed on element “meta” at this point.** (medium) — x1, first at line 100
5. **Element “meta” is missing one or more of the following attributes: “itemprop”, “property”.** (medium) — x1, first at line 100

### Issue groups
- (×1) [error] Bad start tag in “iframe” in “noscript” in “head”. — first at line 98 `<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-K3P64XMJ"`
- (×1) [error] Stray end tag “noscript”. — first at line 98 `></iframe></noscript><!-- E`
- (×1) [error] Attribute “name” not allowed on element “meta” at this point. — first at line 100 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Element “meta” is missing one or more of the following attributes: “itemprop”, “property”. — first at line 100 `<meta name="generator" content="WP Rocket 3.23.3.3" data-wpr-features="wpr_delay`
- (×1) [error] Stray end tag “head”. — first at line 100 `esktop" /></head>
<body`
- (×1) [error] Start tag “body” seen but an element of the same type was already open. — first at line 101 `/></head>
<body class="home wp-singular page-template page-template-template-dyn`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 101 `/></head>
<body class="home wp-singular page-template page-template-template-dyn`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2321 ms._

**Scoring:** 2 violations · 32 passes · critical 0 · serious 0 · moderate 2 · minor 0

### Priority fixes
1. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
2. **region** (medium) — All page content should be contained by landmarks

### Findings

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.header__nav`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.home-hero__main`
- `.home-hero__bottom`
- `canvas`
- `.keywords__mouse`
- `.keywords__intro`
- … and 31 more nodes

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 38 nodes

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2333 ms._

**Capture summary:** 1 console events · 0 mixed-content requests · 13 network requests · 178.1 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| font | 3 | 57.6 KB |
| script | 4 | 45.6 KB |
| document | 1 | 34.6 KB |
| stylesheet | 2 | 34.2 KB |
| other | 1 | 5.5 KB |
| image | 1 | 576 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 2 requests, 13.2 KB
- https://fast.fonts.net — 2 requests, 0 B

**Slowest requests (top 5):**
- https://play.ee/ (document) — 587 ms, 34.6 KB
- https://fast.fonts.net/t/1.css?apiType=css&projectid=d924b670-8ecc-46fd-9fff-80fd9989d037 (stylesheet) — 47 ms, 0 B
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/runtime.30d3b226dcf211e512b1.min.js (script) — 38 ms, 1.0 KB
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js (script) — 38 ms, 31.5 KB
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (script) — 38 ms, 10.1 KB

### Findings

#### Console events
- [warning] Couldn't load preload assets:  

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2333 ms._

**Document:**
- Lang: en
- Title: Perfectly formed web development team - gotoAndPlay
- Canonical: https://play.ee/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 217719

**Meta tags:**
- Description: Small, agile web development team working on big ideas in close collaboration with our clients. Result driven from day one!
- Robots: follow, index, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time)
- Twitter tags: 3
- hreflang:
  - en → http://play.ee/
  - et → http://play.ee/et/
  - x-default → http://play.ee/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×6, h3 ×5, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: we create memorable experiences with
        
                    web technologi
  - h2: Your result
  - h2: we offer
        
                    more than expected
  - h2: Üks
  - h2: meet the team of
        
                    uncommon talent
  - h2: proof to our approach are
        
                    happy clients
  - h3: Deliverables with high quality standards
  - h3: Working with gotoAndPlay is a great experience
  - h3: Speed, attitude, skills!
  - h3: Hardworking, fun & ready to adopt new technologies
  - h3: The sky is the limit
  - h2: take a look at our
        
                    
    case studies

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 23 total — 3 defer, 0 async, 1 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/runtime.30d3b226dcf211e512b1.min.js
- https://play.ee/wp-content/themes/gotoandplay/inc/theme/js/jquery.bfe1bb19d13b3c17b682.min.js (defer)

**Stylesheets:** 1 external, 3 inline (9.6 KB)

**Images:** 50 total — **0 without alt**, **50 without width/height**, 50 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| ee/wp-content/themes/gotoandplay/inc/theme/img/landscape.svg | Please turn your device sideways | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| %2Fsvg%22%20viewBox%3D%220%200%20360%20420%22%3E%3C%2Fsvg%3E | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw== | _(empty)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 46 anchors — 34 external, 1 preconnect, 0 preload.

Vague repeated link text:
- "read more" ×9
- "view our instagram feed" ×3
- "visit our facebook page" ×3
- "visit our linkedin page" ×3
- "eng" ×3
- "est" ×3
- "case studies" ×2
- "styleguide" ×2
- "privacy policy" ×2

**Forms:**
Form 1:
- text — labeled

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **50 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **Vague link text repeated** (medium) — "read more" ×9

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 1 ms._

**Summary:** 3 pass · 0 warn · 0 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Response compressed (gzip / brotli) | ✓ pass | Document response is compressed with gzip. |
| Images lazy-loaded | – n/a | No raster <img> elements found (37 SVGs, 13 placeholders excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (37 SVGs, 13 placeholders excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (37 SVGs, 13 placeholders excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WP Rocket 3.23.3.3`
- Response compressed (gzip / brotli):
  - `content-encoding: gzip`
  - `decoded body: 221727 bytes`
  - `ratio: 0.16`

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

## Security basics
_Captured in 1 ms._

**Verdict: FAILED**

> These are high-level hygiene checks on HTTP headers, TLS, cookies and a few well-known exposed paths. PASS means the basics are in place. It does **not** mean the site is secure: application logic, authentication, plugins, server configuration and dependencies are not tested here. Treat FAILED as a must-fix and PASS as a starting point, not a certificate.

| Check | Tier | Status | Detail |
| --- | --- | --- | --- |
| HTTP redirects to HTTPS | basic | fail | Plain HTTP does not redirect to HTTPS. |
| Strict-Transport-Security | basic | fail | Strict-Transport-Security header is missing. |
| Clickjacking protection | basic | pass | Framing is restricted. |
| X-Content-Type-Options | basic | fail | X-Content-Type-Options header is missing. |
| Cookies Secure + HttpOnly | basic | n/a | The document response sets no cookies. |
| No mixed content | basic | pass | No http:// subresources were loaded. |
| CORS | basic | pass | No wildcard CORS origin. |
| Technology disclosure | basic | warn | Response headers disclose server technology. |
| TLS certificate and protocol | basic | pass | Valid certificate and modern TLS protocol. |
| No exposed sensitive files | basic | pass | None of 6 probed sensitive paths returned real content. |
| Forms do not post to HTTP | basic | pass | No form action uses http://. |
| Content-Security-Policy present | advanced | pass | Content-Security-Policy header is set. |
| CSP is strict | advanced | fail | CSP has 2 issues: default-src missing; object-src is not 'none'. |
| HSTS preload | advanced | fail | Strict-Transport-Security header is missing. |
| Referrer-Policy | advanced | fail | Referrer-Policy header is missing. |
| Permissions-Policy | advanced | fail | Permissions-Policy header is missing. |
| Cross-Origin-Opener-Policy | advanced | fail | Cross-Origin-Opener-Policy header is missing. |
| Cross-Origin-Resource-Policy | advanced | fail | Cross-Origin-Resource-Policy header is missing. |
| Cookies SameSite | advanced | n/a | The document response sets no cookies. |
| Subresource Integrity | advanced | warn | 2 of 2 cross-origin scripts lack an integrity attribute. |
| SPF + DMARC DNS records | advanced | pass | SPF and DMARC records are present. |
| WP version not disclosed | wordpress | pass | No WordPress version found in generator meta or core asset URLs. |
| xmlrpc.php disabled | wordpress | fail | xmlrpc.php accepts POST requests (brute-force / pingback vector). |
| User enumeration blocked | wordpress | pass | No username leak across 3 enumeration probes. |
| readme.html removed | wordpress | pass | readme.html is not served. |
| Directory listing off | wordpress | pass | Uploads directory does not return an index page. |
| debug.log not public | wordpress | pass | debug.log is not served. |
| No config backups or installer | wordpress | warn | Installer /wp-admin/install.php is reachable. Harmless while the site is installed, but it becomes an open takeover path if the database is ever unreachable — block it in .htaccess. |
| Login not on default path | wordpress | warn | Login form is served on the default /wp-login.php path. |